Zurück   Trojaner-Board > Malware entfernen > Überwachung, Datenschutz und Spam

Überwachung, Datenschutz und Spam: Unbekannte Internetseiten in der Chronik

Windows 7 Fragen zu Verschlüsselung, Spam, Datenschutz & co. sind hier erwünscht. Hier geht es um Abwehr von Keyloggern oder aderen Spionagesoftware wie Spyware und Adware. Themen zum "Trojaner entfernen" oder "Malware Probleme" dürfen hier nur diskutiert werden. Benötigst du Hilfe beim Trojaner entfernen oder weil du dir einen Virus eingefangen hast, erstelle ein Thema in den oberen Bereinigungsforen.

Antwort
Alt 14.09.2010, 20:01   #1
CHWurst
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



Hallo zusammen,

ich bin neu hier und habe von der ganzen Thematik keine Ahnung.

Als ich heute in die Chronik meines Firefox guckte musste ich feststellen
das jemand auf Pornografische Internetseiten war. Die Chronik sieht folgender maßen aus: Google-such begriff "kostenlose sex videos" und dann die einzelnen seiten samt Videos schön durch geklickt. Das ganze seit 5 Monaten aber immer nur ein Tag pro Monat.
Der PC ist per WLAN am Router angeschlossen und mit ein 10 stelligen Code gesichert.

Ist es möglich das es ein Hacker ist? Oder geht das nur von meinem PC aus.

Gruß CHWurst

Alt 14.09.2010, 21:30   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



Zitat:
Ist es möglich das es ein Hacker ist? Oder geht das nur von meinem PC aus.
Der 10 stellige WLAN-Code ist nicht optimal. Selbst wenn es die beste Verschlüsselung WPA/WPA2 wäre, das erlaubt 63 Zeichen und die sollte man auch ausnutzen. Welche Verschlüsselung hast Du? WPA oder den billigen Vorgänger WEP?

Bitte auch routinemäßig einen Vollscan mit Malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Danach OTL:

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.
__________________

__________________

Alt 15.09.2010, 20:32   #3
CHWurst
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



Hallo cosinus,

so habe jetzt alles gemacht wie du es mir beschrieben hast.
Und hier die logs:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4621

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

15.09.2010 21:17:29
mbam-log-2010-09-15 (21-17-29).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|)
Durchsuchte Objekte: 357716
Laufzeit: 1 Stunde(n), 49 Minute(n), 34 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
C:\Casino\William Hill CASINO CLUB\_SetupCasino_d8628f_de.exe (Adware.Casino) -> No action taken.
_________________________________________________________________OTL Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 15.09.2010 21:19:47 - Run 1
OTL by OldTimer - Version 3.2.12.1     Folder = C:\Users\Wurst\Desktop
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
6,00 Gb Total Physical Memory | 4,00 Gb Available Physical Memory | 64,00% Memory free
12,00 Gb Paging File | 10,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 48,74 Gb Total Space | 12,35 Gb Free Space | 25,33% Space Free | Partition Type: NTFS
Drive D: | 186,31 Gb Total Space | 100,20 Gb Free Space | 53,78% Space Free | Partition Type: NTFS
Drive E: | 97,66 Gb Total Space | 8,84 Gb Free Space | 9,05% Space Free | Partition Type: NTFS
Drive F: | 39,80 Gb Total Space | 25,96 Gb Free Space | 65,21% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: WURST-PC
Current User Name: Wurst
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [dm Fotowelt] -- "C:\Program Files (x86)\dm\dm Fotowelt\dm Fotowelt.exe" "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [dm Fotowelt] -- "C:\Program Files (x86)\dm\dm Fotowelt\dm Fotowelt.exe" "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{77CB2F9F-67C5-4ADA-9321-B30C9C64727E}" = Microsoft SQL Server Compact 3.5 SP1 x64 (Deutsch)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{987FE247-4E69-4A2E-A961-D14F901FDBF6}" = Logitech Webcam Software
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"lvdrivers_12.10" = Logitech Webcam Software-Treiberpaket
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"WinRAR archiver" = WinRAR
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0C8EBB00-4909-459C-8347-B2068B7F0319}" = CyberLink DVD Menu Template Pack
"{19C64880-BBCA-11D4-9EEE-0004ACDDDB3B}" = CyberLink InstantBurn
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{2217B0B4-35CB-48C6-B640-864DF2F30F99}" = OpenOffice.org 3.2
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 21
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}" = CyberLink WaveEditor
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4902F8E1-B2DC-488C-AEBB-96548B832ED5}" = meta<browser/> 2.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon 3
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker
"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.4 - Deutsch
"{ADD5DB49-72CF-11D8-9D75-000129760D75}" = CyberLink PowerBackup
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B132E67C-EEA5-492B-B368-543CD88D8569}" = AnyDVD Registration
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer
"{BFC218D7-5BCA-41A1-B585-E75E1DCD56A6}" = Media Browser
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C69405BB-27AF-4940-B3DA-04910B4DFD23}_is1" = aTube Catcher 1.0
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call
"{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
"{D3829204-8035-4C55-826D-01BEBBA43B26}" = GameEmu
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{E10DB5DA-E576-40EA-A7FC-1CB2A7B283A6}" = NVIDIA PhysX
"{E3D04529-6EDB-11D8-A372-0050BAE317E1}" = CyberLink PowerDVD Copy
"{E5BD7FEB-28BF-4EF2-82FB-C7360B563A75}_is1" = MCE Standby Tool 0.9.099
"{EA926717-CE5A-4CB4-AB21-9E6E9565A458}" = RCT3 Soaked
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F3759A9F-7AFA-4FB4-8DF1-53F26B979DEE}" = Belkin 54Mbps Wireless Network Adapter
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"{FA440BE8-EC2F-4478-A01A-077DA0606501}" = Microsoft SQL Server Compact 3.5 SP1 (Deutsch)
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Any Video Converter_is1" = Any Video Converter 3.0.7
"Ashampoo Photo Commander 7_is1" = Ashampoo Photo Commander 7.50
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CamSpy_is1" = CamSpy V.3.6.4
"Clean Virus MSN_is1" = Clean Virus MSN
"CloneDVD2" = CloneDVD2
"DivX Setup.divx.com" = DivX-Setup
"dm Fotowelt" = dm Fotowelt
"eBay Icon" = eBay Icon
"Emsisoft Anti-Malware_is1" = Emsisoft Anti-Malware 5.0
"eMule" = eMule
"ImgBurn" = ImgBurn
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
"InstallShield_{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}" = CyberLink WaveEditor
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"InstallShield_{ADD5DB49-72CF-11D8-9D75-000129760D75}" = CyberLink PowerBackup
"InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
"InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}" = CyberLink PowerDVD Copy
"KaraokeDX" = Karaoke for DirectX (remove only)
"Karaoke-DX" = Karaoke for DirectX (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Morphyre" = Morphyre
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"Mozilla Firefox (4.0b4)" = Mozilla Firefox (4.0b4)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"SopCast" = SopCast 3.2.9
"ST4UNST #1" = Peck's Power Join
"Transcode360" = Transcode 360 for Windows Vista
"Update Service" = Update Service
"UseNeXT_is1" = UseNeXT
"uTorrent" = µTorrent
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 0.9.9
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f58cbb372ebb2ec8" = Media Center Studio
"William Hill CASINO CLUB" = William Hill CASINO CLUB
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 11.09.2010 04:51:37 | Computer Name = Wurst-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei
 "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile  8.  Die 
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente
 überein.  Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition:
 WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Verwenden Sie
 das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 12.09.2010 04:19:06 | Computer Name = Wurst-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 12.09.2010 05:09:19 | Computer Name = Wurst-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei
 "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile  8.  Die 
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente
 überein.  Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition:
 WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Verwenden Sie
 das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 13.09.2010 03:40:22 | Computer Name = Wurst-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 13.09.2010 07:06:25 | Computer Name = Wurst-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei
 "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile  8.  Die 
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente
 überein.  Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition:
 WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Verwenden Sie
 das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 14.09.2010 01:46:21 | Computer Name = Wurst-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 14.09.2010 14:17:47 | Computer Name = Wurst-PC | Source = Application Hang | ID = 1002
Description = Programm HiJackThis.exe, Version 2.0.0.4 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 294    Startzeit: 
01cb54391395d270    Endzeit: 92    Anwendungspfad: C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

Berichts-ID:
 5d848c51-c02c-11df-a382-001a4d8507b4  
 
Error - 15.09.2010 03:11:35 | Computer Name = Wurst-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 15.09.2010 03:38:59 | Computer Name = Wurst-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei
 "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile  8.  Die 
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente
 überein.  Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition:
 WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Verwenden Sie
 das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 15.09.2010 03:39:28 | Computer Name = Wurst-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\spybot - search & destroy\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei
 "c:\program files (x86)\spybot - search & destroy\DelZip179.dll" in Zeile 8.  Der
 Wert "*" des "language"-Attributs im assemblyIdentity-Element ist ungültig.
 
[ Media Center Events ]
Error - 06.08.2010 19:30:26 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538
Description = 
 
Error - 06.08.2010 19:31:31 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538
Description = 
 
Error - 06.08.2010 19:33:57 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538
Description = 
 
Error - 06.08.2010 19:40:28 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538
Description = 
 
Error - 06.08.2010 19:45:31 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 543
Description = 
 
Error - 07.08.2010 06:10:01 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538
Description = 
 
Error - 07.08.2010 06:18:49 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538
Description = 
 
Error - 12.08.2010 03:30:59 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538
Description = 
 
Error - 12.08.2010 03:34:36 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538
Description = 
 
Error - 12.08.2010 03:41:06 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538
Description = 
 
[ System Events ]
Error - 31.07.2010 05:07:07 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 610
Description = 
 
Error - 31.07.2010 05:07:08 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 610
Description = 
 
Error - 31.07.2010 09:40:20 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 602
Description = 
 
Error - 01.08.2010 02:46:32 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 602
Description = 
 
Error - 01.08.2010 08:08:48 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 602
Description = 
 
Error - 01.08.2010 08:52:00 | Computer Name = Wurst-PC | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
 nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
 
Error - 01.08.2010 09:51:14 | Computer Name = Wurst-PC | Source = DCOM | ID = 10010
Description = 
 
Error - 02.08.2010 03:44:22 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 602
Description = 
 
Error - 02.08.2010 10:01:36 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 602
Description = 
 
Error - 03.08.2010 03:32:18 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 602
Description = 
 
[ Transcode360 Service Events ]
Error - 12.08.2010 07:19:27 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0
Description = Transcoding error:
 
Error - 12.08.2010 07:19:27 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0
Description =   WARNING: OUTPUT FILE FORMAT IS _MPEG_. See -of help.  ============ Sorry,
 this file format is not recognized/supported =============  === If this file is an
 AVI, ASF or MPEG stream, please contact the author! ===  Cannot open demuxer.  
 
Error - 12.08.2010 07:19:53 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0
Description = Transcoding error:
 
Error - 12.08.2010 07:19:53 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0
Description =   WARNING: OUTPUT FILE FORMAT IS _MPEG_. See -of help.  ============ Sorry,
 this file format is not recognized/supported =============  === If this file is an
 AVI, ASF or MPEG stream, please contact the author! ===  Cannot open demuxer.  
 
Error - 12.08.2010 07:21:04 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0
Description = Transcoding error:
 
Error - 12.08.2010 07:21:04 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0
Description =   WARNING: OUTPUT FILE FORMAT IS _MPEG_. See -of help.  Video stream is
 mandatory!  
 
Error - 12.08.2010 07:25:26 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0
Description = Transcoding error:
 
Error - 12.08.2010 07:25:26 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0
Description =   WARNING: OUTPUT FILE FORMAT IS _MPEG_. See -of help.  ============ Sorry,
 this file format is not recognized/supported =============  === If this file is an
 AVI, ASF or MPEG stream, please contact the author! ===  Cannot open demuxer.  
 
Error - 12.08.2010 07:25:54 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0
Description = Transcoding error:
 
Error - 12.08.2010 07:25:54 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0
Description =   WARNING: OUTPUT FILE FORMAT IS _MPEG_. See -of help.  Video stream is
 mandatory!  
 
 
< End of report >
         
--- --- ---
_________________________________________________________________OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 15.09.2010 21:19:47 - Run 1
OTL by OldTimer - Version 3.2.12.1     Folder = C:\Users\Wurst\Desktop
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
6,00 Gb Total Physical Memory | 4,00 Gb Available Physical Memory | 64,00% Memory free
12,00 Gb Paging File | 10,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 48,74 Gb Total Space | 12,35 Gb Free Space | 25,33% Space Free | Partition Type: NTFS
Drive D: | 186,31 Gb Total Space | 100,20 Gb Free Space | 53,78% Space Free | Partition Type: NTFS
Drive E: | 97,66 Gb Total Space | 8,84 Gb Free Space | 9,05% Space Free | Partition Type: NTFS
Drive F: | 39,80 Gb Total Space | 25,96 Gb Free Space | 65,21% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: WURST-PC
Current User Name: Wurst
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Wurst\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe (Emsi Software GmbH)
PRC - C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe (Emsi Software GmbH)
PRC - C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\MCE Standby Tool\mst.exe (Herman van Eijk)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
PRC - C:\Programme\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Wurst\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files (x86)\Emsisoft Anti-Malware\a2hooks32.dll (Emsi Software GmbH)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (LVPrcS64) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) -- C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (a2AntiMalware) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe (Emsi Software GmbH)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (clr_optimization_v4.0.30319_64) -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (Transcode360) -- C:\Program Files (x86)\Transcode360\Transcode360.exe (Transcode 360)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64j.sys File not found
DRV:64bit: - (upperdev) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64.sys File not found
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys File not found
DRV:64bit: - (nmwcdx64) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys File not found
DRV:64bit: - (nmwcdnsux64) -- C:\Windows\SysNative\drivers\nmwcdnsux64.sys File not found
DRV:64bit: - (nmwcdnsucx64) -- C:\Windows\SysNative\drivers\nmwcdnsucx64.sys File not found
DRV:64bit: - (nmwcdcx64) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys File not found
DRV:64bit: - (hwinterface) -- C:\Windows\SysNative\Drivers\hwinterface.sys File not found
DRV:64bit: - (seehcri) -- C:\Windows\SysNative\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggsemc) -- C:\Windows\SysNative\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggflt) -- C:\Windows\SysNative\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (netr7364) -- C:\Windows\SysNative\drivers\netr7364.sys (Ralink Technology, Corp.)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (cxbu0x64) -- C:\Windows\SysNative\drivers\cxbu0x64.sys (HID Global Corporation)
DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (LVPr2Mon) -- C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (LVPr2M64) -- C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (BthAvrcp) -- C:\Windows\SysNative\drivers\BthAvrcp.sys (CSR, plc)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (vmbus) -- C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) -- C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) -- C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (s3cap) -- C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) -- C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (VClone) -- C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) -- C:\Windows\SysNative\drivers\LV302V64.SYS (Logitech Inc.)
DRV:64bit: - (LVUSBS64) -- C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.)
DRV:64bit: - (sfvfs02) StarForce Protection VFS Driver (version 2.x) -- C:\Windows\SysNative\drivers\sfvfs02.sys (Protection Technology)
DRV:64bit: - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\SysNative\drivers\sfdrv01.sys (Protection Technology)
DRV:64bit: - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\SysNative\drivers\sfhlp02.sys (Protection Technology)
DRV - (a2injectiondriver) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys (Emsi Software GmbH)
DRV - (a2acc) -- C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys (Emsi Software GmbH)
DRV - (hwinterface) -- C:\Windows\SysWOW64\drivers\hwinterface.sys (Buzz)
DRV - (gdrv) -- C:\Windows\gdrv.sys (Windows (R) Server 2003 DDK provider)
DRV - (a2util) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys (Emsi Software GmbH)
DRV - ({B154377D-700F-42cc-9474-23858FBDF4BD}) -- C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl (CyberLink Corp.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 40 DC D7 F6 55 4C CB 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultthis.engineName: "Winload Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.startup.homepage: "hxxp://www.bild.de/"
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.1.0625
FF - prefs.js..extensions.enabledItems: DeviceDetection@logitech.com:1.0.176.0
FF - prefs.js..extensions.enabledItems: {fd639891-5cc6-45ae-9055-a7a6abb5a7a9}:1.2.11.0
FF - prefs.js..extensions.enabledItems: cfxHelper@Triton:1.2
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: finder@meingutscheincode.de:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: extension@virtusdesigns.com:3.6.6
FF - prefs.js..extensions.enabledItems: {3ffb7be0-8bde-11de-8a39-0800200c9a66}:3.6.05.02.10
FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.6.6
FF - prefs.js..extensions.enabledItems: cfxe@Triton:3.6.5
FF - prefs.js..extensions.enabledItems: {12bc3590-67a6-11de-8a39-0800200c9a66}:3.6
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&q="
FF - prefs.js..network.proxy.type: 4
 
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.09.10 16:07:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.09.10 16:07:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b4\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 4\components [2010.08.31 18:40:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b4\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 4\plugins
 
[2010.02.21 09:23:32 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Extensions
[2010.09.15 19:18:59 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions
[2010.02.21 16:43:14 | 000,000,000 | ---D | M] (Eclipse) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}
[2010.02.21 16:38:35 | 000,000,000 | ---D | M] (Purple Fox) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{3ffb7be0-8bde-11de-8a39-0800200c9a66}
[2010.08.19 17:31:29 | 000,000,000 | ---D | M] (Aero Fox XL) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
[2010.06.28 19:09:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010.08.19 17:31:33 | 000,000,000 | ---D | M] (Yoono) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{d9284e50-81fc-11da-a72b-0800200c9a66}
[2010.02.21 13:57:53 | 000,000,000 | ---D | M] (SEB Chipcard Plugin) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{fd639891-5cc6-45ae-9055-a7a6abb5a7a9}
[2010.06.28 19:09:35 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\cfxe@Triton
[2010.06.28 19:09:39 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\cfxHelper@Triton
[2010.02.21 13:39:01 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\DeviceDetection@logitech.com
[2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com
[2010.07.26 18:41:19 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\finder@meingutscheincode.de
[2010.05.22 20:04:12 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\personas@christopher.beard
[2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com\__MACOSX
[2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com\chrome
[2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com\defaults
[2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\mac\browser\extensions
[2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\mac\mozapps\extensions
[2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\win\browser\extensions
[2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\win\mozapps\extensions
[2010.08.19 17:31:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\mac\mozapps\extensions
[2010.08.19 17:31:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\win\mozapps\extensions
[2010.03.24 16:13:02 | 000,000,917 | ---- | M] () -- C:\Users\Wurst\AppData\Roaming\Mozilla\FireFox\Profiles\nikwlstw.default\searchplugins\conduit.xml
[2010.08.19 09:19:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions
[2010.05.23 10:51:28 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.08.19 09:19:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.07.17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010.04.03 14:51:17 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.04.03 14:51:17 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.04.03 14:51:17 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.04.03 14:51:17 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.04.03 14:51:17 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010.09.14 19:38:46 | 000,419,251 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1	www.007guard.com
O1 - Hosts: 127.0.0.1	007guard.com
O1 - Hosts: 127.0.0.1	008i.com
O1 - Hosts: 127.0.0.1	www.008k.com
O1 - Hosts: 127.0.0.1	008k.com
O1 - Hosts: 127.0.0.1	www.00hq.com
O1 - Hosts: 127.0.0.1	00hq.com
O1 - Hosts: 127.0.0.1	010402.com
O1 - Hosts: 127.0.0.1	www.032439.com
O1 - Hosts: 127.0.0.1	032439.com
O1 - Hosts: 127.0.0.1	www.0scan.com
O1 - Hosts: 127.0.0.1	0scan.com
O1 - Hosts: 127.0.0.1	1000gratisproben.com
O1 - Hosts: 127.0.0.1	www.1000gratisproben.com
O1 - Hosts: 127.0.0.1	1001namen.com
O1 - Hosts: 127.0.0.1	www.1001namen.com
O1 - Hosts: 127.0.0.1	100888290cs.com
O1 - Hosts: 127.0.0.1	www.100888290cs.com
O1 - Hosts: 127.0.0.1	www.100sexlinks.com
O1 - Hosts: 127.0.0.1	100sexlinks.com
O1 - Hosts: 127.0.0.1	10sek.com
O1 - Hosts: 127.0.0.1	www.10sek.com
O1 - Hosts: 127.0.0.1	www.1-2005-search.com
O1 - Hosts: 127.0.0.1	1-2005-search.com
O1 - Hosts: 127.0.0.1	123fporn.info
O1 - Hosts: 14465 more lines...
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O4 - HKLM..\Run: [a-squared] C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2guard.exe (Emsi Software GmbH)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [F5D7050v3] C:\Program Files (x86)\Belkin\F5D7050v3\Belkinwcui.exe File not found
O4 - HKLM..\Run: [InstantBurn] C:\PROGRA~2\CYBERL~1\INSTAN~1\Win2K\IBurn.exe (CyberLink Corporation.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [ Malwarebytes Anti-Malware  (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MCE Standby Tool] C:\Program Files (x86)\MCE Standby Tool\mst.exe (Herman van Eijk)
O4 - HKLM..\Run: [PDVD9LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl9] C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe (Logitech Inc.)
O4 - Startup: C:\Users\Wurst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (zipfldra.dll) -  File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\ScCertProp: DllName - Reg Error: Key error. -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\Shell - "" = AutoRun
O33 - MountPoints2\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\Shell\AutoRun\command - "" = I:\Startme.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.09.15 21:09:36 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSCMCDE.DLL
[2010.09.15 21:09:36 | 000,139,264 | ---- | C] (man-tech.de) -- C:\Windows\SysWow64\ssMail.dll
[2010.09.15 21:09:36 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSSTDFMT.DLL
[2010.09.15 21:09:36 | 000,103,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSCOMM32.OCX
[2010.09.15 21:09:36 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSCOMDE.DLL
[2010.09.15 21:09:35 | 000,209,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TABCTL32.OCX
[2010.09.15 21:09:35 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CMDLGDE.DLL
[2010.09.15 21:09:35 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TABCTDE.DLL
[2010.09.15 21:09:35 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WINSKDE.DLL
[2010.09.15 21:09:35 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\STDFTDE.DLL
[2010.09.15 21:09:34 | 000,712,704 | ---- | C] (Fath Software ( www.fathsoft.com )) -- C:\Windows\SysWow64\csCapx.ocx
[2010.09.15 21:09:34 | 000,115,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSINET.OCX
[2010.09.15 21:09:34 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\INETDE.DLL
[2010.09.15 21:09:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CamSpy
[2010.09.15 19:19:55 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Wurst\Desktop\OTL.exe
[2010.09.15 19:18:02 | 002,441,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iertutil.dll
[2010.09.15 17:37:42 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Malwarebytes
[2010.09.15 17:37:29 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010.09.15 17:37:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.09.15 17:37:26 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010.09.15 17:37:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010.09.14 19:32:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Emsisoft Anti-Malware
[2010.09.14 18:47:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010.09.14 18:47:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2010.09.14 18:35:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2010.09.13 17:52:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavalys
[2010.09.04 11:00:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2010.08.31 18:40:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 4
[2010.08.31 16:37:33 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Desktop\Tatoo
[2010.08.29 09:11:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2010.08.25 22:11:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2010.08.25 22:11:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2010.08.25 09:02:39 | 000,861,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2010.08.23 08:34:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AxBx
[2010.08.21 15:16:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SopCast
[2010.08.21 09:30:11 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\dvdcss
[2010.08.19 17:47:22 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\VirtualDubMod_1_5_10_2_All_inclusive
[2010.08.19 09:19:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2010.08.19 09:19:21 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2010.08.19 09:19:21 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2010.08.19 09:19:21 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[2 C:\Users\Wurst\*.tmp files -> C:\Users\Wurst\*.tmp -> ]
[1 C:\Users\Wurst\Documents\*.tmp files -> C:\Users\Wurst\Documents\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2010.09.15 21:23:54 | 002,621,440 | -HS- | M] () -- C:\Users\Wurst\ntuser.dat
[2010.09.15 21:23:51 | 001,068,065 | ---- | M] (PKSoft) -- C:\Users\Wurst\Desktop\setupsc.exe
[2010.09.15 21:22:06 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.09.15 21:22:06 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.09.15 21:02:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.09.15 19:24:57 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.09.15 19:23:45 | 004,957,557 | -H-- | M] () -- C:\Users\Wurst\AppData\Local\IconCache.db
[2010.09.15 19:20:00 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Wurst\Desktop\OTL.exe
[2010.09.15 17:37:32 | 000,001,013 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.09.14 19:38:46 | 000,419,251 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2010.09.14 18:55:01 | 000,419,251 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20100914-193846.backup
[2010.09.14 16:30:18 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010.09.14 16:30:18 | 000,653,928 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2010.09.14 16:30:18 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010.09.14 16:30:18 | 000,129,800 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2010.09.14 16:30:18 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010.08.31 07:19:12 | 002,441,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iertutil.dll
[2010.08.28 16:41:16 | 000,000,823 | ---- | M] () -- C:\Users\Wurst\Desktop\William Hill CASINO CLUB.lnk
[2010.08.25 22:11:17 | 000,001,845 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010.08.23 08:34:13 | 000,001,096 | ---- | M] () -- C:\Users\Wurst\Desktop\Clean Virus MSN.lnk
[2010.08.21 15:16:44 | 000,000,995 | ---- | M] () -- C:\Users\Wurst\Desktop\SopCast.lnk
[2010.08.19 18:08:17 | 000,001,861 | ---- | M] () -- C:\Users\Wurst\Desktop\UseNeXT.lnk
[2010.08.19 17:51:00 | 000,003,193 | ---- | M] () -- C:\Users\Wurst\Desktop\VirtualDub.lnk
[2010.08.19 17:50:50 | 000,004,068 | ---- | M] () -- C:\Users\Wurst\Desktop\VirtualDubMod.lnk
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[2 C:\Users\Wurst\*.tmp files -> C:\Users\Wurst\*.tmp -> ]
[1 C:\Users\Wurst\Documents\*.tmp files -> C:\Users\Wurst\Documents\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010.09.15 17:37:32 | 000,001,013 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.08.28 16:41:16 | 000,000,823 | ---- | C] () -- C:\Users\Wurst\Desktop\William Hill CASINO CLUB.lnk
[2010.08.25 22:11:17 | 000,001,845 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010.08.23 08:34:13 | 000,001,096 | ---- | C] () -- C:\Users\Wurst\Desktop\Clean Virus MSN.lnk
[2010.08.21 15:16:44 | 000,000,995 | ---- | C] () -- C:\Users\Wurst\Desktop\SopCast.lnk
[2010.08.19 17:51:00 | 000,003,193 | ---- | C] () -- C:\Users\Wurst\Desktop\VirtualDub.lnk
[2010.08.19 17:50:50 | 000,004,068 | ---- | C] () -- C:\Users\Wurst\Desktop\VirtualDubMod.lnk
[2010.08.13 20:32:32 | 000,037,376 | ---- | C] () -- C:\Windows\SysWow64\VbVfw.dll
[2010.08.12 12:53:05 | 083,267,584 | ---- | C] () -- C:\ProgramData\arcade.mp3
[2010.08.12 12:09:57 | 000,000,101 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2010.08.04 19:24:32 | 001,551,928 | ---- | C] () -- C:\Program Files (x86)\SetupVirtualCloneDrive.exe
[2010.08.04 19:24:31 | 000,770,938 | ---- | C] () -- C:\Program Files (x86)\KaraokeSetup.exe
[2010.08.03 19:51:25 | 000,000,410 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010.07.25 12:52:49 | 000,000,177 | ---- | C] () -- C:\ProgramData\Temp.log
[2010.07.21 17:26:48 | 000,000,125 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010.06.20 12:23:16 | 000,197,120 | ---- | C] () -- C:\Windows\patchw32.dll
[2010.05.02 08:03:03 | 000,005,632 | ---- | C] () -- C:\Users\Wurst\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.02 07:36:34 | 001,526,060 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.04.02 17:17:34 | 000,179,091 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010.03.06 12:09:17 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\vbzlib1.dll
[2010.02.21 09:14:58 | 000,005,224 | ---- | C] () -- C:\Windows\SysWow64\ucuiinfo.ini
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
< End of report >
         
--- --- ---

So ich das ist so richtig!

Gruß CHWurst
__________________

Alt 15.09.2010, 20:42   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



Zitat:
Zitat von cosinus
Welche Verschlüsselung hast Du? WPA oder den billigen Vorgänger WEP?
Was ist hiermit??
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 15.09.2010, 20:43   #5
CHWurst
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



Oh ja, habe ich vergessen.
Verschlüsselung ist WEP.

Gruß CHWurst


Alt 15.09.2010, 21:06   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



Zitat:
Verschlüsselung ist WEP.
Solltest Du dringend ändern. WEP kann man binnen wenigen Minuten knacken. Stell die Verschlüsselung über eine kabelgebundene Verbindung zum Router ein. Lass die von hier => Generate a Secure Password - kurtm.net einen 63-Zeichen Key generieren und trage diesen als WPA-Schlüssel im Router ein. Den Schlüssel als Textdatei auf einem Stick speichern, damit Du den auf die WLAN-Endgeräte übertragen kannst.
__________________
--> Unbekannte Internetseiten in der Chronik

Alt 15.09.2010, 21:17   #7
CHWurst
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



Was hatte den jetzt der Scan ergeben?
Ist es denn möglich das es ein Hacker war oder das jemand an meinem PC war? Da es laut der Chronik erst in der neuen Wohnung die ich im Februar bezogen habe angefangen hat.

Gruß CHWurst

Alt 15.09.2010, 21:19   #8
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



Ja, bei WEP ist das möglich. Kümmer die Dich erstmal um die Verschlüsselung!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 15.09.2010, 21:22   #9
CHWurst
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



Okay mache ich !

Danke erstmal und schönen Abend noch!

Gruß CHWurst

Alt 16.09.2010, 20:14   #10
CHWurst
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



Hallo cosinus,

habe den Code und die Verschlüsselung geändert.
Kann ich noch was tun oder einfach nur abwarten ob das nochmal vorkommt?

Gruß CHWurst

Alt 16.09.2010, 20:24   #11
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:
ATTFilter
:OTL
O20 - AppInit_DLLs: (zipfldra.dll) -  File not found
O33 - MountPoints2\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\Shell - "" = AutoRun
O33 - MountPoints2\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\Shell\AutoRun\command - "" = I:\Startme.exe -- File not found
[2010.09.15 21:09:36 | 000,139,264 | ---- | C] (man-tech.de) -- C:\Windows\SysWow64\ssMail.dll
:Commands
[purity]
[resethosts]
[emptytemp]
         
Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 16.09.2010, 20:36   #12
CHWurst
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



So hier der bericht!


All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:zipfldra.dll deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\ not found.
File I:\Startme.exe not found.
C:\Windows\SysWOW64\ssMail.dll moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Anni
->Temp folder emptied: 6293031 bytes
->Temporary Internet Files folder emptied: 192538188 bytes
->Java cache emptied: 45519367 bytes
->FireFox cache emptied: 112999840 bytes
->Flash cache emptied: 44403 bytes

User: AppData

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Mcx1-WURST-PC
->Temp folder emptied: 516 bytes
->Temporary Internet Files folder emptied: 34866214 bytes

User: Public

User: Wurst
->Temp folder emptied: 103956494 bytes
->Temporary Internet Files folder emptied: 98600 bytes
->Java cache emptied: 7560216 bytes
->FireFox cache emptied: 94562697 bytes
->Flash cache emptied: 5506 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 1564672 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 366848 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 573,00 mb


OTL by OldTimer - Version 3.2.12.1 log created on 09162010_212800

Files\Folders moved on Reboot...
C:\Users\Wurst\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\logishrd\LVPrcInj02.dll scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Alt 16.09.2010, 20:37   #13
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Starte bitte die OTL.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Kopiere nun den Inhalt in die Textbox.
Code:
ATTFilter
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT
         
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Klick auf .
  • Kopiere nun den Inhalt aus OTL.txt hier in Deinen Thread
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 16.09.2010, 20:57   #14
CHWurst
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



So hier der nächste Bericht.OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 16.09.2010 21:41:39 - Run 2
OTL by OldTimer - Version 3.2.12.1     Folder = C:\Users\Wurst\Desktop
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
6,00 Gb Total Physical Memory | 5,00 Gb Available Physical Memory | 79,00% Memory free
12,00 Gb Paging File | 11,00 Gb Available in Paging File | 89,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 48,74 Gb Total Space | 18,10 Gb Free Space | 37,15% Space Free | Partition Type: NTFS
Drive D: | 186,31 Gb Total Space | 98,83 Gb Free Space | 53,05% Space Free | Partition Type: NTFS
Drive E: | 97,66 Gb Total Space | 8,84 Gb Free Space | 9,05% Space Free | Partition Type: NTFS
Drive F: | 39,80 Gb Total Space | 25,86 Gb Free Space | 64,98% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: WURST-PC
Current User Name: Wurst
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Wurst\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\MCE Standby Tool\mst.exe (Herman van Eijk)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
PRC - C:\Programme\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Wurst\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (LVPrcS64) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) -- C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (NIS) -- C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_64) -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (Transcode360) -- C:\Program Files (x86)\Transcode360\Transcode360.exe (Transcode 360)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64j.sys File not found
DRV:64bit: - (upperdev) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64.sys File not found
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys File not found
DRV:64bit: - (nmwcdx64) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys File not found
DRV:64bit: - (nmwcdnsux64) -- C:\Windows\SysNative\drivers\nmwcdnsux64.sys File not found
DRV:64bit: - (nmwcdnsucx64) -- C:\Windows\SysNative\drivers\nmwcdnsucx64.sys File not found
DRV:64bit: - (nmwcdcx64) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys File not found
DRV:64bit: - (hwinterface) -- C:\Windows\SysNative\Drivers\hwinterface.sys File not found
DRV:64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (seehcri) -- C:\Windows\SysNative\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggsemc) -- C:\Windows\SysNative\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggflt) -- C:\Windows\SysNative\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (netr7364) -- C:\Windows\SysNative\drivers\netr7364.sys (Ralink Technology, Corp.)
DRV:64bit: - (cxbu0x64) -- C:\Windows\SysNative\drivers\cxbu0x64.sys (HID Global Corporation)
DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (LVPr2Mon) -- C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (LVPr2M64) -- C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (BthAvrcp) -- C:\Windows\SysNative\drivers\BthAvrcp.sys (CSR, plc)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (vmbus) -- C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) -- C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) -- C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (s3cap) -- C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) -- C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (VClone) -- C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) -- C:\Windows\SysNative\drivers\LV302V64.SYS (Logitech Inc.)
DRV:64bit: - (LVUSBS64) -- C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.)
DRV:64bit: - (sfvfs02) StarForce Protection VFS Driver (version 2.x) -- C:\Windows\SysNative\drivers\sfvfs02.sys (Protection Technology)
DRV:64bit: - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\SysNative\drivers\sfdrv01.sys (Protection Technology)
DRV:64bit: - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\SysNative\drivers\sfhlp02.sys (Protection Technology)
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100916.002\ex64.sys (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100916.002\eng64.sys (Symantec Corporation)
DRV - (BHDrvx64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20100901.003\BHDrvx64.sys (Symantec Corporation)
DRV - (hwinterface) -- C:\Windows\SysWOW64\drivers\hwinterface.sys (Buzz)
DRV - (gdrv) -- C:\Windows\gdrv.sys (Windows (R) Server 2003 DDK provider)
DRV - (IDSVia64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20100914.003\IDSviA64.sys (Symantec Corporation)
DRV - ({B154377D-700F-42cc-9474-23858FBDF4BD}) -- C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl (CyberLink Corp.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 40 DC D7 F6 55 4C CB 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultthis.engineName: "Winload Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.startup.homepage: "hxxp://www.bild.de/"
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.1.0625
FF - prefs.js..extensions.enabledItems: DeviceDetection@logitech.com:1.0.176.0
FF - prefs.js..extensions.enabledItems: {fd639891-5cc6-45ae-9055-a7a6abb5a7a9}:1.2.11.0
FF - prefs.js..extensions.enabledItems: cfxHelper@Triton:1.2
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: finder@meingutscheincode.de:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: extension@virtusdesigns.com:3.6.6
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:5.1
FF - prefs.js..extensions.enabledItems: {3ffb7be0-8bde-11de-8a39-0800200c9a66}:3.6.05.02.10
FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.6.6
FF - prefs.js..extensions.enabledItems: cfxe@Triton:3.6.5
FF - prefs.js..extensions.enabledItems: {12bc3590-67a6-11de-8a39-0800200c9a66}:3.6
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&q="
FF - prefs.js..network.proxy.type: 4
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2010.09.16 19:47:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\ [2010.09.16 19:46:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.09.16 16:50:34 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.09.16 16:50:34 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b4\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 4\components [2010.08.31 18:40:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b4\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 4\plugins
 
[2010.02.21 09:23:32 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Extensions
[2010.09.16 21:34:02 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions
[2010.02.21 16:43:14 | 000,000,000 | ---D | M] (Eclipse) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}
[2010.02.21 16:38:35 | 000,000,000 | ---D | M] (Purple Fox) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{3ffb7be0-8bde-11de-8a39-0800200c9a66}
[2010.08.19 17:31:29 | 000,000,000 | ---D | M] (Aero Fox XL) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
[2010.06.28 19:09:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010.08.19 17:31:33 | 000,000,000 | ---D | M] (Yoono) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{d9284e50-81fc-11da-a72b-0800200c9a66}
[2010.02.21 13:57:53 | 000,000,000 | ---D | M] (SEB Chipcard Plugin) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{fd639891-5cc6-45ae-9055-a7a6abb5a7a9}
[2010.06.28 19:09:35 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\cfxe@Triton
[2010.06.28 19:09:39 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\cfxHelper@Triton
[2010.02.21 13:39:01 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\DeviceDetection@logitech.com
[2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com
[2010.07.26 18:41:19 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\finder@meingutscheincode.de
[2010.05.22 20:04:12 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\personas@christopher.beard
[2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com\__MACOSX
[2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com\chrome
[2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com\defaults
[2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\mac\browser\extensions
[2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\mac\mozapps\extensions
[2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\win\browser\extensions
[2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\win\mozapps\extensions
[2010.08.19 17:31:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\mac\mozapps\extensions
[2010.08.19 17:31:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\win\mozapps\extensions
[2010.03.24 16:13:02 | 000,000,917 | ---- | M] () -- C:\Users\Wurst\AppData\Roaming\Mozilla\FireFox\Profiles\nikwlstw.default\searchplugins\conduit.xml
[2010.09.16 20:50:43 | 000,002,443 | ---- | M] () -- C:\Users\Wurst\AppData\Roaming\Mozilla\FireFox\Profiles\nikwlstw.default\searchplugins\safesearch.xml
[2010.08.19 09:19:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions
[2010.05.23 10:51:28 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.08.19 09:19:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.07.17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010.04.03 14:51:17 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.04.03 14:51:17 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.04.03 14:51:17 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.04.03 14:51:17 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.04.03 14:51:17 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010.09.16 21:28:01 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1       localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\IPSBHO.DLL (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [InstantBurn] C:\PROGRA~2\CYBERL~1\INSTAN~1\Win2K\IBurn.exe (CyberLink Corporation.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [MCE Standby Tool] C:\Program Files (x86)\MCE Standby Tool\mst.exe (Herman van Eijk)
O4 - HKLM..\Run: [PDVD9LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl9] C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe (Logitech Inc.)
O4 - Startup: C:\Users\Wurst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\ScCertProp: DllName - Reg Error: Key error. -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
 
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 90 Days ==========
 
[2010.09.16 21:28:00 | 000,000,000 | ---D | C] -- C:\_OTL
[2010.09.16 21:26:48 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Wurst\Desktop\OTL.exe
[2010.09.16 20:16:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Symantec Shared
[2010.09.16 19:47:12 | 000,174,640 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010.09.16 19:47:11 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Symantec Shared
[2010.09.16 19:47:11 | 000,000,000 | ---D | C] -- C:\Programme\Symantec
[2010.09.16 19:46:45 | 000,381,488 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\symnets.sys
[2010.09.16 19:46:44 | 000,821,808 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA64.sys
[2010.09.16 19:46:44 | 000,715,824 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.sys
[2010.09.16 19:46:44 | 000,450,096 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymDS64.sys
[2010.09.16 19:46:44 | 000,040,496 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.sys
[2010.09.16 19:46:43 | 000,168,496 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Ironx64.sys
[2010.09.16 19:46:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NISx64
[2010.09.16 19:46:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NISx64\1201000.025
[2010.09.16 19:46:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Internet Security
[2010.09.16 19:46:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2010.09.16 19:46:05 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2010.09.16 19:46:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller
[2010.09.16 19:42:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner
[2010.09.15 21:46:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CamAlert
[2010.09.15 21:09:34 | 000,712,704 | ---- | C] (Fath Software ( www.fathsoft.com )) -- C:\Windows\SysWow64\csCapx.ocx
[2010.09.15 21:09:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CamSpy
[2010.09.15 17:37:42 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Malwarebytes
[2010.09.15 17:37:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.09.15 17:37:26 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010.09.15 17:37:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010.09.14 18:47:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010.09.14 18:47:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2010.09.14 18:35:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2010.09.13 17:52:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavalys
[2010.09.04 11:00:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2010.08.31 18:40:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 4
[2010.08.31 16:37:33 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Desktop\Tatoo
[2010.08.29 09:11:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2010.08.25 22:11:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2010.08.25 22:11:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2010.08.21 15:16:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SopCast
[2010.08.21 09:30:11 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\dvdcss
[2010.08.19 17:47:22 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\VirtualDubMod_1_5_10_2_All_inclusive
[2010.08.19 09:19:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2010.08.15 22:22:41 | 000,000,000 | ---D | C] -- C:\ProgramData\MetaBrowser 2.0
[2010.08.15 22:22:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MetaBrowser 2.0
[2010.08.13 20:46:35 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\DivX
[2010.08.13 20:45:52 | 000,000,000 | ---D | C] -- C:\Programme\DivX
[2010.08.13 20:45:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DivX Shared
[2010.08.13 20:45:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DivX
[2010.08.13 20:44:51 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2010.08.13 20:43:05 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\VirtualDub-1.9.9
[2010.08.13 20:32:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PeckJoin
[2010.08.13 19:54:12 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\Any Video Converter
[2010.08.13 19:53:53 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\AnvSoft
[2010.08.13 19:53:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AnvSoft
[2010.08.13 18:19:04 | 000,000,000 | ---D | C] -- C:\ProgramData\GameEmu
[2010.08.13 18:19:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GameEmu
[2010.08.13 18:17:14 | 000,000,000 | ---D | C] -- C:\Programme\GameEmu
[2010.08.12 13:09:58 | 000,000,000 | ---D | C] -- C:\Roms
[2010.08.12 13:05:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Transcode360
[2010.08.12 12:23:31 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Push-A-Button
[2010.08.12 12:13:46 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Synchronization Services
[2010.08.12 12:13:46 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft SQL Server Compact Edition
[2010.08.12 12:11:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
[2010.08.12 12:11:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2010.08.12 11:06:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MCE Standby Tool
[2010.08.12 09:15:01 | 000,000,000 | ---D | C] -- C:\ProgramData\MediaBrowser
[2010.08.12 09:15:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MediaBrowser
[2010.08.12 09:10:42 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Movienizer
[2010.08.12 08:59:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Media Center Studio
[2010.08.12 08:58:42 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\Apps
[2010.08.12 08:58:41 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\Deployment
[2010.08.11 07:56:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2010.08.11 07:56:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2010.08.06 15:09:08 | 000,000,000 | ---D | C] -- C:\Windows\SQLTools9_KB970892_ENU
[2010.08.06 15:07:20 | 000,000,000 | ---D | C] -- C:\Windows\SQL9_KB970892_ENU
[2010.08.04 20:04:33 | 000,002,996 | ---- | C] (Buzz) -- C:\Windows\SysWow64\drivers\hwinterface.sys
[2010.08.04 19:30:07 | 000,000,000 | ---D | C] -- C:\Assets
[2010.08.04 19:25:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\gs
[2010.08.04 19:24:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KaraokeDX
[2010.08.04 19:24:51 | 001,339,824 | ---- | C] (Spesoft Ltd) -- C:\Windows\SysWow64\sysperxg.dll
[2010.08.04 19:13:12 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Desktop\N64
[2010.08.04 19:12:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Project64 1.6
[2010.08.04 18:17:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server
[2010.08.04 18:14:37 | 000,000,000 | ---D | C] -- C:\ProgramData\My Movies
[2010.08.03 19:52:10 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Desktop\MediaCenter
[2010.07.31 17:41:14 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\cache
[2010.07.31 11:10:45 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\Games for Windows - LIVE Demos
[2010.07.30 22:56:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Elaborate Bytes
[2010.07.28 19:10:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GIGABYTE
[2010.07.26 18:41:47 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\TBlauhut
[2010.07.26 18:41:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2010.07.25 13:54:54 | 000,000,000 | -H-D | C] -- C:\Users\Wurst\Documents\PDRMUSIC.TMP
[2010.07.25 13:53:54 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\Apple Computer
[2010.07.25 13:35:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\CyberLink
[2010.07.25 13:32:08 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\Apple
[2010.07.25 13:32:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2010.07.25 12:53:05 | 000,376,304 | ---- | C] (CyberLink Corporation.) -- C:\Windows\SysNative\drivers\CLBUDF.sys
[2010.07.25 12:53:03 | 000,024,560 | ---- | C] (Cyberlink Co.,Ltd.) -- C:\Windows\SysNative\drivers\CLBStor.sys
[2010.07.25 11:17:53 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\vlc
[2010.07.25 11:17:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2010.07.25 11:06:47 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\UseNeXT
[2010.07.25 11:06:47 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\UseNeXT
[2010.07.25 11:06:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\UseNeXT
[2010.07.24 17:31:32 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Ashampoo
[2010.07.24 17:27:43 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\ashampoo
[2010.07.24 17:27:43 | 000,000,000 | ---D | C] -- C:\ProgramData\ashampoo
[2010.07.24 17:27:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ashampoo
[2010.07.23 17:05:28 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\ImgBurn
[2010.07.23 17:04:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ImgBurn
[2010.07.21 17:50:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Elaborate Bytes
[2010.07.21 17:26:58 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\AnyDVDHD
[2010.07.21 17:26:48 | 000,000,000 | ---D | C] -- C:\ProgramData\SlySoft
[2010.06.27 12:29:37 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\OpenOffice.org
[2010.06.26 10:28:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2010.06.20 12:24:10 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\RCT3
[2010.06.20 12:24:10 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Atari
[2010.06.20 12:23:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PocketSoft
[2010.06.20 12:19:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Atari
[2010.06.20 10:41:43 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\Disco Tycoon
[2010.06.19 00:24:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2010.06.19 00:24:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2010.06.19 00:24:45 | 000,419,840 | ---- | C] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2010.06.19 00:24:45 | 000,413,696 | ---- | C] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2010.06.19 00:24:45 | 000,133,632 | ---- | C] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysNative\OpenAL32.dll
[2010.06.19 00:24:45 | 000,110,592 | ---- | C] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysWow64\OpenAL32.dll
[2010.06.19 00:24:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenAL
[2010.06.19 00:17:21 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Farm Mania 2
[2010.06.19 00:01:00 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\Schwimmbad Tycoon
[2010.06.18 23:45:17 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Desktop\Spiele
[2 C:\Users\Wurst\*.tmp files -> C:\Users\Wurst\*.tmp -> ]
[1 C:\Users\Wurst\Documents\*.tmp files -> C:\Users\Wurst\Documents\*.tmp -> ]
 
========== Files - Modified Within 90 Days ==========
 
[2010.09.16 21:43:07 | 002,621,440 | -HS- | M] () -- C:\Users\Wurst\ntuser.dat
[2010.09.16 21:39:41 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.09.16 21:39:41 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.09.16 21:32:18 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.09.16 21:32:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.09.16 21:31:12 | 004,922,099 | -H-- | M] () -- C:\Users\Wurst\AppData\Local\IconCache.db
[2010.09.16 21:28:01 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2010.09.16 21:26:50 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Wurst\Desktop\OTL.exe
[2010.09.16 21:19:14 | 000,069,906 | ---- | M] () -- C:\Users\Wurst\Documents\cc_20100916_211858.reg
[2010.09.16 19:47:56 | 001,165,798 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Cat.DB
[2010.09.16 19:47:11 | 000,174,640 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010.09.16 19:47:11 | 000,007,440 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010.09.16 19:47:11 | 000,000,854 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010.09.16 19:46:56 | 000,002,565 | ---- | M] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2010.09.16 19:42:54 | 000,001,011 | ---- | M] () -- C:\Users\Wurst\Desktop\CCleaner.lnk
[2010.09.14 18:55:01 | 000,419,251 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20100914-193846.backup
[2010.09.14 16:30:18 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010.09.14 16:30:18 | 000,653,928 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2010.09.14 16:30:18 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010.09.14 16:30:18 | 000,129,800 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2010.09.14 16:30:18 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010.08.25 22:11:17 | 000,001,845 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010.08.21 15:16:44 | 000,000,995 | ---- | M] () -- C:\Users\Wurst\Desktop\SopCast.lnk
[2010.08.19 18:08:17 | 000,001,861 | ---- | M] () -- C:\Users\Wurst\Desktop\UseNeXT.lnk
[2010.08.19 17:51:00 | 000,003,193 | ---- | M] () -- C:\Users\Wurst\Desktop\VirtualDub.lnk
[2010.08.19 17:50:50 | 000,004,068 | ---- | M] () -- C:\Users\Wurst\Desktop\VirtualDubMod.lnk
[2010.08.18 16:05:20 | 000,000,172 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\isolate.ini
[2010.08.15 22:22:42 | 000,002,027 | ---- | M] () -- C:\Users\Wurst\Desktop\MetaBrowser 2.0.lnk
[2010.08.13 19:53:59 | 000,001,138 | ---- | M] () -- C:\Users\Wurst\Desktop\Any Video Converter.lnk
[2010.08.12 14:54:29 | 000,300,152 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010.08.12 13:57:49 | 000,068,040 | ---- | M] () -- C:\Users\Wurst\AppData\Local\GDIPFONTCACHEV1.DAT
[2010.08.12 12:57:45 | 000,001,254 | ---- | M] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk
[2010.08.12 12:55:24 | 001,551,928 | ---- | M] () -- C:\Program Files (x86)\SetupVirtualCloneDrive.exe
[2010.08.12 12:55:23 | 000,770,938 | ---- | M] () -- C:\Program Files (x86)\KaraokeSetup.exe
[2010.08.12 12:53:52 | 083,267,584 | ---- | M] () -- C:\ProgramData\arcade.mp3
[2010.08.12 12:09:57 | 000,000,101 | ---- | M] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2010.08.12 09:41:06 | 000,000,410 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2010.08.09 11:28:14 | 000,000,125 | -HS- | M] () -- C:\ProgramData\.zreglib
[2010.08.07 01:21:29 | 000,000,000 | -H-- | M] () -- C:\Users\Wurst\Documents\Default.rdp
[2010.08.07 00:56:32 | 000,000,375 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.ics
[2010.08.06 15:08:06 | 001,526,060 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.08.04 20:04:33 | 000,002,996 | ---- | M] (Buzz) -- C:\Windows\SysWow64\drivers\hwinterface.sys
[2010.07.30 22:56:21 | 000,001,203 | ---- | M] () -- C:\Users\Public\Desktop\CloneDVD2.lnk
[2010.07.30 21:00:08 | 001,339,824 | ---- | M] (Spesoft Ltd) -- C:\Windows\SysWow64\sysperxg.dll
[2010.07.29 05:33:05 | 000,821,808 | R--- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA64.sys
[2010.07.29 05:33:05 | 000,007,412 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA64.cat
[2010.07.29 05:33:05 | 000,003,373 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA.inf
[2010.07.29 04:54:37 | 000,715,824 | R--- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.sys
[2010.07.29 04:54:37 | 000,040,496 | R--- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.sys
[2010.07.29 04:54:37 | 000,007,414 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.cat
[2010.07.29 04:54:37 | 000,001,422 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.inf
[2010.07.29 04:54:36 | 000,007,410 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.cat
[2010.07.29 04:54:36 | 000,001,438 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.inf
[2010.07.27 18:25:38 | 000,001,239 | ---- | M] () -- C:\Users\Wurst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010.07.25 13:37:50 | 000,002,026 | ---- | M] () -- C:\Users\Public\Desktop\CyberLink Media Suite.lnk
[2010.07.24 18:00:03 | 000,000,727 | ---- | M] () -- C:\Users\Wurst\Documents\My Photos.mfalist
[2010.07.24 17:31:45 | 000,005,632 | ---- | M] () -- C:\Users\Wurst\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.07.24 17:27:42 | 000,001,119 | ---- | M] () -- C:\Users\Public\Desktop\Ashampoo Photo Commander 7.lnk
[2010.07.22 03:27:14 | 000,007,410 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\symnet64.cat
[2010.07.13 03:20:22 | 000,381,488 | R--- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\symnets.sys
[2010.07.13 03:20:00 | 000,001,445 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymNet.inf
[2010.07.13 02:50:50 | 000,007,402 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\iron.cat
[2010.06.27 06:05:55 | 000,168,496 | R--- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Ironx64.sys
[2010.06.27 06:05:55 | 000,000,771 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Iron.inf
[2010.06.19 00:24:45 | 000,419,840 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2010.06.19 00:24:45 | 000,413,696 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2010.06.19 00:24:45 | 000,133,632 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysNative\OpenAL32.dll
[2010.06.19 00:24:45 | 000,110,592 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysWow64\OpenAL32.dll
[2 C:\Users\Wurst\*.tmp files -> C:\Users\Wurst\*.tmp -> ]
[1 C:\Users\Wurst\Documents\*.tmp files -> C:\Users\Wurst\Documents\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010.09.16 21:19:02 | 000,069,906 | ---- | C] () -- C:\Users\Wurst\Documents\cc_20100916_211858.reg
[2010.09.16 19:47:17 | 001,165,798 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Cat.DB
[2010.09.16 19:47:12 | 000,007,440 | ---- | C] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010.09.16 19:47:12 | 000,000,854 | ---- | C] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010.09.16 19:46:56 | 000,002,565 | ---- | C] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2010.09.16 19:46:32 | 000,003,373 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA.inf
[2010.09.16 19:46:32 | 000,002,792 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymDS.inf
[2010.09.16 19:46:32 | 000,001,445 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymNet.inf
[2010.09.16 19:46:32 | 000,001,438 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.inf
[2010.09.16 19:46:32 | 000,001,422 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.inf
[2010.09.16 19:46:32 | 000,000,771 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Iron.inf
[2010.09.16 19:46:25 | 000,007,414 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.cat
[2010.09.16 19:46:25 | 000,007,412 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA64.cat
[2010.09.16 19:46:25 | 000,007,410 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\symnet64.cat
[2010.09.16 19:46:25 | 000,007,410 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.cat
[2010.09.16 19:46:25 | 000,007,406 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymDS64.cat
[2010.09.16 19:46:25 | 000,007,402 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\iron.cat
[2010.09.16 19:46:25 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\isolate.ini
[2010.09.16 19:42:54 | 000,001,011 | ---- | C] () -- C:\Users\Wurst\Desktop\CCleaner.lnk
[2010.08.25 22:11:17 | 000,001,845 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010.08.21 15:16:44 | 000,000,995 | ---- | C] () -- C:\Users\Wurst\Desktop\SopCast.lnk
[2010.08.19 17:51:00 | 000,003,193 | ---- | C] () -- C:\Users\Wurst\Desktop\VirtualDub.lnk
[2010.08.19 17:50:50 | 000,004,068 | ---- | C] () -- C:\Users\Wurst\Desktop\VirtualDubMod.lnk
[2010.08.15 22:22:42 | 000,002,027 | ---- | C] () -- C:\Users\Wurst\Desktop\MetaBrowser 2.0.lnk
[2010.08.13 20:32:32 | 000,037,376 | ---- | C] () -- C:\Windows\SysWow64\VbVfw.dll
[2010.08.13 19:53:59 | 000,001,138 | ---- | C] () -- C:\Users\Wurst\Desktop\Any Video Converter.lnk
[2010.08.12 12:53:05 | 083,267,584 | ---- | C] () -- C:\ProgramData\arcade.mp3
[2010.08.12 12:09:57 | 000,000,101 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2010.08.07 01:21:29 | 000,000,000 | -H-- | C] () -- C:\Users\Wurst\Documents\Default.rdp
[2010.08.04 19:26:51 | 000,001,254 | ---- | C] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk
[2010.08.04 19:24:32 | 001,551,928 | ---- | C] () -- C:\Program Files (x86)\SetupVirtualCloneDrive.exe
[2010.08.04 19:24:31 | 000,770,938 | ---- | C] () -- C:\Program Files (x86)\KaraokeSetup.exe
[2010.08.03 19:51:25 | 000,000,410 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010.07.30 22:56:21 | 000,001,203 | ---- | C] () -- C:\Users\Public\Desktop\CloneDVD2.lnk
[2010.07.27 18:25:38 | 000,001,239 | ---- | C] () -- C:\Users\Wurst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010.07.25 13:37:50 | 000,002,026 | ---- | C] () -- C:\Users\Public\Desktop\CyberLink Media Suite.lnk
[2010.07.25 12:52:49 | 000,000,177 | ---- | C] () -- C:\ProgramData\Temp.log
[2010.07.25 11:06:39 | 000,001,861 | ---- | C] () -- C:\Users\Wurst\Desktop\UseNeXT.lnk
[2010.07.24 18:00:03 | 000,000,727 | ---- | C] () -- C:\Users\Wurst\Documents\My Photos.mfalist
[2010.07.24 17:27:42 | 000,001,119 | ---- | C] () -- C:\Users\Public\Desktop\Ashampoo Photo Commander 7.lnk
[2010.07.21 17:26:48 | 000,000,125 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010.06.20 12:23:16 | 000,197,120 | ---- | C] () -- C:\Windows\patchw32.dll
[2010.05.02 08:03:03 | 000,005,632 | ---- | C] () -- C:\Users\Wurst\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.02 07:36:34 | 001,526,060 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.04.02 17:17:34 | 000,179,091 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010.03.06 12:09:17 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\vbzlib1.dll
[2010.02.21 09:14:58 | 000,005,224 | ---- | C] () -- C:\Windows\SysWow64\ucuiinfo.ini
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[1998.07.06 00:00:00 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\MSCC2DE.DLL
 
========== LOP Check ==========
 
[2010.08.13 19:53:53 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\AnvSoft
[2010.07.24 17:31:32 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Ashampoo
[2010.06.20 12:24:10 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Atari
[2010.02.21 14:06:47 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\DAEMON Tools Lite
[2010.03.06 12:09:34 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Desktopicon
[2010.06.22 19:18:37 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Farm Mania 2
[2010.07.23 18:23:35 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\ImgBurn
[2010.02.21 13:46:01 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Leadertech
[2010.08.12 09:14:02 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Movienizer
[2010.05.02 08:04:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Nokia
[2010.06.27 12:29:37 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\OpenOffice.org
[2010.05.02 08:08:00 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\PC Suite
[2010.04.04 15:39:41 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\PoBros
[2010.08.12 12:23:31 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Push-A-Button
[2010.09.16 19:44:49 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\UseNeXT
[2010.09.16 21:27:40 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\uTorrent
[2010.06.18 19:39:21 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\V-Games
[2010.07.21 17:36:35 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.03.13 18:20:34 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Adobe
[2010.08.13 19:53:53 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\AnvSoft
[2010.07.24 17:31:32 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Ashampoo
[2010.06.20 12:24:10 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Atari
[2010.07.25 20:03:32 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\CyberLink
[2010.02.21 14:06:47 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\DAEMON Tools Lite
[2010.03.06 12:09:34 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Desktopicon
[2010.09.04 08:14:48 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\DivX
[2010.08.21 09:30:11 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\dvdcss
[2010.06.22 19:18:37 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Farm Mania 2
[2010.02.21 09:11:04 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Identities
[2010.07.23 18:23:35 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\ImgBurn
[2010.02.21 09:14:38 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\InstallShield
[2010.02.21 13:46:01 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Leadertech
[2010.02.21 09:41:49 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Macromedia
[2010.09.15 17:37:42 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Malwarebytes
[2010.08.12 14:58:38 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Media Center Programs
[2010.08.04 19:12:35 | 000,000,000 | --SD | M] -- C:\Users\Wurst\AppData\Roaming\Microsoft
[2010.08.12 09:14:02 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Movienizer
[2010.02.21 09:23:32 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Mozilla
[2010.05.02 08:04:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Nokia
[2010.06.27 12:29:37 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\OpenOffice.org
[2010.05.02 08:08:00 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\PC Suite
[2010.04.04 15:39:41 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\PoBros
[2010.08.12 12:23:31 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Push-A-Button
[2010.09.16 19:44:49 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\UseNeXT
[2010.09.16 21:27:40 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\uTorrent
[2010.06.18 19:39:21 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\V-Games
[2010.07.25 11:17:56 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\vlc
[2010.05.22 22:53:14 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2010.03.06 12:09:34 | 000,031,836 | ---- | M] () -- C:\Users\Wurst\AppData\Roaming\Desktopicon\uninst.exe
[2010.08.15 22:22:42 | 000,064,712 | R--- | M] () -- C:\Users\Wurst\AppData\Roaming\Microsoft\Installer\{4902F8E1-B2DC-488C-AEBB-96548B832ED5}\_1B184F214272163F6CA0F7.exe
[2010.08.15 22:22:41 | 000,064,712 | R--- | M] () -- C:\Users\Wurst\AppData\Roaming\Microsoft\Installer\{4902F8E1-B2DC-488C-AEBB-96548B832ED5}\_2495CA173BFDFFE1C83747.exe
[2010.08.15 22:22:41 | 000,064,712 | R--- | M] () -- C:\Users\Wurst\AppData\Roaming\Microsoft\Installer\{4902F8E1-B2DC-488C-AEBB-96548B832ED5}\_6FEFF9B68218417F98F549.exe
[2010.08.04 19:12:35 | 000,040,960 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Wurst\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
[2010.08.04 19:12:35 | 000,040,960 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Wurst\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
[2010.08.04 19:12:35 | 000,008,854 | R--- | M] () -- C:\Users\Wurst\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\Uninstall_Project64__9559F7CA5E344237A2D9D856464AD727.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2008.06.06 14:03:52 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
< End of report >
         
--- --- ---

Alt 17.09.2010, 09:09   #15
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Unbekannte Internetseiten in der Chronik - Standard

Unbekannte Internetseiten in der Chronik



Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!
__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu Unbekannte Internetseiten in der Chronik
chronik, code, einzelne, firefox, folge, folgender, geschlossen, hacker, hallo zusammen, heute, interne, internetseite, internetseiten, kostenlose, neu, router, schön, seite, seiten, stelle, stellige, thema, unbekannte, videos, wlan, zusammen




Ähnliche Themen: Unbekannte Internetseiten in der Chronik


  1. verdächtiger Link in Browser-Chronik
    Plagegeister aller Art und deren Bekämpfung - 08.11.2015 (9)
  2. Sandboxie - Firefox Lesenzeichen,Chronik...usw.
    Antiviren-, Firewall- und andere Schutzprogramme - 17.02.2015 (0)
  3. Unbekannte Programme auf dem PC!
    Plagegeister aller Art und deren Bekämpfung - 17.08.2014 (6)
  4. Unbekannte Dateien im Downloadordner und unbekannte Programme auf dem Desktop
    Plagegeister aller Art und deren Bekämpfung - 01.12.2013 (11)
  5. Facebook Chronik
    Überwachung, Datenschutz und Spam - 04.04.2012 (2)
  6. Wie in Firefox 4 Chronik löschen
    Alles rund um Windows - 16.04.2011 (9)
  7. IE öffnet unbedient mir unbekannte Internetseiten
    Log-Analyse und Auswertung - 26.02.2010 (9)
  8. Firefox und Chronik
    Diskussionsforum - 11.01.2010 (3)
  9. unbekannte Prozesse
    Plagegeister aller Art und deren Bekämpfung - 08.11.2009 (1)
  10. Unbekannte dll's
    Log-Analyse und Auswertung - 30.04.2009 (43)
  11. Unbekannte Schadsoftware
    Log-Analyse und Auswertung - 02.01.2009 (0)
  12. Unbekannte Seiten in der Chronik
    Plagegeister aller Art und deren Bekämpfung - 17.10.2008 (8)
  13. unbekannte Prozesse
    Mülltonne - 16.07.2006 (1)
  14. Unbekannte Dateien
    Log-Analyse und Auswertung - 23.11.2005 (1)
  15. Unbekannte Datei: JET*.tmp
    Plagegeister aller Art und deren Bekämpfung - 04.03.2005 (4)
  16. Unbekannte Dateien
    Plagegeister aller Art und deren Bekämpfung - 10.02.2005 (10)
  17. Unbekannte Dateien
    Plagegeister aller Art und deren Bekämpfung - 09.02.2005 (1)

Zum Thema Unbekannte Internetseiten in der Chronik - Hallo zusammen, ich bin neu hier und habe von der ganzen Thematik keine Ahnung. Als ich heute in die Chronik meines Firefox guckte musste ich feststellen das jemand auf Pornografische - Unbekannte Internetseiten in der Chronik...
Archiv
Du betrachtest: Unbekannte Internetseiten in der Chronik auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.