|
Plagegeister aller Art und deren Bekämpfung: 'C:\Users\***\AppData\Roaming\install\svchost.exe'Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
07.06.2010, 18:57 | #1 |
| 'C:\Users\***\AppData\Roaming\install\svchost.exe' Hallo alle miteinander! Habe eben meinen PC (Windows 7 64bit) gestartet und mein Avira Antivir Personal hat mir sofort Maleware gemeldet! Ich habe wirklich keine Ahnung wo ich ihn mir eingefangen haben könnte! Hier der Bericht von Avira: Code:
ATTFilter Die Datei 'C:\Users\***\AppData\Roaming\install\svchost.exe' enthielt einen Virus oder unerwünschtes Programm 'TR/Dropper.Gen' [trojan]. Durchgeführte Aktion(en): Der Registrierungseintrag <HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\HKCU> konnte nicht entfernt werden. Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4965bd58.qua' verschoben! Ebenfalls habe ich natürlich auch eine HijackThis Log erstellt: HiJackthis Logfile: Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:32:59, on 07.06.2010 Platform: Unknown Windows (WinNT 6.01.3504) MSIE: Internet Explorer v8.00 (8.00.7600.16385) Boot mode: Normal Running processes: C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\VMware\VMware Player\hqtray.exe C:\Windows\SysWOW64\explorer.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\ICQ7.1\ICQ.exe C:\Users\XXX\Downloads\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll R3 - URLSearchHook: (no name) - - (no file) F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files (x86)\VMware\VMware Player\hqtray.exe" O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKCU\..\Run: [0x017] 0x017 O4 - HKCU\..\Run: [systemupdate.exe] C:\windows\systemupdate.exe O4 - HKCU\..\Run: [updat.exe] C:\windows\updat.exe O4 - HKCU\..\Run: [HKCU] C:\Users\XXX\AppData\Roaming\install\svchost.exe O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware player\vsocklib.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware player\vsocklib.dll O13 - Gopher Prefix: O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: JMB36X - Unknown owner - C:\Windows\SysWOW64\XSrvSetup.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NMSAccess - Unknown owner - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: @C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-ufad.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 9762 bytes Dabei denke ich, dass gerade dieser Eintrag von nutzen ist: Code:
ATTFilter O4 - HKCU\..\Run: [HKCU] C:\Users\XXX\AppData\Roaming\install\svchost.exe Liebsten Gruß Sc4v //EDIT Wahrscheinlich sicher erwähnenswert: Die .exe lässt sich von Hand löschen und auch mit TuneUp shreddern aber 3 Sekunden später taucht sie wieder auf! |
07.06.2010, 22:15 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | 'C:\Users\***\AppData\Roaming\install\svchost.exe' Hallo und
__________________bitte nen Vollscan mit Malwarebytes machen und Log posten. Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________ |
08.06.2010, 18:45 | #3 |
| 'C:\Users\***\AppData\Roaming\install\svchost.exe' hi,
__________________danke fürs Willkommenheißen. Ich habe bereits mit Eigeninitiative Malewarebytes Quickscan ausgeführt und somit 6 Viren gekillt (Namen wie zB xXx.XxX, Updat.exe und auch die svchost.exe) --> Neustart und erneuter Scan mit Avira und Malewarebytes brachte keine weiteren Funde oder Warnungen. Dennoch ich poste gleich die Log von Malewarebytes nachdem sie durch ist und die von OTL. Lg und vielen dank schonmal Sc4v PS: Ich hoffe ich habe eine Chance virenfrei zu sein //EDIT hier die alten logs schonmal von malewarebytes (war aber ein schnelldurchlauf) Code:
ATTFilter Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4176 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 07.06.2010 20:58:31 mbam-log-2010-06-07 (20-58-31).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 129965 Laufzeit: 3 Minute(n), 47 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 4 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hkcu (Trojan.Agent) -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Users\Sc4v\AppData\Roaming\logs.dat (Bifrose.Trace) -> Quarantined and deleted successfully. C:\Users\Sc4v\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Quarantined and deleted successfully. C:\Users\Sc4v\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Quarantined and deleted successfully. C:\Users\Sc4v\AppData\Roaming\install\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully. Code:
ATTFilter Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4176 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 07.06.2010 21:23:27 mbam-log-2010-06-07 (21-23-27).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 129237 Laufzeit: 2 Minute(n), 18 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Die anderen gewünschten folgen! Geändert von Sc4v (08.06.2010 um 19:04 Uhr) |
08.06.2010, 19:29 | #4 |
| 'C:\Users\***\AppData\Roaming\install\svchost.exe' Extras.txt Code:
ATTFilter OTL EXTRAS Logfile: |
08.06.2010, 19:31 | #5 |
| 'C:\Users\***\AppData\Roaming\install\svchost.exe' Erstmal sorry für den Tipplepost!!!! Ich weiß ich weiß ich bin Mein Problem war einfach, der Post wäre länger als 75000 Zeichen, deswegen musste(!!!) ich ihn spalten. Gestrige Malewarebytes Log siehe vorletzter Post. Heutiger vollständiger Malewarebytes Log Code:
ATTFilter Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4176 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 08.06.2010 20:15:33 mbam-log-2010-06-08 (20-15-33).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 329511 Laufzeit: 27 Minute(n), 53 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) OTL.txt OTL Logfile: Code:
ATTFilter OTL logfile created on: 08.06.2010 20:17:37 - Run 1 OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\Sc4v\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 6,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 57,00% Memory free 12,00 Gb Paging File | 9,00 Gb Available in Paging File | 77,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 78,03 Gb Total Space | 45,56 Gb Free Space | 58,39% Space Free | Partition Type: NTFS Drive D: | 387,64 Gb Total Space | 109,55 Gb Free Space | 28,26% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: SC4V-PC Current User Name: Sc4v Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis) PRC - C:\Users\Sc4v\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Program Files (x86)\ICQ7.1\ICQ.exe (ICQ, LLC.) PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe () PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation) PRC - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) PRC - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.) PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.) PRC - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe (VMware, Inc.) PRC - C:\Windows\SysWOW64\XSrvSetup.exe () PRC - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.) PRC - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.) PRC - C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (Microsoft Corporation) ========== Modules (SafeList) ========== MOD - C:\Users\Sc4v\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation) MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.) SRV:64bit: - (SbieSvc) -- C:\Program Files\Sandboxie\SbieSvc.exe (tzuk) SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD) SRV:64bit: - (UxTuneUp) -- C:\Windows\SysNative\uxtuneup.dll (TuneUp Software) SRV:64bit: - (WwanSvc) -- C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation) SRV:64bit: - (WbioSrvc) -- C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation) SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation) SRV:64bit: - (Power) -- C:\Windows\SysNative\umpo.dll (Microsoft Corporation) SRV:64bit: - (Themes) -- C:\Windows\SysNative\themeservice.dll (Microsoft Corporation) SRV:64bit: - (sppuinotify) -- C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation) SRV:64bit: - (SensrSvc) -- C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation) SRV:64bit: - (PeerDistSvc) -- C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation) SRV:64bit: - (PNRPsvc) -- C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation) SRV:64bit: - (p2pimsvc) -- C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation) SRV:64bit: - (HomeGroupProvider) -- C:\Windows\SysNative\provsvc.dll (Microsoft Corporation) SRV:64bit: - (RpcEptMapper) -- C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation) SRV:64bit: - (PNRPAutoReg) -- C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation) SRV:64bit: - (HomeGroupListener) -- C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation) SRV:64bit: - (FontCache) -- C:\Windows\SysNative\FntCache.dll (Microsoft Corporation) SRV:64bit: - (Dhcp) -- C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation) SRV:64bit: - (defragsvc) -- C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation) SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation) SRV:64bit: - (bthserv) -- C:\Windows\SysNative\bthserv.dll (Microsoft Corporation) SRV:64bit: - (BDESVC) -- C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation) SRV:64bit: - (AxInstSV) -- C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation) SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SRV:64bit: - (AppIDSvc) -- C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation) SRV:64bit: - (wbengine) -- C:\Windows\SysNative\wbengine.exe (Microsoft Corporation) SRV:64bit: - (sppsvc) -- C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation) SRV:64bit: - (Fax) -- C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation) SRV:64bit: - (msvsmon90) -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe (Microsoft Corporation) SRV - (afcdpsrv) -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis) SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.) SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (TuneUp.Defrag) -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe (TuneUp Software) SRV - (aspnet_state) -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe (Microsoft Corporation) SRV - (clr_optimization_v4.0.30319_64) -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (NMSAccess) -- C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe () SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe (TuneUp Software) SRV - (UxTuneUp) -- C:\Windows\SysWOW64\uxtuneup.dll (TuneUp Software) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (AcrSch2Svc) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis) SRV - (VMnetDHCP) -- C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.) SRV - (VMware NAT Service) -- C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.) SRV - (VMAuthdService) -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe (VMware, Inc.) SRV - (JMB36X) -- C:\Windows\SysWOW64\XSrvSetup.exe () SRV - (BCUService) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.) SRV - (VSS) -- C:\Windows\Vss [2009.07.14 05:20:14 | 000,000,000 | ---D | M] SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2009.07.14 05:20:14 | 000,000,000 | ---D | M] SRV - (HomeGroupProvider) -- C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation) SRV - (Dhcp) -- C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation) SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof () SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (ufad-ws60) -- C:\Program Files (x86)\VMware\VMware Player\vmware-ufad.exe (VMware, Inc.) SRV - (Microsoft Office Groove Audit Service) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation) SRV - (MSSQL$SONY_MEDIAMGR) -- C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (Microsoft Corporation) SRV - (SQLAgent$SONY_MEDIAMGR) -- C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (Microsoft Corporation) SRV - (MSSQLServerADHelper) -- C:\Program Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (afcdp) -- C:\Windows\SysNative\drivers\afcdp.sys (Acronis) DRV:64bit: - (tdrpman251) Acronis Try&Decide and Restore Points filter (build 251) -- C:\Windows\SysNative\drivers\tdrpm251.sys (Acronis) DRV:64bit: - (timounter) -- C:\Windows\SysNative\drivers\timntr.sys (Acronis) DRV:64bit: - (snapman) -- C:\Windows\SysNative\drivers\snapman.sys (Acronis) DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys () DRV:64bit: - (pwdrvio) -- C:\Windows\SysNative\pwdrvio.sys () DRV:64bit: - (pwdspio) -- C:\Windows\SysNative\pwdspio.sys () DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atipmdag.sys (ATI Technologies Inc.) DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.) DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH) DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.) DRV:64bit: - (StarOpen) -- C:\Windows\SysNative\drivers\StarOpen.sys () DRV:64bit: - (JRAID) -- C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.) DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation) DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation) DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek ) DRV:64bit: - (vmx86) -- C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.) DRV:64bit: - (hcmon) -- C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.) DRV:64bit: - (VMnetuserif) -- C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.) DRV:64bit: - (vmci) -- C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.) DRV:64bit: - (vmkbd) -- C:\Windows\SysNative\drivers\VMkbd.sys (VMware, Inc.) DRV:64bit: - (VMnetBridge) -- C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.) DRV:64bit: - (VMnetAdapter) -- C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (KSecPkg) -- C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (hwpolicy) -- C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation) DRV:64bit: - (FsDepends) -- C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (WIMMount) -- C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation) DRV:64bit: - (vhdmp) -- C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation) DRV:64bit: - (vmbus) -- C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation) DRV:64bit: - (storflt) -- C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation) DRV:64bit: - (vdrvroot) -- C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation) DRV:64bit: - (storvsc) -- C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (rdyboost) -- C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation) DRV:64bit: - (pcw) -- C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation) DRV:64bit: - (CNG) -- C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation) DRV:64bit: - (fvevol) -- C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation) DRV:64bit: - (rdpbus) -- C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation) DRV:64bit: - (RDPREFMP) -- C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation) DRV:64bit: - (RasAgileVpn) WAN Miniport (IKEv2) -- C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation) DRV:64bit: - (WfpLwf) -- C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation) DRV:64bit: - (NdisCap) -- C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation) DRV:64bit: - (vwifibus) -- C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation) DRV:64bit: - (1394ohci) -- C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation) DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation) DRV:64bit: - (UmPass) -- C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation) DRV:64bit: - (mshidkmdf) -- C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation) DRV:64bit: - (WudfPf) -- C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation) DRV:64bit: - (MTConfig) -- C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation) DRV:64bit: - (CompositeBus) -- C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation) DRV:64bit: - (Beep) -- C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation) DRV:64bit: - (AppID) -- C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation) DRV:64bit: - (scfilter) -- C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation) DRV:64bit: - (s3cap) -- C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation) DRV:64bit: - (VMBusHID) -- C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation) DRV:64bit: - (discache) -- C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation) DRV:64bit: - (HidBatt) -- C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation) DRV:64bit: - (CmBatt) -- C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation) DRV:64bit: - (AcpiPmi) -- C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation) DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation) DRV:64bit: - (AmdPPM) -- C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (adfs) -- C:\Windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.) DRV - (CSC) -- C:\Windows\CSC [2010.04.17 23:07:32 | 000,000,000 | ---D | M] DRV - (SbieDrv) -- C:\Programme\Sandboxie\SbieDrv.sys (tzuk) DRV - (TuneUpUtilitiesDrv) -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys (TuneUp Software) DRV - (StarOpen) -- C:\Windows\SysWOW64\drivers\StarOpen.sys () DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) DRV - (NetBIOS) -- C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation) DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof () DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof () DRV - (vstor2-ws60) -- C:\Program Files (x86)\VMware\VMware Player\vstor2-ws60.sys (VMware, Inc.) DRV - (adfs) -- C:\Windows\SysWOW64\drivers\adfs.sys (Adobe Systems, Inc.) DRV - (prohlp02) -- C:\Windows\System32\drivers\prohlp02.sys (Protection Technology) DRV - (prodrv06) -- C:\Windows\System32\drivers\prodrv06.sys (Protection Technology) DRV - (prosync1) -- C:\Windows\System32\drivers\prosync1.sys (Protection Technology) DRV - (sfhlp01) -- C:\Windows\System32\drivers\sfhlp01.sys (Protection Technology) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 47 E2 1D CC 51 DE CA 01 [binary data] IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.3 FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.04.19 21:16:57 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.05.31 16:09:40 | 000,000,000 | ---D | M] [2010.04.19 13:20:44 | 000,000,000 | ---D | M] -- C:\Users\Sc4v\AppData\Roaming\mozilla\Extensions [2010.06.08 17:55:33 | 000,000,000 | ---D | M] -- C:\Users\Sc4v\AppData\Roaming\mozilla\Firefox\Profiles\pc3ak93u.default\extensions [2010.05.03 19:02:21 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Sc4v\AppData\Roaming\mozilla\Firefox\Profiles\pc3ak93u.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010.05.02 16:38:52 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Sc4v\AppData\Roaming\mozilla\Firefox\Profiles\pc3ak93u.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010.05.31 15:24:09 | 000,002,004 | ---- | M] () -- C:\Users\Sc4v\AppData\Roaming\Mozilla\FireFox\Profiles\pc3ak93u.default\searchplugins\3dlam-suche.xml [2010.04.19 13:20:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2006.06.16 11:16:04 | 000,205,312 | ---- | M] (NETDIMENSION CORPORATION) -- C:\Program Files (x86)\mozilla firefox\plugins\NPMXENG.DLL [2010.04.01 18:54:38 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.04.01 18:54:38 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.04.01 18:54:38 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.04.01 18:54:38 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.04.01 18:54:38 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL (Microsoft Corporation) O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.) O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe () O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (tzuk) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL (Microsoft Corporation) O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation) O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{7814bd86-4bab-11df-8ea0-6cf049e02be8}\Shell - "" = AutoRun O33 - MountPoints2\{7814bd86-4bab-11df-8ea0-6cf049e02be8}\Shell\AutoRun\command - "" = J:\AutoRunCD.exe -- File not found O33 - MountPoints2\{c90f24ed-4bb9-11df-94c6-6cf049e02be8}\Shell - "" = AutoRun O33 - MountPoints2\{c90f24ed-4bb9-11df-94c6-6cf049e02be8}\Shell\AutoRun\command - "" = H:\setup.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (auto_reactivate \\?\Volume{2f4aee2a-4a65-11df-95fd-806e6f6e6963}\bootwiz\asrm.bin) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.06.08 20:16:43 | 000,571,904 | ---- | C] (OldTimer Tools) -- C:\Users\Sc4v\Desktop\OTL.exe [2010.06.07 22:07:43 | 002,717,096 | ---- | C] (Acronis) -- C:\Windows\SysNative\auto_reactivate.exe [2010.06.07 22:07:35 | 000,000,000 | RHSD | C] -- C:\bootwiz [2010.06.07 21:46:39 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\AppData\Roaming\Acronis [2010.06.07 21:46:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Acronis [2010.06.07 21:44:33 | 000,250,400 | ---- | C] (Acronis) -- C:\Windows\SysNative\drivers\afcdp.sys [2010.06.07 21:44:32 | 001,455,648 | ---- | C] (Acronis) -- C:\Windows\SysNative\drivers\tdrpm251.sys [2010.06.07 21:44:31 | 000,929,312 | ---- | C] (Acronis) -- C:\Windows\SysNative\drivers\timntr.sys [2010.06.07 21:44:26 | 000,254,496 | ---- | C] (Acronis) -- C:\Windows\SysNative\drivers\snapman.sys [2010.06.07 21:44:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Acronis [2010.06.07 21:44:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Acronis [2010.06.07 20:49:00 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\AppData\Roaming\Malwarebytes [2010.06.07 20:48:52 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010.06.07 20:48:51 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2010.06.07 20:48:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010.06.07 20:48:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.06.07 20:00:06 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\Desktop\Neuer Ordner [2010.05.31 19:57:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Project64 1.6 [2010.05.31 16:14:05 | 000,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3drm.dll [2010.05.31 16:09:41 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\AppData\Roaming\install [2010.05.31 16:09:40 | 000,000,000 | ---D | C] -- C:\Programme\MatrixEngine 1.0 [2010.05.31 10:30:22 | 000,122,968 | ---- | C] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysWow64\OpenAL32.dll [2010.05.28 15:52:15 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\AppData\Roaming\Blender Foundation [2010.05.28 15:52:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Blender Foundation [2010.05.24 01:16:38 | 000,000,000 | -HSD | C] -- C:\Windows\ftpcache [2010.05.24 00:21:04 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\Documents\Battlefield 2 [2010.05.21 20:44:41 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet [2010.05.21 20:43:16 | 000,000,000 | ---D | C] -- C:\Programme\Adobe [2010.05.21 20:41:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared [2010.05.21 20:41:04 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Macrovision Shared [2010.05.21 20:41:04 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Adobe [2010.05.20 20:46:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight [2010.05.20 19:39:29 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\Documents\Visual Studio 2008 [2010.05.20 19:38:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 9.0 [2010.05.20 19:38:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Merge Modules [2010.05.20 19:38:12 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft SDKs [2010.05.20 19:38:07 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Visual Studio 9.0 [2010.05.20 19:17:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\aliaswavefront shared [2010.05.20 19:17:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Alias Shared [2010.05.20 19:07:10 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\Desktop\GodMode.{ED7BA470-8E54-465E-825C-99712043E01C} [2010.05.20 18:55:26 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2010.05.16 20:32:41 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Synchronization Services [2010.05.16 20:32:41 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft SQL Server Compact Edition [2010.05.16 20:32:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services [2010.05.16 20:32:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition [2010.05.16 20:32:20 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\Documents\Visual Studio 2010 [2010.05.16 20:31:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0 [2010.05.16 20:31:38 | 000,000,000 | ---D | C] -- C:\Windows\symbols [2010.05.16 20:31:38 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Visual Studio 10.0 [2010.05.16 20:31:38 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Help Viewer [2010.05.16 20:14:55 | 001,942,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll [2010.05.16 20:14:55 | 001,130,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll [2010.05.16 20:14:55 | 000,320,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHost.exe [2010.05.16 20:14:55 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHost.exe [2010.05.16 20:14:55 | 000,109,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHostProxy.dll [2010.05.16 20:14:55 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHostProxy.dll [2010.05.16 20:14:55 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netfxperf.dll [2010.05.16 20:14:55 | 000,048,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netfxperf.dll [2010.05.14 02:59:42 | 000,005,632 | ---- | C] (EnTech Taiwan) -- C:\Windows\SysNative\drivers\pstrip64.sys [2010.05.14 02:59:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PowerStrip [2010.05.13 17:28:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity [2010.05.13 17:17:02 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\Documents\Sony-Medienbibliotheken [2010.05.13 17:17:00 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\AppData\Roaming\Publish Providers [2010.05.13 17:16:57 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\AppData\Local\Sony [2010.05.13 17:13:03 | 000,033,340 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dbmsqlgc.dll [2010.05.13 17:13:03 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dbmsgnet.dll [2010.05.13 17:13:03 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cliconfg.728 [2010.05.13 17:13:02 | 000,306,688 | ---- | C] (InstallShield Software Corporation) -- C:\Windows\IsUninst.exe [2010.05.13 17:13:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server [2010.05.13 17:12:46 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\AppData\Roaming\Sony [2010.05.13 17:12:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Vstplugins [2010.05.13 17:12:10 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spool [2010.05.13 17:12:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony [2010.05.13 17:12:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony [2010.05.13 17:11:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony Setup [2010.05.13 15:51:09 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\Documents\Anke [2010.05.12 16:58:15 | 000,000,000 | ---D | C] -- C:\Users\Sc4v\AppData\Local\Diagnostics [2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010.06.08 20:18:44 | 003,407,872 | -HS- | M] () -- C:\Users\Sc4v\ntuser.dat [2010.06.08 17:50:04 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2010.06.08 17:50:04 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2010.06.08 17:49:19 | 001,671,622 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010.06.08 17:49:19 | 000,716,670 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2010.06.08 17:49:19 | 000,671,988 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010.06.08 17:49:19 | 000,156,346 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2010.06.08 17:49:19 | 000,129,300 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010.06.08 17:45:00 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.06.08 17:44:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.06.08 17:44:58 | 535,683,071 | -HS- | M] () -- C:\hiberfil.sys [2010.06.08 00:27:57 | 004,902,678 | -H-- | M] () -- C:\Users\Sc4v\AppData\Local\IconCache.db [2010.06.07 22:07:43 | 002,717,096 | ---- | M] (Acronis) -- C:\Windows\SysNative\auto_reactivate.exe [2010.06.07 21:44:33 | 000,250,400 | ---- | M] (Acronis) -- C:\Windows\SysNative\drivers\afcdp.sys [2010.06.07 21:44:32 | 001,455,648 | ---- | M] (Acronis) -- C:\Windows\SysNative\drivers\tdrpm251.sys [2010.06.07 21:44:31 | 000,929,312 | ---- | M] (Acronis) -- C:\Windows\SysNative\drivers\timntr.sys [2010.06.07 21:44:26 | 000,254,496 | ---- | M] (Acronis) -- C:\Windows\SysNative\drivers\snapman.sys [2010.06.07 21:44:26 | 000,002,215 | ---- | M] () -- C:\Users\Public\Desktop\Acronis One-Click Backup.lnk [2010.06.07 21:44:26 | 000,001,141 | ---- | M] () -- C:\Users\Public\Desktop\Acronis True Image Home 2010.lnk [2010.06.07 20:48:54 | 000,001,011 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.06.07 20:45:35 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Users\Sc4v\Desktop\OTL.exe [2010.06.03 19:07:09 | 000,001,456 | ---- | M] () -- C:\Windows\Sandboxie.ini [2010.05.31 22:54:48 | 000,000,000 | ---- | M] () -- C:\Users\Sc4v\AppData\Roaming\chrtmp [2010.05.31 11:47:12 | 000,378,606 | ---- | M] () -- C:\Users\Sc4v\Documents\poo.png [2010.05.31 11:41:42 | 011,223,307 | ---- | M] () -- C:\Users\Sc4v\Documents\poo.sc1 [2010.05.28 15:52:50 | 000,002,106 | ---- | M] () -- C:\Users\Sc4v\Desktop\Blender.lnk [2010.05.24 01:16:24 | 000,000,509 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty(R) 2 - Mehrspieler.lnk [2010.05.24 01:16:24 | 000,000,509 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty(R) 2 - Einzelspieler.lnk [2010.05.24 01:16:12 | 000,000,252 | ---- | M] () -- C:\Windows\game.ini [2010.05.24 00:19:30 | 003,020,664 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2010.05.24 00:18:01 | 000,000,761 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 2.lnk [2010.05.23 22:56:11 | 000,000,649 | ---- | M] () -- C:\Users\Sc4v\Desktop\FlatOut2.lnk [2010.05.23 18:58:03 | 000,109,224 | ---- | M] () -- C:\Users\Sc4v\AppData\Local\GDIPFONTCACHEV1.DAT [2010.05.23 18:49:18 | 000,000,681 | ---- | M] () -- C:\Users\Public\Desktop\Age of Empires II.lnk [2010.05.21 20:44:39 | 000,001,139 | ---- | M] () -- C:\Users\Sc4v\Desktop\Adobe Photoshop CS4.lnk [2010.05.21 16:25:31 | 000,008,230 | ---- | M] () -- C:\Users\Sc4v\Screenshot.jpg [2010.05.20 21:07:02 | 000,524,288 | -HS- | M] () -- C:\Users\Sc4v\ntuser.dat{24e15357-6439-11df-842a-fbb0a49bb293}.TMContainer00000000000000000002.regtrans-ms [2010.05.20 21:07:02 | 000,524,288 | -HS- | M] () -- C:\Users\Sc4v\ntuser.dat{24e15357-6439-11df-842a-fbb0a49bb293}.TMContainer00000000000000000001.regtrans-ms [2010.05.20 21:07:02 | 000,065,536 | -HS- | M] () -- C:\Users\Sc4v\ntuser.dat{24e15357-6439-11df-842a-fbb0a49bb293}.TM.blf [2010.05.20 20:46:38 | 000,001,174 | ---- | M] () -- C:\Users\Sc4v\Desktop\Microsoft Visual C++ 2008 Express Edition.lnk [2010.05.16 20:31:36 | 001,648,756 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2010.05.16 18:50:13 | 000,001,144 | ---- | M] () -- C:\Users\Sc4v\Desktop\DarthMod Ultimate Commander.lnk [2010.05.14 01:18:28 | 000,000,205 | ---- | M] () -- C:\Users\Sc4v\Desktop\Counter-Strike.url [2010.05.13 17:28:58 | 000,000,945 | ---- | M] () -- C:\Users\Sc4v\Desktop\Audacity.lnk [2010.05.13 17:16:37 | 000,002,588 | ---- | M] () -- C:\Users\Sc4v\Documents\Vegas registrieren.htm [2010.05.13 17:13:03 | 000,020,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\cliconfg.728 [2010.05.13 17:12:13 | 000,001,894 | ---- | M] () -- C:\Users\Public\Desktop\Vegas 7.0.lnk [2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.06.07 21:44:26 | 000,002,215 | ---- | C] () -- C:\Users\Public\Desktop\Acronis One-Click Backup.lnk [2010.06.07 21:44:26 | 000,001,141 | ---- | C] () -- C:\Users\Public\Desktop\Acronis True Image Home 2010.lnk [2010.06.07 20:48:54 | 000,001,011 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.05.31 22:54:48 | 000,000,000 | ---- | C] () -- C:\Users\Sc4v\AppData\Roaming\chrtmp [2010.05.31 11:41:41 | 011,223,307 | ---- | C] () -- C:\Users\Sc4v\Documents\poo.sc1 [2010.05.31 11:41:33 | 000,378,606 | ---- | C] () -- C:\Users\Sc4v\Documents\poo.png [2010.05.28 15:52:50 | 000,002,106 | ---- | C] () -- C:\Users\Sc4v\Desktop\Blender.lnk [2010.05.24 01:16:24 | 000,000,509 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty(R) 2 - Mehrspieler.lnk [2010.05.24 01:16:24 | 000,000,509 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty(R) 2 - Einzelspieler.lnk [2010.05.24 00:18:01 | 000,000,761 | ---- | C] () -- C:\Users\Public\Desktop\Battlefield 2.lnk [2010.05.23 22:56:12 | 000,000,649 | ---- | C] () -- C:\Users\Sc4v\Desktop\FlatOut2.lnk [2010.05.23 18:49:18 | 000,000,681 | ---- | C] () -- C:\Users\Public\Desktop\Age of Empires II.lnk [2010.05.23 17:35:00 | 000,003,584 | -HS- | C] () -- C:\Users\Sc4v\Thumbs.db [2010.05.21 20:44:39 | 000,001,139 | ---- | C] () -- C:\Users\Sc4v\Desktop\Adobe Photoshop CS4.lnk [2010.05.21 16:25:31 | 000,008,230 | ---- | C] () -- C:\Users\Sc4v\Screenshot.jpg [2010.05.21 16:03:02 | 002,200,064 | ---- | C] () -- C:\Windows\SysWow64\sfml-graphics-d.dll [2010.05.21 16:03:02 | 001,207,296 | ---- | C] () -- C:\Windows\SysWow64\sfml-graphics.dll [2010.05.21 16:03:02 | 000,325,120 | ---- | C] () -- C:\Windows\SysWow64\libsndfile-1.dll [2010.05.21 16:03:02 | 000,294,400 | ---- | C] () -- C:\Windows\SysWow64\sfml-audio-d.dll [2010.05.21 16:03:02 | 000,270,848 | ---- | C] () -- C:\Windows\SysWow64\sfml-network-d.dll [2010.05.21 16:03:02 | 000,199,168 | ---- | C] () -- C:\Windows\SysWow64\sfml-window-d.dll [2010.05.21 16:03:02 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\sfml-system-d.dll [2010.05.21 16:03:02 | 000,089,600 | ---- | C] () -- C:\Windows\SysWow64\sfml-audio.dll [2010.05.21 16:03:02 | 000,081,408 | ---- | C] () -- C:\Windows\SysWow64\sfml-network.dll [2010.05.21 16:00:38 | 000,044,544 | ---- | C] () -- C:\Windows\SysWow64\sfml-window.dll [2010.05.21 16:00:38 | 000,034,816 | ---- | C] () -- C:\Windows\SysWow64\sfml-system.dll [2010.05.20 21:46:01 | 000,034,816 | ---- | C] () -- C:\Windows\SysNative\sfml-system.dll [2010.05.20 20:46:38 | 000,001,174 | ---- | C] () -- C:\Users\Sc4v\Desktop\Microsoft Visual C++ 2008 Express Edition.lnk [2010.05.20 20:15:24 | 000,524,288 | -HS- | C] () -- C:\Users\Sc4v\ntuser.dat{24e15357-6439-11df-842a-fbb0a49bb293}.TMContainer00000000000000000002.regtrans-ms [2010.05.20 20:15:24 | 000,524,288 | -HS- | C] () -- C:\Users\Sc4v\ntuser.dat{24e15357-6439-11df-842a-fbb0a49bb293}.TMContainer00000000000000000001.regtrans-ms [2010.05.20 20:15:24 | 000,065,536 | -HS- | C] () -- C:\Users\Sc4v\ntuser.dat{24e15357-6439-11df-842a-fbb0a49bb293}.TM.blf [2010.05.13 17:28:58 | 000,000,945 | ---- | C] () -- C:\Users\Sc4v\Desktop\Audacity.lnk [2010.05.13 17:16:37 | 000,002,588 | ---- | C] () -- C:\Users\Sc4v\Documents\Vegas registrieren.htm [2010.05.13 17:12:13 | 000,001,894 | ---- | C] () -- C:\Users\Public\Desktop\Vegas 7.0.lnk [2010.05.13 15:15:58 | 000,001,144 | ---- | C] () -- C:\Users\Sc4v\Desktop\DarthMod Ultimate Commander.lnk [2010.05.11 15:22:52 | 000,000,205 | ---- | C] () -- C:\Users\Sc4v\Desktop\Counter-Strike.url [2010.05.04 12:31:27 | 001,648,756 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2010.04.19 23:38:56 | 000,007,168 | ---- | C] () -- C:\Windows\SysWow64\drivers\StarOpen.sys [2010.04.19 21:50:31 | 000,000,252 | ---- | C] () -- C:\Windows\game.ini [2010.04.19 16:47:36 | 000,001,456 | ---- | C] () -- C:\Windows\Sandboxie.ini [2010.04.17 17:18:08 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini [2009.11.06 10:58:04 | 000,178,975 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [1997.06.14 10:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\iyvu9_32.dll < End of report > |
08.06.2010, 20:07 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | 'C:\Users\***\AppData\Roaming\install\svchost.exe' Logs sind nun unauffällig. Warum hast Du Acronis drauf, nutzt Du das Tool auch? Wer aktuelle Images hat, kann sein System schnell mit diesen Recovern und es wie es vorher einmal war (wenn hoffentlich das Image erstellt wurde, als noch keine Viren drauf waren) Noch Funde in der Zwischenzeit oder ist der Rechner nun wieder ok?
__________________ --> 'C:\Users\***\AppData\Roaming\install\svchost.exe' |
08.06.2010, 22:57 | #7 |
| 'C:\Users\***\AppData\Roaming\install\svchost.exe' hi alles normal also keine Funde mehr. Ich habe wie bereits gesagt ne Menge gegoogelt und habe mir direkt gestern die Testversion von Acronis besorgt und heute auch ein Image erstellt. Ich nehme an ich kann dieses Image nun auch problemlos benutzen. Habe fest vor Acronis noch diese Woche zu kaufen um mich mit weniger "Angst" bewegen zu können. Ich danke vielmals für die großartige Hilfe und hoffe hier so schnell keinen Post mehr erstellen zu müssen (nicht böse gemeint :P ) Sc4v |
Themen zu 'C:\Users\***\AppData\Roaming\install\svchost.exe' |
antivir, antivir guard, avg, avira, bho, bitte um hilfe, browser, cdburnerxp, desktop, firefox, google, hijack, hijackthis, hijackthis log, internet, internet explorer, maleware, mozilla, mssql, plug-ins, programm, senden, sicherheit, software, svchost.exe, syswow64, trojan, usb, usb 3.0, virus, windows, windows 7 64bit, windowsprogramm |