![]() |
|
Log-Analyse und Auswertung: PC erstarrt(strg+alt+ent funkzt net),maus und eingabe net möglich!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #4 |
![]() | ![]() PC erstarrt(strg+alt+ent funkzt net),maus und eingabe net möglich! musste wieda teilen, hier der erste teil: die malwarebytes-log : Malwarebytes' Anti-Malware 1.45 w*w.malwarebytes.org Datenbank Version: 3988 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 21.04.2010 03:46:11 mbam-log-2010-04-21 (03-46-11).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 109079 Laufzeit: 5 Minute(n), 9 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) ------------------------------------- die OTL-logs: OTL.Txt OTL logfile created on: 21.04.2010 03:46:38 - Run 1 OTL by OldTimer - Version 3.2.1.3 Folder = C:\Users\***\Desktop 64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000407 | Country: Germany| Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 62,00% Memory free 8,00 Gb Paging File | 7,00 Gb Available in Paging File | 80,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465,76 Gb Total Space | 0,82 Gb Free Space | 0,18% Space Free | Partition Type: NTFS Drive D: | 2,59 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ***-PC Current User Name: *** Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Windows\SysWow64\spool\DRIVERS\x64\3\CNAP2RPK.EXE File not found PRC - C:\Windows\SysWow64\spool\drivers\x64\3\CNAP2LAK.EXE File not found PRC - C:\Windows\SysWow64\spool\DRIVERS\x64\3\CNAB8SWK.EXE File not found PRC - C:\Users\***\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) PRC - C:\Programme\GDATA\AVKTray\AVKTray.exe (G DATA Software AG) PRC - C:\Programme\GDATA\AVK\AVKService.exe (G DATA Software AG) PRC - C:\Program Files (x86)\Common Files\G DATA\AVKProxy\AVKProxy.exe (G DATA Software AG) PRC - C:\Program Files (x86)\Analog Devices\SoundMAX\SoundMAX.exe (Analog Devices, Inc.) PRC - C:\Program Files (x86)\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe (Sony Ericsson Mobile Communications AB) PRC - C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.) PRC - C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe (Teleca AB) PRC - C:\Programme\GDATA\AVK\AvkLnk32.exe (G DATA Software AG) PRC - C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation) ========== Modules (SafeList) ========== MOD - C:\Users\***\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (AEADIFilters) -- C:\Windows\SysNative\AEADISRV.EXE () SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (avg9emc) -- C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.) SRV - (avg9wd) -- C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) SRV - (AVG Security Toolbar Service) -- C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe () SRV - (fsssvc) -- C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation) SRV - (SeaPort) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) SRV - (AVKService) -- C:\Programme\GDATA\AVK\AVKService.exe (G DATA Software AG) SRV - (AVKProxy) -- C:\Program Files (x86)\Common Files\G DATA\AVKProxy\AVKProxy.exe (G DATA Software AG) SRV - (AVKWCtl) -- C:\Programme\GDATA\AVK\AVKWCtlX64.exe (G DATA Software AG) SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (AvkLink32) -- C:\Programme\GDATA\AVK\AvkLnk32.exe (G DATA Software AG) SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2006.11.02 15:34:14 | 000,000,000 | ---D | M] SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof () SRV - (VSS) -- C:\Windows\SysWOW64\wbem\vss.mof () SRV - (MDM) -- C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (AvgTdiA) -- C:\Windows\SysNative\Drivers\avgtdia.sys () DRV:64bit: - (AvgLdx64) -- C:\Windows\SysNative\Drivers\avgldx64.sys () DRV:64bit: - (AvgMfx64) -- C:\Windows\SysNative\Drivers\avgmfx64.sys () DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\DRIVERS\fssfltr.sys () DRV:64bit: - (hamachi) -- C:\Windows\SysNative\DRIVERS\hamachi.sys () DRV:64bit: - (GearAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys () DRV:64bit: - (AF9035BDA) -- C:\Windows\SysNative\DRIVERS\AF9035BDA.sys () DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys () DRV:64bit: - (GRD) -- C:\Windows\SysNative\drivers\GRD.sys () DRV:64bit: - (GDMnIcpt) -- C:\Windows\SysNative\drivers\MiniIcpt.sys () DRV:64bit: - (HookCentre) -- C:\Windows\SysNative\drivers\HookCentre.sys () DRV:64bit: - (gdwfpcd) -- C:\Windows\SysNative\drivers\gdwfpcd64.sys () DRV:64bit: - (ncplelhp) -- C:\Windows\SysNative\DRIVERS\ncplelhp.sys () DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys () DRV:64bit: - (CmBatt) -- C:\Windows\SysNative\DRIVERS\CmBatt.sys () DRV:64bit: - (ADIHdAudAddService) -- C:\Windows\SysNative\drivers\ADIHdAud.sys () DRV:64bit: - (s816mdm) -- C:\Windows\SysNative\DRIVERS\s816mdm.sys () DRV:64bit: - (s816unic) Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM) -- C:\Windows\SysNative\DRIVERS\s816unic.sys () DRV:64bit: - (s816mgmt) Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM) -- C:\Windows\SysNative\DRIVERS\s816mgmt.sys () DRV:64bit: - (s816obex) -- C:\Windows\SysNative\DRIVERS\s816obex.sys () DRV:64bit: - (s816nd5) Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS) -- C:\Windows\SysNative\DRIVERS\s816nd5.sys () DRV:64bit: - (s816mdfl) -- C:\Windows\SysNative\DRIVERS\s816mdfl.sys () DRV:64bit: - (s816bus) Sony Ericsson Device 816 driver (WDM) -- C:\Windows\SysNative\DRIVERS\s816bus.sys () DRV:64bit: - (s115mgmt) Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM) -- C:\Windows\SysNative\DRIVERS\s115mgmt.sys () DRV:64bit: - (s115obex) -- C:\Windows\SysNative\DRIVERS\s115obex.sys () DRV:64bit: - (s115mdm) -- C:\Windows\SysNative\DRIVERS\s115mdm.sys () DRV:64bit: - (s115mdfl) -- C:\Windows\SysNative\DRIVERS\s115mdfl.sys () DRV:64bit: - (s115bus) Sony Ericsson Device 115 driver (WDM) -- C:\Windows\SysNative\DRIVERS\s115bus.sys () DRV:64bit: - (s616unic) Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (WDM) -- C:\Windows\SysNative\DRIVERS\s616unic.sys () DRV:64bit: - (s616obex) -- C:\Windows\SysNative\DRIVERS\s616obex.sys () DRV:64bit: - (s616nd5) Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (NDIS) -- C:\Windows\SysNative\DRIVERS\s616nd5.sys () DRV:64bit: - (s616mgmt) Sony Ericsson Device 616 USB WMC Device Management Drivers (WDM) -- C:\Windows\SysNative\DRIVERS\s616mgmt.sys () DRV:64bit: - (s616mdm) -- C:\Windows\SysNative\DRIVERS\s616mdm.sys () DRV:64bit: - (s616mdfl) -- C:\Windows\SysNative\DRIVERS\s616mdfl.sys () DRV:64bit: - (s616bus) Sony Ericsson Device 616 driver (WDM) -- C:\Windows\SysNative\DRIVERS\s616bus.sys () DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys () DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\DRIVERS\ASACPI.sys () DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\DRIVERS\nvm60x64.sys () DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof () DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof () DRV - (pfc) -- C:\Windows\SysWOW64\drivers\pfc.sys (Padus, Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://w*w.alternate.net [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://w*w.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://w*w.daemon-search.com/default IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll () IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:2.02 FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812 FF - prefs.js..extensions.enabledItems: avg@igeared:4.002.023.004 FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG9\Firefox [2010.04.20 21:55:40 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files (x86)\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010.04.15 02:30:06 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.04.03 08:06:14 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.04.03 08:06:14 | 000,000,000 | ---D | M] [2008.11.04 14:22:06 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Extensions [2010.04.20 03:23:26 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\fgwrrtnv.default\extensions [2009.10.08 23:31:06 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\fgwrrtnv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2009.04.23 13:41:31 | 000,000,000 | ---D | M] (Fast Video Download) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\fgwrrtnv.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8} [2010.04.03 08:10:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2010.03.12 12:25:11 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.03.12 12:25:11 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.03.12 12:25:11 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.03.12 12:25:11 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.03.12 12:25:11 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2006.09.18 23:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2:64bit: - BHO: (G DATA WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Programme\GDATA\Webfilter\AVKWebIEx64.dll () O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.) O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Programme\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.4.4525.1752\swg64.dll (Google Inc.) O2 - BHO: (G DATA WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Programme\GDATA\Webfilter\AVKWebIE.dll () O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Megaupload Toolbar) - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~2\MEGAUP~2\MEGAUP~1.DLL (MEGAUPLOAD ) O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll () O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll () O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.) O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.) O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~2\FlashFXP\IEFlash.dll (IniCom Networks, Inc.) O3:64bit: - HKLM\..\Toolbar: (G DATA WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Programme\GDATA\Webfilter\AVKWebIEx64.dll () O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3 - HKLM\..\Toolbar: (G DATA WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Programme\GDATA\Webfilter\AVKWebIE.dll () O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll () O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM\..\Toolbar: (Megaupload Toolbar) - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~2\MEGAUP~2\MEGAUP~1.DLL (MEGAUPLOAD ) O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~2\TerraTec\TERRAT~1\THCDES~1.DLL (TerraTec Electronic GmbH) O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll () O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll () O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKCU\..\Toolbar\WebBrowser: (Megaupload Toolbar) - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~2\MEGAUP~2\MEGAUP~1.DLL (MEGAUPLOAD ) O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll () O4:64bit: - HKLM..\Run: [CNAP2 Launcher] C:\Windows\SysNative\spool\DRIVERS\x64\3\CNAP2LAK.EXE () O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL () O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL () O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [G DATA AntiVirus Trayapplication] C:\Programme\GDATA\AVKTray\AVKTray.exe (G DATA Software AG) O4 - HKLM..\Run: [Sony Ericsson PC Suite] C:\Program Files (x86)\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe () O4 - HKLM..\Run: [SoundMAX] C:\Program Files (x86)\Analog Devices\SoundMAX\SoundMAX.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe () O4 - HKCU..\Run: [ICQ] C:\Program Files (x86)\ICQ6.5\ICQ.exe (ICQ, LLC.) O4 - HKCU..\Run: [Steam] c:\users\***\saved games\steam\steam.exe (Valve Corporation) O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - Startup: C:\Users\Haydar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Gangsters2Setup.lnk = E:\Applet.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Poker\CDPoker\casino.exe () O9 - Extra 'Tools' menuitem : CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Poker\CDPoker\casino.exe () O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe () O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe () O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe (ICQ, LLC.) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} ht*p://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} ht*p://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19) O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} ht*p://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} h*tp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} ht*p://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} ht*p://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} ht*p://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.) O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll () O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll () O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img36.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img36.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2003.07.09 17:27:28 | 000,000,000 | R--D | M] - D:\AutoRte -- [ UDF ] O32 - AutoRun File - [2003.08.05 19:02:47 | 000,000,000 | R--D | M] - D:\Autorun -- [ UDF ] O32 - AutoRun File - [2003.08.05 19:01:21 | 000,000,055 | R--- | M] () - D:\autorun.inf -- [ UDF ] O33 - MountPoints2\{0e384d54-ac15-11dd-b240-001fc64954bd}\Shell - "" = AutoRun O33 - MountPoints2\{0e384d54-ac15-11dd-b240-001fc64954bd}\Shell\AutoRun\command - "" = F:\autorun.exe -- File not found O33 - MountPoints2\{142bfac4-3c29-11df-908b-001fc64954bd}\Shell\AutoRun\command - "" = G:\POGRESHILI\\sudbinemi.exe -- File not found O33 - MountPoints2\{142bfac4-3c29-11df-908b-001fc64954bd}\Shell\open\command - "" = G:\POGRESHILI\\sudbinemi.exe -- File not found O33 - MountPoints2\{63cc3da5-a92b-11dd-8e78-001fc64954bd}\Shell - "" = AutoRun O33 - MountPoints2\{63cc3da5-a92b-11dd-8e78-001fc64954bd}\Shell\AutoRun\command - "" = E:\Autorun.exe -- File not found O33 - MountPoints2\{8890f4c0-a1e3-11dd-aa37-001fc64954bd}\Shell\AutoRun\command - "" = E:\EmDesk.exe -- File not found O33 - MountPoints2\{8890f4c0-a1e3-11dd-aa37-001fc64954bd}\Shell\EmDesk\command - "" = E:\EmDesk.exe -- File not found O33 - MountPoints2\{ae9456e3-a1e2-11dd-bca0-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{ae9456e3-a1e2-11dd-bca0-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Autorun\autorun.exe -- [2003.08.05 19:02:27 | 000,033,280 | R--- | M] (Microsoft® Corporation) O33 - MountPoints2\{def0d9f4-ca27-11dd-bc97-001fc64954bd}\Shell\AutoRun\command - "" = C:\Windows\SysWow64\setupSNK.exe -- [2008.01.21 04:47:35 | 000,013,312 | ---- | M] (Microsoft Corporation) O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2081.10.08 18:26:00 | 000,000,000 | ---D | C] -- C:\Programme\Google [2010.04.21 03:23:48 | 000,562,176 | ---- | C] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe [2010.04.15 15:45:30 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\avg [2010.04.15 05:21:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\trend micro [2010.04.15 05:21:06 | 000,000,000 | ---D | C] -- C:\rsit [2010.04.15 04:26:25 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes [2010.04.15 04:26:00 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010.04.15 04:25:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010.04.15 04:25:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.04.15 03:43:03 | 000,000,000 | -H-D | C] -- C:\$AVG [2010.04.15 03:29:52 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2010.04.15 03:05:34 | 000,000,000 | ---D | C] -- C:\2967bd363b0d071f346a [2010.04.15 02:34:21 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\AVG Security Toolbar [2010.04.15 02:30:15 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\Avg [2010.04.15 02:30:07 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Security Toolbar [2010.04.15 02:28:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG [2010.04.15 02:28:45 | 000,000,000 | ---D | C] -- C:\ProgramData\avg9 [2010.04.14 16:13:57 | 000,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll [2010.04.14 16:13:56 | 000,062,464 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\SysWow64\l3codeca.acm [2010.04.14 16:12:49 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cabview.dll [2010.04.14 16:12:48 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wintrust.dll [2010.04.03 08:10:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2010.04.03 08:10:27 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2010.04.03 08:10:27 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2010.04.03 08:10:27 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2010.03.31 21:08:06 | 000,833,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wininet.dll [2010.03.31 21:08:06 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll [2010.03.31 21:08:04 | 000,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll [2010.03.31 21:08:03 | 000,476,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2010.03.31 21:08:03 | 000,458,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll [2010.03.31 21:08:03 | 000,389,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll [2010.03.31 21:08:02 | 000,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstime.dll [2010.03.31 21:08:02 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec [2010.03.31 21:08:02 | 000,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll [2010.03.31 21:08:02 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll [2010.03.31 21:08:02 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieencode.dll [2010.03.31 21:08:02 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2010.03.31 21:08:01 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsproxy.dll [2010.03.31 01:05:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works Suite 2004 [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2081.10.08 18:25:34 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{AA93048B-BE70-4702-BAE5-1294877AB5EE}.job [2010.04.21 03:46:37 | 011,010,048 | -HS- | M] () -- C:\Users\***\NTUSER.DAT [2010.04.21 03:44:32 | 001,427,406 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010.04.21 03:44:32 | 000,621,714 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2010.04.21 03:44:32 | 000,589,884 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010.04.21 03:44:32 | 000,123,646 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2010.04.21 03:44:32 | 000,101,896 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010.04.21 03:36:51 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010.04.21 03:36:51 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010.04.21 03:36:48 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.04.21 03:36:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.04.21 03:23:54 | 000,562,176 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe [2010.04.21 03:06:17 | 000,017,408 | ---- | M] () -- C:\Users\***\AppData\Local\WebpageIcons.db [2010.04.20 21:54:45 | 000,524,288 | -HS- | M] () -- C:\Users\***\NTUSER.DAT{888b730a-b457-11de-9458-001fc64954bd}.TMContainer00000000000000000001.regtrans-ms [2010.04.20 21:54:45 | 000,065,536 | -HS- | M] () -- C:\Users\***\NTUSER.DAT{888b730a-b457-11de-9458-001fc64954bd}.TM.blf [2010.04.20 21:53:31 | 004,076,215 | -H-- | M] () -- C:\Users\***\AppData\Local\IconCache.db [2010.04.20 16:52:16 | 000,317,520 | ---- | M] () -- C:\Windows\SysNative\drivers\avgtdia.sys [2010.04.20 16:52:09 | 059,094,882 | ---- | M] () -- C:\Windows\SysNative\drivers\Avg\incavi.avm [2010.04.19 20:34:07 | 000,000,680 | ---- | M] () -- C:\Users\***\AppData\Local\d3d9caps.dat [2010.04.17 19:53:32 | 000,011,318 | ---- | M] () -- C:\Users\***\Documents\Die letzte Rettung-by ***.rtf [2010.04.17 19:53:32 | 000,000,482 | ---- | M] () -- C:\Users\***\AppData\Roaming\wklnhst.dat [2010.04.17 00:56:20 | 000,960,054 | ---- | M] () -- C:\Users\***\Documents\ezu3k5bt.bmp [2010.04.17 00:55:48 | 000,231,254 | ---- | M] () -- C:\Users\***\Documents\45gdgb5z.bmp [2010.04.15 23:18:13 | 000,000,720 | ---- | M] () -- C:\Users\Public\Desktop\William Hill Poker.lnk [2010.04.15 04:48:54 | 000,001,724 | ---- | M] () -- C:\Users\***\Desktop\CCleaner.lnk [2010.04.15 04:26:03 | 000,000,848 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.04.15 04:21:20 | 000,781,909 | ---- | M] () -- C:\Users\***\Desktop\RSIT.exe [2010.04.15 02:39:33 | 000,001,824 | ---- | M] () -- C:\Users\***\Desktop\Steam.lnk [2010.04.15 02:30:32 | 000,001,689 | ---- | M] () -- C:\Users\Public\Desktop\AVG Free 9.0.lnk [2010.04.15 02:30:20 | 000,012,976 | ---- | M] () -- C:\Windows\SysNative\avgrssta.dll [2010.04.15 02:30:16 | 000,269,320 | ---- | M] () -- C:\Windows\SysNative\drivers\avgldx64.sys [2010.04.15 02:30:15 | 000,113,461 | ---- | M] () -- C:\Windows\SysNative\drivers\Avg\iavichjw.avm [2010.04.15 02:30:15 | 000,035,464 | ---- | M] () -- C:\Windows\SysNative\drivers\avgmfx64.sys [2010.04.05 21:29:56 | 000,829,270 | ---- | M] () -- C:\Users\***\Desktop\100_9601.JPG [2010.04.05 21:29:46 | 000,828,538 | ---- | M] () -- C:\Users\***\Desktop\100_9599.JPG [2010.04.05 21:29:46 | 000,824,254 | ---- | M] () -- C:\Users\***\Desktop\100_9600.JPG [2010.04.01 19:40:31 | 000,102,640 | ---- | M] () -- C:\Users\***\AppData\Local\GDIPFONTCACHEV1.DAT [2010.04.01 19:40:09 | 000,382,888 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2010.03.31 21:47:00 | 000,063,540 | ---- | M] () -- C:\Users\***\Desktop\ssk1.frage.rtf [2010.03.31 04:39:22 | 000,052,224 | ---- | M] () -- C:\Users\***\Desktop\Deckblatt.doc [2010.03.31 01:14:12 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI [2010.03.31 01:13:27 | 000,001,910 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2010.03.30 02:44:02 | 001,432,791 | ---- | M] () -- C:\Users\***\Documents\Unbenannt (5).wma [2010.03.30 02:35:40 | 004,176,181 | ---- | M] () -- C:\Users\***\Documents\Unbenannt (4).wma [2010.03.29 15:24:58 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010.03.29 15:24:46 | 000,024,664 | ---- | M] () -- C:\Windows\SysNative\drivers\mbam.sys [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.04.17 00:55:43 | 000,960,054 | ---- | C] () -- C:\Users\***\Documents\ezu3k5bt.bmp [2010.04.17 00:55:37 | 000,231,254 | ---- | C] () -- C:\Users\***\Documents\45gdgb5z.bmp [2010.04.15 23:18:13 | 000,000,720 | ---- | C] () -- C:\Users\Public\Desktop\William Hill Poker.lnk [2010.04.15 04:26:03 | 000,000,848 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.04.15 04:25:57 | 000,024,664 | ---- | C] () -- C:\Windows\SysNative\drivers\mbam.sys [2010.04.15 04:21:06 | 000,781,909 | ---- | C] () -- C:\Users\***\Desktop\RSIT.exe [2010.04.15 02:53:15 | 000,303,061 | ---- | C] () -- C:\Users\***\Desktop\DSC00380.JPG [2010.04.15 02:39:33 | 000,001,824 | ---- | C] () -- C:\Users\***\Desktop\Steam.lnk [2010.04.15 02:30:32 | 000,001,689 | ---- | C] () -- C:\Users\Public\Desktop\AVG Free 9.0.lnk [2010.04.15 02:30:20 | 000,012,976 | ---- | C] () -- C:\Windows\SysNative\avgrssta.dll [2010.04.15 02:30:19 | 000,317,520 | ---- | C] () -- C:\Windows\SysNative\drivers\avgtdia.sys [2010.04.15 02:30:16 | 000,269,320 | ---- | C] () -- C:\Windows\SysNative\drivers\avgldx64.sys [2010.04.15 02:30:15 | 059,094,882 | ---- | C] () -- C:\Windows\SysNative\drivers\Avg\incavi.avm [2010.04.15 02:30:15 | 000,113,461 | ---- | C] () -- C:\Windows\SysNative\drivers\Avg\iavichjw.avm [2010.04.15 02:30:15 | 000,035,464 | ---- | C] () -- C:\Windows\SysNative\drivers\avgmfx64.sys [2010.04.14 16:14:14 | 001,420,688 | ---- | C] () -- C:\Windows\SysNative\drivers\tcpip.sys [2010.04.14 16:14:13 | 000,224,256 | ---- | C] () -- C:\Windows\SysNative\iphlpsvc.dll [2010.04.14 16:14:13 | 000,029,696 | ---- | C] () -- C:\Windows\SysNative\drivers\tunnel.sys [2010.04.14 16:14:11 | 000,273,920 | ---- | C] () -- C:\Windows\SysNative\drivers\mrxsmb10.sys [2010.04.14 16:14:11 | 000,135,168 | ---- | C] () -- C:\Windows\SysNative\drivers\mrxsmb.sys [2010.04.14 16:14:11 | 000,105,472 | ---- | C] () -- C:\Windows\SysNative\drivers\mrxsmb20.sys [2010.04.14 16:14:09 | 004,690,832 | ---- | C] () -- C:\Windows\SysNative\ntoskrnl.exe [2010.04.14 16:13:57 | 000,603,648 | ---- | C] () -- C:\Windows\SysNative\vbscript.dll [2010.04.14 16:13:56 | 000,072,192 | ---- | C] () -- C:\Windows\SysNative\l3codeca.acm [2010.04.14 16:12:49 | 000,104,960 | ---- | C] () -- C:\Windows\SysNative\cabview.dll [2010.04.14 16:12:48 | 000,218,112 | ---- | C] () -- C:\Windows\SysNative\wintrust.dll [2010.04.05 21:28:49 | 000,829,270 | ---- | C] () -- C:\Users\***\Desktop\100_9601.JPG [2010.04.05 21:28:49 | 000,828,538 | ---- | C] () -- C:\Users\***\Desktop\100_9599.JPG [2010.04.05 21:28:49 | 000,824,254 | ---- | C] () -- C:\Users\***\Desktop\100_9600.JPG [2010.03.31 21:56:49 | 000,063,540 | ---- | C] () -- C:\Users\***\Desktop\ssk1.frage.rtf [2010.03.31 21:08:12 | 005,689,344 | ---- | C] () -- C:\Windows\SysNative\mshtml.dll [2010.03.31 21:08:10 | 007,005,696 | ---- | C] () -- C:\Windows\SysNative\ieframe.dll [2010.03.31 21:08:08 | 001,426,944 | ---- | C] () -- C:\Windows\SysNative\urlmon.dll [2010.03.31 21:08:08 | 001,032,704 | ---- | C] () -- C:\Windows\SysNative\wininet.dll [2010.03.31 21:08:06 | 000,208,896 | ---- | C] () -- C:\Windows\SysNative\occache.dll [2010.03.31 21:08:04 | 000,758,784 | ---- | C] () -- C:\Windows\SysNative\mshtmled.dll [2010.03.31 21:08:04 | 000,580,608 | ---- | C] () -- C:\Windows\SysNative\msfeeds.dll [2010.03.31 21:08:04 | 000,422,400 | ---- | C] () -- C:\Windows\SysNative\ieapfltr.dll [2010.03.31 21:08:03 | 000,480,256 | ---- | C] () -- C:\Windows\SysNative\iedkcs32.dll [2010.03.31 21:08:03 | 000,375,296 | ---- | C] () -- C:\Windows\SysNative\iertutil.dll [2010.03.31 21:08:03 | 000,249,856 | ---- | C] () -- C:\Windows\SysNative\iepeers.dll [2010.03.31 21:08:02 | 001,129,984 | ---- | C] () -- C:\Windows\SysNative\mstime.dll [2010.03.31 21:08:02 | 000,485,376 | ---- | C] () -- C:\Windows\SysNative\html.iec [2010.03.31 21:08:02 | 000,267,776 | ---- | C] () -- C:\Windows\SysNative\ieaksie.dll [2010.03.31 21:08:02 | 000,086,528 | ---- | C] () -- C:\Windows\SysNative\ieencode.dll [2010.03.31 21:08:02 | 000,032,768 | ---- | C] () -- C:\Windows\SysNative\ieUnatt.exe [2010.03.31 21:08:01 | 001,383,424 | ---- | C] () -- C:\Windows\SysNative\mshtml.tlb [2010.03.31 21:08:01 | 000,032,256 | ---- | C] () -- C:\Windows\SysNative\jsproxy.dll [2010.03.31 04:39:21 | 000,052,224 | ---- | C] () -- C:\Users\***\Desktop\Deckblatt.doc [2010.03.31 01:17:42 | 000,000,482 | ---- | C] () -- C:\Users\***\AppData\Roaming\wklnhst.dat [2010.03.31 01:14:12 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2010.03.31 01:13:27 | 000,001,910 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2010.03.30 02:44:02 | 001,432,791 | ---- | C] () -- C:\Users\***\Documents\Unbenannt (5).wma [2010.03.30 02:35:40 | 004,176,181 | ---- | C] () -- C:\Users\***\Documents\Unbenannt (4).wma [2010.03.16 20:00:50 | 001,448,408 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2010.03.12 21:48:13 | 000,000,680 | ---- | C] () -- C:\Users\***\AppData\Local\d3d9caps.dat [2010.03.02 22:52:03 | 000,017,408 | ---- | C] () -- C:\Users\***\AppData\Local\WebpageIcons.db [2010.02.09 02:17:27 | 000,000,799 | ---- | C] () -- C:\Users\***\Dokument3.rtf [2010.02.07 20:18:01 | 000,034,148 | ---- | C] () -- C:\Users\***\mert.JPG [2010.02.07 20:17:48 | 000,025,073 | ---- | C] () -- C:\Users\***\ilan16dk1.jpg [2010.02.07 20:17:39 | 000,026,768 | ---- | C] () -- C:\Users\***\komik-resim-7.jpg [2010.02.07 20:15:42 | 000,051,264 | ---- | C] () -- C:\Users\***\on2_530775f1d.jpg [2010.02.07 20:15:31 | 000,098,764 | ---- | C] () -- C:\Users\***\yeniceri10245pv.jpg [2010.02.07 20:11:29 | 000,179,199 | ---- | C] () -- C:\Users\***\komik3pi8.png [2010.02.07 20:10:47 | 000,029,220 | ---- | C] () -- C:\Users\***\yenirakize3.jpg [2010.02.06 18:38:43 | 000,012,920 | ---- | C] () -- C:\Users\***\Dokument.rtf [2009.12.05 15:23:44 | 008,200,006 | ---- | C] () -- C:\Users\***\Memo (2).amr [2009.12.05 12:53:16 | 008,388,006 | ---- | C] () -- C:\Users\***\Memo (1).amr [2009.12.05 11:03:22 | 006,195,238 | ---- | C] () -- C:\Users\***\Memo.amr [2009.11.10 01:46:10 | 000,031,434 | ---- | C] () -- C:\Users\***\agliyan.jpg [2009.11.10 01:45:26 | 000,043,999 | ---- | C] () -- C:\Users\***\dertli.jpg [2009.11.06 11:58:04 | 000,178,975 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat [2009.10.22 17:20:34 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll [2009.10.22 17:20:34 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll [2009.10.22 17:20:34 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll [2009.10.09 00:12:00 | 000,524,288 | -HS- | C] () -- C:\Users\***\NTUSER.DAT{888b730a-b457-11de-9458-001fc64954bd}.TMContainer00000000000000000002.regtrans-ms [2009.10.09 00:12:00 | 000,524,288 | -HS- | C] () -- C:\Users\***\NTUSER.DAT{888b730a-b457-11de-9458-001fc64954bd}.TMContainer00000000000000000001.regtrans-ms [2009.10.09 00:12:00 | 000,065,536 | -HS- | C] () -- C:\Users\***\NTUSER.DAT{888b730a-b457-11de-9458-001fc64954bd}.TM.blf [2009.08.14 22:29:54 | 000,000,277 | ---- | C] () -- C:\Users\***\AppData\Roaming\Gangsters2Setup.lnk [2009.06.30 12:20:02 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2009.03.08 06:55:15 | 000,000,515 | ---- | C] () -- C:\Windows\SIERRA.INI [2009.03.06 00:39:17 | 000,000,353 | ---- | C] () -- C:\Windows\doom3.ini [2008.11.06 18:37:32 | 003,596,288 | ---- | C] () -- C:\Windows\SysWow64\qt-dx331.dll [2008.10.26 15:34:44 | 000,000,259 | ---- | C] () -- C:\Windows\RomeTW.ini [2008.10.25 13:06:03 | 000,027,648 | ---- | C] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008.10.24 17:58:40 | 000,000,732 | ---- | C] () -- C:\Users\***\AppData\Local\d3d9caps64.dat [2008.10.24 17:58:39 | 000,524,288 | -HS- | C] () -- C:\Users\***\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000002.regtrans-ms [2008.10.24 17:58:39 | 000,524,288 | -HS- | C] () -- C:\Users\***\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms [2008.10.24 17:58:39 | 000,262,144 | -H-- | C] () -- C:\Users\***\ntuser.dat.LOG1 [2008.10.24 17:58:39 | 000,065,536 | -HS- | C] () -- C:\Users\***\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf [2008.10.24 17:58:39 | 000,000,020 | -HS- | C] () -- C:\Users\***\ntuser.ini [2008.10.24 17:58:39 | 000,000,000 | -H-- | C] () -- C:\Users\***\ntuser.dat.LOG2 [2008.10.24 17:58:38 | 011,010,048 | -HS- | C] () -- C:\Users\***\NTUSER.DAT [2008.10.24 17:35:02 | 000,000,552 | ---- | C] () -- C:\Users\***\AppData\Local\d3d8caps.dat [2008.10.21 21:09:15 | 000,021,322 | ---- | C] () -- C:\Windows\Ascd_tmp.ini [2008.06.11 09:02:34 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll [2008.06.11 09:02:34 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll [2008.06.11 09:02:34 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll [2008.06.11 09:02:34 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll [2008.06.11 09:02:34 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll [2008.06.11 09:02:34 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll [2008.06.11 09:02:32 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll [2008.06.11 09:02:32 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll [2008.06.11 09:02:32 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll [2008.06.05 08:58:26 | 000,197,912 | ---- | C] () -- C:\Windows\SysWow64\physxcudart_20.dll [2008.01.21 04:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini [2008.01.21 04:49:49 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2007.08.01 05:39:28 | 000,012,536 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS [1997.06.14 10:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\iyvu9_32.dll < End of report > |
Themen zu PC erstarrt(strg+alt+ent funkzt net),maus und eingabe net möglich! |
absturz, antivirus, avg free, avg security toolbar, bho, bildschirm, device driver, diagnostics, e-mail, error, erstarrt, friert ein, g data, geht nicht mehr, google, hdaudio.sys, hijackthis, home, home premium, hängt sich auf, internet, liveupdate.exe, maus, maus geht nicht, monitor, mozilla, nvlddmkm.sys, object, plug-in, problem, programdata, proxy, registry, rootkit, rundll, seaport.exe, security, software, start menu, system, trojaner, usb, virus |