|
Log-Analyse und Auswertung: Backdoor?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
15.12.2009, 19:26 | #1 |
| Backdoor? Guten Abend! Ich hatte vorhin mehrere Infizierte Dateien und Regisrty einträge. Habe sie gleich mit Malwarebytes gelöscht. aber mein Internet ist immernoch viel zu langsam... Hier ist einmal der HijackThis Log -> Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:21:12, on 15.12.2009 Platform: Unknown Windows (WinNT 6.01.3504) MSIE: Unable to get Internet Explorer version! Boot mode: Normal Running processes: C:\Windows\SysWOW64\rundll32.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe C:\Program Files (x86)\Mouse Driver\StartAutorun.exe C:\Program Files (x86)\Mouse Driver\KMConfig.exe C:\Program Files (x86)\Java\jre6\bin\jusched.exe C:\Program Files (x86)\Mouse Driver\KMProcess.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Xfire\Xfire.exe C:\Teamspeak2_RC2\TeamSpeak.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Windows\SysWOW64\NOTEPAD.EXE C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files (x86)\Mouse Driver\StartAutorun.exe KMConfig.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST') O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe O13 - Gopher Prefix: O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files (x86)\Mouse Driver\KMWDSrv.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing) O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%SystemRoot%\system32\wlms\wlms.exe,-1 (WLMS) - Unknown owner - C:\Windows\system32\wlms\wlms.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 8212 bytes Code:
ATTFilter ------------------------------------------------- System Logs ------------------------------------------------- Tue Dec 15 17:34:47 2009 Unrecognized attempt blocked from 212.124.0.204:3641 to 91.16.179.57 TCP:445 Tue Dec 15 17:35:13 2009 DHCP:renew Tue Dec 15 17:35:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:35:43 2009 DHCP:renew Tue Dec 15 17:35:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:36:13 2009 DHCP:renew Tue Dec 15 17:36:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:36:43 2009 DHCP:renew Tue Dec 15 17:36:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:37:13 2009 DHCP:renew Tue Dec 15 17:37:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:37:32 2009 Unrecognized attempt blocked from 77.242.193.67:52090 to 91.16.179.57 TCP:50156 Tue Dec 15 17:37:35 2009 Unrecognized attempt blocked from 77.242.193.67:52090 to 91.16.179.57 TCP:50156 Tue Dec 15 17:37:41 2009 Unrecognized attempt blocked from 77.242.193.67:52090 to 91.16.179.57 TCP:50156 Tue Dec 15 17:37:43 2009 DHCP:renew Tue Dec 15 17:37:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:38:13 2009 DHCP:renew Tue Dec 15 17:38:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:38:33 2009 Disassociated: 00-22-5F-ED-8B-1D Tue Dec 15 17:38:43 2009 DHCP:renew Tue Dec 15 17:38:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:39:13 2009 DHCP:renew Tue Dec 15 17:39:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:39:28 2009 Unrecognized attempt blocked from 79.172.126.40:4646 to 91.16.179.57 TCP:445 Tue Dec 15 17:39:31 2009 Unrecognized attempt blocked from 79.172.126.40:4646 to 91.16.179.57 TCP:445 Tue Dec 15 17:39:43 2009 DHCP:renew Tue Dec 15 17:39:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:39:43 2009 Unrecognized attempt blocked from 94.29.11.10:2376 to 91.16.179.57 TCP:445 Tue Dec 15 17:39:46 2009 Unrecognized attempt blocked from 94.29.11.10:2376 to 91.16.179.57 TCP:445 Tue Dec 15 17:40:13 2009 DHCP:renew Tue Dec 15 17:40:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:40:43 2009 DHCP:renew Tue Dec 15 17:40:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:41:13 2009 DHCP:renew Tue Dec 15 17:41:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:41:43 2009 DHCP:renew Tue Dec 15 17:41:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:42:13 2009 DHCP:renew Tue Dec 15 17:42:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:42:43 2009 DHCP:renew Tue Dec 15 17:42:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:42:45 2009 Unrecognized attempt blocked from 79.89.88.88:3757 to 91.16.179.57 TCP:445 Tue Dec 15 17:42:48 2009 Unrecognized attempt blocked from 79.89.88.88:3757 to 91.16.179.57 TCP:445 Tue Dec 15 17:43:13 2009 DHCP:renew Tue Dec 15 17:43:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:43:43 2009 DHCP:renew Tue Dec 15 17:43:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:44:13 2009 DHCP:renew Tue Dec 15 17:44:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:44:43 2009 DHCP:renew Tue Dec 15 17:44:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:45:10 2009 Unrecognized attempt blocked from 156.17.235.91:2890 to 91.16.179.57 TCP:445 Tue Dec 15 17:45:13 2009 DHCP:renew Tue Dec 15 17:45:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:45:13 2009 Unrecognized attempt blocked from 156.17.235.91:2890 to 91.16.179.57 TCP:445 Tue Dec 15 17:45:43 2009 DHCP:renew Tue Dec 15 17:45:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:46:13 2009 DHCP:renew Tue Dec 15 17:46:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:46:43 2009 DHCP:renew Tue Dec 15 17:46:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:47:13 2009 DHCP:renew Tue Dec 15 17:47:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:47:43 2009 DHCP:renew Tue Dec 15 17:47:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:48:13 2009 DHCP:renew Tue Dec 15 17:48:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:48:43 2009 DHCP:renew Tue Dec 15 17:48:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:48:45 2009 Unrecognized attempt blocked from 78.88.232.6:4040 to 91.16.179.57 TCP:445 Tue Dec 15 17:48:48 2009 Unrecognized attempt blocked from 78.88.232.6:4040 to 91.16.179.57 TCP:445 Tue Dec 15 17:49:13 2009 DHCP:renew Tue Dec 15 17:49:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:49:43 2009 DHCP:renew Tue Dec 15 17:49:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:49:44 2009 Unrecognized attempt blocked from 64.188.187.251:1811 to 91.16.179.57 TCP:445 Tue Dec 15 17:49:47 2009 Unrecognized attempt blocked from 64.188.187.251:1811 to 91.16.179.57 TCP:445 Tue Dec 15 17:50:03 2009 Unrecognized attempt blocked from 186.58.0.93:2691 to 91.16.179.57 TCP:445 Tue Dec 15 17:50:06 2009 Unrecognized attempt blocked from 186.58.0.93:2691 to 91.16.179.57 TCP:445 Tue Dec 15 17:50:13 2009 DHCP:renew Tue Dec 15 17:50:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:50:20 2009 Unrecognized attempt blocked from 89.42.211.93:2297 to 91.16.179.57 TCP:445 Tue Dec 15 17:50:23 2009 Unrecognized attempt blocked from 89.42.211.93:2297 to 91.16.179.57 TCP:445 Tue Dec 15 17:50:43 2009 DHCP:renew Tue Dec 15 17:50:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:51:13 2009 DHCP:renew Tue Dec 15 17:51:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:51:43 2009 DHCP:renew Tue Dec 15 17:51:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:52:13 2009 DHCP:renew Tue Dec 15 17:52:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:52:36 2009 Unrecognized attempt blocked from 59.93.123.200:3493 to 91.16.179.57 TCP:445 Tue Dec 15 17:52:39 2009 Unrecognized attempt blocked from 59.93.123.200:3493 to 91.16.179.57 TCP:445 Tue Dec 15 17:52:43 2009 DHCP:renew Tue Dec 15 17:52:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:53:13 2009 DHCP:renew Tue Dec 15 17:53:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:53:43 2009 DHCP:renew Tue Dec 15 17:53:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:54:13 2009 DHCP:renew Tue Dec 15 17:54:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:54:43 2009 DHCP:renew Tue Dec 15 17:54:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:55:13 2009 DHCP:renew Tue Dec 15 17:55:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:55:43 2009 DHCP:renew Tue Dec 15 17:55:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:55:54 2009 Unrecognized attempt blocked from 85.15.88.95:1748 to 91.16.179.57 TCP:445 Tue Dec 15 17:55:57 2009 Unrecognized attempt blocked from 85.15.88.95:1748 to 91.16.179.57 TCP:445 Tue Dec 15 17:56:13 2009 DHCP:renew Tue Dec 15 17:56:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:56:43 2009 DHCP:renew Tue Dec 15 17:56:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:57:13 2009 DHCP:renew Tue Dec 15 17:57:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:57:43 2009 DHCP:renew Tue Dec 15 17:57:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:58:13 2009 DHCP:renew Tue Dec 15 17:58:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:58:43 2009 DHCP:renew Tue Dec 15 17:58:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:59:13 2009 DHCP:renew Tue Dec 15 17:59:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 17:59:43 2009 DHCP:renew Tue Dec 15 17:59:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:00:13 2009 DHCP:renew Tue Dec 15 18:00:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:00:43 2009 DHCP:renew Tue Dec 15 18:00:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:01:13 2009 DHCP:renew Tue Dec 15 18:01:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:01:43 2009 DHCP:renew Tue Dec 15 18:01:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:02:00 2009 Unrecognized attempt blocked from 99.38.140.234:2465 to 91.16.179.57 TCP:445 Tue Dec 15 18:02:02 2009 Unrecognized attempt blocked from 99.38.140.234:2465 to 91.16.179.57 TCP:445 Tue Dec 15 18:02:13 2009 DHCP:renew Tue Dec 15 18:02:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:02:43 2009 DHCP:renew Tue Dec 15 18:02:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:03:13 2009 DHCP:renew Tue Dec 15 18:03:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:03:43 2009 DHCP:renew Tue Dec 15 18:03:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:04:13 2009 DHCP:renew Tue Dec 15 18:04:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:04:43 2009 DHCP:renew Tue Dec 15 18:04:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:05:06 2009 Unrecognized attempt blocked from 94.66.101.2:3693 to 91.16.179.57 TCP:445 Tue Dec 15 18:05:09 2009 Unrecognized attempt blocked from 94.66.101.2:3693 to 91.16.179.57 TCP:445 Tue Dec 15 18:05:13 2009 DHCP:renew Tue Dec 15 18:05:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:05:43 2009 DHCP:renew Tue Dec 15 18:05:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:06:13 2009 DHCP:renew Tue Dec 15 18:06:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:06:43 2009 DHCP:renew Tue Dec 15 18:06:43 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:07:13 2009 DHCP:renew Tue Dec 15 18:07:13 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:07:43 2009 DHCP:renew Tue Dec 15 18:07:43 2009 DHCP:nak Tue Dec 15 18:07:43 2009 Release IP Tue Dec 15 18:07:43 2009 DHCP:discover() Tue Dec 15 18:07:45 2009 DHCP:offer(192.168.1.1) Tue Dec 15 18:07:45 2009 DHCP:request(91.16.216.222) Tue Dec 15 18:07:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:08:12 2009 ADPM ep 42193 ipa 152 ip 42193 UNo20 Tue Dec 15 18:08:12 2009 ADPM ep 42193 ipa 152 ip 42193 UNo21 Tue Dec 15 18:08:12 2009 DPM ep 42193 Tue Dec 15 18:08:15 2009 DHCP:renew Tue Dec 15 18:08:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:08:45 2009 DHCP:renew Tue Dec 15 18:08:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:09:15 2009 DHCP:renew Tue Dec 15 18:09:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:09:45 2009 DHCP:renew Tue Dec 15 18:09:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:10:01 2009 Associated: 00-22-5F-ED-8B-1D st=0 Tue Dec 15 18:10:15 2009 DHCP:renew Tue Dec 15 18:10:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:10:25 2009 Unrecognized attempt blocked from 77.242.193.65:56011 to 91.16.216.222 TCP:50929 Tue Dec 15 18:10:28 2009 Unrecognized attempt blocked from 77.242.193.65:56011 to 91.16.216.222 TCP:50929 Tue Dec 15 18:10:34 2009 Unrecognized attempt blocked from 77.242.193.65:56011 to 91.16.216.222 TCP:50929 Tue Dec 15 18:10:45 2009 DHCP:renew Tue Dec 15 18:10:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:11:15 2009 DHCP:renew Tue Dec 15 18:11:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:11:45 2009 DHCP:renew Tue Dec 15 18:11:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:11:46 2009 Disassociated: 00-22-5F-ED-8B-1D Tue Dec 15 18:12:15 2009 DHCP:renew Tue Dec 15 18:12:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:12:45 2009 DHCP:renew Tue Dec 15 18:12:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:13:15 2009 DHCP:renew Tue Dec 15 18:13:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:13:45 2009 DHCP:renew Tue Dec 15 18:13:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:14:15 2009 DHCP:renew Tue Dec 15 18:14:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:14:45 2009 DHCP:renew Tue Dec 15 18:14:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:15:15 2009 DHCP:renew Tue Dec 15 18:15:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:15:45 2009 DHCP:renew Tue Dec 15 18:15:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:16:15 2009 DHCP:renew Tue Dec 15 18:16:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:16:45 2009 DHCP:renew Tue Dec 15 18:16:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:17:15 2009 DHCP:renew Tue Dec 15 18:17:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:17:45 2009 DHCP:renew Tue Dec 15 18:17:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:18:15 2009 DHCP:renew Tue Dec 15 18:18:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:18:45 2009 DHCP:renew Tue Dec 15 18:18:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:19:15 2009 DHCP:renew Tue Dec 15 18:19:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:19:45 2009 DHCP:renew Tue Dec 15 18:19:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:19:58 2009 Unrecognized attempt blocked from 91.89.50.80:40008 to 91.16.216.222 TCP:135 Tue Dec 15 18:20:15 2009 DHCP:renew Tue Dec 15 18:20:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:20:45 2009 DHCP:renew Tue Dec 15 18:20:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:21:15 2009 DHCP:renew Tue Dec 15 18:21:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:21:45 2009 DHCP:renew Tue Dec 15 18:21:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:22:15 2009 DHCP:renew Tue Dec 15 18:22:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:22:45 2009 DHCP:renew Tue Dec 15 18:22:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:23:15 2009 DHCP:renew Tue Dec 15 18:23:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:23:45 2009 DHCP:renew Tue Dec 15 18:23:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:24:15 2009 DHCP:renew Tue Dec 15 18:24:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:24:45 2009 DHCP:renew Tue Dec 15 18:24:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:25:15 2009 DHCP:renew Tue Dec 15 18:25:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:25:45 2009 DHCP:renew Tue Dec 15 18:25:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:26:15 2009 DHCP:renew Tue Dec 15 18:26:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:26:45 2009 DHCP:renew Tue Dec 15 18:26:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:27:15 2009 DHCP:renew Tue Dec 15 18:27:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:27:45 2009 DHCP:renew Tue Dec 15 18:27:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:28:15 2009 DHCP:renew Tue Dec 15 18:28:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:28:45 2009 DHCP:renew Tue Dec 15 18:28:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:29:15 2009 DHCP:renew Tue Dec 15 18:29:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:29:45 2009 DHCP:renew Tue Dec 15 18:29:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:30:15 2009 DHCP:renew Tue Dec 15 18:30:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:30:45 2009 DHCP:renew Tue Dec 15 18:30:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:31:15 2009 DHCP:renew Tue Dec 15 18:31:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:31:45 2009 DHCP:renew Tue Dec 15 18:31:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:32:15 2009 DHCP:renew Tue Dec 15 18:32:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:32:45 2009 DHCP:renew Tue Dec 15 18:32:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:33:15 2009 DHCP:renew Tue Dec 15 18:33:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:33:45 2009 DHCP:renew Tue Dec 15 18:33:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:34:15 2009 DHCP:renew Tue Dec 15 18:34:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:34:45 2009 DHCP:renew Tue Dec 15 18:34:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:35:15 2009 DHCP:renew Tue Dec 15 18:35:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:35:45 2009 DHCP:renew Tue Dec 15 18:35:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:36:15 2009 DHCP:renew Tue Dec 15 18:36:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:36:45 2009 DHCP:renew Tue Dec 15 18:36:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:37:15 2009 DHCP:renew Tue Dec 15 18:37:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:37:45 2009 DHCP:renew Tue Dec 15 18:37:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:38:15 2009 DHCP:renew Tue Dec 15 18:38:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:38:45 2009 DHCP:renew Tue Dec 15 18:38:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:39:15 2009 DHCP:renew Tue Dec 15 18:39:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:39:45 2009 DHCP:renew Tue Dec 15 18:39:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:40:15 2009 DHCP:renew Tue Dec 15 18:40:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:40:45 2009 DHCP:renew Tue Dec 15 18:40:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:41:15 2009 DHCP:renew Tue Dec 15 18:41:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:41:45 2009 DHCP:renew Tue Dec 15 18:41:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:42:15 2009 DHCP:renew Tue Dec 15 18:42:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:42:45 2009 DHCP:renew Tue Dec 15 18:42:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:43:15 2009 DHCP:renew Tue Dec 15 18:43:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:43:45 2009 DHCP:renew Tue Dec 15 18:43:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:44:15 2009 DHCP:renew Tue Dec 15 18:44:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:44:45 2009 DHCP:renew Tue Dec 15 18:44:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:45:15 2009 DHCP:renew Tue Dec 15 18:45:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:45:45 2009 DHCP:renew Tue Dec 15 18:45:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:46:15 2009 DHCP:renew Tue Dec 15 18:46:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:46:45 2009 DHCP:renew Tue Dec 15 18:46:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:47:15 2009 DHCP:renew Tue Dec 15 18:47:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:47:45 2009 DHCP:renew Tue Dec 15 18:47:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:48:15 2009 DHCP:renew Tue Dec 15 18:48:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:48:45 2009 DHCP:renew Tue Dec 15 18:48:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:49:15 2009 DHCP:renew Tue Dec 15 18:49:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:49:45 2009 DHCP:renew Tue Dec 15 18:49:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:50:15 2009 DHCP:renew Tue Dec 15 18:50:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:50:45 2009 DHCP:renew Tue Dec 15 18:50:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:51:01 2009 TX TCP reset for 192.168.0.152(51711) -> 192.168.0.1(80) Tue Dec 15 18:51:15 2009 DHCP:renew Tue Dec 15 18:51:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:51:23 2009 TX TCP reset for 192.168.0.152(51825) -> 192.168.0.1(80) Tue Dec 15 18:51:23 2009 TX TCP reset for 192.168.0.152(51827) -> 192.168.0.1(80) Tue Dec 15 18:51:45 2009 DHCP:renew Tue Dec 15 18:51:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:52:11 2009 TX TCP reset for 192.168.0.152(52025) -> 192.168.0.1(80) Tue Dec 15 18:52:15 2009 DHCP:renew Tue Dec 15 18:52:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:52:45 2009 DHCP:renew Tue Dec 15 18:52:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:53:15 2009 DHCP:renew Tue Dec 15 18:53:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:53:45 2009 DHCP:renew Tue Dec 15 18:53:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:54:15 2009 DHCP:renew Tue Dec 15 18:54:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:54:45 2009 DHCP:renew Tue Dec 15 18:54:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:55:15 2009 DHCP:renew Tue Dec 15 18:55:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:55:45 2009 DHCP:renew Tue Dec 15 18:55:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:56:15 2009 DHCP:renew Tue Dec 15 18:56:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:56:45 2009 DHCP:renew Tue Dec 15 18:56:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:57:15 2009 DHCP:renew Tue Dec 15 18:57:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:57:45 2009 DHCP:renew Tue Dec 15 18:57:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:58:15 2009 DHCP:renew Tue Dec 15 18:58:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:58:45 2009 DHCP:renew Tue Dec 15 18:58:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:59:15 2009 DHCP:renew Tue Dec 15 18:59:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 18:59:45 2009 DHCP:renew Tue Dec 15 18:59:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:00:15 2009 DHCP:renew Tue Dec 15 19:00:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:00:45 2009 DHCP:renew Tue Dec 15 19:00:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:01:15 2009 DHCP:renew Tue Dec 15 19:01:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:01:45 2009 DHCP:renew Tue Dec 15 19:01:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:02:15 2009 DHCP:renew Tue Dec 15 19:02:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:02:45 2009 DHCP:renew Tue Dec 15 19:02:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:03:15 2009 DHCP:renew Tue Dec 15 19:03:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:03:45 2009 DHCP:renew Tue Dec 15 19:03:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:04:15 2009 DHCP:renew Tue Dec 15 19:04:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:04:45 2009 DHCP:renew Tue Dec 15 19:04:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:05:15 2009 DHCP:renew Tue Dec 15 19:05:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:05:45 2009 DHCP:renew Tue Dec 15 19:05:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:06:15 2009 DHCP:renew Tue Dec 15 19:06:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:06:45 2009 DHCP:renew Tue Dec 15 19:06:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:07:15 2009 DHCP:renew Tue Dec 15 19:07:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:07:45 2009 DHCP:renew Tue Dec 15 19:07:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:08:15 2009 DHCP:renew Tue Dec 15 19:08:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:08:45 2009 DHCP:renew Tue Dec 15 19:08:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:09:15 2009 DHCP:renew Tue Dec 15 19:09:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:09:45 2009 DHCP:renew Tue Dec 15 19:09:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:10:15 2009 DHCP:renew Tue Dec 15 19:10:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:10:45 2009 DHCP:renew Tue Dec 15 19:10:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:11:15 2009 DHCP:renew Tue Dec 15 19:11:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:11:45 2009 DHCP:renew Tue Dec 15 19:11:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:12:15 2009 DHCP:renew Tue Dec 15 19:12:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:12:45 2009 DHCP:renew Tue Dec 15 19:12:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:13:15 2009 DHCP:renew Tue Dec 15 19:13:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:13:45 2009 DHCP:renew Tue Dec 15 19:13:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:14:15 2009 DHCP:renew Tue Dec 15 19:14:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:14:45 2009 DHCP:renew Tue Dec 15 19:14:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:15:15 2009 DHCP:renew Tue Dec 15 19:15:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:15:45 2009 DHCP:renew Tue Dec 15 19:15:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:16:15 2009 DHCP:renew Tue Dec 15 19:16:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:16:45 2009 DHCP:renew Tue Dec 15 19:16:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:16:45 2009 Unrecognized attempt blocked from 91.37.172.120:3378 to 91.16.216.222 TCP:135 Tue Dec 15 19:16:48 2009 Unrecognized attempt blocked from 91.37.172.120:3378 to 91.16.216.222 TCP:135 Tue Dec 15 19:17:15 2009 DHCP:renew Tue Dec 15 19:17:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:17:21 2009 Associated: 00-22-5F-ED-8B-1D st=0 Tue Dec 15 19:17:45 2009 DHCP:renew Tue Dec 15 19:17:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:18:15 2009 DHCP:renew Tue Dec 15 19:18:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:18:45 2009 DHCP:renew Tue Dec 15 19:18:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:18:46 2009 Unrecognized attempt blocked from 91.3.101.152:2515 to 91.16.216.222 TCP:135 Tue Dec 15 19:18:49 2009 Unrecognized attempt blocked from 91.3.101.152:2515 to 91.16.216.222 TCP:135 Tue Dec 15 19:19:15 2009 DHCP:renew Tue Dec 15 19:19:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:19:45 2009 DHCP:renew Tue Dec 15 19:19:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:20:15 2009 DHCP:renew Tue Dec 15 19:20:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:20:45 2009 DHCP:renew Tue Dec 15 19:20:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:21:15 2009 DHCP:renew Tue Dec 15 19:21:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:21:45 2009 DHCP:renew Tue Dec 15 19:21:45 2009 DHCP:ack(DOL=60,T1=30,T2=53) Tue Dec 15 19:22:15 2009 DHCP:renew Tue Dec 15 19:22:15 2009 DHCP:ack(DOL=60,T1=30,T2=53) FoX Edit: Hier nochmal ein log von Malwarebytes: Code:
ATTFilter Malwarebytes' Anti-Malware 1.42 Datenbank Version: 3289 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 15.12.2009 16:49:32 mbam-log-2009-12-15 (16-49-32).txt Scan-Methode: Quick-Scan Durchsuchte Objekte: 86746 Laufzeit: 2 minute(s), 59 second(s) Infizierte Speicherprozesse: 1 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 2 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 1 Infizierte Verzeichnisse: 0 Infizierte Dateien: 5 Infizierte Speicherprozesse: C:\Windows\msb.exe (Trojan.Agent) -> Failed to unload process. Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vegas (Trojan.FakeAlert) -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Windows\cssrs.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\msa.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\msb.exe (Trojan.Agent) -> Delete on reboot. C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Windows\System32\sshnas.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. Hier noch ein Log von Randoms System Information Tool: Code:
ATTFilter Logfile of random's system information tool 1.06 (written by random/random) Run by Kevin at 2009-12-15 19:41:40 Microsoft Windows 7 Enterprise System drive C: has 98 GB (74%) free of 131 GB Total RAM: 4095 MB (61% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:41:40, on 15.12.2009 Platform: Unknown Windows (WinNT 6.01.3504) MSIE: Unable to get Internet Explorer version! Boot mode: Normal Running processes: C:\Windows\SysWOW64\rundll32.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe C:\Program Files (x86)\Mouse Driver\StartAutorun.exe C:\Program Files (x86)\Mouse Driver\KMConfig.exe C:\Program Files (x86)\Java\jre6\bin\jusched.exe C:\Program Files (x86)\Mouse Driver\KMProcess.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Xfire\Xfire.exe C:\Teamspeak2_RC2\TeamSpeak.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Users\Kevin\Desktop\RSIT.exe C:\Program Files (x86)\Trend Micro\HijackThis\Kevin.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files (x86)\Mouse Driver\StartAutorun.exe KMConfig.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST') O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe O13 - Gopher Prefix: O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files (x86)\Mouse Driver\KMWDSrv.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing) O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%SystemRoot%\system32\wlms\wlms.exe,-1 (WLMS) - Unknown owner - C:\Windows\system32\wlms\wlms.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 8207 bytes ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2009-10-10 41760] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "KMCONFIG"=C:\Program Files (x86)\Mouse Driver\StartAutorun.exe [2007-03-06 212992] "SunJavaUpdateSched"=C:\Program Files (x86)\Java\jre6\bin\jusched.exe [2009-10-10 149280] "StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-11-04 98304] "ATICustomerCare"=C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe [2009-06-14 307200] "avast!"=C:\Program Files\Alwil Software\Avast4\ashDisp.exe [2009-11-25 81000] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"=C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856] "DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe [2008-07-24 490952] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vga.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vgasave.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=0 "ConsentPromptBehaviorUser"=3 "EnableLUA"=0 "EnableUIADesktopToggle"=0 "PromptOnSecureDesktop"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoActiveDesktop"= "ForceActiveDesktopOn"= "NoActiveDesktopChanges"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7053540b-afee-11de-bc59-806e6f6e6963}] shell\AutoRun\command - F:\wolfET.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d955ee15-c55c-11de-9972-001837059687}] shell\AutoRun\command - H:\autorun.exe ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 months====== 2009-12-15 19:40:23 ----D---- C:\rsit 2009-12-15 16:45:40 ----D---- C:\Users\Kevin\AppData\Roaming\Malwarebytes 2009-12-15 16:45:34 ----D---- C:\ProgramData\Malwarebytes 2009-12-15 16:45:33 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2009-12-15 16:18:02 ----D---- C:\Program Files (x86)\Trend Micro 2009-12-10 18:06:19 ----D---- C:\Program Files (x86)\Nuclear Coffee 2009-12-09 21:05:40 ----A---- C:\Windows\system32\WNASPI32.DLL 2009-12-09 21:05:37 ----D---- C:\Program Files (x86)\4Musics MP3 to OGG Converter 2009-12-09 14:50:08 ----D---- C:\Program Files (x86)\Ubisoft 2009-12-09 14:40:01 ----D---- C:\Program Files (x86)\No23 Recorder 2009-12-07 18:13:46 ----A---- C:\Windows\system32\d3dx9.dll 2009-12-07 18:13:46 ----A---- C:\Windows\system32\D3DX81ab.dll 2009-12-07 18:13:45 ----D---- C:\Program Files (x86)\Cheat Engine 2009-12-07 00:35:24 ----D---- C:\Program Files (x86)\WashAndGo 2009-12-06 13:01:02 ----D---- C:\Users\Kevin\AppData\Roaming\ASCOMP Software 2009-12-04 20:38:38 ----A---- C:\Windows\system32\iacenc.dll 2009-12-03 23:24:53 ----D---- C:\Users\Kevin\AppData\Roaming\PE Explorer 2009-12-03 23:24:49 ----D---- C:\Program Files (x86)\PE Explorer 2009-12-03 23:06:13 ----A---- C:\Windows\system32\aswBoot.exe 2009-12-03 12:43:37 ----D---- C:\ProgramData\PopCap Games 2009-12-03 12:43:37 ----D---- C:\Program Files (x86)\PopCap Games 2009-12-01 15:49:44 ----D---- C:\Program Files (x86)\JoWood 2009-12-01 13:05:32 ----A---- C:\Windows\CD_Start.INI 2009-11-30 20:33:46 ----A---- C:\Windows\system32\xfcodec.dll 2009-11-29 14:11:36 ----D---- C:\ProgramData\ATI 2009-11-29 14:08:53 ----D---- C:\Program Files (x86)\ATI 2009-11-28 20:12:32 ----D---- C:\Program Files (x86)\ArtMoney 2009-11-26 18:53:07 ----D---- C:\Fraps 2009-11-22 10:39:45 ----D---- C:\Program Files (x86)\CCleaner 2009-11-21 09:46:32 ----A---- C:\Windows\system32\frapsvid.dll 2009-11-18 20:28:37 ----D---- C:\Program Files (x86)\ManuAdminMod TCP Console 2009-11-16 14:19:12 ----D---- C:\ProgramData\Test Drive Unlimited 2009-11-16 14:10:22 ----RHD---- C:\Users\Kevin\AppData\Roaming\SecuROM 2009-11-16 14:10:21 ----A---- C:\Windows\system32\CmdLineExt_x64.dll ======List of files/folders modified in the last 1 months====== 2009-12-15 19:41:40 ----D---- C:\Windows\Temp 2009-12-15 19:40:27 ----D---- C:\Windows\Prefetch 2009-12-15 18:50:05 ----D---- C:\Program Files (x86)\Mozilla Firefox 2009-12-15 18:42:31 ----HD---- C:\Program Files (x86)\InstallShield Installation Information 2009-12-15 18:42:30 ----SHD---- C:\System Volume Information 2009-12-15 18:16:40 ----D---- C:\Windows\debug 2009-12-15 18:16:40 ----D---- C:\Windows 2009-12-15 16:49:32 ----D---- C:\Windows\SysWOW64 2009-12-15 16:49:31 ----D---- C:\Windows\Tasks 2009-12-15 16:45:35 ----D---- C:\Windows\system32\drivers 2009-12-15 16:45:34 ----HD---- C:\ProgramData 2009-12-15 16:45:33 ----RD---- C:\Program Files (x86) 2009-12-15 15:45:23 ----D---- C:\Users\Kevin\AppData\Roaming\teamspeak2 2009-12-15 13:39:50 ----D---- C:\Users\Kevin\AppData\Roaming\BitTorrent 2009-12-14 22:12:36 ----D---- C:\Users\Kevin\AppData\Roaming\Xfire 2009-12-14 20:46:30 ----A---- C:\Windows\system32\PnkBstrB.exe 2009-12-14 16:55:45 ----D---- C:\Users\Kevin\AppData\Roaming\Skype 2009-12-14 16:09:23 ----D---- C:\Users\Kevin\AppData\Roaming\skypePM 2009-12-13 14:08:13 ----SHD---- C:\Windows\Installer 2009-12-13 09:59:47 ----D---- C:\ProgramData\Xfire 2009-12-13 00:15:30 ----SD---- C:\Users\Kevin\AppData\Roaming\Microsoft 2009-12-12 02:57:46 ----A---- C:\Windows\BlendSettings.ini 2009-12-11 22:28:09 ----RD---- C:\Program Files 2009-12-09 16:34:26 ----A---- C:\Windows\system32\PnkBstrA.exe 2009-12-09 14:53:46 ----RSD---- C:\Windows\assembly 2009-12-09 14:52:45 ----A---- C:\Windows\system32\pbsvc.exe 2009-12-08 19:18:35 ----D---- C:\Windows\System32 2009-12-08 19:18:35 ----D---- C:\Windows\inf 2009-12-07 00:16:43 ----D---- C:\Program Files (x86)\Lavalys 2009-12-03 12:41:42 ----D---- C:\Program Files (x86)\Xfire 2009-11-29 22:57:59 ----SD---- C:\ProgramData\Microsoft 2009-11-29 22:53:13 ----D---- C:\Users\Kevin\AppData\Roaming\gtk-2.0 2009-11-29 03:22:55 ----D---- C:\Users\Kevin\AppData\Roaming\ICQ 2009-11-24 21:19:28 ----D---- C:\Windows\Downloaded Program Files 2009-11-22 10:43:11 ----D---- C:\ProgramData\Codemasters 2009-11-22 10:40:11 ----D---- C:\Windows\Minidump 2009-11-21 15:34:11 ----D---- C:\Windows\Logs 2009-11-18 20:29:27 ----D---- C:\Users\Kevin\AppData\Roaming\HLSW Geändert von fox213 (15.12.2009 um 19:46 Uhr) |