|
Log-Analyse und Auswertung: Einige Internetseiten lassen sich nicht öffnen (web.de,msn.de...)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
30.05.2010, 23:15 | #1 |
| Einige Internetseiten lassen sich nicht öffnen (web.de,msn.de...) Guten Abend. Ich habe schon seit 2 Tagen ein Problem. Ich kann einige Internetseiten wie microsoft, msn, chip und auch web.de nicht öffnen. Habe schon ettliche male die Interneteinstellungen gecheckt, eine Systemwiederherstellung vollzogen und sogar meine DNS cache in der CMD gelöscht (mit dem befehl ipconfig) Mein Betriebssystem ist übrigens Windows 7 Code:
ATTFilter OTL Extras logfile created on: 30.05.2010 23:57:16 - Run 1 OTL by OldTimer - Version 3.2.5.1 Folder = C:\Users\MrMijagi\Downloads 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 58,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 67,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 149,04 Gb Total Space | 100,77 Gb Free Space | 67,62% Space Free | Partition Type: NTFS Drive D: | 451,76 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF Drive E: | 470,73 Mb Total Space | 183,75 Mb Free Space | 39,03% Space Free | Partition Type: FAT Drive F: | 1,36 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: MRMIJAGI-PC Current User Name: MrMijagi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "NVIDIA Display Control Panel" = NVIDIA Display Control Panel "NVIDIA Drivers" = NVIDIA Drivers "WinRAR archiver" = WinRAR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{DEA314C4-0929-4250-BC92-98E4C105F28D}" = NVIDIA PhysX "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "CCleaner" = CCleaner "Darkness Within 2: The Dark Lineage_is1" = Darkness Within 2: The Dark Lineage "Download Accelerator Plus (DAP)" = Download Accelerator Plus (DAP) "EvJO Wallpaper Changer_is1" = EvJO Wallpaper Changer v2.0 "Game Booster_is1" = Game Booster "League of Legends_is1" = League of Legends "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3) "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "Xfire" = Xfire (remove only) "XfireXO Toolbar" = XfireXO Toolbar "XKick" = XKick 1.0.0.0 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 28.05.2010 07:57:54 | Computer Name = MrMijagi-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: Kicks.exe, Version: 4.0.0.1, Zeitstempel: 0x4b836eda Name des fehlerhaften Moduls: Kicks.exe, Version: 4.0.0.1, Zeitstempel: 0x4b836eda Ausnahmecode: 0xc0000005 Fehleroffset: 0x0013acac ID des fehlerhaften Prozesses: 0xf7c Startzeit der fehlerhaften Anwendung: 0x01cafe5ca41766b4 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\RunUp_SG\KicksOnline\Kicks.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\RunUp_SG\KicksOnline\Kicks.exe Berichtskennung: 3f615605-6a50-11df-9c0f-001d92a1e339 Error - 29.05.2010 11:00:02 | Computer Name = MrMijagi-PC | Source = SideBySide | ID = 16842815 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. [ System Events ] Error - 28.05.2010 16:34:28 | Computer Name = MrMijagi-PC | Source = Service Control Manager | ID = 7030 Description = Der Dienst "ICQ Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error - 28.05.2010 17:53:17 | Computer Name = MrMijagi-PC | Source = bowser | ID = 8003 Description = Error - 28.05.2010 20:54:08 | Computer Name = MrMijagi-PC | Source = Service Control Manager | ID = 7016 Description = Der Dienst "NVIDIA Stereoscopic 3D Driver Service" hat einen ungültigen aktuellen Status gemeldet: 0 Error - 29.05.2010 13:45:12 | Computer Name = MrMijagi-PC | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden. Error - 29.05.2010 13:45:13 | Computer Name = MrMijagi-PC | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden. Error - 29.05.2010 13:45:14 | Computer Name = MrMijagi-PC | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden. Error - 29.05.2010 14:00:13 | Computer Name = MrMijagi-PC | Source = Service Control Manager | ID = 7016 Description = Der Dienst "NVIDIA Stereoscopic 3D Driver Service" hat einen ungültigen aktuellen Status gemeldet: 0 Error - 29.05.2010 17:43:48 | Computer Name = MrMijagi-PC | Source = bowser | ID = 8003 Description = Error - 29.05.2010 19:34:17 | Computer Name = MrMijagi-PC | Source = Service Control Manager | ID = 7016 Description = Der Dienst "NVIDIA Stereoscopic 3D Driver Service" hat einen ungültigen aktuellen Status gemeldet: 0 Error - 30.05.2010 07:39:21 | Computer Name = MrMijagi-PC | Source = NetBT | ID = 4321 Description = Der Name "WORKGROUP :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.2.103 registriert werden. Der Computer mit IP-Adresse 192.168.2.1 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Code:
ATTFilter Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4156 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 31.05.2010 00:01:49 mbam-log-2010-05-31 (00-01-49).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 117011 Laufzeit: 2 Minute(n), 31 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:59:34, on 30.05.2010 Platform: Unknown Windows (WinNT 6.01.3504) MSIE: Internet Explorer v8.00 (8.00.7600.16385) Boot mode: Normal Running processes: C:\Program Files (x86)\EvJOSoft\Wallpaper Changer\EvJOWall.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Suite CBE 10\avp.exe C:\Program Files (x86)\Xfire\Xfire.exe C:\Program Files (x86)\DAP\DAP.EXE C:\Users\MrMijagi\Downloads\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll R3 - URLSearchHook: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll R3 - URLSearchHook: (no name) - - (no file) F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Suite CBE 10\ievkbd.dll O2 - BHO: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Suite CBE 10\klwtbbho.dll O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~2\DAP\DAPIEL~1.DLL O3 - Toolbar: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Suite CBE 10\avp.exe" O4 - HKCU\..\Run: [EvJOWall] C:\Program Files (x86)\EvJOSoft\Wallpaper Changer\EvJOWall.exe O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [7 Taskbar Tweaker] "C:\Users\MrMijagi\Downloads\7 Taskbar Tweaker x64.exe" -hidewnd O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files (x86)\DAP\DAP.EXE" /STARTUP O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7.1\ICQ.exe" silent loginmode=4 O4 - Startup: Xfire.lnk = C:\Program Files (x86)\Xfire\Xfire.exe O8 - Extra context menu item: &Clean Traces - C:\Program Files (x86)\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files (x86)\DAP\dapextie.htm O8 - Extra context menu item: Download &all with DAP - C:\Program Files (x86)\DAP\dapextie2.htm O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Suite CBE 10\ie_banner_deny.htm O9 - Extra button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Suite CBE 10\klwtbbho.dll O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe O9 - Extra button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Suite CBE 10\klwtbbho.dll O13 - Gopher Prefix: O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O20 - AppInit_DLLs: C:\PROGRA~3\AVP9\mzvkbd3.dll,C:\PROGRA~3\AVP9\sbhook.dll O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Kaspersky Security Suite CBE 10 (AVP) - Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Suite CBE 10\avp.exe O23 - Service: DATA BECKER Update Service (DBService) - DATA BECKER GmbH & Co KG - C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 7976 bytes |
30.05.2010, 23:19 | #2 |
| Einige Internetseiten lassen sich nicht öffnen (web.de,msn.de...)Code:
ATTFilter OTL logfile created on: 30.05.2010 23:57:16 - Run 1 OTL by OldTimer - Version 3.2.5.1 Folder = C:\Users\MrMijagi\Downloads 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 58,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 67,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 149,04 Gb Total Space | 100,77 Gb Free Space | 67,62% Space Free | Partition Type: NTFS Drive D: | 451,76 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF Drive E: | 470,73 Mb Total Space | 183,75 Mb Free Space | 39,03% Space Free | Partition Type: FAT Drive F: | 1,36 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: MRMIJAGI-PC Current User Name: MrMijagi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Users\MrMijagi\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Java\jre6\bin\javaw.exe (Sun Microsystems, Inc.) PRC - C:\Program Files (x86)\DAP\DAP.exe (SpeedBit Ltd.) PRC - C:\Program Files (x86)\Xfire\Xfire.exe (Xfire Inc.) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.) PRC - C:\Program Files (x86)\EvJOSoft\Wallpaper Changer\EvJOWall.exe (EvJOSoft) ========== Modules (SafeList) ========== MOD - C:\Users\MrMijagi\Downloads\OTL.exe (OldTimer Tools) MOD - C:\Program Files (x86)\Xfire\xfire_toucan_42654.dll (Xfire Inc.) MOD - C:\Windows\SysWOW64\wsock32.dll (Microsoft Corporation) MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation) MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (WwanSvc) -- C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation) SRV:64bit: - (WbioSrvc) -- C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation) SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation) SRV:64bit: - (Power) -- C:\Windows\SysNative\umpo.dll (Microsoft Corporation) SRV:64bit: - (Themes) -- C:\Windows\SysNative\themeservice.dll (Microsoft Corporation) SRV:64bit: - (sppuinotify) -- C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation) SRV:64bit: - (SensrSvc) -- C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation) SRV:64bit: - (PeerDistSvc) -- C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation) SRV:64bit: - (PNRPsvc) -- C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation) SRV:64bit: - (p2pimsvc) -- C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation) SRV:64bit: - (HomeGroupProvider) -- C:\Windows\SysNative\provsvc.dll (Microsoft Corporation) SRV:64bit: - (RpcEptMapper) -- C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation) SRV:64bit: - (PNRPAutoReg) -- C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation) SRV:64bit: - (HomeGroupListener) -- C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation) SRV:64bit: - (FontCache) -- C:\Windows\SysNative\FntCache.dll (Microsoft Corporation) SRV:64bit: - (Dhcp) -- C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation) SRV:64bit: - (defragsvc) -- C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation) SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation) SRV:64bit: - (bthserv) -- C:\Windows\SysNative\bthserv.dll (Microsoft Corporation) SRV:64bit: - (BDESVC) -- C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation) SRV:64bit: - (AxInstSV) -- C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation) SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SRV:64bit: - (AppIDSvc) -- C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation) SRV:64bit: - (wbengine) -- C:\Windows\SysNative\wbengine.exe (Microsoft Corporation) SRV:64bit: - (sppsvc) -- C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation) SRV:64bit: - (Fax) -- C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation) SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) SRV - (VSS) -- C:\Windows\Vss [2009.07.14 05:20:14 | 000,000,000 | ---D | M] SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2009.07.14 05:20:14 | 000,000,000 | ---D | M] SRV - (HomeGroupProvider) -- C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation) SRV - (Dhcp) -- C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation) SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof () SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.) ========== Driver Services (SafeList) ========== DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys () DRV:64bit: - (KSecPkg) -- C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation) DRV:64bit: - (fvevol) -- C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (hwpolicy) -- C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation) DRV:64bit: - (FsDepends) -- C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (WIMMount) -- C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation) DRV:64bit: - (vhdmp) -- C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation) DRV:64bit: - (vmbus) -- C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation) DRV:64bit: - (storflt) -- C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation) DRV:64bit: - (vdrvroot) -- C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation) DRV:64bit: - (storvsc) -- C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (rdyboost) -- C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation) DRV:64bit: - (pcw) -- C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation) DRV:64bit: - (CNG) -- C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation) DRV:64bit: - (rdpbus) -- C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation) DRV:64bit: - (RDPREFMP) -- C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation) DRV:64bit: - (RasAgileVpn) WAN Miniport (IKEv2) -- C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation) DRV:64bit: - (WfpLwf) -- C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation) DRV:64bit: - (NdisCap) -- C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation) DRV:64bit: - (vwifibus) -- C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation) DRV:64bit: - (1394ohci) -- C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation) DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation) DRV:64bit: - (UmPass) -- C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation) DRV:64bit: - (mshidkmdf) -- C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation) DRV:64bit: - (WudfPf) -- C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation) DRV:64bit: - (MTConfig) -- C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation) DRV:64bit: - (CompositeBus) -- C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation) DRV:64bit: - (Beep) -- C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation) DRV:64bit: - (AppID) -- C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation) DRV:64bit: - (scfilter) -- C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation) DRV:64bit: - (s3cap) -- C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation) DRV:64bit: - (VMBusHID) -- C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation) DRV:64bit: - (discache) -- C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation) DRV:64bit: - (HidBatt) -- C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation) DRV:64bit: - (CmBatt) -- C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation) DRV:64bit: - (AcpiPmi) -- C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation) DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation) DRV:64bit: - (AmdPPM) -- C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (KMWDFILTER) -- C:\Windows\SysNative\drivers\KMWDFILTER.sys (Windows (R) Codename Longhorn DDK provider) DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation ) DRV - (CSC) -- C:\Windows\CSC [2010.05.28 04:07:27 | 000,000,000 | ---D | M] DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) DRV - (NetBIOS) -- C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation) DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof () DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof () ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll (Conduit Ltd.) IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.speedbit.com/?aff=105 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.openintab: true FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.3 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2 FF - prefs.js..extensions.enabledItems: {097d3191-e6fa-4728-9826-b533d755359d}:0.7.11 FF - prefs.js..extensions.enabledItems: YoutubeDownloader@PeterOlayev.com:1.4 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:9.0.0.747 FF - prefs.js..extensions.enabledItems: {5e5ab302-7f65-44cd-8211-c1d4caaccea3}:2.6.0.15 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105 FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.05.28 03:38:41 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.05.30 18:41:33 | 000,000,000 | ---D | M] [2010.05.28 03:38:49 | 000,000,000 | ---D | M] -- C:\Users\MrMijagi\AppData\Roaming\mozilla\Extensions [2010.05.30 23:49:58 | 000,000,000 | ---D | M] -- C:\Users\MrMijagi\AppData\Roaming\mozilla\Firefox\Profiles\cfnggaj0.default\extensions [2010.05.28 03:43:39 | 000,000,000 | ---D | M] (All-in-One Sidebar) -- C:\Users\MrMijagi\AppData\Roaming\mozilla\Firefox\Profiles\cfnggaj0.default\extensions\{097d3191-e6fa-4728-9826-b533d755359d} [2010.05.28 03:43:39 | 000,000,000 | ---D | M] (FlashGot) -- C:\Users\MrMijagi\AppData\Roaming\mozilla\Firefox\Profiles\cfnggaj0.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34} [2010.05.30 16:11:41 | 000,000,000 | ---D | M] (XfireXO Toolbar) -- C:\Users\MrMijagi\AppData\Roaming\mozilla\Firefox\Profiles\cfnggaj0.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} [2010.05.30 23:46:41 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\MrMijagi\AppData\Roaming\mozilla\Firefox\Profiles\cfnggaj0.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2010.05.28 03:43:39 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\MrMijagi\AppData\Roaming\mozilla\Firefox\Profiles\cfnggaj0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010.05.28 03:43:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MrMijagi\AppData\Roaming\mozilla\Firefox\Profiles\cfnggaj0.default\extensions\{dc572301-7619-498c-a57d-39143191b318} [2010.05.28 03:43:39 | 000,000,000 | ---D | M] -- C:\Users\MrMijagi\AppData\Roaming\mozilla\Firefox\Profiles\cfnggaj0.default\extensions\YoutubeDownloader@PeterOlayev.com [2010.05.30 19:04:27 | 000,002,059 | ---- | M] () -- C:\Users\MrMijagi\AppData\Roaming\Mozilla\FireFox\Profiles\cfnggaj0.default\searchplugins\daemon-search.xml [2010.02.03 15:37:50 | 000,000,947 | ---- | M] () -- C:\Users\MrMijagi\AppData\Roaming\Mozilla\FireFox\Profiles\cfnggaj0.default\searchplugins\icqplugin.xml [2010.05.30 23:49:58 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2010.05.30 18:41:33 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010.05.30 16:06:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions\linkfilter@kaspersky.ru [2010.05.30 18:41:28 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2009.07.03 00:34:44 | 000,083,376 | ---- | M] (NHN USA Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npijjiautoinstallpluginff.dll [2009.10.06 11:40:40 | 000,098,304 | ---- | M] (OGPlanet Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npOGPPlugin.dll [2010.02.01 18:19:42 | 000,238,776 | ---- | M] (Pando Networks) -- C:\Program Files (x86)\mozilla firefox\plugins\npPandoWebInst.dll [2006.08.09 12:16:08 | 000,030,408 | ---- | M] ( ) -- C:\Program Files (x86)\mozilla firefox\plugins\npWebLaunch.dll [2010.04.01 18:54:38 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.04.01 18:54:38 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.04.01 18:54:38 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.04.01 18:54:38 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.04.01 18:54:38 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll (Conduit Ltd.) O2 - BHO: (DAPIELoader Class) - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~2\DAP\DAPIEL~1.DLL (SpeedBit Ltd.) O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [DownloadAccelerator] C:\Program Files (x86)\DAP\DAP.EXE (SpeedBit Ltd.) O4 - HKCU..\Run: [EvJOWall] C:\Program Files (x86)\EvJOSoft\Wallpaper Changer\EvJOWall.exe (EvJOSoft) O4 - Startup: C:\Users\MrMijagi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files (x86)\Xfire\Xfire.exe (Xfire Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation) O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010.05.29 18:27:42 | 000,000,108 | R--- | M] () - F:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{12d18b77-6c0e-11df-b261-001d92a1e339}\Shell - "" = AutoRun O33 - MountPoints2\{12d18b77-6c0e-11df-b261-001d92a1e339}\Shell\AutoRun\command - "" = F:\DarknessWithin2.exe -- [2010.05.29 18:27:42 | 1464,753,942 | R--- | M] ( ) O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.05.30 23:46:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner [2010.05.30 19:21:56 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Roaming\NVIDIA [2010.05.30 19:21:11 | 000,000,000 | ---D | C] -- C:\Windows\DEA314C409294250BC9298E4C105F28D.TMP [2010.05.30 19:21:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard [2010.05.30 19:21:05 | 000,530,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_6.dll [2010.05.30 19:21:05 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_6.dll [2010.05.30 19:21:05 | 000,078,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_4.dll [2010.05.30 19:21:05 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_4.dll [2010.05.30 19:21:04 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_6.dll [2010.05.30 19:21:04 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_6.dll [2010.05.30 19:21:04 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_7.dll [2010.05.30 19:21:04 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_7.dll [2010.05.30 19:21:01 | 000,517,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_5.dll [2010.05.30 19:21:01 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_5.dll [2010.05.30 19:21:01 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_5.dll [2010.05.30 19:21:01 | 000,176,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_5.dll [2010.05.30 19:21:00 | 005,554,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dcsx_42.dll [2010.05.30 19:21:00 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_42.dll [2010.05.30 19:21:00 | 002,582,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_42.dll [2010.05.30 19:21:00 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_42.dll [2010.05.30 19:21:00 | 000,523,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_42.dll [2010.05.30 19:21:00 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_42.dll [2010.05.30 19:21:00 | 000,285,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx11_42.dll [2010.05.30 19:21:00 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_42.dll [2010.05.30 19:20:59 | 002,475,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_42.dll [2010.05.30 19:20:59 | 002,430,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_41.dll [2010.05.30 19:20:59 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_42.dll [2010.05.30 19:20:59 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_41.dll [2010.05.30 19:20:59 | 000,520,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_41.dll [2010.05.30 19:20:59 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_41.dll [2010.05.30 19:20:58 | 005,425,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_41.dll [2010.05.30 19:20:58 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_41.dll [2010.05.30 19:20:58 | 000,521,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_4.dll [2010.05.30 19:20:58 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_4.dll [2010.05.30 19:20:58 | 000,073,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_3.dll [2010.05.30 19:20:58 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_3.dll [2010.05.30 19:20:57 | 002,605,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_40.dll [2010.05.30 19:20:57 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_40.dll [2010.05.30 19:20:57 | 000,519,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_40.dll [2010.05.30 19:20:57 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_40.dll [2010.05.30 19:20:57 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_4.dll [2010.05.30 19:20:57 | 000,174,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_4.dll [2010.05.30 19:20:57 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_6.dll [2010.05.30 19:20:57 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_6.dll [2010.05.30 19:20:56 | 005,631,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_40.dll [2010.05.30 19:20:56 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_40.dll [2010.05.30 19:20:55 | 000,518,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_3.dll [2010.05.30 19:20:55 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_3.dll [2010.05.30 19:20:55 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_3.dll [2010.05.30 19:20:55 | 000,175,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_3.dll [2010.05.30 19:20:55 | 000,074,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_2.dll [2010.05.30 19:20:55 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_2.dll [2010.05.30 19:20:55 | 000,025,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_5.dll [2010.05.30 19:20:55 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_5.dll [2010.05.30 19:20:53 | 000,513,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_2.dll [2010.05.30 19:20:53 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_2.dll [2010.05.30 19:20:53 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_2.dll [2010.05.30 19:20:53 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_2.dll [2010.05.30 19:20:53 | 000,072,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_1.dll [2010.05.30 19:20:53 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_1.dll [2010.05.30 19:20:52 | 001,942,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_39.dll [2010.05.30 19:20:52 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_39.dll [2010.05.30 19:20:52 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_39.dll [2010.05.30 19:20:52 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_39.dll [2010.05.30 19:20:51 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_39.dll [2010.05.30 19:20:50 | 000,511,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_1.dll [2010.05.30 19:20:50 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_1.dll [2010.05.30 19:20:50 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_1.dll [2010.05.30 19:20:50 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_1.dll [2010.05.30 19:20:50 | 000,068,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_0.dll [2010.05.30 19:20:50 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_0.dll [2010.05.30 19:20:50 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_4.dll [2010.05.30 19:20:50 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_4.dll [2010.05.30 19:20:49 | 004,991,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_38.dll [2010.05.30 19:20:49 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_38.dll [2010.05.30 19:20:49 | 001,941,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_38.dll [2010.05.30 19:20:49 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_38.dll [2010.05.30 19:20:49 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_38.dll [2010.05.30 19:20:49 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_38.dll [2010.05.30 19:20:46 | 000,489,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_0.dll [2010.05.30 19:20:46 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_0.dll [2010.05.30 19:20:44 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_0.dll [2010.05.30 19:20:44 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_0.dll [2010.05.30 19:20:43 | 004,910,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_37.dll [2010.05.30 19:20:43 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_37.dll [2010.05.30 19:20:43 | 001,860,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_37.dll [2010.05.30 19:20:43 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_37.dll [2010.05.30 19:20:43 | 000,529,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_37.dll [2010.05.30 19:20:43 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_37.dll [2010.05.30 19:20:43 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_3.dll [2010.05.30 19:20:43 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_3.dll [2010.05.30 19:20:41 | 000,411,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_10.dll [2010.05.30 19:20:41 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_10.dll [2010.05.30 19:20:39 | 005,081,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_36.dll [2010.05.30 19:20:39 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_36.dll [2010.05.30 19:20:39 | 002,006,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_36.dll [2010.05.30 19:20:39 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_36.dll [2010.05.30 19:20:39 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_36.dll [2010.05.30 19:20:39 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_36.dll [2010.05.30 19:20:38 | 005,073,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_35.dll [2010.05.30 19:20:38 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_35.dll [2010.05.30 19:20:38 | 001,985,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_35.dll [2010.05.30 19:20:38 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_35.dll [2010.05.30 19:20:38 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_35.dll [2010.05.30 19:20:38 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_35.dll [2010.05.30 19:20:38 | 000,411,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_9.dll [2010.05.30 19:20:38 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_9.dll [2010.05.30 19:20:37 | 004,496,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_34.dll [2010.05.30 19:20:37 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_34.dll [2010.05.30 19:20:37 | 001,401,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_34.dll [2010.05.30 19:20:37 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_34.dll [2010.05.30 19:20:37 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_34.dll [2010.05.30 19:20:37 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_34.dll [2010.05.30 19:20:37 | 000,409,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_8.dll [2010.05.30 19:20:37 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_8.dll [2010.05.30 19:20:37 | 000,107,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_3.dll [2010.05.30 19:20:37 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_3.dll [2010.05.30 19:20:37 | 000,021,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_2.dll [2010.05.30 19:20:37 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_2.dll [2010.05.30 19:20:35 | 004,494,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_33.dll [2010.05.30 19:20:35 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_33.dll [2010.05.30 19:20:35 | 001,400,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_33.dll [2010.05.30 19:20:35 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_33.dll [2010.05.30 19:20:35 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_33.dll [2010.05.30 19:20:35 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_33.dll [2010.05.30 19:20:35 | 000,403,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_7.dll [2010.05.30 19:20:35 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_7.dll [2010.05.30 19:20:34 | 004,398,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_32.dll [2010.05.30 19:20:34 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_32.dll [2010.05.30 19:20:34 | 000,469,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10.dll [2010.05.30 19:20:34 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10.dll [2010.05.30 19:20:34 | 000,393,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_6.dll [2010.05.30 19:20:34 | 000,390,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_5.dll [2010.05.30 19:20:34 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_6.dll [2010.05.30 19:20:34 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_5.dll [2010.05.30 19:20:33 | 003,977,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_31.dll [2010.05.30 19:20:33 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_31.dll [2010.05.30 19:20:33 | 000,364,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_4.dll [2010.05.30 19:20:33 | 000,363,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_3.dll [2010.05.30 19:20:33 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_4.dll [2010.05.30 19:20:33 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_3.dll [2010.05.30 19:20:33 | 000,083,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_2.dll [2010.05.30 19:20:33 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_2.dll [2010.05.30 19:20:33 | 000,017,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_1.dll [2010.05.30 19:20:33 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_1.dll [2010.05.30 19:20:32 | 000,354,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_2.dll [2010.05.30 19:20:32 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_2.dll [2010.05.30 19:20:32 | 000,083,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_1.dll [2010.05.30 19:20:32 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_1.dll [2010.05.30 19:20:31 | 000,352,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_1.dll [2010.05.30 19:20:31 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_1.dll [2010.05.30 19:20:27 | 003,927,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_30.dll [2010.05.30 19:20:27 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_30.dll [2010.05.30 19:20:26 | 003,830,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_29.dll [2010.05.30 19:20:26 | 003,815,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_28.dll [2010.05.30 19:20:26 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_29.dll [2010.05.30 19:20:26 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_28.dll [2010.05.30 19:20:26 | 000,355,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_0.dll [2010.05.30 19:20:26 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_0.dll [2010.05.30 19:20:26 | 000,016,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_0.dll [2010.05.30 19:20:26 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_0.dll [2010.05.30 19:20:25 | 003,823,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_25.dll [2010.05.30 19:20:25 | 003,807,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_27.dll [2010.05.30 19:20:25 | 003,767,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_26.dll [2010.05.30 19:20:25 | 003,544,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_24.dll [2010.05.30 19:20:25 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_25.dll [2010.05.30 19:20:25 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_27.dll [2010.05.30 19:20:25 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_26.dll [2010.05.30 19:20:25 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_24.dll [2010.05.30 19:13:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Iceberg Interactive [2010.05.30 19:04:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite [2010.05.30 19:03:48 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Roaming\DAEMON Tools Lite [2010.05.30 19:03:46 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite [2010.05.30 18:44:18 | 000,000,000 | ---D | C] -- C:\Programme\JDownloader [2010.05.30 18:41:33 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll [2010.05.30 18:41:33 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2010.05.30 18:41:33 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2010.05.30 18:41:33 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2010.05.30 17:36:50 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System\d3dx9_39.dll [2010.05.30 17:35:33 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_39.dll [2010.05.30 17:09:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2010.05.30 17:09:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy [2010.05.30 17:02:46 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Roaming\Malwarebytes [2010.05.30 17:02:39 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010.05.30 17:02:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.05.30 17:02:38 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2010.05.30 17:02:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010.05.30 16:15:48 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files [2010.05.30 16:11:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit [2010.05.30 15:17:58 | 000,000,000 | -H-D | C] -- C:\ProgramData\AVP9 [2010.05.30 15:17:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab [2010.05.30 15:17:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Kaspersky Lab [2010.05.29 19:59:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SlySoft [2010.05.29 01:21:27 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Local\Diagnostics [2010.05.29 00:14:16 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Roaming\LolClient [2010.05.28 22:34:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ICQ6Toolbar [2010.05.28 22:34:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\InstallShield Installation Information [2010.05.28 22:34:25 | 000,000,000 | ---D | C] -- C:\ProgramData\ICQ [2010.05.28 22:34:03 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Roaming\ICQ [2010.05.28 22:34:03 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Local\AOL [2010.05.28 22:34:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ICQ7.1 [2010.05.28 22:31:16 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx [2010.05.28 22:31:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe [2010.05.28 22:31:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR [2010.05.28 22:29:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\League of Legends [2010.05.28 22:13:36 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Local\PMB Files [2010.05.28 22:13:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks [2010.05.28 19:11:30 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\INCA Shared [2010.05.28 18:50:31 | 000,000,000 | ---D | C] -- C:\gpotato [2010.05.28 17:10:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Vision [2010.05.28 16:30:05 | 000,000,000 | ---D | C] -- C:\ProgramData\DATA BECKER Downloads [2010.05.28 16:30:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ProtectDisc [2010.05.28 16:30:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DATA BECKER [2010.05.28 16:16:17 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Roaming\WinRAR [2010.05.28 16:16:05 | 000,000,000 | ---D | C] -- C:\Programme\WinRAR [2010.05.28 16:13:55 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Local\ElevatedDiagnostics [2010.05.28 15:16:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XfireXO [2010.05.28 15:16:28 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Roaming\Xfire [2010.05.28 15:16:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Xfire [2010.05.28 15:16:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xfire [2010.05.28 14:52:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2010.05.28 14:52:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2010.05.28 14:52:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java [2010.05.28 14:06:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit [2010.05.28 13:48:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RunUp_SG [2010.05.28 12:45:49 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Roaming\Macromedia [2010.05.28 12:45:49 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Roaming\Adobe [2010.05.28 12:45:47 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed [2010.05.28 05:05:50 | 000,000,000 | -HSD | C] -- C:\Boot [2010.05.28 04:09:43 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2010.05.28 04:07:33 | 000,000,000 | -HSD | C] -- C:\System Volume Information [2010.05.28 04:07:27 | 000,000,000 | ---D | C] -- C:\Windows\CSC [2010.05.28 04:01:00 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\Documents\EvJOWallpaper [2010.05.28 04:00:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EvJOSoft [2010.05.28 03:55:32 | 001,077,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSCOMCTL.OCX [2010.05.28 03:55:32 | 000,368,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vbar332.dll [2010.05.28 03:55:32 | 000,140,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\COMDLG32.OCX [2010.05.28 03:55:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wallpaper Juggler [2010.05.28 03:45:59 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP [2010.05.28 03:45:58 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\Documents\My DAP Downloads [2010.05.28 03:45:57 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedBit [2010.05.28 03:45:56 | 000,172,032 | ---- | C] (Jin Hui E-mail: jinhui@jcomsoft.com Web: hxxp://www.jcomsoft.com) -- C:\Windows\SysWow64\AniGIF.ocx [2010.05.28 03:45:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAP [2010.05.28 03:41:00 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browserchoice.exe [2010.05.28 03:38:41 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Roaming\Mozilla [2010.05.28 03:38:41 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Local\Mozilla [2010.05.28 03:38:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2010.05.28 03:31:02 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA [2010.05.28 03:30:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation [2010.05.28 03:30:35 | 000,000,000 | -HSD | C] -- C:\Windows\Installer [2010.05.28 03:30:30 | 000,000,000 | ---D | C] -- C:\Programme\NVIDIA Corporation [2010.05.28 03:29:51 | 004,503,144 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll [2010.05.28 03:29:51 | 000,930,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpinst.exe [2010.05.28 03:29:51 | 000,064,616 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll [2010.05.28 03:29:51 | 000,056,424 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll [2010.05.28 03:29:51 | 000,011,240 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvBridge.kmd [2010.05.28 03:29:49 | 021,005,928 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll [2010.05.28 03:29:49 | 015,227,496 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll [2010.05.28 03:29:49 | 003,215,464 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvencodemft.dll [2010.05.28 03:29:49 | 002,907,752 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvencodemft.dll [2010.05.28 03:29:49 | 000,384,616 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdecodemft.dll [2010.05.28 03:29:49 | 000,316,008 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvdecodemft.dll [2010.05.28 03:29:47 | 011,906,664 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll [2010.05.28 03:29:47 | 009,386,600 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll [2010.05.28 03:29:47 | 002,893,416 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll [2010.05.28 03:29:47 | 002,646,632 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll [2010.05.28 03:29:47 | 002,106,472 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll [2010.05.28 03:29:47 | 002,009,704 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll [2010.05.28 03:29:46 | 016,061,032 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll [2010.05.28 03:29:46 | 011,647,592 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll [2010.05.28 03:29:46 | 005,444,200 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll [2010.05.28 03:29:46 | 004,029,544 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll [2010.05.28 03:29:46 | 001,592,936 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll [2010.05.28 03:29:46 | 001,296,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll [2010.05.28 03:29:46 | 000,254,056 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcod1914.dll [2010.05.28 03:29:46 | 000,254,056 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcod.dll [2010.05.28 03:29:41 | 000,000,000 | ---D | C] -- C:\NVIDIA [2010.05.28 03:26:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Artechsoft [2010.05.28 03:24:38 | 000,612,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2010.05.28 03:24:38 | 000,427,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll [2010.05.28 03:24:35 | 014,629,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll [2010.05.28 03:24:34 | 011,406,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll [2010.05.28 03:24:33 | 001,975,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CertEnroll.dll [2010.05.28 03:24:33 | 001,320,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CertEnroll.dll [2010.05.28 03:24:32 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL [2010.05.28 03:24:32 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL [2010.05.28 03:24:24 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll [2010.05.28 03:24:24 | 000,422,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll [2010.05.28 03:24:24 | 000,369,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll [2010.05.28 03:24:24 | 000,365,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll [2010.05.28 03:24:24 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe [2010.05.28 03:24:24 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe [2010.05.28 03:24:24 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe [2010.05.28 03:24:24 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe [2010.05.28 03:24:24 | 000,306,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe [2010.05.28 03:24:24 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe [2010.05.28 03:24:24 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe [2010.05.28 03:24:24 | 000,277,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe [2010.05.28 03:24:24 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll [2010.05.28 03:24:24 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll [2010.05.28 03:24:24 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll [2010.05.28 03:24:24 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll [2010.05.28 03:24:18 | 000,366,080 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll [2010.05.28 03:24:18 | 000,293,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll [2010.05.28 03:24:18 | 000,148,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll [2010.05.28 03:24:18 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll [2010.05.28 03:24:18 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll [2010.05.28 03:24:18 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll [2010.05.28 03:24:16 | 002,870,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe [2010.05.28 03:24:16 | 002,614,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe [2010.05.28 03:24:16 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe [2010.05.28 03:24:15 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2010.05.28 03:24:15 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2010.05.28 03:24:15 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2010.05.28 03:24:15 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2010.05.28 03:24:15 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2010.05.28 03:24:15 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2010.05.28 03:24:12 | 001,192,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wininet.dll [2010.05.28 03:24:12 | 001,026,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstime.dll [2010.05.28 03:24:12 | 000,977,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wininet.dll [2010.05.28 03:24:12 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstime.dll [2010.05.28 03:24:12 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iedkcs32.dll [2010.05.28 03:24:12 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll [2010.05.28 03:24:12 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedsbs.dll [2010.05.28 03:24:11 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedsbs.dll [2010.05.28 03:24:07 | 000,223,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fvevol.sys [2010.05.28 03:24:06 | 001,572,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll [2010.05.28 03:24:05 | 001,328,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll [2010.05.28 03:24:05 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\avifil32.dll [2010.05.28 03:24:05 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mciavi32.dll [2010.05.28 03:24:05 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iyuv_32.dll [2010.05.28 03:24:05 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvidc32.dll [2010.05.28 03:24:05 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msyuv.dll [2010.05.28 03:24:05 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrle32.dll [2010.05.28 03:24:05 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsbyuv.dll [2010.05.28 03:23:59 | 005,509,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2010.05.28 03:23:58 | 003,954,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2010.05.28 03:23:58 | 003,899,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2010.05.28 03:23:55 | 000,852,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2010.05.28 03:23:55 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2010.05.28 03:23:52 | 001,446,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll [2010.05.28 03:23:52 | 000,153,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ksecpkg.sys [2010.05.28 03:23:50 | 000,960,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll [2010.05.28 03:23:49 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll [2010.05.28 03:23:49 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll [2010.05.28 03:23:49 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdri.dll [2010.05.28 03:23:49 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll [2010.05.28 03:23:49 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax [2010.05.28 03:23:49 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax [2010.05.28 03:23:30 | 000,315,392 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\HideWin.exe [2010.05.28 03:23:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield [2010.05.28 03:20:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel [2010.05.28 03:20:02 | 000,000,000 | ---D | C] -- C:\Intel [2010.05.28 03:19:57 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll [2010.05.28 03:19:57 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wintrust.dll [2010.05.28 03:19:56 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cabview.dll [2010.05.28 03:19:56 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cabview.dll [2010.05.28 03:17:01 | 000,000,000 | R--D | C] -- C:\Users\MrMijagi\Searches [2010.05.28 03:16:53 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Roaming\Identities [2010.05.28 03:16:49 | 000,000,000 | R--D | C] -- C:\Users\MrMijagi\Contacts [2010.05.28 03:16:47 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Local\VirtualStore [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\Vorlagen [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\AppData\Local\Verlauf [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\AppData\Local\Temporary Internet Files [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\Startmenü [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\SendTo [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\Recent [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\Netzwerkumgebung [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\Lokale Einstellungen [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\Documents\Eigene Videos [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\Documents\Eigene Musik [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\Eigene Dateien [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\Documents\Eigene Bilder [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\Druckumgebung [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\Cookies [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\AppData\Local\Anwendungsdaten [2010.05.28 03:16:31 | 000,000,000 | -HSD | C] -- C:\Users\MrMijagi\Anwendungsdaten [2010.05.28 03:16:30 | 000,000,000 | --SD | C] -- C:\Users\MrMijagi\AppData\Roaming\Microsoft [2010.05.28 03:16:30 | 000,000,000 | R--D | C] -- C:\Users\MrMijagi\Videos [2010.05.28 03:16:30 | 000,000,000 | R--D | C] -- C:\Users\MrMijagi\Saved Games [2010.05.28 03:16:30 | 000,000,000 | R--D | C] -- C:\Users\MrMijagi\Pictures [2010.05.28 03:16:30 | 000,000,000 | R--D | C] -- C:\Users\MrMijagi\Music [2010.05.28 03:16:30 | 000,000,000 | R--D | C] -- C:\Users\MrMijagi\Links [2010.05.28 03:16:30 | 000,000,000 | R--D | C] -- C:\Users\MrMijagi\Favorites [2010.05.28 03:16:30 | 000,000,000 | R--D | C] -- C:\Users\MrMijagi\Downloads [2010.05.28 03:16:30 | 000,000,000 | R--D | C] -- C:\Users\MrMijagi\Documents [2010.05.28 03:16:30 | 000,000,000 | R--D | C] -- C:\Users\MrMijagi\Desktop [2010.05.28 03:16:30 | 000,000,000 | -H-D | C] -- C:\Users\MrMijagi\AppData [2010.05.28 03:16:30 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Local\Temp [2010.05.28 03:16:30 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Local\Microsoft [2010.05.28 03:16:30 | 000,000,000 | ---D | C] -- C:\Users\MrMijagi\AppData\Roaming\Media Center Programs [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\Recovery [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\Programme [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\Programme\Gemeinsame Dateien [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\ProgramData\Desktop [2010.05.28 03:14:09 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010.05.30 23:58:08 | 001,048,576 | -HS- | M] () -- C:\Users\MrMijagi\ntuser.dat [2010.05.30 23:49:47 | 000,008,118 | ---- | M] () -- C:\Users\MrMijagi\Documents\cc_20100530_234926.reg [2010.05.30 23:46:38 | 000,001,885 | ---- | M] () -- C:\Users\MrMijagi\Desktop\CCleaner.lnk [2010.05.30 19:18:50 | 000,001,293 | ---- | M] () -- C:\Users\Public\Desktop\Darkness Within 2.lnk [2010.05.30 19:16:41 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010.05.30 19:16:41 | 000,643,628 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2010.05.30 19:16:41 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010.05.30 19:16:41 | 000,126,188 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2010.05.30 19:16:41 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010.05.30 19:14:48 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2010.05.30 19:14:48 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2010.05.30 19:09:39 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.05.30 19:09:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.05.30 19:09:20 | 1610,059,776 | -HS- | M] () -- C:\hiberfil.sys [2010.05.30 19:07:54 | 001,680,425 | -H-- | M] () -- C:\Users\MrMijagi\AppData\Local\IconCache.db [2010.05.30 19:04:24 | 000,834,544 | ---- | M] () -- C:\Windows\SysNative\drivers\sptd.sys [2010.05.30 19:04:24 | 000,001,950 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk [2010.05.30 18:41:28 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll [2010.05.30 18:41:28 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2010.05.30 18:41:28 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2010.05.30 18:41:28 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2010.05.30 17:24:29 | 000,524,288 | -HS- | M] () -- C:\Users\MrMijagi\ntuser.dat{d1b2c3a2-6bc9-11df-bf1c-001d92a1e339}.TMContainer00000000000000000002.regtrans-ms [2010.05.30 17:24:29 | 000,524,288 | -HS- | M] () -- C:\Users\MrMijagi\ntuser.dat{d1b2c3a2-6bc9-11df-bf1c-001d92a1e339}.TMContainer00000000000000000001.regtrans-ms [2010.05.30 17:24:29 | 000,065,536 | -HS- | M] () -- C:\Users\MrMijagi\ntuser.dat{d1b2c3a2-6bc9-11df-bf1c-001d92a1e339}.TM.blf [2010.05.30 17:09:38 | 000,001,258 | ---- | M] () -- C:\Users\MrMijagi\Desktop\Spybot - Search & Destroy.lnk [2010.05.30 17:02:42 | 000,001,009 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.05.30 16:49:36 | 000,001,201 | ---- | M] () -- C:\Users\MrMijagi\Desktop\cmd.lnk [2010.05.30 16:37:22 | 000,002,002 | ---- | M] () -- C:\Users\Public\Desktop\League of Legends.lnk [2010.05.30 16:11:32 | 000,000,999 | ---- | M] () -- C:\Users\MrMijagi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk [2010.05.30 16:11:32 | 000,000,963 | ---- | M] () -- C:\Users\Public\Desktop\Xfire.lnk [2010.05.30 14:08:22 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\0000124C.LCS [2010.05.29 20:29:43 | 000,000,041 | -HS- | M] () -- C:\ProgramData\.zreglib [2010.05.29 19:45:33 | 000,236,583 | ---- | M] () -- C:\Users\MrMijagi\Documents\1275101086225.gif [2010.05.28 16:36:49 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\00000FE2.LCS [2010.05.28 16:30:14 | 000,057,560 | ---- | M] () -- C:\Users\MrMijagi\AppData\Local\GDIPFONTCACHEV1.DAT [2010.05.28 14:06:22 | 000,001,072 | ---- | M] () -- C:\Users\Public\Desktop\Game Booster.lnk [2010.05.28 13:49:33 | 000,001,239 | ---- | M] () -- C:\Users\MrMijagi\Desktop\KicksOnline.lnk [2010.05.28 05:05:52 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK [2010.05.28 04:10:46 | 000,057,050 | ---- | M] () -- C:\Windows\SysWow64\license.rtf [2010.05.28 04:10:46 | 000,057,050 | ---- | M] () -- C:\Windows\SysNative\license.rtf [2010.05.28 04:09:08 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf [2010.05.28 04:02:19 | 002,359,350 | ---- | M] () -- C:\Windows\WPCWallpaper.bmp [2010.05.28 04:01:21 | 000,002,213 | ---- | M] () -- C:\Users\MrMijagi\Documents\df.lst [2010.05.28 03:47:54 | 000,274,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2010.05.28 03:45:56 | 000,172,032 | ---- | M] (Jin Hui E-mail: jinhui@jcomsoft.com Web: hxxp://www.jcomsoft.com) -- C:\Windows\SysWow64\AniGIF.ocx [2010.05.28 03:38:44 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat [2010.05.28 03:38:38 | 000,001,939 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2010.05.28 03:32:09 | 000,524,288 | -HS- | M] () -- C:\Users\MrMijagi\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2010.05.28 03:32:09 | 000,524,288 | -HS- | M] () -- C:\Users\MrMijagi\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2010.05.28 03:32:09 | 000,065,536 | -HS- | M] () -- C:\Users\MrMijagi\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2010.05.28 03:26:29 | 000,001,183 | ---- | M] () -- C:\Users\MrMijagi\Desktop\XKickOnline.lnk [2010.05.28 03:23:30 | 000,315,392 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\HideWin.exe [2010.05.28 03:16:31 | 000,000,020 | -HS- | M] () -- C:\Users\MrMijagi\ntuser.ini [2010.05.28 03:14:30 | 000,171,136 | RHS- | M] () -- C:\w7ldr [2010.05.11 20:32:38 | 000,041,872 | ---- | M] () -- C:\Windows\SysWow64\xfcodec.dll [2010.05.11 20:32:38 | 000,027,536 | ---- | M] () -- C:\Windows\SysNative\xfcodec64.dll [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.05.30 23:49:29 | 000,008,118 | ---- | C] () -- C:\Users\MrMijagi\Documents\cc_20100530_234926.reg [2010.05.30 23:46:38 | 000,001,885 | ---- | C] () -- C:\Users\MrMijagi\Desktop\CCleaner.lnk [2010.05.30 19:18:50 | 000,001,293 | ---- | C] () -- C:\Users\Public\Desktop\Darkness Within 2.lnk [2010.05.30 19:04:24 | 000,834,544 | ---- | C] () -- C:\Windows\SysNative\drivers\sptd.sys [2010.05.30 19:04:24 | 000,001,950 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk [2010.05.30 17:09:38 | 000,001,258 | ---- | C] () -- C:\Users\MrMijagi\Desktop\Spybot - Search & Destroy.lnk [2010.05.30 17:02:42 | 000,001,009 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.05.30 16:49:32 | 000,001,201 | ---- | C] () -- C:\Users\MrMijagi\Desktop\cmd.lnk [2010.05.30 16:37:22 | 000,002,002 | ---- | C] () -- C:\Users\Public\Desktop\League of Legends.lnk [2010.05.30 16:11:32 | 000,000,999 | ---- | C] () -- C:\Users\MrMijagi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk [2010.05.30 16:11:32 | 000,000,963 | ---- | C] () -- C:\Users\Public\Desktop\Xfire.lnk [2010.05.30 16:08:44 | 000,524,288 | -HS- | C] () -- C:\Users\MrMijagi\ntuser.dat{d1b2c3a2-6bc9-11df-bf1c-001d92a1e339}.TMContainer00000000000000000002.regtrans-ms [2010.05.30 16:08:44 | 000,524,288 | -HS- | C] () -- C:\Users\MrMijagi\ntuser.dat{d1b2c3a2-6bc9-11df-bf1c-001d92a1e339}.TMContainer00000000000000000001.regtrans-ms [2010.05.30 16:08:44 | 000,065,536 | -HS- | C] () -- C:\Users\MrMijagi\ntuser.dat{d1b2c3a2-6bc9-11df-bf1c-001d92a1e339}.TM.blf [2010.05.29 20:29:43 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib [2010.05.29 19:45:26 | 000,236,583 | ---- | C] () -- C:\Users\MrMijagi\Documents\1275101086225.gif [2010.05.28 16:39:30 | 000,004,096 | ---- | C] () -- C:\Users\Public\Documents\0000124C.LCS [2010.05.28 16:30:23 | 000,004,096 | ---- | C] () -- C:\Users\Public\Documents\00000FE2.LCS [2010.05.28 14:06:22 | 000,001,072 | ---- | C] () -- C:\Users\Public\Desktop\Game Booster.lnk [2010.05.28 13:49:33 | 000,001,239 | ---- | C] () -- C:\Users\MrMijagi\Desktop\KicksOnline.lnk [2010.05.28 05:05:52 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK [2010.05.28 05:05:50 | 000,383,562 | RHS- | C] () -- C:\bootmgr [2010.05.28 04:09:08 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf [2010.05.28 04:07:01 | 1610,059,776 | -HS- | C] () -- C:\hiberfil.sys [2010.05.28 04:01:21 | 000,002,213 | ---- | C] () -- C:\Users\MrMijagi\Documents\df.lst [2010.05.28 03:59:42 | 002,359,350 | ---- | C] () -- C:\Windows\WPCWallpaper.bmp [2010.05.28 03:38:44 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2010.05.28 03:38:38 | 000,001,939 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2010.05.28 03:29:51 | 000,009,832 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb [2010.05.28 03:26:29 | 000,001,183 | ---- | C] () -- C:\Users\MrMijagi\Desktop\XKickOnline.lnk [2010.05.28 03:16:31 | 000,000,020 | -HS- | C] () -- C:\Users\MrMijagi\ntuser.ini [2010.05.28 03:16:30 | 001,048,576 | -HS- | C] () -- C:\Users\MrMijagi\ntuser.dat [2010.05.28 03:16:30 | 000,524,288 | -HS- | C] () -- C:\Users\MrMijagi\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2010.05.28 03:16:30 | 000,524,288 | -HS- | C] () -- C:\Users\MrMijagi\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2010.05.28 03:16:30 | 000,262,144 | -HS- | C] () -- C:\Users\MrMijagi\ntuser.dat.LOG1 [2010.05.28 03:16:30 | 000,065,536 | -HS- | C] () -- C:\Users\MrMijagi\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2010.05.28 03:16:30 | 000,000,000 | -HS- | C] () -- C:\Users\MrMijagi\ntuser.dat.LOG2 [2010.05.28 03:14:30 | 000,171,136 | RHS- | C] () -- C:\w7ldr [2010.05.11 20:32:38 | 000,041,872 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll [2010.05.11 20:32:38 | 000,027,536 | ---- | C] () -- C:\Windows\SysNative\xfcodec64.dll [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll ========== Alternate Data Streams ========== @Alternate Data Stream - 24 bytes -> C:\Windows:58CBEE991369A304 @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:010ADD2C < End of report > |
31.05.2010, 21:11 | #3 |
| Einige Internetseiten lassen sich nicht öffnen (web.de,msn.de...) Habe noch was vergessen!
__________________Habe mit Malwarebytes vor 2 Tagen eine infizierte Datei gefunden... Danke schonmal euch alle für eure Hilfe. Code:
ATTFilter Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4156 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 30.05.2010 17:23:41 mbam-log-2010-05-30 (17-23-41).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Durchsuchte Objekte: 224556 Laufzeit: 19 Minute(n), 42 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 1 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Users\MrMijagi\AppData\Local\Temp\STBRINST\CONTENT\Speedbit.dll (Adware.EcoBar) -> Quarantined and deleted successfully. |
Themen zu Einige Internetseiten lassen sich nicht öffnen (web.de,msn.de...) |
askbar, becker, befehl, betriebssystem, c:\windows\system32\rundll32.exe, cache, chip, cmd, dns, einstellungen, firefox.exe, gecheckt, gelöscht, guten, install.exe, inter, interne, interneteinstellungen, internetseite, internetseiten, ip-adresse, ipconfig, league of legends, location, malwarebytes' anti-malware, microsoft, msn, nicht öffnen, oldtimer, plug-in, richtlinie, saver, security suite, seite, seiten, shell32.dll, shortcut, systemwiederherstellung, syswow64, tagen, traces, web.de, windows, windows 7, öffnen |