| ![]() Unbekannte Internetseiten in der Chronik Hallo zusammen, ich bin neu hier und habe von der ganzen Thematik keine Ahnung. Als ich heute in die Chronik meines Firefox guckte musste ich feststellen das jemand auf Pornografische Internetseiten war. Die Chronik sieht folgender maßen aus: Google-such begriff "kostenlose sex videos" und dann die einzelnen seiten samt Videos schön durch geklickt. Das ganze seit 5 Monaten aber immer nur ein Tag pro Monat. Der PC ist per WLAN am Router angeschlossen und mit ein 10 stelligen Code gesichert. Ist es möglich das es ein Hacker ist? Oder geht das nur von meinem PC aus. Gruß CHWurst |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Unbekannte Internetseiten in der ChronikZitat:
Bitte auch routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
| ![]() Unbekannte Internetseiten in der Chronik Hallo cosinus,
__________________so habe jetzt alles gemacht wie du es mir beschrieben hast. Und hier die logs: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4621 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 15.09.2010 21:17:29 mbam-log-2010-09-15 (21-17-29).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|) Durchsuchte Objekte: 357716 Laufzeit: 1 Stunde(n), 49 Minute(n), 34 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 1 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Casino\William Hill CASINO CLUB\_SetupCasino_d8628f_de.exe (Adware.Casino) -> No action taken. _________________________________________________________________OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 15.09.2010 21:19:47 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Wurst\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 6,00 Gb Total Physical Memory | 4,00 Gb Available Physical Memory | 64,00% Memory free 12,00 Gb Paging File | 10,00 Gb Available in Paging File | 80,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 48,74 Gb Total Space | 12,35 Gb Free Space | 25,33% Space Free | Partition Type: NTFS Drive D: | 186,31 Gb Total Space | 100,20 Gb Free Space | 53,78% Space Free | Partition Type: NTFS Drive E: | 97,66 Gb Total Space | 8,84 Gb Free Space | 9,05% Space Free | Partition Type: NTFS Drive F: | 39,80 Gb Total Space | 25,96 Gb Free Space | 65,21% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: WURST-PC Current User Name: Wurst Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [dm Fotowelt] -- "C:\Program Files (x86)\dm\dm Fotowelt\dm Fotowelt.exe" "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [dm Fotowelt] -- "C:\Program Files (x86)\dm\dm Fotowelt\dm Fotowelt.exe" "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 "{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2 "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{77CB2F9F-67C5-4ADA-9321-B30C9C64727E}" = Microsoft SQL Server Compact 3.5 SP1 x64 (Deutsch) "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{987FE247-4E69-4A2E-A961-D14F901FDBF6}" = Logitech Webcam Software "{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64 "{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "lvdrivers_12.10" = Logitech Webcam Software-Treiberpaket "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "NVIDIA Display Control Panel" = NVIDIA Display Control Panel "NVIDIA Drivers" = NVIDIA Drivers "WinRAR archiver" = WinRAR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{0C8EBB00-4909-459C-8347-B2068B7F0319}" = CyberLink DVD Menu Template Pack "{19C64880-BBCA-11D4-9EEE-0004ACDDDB3B}" = CyberLink InstantBurn "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{2217B0B4-35CB-48C6-B640-864DF2F30F99}" = OpenOffice.org 3.2 "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 21 "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}" = CyberLink WaveEditor "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis "{4902F8E1-B2DC-488C-AEBB-96548B832ED5}" = meta<browser/> 2.0 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update "{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable "{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon 3 "{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker "{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9 "{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support "{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.4 - Deutsch "{ADD5DB49-72CF-11D8-9D75-000129760D75}" = CyberLink PowerBackup "{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger "{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86 "{B132E67C-EEA5-492B-B368-543CD88D8569}" = AnyDVD Registration "{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer "{BFC218D7-5BCA-41A1-B585-E75E1DCD56A6}" = Media Browser "{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint "{C69405BB-27AF-4940-B3DA-04910B4DFD23}_is1" = aTube Catcher 1.0 "{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call "{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow "{D3829204-8035-4C55-826D-01BEBBA43B26}" = GameEmu "{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker "{E10DB5DA-E576-40EA-A7FC-1CB2A7B283A6}" = NVIDIA PhysX "{E3D04529-6EDB-11D8-A372-0050BAE317E1}" = CyberLink PowerDVD Copy "{E5BD7FEB-28BF-4EF2-82FB-C7360B563A75}_is1" = MCE Standby Tool 0.9.099 "{EA926717-CE5A-4CB4-AB21-9E6E9565A458}" = RCT3 Soaked "{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F3759A9F-7AFA-4FB4-8DF1-53F26B979DEE}" = Belkin 54Mbps Wireless Network Adapter "{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE "{FA440BE8-EC2F-4478-A01A-077DA0606501}" = Microsoft SQL Server Compact 3.5 SP1 (Deutsch) "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.5 "Any Video Converter_is1" = Any Video Converter 3.0.7 "Ashampoo Photo Commander 7_is1" = Ashampoo Photo Commander 7.50 "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "CamSpy_is1" = CamSpy V.3.6.4 "Clean Virus MSN_is1" = Clean Virus MSN "CloneDVD2" = CloneDVD2 "DivX Setup.divx.com" = DivX-Setup "dm Fotowelt" = dm Fotowelt "eBay Icon" = eBay Icon "Emsisoft Anti-Malware_is1" = Emsisoft Anti-Malware 5.0 "eMule" = eMule "ImgBurn" = ImgBurn "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite "InstallShield_{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}" = CyberLink WaveEditor "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow "InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9 "InstallShield_{ADD5DB49-72CF-11D8-9D75-000129760D75}" = CyberLink PowerBackup "InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow "InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}" = CyberLink PowerDVD Copy "KaraokeDX" = Karaoke for DirectX (remove only) "Karaoke-DX" = Karaoke for DirectX (remove only) "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Morphyre" = Morphyre "Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9) "Mozilla Firefox (4.0b4)" = Mozilla Firefox (4.0b4) "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "OpenAL" = OpenAL "SopCast" = SopCast 3.2.9 "ST4UNST #1" = Peck's Power Join "Transcode360" = Transcode 360 for Windows Vista "Update Service" = Update Service "UseNeXT_is1" = UseNeXT "uTorrent" = µTorrent "VirtualCloneDrive" = VirtualCloneDrive "VLC media player" = VLC media player 0.9.9 "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "f58cbb372ebb2ec8" = Media Center Studio "William Hill CASINO CLUB" = William Hill CASINO CLUB ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 11.09.2010 04:51:37 | Computer Name = Wurst-PC | Source = SideBySide | ID = 16842787 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile 8. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error - 12.09.2010 04:19:06 | Computer Name = Wurst-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error - 12.09.2010 05:09:19 | Computer Name = Wurst-PC | Source = SideBySide | ID = 16842787 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile 8. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error - 13.09.2010 03:40:22 | Computer Name = Wurst-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error - 13.09.2010 07:06:25 | Computer Name = Wurst-PC | Source = SideBySide | ID = 16842787 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile 8. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error - 14.09.2010 01:46:21 | Computer Name = Wurst-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error - 14.09.2010 14:17:47 | Computer Name = Wurst-PC | Source = Application Hang | ID = 1002 Description = Programm HiJackThis.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 294 Startzeit: 01cb54391395d270 Endzeit: 92 Anwendungspfad: C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe Berichts-ID: 5d848c51-c02c-11df-a382-001a4d8507b4 Error - 15.09.2010 03:11:35 | Computer Name = Wurst-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error - 15.09.2010 03:38:59 | Computer Name = Wurst-PC | Source = SideBySide | ID = 16842787 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile 8. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error - 15.09.2010 03:39:28 | Computer Name = Wurst-PC | Source = SideBySide | ID = 16842815 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\spybot - search & destroy\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program files (x86)\spybot - search & destroy\DelZip179.dll" in Zeile 8. Der Wert "*" des "language"-Attributs im assemblyIdentity-Element ist ungültig. [ Media Center Events ] Error - 06.08.2010 19:30:26 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538 Description = Error - 06.08.2010 19:31:31 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538 Description = Error - 06.08.2010 19:33:57 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538 Description = Error - 06.08.2010 19:40:28 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538 Description = Error - 06.08.2010 19:45:31 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 543 Description = Error - 07.08.2010 06:10:01 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538 Description = Error - 07.08.2010 06:18:49 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538 Description = Error - 12.08.2010 03:30:59 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538 Description = Error - 12.08.2010 03:34:36 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538 Description = Error - 12.08.2010 03:41:06 | Computer Name = Wurst-PC | Source = Microsoft-Windows-Media Center Extender | ID = 538 Description = [ System Events ] Error - 31.07.2010 05:07:07 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 610 Description = Error - 31.07.2010 05:07:08 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 610 Description = Error - 31.07.2010 09:40:20 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 602 Description = Error - 01.08.2010 02:46:32 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 602 Description = Error - 01.08.2010 08:08:48 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 602 Description = Error - 01.08.2010 08:52:00 | Computer Name = Wurst-PC | Source = volsnap | ID = 393252 Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error - 01.08.2010 09:51:14 | Computer Name = Wurst-PC | Source = DCOM | ID = 10010 Description = Error - 02.08.2010 03:44:22 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 602 Description = Error - 02.08.2010 10:01:36 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 602 Description = Error - 03.08.2010 03:32:18 | Computer Name = Wurst-PC | Source = SCardSvr | ID = 602 Description = [ Transcode360 Service Events ] Error - 12.08.2010 07:19:27 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0 Description = Transcoding error: Error - 12.08.2010 07:19:27 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0 Description = WARNING: OUTPUT FILE FORMAT IS _MPEG_. See -of help. ============ Sorry, this file format is not recognized/supported ============= === If this file is an AVI, ASF or MPEG stream, please contact the author! === Cannot open demuxer. Error - 12.08.2010 07:19:53 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0 Description = Transcoding error: Error - 12.08.2010 07:19:53 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0 Description = WARNING: OUTPUT FILE FORMAT IS _MPEG_. See -of help. ============ Sorry, this file format is not recognized/supported ============= === If this file is an AVI, ASF or MPEG stream, please contact the author! === Cannot open demuxer. Error - 12.08.2010 07:21:04 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0 Description = Transcoding error: Error - 12.08.2010 07:21:04 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0 Description = WARNING: OUTPUT FILE FORMAT IS _MPEG_. See -of help. Video stream is mandatory! Error - 12.08.2010 07:25:26 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0 Description = Transcoding error: Error - 12.08.2010 07:25:26 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0 Description = WARNING: OUTPUT FILE FORMAT IS _MPEG_. See -of help. ============ Sorry, this file format is not recognized/supported ============= === If this file is an AVI, ASF or MPEG stream, please contact the author! === Cannot open demuxer. Error - 12.08.2010 07:25:54 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0 Description = Transcoding error: Error - 12.08.2010 07:25:54 | Computer Name = Wurst-PC | Source = transcode360-log | ID = 0 Description = WARNING: OUTPUT FILE FORMAT IS _MPEG_. See -of help. Video stream is mandatory! < End of report > _________________________________________________________________OTL Logfile: Code:
ATTFilter OTL logfile created on: 15.09.2010 21:19:47 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Wurst\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 6,00 Gb Total Physical Memory | 4,00 Gb Available Physical Memory | 64,00% Memory free 12,00 Gb Paging File | 10,00 Gb Available in Paging File | 80,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 48,74 Gb Total Space | 12,35 Gb Free Space | 25,33% Space Free | Partition Type: NTFS Drive D: | 186,31 Gb Total Space | 100,20 Gb Free Space | 53,78% Space Free | Partition Type: NTFS Drive E: | 97,66 Gb Total Space | 8,84 Gb Free Space | 9,05% Space Free | Partition Type: NTFS Drive F: | 39,80 Gb Total Space | 25,96 Gb Free Space | 65,21% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: WURST-PC Current User Name: Wurst Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Users\Wurst\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe (Emsi Software GmbH) PRC - C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe (Emsi Software GmbH) PRC - C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (Mozilla Corporation) PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Program Files (x86)\MCE Standby Tool\mst.exe (Herman van Eijk) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org) PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink) PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) PRC - C:\Program Files (x86)\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.) PRC - C:\Programme\Logitech\Logitech WebCam Software\LWS.exe () PRC - C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe () PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Logitech Inc.) PRC - C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink) PRC - C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe (Logitech Inc.) PRC - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.) PRC - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG) PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.) ========== Modules (SafeList) ========== MOD - C:\Users\Wurst\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Program Files (x86)\Emsisoft Anti-Malware\a2hooks32.dll (Emsi Software GmbH) MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (LVPrcS64) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.) SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation) SRV:64bit: - (PeerDistSvc) -- C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation) SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation) SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SRV - (a2AntiMalware) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe (Emsi Software GmbH) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (clr_optimization_v4.0.30319_64) -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.) SRV - (Transcode360) -- C:\Program Files (x86)\Transcode360\Transcode360.exe (Transcode 360) ========== Driver Services (SafeList) ========== DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64j.sys File not found DRV:64bit: - (upperdev) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64.sys File not found DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys File not found DRV:64bit: - (nmwcdx64) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys File not found DRV:64bit: - (nmwcdnsux64) -- C:\Windows\SysNative\drivers\nmwcdnsux64.sys File not found DRV:64bit: - (nmwcdnsucx64) -- C:\Windows\SysNative\drivers\nmwcdnsucx64.sys File not found DRV:64bit: - (nmwcdcx64) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys File not found DRV:64bit: - (hwinterface) -- C:\Windows\SysNative\Drivers\hwinterface.sys File not found DRV:64bit: - (seehcri) -- C:\Windows\SysNative\drivers\seehcri.sys (Sony Ericsson Mobile Communications) DRV:64bit: - (ggsemc) -- C:\Windows\SysNative\drivers\ggsemc.sys (Sony Ericsson Mobile Communications) DRV:64bit: - (ggflt) -- C:\Windows\SysNative\drivers\ggflt.sys (Sony Ericsson Mobile Communications) DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH) DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys () DRV:64bit: - (netr7364) -- C:\Windows\SysNative\drivers\netr7364.sys (Ralink Technology, Corp.) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH) DRV:64bit: - (cxbu0x64) -- C:\Windows\SysNative\drivers\cxbu0x64.sys (HID Global Corporation) DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG) DRV:64bit: - (LVPr2Mon) -- C:\Windows\SysNative\drivers\LVPr2M64.sys () DRV:64bit: - (LVPr2M64) -- C:\Windows\SysNative\drivers\LVPr2M64.sys () DRV:64bit: - (BthAvrcp) -- C:\Windows\SysNative\drivers\BthAvrcp.sys (CSR, plc) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (vmbus) -- C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation) DRV:64bit: - (storflt) -- C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation) DRV:64bit: - (storvsc) -- C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation) DRV:64bit: - (s3cap) -- C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation) DRV:64bit: - (VMBusHID) -- C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation) DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation) DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof () DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (VClone) -- C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG) DRV:64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) -- C:\Windows\SysNative\drivers\LV302V64.SYS (Logitech Inc.) DRV:64bit: - (LVUSBS64) -- C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.) DRV:64bit: - (sfvfs02) StarForce Protection VFS Driver (version 2.x) -- C:\Windows\SysNative\drivers\sfvfs02.sys (Protection Technology) DRV:64bit: - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\SysNative\drivers\sfdrv01.sys (Protection Technology) DRV:64bit: - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\SysNative\drivers\sfhlp02.sys (Protection Technology) DRV - (a2injectiondriver) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys (Emsi Software GmbH) DRV - (a2acc) -- C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys (Emsi Software GmbH) DRV - (hwinterface) -- C:\Windows\SysWOW64\drivers\hwinterface.sys (Buzz) DRV - (gdrv) -- C:\Windows\gdrv.sys (Windows (R) Server 2003 DDK provider) DRV - (a2util) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys (Emsi Software GmbH) DRV - ({B154377D-700F-42cc-9474-23858FBDF4BD}) -- C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl (CyberLink Corp.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 40 DC D7 F6 55 4C CB 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultthis.engineName: "Winload Customized Web Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.startup.homepage: "hxxp://www.bild.de/" FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.1.0625 FF - prefs.js..extensions.enabledItems: DeviceDetection@logitech.com: FF - prefs.js..extensions.enabledItems: {fd639891-5cc6-45ae-9055-a7a6abb5a7a9}: FF - prefs.js..extensions.enabledItems: cfxHelper@Triton:1.2 FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.3 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: finder@meingutscheincode.de:1.0.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: extension@virtusdesigns.com:3.6.6 FF - prefs.js..extensions.enabledItems: {3ffb7be0-8bde-11de-8a39-0800200c9a66}: FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.6.6 FF - prefs.js..extensions.enabledItems: cfxe@Triton:3.6.5 FF - prefs.js..extensions.enabledItems: {12bc3590-67a6-11de-8a39-0800200c9a66}:3.6 FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&q=" FF - prefs.js..network.proxy.type: 4 FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.09.10 16:07:19 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.09.10 16:07:19 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0b4\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 4\components [2010.08.31 18:40:51 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0b4\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 4\plugins [2010.02.21 09:23:32 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Extensions [2010.09.15 19:18:59 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions [2010.02.21 16:43:14 | 000,000,000 | ---D | M] (Eclipse) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66} [2010.02.21 16:38:35 | 000,000,000 | ---D | M] (Purple Fox) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{3ffb7be0-8bde-11de-8a39-0800200c9a66} [2010.08.19 17:31:29 | 000,000,000 | ---D | M] (Aero Fox XL) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66} [2010.06.28 19:09:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} [2010.08.19 17:31:33 | 000,000,000 | ---D | M] (Yoono) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{d9284e50-81fc-11da-a72b-0800200c9a66} [2010.02.21 13:57:53 | 000,000,000 | ---D | M] (SEB Chipcard Plugin) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{fd639891-5cc6-45ae-9055-a7a6abb5a7a9} [2010.06.28 19:09:35 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\cfxe@Triton [2010.06.28 19:09:39 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\cfxHelper@Triton [2010.02.21 13:39:01 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\DeviceDetection@logitech.com [2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com [2010.07.26 18:41:19 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\finder@meingutscheincode.de [2010.05.22 20:04:12 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\personas@christopher.beard [2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com\__MACOSX [2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com\chrome [2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com\defaults [2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\mac\browser\extensions [2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\mac\mozapps\extensions [2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\win\browser\extensions [2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\win\mozapps\extensions [2010.08.19 17:31:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\mac\mozapps\extensions [2010.08.19 17:31:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\win\mozapps\extensions [2010.03.24 16:13:02 | 000,000,917 | ---- | M] () -- C:\Users\Wurst\AppData\Roaming\Mozilla\FireFox\Profiles\nikwlstw.default\searchplugins\conduit.xml [2010.08.19 09:19:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2010.05.23 10:51:28 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010.08.19 09:19:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010.07.17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2010.04.03 14:51:17 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.04.03 14:51:17 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.04.03 14:51:17 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.04.03 14:51:17 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.04.03 14:51:17 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.09.14 19:38:46 | 000,419,251 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: www.007guard.com O1 - Hosts: 007guard.com O1 - Hosts: 008i.com O1 - Hosts: www.008k.com O1 - Hosts: 008k.com O1 - Hosts: www.00hq.com O1 - Hosts: 00hq.com O1 - Hosts: 010402.com O1 - Hosts: www.032439.com O1 - Hosts: 032439.com O1 - Hosts: www.0scan.com O1 - Hosts: 0scan.com O1 - Hosts: 1000gratisproben.com O1 - Hosts: www.1000gratisproben.com O1 - Hosts: 1001namen.com O1 - Hosts: www.1001namen.com O1 - Hosts: 100888290cs.com O1 - Hosts: www.100888290cs.com O1 - Hosts: www.100sexlinks.com O1 - Hosts: 100sexlinks.com O1 - Hosts: 10sek.com O1 - Hosts: www.10sek.com O1 - Hosts: www.1-2005-search.com O1 - Hosts: 1-2005-search.com O1 - Hosts: 123fporn.info O1 - Hosts: 14465 more lines... O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O4 - HKLM..\Run: [a-squared] C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2guard.exe (Emsi Software GmbH) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink) O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [F5D7050v3] C:\Program Files (x86)\Belkin\F5D7050v3\Belkinwcui.exe File not found O4 - HKLM..\Run: [InstantBurn] C:\PROGRA~2\CYBERL~1\INSTAN~1\Win2K\IBurn.exe (CyberLink Corporation.) O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe () O4 - HKLM..\Run: [ Malwarebytes Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [MCE Standby Tool] C:\Program Files (x86)\MCE Standby Tool\mst.exe (Herman van Eijk) O4 - HKLM..\Run: [PDVD9LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.) O4 - HKLM..\Run: [RemoteControl9] C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.) O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG) O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe (Logitech Inc.) O4 - Startup: C:\Users\Wurst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (zipfldra.dll) - File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20:64bit: - Winlogon\Notify\ScCertProp: DllName - Reg Error: Key error. - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\Shell - "" = AutoRun O33 - MountPoints2\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\Shell\AutoRun\command - "" = I:\Startme.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.09.15 21:09:36 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSCMCDE.DLL [2010.09.15 21:09:36 | 000,139,264 | ---- | C] (man-tech.de) -- C:\Windows\SysWow64\ssMail.dll [2010.09.15 21:09:36 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSSTDFMT.DLL [2010.09.15 21:09:36 | 000,103,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSCOMM32.OCX [2010.09.15 21:09:36 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSCOMDE.DLL [2010.09.15 21:09:35 | 000,209,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TABCTL32.OCX [2010.09.15 21:09:35 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CMDLGDE.DLL [2010.09.15 21:09:35 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TABCTDE.DLL [2010.09.15 21:09:35 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WINSKDE.DLL [2010.09.15 21:09:35 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\STDFTDE.DLL [2010.09.15 21:09:34 | 000,712,704 | ---- | C] (Fath Software ( www.fathsoft.com )) -- C:\Windows\SysWow64\csCapx.ocx [2010.09.15 21:09:34 | 000,115,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSINET.OCX [2010.09.15 21:09:34 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\INETDE.DLL [2010.09.15 21:09:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CamSpy [2010.09.15 19:19:55 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Wurst\Desktop\OTL.exe [2010.09.15 19:18:02 | 002,441,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iertutil.dll [2010.09.15 17:37:42 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Malwarebytes [2010.09.15 17:37:29 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010.09.15 17:37:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.09.15 17:37:26 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2010.09.15 17:37:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010.09.14 19:32:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Emsisoft Anti-Malware [2010.09.14 18:47:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2010.09.14 18:47:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy [2010.09.14 18:35:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro [2010.09.13 17:52:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavalys [2010.09.04 11:00:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight [2010.08.31 18:40:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 4 [2010.08.31 16:37:33 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Desktop\Tatoo [2010.08.29 09:11:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine [2010.08.25 22:11:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime [2010.08.25 22:11:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer [2010.08.25 09:02:39 | 000,861,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll [2010.08.23 08:34:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AxBx [2010.08.21 15:16:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SopCast [2010.08.21 09:30:11 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\dvdcss [2010.08.19 17:47:22 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\VirtualDubMod_1_5_10_2_All_inclusive [2010.08.19 09:19:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2010.08.19 09:19:21 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2010.08.19 09:19:21 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2010.08.19 09:19:21 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [2 C:\Users\Wurst\*.tmp files -> C:\Users\Wurst\*.tmp -> ] [1 C:\Users\Wurst\Documents\*.tmp files -> C:\Users\Wurst\Documents\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010.09.15 21:23:54 | 002,621,440 | -HS- | M] () -- C:\Users\Wurst\ntuser.dat [2010.09.15 21:23:51 | 001,068,065 | ---- | M] (PKSoft) -- C:\Users\Wurst\Desktop\setupsc.exe [2010.09.15 21:22:06 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2010.09.15 21:22:06 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2010.09.15 21:02:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.09.15 19:24:57 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.09.15 19:23:45 | 004,957,557 | -H-- | M] () -- C:\Users\Wurst\AppData\Local\IconCache.db [2010.09.15 19:20:00 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Wurst\Desktop\OTL.exe [2010.09.15 17:37:32 | 000,001,013 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.09.14 19:38:46 | 000,419,251 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2010.09.14 18:55:01 | 000,419,251 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20100914-193846.backup [2010.09.14 16:30:18 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010.09.14 16:30:18 | 000,653,928 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2010.09.14 16:30:18 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010.09.14 16:30:18 | 000,129,800 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2010.09.14 16:30:18 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010.08.31 07:19:12 | 002,441,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iertutil.dll [2010.08.28 16:41:16 | 000,000,823 | ---- | M] () -- C:\Users\Wurst\Desktop\William Hill CASINO CLUB.lnk [2010.08.25 22:11:17 | 000,001,845 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk [2010.08.23 08:34:13 | 000,001,096 | ---- | M] () -- C:\Users\Wurst\Desktop\Clean Virus MSN.lnk [2010.08.21 15:16:44 | 000,000,995 | ---- | M] () -- C:\Users\Wurst\Desktop\SopCast.lnk [2010.08.19 18:08:17 | 000,001,861 | ---- | M] () -- C:\Users\Wurst\Desktop\UseNeXT.lnk [2010.08.19 17:51:00 | 000,003,193 | ---- | M] () -- C:\Users\Wurst\Desktop\VirtualDub.lnk [2010.08.19 17:50:50 | 000,004,068 | ---- | M] () -- C:\Users\Wurst\Desktop\VirtualDubMod.lnk [2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [2 C:\Users\Wurst\*.tmp files -> C:\Users\Wurst\*.tmp -> ] [1 C:\Users\Wurst\Documents\*.tmp files -> C:\Users\Wurst\Documents\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.09.15 17:37:32 | 000,001,013 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.08.28 16:41:16 | 000,000,823 | ---- | C] () -- C:\Users\Wurst\Desktop\William Hill CASINO CLUB.lnk [2010.08.25 22:11:17 | 000,001,845 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk [2010.08.23 08:34:13 | 000,001,096 | ---- | C] () -- C:\Users\Wurst\Desktop\Clean Virus MSN.lnk [2010.08.21 15:16:44 | 000,000,995 | ---- | C] () -- C:\Users\Wurst\Desktop\SopCast.lnk [2010.08.19 17:51:00 | 000,003,193 | ---- | C] () -- C:\Users\Wurst\Desktop\VirtualDub.lnk [2010.08.19 17:50:50 | 000,004,068 | ---- | C] () -- C:\Users\Wurst\Desktop\VirtualDubMod.lnk [2010.08.13 20:32:32 | 000,037,376 | ---- | C] () -- C:\Windows\SysWow64\VbVfw.dll [2010.08.12 12:53:05 | 083,267,584 | ---- | C] () -- C:\ProgramData\arcade.mp3 [2010.08.12 12:09:57 | 000,000,101 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc [2010.08.04 19:24:32 | 001,551,928 | ---- | C] () -- C:\Program Files (x86)\SetupVirtualCloneDrive.exe [2010.08.04 19:24:31 | 000,770,938 | ---- | C] () -- C:\Program Files (x86)\KaraokeSetup.exe [2010.08.03 19:51:25 | 000,000,410 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010.07.25 12:52:49 | 000,000,177 | ---- | C] () -- C:\ProgramData\Temp.log [2010.07.21 17:26:48 | 000,000,125 | -HS- | C] () -- C:\ProgramData\.zreglib [2010.06.20 12:23:16 | 000,197,120 | ---- | C] () -- C:\Windows\patchw32.dll [2010.05.02 08:03:03 | 000,005,632 | ---- | C] () -- C:\Users\Wurst\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.05.02 07:36:34 | 001,526,060 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2010.04.02 17:17:34 | 000,179,091 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat [2010.03.06 12:09:17 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\vbzlib1.dll [2010.02.21 09:14:58 | 000,005,224 | ---- | C] () -- C:\Windows\SysWow64\ucuiinfo.ini [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll < End of report > So ich das ist so richtig! /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Unbekannte Internetseiten in der ChronikZitat:
| ![]() Unbekannte Internetseiten in der Chronik Oh ja, habe ich vergessen. Verschlüsselung ist WEP. Gruß CHWurst |
__________________ --> Unbekannte Internetseiten in der Chronik |
| ![]() Unbekannte Internetseiten in der Chronik Was hatte den jetzt der Scan ergeben? Ist es denn möglich das es ein Hacker war oder das jemand an meinem PC war? Da es laut der Chronik erst in der neuen Wohnung die ich im Februar bezogen habe angefangen hat. Gruß CHWurst |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Unbekannte Internetseiten in der Chronik Ja, bei WEP ist das möglich. Kümmer die Dich erstmal um die Verschlüsselung!
| ![]() Unbekannte Internetseiten in der Chronik Okay mache ich ! Danke erstmal und schönen Abend noch! Gruß CHWurst |
| ![]() Unbekannte Internetseiten in der Chronik Hallo cosinus, habe den Code und die Verschlüsselung geändert. Kann ich noch was tun oder einfach nur abwarten ob das nochmal vorkommt? Gruß CHWurst |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Unbekannte Internetseiten in der Chronik Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL O20 - AppInit_DLLs: (zipfldra.dll) - File not found O33 - MountPoints2\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\Shell - "" = AutoRun O33 - MountPoints2\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\Shell\AutoRun\command - "" = I:\Startme.exe -- File not found [2010.09.15 21:09:36 | 000,139,264 | ---- | C] (man-tech.de) -- C:\Windows\SysWow64\ssMail.dll :Commands [purity] [resethosts] [emptytemp] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.
| ![]() Unbekannte Internetseiten in der Chronik So hier der bericht! All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:zipfldra.dll deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2bad4fca-38d5-11df-8ff4-001bdc0f7649}\ not found. File I:\Startme.exe not found. C:\Windows\SysWOW64\ssMail.dll moved successfully. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Anni ->Temp folder emptied: 6293031 bytes ->Temporary Internet Files folder emptied: 192538188 bytes ->Java cache emptied: 45519367 bytes ->FireFox cache emptied: 112999840 bytes ->Flash cache emptied: 44403 bytes User: AppData User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Mcx1-WURST-PC ->Temp folder emptied: 516 bytes ->Temporary Internet Files folder emptied: 34866214 bytes User: Public User: Wurst ->Temp folder emptied: 103956494 bytes ->Temporary Internet Files folder emptied: 98600 bytes ->Java cache emptied: 7560216 bytes ->FireFox cache emptied: 94562697 bytes ->Flash cache emptied: 5506 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 1564672 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 366848 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 573,00 mb OTL by OldTimer - Version log created on 09162010_212800 Files\Folders moved on Reboot... C:\Users\Wurst\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File move failed. C:\Windows\temp\logishrd\LVPrcInj02.dll scheduled to be moved on reboot. Registry entries deleted on Reboot... |
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
| ![]() Unbekannte Internetseiten in der Chronik So hier der nächste Bericht.OTL Logfile: Code:
ATTFilter OTL logfile created on: 16.09.2010 21:41:39 - Run 2 OTL by OldTimer - Version Folder = C:\Users\Wurst\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 6,00 Gb Total Physical Memory | 5,00 Gb Available Physical Memory | 79,00% Memory free 12,00 Gb Paging File | 11,00 Gb Available in Paging File | 89,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 48,74 Gb Total Space | 18,10 Gb Free Space | 37,15% Space Free | Partition Type: NTFS Drive D: | 186,31 Gb Total Space | 98,83 Gb Free Space | 53,05% Space Free | Partition Type: NTFS Drive E: | 97,66 Gb Total Space | 8,84 Gb Free Space | 9,05% Space Free | Partition Type: NTFS Drive F: | 39,80 Gb Total Space | 25,86 Gb Free Space | 64,98% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: WURST-PC Current User Name: Wurst Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: On Skip Microsoft Files: On File Age = 90 Days Output = Minimal Quick Scan ========== Processes (SafeList) ========== PRC - C:\Users\Wurst\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () PRC - C:\Program Files (x86)\Norton Internet Security\Engine\\ccSvcHst.exe (Symantec Corporation) PRC - C:\Program Files (x86)\MCE Standby Tool\mst.exe (Herman van Eijk) PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org) PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink) PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) PRC - C:\Program Files (x86)\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.) PRC - C:\Programme\Logitech\Logitech WebCam Software\LWS.exe () PRC - C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe () PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Logitech Inc.) PRC - C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink) PRC - C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe (Logitech Inc.) PRC - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.) PRC - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG) ========== Modules (SafeList) ========== MOD - C:\Users\Wurst\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (LVPrcS64) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.) SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation) SRV:64bit: - (PeerDistSvc) -- C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation) SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation) SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SRV - (NIS) -- C:\Program Files (x86)\Norton Internet Security\Engine\\ccSvcHst.exe (Symantec Corporation) SRV - (clr_optimization_v4.0.30319_64) -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) SRV - (Transcode360) -- C:\Program Files (x86)\Transcode360\Transcode360.exe (Transcode 360) ========== Driver Services (SafeList) ========== DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64j.sys File not found DRV:64bit: - (upperdev) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64.sys File not found DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys File not found DRV:64bit: - (nmwcdx64) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys File not found DRV:64bit: - (nmwcdnsux64) -- C:\Windows\SysNative\drivers\nmwcdnsux64.sys File not found DRV:64bit: - (nmwcdnsucx64) -- C:\Windows\SysNative\drivers\nmwcdnsucx64.sys File not found DRV:64bit: - (nmwcdcx64) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys File not found DRV:64bit: - (hwinterface) -- C:\Windows\SysNative\Drivers\hwinterface.sys File not found DRV:64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation) DRV:64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA64.sys (Symantec Corporation) DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.sys (Symantec Corporation) DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.sys (Symantec Corporation) DRV:64bit: - (SymNetS) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\symnets.sys (Symantec Corporation) DRV:64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Ironx64.sys (Symantec Corporation) DRV:64bit: - (SymDS) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymDS64.sys (Symantec Corporation) DRV:64bit: - (seehcri) -- C:\Windows\SysNative\drivers\seehcri.sys (Sony Ericsson Mobile Communications) DRV:64bit: - (ggsemc) -- C:\Windows\SysNative\drivers\ggsemc.sys (Sony Ericsson Mobile Communications) DRV:64bit: - (ggflt) -- C:\Windows\SysNative\drivers\ggflt.sys (Sony Ericsson Mobile Communications) DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys () DRV:64bit: - (netr7364) -- C:\Windows\SysNative\drivers\netr7364.sys (Ralink Technology, Corp.) DRV:64bit: - (cxbu0x64) -- C:\Windows\SysNative\drivers\cxbu0x64.sys (HID Global Corporation) DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG) DRV:64bit: - (LVPr2Mon) -- C:\Windows\SysNative\drivers\LVPr2M64.sys () DRV:64bit: - (LVPr2M64) -- C:\Windows\SysNative\drivers\LVPr2M64.sys () DRV:64bit: - (BthAvrcp) -- C:\Windows\SysNative\drivers\BthAvrcp.sys (CSR, plc) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (vmbus) -- C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation) DRV:64bit: - (storflt) -- C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation) DRV:64bit: - (storvsc) -- C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation) DRV:64bit: - (s3cap) -- C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation) DRV:64bit: - (VMBusHID) -- C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation) DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation) DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof () DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (VClone) -- C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG) DRV:64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) -- C:\Windows\SysNative\drivers\LV302V64.SYS (Logitech Inc.) DRV:64bit: - (LVUSBS64) -- C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.) DRV:64bit: - (sfvfs02) StarForce Protection VFS Driver (version 2.x) -- C:\Windows\SysNative\drivers\sfvfs02.sys (Protection Technology) DRV:64bit: - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\SysNative\drivers\sfdrv01.sys (Protection Technology) DRV:64bit: - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\SysNative\drivers\sfhlp02.sys (Protection Technology) DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100916.002\ex64.sys (Symantec Corporation) DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation) DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation) DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100916.002\eng64.sys (Symantec Corporation) DRV - (BHDrvx64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20100901.003\BHDrvx64.sys (Symantec Corporation) DRV - (hwinterface) -- C:\Windows\SysWOW64\drivers\hwinterface.sys (Buzz) DRV - (gdrv) -- C:\Windows\gdrv.sys (Windows (R) Server 2003 DDK provider) DRV - (IDSVia64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20100914.003\IDSviA64.sys (Symantec Corporation) DRV - ({B154377D-700F-42cc-9474-23858FBDF4BD}) -- C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl (CyberLink Corp.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 40 DC D7 F6 55 4C CB 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultthis.engineName: "Winload Customized Web Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.startup.homepage: "hxxp://www.bild.de/" FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.1.0625 FF - prefs.js..extensions.enabledItems: DeviceDetection@logitech.com: FF - prefs.js..extensions.enabledItems: {fd639891-5cc6-45ae-9055-a7a6abb5a7a9}: FF - prefs.js..extensions.enabledItems: cfxHelper@Triton:1.2 FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.3 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: finder@meingutscheincode.de:1.0.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: extension@virtusdesigns.com:3.6.6 FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0 FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:5.1 FF - prefs.js..extensions.enabledItems: {3ffb7be0-8bde-11de-8a39-0800200c9a66}: FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.6.6 FF - prefs.js..extensions.enabledItems: cfxe@Triton:3.6.5 FF - prefs.js..extensions.enabledItems: {12bc3590-67a6-11de-8a39-0800200c9a66}:3.6 FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&q=" FF - prefs.js..network.proxy.type: 4 FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2010.09.16 19:47:28 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\ [2010.09.16 19:46:22 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.09.16 16:50:34 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.09.16 16:50:34 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0b4\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 4\components [2010.08.31 18:40:51 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0b4\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 4\plugins [2010.02.21 09:23:32 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Extensions [2010.09.16 21:34:02 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions [2010.02.21 16:43:14 | 000,000,000 | ---D | M] (Eclipse) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66} [2010.02.21 16:38:35 | 000,000,000 | ---D | M] (Purple Fox) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{3ffb7be0-8bde-11de-8a39-0800200c9a66} [2010.08.19 17:31:29 | 000,000,000 | ---D | M] (Aero Fox XL) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66} [2010.06.28 19:09:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} [2010.08.19 17:31:33 | 000,000,000 | ---D | M] (Yoono) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{d9284e50-81fc-11da-a72b-0800200c9a66} [2010.02.21 13:57:53 | 000,000,000 | ---D | M] (SEB Chipcard Plugin) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{fd639891-5cc6-45ae-9055-a7a6abb5a7a9} [2010.06.28 19:09:35 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\cfxe@Triton [2010.06.28 19:09:39 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\cfxHelper@Triton [2010.02.21 13:39:01 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\DeviceDetection@logitech.com [2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com [2010.07.26 18:41:19 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\finder@meingutscheincode.de [2010.05.22 20:04:12 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\personas@christopher.beard [2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com\__MACOSX [2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com\chrome [2010.08.19 17:31:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\extension@virtusdesigns.com\defaults [2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\mac\browser\extensions [2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\mac\mozapps\extensions [2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\win\browser\extensions [2010.02.21 16:43:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\win\mozapps\extensions [2010.08.19 17:31:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\mac\mozapps\extensions [2010.08.19 17:31:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wurst\AppData\Roaming\mozilla\Firefox\Profiles\nikwlstw.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\win\mozapps\extensions [2010.03.24 16:13:02 | 000,000,917 | ---- | M] () -- C:\Users\Wurst\AppData\Roaming\Mozilla\FireFox\Profiles\nikwlstw.default\searchplugins\conduit.xml [2010.09.16 20:50:43 | 000,002,443 | ---- | M] () -- C:\Users\Wurst\AppData\Roaming\Mozilla\FireFox\Profiles\nikwlstw.default\searchplugins\safesearch.xml [2010.08.19 09:19:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2010.05.23 10:51:28 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010.08.19 09:19:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010.07.17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2010.04.03 14:51:17 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.04.03 14:51:17 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.04.03 14:51:17 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.04.03 14:51:17 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.04.03 14:51:17 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.09.16 21:28:01 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts O1 - Hosts: localhost O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\\IPSBHO.DLL (Symantec Corporation) O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink) O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [InstantBurn] C:\PROGRA~2\CYBERL~1\INSTAN~1\Win2K\IBurn.exe (CyberLink Corporation.) O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe () O4 - HKLM..\Run: [MCE Standby Tool] C:\Program Files (x86)\MCE Standby Tool\mst.exe (Herman van Eijk) O4 - HKLM..\Run: [PDVD9LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.) O4 - HKLM..\Run: [RemoteControl9] C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.) O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG) O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe (Logitech Inc.) O4 - Startup: C:\Users\Wurst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20:64bit: - Winlogon\Notify\ScCertProp: DllName - Reg Error: Key error. - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SafeBootMin:64bit: Base - Driver Group SafeBootMin:64bit: Boot Bus Extender - Driver Group SafeBootMin:64bit: Boot file system - Driver Group SafeBootMin:64bit: File system - Driver Group SafeBootMin:64bit: Filter - Driver Group SafeBootMin:64bit: HelpSvc - Service SafeBootMin:64bit: PCI Configuration - Driver Group SafeBootMin:64bit: PNP Filter - Driver Group SafeBootMin:64bit: Primary disk - Driver Group SafeBootMin:64bit: sacsvr - Service SafeBootMin:64bit: SCSI Class - Driver Group SafeBootMin:64bit: System Bus Extender - Driver Group SafeBootMin:64bit: vmms - Service SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vmms - Service SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SafeBootNet:64bit: Base - Driver Group SafeBootNet:64bit: Boot Bus Extender - Driver Group SafeBootNet:64bit: Boot file system - Driver Group SafeBootNet:64bit: File system - Driver Group SafeBootNet:64bit: Filter - Driver Group SafeBootNet:64bit: HelpSvc - Service SafeBootNet:64bit: Messenger - Service SafeBootNet:64bit: NDIS Wrapper - Driver Group SafeBootNet:64bit: NetBIOSGroup - Driver Group SafeBootNet:64bit: NetDDEGroup - Driver Group SafeBootNet:64bit: Network - Driver Group SafeBootNet:64bit: NetworkProvider - Driver Group SafeBootNet:64bit: PCI Configuration - Driver Group SafeBootNet:64bit: PNP Filter - Driver Group SafeBootNet:64bit: PNP_TDI - Driver Group SafeBootNet:64bit: Primary disk - Driver Group SafeBootNet:64bit: rdsessmgr - Service SafeBootNet:64bit: sacsvr - Service SafeBootNet:64bit: SCSI Class - Driver Group SafeBootNet:64bit: Streams Drivers - Driver Group SafeBootNet:64bit: System Bus Extender - Driver Group SafeBootNet:64bit: TDI - Driver Group SafeBootNet:64bit: vmms - Service SafeBootNet:64bit: WudfUsbccidDriver - Driver SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vmms - Service SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.) Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.) Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.) Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.) Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 90 Days ========== [2010.09.16 21:28:00 | 000,000,000 | ---D | C] -- C:\_OTL [2010.09.16 21:26:48 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Wurst\Desktop\OTL.exe [2010.09.16 20:16:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Symantec Shared [2010.09.16 19:47:12 | 000,174,640 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS [2010.09.16 19:47:11 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Symantec Shared [2010.09.16 19:47:11 | 000,000,000 | ---D | C] -- C:\Programme\Symantec [2010.09.16 19:46:45 | 000,381,488 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\symnets.sys [2010.09.16 19:46:44 | 000,821,808 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA64.sys [2010.09.16 19:46:44 | 000,715,824 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.sys [2010.09.16 19:46:44 | 000,450,096 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymDS64.sys [2010.09.16 19:46:44 | 000,040,496 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.sys [2010.09.16 19:46:43 | 000,168,496 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Ironx64.sys [2010.09.16 19:46:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NISx64 [2010.09.16 19:46:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NISx64\1201000.025 [2010.09.16 19:46:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Internet Security [2010.09.16 19:46:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton [2010.09.16 19:46:05 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller [2010.09.16 19:46:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller [2010.09.16 19:42:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner [2010.09.15 21:46:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CamAlert [2010.09.15 21:09:34 | 000,712,704 | ---- | C] (Fath Software ( www.fathsoft.com )) -- C:\Windows\SysWow64\csCapx.ocx [2010.09.15 21:09:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CamSpy [2010.09.15 17:37:42 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Malwarebytes [2010.09.15 17:37:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.09.15 17:37:26 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2010.09.15 17:37:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010.09.14 18:47:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2010.09.14 18:47:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy [2010.09.14 18:35:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro [2010.09.13 17:52:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavalys [2010.09.04 11:00:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight [2010.08.31 18:40:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 4 [2010.08.31 16:37:33 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Desktop\Tatoo [2010.08.29 09:11:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine [2010.08.25 22:11:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime [2010.08.25 22:11:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer [2010.08.21 15:16:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SopCast [2010.08.21 09:30:11 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\dvdcss [2010.08.19 17:47:22 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\VirtualDubMod_1_5_10_2_All_inclusive [2010.08.19 09:19:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2010.08.15 22:22:41 | 000,000,000 | ---D | C] -- C:\ProgramData\MetaBrowser 2.0 [2010.08.15 22:22:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MetaBrowser 2.0 [2010.08.13 20:46:35 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\DivX [2010.08.13 20:45:52 | 000,000,000 | ---D | C] -- C:\Programme\DivX [2010.08.13 20:45:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DivX Shared [2010.08.13 20:45:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DivX [2010.08.13 20:44:51 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX [2010.08.13 20:43:05 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\VirtualDub-1.9.9 [2010.08.13 20:32:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PeckJoin [2010.08.13 19:54:12 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\Any Video Converter [2010.08.13 19:53:53 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\AnvSoft [2010.08.13 19:53:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AnvSoft [2010.08.13 18:19:04 | 000,000,000 | ---D | C] -- C:\ProgramData\GameEmu [2010.08.13 18:19:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GameEmu [2010.08.13 18:17:14 | 000,000,000 | ---D | C] -- C:\Programme\GameEmu [2010.08.12 13:09:58 | 000,000,000 | ---D | C] -- C:\Roms [2010.08.12 13:05:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Transcode360 [2010.08.12 12:23:31 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Push-A-Button [2010.08.12 12:13:46 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Synchronization Services [2010.08.12 12:13:46 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft SQL Server Compact Edition [2010.08.12 12:11:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services [2010.08.12 12:11:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition [2010.08.12 11:06:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MCE Standby Tool [2010.08.12 09:15:01 | 000,000,000 | ---D | C] -- C:\ProgramData\MediaBrowser [2010.08.12 09:15:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MediaBrowser [2010.08.12 09:10:42 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Movienizer [2010.08.12 08:59:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Media Center Studio [2010.08.12 08:58:42 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\Apps [2010.08.12 08:58:41 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\Deployment [2010.08.11 07:56:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update [2010.08.11 07:56:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple [2010.08.06 15:09:08 | 000,000,000 | ---D | C] -- C:\Windows\SQLTools9_KB970892_ENU [2010.08.06 15:07:20 | 000,000,000 | ---D | C] -- C:\Windows\SQL9_KB970892_ENU [2010.08.04 20:04:33 | 000,002,996 | ---- | C] (Buzz) -- C:\Windows\SysWow64\drivers\hwinterface.sys [2010.08.04 19:30:07 | 000,000,000 | ---D | C] -- C:\Assets [2010.08.04 19:25:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\gs [2010.08.04 19:24:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KaraokeDX [2010.08.04 19:24:51 | 001,339,824 | ---- | C] (Spesoft Ltd) -- C:\Windows\SysWow64\sysperxg.dll [2010.08.04 19:13:12 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Desktop\N64 [2010.08.04 19:12:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Project64 1.6 [2010.08.04 18:17:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server [2010.08.04 18:14:37 | 000,000,000 | ---D | C] -- C:\ProgramData\My Movies [2010.08.03 19:52:10 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Desktop\MediaCenter [2010.07.31 17:41:14 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\cache [2010.07.31 11:10:45 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\Games for Windows - LIVE Demos [2010.07.30 22:56:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Elaborate Bytes [2010.07.28 19:10:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GIGABYTE [2010.07.26 18:41:47 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\TBlauhut [2010.07.26 18:41:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit [2010.07.25 13:54:54 | 000,000,000 | -H-D | C] -- C:\Users\Wurst\Documents\PDRMUSIC.TMP [2010.07.25 13:53:54 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\Apple Computer [2010.07.25 13:35:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\CyberLink [2010.07.25 13:32:08 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\Apple [2010.07.25 13:32:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple [2010.07.25 12:53:05 | 000,376,304 | ---- | C] (CyberLink Corporation.) -- C:\Windows\SysNative\drivers\CLBUDF.sys [2010.07.25 12:53:03 | 000,024,560 | ---- | C] (Cyberlink Co.,Ltd.) -- C:\Windows\SysNative\drivers\CLBStor.sys [2010.07.25 11:17:53 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\vlc [2010.07.25 11:17:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN [2010.07.25 11:06:47 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\UseNeXT [2010.07.25 11:06:47 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\UseNeXT [2010.07.25 11:06:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\UseNeXT [2010.07.24 17:31:32 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Ashampoo [2010.07.24 17:27:43 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Local\ashampoo [2010.07.24 17:27:43 | 000,000,000 | ---D | C] -- C:\ProgramData\ashampoo [2010.07.24 17:27:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ashampoo [2010.07.23 17:05:28 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\ImgBurn [2010.07.23 17:04:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ImgBurn [2010.07.21 17:50:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Elaborate Bytes [2010.07.21 17:26:58 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\AnyDVDHD [2010.07.21 17:26:48 | 000,000,000 | ---D | C] -- C:\ProgramData\SlySoft [2010.06.27 12:29:37 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\OpenOffice.org [2010.06.26 10:28:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET [2010.06.20 12:24:10 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\RCT3 [2010.06.20 12:24:10 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Atari [2010.06.20 12:23:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PocketSoft [2010.06.20 12:19:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Atari [2010.06.20 10:41:43 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\Disco Tycoon [2010.06.19 00:24:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies [2010.06.19 00:24:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard [2010.06.19 00:24:45 | 000,419,840 | ---- | C] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll [2010.06.19 00:24:45 | 000,413,696 | ---- | C] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll [2010.06.19 00:24:45 | 000,133,632 | ---- | C] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysNative\OpenAL32.dll [2010.06.19 00:24:45 | 000,110,592 | ---- | C] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysWow64\OpenAL32.dll [2010.06.19 00:24:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenAL [2010.06.19 00:17:21 | 000,000,000 | ---D | C] -- C:\Users\Wurst\AppData\Roaming\Farm Mania 2 [2010.06.19 00:01:00 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Documents\Schwimmbad Tycoon [2010.06.18 23:45:17 | 000,000,000 | ---D | C] -- C:\Users\Wurst\Desktop\Spiele [2 C:\Users\Wurst\*.tmp files -> C:\Users\Wurst\*.tmp -> ] [1 C:\Users\Wurst\Documents\*.tmp files -> C:\Users\Wurst\Documents\*.tmp -> ] ========== Files - Modified Within 90 Days ========== [2010.09.16 21:43:07 | 002,621,440 | -HS- | M] () -- C:\Users\Wurst\ntuser.dat [2010.09.16 21:39:41 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2010.09.16 21:39:41 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2010.09.16 21:32:18 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.09.16 21:32:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.09.16 21:31:12 | 004,922,099 | -H-- | M] () -- C:\Users\Wurst\AppData\Local\IconCache.db [2010.09.16 21:28:01 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts [2010.09.16 21:26:50 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Wurst\Desktop\OTL.exe [2010.09.16 21:19:14 | 000,069,906 | ---- | M] () -- C:\Users\Wurst\Documents\cc_20100916_211858.reg [2010.09.16 19:47:56 | 001,165,798 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Cat.DB [2010.09.16 19:47:11 | 000,174,640 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS [2010.09.16 19:47:11 | 000,007,440 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT [2010.09.16 19:47:11 | 000,000,854 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF [2010.09.16 19:46:56 | 000,002,565 | ---- | M] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk [2010.09.16 19:42:54 | 000,001,011 | ---- | M] () -- C:\Users\Wurst\Desktop\CCleaner.lnk [2010.09.14 18:55:01 | 000,419,251 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20100914-193846.backup [2010.09.14 16:30:18 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010.09.14 16:30:18 | 000,653,928 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2010.09.14 16:30:18 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010.09.14 16:30:18 | 000,129,800 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2010.09.14 16:30:18 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010.08.25 22:11:17 | 000,001,845 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk [2010.08.21 15:16:44 | 000,000,995 | ---- | M] () -- C:\Users\Wurst\Desktop\SopCast.lnk [2010.08.19 18:08:17 | 000,001,861 | ---- | M] () -- C:\Users\Wurst\Desktop\UseNeXT.lnk [2010.08.19 17:51:00 | 000,003,193 | ---- | M] () -- C:\Users\Wurst\Desktop\VirtualDub.lnk [2010.08.19 17:50:50 | 000,004,068 | ---- | M] () -- C:\Users\Wurst\Desktop\VirtualDubMod.lnk [2010.08.18 16:05:20 | 000,000,172 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\isolate.ini [2010.08.15 22:22:42 | 000,002,027 | ---- | M] () -- C:\Users\Wurst\Desktop\MetaBrowser 2.0.lnk [2010.08.13 19:53:59 | 000,001,138 | ---- | M] () -- C:\Users\Wurst\Desktop\Any Video Converter.lnk [2010.08.12 14:54:29 | 000,300,152 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2010.08.12 13:57:49 | 000,068,040 | ---- | M] () -- C:\Users\Wurst\AppData\Local\GDIPFONTCACHEV1.DAT [2010.08.12 12:57:45 | 000,001,254 | ---- | M] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk [2010.08.12 12:55:24 | 001,551,928 | ---- | M] () -- C:\Program Files (x86)\SetupVirtualCloneDrive.exe [2010.08.12 12:55:23 | 000,770,938 | ---- | M] () -- C:\Program Files (x86)\KaraokeSetup.exe [2010.08.12 12:53:52 | 083,267,584 | ---- | M] () -- C:\ProgramData\arcade.mp3 [2010.08.12 12:09:57 | 000,000,101 | ---- | M] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc [2010.08.12 09:41:06 | 000,000,410 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2010.08.09 11:28:14 | 000,000,125 | -HS- | M] () -- C:\ProgramData\.zreglib [2010.08.07 01:21:29 | 000,000,000 | -H-- | M] () -- C:\Users\Wurst\Documents\Default.rdp [2010.08.07 00:56:32 | 000,000,375 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.ics [2010.08.06 15:08:06 | 001,526,060 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2010.08.04 20:04:33 | 000,002,996 | ---- | M] (Buzz) -- C:\Windows\SysWow64\drivers\hwinterface.sys [2010.07.30 22:56:21 | 000,001,203 | ---- | M] () -- C:\Users\Public\Desktop\CloneDVD2.lnk [2010.07.30 21:00:08 | 001,339,824 | ---- | M] (Spesoft Ltd) -- C:\Windows\SysWow64\sysperxg.dll [2010.07.29 05:33:05 | 000,821,808 | R--- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA64.sys [2010.07.29 05:33:05 | 000,007,412 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA64.cat [2010.07.29 05:33:05 | 000,003,373 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA.inf [2010.07.29 04:54:37 | 000,715,824 | R--- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.sys [2010.07.29 04:54:37 | 000,040,496 | R--- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.sys [2010.07.29 04:54:37 | 000,007,414 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.cat [2010.07.29 04:54:37 | 000,001,422 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.inf [2010.07.29 04:54:36 | 000,007,410 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.cat [2010.07.29 04:54:36 | 000,001,438 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.inf [2010.07.27 18:25:38 | 000,001,239 | ---- | M] () -- C:\Users\Wurst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk [2010.07.25 13:37:50 | 000,002,026 | ---- | M] () -- C:\Users\Public\Desktop\CyberLink Media Suite.lnk [2010.07.24 18:00:03 | 000,000,727 | ---- | M] () -- C:\Users\Wurst\Documents\My Photos.mfalist [2010.07.24 17:31:45 | 000,005,632 | ---- | M] () -- C:\Users\Wurst\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.07.24 17:27:42 | 000,001,119 | ---- | M] () -- C:\Users\Public\Desktop\Ashampoo Photo Commander 7.lnk [2010.07.22 03:27:14 | 000,007,410 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\symnet64.cat [2010.07.13 03:20:22 | 000,381,488 | R--- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\symnets.sys [2010.07.13 03:20:00 | 000,001,445 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymNet.inf [2010.07.13 02:50:50 | 000,007,402 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\iron.cat [2010.06.27 06:05:55 | 000,168,496 | R--- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Ironx64.sys [2010.06.27 06:05:55 | 000,000,771 | R--- | M] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Iron.inf [2010.06.19 00:24:45 | 000,419,840 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll [2010.06.19 00:24:45 | 000,413,696 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll [2010.06.19 00:24:45 | 000,133,632 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysNative\OpenAL32.dll [2010.06.19 00:24:45 | 000,110,592 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysWow64\OpenAL32.dll [2 C:\Users\Wurst\*.tmp files -> C:\Users\Wurst\*.tmp -> ] [1 C:\Users\Wurst\Documents\*.tmp files -> C:\Users\Wurst\Documents\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.09.16 21:19:02 | 000,069,906 | ---- | C] () -- C:\Users\Wurst\Documents\cc_20100916_211858.reg [2010.09.16 19:47:17 | 001,165,798 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Cat.DB [2010.09.16 19:47:12 | 000,007,440 | ---- | C] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT [2010.09.16 19:47:12 | 000,000,854 | ---- | C] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF [2010.09.16 19:46:56 | 000,002,565 | ---- | C] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk [2010.09.16 19:46:32 | 000,003,373 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA.inf [2010.09.16 19:46:32 | 000,002,792 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymDS.inf [2010.09.16 19:46:32 | 000,001,445 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymNet.inf [2010.09.16 19:46:32 | 000,001,438 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.inf [2010.09.16 19:46:32 | 000,001,422 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.inf [2010.09.16 19:46:32 | 000,000,771 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\Iron.inf [2010.09.16 19:46:25 | 000,007,414 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtspx64.cat [2010.09.16 19:46:25 | 000,007,412 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymEFA64.cat [2010.09.16 19:46:25 | 000,007,410 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\symnet64.cat [2010.09.16 19:46:25 | 000,007,410 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\srtsp64.cat [2010.09.16 19:46:25 | 000,007,406 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\SymDS64.cat [2010.09.16 19:46:25 | 000,007,402 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\iron.cat [2010.09.16 19:46:25 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1201000.025\isolate.ini [2010.09.16 19:42:54 | 000,001,011 | ---- | C] () -- C:\Users\Wurst\Desktop\CCleaner.lnk [2010.08.25 22:11:17 | 000,001,845 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk [2010.08.21 15:16:44 | 000,000,995 | ---- | C] () -- C:\Users\Wurst\Desktop\SopCast.lnk [2010.08.19 17:51:00 | 000,003,193 | ---- | C] () -- C:\Users\Wurst\Desktop\VirtualDub.lnk [2010.08.19 17:50:50 | 000,004,068 | ---- | C] () -- C:\Users\Wurst\Desktop\VirtualDubMod.lnk [2010.08.15 22:22:42 | 000,002,027 | ---- | C] () -- C:\Users\Wurst\Desktop\MetaBrowser 2.0.lnk [2010.08.13 20:32:32 | 000,037,376 | ---- | C] () -- C:\Windows\SysWow64\VbVfw.dll [2010.08.13 19:53:59 | 000,001,138 | ---- | C] () -- C:\Users\Wurst\Desktop\Any Video Converter.lnk [2010.08.12 12:53:05 | 083,267,584 | ---- | C] () -- C:\ProgramData\arcade.mp3 [2010.08.12 12:09:57 | 000,000,101 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc [2010.08.07 01:21:29 | 000,000,000 | -H-- | C] () -- C:\Users\Wurst\Documents\Default.rdp [2010.08.04 19:26:51 | 000,001,254 | ---- | C] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk [2010.08.04 19:24:32 | 001,551,928 | ---- | C] () -- C:\Program Files (x86)\SetupVirtualCloneDrive.exe [2010.08.04 19:24:31 | 000,770,938 | ---- | C] () -- C:\Program Files (x86)\KaraokeSetup.exe [2010.08.03 19:51:25 | 000,000,410 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010.07.30 22:56:21 | 000,001,203 | ---- | C] () -- C:\Users\Public\Desktop\CloneDVD2.lnk [2010.07.27 18:25:38 | 000,001,239 | ---- | C] () -- C:\Users\Wurst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk [2010.07.25 13:37:50 | 000,002,026 | ---- | C] () -- C:\Users\Public\Desktop\CyberLink Media Suite.lnk [2010.07.25 12:52:49 | 000,000,177 | ---- | C] () -- C:\ProgramData\Temp.log [2010.07.25 11:06:39 | 000,001,861 | ---- | C] () -- C:\Users\Wurst\Desktop\UseNeXT.lnk [2010.07.24 18:00:03 | 000,000,727 | ---- | C] () -- C:\Users\Wurst\Documents\My Photos.mfalist [2010.07.24 17:27:42 | 000,001,119 | ---- | C] () -- C:\Users\Public\Desktop\Ashampoo Photo Commander 7.lnk [2010.07.21 17:26:48 | 000,000,125 | -HS- | C] () -- C:\ProgramData\.zreglib [2010.06.20 12:23:16 | 000,197,120 | ---- | C] () -- C:\Windows\patchw32.dll [2010.05.02 08:03:03 | 000,005,632 | ---- | C] () -- C:\Users\Wurst\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.05.02 07:36:34 | 001,526,060 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2010.04.02 17:17:34 | 000,179,091 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat [2010.03.06 12:09:17 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\vbzlib1.dll [2010.02.21 09:14:58 | 000,005,224 | ---- | C] () -- C:\Windows\SysWow64\ucuiinfo.ini [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [1998.07.06 00:00:00 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\MSCC2DE.DLL ========== LOP Check ========== [2010.08.13 19:53:53 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\AnvSoft [2010.07.24 17:31:32 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Ashampoo [2010.06.20 12:24:10 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Atari [2010.02.21 14:06:47 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\DAEMON Tools Lite [2010.03.06 12:09:34 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Desktopicon [2010.06.22 19:18:37 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Farm Mania 2 [2010.07.23 18:23:35 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\ImgBurn [2010.02.21 13:46:01 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Leadertech [2010.08.12 09:14:02 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Movienizer [2010.05.02 08:04:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Nokia [2010.06.27 12:29:37 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\OpenOffice.org [2010.05.02 08:08:00 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\PC Suite [2010.04.04 15:39:41 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\PoBros [2010.08.12 12:23:31 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Push-A-Button [2010.09.16 19:44:49 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\UseNeXT [2010.09.16 21:27:40 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\uTorrent [2010.06.18 19:39:21 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\V-Games [2010.07.21 17:36:35 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2010.03.13 18:20:34 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Adobe [2010.08.13 19:53:53 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\AnvSoft [2010.07.24 17:31:32 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Ashampoo [2010.06.20 12:24:10 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Atari [2010.07.25 20:03:32 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\CyberLink [2010.02.21 14:06:47 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\DAEMON Tools Lite [2010.03.06 12:09:34 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Desktopicon [2010.09.04 08:14:48 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\DivX [2010.08.21 09:30:11 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\dvdcss [2010.06.22 19:18:37 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Farm Mania 2 [2010.02.21 09:11:04 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Identities [2010.07.23 18:23:35 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\ImgBurn [2010.02.21 09:14:38 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\InstallShield [2010.02.21 13:46:01 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Leadertech [2010.02.21 09:41:49 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Macromedia [2010.09.15 17:37:42 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Malwarebytes [2010.08.12 14:58:38 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Media Center Programs [2010.08.04 19:12:35 | 000,000,000 | --SD | M] -- C:\Users\Wurst\AppData\Roaming\Microsoft [2010.08.12 09:14:02 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Movienizer [2010.02.21 09:23:32 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Mozilla [2010.05.02 08:04:33 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Nokia [2010.06.27 12:29:37 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\OpenOffice.org [2010.05.02 08:08:00 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\PC Suite [2010.04.04 15:39:41 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\PoBros [2010.08.12 12:23:31 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\Push-A-Button [2010.09.16 19:44:49 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\UseNeXT [2010.09.16 21:27:40 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\uTorrent [2010.06.18 19:39:21 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\V-Games [2010.07.25 11:17:56 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\vlc [2010.05.22 22:53:14 | 000,000,000 | ---D | M] -- C:\Users\Wurst\AppData\Roaming\WinRAR < %APPDATA%\*.exe /s > [2010.03.06 12:09:34 | 000,031,836 | ---- | M] () -- C:\Users\Wurst\AppData\Roaming\Desktopicon\uninst.exe [2010.08.15 22:22:42 | 000,064,712 | R--- | M] () -- C:\Users\Wurst\AppData\Roaming\Microsoft\Installer\{4902F8E1-B2DC-488C-AEBB-96548B832ED5}\_1B184F214272163F6CA0F7.exe [2010.08.15 22:22:41 | 000,064,712 | R--- | M] () -- C:\Users\Wurst\AppData\Roaming\Microsoft\Installer\{4902F8E1-B2DC-488C-AEBB-96548B832ED5}\_2495CA173BFDFFE1C83747.exe [2010.08.15 22:22:41 | 000,064,712 | R--- | M] () -- C:\Users\Wurst\AppData\Roaming\Microsoft\Installer\{4902F8E1-B2DC-488C-AEBB-96548B832ED5}\_6FEFF9B68218417F98F549.exe [2010.08.04 19:12:35 | 000,040,960 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Wurst\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe [2010.08.04 19:12:35 | 000,040,960 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Wurst\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe [2010.08.04 19:12:35 | 000,008,854 | R--- | M] () -- C:\Users\Wurst\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\Uninstall_Project64__9559F7CA5E344237A2D9D856464AD727.exe < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys < MD5 for: ATAPI.SYS > [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll [2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll < MD5 for: EVENTLOG.DLL > [2008.06.06 14:03:52 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll < MD5 for: IASTORV.SYS > [2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys [2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys < MD5 for: NETLOGON.DLL > [2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll < MD5 for: NVSTOR.SYS > [2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys [2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys < MD5 for: SCECLI.DLL > [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll [2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll < MD5 for: USER32.DLL > [2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll [2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll [2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll [2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll < MD5 for: USERINIT.EXE > [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe [2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe [2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe [2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe < MD5 for: WS2IFSL.SYS > [2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < End of report > |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Unbekannte Internetseiten in der Chronik Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!!
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
