Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Funny UST Scandal.avi.exe

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 31.05.2010, 10:18   #1
rafelder
 
Funny UST Scandal.avi.exe - Standard

Funny UST Scandal.avi.exe



Hallo zusammen,
ich hatte auf dem Computer einer Bekannten den o.g Virus (Win32:AutoRun_RW) gefunden. Nachdem ich ihn (hoffentlich) entfernt habe und nach den Vorgaben den CCleaner, MAM und RSIT benutzt habe, hier mal das letzte .log File
Ich hoffe dass jetzt alles sauber ist und bedanke mich schon mal im Voraus für eure Mühe.

RSIT Logfile:
Code:
ATTFilter
Logfile of random's system information tool 1.07 (written by random/random)
Run by *xxx* at 2010-05-31 11:06:31
Microsoft Windows XP Professional Service Pack 3
System drive C: has 192 GB (82%) free of 234 GB
Total RAM: 1022 MB (50% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:06:36, on 31.05.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Programme\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programme\Corel\Corel Photo Album 6\MediaDetect.exe
C:\WINDOWS\VM_STI.EXE
C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Programme\MioNet\MioNetManager.exe
C:\Programme\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\MioNet\jvm\bin\MioNet.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Programme\Brother\Brmfcmon\BrMfcmon.exe
C:\Programme\Philips\SPC 200NC PC Camera\TrayMin200.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Dokumente und Einstellungen\Monika\Desktop\Viren-Programme\RSIT.exe
C:\Programme\trend micro\Monika.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.web.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: Shell=explorer.exe, killer.exe
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Programme\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC 200NC PC Camera
O4 - HKLM\..\Run: [PPort11reminder] "C:\Programme\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
O4 - HKLM\..\Run: [BrMfcWnd] C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Programme\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [zzz_ImInstaller_IncrediMail] "C:\Dokumente und Einstellungen\Monika\Lokale Einstellungen\Temp\ImInstaller\IncrediMail\incredimail_install.exe" -startup  -product IncrediMail  
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [ Malwarebytes Anti-Malware  (reboot)] "C:\Programme\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: TrayMin300.exe.lnk = ?
O8 - Extra context menu item: Google Sidewiki... - res://C:\Programme\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programme\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Programme\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MioNet Service (MioNet) - Unknown owner - C:\Programme\MioNet\MioNetManager.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Programme\Intel\PROSetWired\NCS\Sync\NetSvc.exe

--
End of file - 7931 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\ISP-Anmeldungserinnerung 1.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
DriveLetterAccess - C:\WINDOWS\system32\dla\tfswshx.dll [2004-12-06 118842]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll [2010-05-29 278128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Programme\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll [2010-05-29 814648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll [2010-05-29 278128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-09-29 67584]
"SunJavaUpdateSched"=C:\Programme\Java\j2re1.4.2_03\bin\jusched.exe [2003-11-19 32881]
"SigmatelSysTrayApp"=C:\WINDOWS\stsystra.exe [2005-03-23 339968]
"ATIPTA"=C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-08-05 344064]
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe [2004-12-06 127035]
"Corel Photo Downloader"=C:\Programme\Corel\Corel Photo Album 6\MediaDetect.exe [2005-08-31 106496]
"BigDogPath"=C:\WINDOWS\VM_STI.EXE [2004-06-09 40960]
"PPort11reminder"=C:\Programme\ScanSoft\PaperPort\Ereg\Ereg.exe [2007-02-01 255528]
"BrMfcWnd"=C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe [2007-03-23 663552]
"ControlCenter3"=C:\Programme\Brother\ControlCenter3\brctrcen.exe [2007-01-26 65536]
"ArcSoft Connection Service"=C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe [2007-10-11 31232]
"zzz_ImInstaller_IncrediMail"=C:\Dokumente und Einstellungen\Monika\Lokale Einstellungen\Temp\ImInstaller\IncrediMail\incredimail_install.exe [2010-03-09 583272]
"NWEReboot"= []
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-05-06 2815192]
" Malwarebytes Anti-Malware  (reboot)"=C:\Programme\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe [2010-04-29 437584]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Skype"=C:\Programme\Skype\\Phone\Skype.exe [2010-05-13 26192168]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-05-11 40048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
C:\Programme\CyberLink\PowerDVD\DVDLauncher.exe [2005-02-23 53248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
C:\Programme\ICQLite\ICQLite.exe [2006-07-11 3144800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
C:\Programme\ScanSoft\PaperPort\IndexSearch.exe [2007-01-29 46632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\ISUSPM.exe [2005-06-10 249856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe [2005-06-10 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Programme\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
C:\Programme\ScanSoft\PaperPort\pptd40nt.exe [2007-01-29 30248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Runonce]
C:\WINDOWS\smss.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-17 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^dlbcserv.lnk]
C:\PROGRA~1\DELLPH~1\dlbcserv.exe  []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^PHOTOfunSTUDIO -viewer-.lnk]
C:\PROGRA~1\PANASO~1\PHOTOF~1\PHAUTO~1.EXE [2007-11-16 40960]

C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart
TrayMin300.exe.lnk - C:\Programme\Philips\SPC 200NC PC Camera\TrayMin200.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=
scecli
scecli

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Programme\Messenger\msmsgs.exe"="C:\Programme\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\WINDOWS\system32\fxsclnt.exe"="C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft  Fax Console"
"C:\Dokumente und Einstellungen\Monika\Lokale Einstellungen\Temp\ImInstaller\incredimail_installer.exe"="C:\Dokumente und Einstellungen\Monika\Lokale Einstellungen\Temp\ImInstaller\incredimail_installer.exe:*:Enabled:IncrediMail Installer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Programme\Skype\Plugin Manager\skypePM.exe"="C:\Programme\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Programme\Skype\Phone\Skype.exe"="C:\Programme\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{81231810-2b90-11df-9681-00123fb918b7}]
shell\Autoplay\command - K:\smss.exe
shell\AutoRun\command - K:\smss.exe
shell\Explore\command - K:\smss.exe
shell\Open\command - K:\smss.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97efed4c-e560-11dd-95dc-00123fb918b7}]
shell\Autoplay\command - J:\smss.exe
shell\AutoRun\command - J:\smss.exe
shell\Explore\command - J:\smss.exe
shell\Open\command - J:\smss.exe


======File associations======

.reg - edit - 
.reg - open - "%1" %*
.vbs - edit - 
.vbs - open - "%1" %*

======List of files/folders created in the last 1 months======

2010-05-31 10:31:23 ----D---- C:\rsit
2010-05-31 10:14:46 ----D---- C:\Programme\CCleaner
2010-05-31 09:44:58 ----D---- C:\Dokumente und Einstellungen\Monika\Anwendungsdaten\Malwarebytes
2010-05-31 09:44:44 ----D---- C:\Programme\Malwarebytes' Anti-Malware
2010-05-31 09:44:44 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
2010-05-30 13:30:28 ----D---- C:\Dokumente und Einstellungen\Monika\Anwendungsdaten\Ashampoo
2010-05-30 13:24:58 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ashampoo
2010-05-30 13:24:42 ----D---- C:\Programme\Ashampoo
2010-05-30 12:22:57 ----D---- C:\WINDOWS\system32\en-US
2010-05-30 12:22:46 ----D---- C:\Programme\Microsoft.NET
2010-05-30 12:22:35 ----SHD---- C:\Config.Msi
2010-05-30 11:25:42 ----D---- C:\Dokumente und Einstellungen\Monika\Anwendungsdaten\XnView
2010-05-30 11:25:28 ----D---- C:\Programme\XnView
2010-05-30 00:18:30 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-05-30 00:18:18 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-05-30 00:10:41 ----D---- C:\Dokumente und Einstellungen\Monika\Anwendungsdaten\ArcSoft
2010-05-30 00:01:17 ----D---- C:\WINDOWS\pss
2010-05-29 23:55:15 ----D---- C:\Programme\RegCleaner
2010-05-29 23:54:11 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Windows Genuine Advantage
2010-05-29 23:52:50 ----D---- C:\Programme\Trend Micro
2010-05-29 23:39:37 ----D---- C:\WINDOWS\system32\appmgmt
2010-05-29 23:32:26 ----D---- C:\Dokumente und Einstellungen\Monika\Anwendungsdaten\skypePM
2010-05-29 23:31:43 ----D---- C:\Programme\Gemeinsame Dateien\Skype
2010-05-29 23:31:34 ----RD---- C:\Programme\Skype
2010-05-29 23:31:04 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype
2010-05-29 22:45:06 ----D---- C:\WINDOWS\Prefetch
2010-05-29 22:42:24 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-05-29 22:42:11 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-05-29 22:42:00 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-05-29 22:41:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-05-29 22:41:40 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-05-29 22:41:31 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-05-29 22:41:21 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-05-29 22:41:10 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-05-29 22:40:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-05-29 22:40:46 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-05-29 22:40:33 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-05-29 22:40:16 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-05-29 22:40:06 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-05-29 22:39:56 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-05-29 22:39:46 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-05-29 22:39:34 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-05-29 22:39:24 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-05-29 22:39:12 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-05-29 22:39:01 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-05-29 22:38:50 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-05-29 22:38:37 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-05-29 22:38:25 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-05-29 22:38:13 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-05-29 22:38:01 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-05-29 22:37:48 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-05-29 22:37:35 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-05-29 22:37:22 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-05-29 22:37:12 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-05-29 22:37:02 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2010-05-29 22:36:51 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2010-05-29 22:36:40 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2010-05-29 22:36:29 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-05-29 22:36:19 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-05-29 22:36:09 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-05-29 22:35:59 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-05-29 22:35:47 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-05-29 22:35:36 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2010-05-29 22:35:25 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-05-29 22:35:12 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-05-29 22:35:01 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-05-29 22:34:51 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2010-05-29 22:34:41 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$
2010-05-29 22:34:32 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-05-29 22:34:22 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-05-29 22:34:09 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-05-29 22:33:59 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-05-29 22:33:48 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2010-05-29 22:33:39 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2010-05-29 22:33:28 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-05-29 22:33:16 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2010-05-29 22:33:06 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2010-05-29 22:32:57 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-05-29 22:32:48 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2010-05-29 22:32:37 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-05-29 22:32:27 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-05-29 22:32:13 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-05-29 22:31:56 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-05-29 22:31:46 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2010-05-29 22:31:36 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-05-29 22:31:25 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_1$
2010-05-29 22:31:15 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2010-05-29 22:31:05 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2010-05-29 22:30:53 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-05-29 22:30:43 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-05-29 22:30:32 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-05-29 22:30:21 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-05-29 22:30:12 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2010-05-29 22:30:01 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-05-29 22:29:50 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-05-29 22:29:40 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-05-29 22:29:30 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-05-29 22:29:17 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-05-29 22:29:08 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2010-05-29 22:28:55 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-05-29 22:15:00 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-05-29 21:21:47 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-05-29 21:21:40 ----D---- C:\Programme\Alwil Software
2010-05-29 21:21:40 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Alwil Software
2010-05-29 20:47:38 ----D---- C:\log
2010-05-29 20:19:19 ----D---- C:\!KillBox
2010-05-29 19:40:34 ----D---- C:\Programme\Panda Security
2010-05-29 19:25:37 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SecTaskMan
2010-05-29 19:25:33 ----D---- C:\Programme\Security Task Manager
2010-05-29 17:44:54 ----D---- C:\WINDOWS\system32\de
2010-05-29 17:44:54 ----D---- C:\WINDOWS\system32\bits
2010-05-29 17:44:54 ----D---- C:\WINDOWS\l2schemas
2010-05-29 17:41:06 ----D---- C:\WINDOWS\network diagnostic
2010-05-29 17:38:35 ----A---- C:\WINDOWS\system32\qmgr.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\samsrv.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\samlib.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\rshx32.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\rastapi.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\rasman.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\rasdlg.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\rasauto.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\rasapi32.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\printui.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\perfctrs.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\olecnv32.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\oleaut32.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\nwprovau.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\ntvdm.exe
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\ntprint.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\ntlsapi.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\ntdll.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\nslookup.exe
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\msv1_0.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\msgsvc.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\mgmtapi.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\lsasrv.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\locator.exe
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\localspl.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\lmhsvc.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\kernel32.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\imagehlp.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\ftp.exe
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\format.com
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\dhcpcsvc.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\csrsrv.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\comdlg32.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\comctl32.dll
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\cmd.exe
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\cacls.exe
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\autoconv.exe
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\autochk.exe
2010-05-29 17:38:01 ----A---- C:\WINDOWS\system32\advapi32.dll
2010-05-29 17:38:00 ----A---- C:\WINDOWS\system32\setupapi.dll
2010-05-29 17:38:00 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-05-29 17:38:00 ----A---- C:\WINDOWS\system32\services.exe
2010-05-29 17:38:00 ----A---- C:\WINDOWS\system32\schannel.dll
2010-05-29 17:38:00 ----A---- C:\WINDOWS\system32\scardsvr.exe
2010-05-29 17:38:00 ----A---- C:\WINDOWS\system32\savedump.exe
2010-05-29 17:37:59 ----A---- C:\WINDOWS\system32\wkssvc.dll
2010-05-29 17:37:59 ----A---- C:\WINDOWS\system32\win32spl.dll
2010-05-29 17:37:59 ----A---- C:\WINDOWS\system32\userinit.exe
2010-05-29 17:37:59 ----A---- C:\WINDOWS\system32\untfs.dll
2010-05-29 17:37:59 ----A---- C:\WINDOWS\system32\ulib.dll
2010-05-29 17:37:59 ----A---- C:\WINDOWS\system32\tcpmonui.dll
2010-05-29 17:37:59 ----A---- C:\WINDOWS\system32\syssetup.dll
2010-05-29 17:37:59 ----A---- C:\WINDOWS\system32\srvsvc.dll
2010-05-29 17:37:59 ----A---- C:\WINDOWS\system32\smss.exe
2010-05-29 17:37:58 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2010-05-29 17:37:58 ----A---- C:\WINDOWS\system32\ntkrnlpa.exe
2010-05-29 17:37:58 ----A---- C:\WINDOWS\system32\HAL.DLL
2010-05-29 17:31:50 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-05-29 17:31:44 ----HDC---- C:\WINDOWS\$NtUninstallKB978542_0$

======List of files/folders modified in the last 1 months======

2010-05-31 10:34:22 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-31 10:24:36 ----D---- C:\WINDOWS\Debug
2010-05-31 10:24:36 ----D---- C:\WINDOWS
2010-05-31 10:24:35 ----D---- C:\WINDOWS\Temp
2010-05-31 10:24:35 ----D---- C:\WINDOWS\Minidump
2010-05-31 10:14:46 ----RD---- C:\Programme
2010-05-31 09:44:46 ----D---- C:\WINDOWS\system32\drivers
2010-05-31 08:55:13 ----D---- C:\Dokumente und Einstellungen\Monika\Anwendungsdaten\Skype
2010-05-31 08:51:08 ----D---- C:\WINDOWS\Registration
2010-05-30 16:55:45 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-05-30 13:16:10 ----RSD---- C:\WINDOWS\assembly
2010-05-30 13:16:10 ----D---- C:\WINDOWS\Microsoft.NET
2010-05-30 12:29:38 ----SHD---- C:\WINDOWS\Installer
2010-05-30 12:29:37 ----D---- C:\WINDOWS\system32
2010-05-30 12:29:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-05-30 12:28:52 ----D---- C:\WINDOWS\system32\de-DE
2010-05-30 12:27:50 ----D---- C:\WINDOWS\WinSxS
2010-05-30 00:29:30 ----RASH---- C:\boot.ini
2010-05-30 00:29:30 ----A---- C:\WINDOWS\win.ini
2010-05-30 00:29:30 ----A---- C:\WINDOWS\system.ini
2010-05-30 00:18:36 ----HD---- C:\WINDOWS\inf
2010-05-30 00:18:34 ----RSHD---- C:\WINDOWS\system32\dllcache
2010-05-30 00:17:41 ----HD---- C:\WINDOWS\$hf_mig$
2010-05-30 00:17:41 ----D---- C:\WINDOWS\system32\CatRoot
2010-05-30 00:04:19 ----D---- C:\Programme\MioNet
2010-05-29 23:31:43 ----D---- C:\Programme\Gemeinsame Dateien
2010-05-29 22:44:14 ----D---- C:\WINDOWS\system32\Setup
2010-05-29 22:44:14 ----D---- C:\WINDOWS\AppPatch
2010-05-29 22:44:14 ----D---- C:\Programme\Messenger
2010-05-29 22:44:13 ----D---- C:\WINDOWS\system32\wbem
2010-05-29 22:44:13 ----D---- C:\Programme\Gemeinsame Dateien\System
2010-05-29 22:44:12 ----RSD---- C:\WINDOWS\Fonts
2010-05-29 22:41:32 ----D---- C:\Programme\Outlook Express
2010-05-29 22:40:08 ----D---- C:\Programme\Movie Maker
2010-05-29 22:34:36 ----D---- C:\WINDOWS\security
2010-05-29 22:24:32 ----D---- C:\WINDOWS\system32\inetsrv
2010-05-29 22:24:31 ----D---- C:\WINDOWS\ime
2010-05-29 22:24:31 ----D---- C:\WINDOWS\Help
2010-05-29 22:24:15 ----D---- C:\WINDOWS\system32\usmt
2010-05-29 22:24:14 ----D---- C:\Programme\Internet Explorer
2010-05-29 22:24:13 ----D---- C:\WINDOWS\PeerNet
2010-05-29 22:21:41 ----D---- C:\WINDOWS\ServicePackFiles
2010-05-29 22:21:31 ----D---- C:\WINDOWS\system32\Restore
2010-05-29 22:21:31 ----D---- C:\WINDOWS\system32\npp
2010-05-29 22:21:30 ----D---- C:\WINDOWS\msagent
2010-05-29 22:21:28 ----D---- C:\WINDOWS\srchasst
2010-05-29 22:21:28 ----D---- C:\Programme\NetMeeting
2010-05-29 22:21:27 ----D---- C:\WINDOWS\system32\Com
2010-05-29 22:21:24 ----D---- C:\Programme\Windows NT
2010-05-29 22:21:06 ----D---- C:\WINDOWS\system32\oobe
2010-05-29 22:21:04 ----D---- C:\WINDOWS\system
2010-05-29 22:18:09 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-05-29 22:14:57 ----D---- C:\WINDOWS\ehome
2010-05-29 22:05:26 ----A---- C:\WINDOWS\NeroDigital.ini
2010-05-29 21:21:53 ----D---- C:\Programme\Gemeinsame Dateien\Microsoft Shared
2010-05-29 18:10:18 ----D---- C:\Temp
2010-05-29 17:48:10 ----SD---- C:\WINDOWS\Tasks
2010-05-29 17:30:51 ----D---- C:\Programme\Mozilla Firefox
2010-05-29 17:28:13 ----D---- C:\WINDOWS\system32\FxsTmp
2010-05-15 18:46:17 ----D---- C:\WINDOWS\SoftwareDistribution

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-05-06 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-05-06 164048]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-05-06 46672]
R1 intelppm;Intel-Prozessortreiber; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40448]
R1 kbdhid;Tastatur-HID-Treiber; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
R1 sscdbhk5;sscdbhk5; C:\WINDOWS\system32\drivers\sscdbhk5.sys [2004-07-14 5627]
R1 ssrtln;ssrtln; C:\WINDOWS\system32\drivers\ssrtln.sys [2004-07-14 23545]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-05-06 19024]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-05-06 100432]
R2 drvnddm;drvnddm; C:\WINDOWS\system32\drivers\drvnddm.sys [2004-11-23 40480]
R2 tfsnboio;tfsnboio; C:\WINDOWS\system32\dla\tfsnboio.sys [2004-12-06 25883]
R2 tfsncofs;tfsncofs; C:\WINDOWS\system32\dla\tfsncofs.sys [2004-12-06 34843]
R2 tfsndrct;tfsndrct; C:\WINDOWS\system32\dla\tfsndrct.sys [2004-12-06 4123]
R2 tfsndres;tfsndres; C:\WINDOWS\system32\dla\tfsndres.sys [2004-12-06 2271]
R2 tfsnifs;tfsnifs; C:\WINDOWS\system32\dla\tfsnifs.sys [2004-12-06 86586]
R2 tfsnopio;tfsnopio; C:\WINDOWS\system32\dla\tfsnopio.sys [2004-12-06 15227]
R2 tfsnpool;tfsnpool; C:\WINDOWS\system32\dla\tfsnpool.sys [2004-12-06 6363]
R2 tfsnudf;tfsnudf; C:\WINDOWS\system32\dla\tfsnudf.sys [2004-12-06 98714]
R2 tfsnudfa;tfsnudfa; C:\WINDOWS\system32\dla\tfsnudfa.sys [2004-12-06 100603]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-05-06 23376]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-08-04 1273344]
R3 E100B;Intel(R) PRO Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2004-10-14 155648]
R3 HDAudBus;Microsoft UAA-Bustreiber für High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class-Treiber; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Maus-HID-Treiber; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-18 12288]
R3 STHDA;High Definition Audio Driver (WDM) - SigmaTel CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2005-06-15 180864]
R3 usbccgp;Microsoft Standard-USB-Haupttreiber; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB-Standardhubtreiber; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;USB-Massenspeichertreiber; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Miniporttreiber für universellen Microsoft USB-Hostcontroller; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 BrScnUsb;Brother USB Still Image driver; C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 15295]
S3 BrSerIf;Brother MFC Serial Port Interface WDM Driver; C:\WINDOWS\System32\Drivers\BrSerIf.sys [2006-12-12 52224]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver; C:\WINDOWS\System32\Drivers\BrUsbSer.sys [2006-09-03 11904]
S3 CCDECODE;Untertiteldecoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 MHNDRV;MHN-Treiber; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI-Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV-/Videoverbindung; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA-IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Microsoft USB-Druckerklasse; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 WSTCODEC;World Standard Teletext-Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 ZSMC301b;Philips SPC 200NC PC Camera; C:\WINDOWS\System32\Drivers\usbVM31b.sys [2005-02-26 91527]
S4 agp440;Intel AGP-Bus-Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
S4 agpCPQ;Compaq AGP-Bus-Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;ALI AGP-Bus-Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;AMD AGP-Bus-Filtertreiber; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-14 5504]
S4 sisagp;SIS AGP-Bus-Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 viaagp;VIA AGP-Bus-Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe [2007-10-11 51712]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-08-04 380928]
R2 avast! Antivirus;avast! Antivirus; C:\Programme\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2005-10-11 237568]
R2 ehSched;Media Center-Planerdienst; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 LexBceS;LexBce Server; C:\WINDOWS\system32\LEXBCES.EXE [2004-03-05 311296]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 MioNet;MioNet Service; C:\Programme\MioNet\MioNetManager.exe [2005-07-15 139264]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Programme\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Programme\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268800]
S2 gupdate;Google Update Service (gupdate); C:\Programme\Google\Update\GoogleUpdate.exe [2010-02-19 135664]
S3 aspnet_state;ASP.NET-Zustandsdienst; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 gusvc;Google Software Updater; C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-30 182768]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 NetSvc;Intel NCS NetService; C:\Programme\Intel\PROSetWired\NCS\Sync\NetSvc.exe [2004-11-19 147456]
S3 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-08-04 38912]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------
         
--- --- ---

 

Themen zu Funny UST Scandal.avi.exe
adobe, antivirus, autorun, avast!, bho, browser, browseui preloader, computer, desktop, downloader, einstellungen, firefox, google, gupdate, hijack, hijackthis, hkus\s-1-5-18, iminstaller, install.exe, internet, internet explorer, logfile, malwarebytes' anti-malware, media center, monitor, mozilla, notification, nt.exe, registry, server, skype.exe, software, studio, system, virus, windows, windows xp




Zum Thema Funny UST Scandal.avi.exe - Hallo zusammen, ich hatte auf dem Computer einer Bekannten den o.g Virus (Win32:AutoRun_RW) gefunden. Nachdem ich ihn (hoffentlich) entfernt habe und nach den Vorgaben den CCleaner, MAM und RSIT benutzt - Funny UST Scandal.avi.exe...
Archiv
Du betrachtest: Funny UST Scandal.avi.exe auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.