|
Log-Analyse und Auswertung: Av AntiRootkit scan - gefährlicher Fund?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
07.01.2010, 17:40 | #1 |
| Av AntiRootkit scan - gefährlicher Fund? Hallo zusammen! Ich habe geraden einen Rootkit scan mit Av AntiRootkit Tool gemacht und habe das folgenden Report erhalten: Code:
ATTFilter Avira AntiRootkit Tool (1.1.0.1) ======================================================================================================== - Scan started Donnerstag, 7. Januar 2010 - 16:49:27 ======================================================================================================== -------------------------------------------------------------------------------------------------------- Configuration: -------------------------------------------------------------------------------------------------------- - [X] Scan files - [X] Scan registry - [X] Scan processes - [ ] Fast scan - Working disk total size : 186.30 GB - Working disk free size : 25.38 GB (13 %) -------------------------------------------------------------------------------------------------------- Results: Embedded nulls : HKEY_USERS\S-1-5-21-1757981266-1060284298-839522115-1006\Software\YourCompanyName\YourProductName\Version Hidden value : HKEY_USERS\S-1-5-21-1757981266-1060284298-839522115-1006\Software\YourCompanyName\YourProductName\Version -> versiondata Hidden key : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\notify Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> autorestartshell Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> defaultdomainname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> defaultusername Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> legalnoticecaption Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> legalnoticetext Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> powerdownaftershutdown Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> reportbootok Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> shell Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> shutdownwithoutlogon Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> system Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> userinit Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> vmapplet Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> sfcquota Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> allocatecdroms Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> allocatedasd Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> allocatefloppies Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> cachedlogonscount Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> forceunlocklogon Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> passwordexpirywarning Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> scremoveoption Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> allowmultipletssessions Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> uihost Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> logontype Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> background Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> debugservercommand Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> sfcdisable Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> winstationsdisabled Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> hibernationpreviouslyenabled Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> showlogonoptions Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> altdefaultusername Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> altdefaultdomainname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> nomachinepolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> nouserpolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> noslowlink Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> nobackgroundpolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> nogpolistchanges Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> peruserlocalsettings Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> requiressuccessfulregistry Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> enableasynchronousprocessing Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> dllname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> processgrouppolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} -> dllname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} -> processgrouppolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} -> nogpolistchanges Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} -> requiressucessfulregistry Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} -> displayname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} -> requiressuccessfulregistry Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} -> displayname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} -> dllname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} -> nogpolistchanges Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} -> processgrouppolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} -> processgrouppolicyex Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} -> requiressuccessfulregistry Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> processgrouppolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> generategrouppolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> extensionrsopplanningdebuglevel Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> processgrouppolicyex Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> extensiondebuglevel Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> dllname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> nouserpolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> nogpolistchanges Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> enableasynchronousprocessing Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> maxnogpolistchangesinterval Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> processgrouppolicyex Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> generategrouppolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> processgrouppolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> dllname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> noslowlink Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> nobackgroundpolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> nogpolistchanges Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> nomachinepolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> displayname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} -> processgrouppolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} -> dllname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} -> nouserpolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} -> nogpolistchanges Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} -> requiressuccessfulregistry Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> dllname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> enableasynchronousprocessing Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> nobackgroundpolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> nogpolistchanges Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> nomachinepolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> noslowlink Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> nouserpolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> peruserlocalsettings Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> processgrouppolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> requiressuccessfulregistry Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> dllname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> processgrouppolicyex Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> generategrouppolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> nobackgroundpolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> requiressucessfulregistry Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> noslowlink Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> peruserlocalsettings Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> eventsources Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} -> displayname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} -> dllname Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} -> nogpolistchanges Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} -> processgrouppolicy Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} -> processgrouppolicyex Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} -> requiressuccessfulregistry Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> hilfeassistent Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> tsinternetuser Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> sqlagentcmdexec Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> netshowservices Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> helpassistant Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> iwam_ Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> iusr_ Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> vusr_ Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> aspnet -------------------------------------------------------------------------------------------------------- Files: 0/258891 Registry items: 113/573397 Processes: 0/54 Scan time: 00:18:10 -------------------------------------------------------------------------------------------------------- Active processes: - ksqoalfc.exe (PID 1460) (Avira AntiRootkit Tool) - update.exe (PID 2540) - avnotify.exe (PID 3576) - System (PID 4) - smss.exe (PID 636) - csrss.exe (PID 872) - winlogon.exe (PID 904) - services.exe (PID 952) - lsass.exe (PID 964) - ati2evxx.exe (PID 1124) - svchost.exe (PID 1140) - svchost.exe (PID 1212) - svchost.exe (PID 1356) - InCDsrv.exe (PID 1376) - ati2evxx.exe (PID 1452) - svchost.exe (PID 1524) - svchost.exe (PID 1648) - svchost.exe (PID 1728) - spoolsv.exe (PID 1784) - sched.exe (PID 1832) - svchost.exe (PID 1912) - avguard.exe (PID 1960) - AOLacsd.exe (PID 1972) - AppleMobileDeviceService.exe (PID 1988) - bgsvcgen.exe (PID 2044) - mDNSResponder.exe (PID 144) - ICQ Service.exe (PID 192) - svchost.exe (PID 544) - wanmpsvc.exe (PID 664) - alg.exe (PID 1392) - explorer.exe (PID 2272) - SOUNDMAN.EXE (PID 2556) - InCD.exe (PID 2712) - Application Launcher.exe (PID 2772) - QTTask.exe (PID 2788) - realplay.exe (PID 2796) - SweetIM.exe (PID 2804) - avgnt.exe (PID 2820) - ctfmon.exe (PID 2828) - MOM.exe (PID 2840) - hpotdd01.exe (PID 2892) - WiFiN.exe (PID 2916) - aolsoftware.exe (PID 3112) - CCC.exe (PID 3532) - OIS.EXE (PID 3776) - Generic.exe (PID 3344) - epmworker.exe (PID 3260) - iexplore.exe (PID 3440) - iexplore.exe (PID 3608) - iexplore.exe (PID 3296) - iexplore.exe (PID 2596) - iexplore.exe (PID 2524) - notepad.exe (PID 276) - avirarkd.exe (PID 1876) ======================================================================================================== - Scan finished Donnerstag, 7. Januar 2010 - 17:07:37 ======================================================================================================== Hab es gestern auch noch mit GMER versucht und gescannt, dann aber nach einiger zeit abgebrochen, da es sehr langsam voran ging. Hier der Report: Code:
ATTFilter GMER 1.0.15.14966 - h******w.gmer.net Rootkit scan 2010-01-07 053009 Windows 5.1.2600 Service Pack 2 ---- System - GMER 1.0.15 ---- SSDT F7C8D106 ZwCreateKey SSDT F7C8D0FC ZwCreateThread SSDT F7C8D10B ZwDeleteKey SSDT F7C8D115 ZwDeleteValueKey SSDT F7C8D11A ZwLoadKey SSDT F7C8D0E8 ZwOpenProcess SSDT F7C8D0ED ZwOpenThread SSDT F7C8D124 ZwReplaceKey SSDT F7C8D11F ZwRestoreKey SSDT F7C8D110 ZwSetValueKey SSDT F7C8D0F7 ZwTerminateProcess ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwCallbackReturn + 2514 80501404 4 Bytes CALL 5147DCD9 ---- User IATEAT - GMER 1.0.15 ---- IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32msvcrt.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32WS2_32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32psapi.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32psapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32userenv.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32userenv.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32userenv.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32userenv.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32MSVCRT.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32MSVCRT.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32shell32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32shell32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32shell32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32shell32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32shell32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC) ---- Devices - GMER 1.0.15 ---- Device pci.sys (NT-Plug & Play PCI-EnumeratorMicrosoft Corporation) ---- EOF - GMER 1.0.15 ---- Die Datei 'G:\System Volume Information\_restore{BACF4CAC-049B-4C5F-863E-E8BDEFFFEB3C}\RP22\A0003150.exe' enthielt einen Virus oder unerwünschtes Programm 'TR/FraudPack.aebj' [trojan]. Durchgeführte Aktion(en): Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4b751eed.qua' verschoben! Der normale Virenscanner von AV findet keine Viren. Bitte um schnelle Hilfe! Danke im voraus! |
07.01.2010, 21:25 | #3 |
| Av AntiRootkit scan - gefährlicher Fund? Also hab jetzt die neuste Version von GMER 3 Stunden laufen lassen.. bei den Programmen war kein vorwärts mehr.. aber ich denke ich hab bereits fast alles im Report:
__________________Code:
ATTFilter GMER 1.0.15.15281 - h***://w**.gmer.net Rootkit scan 2010-01-07 21:05:19 Windows 5.1.2600 Service Pack 2 Running: n211nvn0.exe; Driver: G:\DOKUME~1\******\LOKALE~1\Temp\kxnyqkoc.sys ---- System - GMER 1.0.15 ---- SSDT F7C18D9E ZwCreateKey SSDT F7C18D94 ZwCreateThread SSDT F7C18DA3 ZwDeleteKey SSDT F7C18DAD ZwDeleteValueKey SSDT F7C18DB2 ZwLoadKey SSDT F7C18D80 ZwOpenProcess SSDT F7C18D85 ZwOpenThread SSDT F7C18DBC ZwReplaceKey SSDT F7C18DB7 ZwRestoreKey SSDT F7C18DA8 ZwSetValueKey SSDT F7C18D8F ZwTerminateProcess ---- Kernel code sections - GMER 1.0.15 ---- .text G:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF6212000, 0x187662, 0xE8000020] .text G:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xA7D48300, 0x22020, 0xE8000020] .text G:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xF7994300, 0x1B7E, 0xE8000020] ---- User IAT/EAT - GMER 1.0.15 ---- IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\psapi.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\psapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\userenv.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\shell32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) ---- Devices - GMER 1.0.15 ---- Device pci.sys (NT-Plug & Play PCI-Enumerator/Microsoft Corporation) AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@AutoRestartShell 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@DefaultDomainName ******-****** Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@DefaultUserName ****** Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@LegalNoticeCaption Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@LegalNoticeText Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@PowerdownAfterShutdown 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@ReportBootOk 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@Shell Explorer.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@ShutdownWithoutLogon 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@System Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit G:\WINDOWS\system32\userinit.exe, Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@VmApplet rundll32 shell32,Control_RunDLL "sysdm.cpl" Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@SfcQuota -1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@allocatecdroms 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@allocatedasd 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@allocatefloppies 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@cachedlogonscount 10 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@forceunlocklogon 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@passwordexpirywarning 14 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@scremoveoption 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@AllowMultipleTSSessions 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@UIHost logonui.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@LogonType 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@Background 0 0 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@DebugServerCommand no Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@SFCDisable 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@WinStationsDisabled 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@HibernationPreviouslyEnabled 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@ShowLogonOptions 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@AltDefaultUserName ****** Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@AltDefaultDomainName ******-****** Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@ Microsoft-Datentr?gerkontingent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoMachinePolicy 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoUserPolicy 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoSlowLink 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoBackgroundPolicy 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoGPOListChanges 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@PerUserLocalSettings 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@RequiresSuccessfulRegistry 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@EnableAsynchronousProcessing 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@DllName dskquota.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@ProcessGroupPolicy ProcessGroupPolicy Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@ Internet Explorer Zonemapping Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@DllName G:\WINDOWS\system32\iedkcs32.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@ProcessGroupPolicy ProcessGroupPolicyForZoneMap Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@NoGPOListChanges 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@RequiresSucessfulRegistry 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@DisplayName @G:\WINDOWS\system32\iedkcs32.dll.mui,-3051 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@RequiresSuccessfulRegistry 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@ Internet Explorer User Accelerators Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@DisplayName @G:\WINDOWS\system32\iedkcs32.dll.mui,-3051 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@DllName G:\WINDOWS\system32\iedkcs32.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@NoGPOListChanges 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@ProcessGroupPolicy ProcessGroupPolicyForActivities Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@ProcessGroupPolicyEx ProcessGroupPolicyForActivitiesEx Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@RequiresSuccessfulRegistry 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ProcessGroupPolicy SceProcessSecurityPolicyGPO Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@GenerateGroupPolicy SceGenerateGroupPolicy Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ExtensionRsopPlanningDebugLevel 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ProcessGroupPolicyEx SceProcessSecurityPolicyGPOEx Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ExtensionDebugLevel 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@DllName scecli.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ Security Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@NoUserPolicy 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@NoGPOListChanges 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@EnableAsynchronousProcessing 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@MaxNoGPOListChangesInterval 960 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@ProcessGroupPolicyEx ProcessGroupPolicyEx Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@GenerateGroupPolicy GenerateGroupPolicy Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@ProcessGroupPolicy ProcessGroupPolicy Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@DllName G:\WINDOWS\system32\iedkcs32.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@ Internet Explorer Branding Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoSlowLink 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoBackgroundPolicy 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoGPOListChanges 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoMachinePolicy 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@DisplayName @G:\WINDOWS\system32\iedkcs32.dll.mui,-3014 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@ProcessGroupPolicy SceProcessEFSRecoveryGPO Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@DllName scecli.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@ EFS recovery Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@NoUserPolicy 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@NoGPOListChanges 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@RequiresSuccessfulRegistry 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@ Microsoft Offline Files Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@DllName %SystemRoot%\System32\cscui.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@EnableAsynchronousProcessing 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoBackgroundPolicy 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoGPOListChanges 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoMachinePolicy 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoSlowLink 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoUserPolicy 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@PerUserLocalSettings 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@ProcessGroupPolicy ProcessGroupPolicy Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@RequiresSuccessfulRegistry 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@ Softwareinstallation Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@DllName appmgmts.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@ProcessGroupPolicyEx ProcessGroupPolicyObjectsEx Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@GenerateGroupPolicy GenerateGroupPolicy Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@NoBackgroundPolicy 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@RequiresSucessfulRegistry 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@NoSlowLink 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@PerUserLocalSettings 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@EventSources (Application Management,Application)?(MsiInstaller,Application)? Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@ Internet Explorer Machine Accelerators Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@DisplayName @G:\WINDOWS\system32\iedkcs32.dll.mui,-3051 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@DllName G:\WINDOWS\system32\iedkcs32.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@NoGPOListChanges 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@ProcessGroupPolicy ProcessGroupPolicyForActivities Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@ProcessGroupPolicyEx ProcessGroupPolicyForActivitiesEx Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@RequiresSuccessfulRegistry 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@DLLName Ati2evxx.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Asynchronous 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Impersonate 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Lock AtiLockEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Logoff AtiLogoffEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Logon AtiLogonEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Disconnect AtiDisConnectEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Reconnect AtiReConnectEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Safe 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Shutdown AtiShutdownEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@StartScreenSaver AtiStartScreenSaverEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@StartShell AtiStartShellEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Startup AtiStartupEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@StopScreenSaver AtiStopScreenSaverEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Unlock AtiUnLockEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain@Asynchronous 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain@Impersonate 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain@DllName crypt32.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain@Logoff ChainWlxLogoffEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet@Asynchronous 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet@Impersonate 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet@DllName cryptnet.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet@Logoff CryptnetWlxLogoffEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@DLLName cscdll.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@Logon WinlogonLogonEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@Logoff WinlogonLogoffEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@ScreenSaver WinlogonScreenSaverEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@Startup WinlogonStartupEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@Shutdown WinlogonShutdownEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@StartShell WinlogonStartShellEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@Impersonate 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@Asynchronous 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@DLLName wlnotify.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Logon SCardStartCertProp Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Logoff SCardStopCertProp Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Lock SCardSuspendCertProp Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Unlock SCardResumeCertProp Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Enabled 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Impersonate 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Asynchronous 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule@Asynchronous 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule@DllName wlnotify.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule@Impersonate 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule@StartShell SchedStartShell Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule@Logoff SchedEventLogOff Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy@Logoff WLEventLogoff Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy@Impersonate 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy@Asynchronous 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy@DllName sclgntfy.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@DLLName WlNotify.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Lock SensLockEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Logon SensLogonEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Logoff SensLogoffEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Safe 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@MaxWait 600 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@StartScreenSaver SensStartScreenSaverEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@StopScreenSaver SensStopScreenSaverEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Startup SensStartupEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Shutdown SensShutdownEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@StartShell SensStartShellEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@PostShell SensPostShellEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Disconnect SensDisconnectEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Reconnect SensReconnectEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Unlock SensUnlockEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Impersonate 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Asynchronous 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Asynchronous 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@DllName wlnotify.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Impersonate 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Logoff TSEventLogoff Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Logon TSEventLogon Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@PostShell TSEventPostShell Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Shutdown TSEventShutdown Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@StartShell TSEventStartShell Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Startup TSEventStartup Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@MaxWait 600 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Reconnect TSEventReconnect Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Disconnect TSEventDisconnect Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Logon WLEventLogon Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Logoff WLEventLogoff Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Startup WLEventStartup Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Shutdown WLEventShutdown Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@StartScreenSaver WLEventStartScreenSaver Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@StopScreenSaver WLEventStopScreenSaver Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Lock WLEventLock Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Unlock WLEventUnlock Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@StartShell WLEventStartShell Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@PostShell WLEventPostShell Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Disconnect WLEventDisconnect Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Reconnect WLEventReconnect Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Impersonate 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Asynchronous 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@SafeMode 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@MaxWait -1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@DllName WgaLogon.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Event 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@EulaAccepted 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings@Data 0x01 0x00 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon@DLLName wlnotify.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon@Logon RegisterTicketExpiredNotificationEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon@Logoff UnregisterTicketExpiredNotificationEvent Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon@Impersonate 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon@Asynchronous 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SCLogon Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@Hilfeassistent 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@TsInternetUser 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@SQLAgentCmdExec 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@NetShowServices 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@HelpAssistant 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@IWAM_ 65536 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@IUSR_ 65536 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@VUSR_ 65536 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@ASPNET 0 ---- EOF - GMER 1.0.15 ---- Bei Av AntiRootkit Tool war alles rot. Sry kenn mich damit nicht so gut aus. Also sind die Einträge i. O.? Sind ja viele dabei die schon av gefunden hatte... |
08.01.2010, 18:08 | #4 |
| Av AntiRootkit scan - gefährlicher Fund? Kann mir jemand sagen ob in dem Report nun gefährliche Rootkits drin sind? Oder soll ich den Beitrag in ein anderes Forum posten? |
08.01.2010, 18:17 | #5 | |
| Av AntiRootkit scan - gefährlicher Fund?Zitat:
__________________ MfG Ralf |
08.01.2010, 22:23 | #6 |
| Av AntiRootkit scan - gefährlicher Fund? Okay sry. Hier der Report: Code:
ATTFilter Malwarebytes' Anti-Malware 1.44 Datenbank Version: 3519 Windows 5.1.2600 Service Pack 2 Internet Explorer 8.0.6001.18702 08.01.2010 22:18:33 mbam-log-2010-01-08 (22-18-28).txt Scan-Methode: Vollständiger Scan (G:\|) Durchsuchte Objekte: 357437 Laufzeit: 2 hour(s), 33 minute(s), 10 second(s) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 3 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 3 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> No action taken. Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: G:\Dokumente und Einstellungen\******\Lokale Einstellungen\Temp\87.tmp (Backdoor.Bot) -> No action taken. G:\WINDOWS\system32\qgjo.ijo (Backdoor.Bot) -> No action taken. G:\Programme\ICQToolbar\toolbaru.dll (Trojan.BHO) -> No action taken. |
09.01.2010, 13:30 | #8 |
| Av AntiRootkit scan - gefährlicher Fund? Okay werde ich gleich machen. Kannst du mir sagen was die Viren, oder was auch immer es ist anrichten oder vielleicht schon angerichtet haben? Und mit welchen Folgen ich rechnen muss? |
09.01.2010, 13:34 | #9 |
| Av AntiRootkit scan - gefährlicher Fund? Mit allem! Passworte klauen, Spam versenden, DDos Attacken fahren. Bei so viel neuer Malware muss man immer vom schlimmsten ausgehen...
__________________ MfG Ralf |
09.01.2010, 13:46 | #10 |
| Av AntiRootkit scan - gefährlicher Fund? Hier der RSIT Report Code:
ATTFilter Logfile of random's system information tool 1.06 (written by random/random) Run by ****** at 2010-01-09 13:36:03 Microsoft Windows XP Home Edition Service Pack 2 System drive G: has 40 GB (21%) free of 191 GB Total RAM: 1023 MB (54% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:36:18, on 09.01.2010 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: G:\WINDOWS\System32\smss.exe G:\WINDOWS\system32\winlogon.exe G:\WINDOWS\system32\services.exe G:\WINDOWS\system32\lsass.exe G:\WINDOWS\system32\Ati2evxx.exe G:\WINDOWS\system32\svchost.exe G:\WINDOWS\System32\svchost.exe G:\Programme\Ahead\InCD\InCDsrv.exe G:\WINDOWS\system32\svchost.exe G:\WINDOWS\system32\spoolsv.exe G:\Programme\Avira\AntiVir Desktop\sched.exe G:\Programme\Avira\AntiVir Desktop\avguard.exe G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe G:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe G:\WINDOWS\system32\bgsvcgen.exe G:\Programme\Bonjour\mDNSResponder.exe G:\Programme\ICQ6Toolbar\ICQ Service.exe G:\WINDOWS\system32\svchost.exe G:\WINDOWS\wanmpsvc.exe G:\WINDOWS\system32\Ati2evxx.exe G:\WINDOWS\Explorer.EXE G:\WINDOWS\SOUNDMAN.EXE G:\Programme\Ahead\InCD\InCD.exe G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe G:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe G:\Programme\QuickTime\qttask.exe G:\Programme\Real\RealPlayer\RealPlay.exe G:\Programme\SweetIM\Messenger\SweetIM.exe G:\Programme\ATI Technologies\ATI.ACE\Core-Static\MOM.exe G:\Programme\Avira\AntiVir Desktop\avgnt.exe G:\WINDOWS\system32\ctfmon.exe G:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe G:\Programme\Hercules\WiFiStation\WiFiN.exe G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe G:\Programme\ATI Technologies\ATI.ACE\Core-Static\ccc.exe G:\Dokumente und Einstellungen\******\Desktop\RSIT.exe G:\Programme\trend micro\******.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - G:\Programme\ICQ6Toolbar\ICQToolBar.dll R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - G:\Programme\SweetIM\Toolbars\Internet Explorer\mgHelper.dll R3 - URLSearchHook: (no name) - - (no file) O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - G:\PROGRA~1\ICQTOO~1\toolbaru.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Programme\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - G:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - G:\Programme\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - G:\Programme\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - G:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - G:\Programme\ICQ6Toolbar\ICQToolBar.dll O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - G:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - G:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [InCD] G:\Programme\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [AOLDialer] G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "G:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [StartCCC] "G:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" O4 - HKLM\..\Run: [QuickTime Task] "G:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [RealTray] G:\Programme\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [SweetIM] G:\Programme\SweetIM\Messenger\SweetIM.exe O4 - HKLM\..\Run: [Google Desktop Search] "G:\Programme\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [avgnt] "G:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [OM_Monitor] G:\Programme\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart O4 - HKCU\..\RunOnce: [Shockwave Updater] G:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; SIMBAR={6D66A990-DA01-11DD-8E2B-00038A000015}; GTB6; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://de.games.emule.com/spongebob-flip-or-flop/" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: hpoddt01.exe.lnk = ? O4 - Global Startup: WiFi Station.lnk = G:\Programme\Hercules\WiFiStation\WiFiN.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://G:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://G:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Programme\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Programme\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - G:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - G:\Programme\ICQ6.5\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - G:\Programme\ICQ6.5\ICQ.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Programme\Messenger\msmsgs.exe O12 - Plugin for .spop: G:\Programme\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1109841254421 O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - G:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: G:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - G:\Programme\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - G:\Programme\Avira\AntiVir Desktop\avguard.exe O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe O23 - Service: Apple Mobile Device - Apple Inc. - G:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - G:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - G:\WINDOWS\system32\ati2sgag.exe O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - G:\WINDOWS\system32\bgsvcgen.exe O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - G:\Programme\Bonjour\mDNSResponder.exe O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - G:\Programme\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Software Updater (gusvc) - Google - G:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: ICQ Service - Unknown owner - G:\Programme\ICQ6Toolbar\ICQ Service.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - G:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - G:\Programme\Ahead\InCD\InCDsrv.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - G:\Programme\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - G:\WINDOWS\system32\HPZipm12.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - G:\WINDOWS\wanmpsvc.exe O24 - Desktop Component 0: (no name) - file:///G:/DOKUME~1/******/LOKALE~1/Temp/msohtml1/01/clip_image002.jpg O24 - Desktop Component 1: (no name) - file:///G:/DOKUME~1/******/LOKALE~1/Temp/msohtml1/01/clip_image001.jpg -- End of file - 10099 bytes ======Scheduled tasks folder====== G:\WINDOWS\tasks\AppleSoftwareUpdate.job G:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1110399772.job G:\WINDOWS\tasks\User_Feed_Synchronization-{11AC6B45-AAD3-422F-8F9C-A720B6FDBF0C}.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}] XTTBPos00 Class - G:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Adobe PDF Reader Link Helper - G:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] SSVHelper Class - G:\Programme\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - G:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-09 256112] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] Google Toolbar Notifier BHO - G:\Programme\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2009-09-09 761840] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}] Google Dictionary Compression sdch - G:\Programme\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-09-09 458736] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}] SweetIM Toolbar Helper - G:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2008-10-08 1172792] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - G:\Programme\ICQ6Toolbar\ICQToolBar.dll [2009-06-01 962808] {EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - G:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2008-10-08 1172792] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - G:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-09 256112] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "SoundMan"=G:\WINDOWS\SOUNDMAN.EXE [2004-11-15 77824] "InCD"=G:\Programme\Ahead\InCD\InCD.exe [2004-09-07 1400944] "AOLDialer"=G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe [2007-06-21 70952] "Sony Ericsson PC Suite"=G:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [2006-11-24 487424] "StartCCC"=G:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440] "QuickTime Task"=G:\Programme\QuickTime\qttask.exe [2008-05-27 413696] "RealTray"=G:\Programme\Real\RealPlayer\RealPlay.exe [2005-03-09 26112] "SweetIM"=G:\Programme\SweetIM\Messenger\SweetIM.exe [2008-12-02 111928] "Google Desktop Search"=G:\Programme\Google\Google Desktop Search\GoogleDesktop.exe [2009-05-31 1838592] "avgnt"=G:\Programme\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"=G:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360] "OM_Monitor"=G:\Programme\OLYMPUS\OLYMPUS Master\Monitor.exe [2006-05-16 57344] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Shockwave Updater"=G:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE [2008-11-24 460216] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] G:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier] G:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-07-22 116040] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager] G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\AOLSoftware.exe [2006-11-17 50736] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] G:\Programme\iTunes\iTunesHelper.exe [2008-07-30 289064] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] G:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor] G:\Programme\OLYMPUS\OLYMPUS Master\FirstStart.exe [2006-05-16 40960] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Profiler] G:\Programme\Saitek\Software\Profiler.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] G:\Programme\QuickTime\QTTask.exe [2008-05-27 413696] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] G:\Programme\Real\RealPlayer\RealPlay.exe [2005-03-09 26112] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] G:\Programme\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [2003-12-08 32768] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiMfd] G:\Programme\Saitek\Software\SaiMfd.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] G:\Programme\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TerraTec Remote Control] G:\Programme\TerraTec\Cinergy 400 TV\TTTVRC.exe [2002-05-21 204800] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] G:\Programme\Winamp\winampa.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\G:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^AOL 9.0 Tray-Symbol.lnk] G:\PROGRA~1\AOL9~1.0\aoltray.exe [2004-05-10 156784] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\G:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^hp psc 1000 series.lnk] G:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpohmr08.exe [2003-04-06 147456] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\G:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^VIA RAID TOOL.lnk] G:\PROGRA~1\VIA\RAID\RAID_T~1.EXE [2004-07-14 585728] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\G:^Dokumente und Einstellungen^******^Startmenü^Programme^Autostart^hamachi.lnk] G:\PROGRA~1\Hamachi\hamachi.exe [2008-01-07 624416] G:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart hpoddt01.exe.lnk - G:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe WiFi Station.lnk - G:\Programme\Hercules\WiFiStation\WiFiN.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLS"="G:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent] G:\WINDOWS\system32\Ati2evxx.dll [2008-02-26 126976] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] G:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - G:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveAutoRun"=FFFFFFFF [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "HonorAutoRunSetting"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe"="G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL" "G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe"="G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe:*:Enabled:AOL" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "G:\Programme\EA GAMES\Need for Speed Underground 2\speed2.exe"="G:\Programme\EA GAMES\Need for Speed Underground 2\speed2.exe:*:Enabled:speed2" "G:\Programme\Firefly Studios\CivCity Rom\CivCity Rome.exe"="G:\Programme\Firefly Studios\CivCity Rom\CivCity Rome.exe:*:Enabled:CivCity Rome" "G:\Programme\Gemeinsame Dateien\aol\1176588086\ee\aolsoftware.exe"="G:\Programme\Gemeinsame Dateien\aol\1176588086\ee\aolsoftware.exe:*:Enabled:AOL Shared Components" "G:\Programme\ICQ6\ICQ.exe"="G:\Programme\ICQ6\ICQ.exe:*:Enabled:ICQ6" "G:\Programme\Counter-Strike 1.6\hl.exe"="G:\Programme\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Internet Explorer\iexplore.exe"="G:\Programme\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer" "G:\Programme\Hamachi\hamachi.exe"="G:\Programme\Hamachi\hamachi.exe:*:Enabled:Hamachi Client" "G:\Programme\Counter-Strike 1.6\hlds.exe"="G:\Programme\Counter-Strike 1.6\hlds.exe:*:Enabled:HLDS Launcher" "G:\Programme\MotoGP\motogp.exe"="G:\Programme\MotoGP\motogp.exe:*:Enabled:motogp" "G:\Programme\AOL 9.0\waol.exe"="G:\Programme\AOL 9.0\waol.exe:*:Enabled:AOL" "G:\Programme\TrackMania Nations ESWC\TmNationsESWC.exe"="G:\Programme\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC" "G:\Programme\Steam\steamapps\mycs1375\counter-strike\hl.exe"="G:\Programme\Steam\steamapps\mycs1375\counter-strike\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Steam\Steam.exe"="G:\Programme\Steam\Steam.exe:*:Enabled:Steam" "G:\Programme\Steam\steamapps\mycs1375\day of defeat\hl.exe"="G:\Programme\Steam\steamapps\mycs1375\day of defeat\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Steam\steamapps\mycs1375\dedicated server\hlds.exe"="G:\Programme\Steam\steamapps\mycs1375\dedicated server\hlds.exe:*:Enabled:HLDS Launcher" "G:\Programme\Steam\steamapps\mycs1375\deathmatch classic\hl.exe"="G:\Programme\Steam\steamapps\mycs1375\deathmatch classic\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Steam\steamapps\mycs1375\opposing force\hl.exe"="G:\Programme\Steam\steamapps\mycs1375\opposing force\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Steam\steamapps\mycs1375\ricochet\hl.exe"="G:\Programme\Steam\steamapps\mycs1375\ricochet\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Steam\steamapps\mycs1375\half-life\hl.exe"="G:\Programme\Steam\steamapps\mycs1375\half-life\hl.exe:*:Enabled:Half-Life Launcher" "G:\WINDOWS\system32\dpvsetup.exe"="G:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test" "G:\WINDOWS\system32\rundll32.exe"="G:\WINDOWS\system32\rundll32.exe:*:Enabled:Eine DLL-Datei als Anwendung ausführen" "G:\Programme\Steam\steamapps\vinamilk\counter-strike\hl.exe"="G:\Programme\Steam\steamapps\vinamilk\counter-strike\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Zattoo\zattood.exe"="G:\Programme\Zattoo\zattood.exe:*:Enabled:zattood" "G:\Programme\Zattoo\Zattoo2.exe"="G:\Programme\Zattoo\Zattoo2.exe:*:Enabled: " "G:\Programme\Age of Empires II\age2_x1\age2_x1.exe"="G:\Programme\Age of Empires II\age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion" "G:\Programme\Metin2_Germany\metin2.bin"="G:\Programme\Metin2_Germany\metin2.bin:*:Enabled:metin2" "G:\Programme\Zattoo\Zattoo.exe"="G:\Programme\Zattoo\Zattoo.exe:*:Enabled: " "G:\Programme\Bonjour\mDNSResponder.exe"="G:\Programme\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour" "G:\Programme\iTunes\iTunes.exe"="G:\Programme\iTunes\iTunes.exe:*:Enabled:iTunes" "G:\Programme\Reallusion\CrazyTalk for Skype\CT4Skype.exe"="G:\Programme\Reallusion\CrazyTalk for Skype\CT4Skype.exe:*:Enabled:CrazyTalk" "G:\Programme\Steam\steamapps\common\trackmania nations forever\TmForever.exe"="G:\Programme\Steam\steamapps\common\trackmania nations forever\TmForever.exe:*:Enabled:TrackMania Nations Forever" "G:\Programme\Steam\steamapps\common\trackmania nations forever\TmForeverLauncher.exe"="G:\Programme\Steam\steamapps\common\trackmania nations forever\TmForeverLauncher.exe:*:Enabled:TrackMania Nations Forever" "G:\Programme\Counter-Strike 1.6 Neu\hl.exe"="G:\Programme\Counter-Strike 1.6 Neu\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Counter-Strike 1.6 Neu\hlds.exe"="G:\Programme\Counter-Strike 1.6 Neu\hlds.exe:*:Enabled:HLDS Launcher" "G:\Programme\ICQ6.5\ICQ.exe"="G:\Programme\ICQ6.5\ICQ.exe:*:Enabled:ICQ6" "G:\Programme\Mozilla Firefox\firefox.exe"="G:\Programme\Mozilla Firefox\firefox.exe:*:Enabled:Firefox" "G:\Programme\Real\RealPlayer\realplay.exe"="G:\Programme\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer" "H:\Left_4_Dead\left 4 dead\left4dead.exe"="H:\Left_4_Dead\left 4 dead\left4dead.exe:*:Disabled:left4dead" "G:\Programme\Left_4_Dead\left 4 dead\left4dead.exe"="G:\Programme\Left_4_Dead\left 4 dead\left4dead.exe:*:Disabled:left4dead" "G:\Programme\Opera\opera.exe"="G:\Programme\Opera\opera.exe:*:Enabled:Opera Internet Browser" "G:\Programme\Skype\Phone\Skype.exe"="G:\Programme\Skype\Phone\Skype.exe:*:Enabled:Skype" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe"="G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL" "G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe"="G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe:*:Enabled:AOL" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "G:\Programme\AOL 9.0\waol.exe"="G:\Programme\AOL 9.0\waol.exe:*:Enabled:AOL" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bae47d43-f6f1-11de-90cc-0008d390423f}] shell\AutoRun\command - H:\USBAutoRun.exe ======List of files/folders created in the last 1 months====== 2010-01-09 13:36:03 ----D---- G:\rsit 2010-01-09 13:36:03 ----D---- G:\Programme\trend micro 2010-01-08 18:35:49 ----D---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\Malwarebytes 2010-01-08 18:35:26 ----D---- G:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes 2010-01-08 18:35:22 ----D---- G:\Programme\Malwarebytes' Anti-Malware 2010-01-01 18:32:32 ----A---- G:\WINDOWS\Sublock.dll 2010-01-01 18:32:32 ----A---- G:\WINDOWS\LGMobileDL.dll 2010-01-01 18:32:32 ----A---- G:\WINDOWS\Imei_dll.dll 2010-01-01 18:32:32 ----A---- G:\WINDOWS\esn.dll 2010-01-01 18:32:32 ----A---- G:\WINDOWS\AuthDll.dll 2010-01-01 18:21:11 ----A---- G:\WINDOWS\system32\msxml4a.dll 2010-01-01 18:21:11 ----A---- G:\WINDOWS\system32\lgAxconfig.ini 2010-01-01 18:21:11 ----A---- G:\WINDOWS\system32\CommonDL.dll 2010-01-01 18:21:06 ----D---- G:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LGMOBILEAX 2010-01-01 18:09:20 ----A---- G:\WINDOWS\system32\NMSDVDXU.dll 2010-01-01 18:09:10 ----HD---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\{D94BA408-F110-488B-A65E-3AE7945F79E6} 2010-01-01 17:44:14 ----D---- G:\Sounds 2010-01-01 17:22:21 ----D---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\LG Electronics 2010-01-01 17:21:36 ----D---- G:\Programme\LG Electronics 2009-12-19 14:57:04 ----D---- G:\Programme\Maxima-5.20.1 2009-12-16 22:12:37 ----D---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\Opera 2009-12-16 22:12:23 ----D---- G:\Programme\Opera 2009-12-14 10:24:56 ----A---- G:\WINDOWS\ntbtlog.txt ======List of files/folders modified in the last 1 months====== 2010-01-09 13:36:11 ----D---- G:\WINDOWS\Prefetch 2010-01-09 13:36:03 ----D---- G:\Programme 2010-01-09 13:33:27 ----A---- G:\WINDOWS\RTacDbg.txt 2010-01-09 13:33:22 ----D---- G:\WINDOWS 2010-01-09 13:23:59 ----D---- G:\WINDOWS\Temp 2010-01-09 12:58:38 ----A---- G:\WINDOWS\NeroDigital.ini 2010-01-09 11:43:31 ----D---- G:\WINDOWS\system32\CatRoot2 2010-01-09 02:08:37 ----A---- G:\WINDOWS\SchedLgU.Txt 2010-01-08 23:09:38 ----D---- G:\Programme\Mozilla Firefox 2010-01-08 21:17:13 ----D---- G:\WINDOWS\system32\drivers 2010-01-08 19:48:24 ----D---- G:\WINDOWS\system32\config 2010-01-08 13:58:48 ----HD---- G:\Programme\InstallShield Installation Information 2010-01-08 13:58:47 ----D---- G:\WINDOWS\system32 2010-01-07 17:57:10 ----D---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\Skype 2010-01-07 17:42:39 ----D---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\skypePM 2010-01-07 00:51:27 ----SHD---- G:\System Volume Information 2010-01-07 00:51:27 ----D---- G:\WINDOWS\system32\Restore 2010-01-06 18:19:26 ----D---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\ICQ 2010-01-04 23:33:26 ----D---- G:\Programme\Steam 2010-01-01 22:32:26 ----D---- G:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TrackMania 2010-01-01 18:14:43 ----D---- G:\WINDOWS\system32\CatRoot 2010-01-01 18:12:51 ----HD---- G:\WINDOWS\inf 2010-01-01 18:12:45 ----SHD---- G:\WINDOWS\Installer 2010-01-01 18:11:18 ----A---- G:\WINDOWS\system32\PerfStringBackup.INI 2010-01-01 17:45:54 ----SD---- G:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft 2009-12-29 21:46:29 ----D---- G:\Programme\ICQ6.5 2009-12-15 00:11:12 ----RSHDC---- G:\WINDOWS\system32\dllcache 2009-12-15 00:11:10 ----HDC---- G:\WINDOWS\$NtUninstallKB970430$ 2009-12-15 00:11:05 ----A---- G:\WINDOWS\imsins.BAK 2009-12-15 00:11:01 ----HDC---- G:\WINDOWS\$NtUninstallKB974318$ 2009-12-15 00:10:47 ----D---- G:\Programme\Internet Explorer 2009-12-15 00:10:14 ----HDC---- G:\WINDOWS\$NtUninstallKB973904$ 2009-12-15 00:10:06 ----HDC---- G:\WINDOWS\$NtUninstallKB974392$ 2009-12-15 00:09:55 ----HDC---- G:\WINDOWS\$NtUninstallKB971737$ 2009-12-14 18:31:29 ----D---- G:\WINDOWS\system32\wbem 2009-12-14 18:31:28 ----D---- G:\WINDOWS\Registration 2009-12-14 10:26:22 ----D---- G:\Dokumente und Einstellungen ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 AFS2K;AFS2k; G:\WINDOWS\system32\drivers\AFS2K.sys [2005-03-09 82380] R1 AmdK8;AMD Athlon64 Processor Driver; G:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-05-08 35840] R1 avgio;avgio; \??\G:\Programme\Avira\AntiVir Desktop\avgio.sys [] R1 avipbb;avipbb; G:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104] R1 BUFADPT;BUFADPT; \??\G:\WINDOWS\system32\BUFADPT.SYS [] R1 cdrbsdrv;cdrbsdrv; G:\WINDOWS\system32\drivers\cdrbsdrv.sys [2005-05-10 32256] R1 InCDPass;InCDPass; G:\WINDOWS\System32\DRIVERS\InCDPass.sys [2004-09-07 28544] R1 ssmdrv;ssmdrv; G:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520] R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; G:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-11-28 21035] R2 ASCTRM;ASCTRM; G:\WINDOWS\system32\drivers\ASCTRM.sys [2005-03-09 8552] R2 atksgt;atksgt; G:\WINDOWS\system32\DRIVERS\atksgt.sys [2007-07-03 165376] R2 avgntflt;avgntflt; G:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-12-07 56816] R2 lirsgt;lirsgt; G:\WINDOWS\system32\DRIVERS\lirsgt.sys [2007-07-03 18048] R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); G:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-11-17 2297664] R3 Arp1394;1394-ARP-Clientprotokoll; G:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800] R3 ati2mtag;ati2mtag; G:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-02-26 2863616] R3 Cap7134;Cinergy 400 TV Capture; G:\WINDOWS\system32\DRIVERS\Cap7134.sys [2002-02-12 419584] R3 GEARAspiWDM;GEAR CDRom Filter; G:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2008-01-29 16168] R3 hamachi;Hamachi Network Interface; G:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-01-07 25280] R3 HidUsb;Microsoft HID Class-Treiber; G:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600] R3 HPZid412;IEEE-1284.4 Driver HPZid412; G:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-03-09 51024] R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; G:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-03-09 16080] R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; G:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-03-09 21456] R3 LgBttPort;LGE Bluetooth TransPort; G:\WINDOWS\system32\DRIVERS\lgbtport.sys [2009-09-29 12160] R3 lgbusenum;LG Bluetooth Bus Enumerator; G:\WINDOWS\system32\DRIVERS\lgbtbus.sys [2009-09-29 10496] R3 LGVMODEM;LGE Virtual Modem; G:\WINDOWS\system32\DRIVERS\lgvmodem.sys [2009-09-29 12928] R3 MODEMCSA;Unimodem-Datenstromfiltergerät; G:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128] R3 mouhid;Maus-HID-Treiber; G:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-18 12288] R3 NIC1394;1394-Netzwerktreiber; G:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824] R3 pfc;Padus ASPI Shell; G:\WINDOWS\system32\drivers\pfc.sys [2003-12-05 10368] R3 ROOTMODEM;Microsoft Legacy Modem Driver; G:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888] R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver; G:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2004-10-15 71168] R3 RTL8192su;%RTL8192su.DeviceDesc.DispName%; G:\WINDOWS\system32\DRIVERS\RTL8192su.sys [2009-04-23 572800] R3 TTTvTune;Cinergy 400 TV Tuner; G:\WINDOWS\system32\DRIVERS\PhTvTune.sys [2002-02-12 16128] R3 usbccgp;Microsoft Standard-USB-Haupttreiber; G:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616] R3 usbehci;Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller; G:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624] R3 usbhub;USB2-aktivierter Hub; G:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600] R3 usbprint;Microsoft USB-Druckerklasse; G:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856] R3 usbscan;USB-Scannertreiber; G:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104] R3 usbstor;USB-Massenspeichertreiber; G:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496] R3 usbuhci;Miniporttreiber für universellen Microsoft USB-Hostcontroller; G:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480] R3 wanatw;WAN Miniport (ATW); G:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588] R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; G:\WINDOWS\system32\drivers\WmBEnum.sys [2004-04-14 10144] R3 WmXlCore;Logitech WingMan Translation Layer Driver; G:\WINDOWS\system32\drivers\WmXlCore.sys [2004-04-14 44064] R4 InCDfs;InCD File System; G:\WINDOWS\system32\drivers\InCDfs.sys [2004-09-07 91136] S1 hidfltr;HID Filter Driver; G:\WINDOWS\system32\drivers\MWhid.sys [2004-07-22 13300] S1 kbdhid;Tastatur-HID-Treiber; G:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848] S3 CCDECODE;Untertiteldecoder; G:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024] S3 ENTECH;ENTECH; \??\G:\WINDOWS\system32\DRIVERS\ENTECH.SYS [] S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS [] S3 lac97inf;lac97inf; \??\G:\DOKUME~1\********\LOKALE~1\Temp\lac97inf.sys [] S3 MSICPL;MSICPL; \??\F:\install4\MSICPL.sys [] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; G:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504] S3 NABTSFEC;NABTS/FEC VBI-Codec; G:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376] S3 NdisIP;Microsoft TV-/Videoverbindung; G:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880] S3 NTACCESS;NTACCESS; \??\F:\NTACCESS.sys [] S3 SaiH5F0D;SaiH5F0D; G:\WINDOWS\system32\DRIVERS\SaiH5F0D.sys [2005-11-14 176640] S3 SaiMini;SaiMini; G:\WINDOWS\system32\DRIVERS\SaiMini.sys [2005-07-22 13312] S3 SaiNtBus;SaiNtBus; G:\WINDOWS\system32\drivers\SaiBus.sys [2005-07-22 33792] S3 SaiU5F0D;SaiU5F0D; G:\WINDOWS\system32\DRIVERS\SaiU5F0D.sys [2005-11-14 27264] S3 se45bus;Sony Ericsson Device 069 driver (WDM); G:\WINDOWS\system32\DRIVERS\se45bus.sys [2006-11-30 61536] S3 se45mdfl;Sony Ericsson Device 069 USB WMC Modem Filter; G:\WINDOWS\system32\DRIVERS\se45mdfl.sys [2006-11-30 9360] S3 se45mdm;Sony Ericsson Device 069 USB WMC Modem Driver; G:\WINDOWS\system32\DRIVERS\se45mdm.sys [2006-11-30 97088] S3 se45mgmt;Sony Ericsson Device 069 USB WMC Device Management Drivers (WDM); G:\WINDOWS\system32\DRIVERS\se45mgmt.sys [2006-11-30 88624] S3 se45nd5;Sony Ericsson Device 069 USB Ethernet Emulation SEMC45 (NDIS); G:\WINDOWS\system32\DRIVERS\se45nd5.sys [2006-11-30 18704] S3 se45obex;Sony Ericsson Device 069 USB WMC OBEX Interface; G:\WINDOWS\system32\DRIVERS\se45obex.sys [2006-11-30 86432] S3 se45unic;Sony Ericsson Device 069 USB Ethernet Emulation SEMC45 (WDM); G:\WINDOWS\system32\DRIVERS\se45unic.sys [2006-11-30 90800] S3 SetupNTGLM7X;SetupNTGLM7X; \??\F:\NTGLM7X.sys [] S3 SLIP;BDA Slip De-Framer; G:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136] S3 streamip;BDA-IPSink; G:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360] S3 usbbus;LGE Mobile Composite USB Device; G:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2009-08-21 13056] S3 UsbDiag;LGE Mobile USB Serial Port; G:\WINDOWS\system32\DRIVERS\lgusbdiag.sys [2009-08-21 20864] S3 USBModem;LGE Mobile USB Modem; G:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2009-08-21 24960] S3 WLIU2KG125S;BUFFALO WLI-U2-KG125S Wireless LAN Adapter Driver; G:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 12672] S3 WmFilter;Logitech WingMan HID Filter Driver; G:\WINDOWS\system32\drivers\WmFilter.sys [2004-04-14 21280] S3 WmVirHid;Logitech Virtual Hid Device Driver; G:\WINDOWS\system32\drivers\WmVirHid.sys [2004-04-14 5600] S3 WpdUsb;WpdUsb; G:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528] S3 WSTCODEC;World Standard Teletext-Codec; G:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; G:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944] S4 IntelIde;IntelIde; G:\WINDOWS\system32\drivers\IntelIde.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AntiVirSchedulerService;Avira AntiVir Planer; G:\Programme\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289] R2 AntiVirService;Avira AntiVir Guard; G:\Programme\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089] R2 AOL ACS;AOL Connectivity Service; G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe [2006-10-23 46640] R2 Apple Mobile Device;Apple Mobile Device; G:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-07-22 116040] R2 Ati HotKey Poller;Ati HotKey Poller; G:\WINDOWS\system32\Ati2evxx.exe [2008-02-26 520192] R2 bgsvcgen;B's Recorder GOLD Library General Service; G:\WINDOWS\system32\bgsvcgen.exe [2005-04-30 86016] R2 Bonjour Service;Bonjour-Dienst; G:\Programme\Bonjour\mDNSResponder.exe [2007-07-24 229376] R2 ICQ Service;ICQ Service; G:\Programme\ICQ6Toolbar\ICQ Service.exe [2009-06-01 222968] R2 InCDsrv;InCD Helper; G:\Programme\Ahead\InCD\InCDsrv.exe [2004-09-07 1151090] R2 WANMiniportService;WAN Miniport (ATW) Service; G:\WINDOWS\wanmpsvc.exe [2003-08-27 65536] R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; G:\WINDOWS\system32\svchost.exe [2004-08-04 14336] S2 ATI Smart;ATI Smart; G:\WINDOWS\system32\ati2sgag.exe [2008-02-25 593920] S3 aspnet_state;ASP.NET State Service; G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; g:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104] S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589; G:\Programme\Google\Google Desktop Search\GoogleDesktop.exe [2009-05-31 1838592] S3 gusvc;Google Software Updater; G:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-09 182768] S3 IDriverT;InstallDriver Table Manager; G:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632] S3 idsvc;Windows CardSpace; g:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664] S3 iPod Service;iPod-Dienst; G:\Programme\iPod\bin\iPodService.exe [2008-07-30 532264] S3 ose;Office Source Engine; G:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136] S3 Pml Driver HPZ12;Pml Driver HPZ12; G:\WINDOWS\system32\HPZipm12.exe [2003-03-09 65795] S3 WMPNetworkSvc;Windows Media Player-Netzwerkfreigabedienst; G:\Programme\Windows Media Player\WMPNetwk.exe [2006-10-24 920576] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; g:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096] -----------------EOF----------------- |
09.01.2010, 13:55 | #11 |
| Av AntiRootkit scan - gefährlicher Fund? Das wichtigste ist Passworte von einem sauberen Rechner aus zu aendern und den infizierten Rechner nicht mehr ins Internet lassen...
__________________ MfG Ralf |
09.01.2010, 20:18 | #12 |
| Av AntiRootkit scan - gefährlicher Fund? Kurz eine Frage.. Hab jetzt die Daten auf einer Externen Platte und die mal gescannt und das ist der Report: Code:
ATTFilter Malwarebytes' Anti-Malware 1.44 Datenbank Version: 3519 Windows 5.1.2600 Service Pack 2 Internet Explorer 8.0.6001.18702 08.01.2010 23:58:54 mbam-log-2010-01-08 (23-58-49).txt Scan-Methode: Vollständiger Scan (H:\|) Durchsuchte Objekte: 150920 Laufzeit: 32 minute(s), 32 second(s) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 3 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 1 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> No action taken. Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: G:\Programme\ICQToolbar\toolbaru.dll (Trojan.BHO) -> No action taken. Ich hab auch noch mal GMER laufen lassen, aber den selben Report bekommen. Ich setze jetzt erstmal das System neu auf. Muss ich noch was bei kopieren meiner Daten zurück auf den Rechner beachten? Scanns? oder evtl mit ubuntu live cd? |
10.01.2010, 21:23 | #13 |
| Av AntiRootkit scan - gefährlicher Fund? Ein zusaetzlicher Scan der externen, bzw andewren Partitionen ist nicht verkehrt. Wichtig ist auch, keine ausfuehrbaren Programme der externen Datentraeger und Festplatten zu nutzen, diese sollte man aus vertrauenswuerdiger Quelle neu beschaffen!
__________________ MfG Ralf |
18.01.2010, 23:59 | #14 |
| Av AntiRootkit scan - gefährlicher Fund? Hallo, habe mein System neu aufgesetz Daten gesichert, Scans ausgeführt etc. . Die Externe war mit großer wahrscheinlichkeit nicht befallen. Habe nur zur neugierde mit avira antirootkit tool erneut gescannt und es kamen so ziemlich die gleichen Ergebnisse. Vermutlich werden diese immer angezeigt. Malwarebytes und das normal Antivir finden bei Scanns hingegen nichts. Vielen Dank für deine Hilfe raman! |
Themen zu Av AntiRootkit scan - gefährlicher Fund? |
.dll, 1.exe, antirootkittool, antivir, avgnt.exe, avira, ccc.exe, csrss.exe, dll, explorer.exe, icq, iexplore.exe, langsam, logon.exe, lsass.exe, microsoft, mom.exe, namen, neu, notepad.exe, realplay.exe, rootkit, scan, sched.exe, schnelle hilfe, secur, sehr langsam, services.exe, shell32.dll, software, svchost.exe, system volume information, trojan, virus, windows, winlogon, winlogon.exe |