Log-Analyse und Auswertung: PC fährt runter und ist lahmer als sonst!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.
| ![]() PC fährt runter und ist lahmer als sonst! Hallo, und gleich im Voraus ein riesiges Dankeschön für die Arbeit die ihr hier leistet und die Zeit die ihr opfert, das ist wirklich eine saubere Sache! Zu meinem Problem: Seit 2-3 Tagen ist mein PC furchtbar lahm, anfangs hat er sich sogar selbst runter und wieder hochgefahren ("Windows wird in weniger als 1 Minute beendet"). Die Probleme scheinen jedoch wieder besser zu werden, runtergefahren hat er sich seit gestern nicht mehr und die Geschwindigkeit ist auch wieder okay, und das, ohne dass ich irgendetwas gemacht habe. (Lediglich hier im Forum wollen die Amazon Werbungen nicht laden, weswegen manche Seiten unvollständig angezeigt werden...) Ich wollte zwar das System neu aufsetzen, aber vielleicht ist das ja garnicht mehr nötig? Hatte 3 Funde mit Malwarebytes was mich dann direkt geschockt hat, daher wollt ich einfach mal freundlich bitten ob sich Jemand meine Logs ansehen könnte, bevor ich alles kurz und klein schlagen muss... Was ich bisher gemacht habe: - Scan mit Antivir (ergebnislos) - Sämtliche wichtigen Passwörter auf einem sauberen PC geändert - Scans mit Malwarebytes und OTL Hier meine Logs, Malwarebytes: Code:
ATTFilter Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4850 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18975 16.10.2010 17:21:47 mbam-log-2010-10-16 (17-21-47).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 139171 Laufzeit: 10 Minute(n), 17 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 2 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 1 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\helper (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\desktop sms (Worm.P2P) -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Users\***\AppData\Roaming\Helper\bin\liveu.exe (Trojan.Agent) -> Quarantined and deleted successfully. Code:
ATTFilter OTL logfile created on: 16.10.2010 17:38:40 - Run 2 OTL by OldTimer - Version Folder = C:\Users\***\Downloads Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18975) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 52,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 71,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 93,08 Gb Total Space | 17,04 Gb Free Space | 18,31% Space Free | Partition Type: NTFS Drive E: | 91,76 Gb Total Space | 87,39 Gb Free Space | 95,24% Space Free | Partition Type: NTFS Computer Name: ***-PC | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\***\Downloads\OTL(2).exe (OldTimer Tools) PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation) PRC - C:\Programme\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.) PRC - C:\Programme\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) PRC - C:\Programme\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Programme\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Programme\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks) PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) PRC - C:\Programme\TOSHIBA\TOSCDSPD\TOSCDSPD.exe () PRC - C:\Programme\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) PRC - c:\Programme\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.) PRC - C:\Programme\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation) PRC - C:\Programme\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) PRC - C:\Programme\Windows Defender\MSASCui.exe (Microsoft Corporation) PRC - C:\Programme\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) PRC - c:\Programme\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) PRC - C:\Programme\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.) PRC - C:\Programme\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION) PRC - C:\Programme\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION) PRC - C:\Programme\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION) PRC - c:\Programme\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation) PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) PRC - c:\Programme\McAfee\MSC\mcuimgr.exe (McAfee, Inc.) PRC - C:\Programme\McAfee.com\Agent\mcagent.exe (McAfee, Inc.) PRC - C:\Programme\McAfee\MPF\MpfSrv.exe (McAfee, Inc.) PRC - C:\Programme\Canon\IJPLM\ijplmsvc.exe () PRC - C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation) PRC - C:\Programme\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.) ========== Modules (SafeList) ========== MOD - C:\Users\***\Downloads\OTL(2).exe (OldTimer Tools) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation) MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (npggsvc) -- C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.) SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.) SRV - (WinHttpAutoProxySvc) -- winhttp.dll (Microsoft Corporation) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (McNASvc) -- c:\Programme\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.) SRV - (TNaviSrv) -- C:\Programme\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (TosCoSrv) -- c:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) SRV - (mcmscsvc) -- C:\Programme\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.) SRV - (ConfigFree Service) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION) SRV - (TOSHIBA SMART Log Service) -- c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation) SRV - (TODDSrv) -- C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) SRV - (MpfService) -- C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.) SRV - (IJPLMSVC) -- C:\Programme\Canon\IJPLM\ijplmsvc.exe () SRV - (UleadBurningHelper) -- C:\Programme\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.) SRV - (FirebirdServerMAGIXInstance) -- C:\Programme\MAGIX\Common\Database\bin\fbserver.exe (MAGIX®) ========== Driver Services (SafeList) ========== DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.) DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys () DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH) DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.) DRV - (tos_sps32) -- C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation) DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.) DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation) DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.) DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.) DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems) DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company) DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.) DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic) DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation) DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation) DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.) DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation) DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd) DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.) DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic) DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.) DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex) DRV - (HSFHWAZL) -- C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.) DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic) DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation) DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation) DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.) DRV - (NETw3v32) Intel(R) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation) DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.) DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.) DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.) DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.) DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation ) DRV - (RTL8187B) -- C:\Windows\System32\drivers\rtl8187B.sys (Realtek Semiconductor Corporation ) DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.) DRV - (TVALZ) -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation) DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.) DRV - (HSF_DPV) -- C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.) DRV - (HSXHWAZL) -- C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.) DRV - (winachsf) -- C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.) DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.) DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation) DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation) DRV - (MPFP) -- C:\Windows\System32\drivers\Mpfp.sys (McAfee, Inc.) DRV - (RtlProt) -- C:\Windows\System32\drivers\RtlProt.sys (Windows (R) Codename Longhorn DDK provider) DRV - (FwLnk) -- C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation) DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation) DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.) DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation) DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH) DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.) DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.) DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.) DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic) DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic) DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation) DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic) DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.) DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.) DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.) DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.) DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.) DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.) DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies) DRV - (tdcmdpst) -- C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.) DRV - (PID_0928) Logitech QuickCam Express(PID_0928) -- C:\Windows\System32\drivers\LV561AV.SYS (Logitech Inc.) DRV - (LVUSBSta) -- C:\Windows\System32\drivers\LVUSBSta.sys (Logitech Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "www.google.de" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2 FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6 FF - prefs.js..extensions.enabledItems: web@veoh.com:1.4 FF - prefs.js..extensions.enabledItems: foxyproxy@eric.h.jung:2.22.1 FF - prefs.js..keyword.URL: "hxxp://www.google.de/search?hl=de&q=" FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.09.18 22:34:17 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.09.18 22:34:17 | 000,000,000 | ---D | M] [2008.07.06 15:37:53 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Extensions [2010.10.16 11:09:27 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\cc0tpddt.default\extensions [2010.05.03 14:44:38 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\cc0tpddt.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010.04.10 14:02:00 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\cc0tpddt.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2010.09.10 00:21:43 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\cc0tpddt.default\extensions\foxyproxy@eric.h.jung [2010.10.16 17:18:02 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\FireFox\Profiles\cc0tpddt.default\searchplugins\icqplugin-1.xml [2009.09.11 00:30:27 | 000,000,961 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\FireFox\Profiles\cc0tpddt.default\searchplugins\icqplugin-3.xml [2009.10.28 23:49:32 | 000,000,961 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\FireFox\Profiles\cc0tpddt.default\searchplugins\icqplugin-4.xml [2009.11.06 16:39:28 | 000,000,961 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\FireFox\Profiles\cc0tpddt.default\searchplugins\icqplugin-5.xml [2009.07.13 17:12:02 | 000,000,944 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\FireFox\Profiles\cc0tpddt.default\searchplugins\icqplugin.xml [2010.04.24 17:09:51 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions [2009.07.16 11:45:19 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2008.09.04 02:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npbittorrent.dll [2010.09.18 22:34:11 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010.09.18 22:34:11 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml [2010.09.18 22:34:11 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010.09.18 22:34:11 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010.09.18 22:34:11 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programme\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4 - HKLM..\Run: [00TCrdMain] C:\Programme\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [ Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.) O4 - HKLM..\Run: [NDSTray.exe] File not found O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [SmoothView] C:\Programme\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (TOSHIBA) O4 - HKLM..\Run: [TPwrMain] C:\Programme\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [Comobj] C:\Users\***\AppData\Roaming\Adobe\Update\apires.exe () O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation) O4 - HKCU..\Run: [TOSCDSPD] File not found O4 - HKCU..\Run: [VeohPlugin] C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks) O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103471 -Mozilla\5.0 ( File not found O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: eBay - Der weltweite Online Marktplatz - {76577871-04EC-495E-A12B-91F7C3600AFA} - File not found O9 - Extra Button: Amazon.de - {8A918C1D-E123-4E36-B562-5C1519E434CE} - File not found O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19) O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - igfxdev.dll (Intel Corporation) O24 - Desktop WallPaper: C:\Users\***\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\***\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{03508a0d-213c-11df-ab47-b64b2f2a0af3}\Shell - "" = AutoRun O33 - MountPoints2\{03508a0d-213c-11df-ab47-b64b2f2a0af3}\Shell\AutoRun\command - "" = H:\autorun.exe -- File not found O33 - MountPoints2\{33caca0d-09be-11df-9a6d-85cd6a02a7f6}\Shell - "" = AutoRun O33 - MountPoints2\{33caca0d-09be-11df-9a6d-85cd6a02a7f6}\Shell\AutoRun\command - "" = D:\Autorun.exe -- File not found O33 - MountPoints2\{36d25be2-8c00-11df-9db7-c7eea72211f8}\Shell - "" = AutoRun O33 - MountPoints2\{36d25be2-8c00-11df-9db7-c7eea72211f8}\Shell\AutoRun\command - "" = G:\StartVMCLite.exe -- File not found O33 - MountPoints2\{36d25be3-8c00-11df-9db7-c7eea72211f8}\Shell - "" = AutoRun O33 - MountPoints2\{36d25be3-8c00-11df-9db7-c7eea72211f8}\Shell\AutoRun\command - "" = G:\StartVMCLite.exe -- File not found O33 - MountPoints2\{3e48449e-1b15-11de-9de3-bae3181cf16a}\Shell - "" = AutoRun O33 - MountPoints2\{3e48449e-1b15-11de-9de3-bae3181cf16a}\Shell\AutoRun\command - "" = D:\StartVMCLite.exe -- File not found O33 - MountPoints2\{3e48449f-1b15-11de-9de3-bae3181cf16a}\Shell - "" = AutoRun O33 - MountPoints2\{3e48449f-1b15-11de-9de3-bae3181cf16a}\Shell\AutoRun\command - "" = G:\StartVMCLite.exe -- File not found O33 - MountPoints2\{890fb764-f445-11dd-b4a0-cd673168001b}\Shell - "" = AutoRun O33 - MountPoints2\{890fb764-f445-11dd-b4a0-cd673168001b}\Shell\AutoRun\command - "" = D:\StartVMCLite.exe -- File not found O33 - MountPoints2\{890fb765-f445-11dd-b4a0-cd673168001b}\Shell - "" = AutoRun O33 - MountPoints2\{890fb765-f445-11dd-b4a0-cd673168001b}\Shell\AutoRun\command - "" = G:\StartVMCLite.exe -- File not found O33 - MountPoints2\{89197064-7359-11dd-ab65-f015ba2163bc}\Shell - "" = AutoRun O33 - MountPoints2\{89197064-7359-11dd-ab65-f015ba2163bc}\Shell\AutoRun\command - "" = D:\StartVMCLite.exe -- File not found O33 - MountPoints2\{8919706a-7359-11dd-ab65-f015ba2163bc}\Shell - "" = AutoRun O33 - MountPoints2\{8919706a-7359-11dd-ab65-f015ba2163bc}\Shell\AutoRun\command - "" = D:\StartVMCLite.exe -- File not found O33 - MountPoints2\{cd0f1183-7363-11dd-8c55-c6a6a489b7f8}\Shell - "" = AutoRun O33 - MountPoints2\{cd0f1183-7363-11dd-8c55-c6a6a489b7f8}\Shell\AutoRun\command - "" = D:\StartVMCLite.exe -- File not found O33 - MountPoints2\{cd0f1184-7363-11dd-8c55-c6a6a489b7f8}\Shell - "" = AutoRun O33 - MountPoints2\{cd0f1184-7363-11dd-8c55-c6a6a489b7f8}\Shell\AutoRun\command - "" = G:\StartVMCLite.exe -- File not found O33 - MountPoints2\{f3f5e271-25a3-11de-9814-9e25e16d1fa9}\Shell\AutoRun\command - "" = G:\setupSNK.exe -- File not found O33 - MountPoints2\D\Shell - "" = AutoRun O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\StartVMCLite.exe -- File not found O33 - MountPoints2\H\Shell - "" = AutoRun O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.10.16 17:05:42 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes [2010.10.16 17:05:05 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2010.10.16 17:04:55 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2010.10.16 17:04:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.10.16 17:04:54 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware [2010.10.14 12:33:02 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Helper [2010.10.13 12:04:58 | 008,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL [2010.10.13 12:04:17 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netevent.dll [2010.10.13 12:03:34 | 000,157,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll [2010.10.13 12:03:27 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2010.10.13 12:03:27 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2010.10.13 12:03:27 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2010.10.13 12:03:26 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2010.10.13 12:03:26 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll [2010.10.13 12:03:25 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2010.10.13 12:03:25 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2010.10.13 12:03:25 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2010.10.13 12:03:25 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2010.10.13 12:03:25 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2010.10.13 12:03:25 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2010.10.13 12:03:25 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2010.10.13 12:03:25 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2010.10.13 12:03:25 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2010.10.13 12:03:25 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2010.10.13 12:03:25 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2010.10.13 12:03:25 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2010.10.13 12:03:19 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40.dll [2010.10.13 12:03:19 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40u.dll [2010.10.13 12:03:12 | 002,038,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2010.10.13 12:03:10 | 000,231,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshsq.dll [2010.10.13 12:03:08 | 000,867,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpmde.dll [2010.10.10 15:26:05 | 000,000,000 | ---D | C] -- C:\Programme\ASCII [2010.10.09 16:53:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Umineko6 [2010.10.09 16:33:44 | 000,000,000 | ---D | C] -- C:\Users\***\Documents\umineko-ep6 [2010.10.04 21:28:33 | 003,890,920 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Windows\System32\GameMon.des [2010.10.04 19:15:52 | 000,000,000 | ---D | C] -- C:\Programme\gPotato.eu [2010.10.04 15:55:24 | 000,000,000 | ---D | C] -- C:\Programme\Neffy [2010.09.29 11:44:12 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll [2010.09.24 09:49:53 | 000,000,000 | ---D | C] -- C:\Programme\NosTale(DE) [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Users\***\Documents\*.tmp files -> C:\Users\***\Documents\*.tmp -> ] [1 C:\Users\***\Desktop\*.tmp files -> C:\Users\***\Desktop\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010.10.16 17:31:08 | 000,038,561 | ---- | M] () -- C:\Windows\System32\Config.MPF [2010.10.16 17:28:22 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{28AB3EC4-FDC9-46B8-BDE7-41DC0D0D40F0}.job [2010.10.16 17:25:54 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2010.10.16 17:25:43 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010.10.16 17:25:43 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010.10.16 17:25:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.10.16 17:25:30 | 2136,961,024 | -HS- | M] () -- C:\hiberfil.sys [2010.10.16 17:05:10 | 000,000,823 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.10.16 16:57:00 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2010.10.16 16:16:41 | 000,618,442 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2010.10.16 16:16:41 | 000,587,178 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2010.10.16 16:16:41 | 000,122,842 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2010.10.16 16:16:41 | 000,101,250 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2010.10.15 17:22:06 | 000,000,560 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for ***.job [2010.10.15 12:04:23 | 000,075,264 | ---- | M] () -- C:\Users\***\Desktop\Bus_WiSe_1011_a.doc [2010.10.15 10:32:35 | 000,322,848 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2010.10.13 12:50:19 | 000,015,961 | ---- | M] () -- C:\Users\***\Desktop\Altklausur_2010.docx [2010.10.12 13:59:30 | 000,032,725 | ---- | M] () -- C:\Users\***\Desktop\plan5sem-2010.pdf [2010.10.09 20:59:11 | 000,053,760 | ---- | M] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.10.09 17:01:21 | 000,001,326 | ---- | M] () -- C:\Users\***\Desktop\Umineko no Naku Koro ni EP6.exe.lnk [2010.10.04 19:26:22 | 000,000,908 | ---- | M] () -- C:\Users\***\Desktop\Flyff.lnk [2010.10.01 01:00:00 | 000,000,348 | ---- | M] () -- C:\Windows\tasks\McQcTask.job [2010.09.25 11:22:18 | 000,002,078 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk [2010.09.24 09:54:11 | 000,001,471 | ---- | M] () -- C:\Users\Public\Desktop\NosTale.lnk [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Users\***\Documents\*.tmp files -> C:\Users\***\Documents\*.tmp -> ] [1 C:\Users\***\Desktop\*.tmp files -> C:\Users\***\Desktop\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.10.16 17:05:10 | 000,000,823 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.10.15 12:04:21 | 000,075,264 | ---- | C] () -- C:\Users\***\Desktop\Bus_WiSe_1011_a.doc [2010.10.13 12:50:17 | 000,015,961 | ---- | C] () -- C:\Users\***\Desktop\Altklausur_2010.docx [2010.10.12 13:59:30 | 000,032,725 | ---- | C] () -- C:\Users\***\Desktop\plan5sem-2010.pdf [2010.10.10 15:26:18 | 000,087,040 | ---- | C] () -- C:\Windows\UnGins.exe [2010.10.10 15:26:06 | 000,237,568 | ---- | C] () -- C:\Windows\System32\Unlha32.dll [2010.10.10 15:26:05 | 000,473,600 | ---- | C] () -- C:\Windows\System32\Harmony.dll [2010.10.09 17:01:04 | 000,001,326 | ---- | C] () -- C:\Users\***\Desktop\Umineko no Naku Koro ni EP6.exe.lnk [2010.10.04 19:26:22 | 000,000,908 | ---- | C] () -- C:\Users\***\Desktop\Flyff.lnk [2010.09.25 11:22:18 | 000,002,078 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk [2010.09.24 09:54:11 | 000,001,471 | ---- | C] () -- C:\Users\Public\Desktop\NosTale.lnk [2010.02.24 14:49:55 | 000,000,292 | ---- | C] () -- C:\Windows\vtmb.ini [2010.01.25 16:26:11 | 000,691,696 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys [2009.12.09 23:17:05 | 000,089,300 | ---- | C] () -- C:\Windows\System32\HCDTRULE.DLL [2009.12.09 23:17:00 | 000,032,768 | ---- | C] () -- C:\Windows\System32\thapi.dll [2009.12.09 21:02:45 | 000,001,025 | ---- | C] () -- C:\Windows\System32\sysprst.dll [2009.12.09 21:02:45 | 000,000,203 | ---- | C] () -- C:\Windows\System32\lsprst.dll [2009.09.11 14:41:56 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009.04.12 13:36:43 | 000,005,864 | ---- | C] () -- C:\Users\***\AppData\Local\d3d9caps.dat [2009.04.10 13:01:55 | 000,000,056 | RHS- | C] () -- C:\Windows\System32\7CB775C798.sys [2009.04.10 13:01:39 | 000,000,952 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys [2009.02.17 18:02:49 | 000,000,552 | ---- | C] () -- C:\Users\***\AppData\Local\d3d8caps.dat [2009.01.26 13:48:12 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2009.01.18 17:59:36 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2008.07.23 18:50:52 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll [2008.07.23 18:46:38 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll [2008.07.20 18:55:18 | 000,053,760 | ---- | C] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008.07.08 23:30:00 | 000,000,016 | -H-- | C] () -- C:\Users\***\AppData\Roaming\mxfilerelatedcache.mxc2 [2008.07.08 23:30:00 | 000,000,016 | -H-- | C] () -- C:\Users\***\AppData\Local\mxfilerelatedcache.mxc2 [2008.07.06 14:13:53 | 000,000,242 | ---- | C] () -- C:\Users\***\AppData\Roaming\wklnhst.dat [2008.07.06 11:15:07 | 000,131,072 | ---- | C] () -- C:\Windows\System32\EnumDevLib.dll [2008.07.06 11:13:07 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini [2008.07.06 11:13:07 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll [2008.07.06 11:13:07 | 000,009,480 | ---- | C] () -- C:\Windows\System32\tosmreg.ini [2008.07.06 11:13:07 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini [2008.04.01 13:16:40 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI [2008.03.31 10:34:28 | 000,006,642 | ---- | C] () -- C:\Windows\mgxoschk.ini [2008.03.31 10:21:26 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll [2008.03.31 10:21:26 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll [2008.03.31 10:21:26 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll [2008.03.31 10:21:26 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll [2008.03.31 10:21:26 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll [2008.03.31 10:21:26 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll [2008.03.31 09:40:32 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll [2008.03.31 09:39:41 | 001,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll [2008.03.31 09:39:41 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll [2008.03.31 09:39:41 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1329.dll [2008.03.31 09:39:41 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2005.01.31 08:37:58 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini [1999.01.27 13:39:06 | 000,065,024 | ---- | C] () -- C:\Windows\System32\indounin.dll [1997.06.13 07:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\Iyvu9_32.dll < End of report > Code:
ATTFilter OTL Extras logfile created on: 16.10.2010 17:38:40 - Run 2 OTL by OldTimer - Version Folder = C:\Users\***\Downloads Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18975) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 52,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 71,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 93,08 Gb Total Space | 17,04 Gb Free Space | 18,31% Space Free | Partition Type: NTFS Drive E: | 91,76 Gb Total Space | 87,39 Gb Free Space | 95,24% Space Free | Partition Type: NTFS Computer Name: ***-PC | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.) ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{12919807-C378-4DDC-A32F-848809A0AF28}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2DBF1338-6FDE-4885-A23D-FD37152A38EB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2FED32EF-F63E-4A28-B4C3-6178CA21DBEF}" = lport=2869 | protocol=6 | dir=in | app=system | "{4416F2BC-A254-47EA-A4F5-530065A0C7AA}" = lport=2869 | protocol=6 | dir=in | app=system | "{450D3D11-F1F3-4678-BC52-B450DB06E694}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5023736B-9781-4E59-B240-F2492D199C8C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{5102A39A-864D-4212-BCCE-6D6791D98D2F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5A18735B-8B1B-4649-915A-7789F3887C14}" = lport=10243 | protocol=6 | dir=in | app=system | "{6BE51516-15BD-4B65-95F3-17C839F0652C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{738BBF97-9EDC-4B00-BC05-A9932D4C1B55}" = rport=10243 | protocol=6 | dir=out | app=system | "{83CED82D-5516-4483-9473-26FDFD232C0D}" = lport=2869 | protocol=6 | dir=in | app=system | "{898F0CEF-4246-4367-B9D3-35EF2BA5D5FA}" = lport=2869 | protocol=6 | dir=in | app=system | "{9348A34F-C730-430B-BEBA-E7D83C6022D9}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A1045BA4-D1B6-46A7-8E6F-A36F9675E9C4}" = lport=2869 | protocol=6 | dir=in | app=system | "{B83C94B4-5FB9-4A45-BA32-0E6ACA342219}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{C07BABA2-ABBA-48BE-B66E-A8C31200EC16}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D0F059BC-544D-44ED-9B1C-246E78BCF54F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{094FA324-3432-4392-805F-2F4A4FF9F9C0}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | "{0AD1B980-EA15-4ED9-A9CD-983FC27C0DE4}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe | "{0F474225-0DB2-4513-B0A7-2C7D2AECA396}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{1C0B5523-AA3C-42E1-A06F-AC3115DA2F82}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe | "{264AD80D-D6D7-4CAB-AACC-CF9679AA69DF}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe | "{2B394B55-6FEC-4B26-B4C6-B9C01C7E0E3F}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{42737AD4-3979-4591-9837-BE9B07B16D6D}" = dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe | "{4E302A80-D970-4C11-BF9A-6D5960BF2E94}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{5B4F54D2-B5AE-4886-9126-A4767106B99B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{693528D5-71AB-43A0-94E9-C35482D75341}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{6CDD49C2-6549-4AF2-BDDE-B535D11D898B}" = protocol=17 | dir=in | app=c:\program files\smartftp client\smartftp.exe | "{78DAD281-48A0-4E13-9D77-08A44F0D673E}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{886AD8D0-7CAA-4E80-8FD0-4609677B4DAD}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{89FFE642-8282-4DD2-B9D0-18BA8BC623E8}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{8B1A6C7F-95AA-414B-B637-306710BCE471}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{8E88EAE0-2185-4460-B9F5-138934360EC0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{979D475C-C161-4843-B143-0548265C8713}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{9C05BCED-CF3C-41B0-BAD5-C397FC5C25C0}" = protocol=6 | dir=in | app=c:\program files\smartftp client\smartftp.exe | "{A331B367-4452-41D7-B683-182B1BD5CF5C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{B0A865D3-490B-421C-A7E0-2BE8D2C6E5F5}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{BE8CF286-8EF5-412E-A18C-1548547863F9}" = protocol=6 | dir=out | app=system | "{BFF732CB-E6FD-4660-A030-4DC7E47E9E37}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C464F03E-A8FA-46AA-8D1A-9C6746747193}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | "{CAAF8D2D-8B0A-476B-920E-939875F37EAD}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe | "{CFA69412-BEEB-4923-8954-9467178CAD01}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{D1459E3A-D3C6-4B6B-86B6-5C49EF3C3253}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{D47D153A-9384-4C96-B29B-BC17F6E6555C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{D7465523-7F28-4D9A-9807-752C3DE8E4CC}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe | "{DFB98BED-54D4-43B3-9AE5-145BA8A3E3EE}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "{E18B4BC3-2D81-409C-9F16-1FAC632FE562}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | "{E61396A0-D81C-48E1-BF88-953F3DCD2D81}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "{FB4CE107-6CCF-421A-9791-C4F25A8EC5F8}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | "{FBC95DA2-EAD9-472F-AE0D-D765EE14E99A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{FBDCCB43-1EE5-47F7-863C-98CC35BA66CA}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | "TCP Query User{14A931FA-D318-46FF-90C8-90A74DB3A988}C:\program files\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire\xfire.exe | "TCP Query User{2584175E-3022-45A3-A9BB-1E1D7D41DE7C}C:\users\***\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\***\program files\dna\btdna.exe | "TCP Query User{2BFB8D74-CAAF-4170-9D9C-58283148127A}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "TCP Query User{2E4808B4-26FF-4EDB-868F-EC1FEE73DA32}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | "TCP Query User{3A42CF3D-328D-48EF-8769-08FD54FC887C}C:\program files\qip\qip.exe" = protocol=6 | dir=in | app=c:\program files\qip\qip.exe | "TCP Query User{4860269D-F2CD-468C-8D6C-87B72DCB194A}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "TCP Query User{497768EA-AB05-4D7C-A7A1-393CC32C033B}C:\program files\ws_ftp\ws_ftp95.exe" = protocol=6 | dir=in | app=c:\program files\ws_ftp\ws_ftp95.exe | "TCP Query User{4E1850E0-F741-4F4F-BAB5-04DFE06CCD2D}C:\users\***\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\***\program files\dna\btdna.exe | "TCP Query User{51D3AE86-89BA-4903-8401-B3BFDC5D9F4E}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe | "TCP Query User{6BDCBD5A-9153-4FAF-AA92-2369C2C20441}C:\program files\java\jre1.6.0_07\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre1.6.0_07\bin\javaw.exe | "TCP Query User{6F1E26B9-83B3-4575-879C-68903FCD3F5F}C:\program files\java\jre1.6.0_07\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre1.6.0_07\bin\javaw.exe | "TCP Query User{8DD78664-999C-499D-A9E1-83C8807BD9A0}C:\users\***\desktop\scarlet weather rhapsody\th123.exe" = protocol=6 | dir=in | app=c:\users\***\desktop\scarlet weather rhapsody\th123.exe | "TCP Query User{A091B801-EAE8-4293-BE79-489CCEF7E0FB}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | "TCP Query User{A1CB1B07-0288-4FD5-9B20-76438670EA75}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "TCP Query User{C7D3DC60-A6E7-4AB9-8A15-E7A177B06FB3}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "TCP Query User{D84AE58A-3917-4432-92EB-66270A89BA08}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "TCP Query User{DF6C3344-3E0C-4D99-ABF3-8651BD457753}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe | "TCP Query User{E77D49BB-CC80-42F5-8FF2-E73948D0AFB9}C:\program files\qip\qip.exe" = protocol=6 | dir=in | app=c:\program files\qip\qip.exe | "TCP Query User{F2E0E5FB-7D8F-47FC-8F71-FDDCD4AF73CF}C:\program files\ws_ftp\ws_ftp95.exe" = protocol=6 | dir=in | app=c:\program files\ws_ftp\ws_ftp95.exe | "UDP Query User{069E868A-0FDB-4756-A9A3-8FBE1B3C3F75}C:\users\***\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\***\program files\dna\btdna.exe | "UDP Query User{132E3D5A-59DF-414C-9778-386C0095004D}C:\program files\ws_ftp\ws_ftp95.exe" = protocol=17 | dir=in | app=c:\program files\ws_ftp\ws_ftp95.exe | "UDP Query User{1EEA91A7-68A0-4E35-B54D-0142683BA7DB}C:\users\***\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\***\program files\dna\btdna.exe | "UDP Query User{3A90542E-A543-4EE0-8220-12F62315BECA}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "UDP Query User{412529B6-0B76-4EB3-AD88-E0D5A9BE141F}C:\program files\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files\xfire\xfire.exe | "UDP Query User{491CF006-7539-4550-BBE9-77CE68D78B71}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe | "UDP Query User{4F98AE32-6671-4AE7-8C34-FAF8103C49A4}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe | "UDP Query User{5A6890FB-A6C4-400F-BA3E-9B3CB7EF6CDE}C:\program files\java\jre1.6.0_07\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre1.6.0_07\bin\javaw.exe | "UDP Query User{5C061FF0-4571-4ADC-B234-CBCC22497429}C:\program files\qip\qip.exe" = protocol=17 | dir=in | app=c:\program files\qip\qip.exe | "UDP Query User{8415CF80-C231-436C-AE63-003CE1830BA6}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "UDP Query User{912FB7D5-1BD3-4EBA-BE67-8AE76EB48DB5}C:\users\***\desktop\scarlet weather rhapsody\th123.exe" = protocol=17 | dir=in | app=c:\users\***\desktop\scarlet weather rhapsody\th123.exe | "UDP Query User{92FAD6ED-A56E-4F4B-9120-B094AE475D6F}C:\program files\qip\qip.exe" = protocol=17 | dir=in | app=c:\program files\qip\qip.exe | "UDP Query User{9B456189-9DA1-4EE7-A50D-4D49DF3F706F}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "UDP Query User{CF72A532-77C7-45BC-AC6F-CAE6A82BF6AD}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe | "UDP Query User{D00549CB-E18A-407B-8288-2B363EA8C068}C:\program files\ws_ftp\ws_ftp95.exe" = protocol=17 | dir=in | app=c:\program files\ws_ftp\ws_ftp95.exe | "UDP Query User{DF2D1C5A-EDBB-4F17-B800-900A3C430F51}C:\program files\java\jre1.6.0_07\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre1.6.0_07\bin\javaw.exe | "UDP Query User{E68FDBD1-2796-4B36-B808-0346F95FD3F8}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "UDP Query User{ED67467F-2718-4D97-A4DE-C82DDE33C96D}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "UDP Query User{FADAC09D-48CA-4620-9BE6-8ED3520EF5B3}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{02CA24DD-C8B0-4280-BE53-7862869C2EB1}" = Realtek WiFi Protected Setup Library "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series" = Canon iP2600 series "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4500_series" = Canon iP4500 series "{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime "{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product Information "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0 "{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java(TM) 6 Update 19 "{2883F6F5-0509-43F3-868C-D50330DD9DD3}" = TOSHIBA Hardware Setup "{2C08D7E7-9EE1-4A08-AFE0-745F02DCD6A4}_is1" = Pokemon Online 0.9.90 "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3 "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 "{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting "{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger "{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4B1E87C3-00DE-4898-8E39-E390AAEF2391}" = TOSHIBA Supervisor Password "{4E868D3D-6EEB-4273-926C-2287236B5B79}" = 3DVIA Player 4.1 "{4FF03FA9-8CC6-4133-97D7-4B12BA73BA3D}" = ViewerLite 5.0 "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{56995235-B76E-44A6-BA17-8FF13D3F907A}" = TOSHIBA Benutzerhandbücher "{5980B928-1C95-4B3E-957B-B02D8147FF9E}" = Desktop SMS "{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TRDCReminder "{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista "{895722FE-25FE-4854-95AC-B0C42F9DBEDA}" = REALTEK RTL8187B Wireless LAN Driver "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8B3E6604-B33C-4717-A4EB-217707E7DEEE}" = SmartFTP Client "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab "{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer "{A8725910-BA4B-4D85-94ED-9BBB89E0229B}" = HyperChem 8.0 Software "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1031-7B44-A81300000003}" = Adobe Reader 8.1.3 - Deutsch "{B5761811-28F3-4257-B537-815C5EEF472C}" = Vodafone Mobile Connect Lite "{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser "{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{B7323F82-22EE-41BF-9CD1-26D70ECEB2E4}" = SmartFTP Client German (Germany) MUI "{C4E2A4A7-B623-40CB-8EEA-72F577E49D56}" = Vampire - The Masquerade Bloodlines "{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader "{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9-Reihe "{E4406ED3-B04C-44F1-ABB4-08775B74934F}" = Call Of Cthulhu DCoTE "{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORDCLauncher "{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA "{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials "{F916C6DF-2601-4385-9500-C45FF398D4CB}" = Install(GE) "{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package "7-Zip" = 7-Zip 4.57 "ACDLabs in C__Program_Files_ACDFREE12_" = ACD/Labs Software in C:\Program Files\ACDFREE12\ "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11 "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "Canon iP2600 series Benutzerregistrierung" = Canon iP2600 series Benutzerregistrierung "Canon iP4500 series Benutzerregistrierung" = Canon iP4500 series Benutzerregistrierung "CANONIJPLM100" = PIXMA Extended Survey Program "CanonMyPrinter" = Canon My Printer "CanonSolutionMenu" = Canon Utilities Solution Menu "CCleaner" = CCleaner "CEP - Colour Enable Packages_is1" = CEP - Color Enable Package "CLC Sequence Viewer 6.0" = CLC Sequence Viewer 6.0 "CNXT_MODEM_PCI_VEN_14F1&DEV_2C06&SUBSYS_14F10000" = HDAUDIO Soft Data Fax Modem with SmartCP "coreavc_is1" = CoreAVC Pro "Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX "Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition (D) "Free Audio CD Burner_is1" = Free Audio CD Burner version 1.2 "HDMI" = Intel(R) Graphics Media Accelerator Driver "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center "InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TRDCReminder "InstallShield_{C4E2A4A7-B623-40CB-8EEA-72F577E49D56}" = Vampire - The Masquerade Bloodlines "InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORDCLauncher "InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package "IrfanView" = IrfanView (remove only) "JDownloader" = JDownloader "MAGIX Digital Foto Maker SE D" = MAGIX Digital Foto Maker SE (D) "MAGIX Foto Suite D" = MAGIX Foto Suite (D) "MAGIX Online Druck Service D" = MAGIX Online Druck Service (D) "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "McAfee Security Scan" = McAfee Security Scan Plus "MediaNavigation.CDLabelPrint" = CD-LabelPrint "Messenger Plus! Live" = Messenger Plus! Live "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10) "MSC" = McAfee SecurityCenter "myphotobook" = myphotobook 3.5 "Neffy" = Neffy 1,3,29,0 "NosTale(DE)_is1" = Nostale(DE) "NSS" = Norton Security Scan "OpenAL" = OpenAL "Petz 4" = Petz 4 "PetzA_is1" = PetzA 2.2.5 "Picasa2" = Picasa 2 "QIP2005" = QIP 2005 Uninstall "Rainbow Client Activator 2.0 English" = Client Activator 2.0 - English (2) "Rainbow Client Activator 2.0 English All" = Client Activator 2.0 - English (All) "RealAlt_is1" = Real Alternative 1.8.2 "RPG Maker 2000 1.07b" = RPG Maker 2000 1.07b "RTP for RM2K (Png, Wav, Midi, Fonts)" = RTP for RM2K (Png, Wav, Midi, Fonts) "ScummVM_is1" = ScummVM 0.12.0 "SmartFTP Client 4.0 Setup Files" = SmartFTP Client 4.0 Setup Files (remove only) "SynTPDeinstKey" = Synaptics Pointing Device Driver "SystemRequirementsLab" = System Requirements Lab "Uninstall_is1" = Uninstall "Veoh Web Player Beta" = Veoh Web Player Beta "VLC media player" = VLC media player 1.0.2 "Windows Media Encoder 9" = Windows Media Encoder 9-Reihe "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR archiver ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Umineko no Naku Koro ni English" = Umineko no Naku Koro ni English v4.3.1 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 26.12.2009 09:36:10 | Computer Name = ***-PC | Source = WinMgmt | ID = 10 Description = Error - 26.12.2009 14:13:35 | Computer Name = ***-PC | Source = WinMgmt | ID = 10 Description = Error - 27.12.2009 06:23:15 | Computer Name = ***-PC | Source = WinMgmt | ID = 10 Description = Error - 28.12.2009 04:48:13 | Computer Name = ***-PC | Source = WinMgmt | ID = 10 Description = Error - 29.12.2009 05:24:32 | Computer Name = ***-PC | Source = WinMgmt | ID = 10 Description = Error - 30.12.2009 06:37:32 | Computer Name = ***-PC | Source = WinMgmt | ID = 10 Description = Error - 30.12.2009 09:28:02 | Computer Name = ***-PC | Source = WinMgmt | ID = 10 Description = Error - 30.12.2009 18:56:37 | Computer Name = ***-PC | Source = WinMgmt | ID = 10 Description = Error - 31.12.2009 05:44:13 | Computer Name = ***-PC | Source = WinMgmt | ID = 10 Description = Error - 31.12.2009 21:45:13 | Computer Name = ***-PC | Source = WinMgmt | ID = 10 Description = [ OSession Events ] Error - 18.07.2009 07:01:22 | Computer Name = ***-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6504.5001, Microsoft Office Version: 12.0.6215.1000. This session lasted 685 seconds with 660 seconds of active time. This session ended with a crash. Error - 05.08.2009 15:09:45 | Computer Name = ***-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 3130 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 15.10.2010 07:12:33 | Computer Name = ***-PC | Source = Server | ID = 2505 Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{D938C1A4-55D1-4201-91E5-360C34A87D18} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error - 15.10.2010 09:18:29 | Computer Name = ***-PC | Source = Server | ID = 2505 Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{D938C1A4-55D1-4201-91E5-360C34A87D18} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error - 15.10.2010 11:40:37 | Computer Name = ***-PC | Source = DCOM | ID = 10010 Description = Error - 15.10.2010 11:48:06 | Computer Name = ***-PC | Source = Server | ID = 2505 Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{D938C1A4-55D1-4201-91E5-360C34A87D18} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error - 15.10.2010 11:48:08 | Computer Name = ***-PC | Source = Server | ID = 2505 Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{D938C1A4-55D1-4201-91E5-360C34A87D18} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error - 15.10.2010 16:24:20 | Computer Name = ***-PC | Source = Server | ID = 2505 Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{D938C1A4-55D1-4201-91E5-360C34A87D18} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error - 15.10.2010 16:24:22 | Computer Name = ***-PC | Source = Server | ID = 2505 Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{D938C1A4-55D1-4201-91E5-360C34A87D18} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error - 16.10.2010 04:59:23 | Computer Name = ***-PC | Source = Server | ID = 2505 Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{D938C1A4-55D1-4201-91E5-360C34A87D18} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error - 16.10.2010 10:21:21 | Computer Name = ***-PC | Source = Server | ID = 2505 Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{D938C1A4-55D1-4201-91E5-360C34A87D18} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error - 16.10.2010 10:21:23 | Computer Name = ***-PC | Source = Server | ID = 2505 Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{D938C1A4-55D1-4201-91E5-360C34A87D18} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. < End of report > Liebe Grüße ![]() |
![]() | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() PC fährt runter und ist lahmer als sonst! Gibt es noch weitere Logs von Malwarebytes? Wenn ja bitte alle Logs posten.
__________________ |
![]() | #3 |
| ![]() PC fährt runter und ist lahmer als sonst! Hab ich was übersehen, ich hoffe nicht? Ich labe Malwarebytes jetzt nochmal laufen lassen und hier den neueren Log:
ATTFilter Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4853 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18975 17.10.2010 16:17:04 mbam-log-2010-10-17 (16-17-04).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 139042 Laufzeit: 17 Minute(n), 11 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Code:
ATTFilter Emsisoft Anti-Malware - Version 1.0 Letztes Update: 16.10.2010 20:33:20 Scan Einstellungen: Scan Methode: Smart Scan Objekte: Speicher, Traces, Cookies, C:\Windows\, C:\Program Files Archiv Scan: Aus Heuristik: Aus ADS Scan: An Scan Beginn: 16.10.2010 20:34:06 Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems gefunden: Trace.Registry.Trymedia!A2 Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems\ActiveMARK Software gefunden: Trace.Registry.Trymedia!A2 C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\Low\***@doubleclick[1].txt gefunden: Trace.TrackingCookie.doubleclick!A2 C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\cc0tpddt.default\cookies.sqlite:1287243160333000 gefunden: Trace.TrackingCookie.doubleclick.net!A2 C:\Windows\Rainbow Technologies\Client Activator\2.0\English\ACTIVATOR.EXE gefunden: Trojan-Dropper.Win32.Mudrop!IK C:\Program Files\NosTale(DE)\ewsf.ews gefunden: Hoax.Win32.BadJoke.Delf.dz!A2 Gescannt Dateien: 149880 Traces: 397713 Cookies: 50 Prozesse: 72 Gefunden Dateien: 2 Traces: 2 Cookies: 2 Prozesse: 0 Registry Keys: 0 Scan Ende: 16.10.2010 23:21:53 Scan Zeit: 2:47:47 C:\Program Files\NosTale(DE)\ewsf.ews Quarantäne Hoax.Win32.BadJoke.Delf.dz!A2 C:\Windows\Rainbow Technologies\Client Activator\2.0\English\ACTIVATOR.EXE Quarantäne Trojan-Dropper.Win32.Mudrop!IK Quarantäne Dateien: 2 Traces: 0 Cookies: 0 C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\cc0tpddt.default\cookies.sqlite:1287243160333000 Gelöscht Trace.TrackingCookie.doubleclick.net!A2 C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\Low\***@doubleclick[1].txt Gelöscht Trace.TrackingCookie.doubleclick!A2 Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems Gelöscht Trace.Registry.Trymedia!A2 Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems\ActiveMARK Software Gelöscht Trace.Registry.Trymedia!A2 Gelöscht Dateien: 0 Traces: 2 Cookies: 2 |
![]() | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() PC fährt runter und ist lahmer als sonst! Ich hab nur nachgefragt, da in letzter Zeit häufig die Logs ohne Funde gepostet wurden. Das ist natürlich sinnfrei. Hast Du jetzt also insgesamt 2x mit MBAM gescannt, jew. Quickscan?
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #5 |
| ![]() PC fährt runter und ist lahmer als sonst! Ja genau! =) |
![]() | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() PC fährt runter und ist lahmer als sonst! Bitte routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Danach neue OTL-Logs machen: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________ --> PC fährt runter und ist lahmer als sonst! |
![]() | #7 |
| ![]() PC fährt runter und ist lahmer als sonst! Alles klar! (Sorry hat jetzt ziemlich gedauert!) Hier der vollständige Malwarebytes Scan: Code:
ATTFilter Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4861 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18975 17.10.2010 19:48:19 mbam-log-2010-10-17 (19-48-19).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|) Durchsuchte Objekte: 294219 Laufzeit: 2 Stunde(n), 17 Minute(n), 39 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Code:
ATTFilter OTL logfile created on: 17.10.2010 19:56:08 - Run 3 OTL by OldTimer - Version Folder = C:\Users\***\Downloads Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18975) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 47,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 69,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 93,08 Gb Total Space | 36,53 Gb Free Space | 39,24% Space Free | Partition Type: NTFS Drive E: | 91,76 Gb Total Space | 87,39 Gb Free Space | 95,24% Space Free | Partition Type: NTFS Computer Name: ***-PC | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\***\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Programme\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.) PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH) PRC - C:\Programme\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation) PRC - C:\Programme\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks) PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) PRC - C:\Programme\TOSHIBA\TOSCDSPD\TOSCDSPD.exe () PRC - C:\Programme\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) PRC - C:\Programme\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation) PRC - C:\Programme\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) PRC - C:\Programme\Windows Defender\MSASCui.exe (Microsoft Corporation) PRC - C:\Programme\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) PRC - c:\Programme\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) PRC - C:\Programme\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION) PRC - C:\Programme\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION) PRC - C:\Programme\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION) PRC - c:\Programme\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation) PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) PRC - C:\Programme\Canon\IJPLM\ijplmsvc.exe () PRC - C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation) PRC - C:\Programme\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.) ========== Modules (SafeList) ========== MOD - C:\Users\***\Downloads\OTL.exe (OldTimer Tools) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation) MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (npggsvc) -- C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.) SRV - (WinHttpAutoProxySvc) -- winhttp.dll (Microsoft Corporation) SRV - (TNaviSrv) -- C:\Programme\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (TosCoSrv) -- c:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) SRV - (ConfigFree Service) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION) SRV - (TOSHIBA SMART Log Service) -- c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation) SRV - (TODDSrv) -- C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) SRV - (IJPLMSVC) -- C:\Programme\Canon\IJPLM\ijplmsvc.exe () SRV - (UleadBurningHelper) -- C:\Programme\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.) SRV - (FirebirdServerMAGIXInstance) -- C:\Programme\MAGIX\Common\Database\bin\fbserver.exe (MAGIX®) ========== Driver Services (SafeList) ========== DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.) DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys () DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.) DRV - (tos_sps32) -- C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation) DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.) DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation) DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.) DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.) DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems) DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company) DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.) DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic) DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation) DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation) DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.) DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation) DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd) DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.) DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic) DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.) DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex) DRV - (HSFHWAZL) -- C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.) DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic) DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation) DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation) DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.) DRV - (NETw3v32) Intel(R) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation) DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.) DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.) DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.) DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.) DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation ) DRV - (RTL8187B) -- C:\Windows\System32\drivers\rtl8187B.sys (Realtek Semiconductor Corporation ) DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.) DRV - (TVALZ) -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation) DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.) DRV - (HSF_DPV) -- C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.) DRV - (HSXHWAZL) -- C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.) DRV - (winachsf) -- C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.) DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.) DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation) DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation) DRV - (RtlProt) -- C:\Windows\System32\drivers\RtlProt.sys (Windows (R) Codename Longhorn DDK provider) DRV - (FwLnk) -- C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation) DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation) DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.) DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation) DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH) DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.) DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.) DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.) DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic) DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic) DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation) DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic) DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.) DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.) DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.) DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.) DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.) DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.) DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies) DRV - (tdcmdpst) -- C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.) DRV - (PID_0928) Logitech QuickCam Express(PID_0928) -- C:\Windows\System32\drivers\LV561AV.SYS (Logitech Inc.) DRV - (LVUSBSta) -- C:\Windows\System32\drivers\LVUSBSta.sys (Logitech Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "www.google.de" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2 FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6 FF - prefs.js..extensions.enabledItems: web@veoh.com:1.4 FF - prefs.js..extensions.enabledItems: foxyproxy@eric.h.jung:2.22.1 FF - prefs.js..keyword.URL: "hxxp://www.google.de/search?hl=de&q=" FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.09.18 22:34:17 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.10.17 15:37:03 | 000,000,000 | ---D | M] [2008.07.06 15:37:53 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Extensions [2010.10.17 11:38:06 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\cc0tpddt.default\extensions [2010.05.03 14:44:38 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\cc0tpddt.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010.04.10 14:02:00 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\cc0tpddt.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2010.09.10 00:21:43 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\cc0tpddt.default\extensions\foxyproxy@eric.h.jung [2010.10.16 17:18:02 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\FireFox\Profiles\cc0tpddt.default\searchplugins\icqplugin-1.xml [2009.09.11 00:30:27 | 000,000,961 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\FireFox\Profiles\cc0tpddt.default\searchplugins\icqplugin-3.xml [2009.10.28 23:49:32 | 000,000,961 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\FireFox\Profiles\cc0tpddt.default\searchplugins\icqplugin-4.xml [2009.11.06 16:39:28 | 000,000,961 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\FireFox\Profiles\cc0tpddt.default\searchplugins\icqplugin-5.xml [2009.07.13 17:12:02 | 000,000,944 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\FireFox\Profiles\cc0tpddt.default\searchplugins\icqplugin.xml [2010.04.24 17:09:51 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions [2009.07.16 11:45:19 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2008.09.04 02:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npbittorrent.dll [2010.09.18 22:34:11 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010.09.18 22:34:11 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml [2010.09.18 22:34:11 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010.09.18 22:34:11 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010.09.18 22:34:11 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programme\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4 - HKLM..\Run: [00TCrdMain] C:\Programme\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [ Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NDSTray.exe] File not found O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [SmoothView] C:\Programme\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (TOSHIBA) O4 - HKLM..\Run: [TPwrMain] C:\Programme\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [Comobj] C:\Users\***\AppData\Roaming\Adobe\Update\apires.exe () O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation) O4 - HKCU..\Run: [TOSCDSPD] File not found O4 - HKCU..\Run: [VeohPlugin] C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks) O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103471 -Mozilla\5.0 ( File not found O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: eBay - Der weltweite Online Marktplatz - {76577871-04EC-495E-A12B-91F7C3600AFA} - File not found O9 - Extra Button: Amazon.de - {8A918C1D-E123-4E36-B562-5C1519E434CE} - File not found O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19) O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - igfxdev.dll (Intel Corporation) O24 - Desktop WallPaper: C:\Users\***\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\***\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{03508a0d-213c-11df-ab47-b64b2f2a0af3}\Shell - "" = AutoRun O33 - MountPoints2\{03508a0d-213c-11df-ab47-b64b2f2a0af3}\Shell\AutoRun\command - "" = H:\autorun.exe -- File not found O33 - MountPoints2\{33caca0d-09be-11df-9a6d-85cd6a02a7f6}\Shell - "" = AutoRun O33 - MountPoints2\{33caca0d-09be-11df-9a6d-85cd6a02a7f6}\Shell\AutoRun\command - "" = D:\Autorun.exe -- File not found O33 - MountPoints2\{36d25be2-8c00-11df-9db7-c7eea72211f8}\Shell - "" = AutoRun O33 - MountPoints2\{36d25be2-8c00-11df-9db7-c7eea72211f8}\Shell\AutoRun\command - "" = G:\StartVMCLite.exe -- File not found O33 - MountPoints2\{36d25be3-8c00-11df-9db7-c7eea72211f8}\Shell - "" = AutoRun O33 - MountPoints2\{36d25be3-8c00-11df-9db7-c7eea72211f8}\Shell\AutoRun\command - "" = G:\StartVMCLite.exe -- File not found O33 - MountPoints2\{3e48449e-1b15-11de-9de3-bae3181cf16a}\Shell - "" = AutoRun O33 - MountPoints2\{3e48449e-1b15-11de-9de3-bae3181cf16a}\Shell\AutoRun\command - "" = D:\StartVMCLite.exe -- File not found O33 - MountPoints2\{3e48449f-1b15-11de-9de3-bae3181cf16a}\Shell - "" = AutoRun O33 - MountPoints2\{3e48449f-1b15-11de-9de3-bae3181cf16a}\Shell\AutoRun\command - "" = G:\StartVMCLite.exe -- File not found O33 - MountPoints2\{890fb764-f445-11dd-b4a0-cd673168001b}\Shell - "" = AutoRun O33 - MountPoints2\{890fb764-f445-11dd-b4a0-cd673168001b}\Shell\AutoRun\command - "" = D:\StartVMCLite.exe -- File not found O33 - MountPoints2\{890fb765-f445-11dd-b4a0-cd673168001b}\Shell - "" = AutoRun O33 - MountPoints2\{890fb765-f445-11dd-b4a0-cd673168001b}\Shell\AutoRun\command - "" = G:\StartVMCLite.exe -- File not found O33 - MountPoints2\{89197064-7359-11dd-ab65-f015ba2163bc}\Shell - "" = AutoRun O33 - MountPoints2\{89197064-7359-11dd-ab65-f015ba2163bc}\Shell\AutoRun\command - "" = D:\StartVMCLite.exe -- File not found O33 - MountPoints2\{8919706a-7359-11dd-ab65-f015ba2163bc}\Shell - "" = AutoRun O33 - MountPoints2\{8919706a-7359-11dd-ab65-f015ba2163bc}\Shell\AutoRun\command - "" = D:\StartVMCLite.exe -- File not found O33 - MountPoints2\{cd0f1183-7363-11dd-8c55-c6a6a489b7f8}\Shell - "" = AutoRun O33 - MountPoints2\{cd0f1183-7363-11dd-8c55-c6a6a489b7f8}\Shell\AutoRun\command - "" = D:\StartVMCLite.exe -- File not found O33 - MountPoints2\{cd0f1184-7363-11dd-8c55-c6a6a489b7f8}\Shell - "" = AutoRun O33 - MountPoints2\{cd0f1184-7363-11dd-8c55-c6a6a489b7f8}\Shell\AutoRun\command - "" = G:\StartVMCLite.exe -- File not found O33 - MountPoints2\{f3f5e271-25a3-11de-9814-9e25e16d1fa9}\Shell\AutoRun\command - "" = G:\setupSNK.exe -- File not found O33 - MountPoints2\D\Shell - "" = AutoRun O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\StartVMCLite.exe -- File not found O33 - MountPoints2\H\Shell - "" = AutoRun O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.10.17 17:01:47 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Avira [2010.10.17 16:59:39 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2010.10.17 16:59:10 | 000,124,784 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2010.10.17 16:59:10 | 000,017,016 | ---- | C] (AVIRA GmbH) -- C:\Windows\System32\drivers\avgntmgr.sys [2010.10.17 16:59:09 | 000,051,992 | ---- | C] (AVIRA GmbH) -- C:\Windows\System32\drivers\avgntdd.sys [2010.10.17 16:58:52 | 000,000,000 | ---D | C] -- C:\Programme\Avira [2010.10.17 16:58:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2010.10.17 15:36:40 | 000,000,000 | ---D | C] -- C:\Programme\Adobe [2010.10.16 19:38:15 | 000,000,000 | ---D | C] -- C:\Users\***\Documents\EmergencyKit [2010.10.16 17:05:42 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes [2010.10.16 17:05:05 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2010.10.16 17:04:55 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2010.10.16 17:04:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.10.16 17:04:54 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware [2010.10.14 12:33:02 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Helper [2010.10.13 12:04:58 | 008,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL [2010.10.13 12:04:17 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netevent.dll [2010.10.13 12:03:34 | 000,157,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll [2010.10.13 12:03:27 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2010.10.13 12:03:27 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2010.10.13 12:03:27 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2010.10.13 12:03:26 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2010.10.13 12:03:26 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll [2010.10.13 12:03:25 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2010.10.13 12:03:25 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2010.10.13 12:03:25 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2010.10.13 12:03:25 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2010.10.13 12:03:25 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2010.10.13 12:03:25 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2010.10.13 12:03:25 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2010.10.13 12:03:25 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2010.10.13 12:03:25 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2010.10.13 12:03:25 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2010.10.13 12:03:25 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2010.10.13 12:03:25 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2010.10.13 12:03:19 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40.dll [2010.10.13 12:03:19 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40u.dll [2010.10.13 12:03:12 | 002,038,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2010.10.13 12:03:10 | 000,231,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshsq.dll [2010.10.13 12:03:08 | 000,867,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpmde.dll [2010.10.10 15:26:05 | 000,000,000 | ---D | C] -- C:\Programme\ASCII [2010.10.09 16:53:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Umineko6 [2010.10.04 21:28:33 | 003,890,920 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Windows\System32\GameMon.des [2010.10.04 19:15:52 | 000,000,000 | ---D | C] -- C:\Programme\gPotato.eu [2010.10.04 15:55:24 | 000,000,000 | ---D | C] -- C:\Programme\Neffy [2010.09.29 11:44:12 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll [2010.09.24 09:49:53 | 000,000,000 | ---D | C] -- C:\Programme\NosTale(DE) [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Users\***\Desktop\*.tmp files -> C:\Users\***\Desktop\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010.10.17 19:57:00 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2010.10.17 19:57:00 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2010.10.17 19:05:55 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010.10.17 19:05:55 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010.10.17 18:09:54 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{28AB3EC4-FDC9-46B8-BDE7-41DC0D0D40F0}.job [2010.10.17 17:05:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.10.17 17:05:42 | 2136,961,024 | -HS- | M] () -- C:\hiberfil.sys [2010.10.17 16:27:53 | 000,053,760 | ---- | M] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.10.17 15:59:23 | 000,004,090 | ---- | M] () -- C:\Users\***\Documents\cc_20101017_155914.reg [2010.10.17 15:37:03 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk [2010.10.16 17:05:10 | 000,000,823 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.10.16 16:16:41 | 000,618,442 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2010.10.16 16:16:41 | 000,587,178 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2010.10.16 16:16:41 | 000,122,842 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2010.10.16 16:16:41 | 000,101,250 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2010.10.15 12:04:23 | 000,075,264 | ---- | M] () -- C:\Users\***\Desktop\Bus_WiSe_1011_a.doc [2010.10.15 10:32:35 | 000,322,848 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2010.10.13 12:50:19 | 000,015,961 | ---- | M] () -- C:\Users\***\Desktop\Altklausur_2010.docx [2010.10.12 13:59:30 | 000,032,725 | ---- | M] () -- C:\Users\***\Desktop\plan5sem-2010.pdf [2010.10.09 17:01:21 | 000,001,326 | ---- | M] () -- C:\Users\***\Desktop\Umineko no Naku Koro ni EP6.exe.lnk [2010.10.04 19:26:22 | 000,000,908 | ---- | M] () -- C:\Users\***\Desktop\Flyff.lnk [2010.09.25 11:22:18 | 000,002,078 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Users\***\Desktop\*.tmp files -> C:\Users\***\Desktop\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.10.17 15:59:16 | 000,004,090 | ---- | C] () -- C:\Users\***\Documents\cc_20101017_155914.reg [2010.10.17 15:37:03 | 000,001,892 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk [2010.10.16 17:05:10 | 000,000,823 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.10.15 12:04:21 | 000,075,264 | ---- | C] () -- C:\Users\***\Desktop\Bus_WiSe_1011_a.doc [2010.10.13 12:50:17 | 000,015,961 | ---- | C] () -- C:\Users\***\Desktop\Altklausur_2010.docx [2010.10.12 13:59:30 | 000,032,725 | ---- | C] () -- C:\Users\***\Desktop\plan5sem-2010.pdf [2010.10.10 15:26:18 | 000,087,040 | ---- | C] () -- C:\Windows\UnGins.exe [2010.10.09 17:01:04 | 000,001,326 | ---- | C] () -- C:\Users\***\Desktop\Umineko no Naku Koro ni EP6.exe.lnk [2010.10.04 19:26:22 | 000,000,908 | ---- | C] () -- C:\Users\***\Desktop\Flyff.lnk [2010.09.25 11:22:18 | 000,002,078 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk [2010.02.24 14:49:55 | 000,000,292 | ---- | C] () -- C:\Windows\vtmb.ini [2010.01.25 16:26:11 | 000,691,696 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys [2009.12.09 23:17:05 | 000,089,300 | ---- | C] () -- C:\Windows\System32\HCDTRULE.DLL [2009.12.09 23:17:00 | 000,032,768 | ---- | C] () -- C:\Windows\System32\thapi.dll [2009.12.09 21:02:45 | 000,001,025 | ---- | C] () -- C:\Windows\System32\sysprst.dll [2009.12.09 21:02:45 | 000,000,203 | ---- | C] () -- C:\Windows\System32\lsprst.dll [2009.09.11 14:41:56 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009.04.12 13:36:43 | 000,005,864 | ---- | C] () -- C:\Users\***\AppData\Local\d3d9caps.dat [2009.04.10 13:01:55 | 000,000,056 | RHS- | C] () -- C:\Windows\System32\7CB775C798.sys [2009.04.10 13:01:39 | 000,000,952 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys [2009.02.17 18:02:49 | 000,000,552 | ---- | C] () -- C:\Users\***\AppData\Local\d3d8caps.dat [2009.01.26 13:48:12 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2009.01.18 17:59:36 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2008.07.23 18:50:52 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll [2008.07.23 18:46:38 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll [2008.07.20 18:55:18 | 000,053,760 | ---- | C] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008.07.08 23:30:00 | 000,000,016 | -H-- | C] () -- C:\Users\***\AppData\Roaming\mxfilerelatedcache.mxc2 [2008.07.08 23:30:00 | 000,000,016 | -H-- | C] () -- C:\Users\***\AppData\Local\mxfilerelatedcache.mxc2 [2008.07.06 14:13:53 | 000,000,242 | ---- | C] () -- C:\Users\***\AppData\Roaming\wklnhst.dat [2008.07.06 11:15:07 | 000,131,072 | ---- | C] () -- C:\Windows\System32\EnumDevLib.dll [2008.07.06 11:13:07 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini [2008.07.06 11:13:07 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll [2008.07.06 11:13:07 | 000,009,480 | ---- | C] () -- C:\Windows\System32\tosmreg.ini [2008.07.06 11:13:07 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini [2008.04.01 13:16:40 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI [2008.03.31 10:34:28 | 000,006,642 | ---- | C] () -- C:\Windows\mgxoschk.ini [2008.03.31 10:21:26 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll [2008.03.31 10:21:26 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll [2008.03.31 10:21:26 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll [2008.03.31 10:21:26 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll [2008.03.31 10:21:26 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll [2008.03.31 10:21:26 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll [2008.03.31 09:40:32 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll [2008.03.31 09:39:41 | 001,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll [2008.03.31 09:39:41 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll [2008.03.31 09:39:41 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1329.dll [2008.03.31 09:39:41 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2005.01.31 08:37:58 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini [1999.01.27 13:39:06 | 000,065,024 | ---- | C] () -- C:\Windows\System32\indounin.dll [1997.06.13 07:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\Iyvu9_32.dll < End of report > Code:
ATTFilter OTL Extras logfile created on: 17.10.2010 19:56:08 - Run 3 OTL by OldTimer - Version Folder = C:\Users\***\Downloads Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18975) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 47,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 69,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 93,08 Gb Total Space | 36,53 Gb Free Space | 39,24% Space Free | Partition Type: NTFS Drive E: | 91,76 Gb Total Space | 87,39 Gb Free Space | 95,24% Space Free | Partition Type: NTFS Computer Name: ***-PC | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.) ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{12919807-C378-4DDC-A32F-848809A0AF28}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2DBF1338-6FDE-4885-A23D-FD37152A38EB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2FED32EF-F63E-4A28-B4C3-6178CA21DBEF}" = lport=2869 | protocol=6 | dir=in | app=system | "{4416F2BC-A254-47EA-A4F5-530065A0C7AA}" = lport=2869 | protocol=6 | dir=in | app=system | "{450D3D11-F1F3-4678-BC52-B450DB06E694}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5023736B-9781-4E59-B240-F2492D199C8C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{5102A39A-864D-4212-BCCE-6D6791D98D2F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5A18735B-8B1B-4649-915A-7789F3887C14}" = lport=10243 | protocol=6 | dir=in | app=system | "{6BE51516-15BD-4B65-95F3-17C839F0652C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{738BBF97-9EDC-4B00-BC05-A9932D4C1B55}" = rport=10243 | protocol=6 | dir=out | app=system | "{83CED82D-5516-4483-9473-26FDFD232C0D}" = lport=2869 | protocol=6 | dir=in | app=system | "{898F0CEF-4246-4367-B9D3-35EF2BA5D5FA}" = lport=2869 | protocol=6 | dir=in | app=system | "{9348A34F-C730-430B-BEBA-E7D83C6022D9}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A1045BA4-D1B6-46A7-8E6F-A36F9675E9C4}" = lport=2869 | protocol=6 | dir=in | app=system | "{B83C94B4-5FB9-4A45-BA32-0E6ACA342219}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{C07BABA2-ABBA-48BE-B66E-A8C31200EC16}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D0F059BC-544D-44ED-9B1C-246E78BCF54F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{094FA324-3432-4392-805F-2F4A4FF9F9C0}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | "{0AD1B980-EA15-4ED9-A9CD-983FC27C0DE4}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe | "{0F474225-0DB2-4513-B0A7-2C7D2AECA396}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{1C0B5523-AA3C-42E1-A06F-AC3115DA2F82}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe | "{264AD80D-D6D7-4CAB-AACC-CF9679AA69DF}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe | "{2B394B55-6FEC-4B26-B4C6-B9C01C7E0E3F}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{4E302A80-D970-4C11-BF9A-6D5960BF2E94}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{5B4F54D2-B5AE-4886-9126-A4767106B99B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{693528D5-71AB-43A0-94E9-C35482D75341}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{6CDD49C2-6549-4AF2-BDDE-B535D11D898B}" = protocol=17 | dir=in | app=c:\program files\smartftp client\smartftp.exe | "{78DAD281-48A0-4E13-9D77-08A44F0D673E}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{886AD8D0-7CAA-4E80-8FD0-4609677B4DAD}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{89FFE642-8282-4DD2-B9D0-18BA8BC623E8}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{8B1A6C7F-95AA-414B-B637-306710BCE471}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{8E88EAE0-2185-4460-B9F5-138934360EC0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{979D475C-C161-4843-B143-0548265C8713}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{9C05BCED-CF3C-41B0-BAD5-C397FC5C25C0}" = protocol=6 | dir=in | app=c:\program files\smartftp client\smartftp.exe | "{A331B367-4452-41D7-B683-182B1BD5CF5C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{B0A865D3-490B-421C-A7E0-2BE8D2C6E5F5}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{BE8CF286-8EF5-412E-A18C-1548547863F9}" = protocol=6 | dir=out | app=system | "{BFF732CB-E6FD-4660-A030-4DC7E47E9E37}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C464F03E-A8FA-46AA-8D1A-9C6746747193}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | "{CAAF8D2D-8B0A-476B-920E-939875F37EAD}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe | "{CFA69412-BEEB-4923-8954-9467178CAD01}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{D1459E3A-D3C6-4B6B-86B6-5C49EF3C3253}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{D47D153A-9384-4C96-B29B-BC17F6E6555C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{D7465523-7F28-4D9A-9807-752C3DE8E4CC}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe | "{DFB98BED-54D4-43B3-9AE5-145BA8A3E3EE}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "{E18B4BC3-2D81-409C-9F16-1FAC632FE562}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | "{E61396A0-D81C-48E1-BF88-953F3DCD2D81}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "{FB4CE107-6CCF-421A-9791-C4F25A8EC5F8}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | "{FBC95DA2-EAD9-472F-AE0D-D765EE14E99A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{FBDCCB43-1EE5-47F7-863C-98CC35BA66CA}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | "TCP Query User{14A931FA-D318-46FF-90C8-90A74DB3A988}C:\program files\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire\xfire.exe | "TCP Query User{2584175E-3022-45A3-A9BB-1E1D7D41DE7C}C:\users\***\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\***\program files\dna\btdna.exe | "TCP Query User{2BFB8D74-CAAF-4170-9D9C-58283148127A}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "TCP Query User{2E4808B4-26FF-4EDB-868F-EC1FEE73DA32}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | "TCP Query User{3A42CF3D-328D-48EF-8769-08FD54FC887C}C:\program files\qip\qip.exe" = protocol=6 | dir=in | app=c:\program files\qip\qip.exe | "TCP Query User{4860269D-F2CD-468C-8D6C-87B72DCB194A}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "TCP Query User{497768EA-AB05-4D7C-A7A1-393CC32C033B}C:\program files\ws_ftp\ws_ftp95.exe" = protocol=6 | dir=in | app=c:\program files\ws_ftp\ws_ftp95.exe | "TCP Query User{4E1850E0-F741-4F4F-BAB5-04DFE06CCD2D}C:\users\***\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\***\program files\dna\btdna.exe | "TCP Query User{51D3AE86-89BA-4903-8401-B3BFDC5D9F4E}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe | "TCP Query User{6BDCBD5A-9153-4FAF-AA92-2369C2C20441}C:\program files\java\jre1.6.0_07\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre1.6.0_07\bin\javaw.exe | "TCP Query User{6F1E26B9-83B3-4575-879C-68903FCD3F5F}C:\program files\java\jre1.6.0_07\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre1.6.0_07\bin\javaw.exe | "TCP Query User{8DD78664-999C-499D-A9E1-83C8807BD9A0}C:\users\***\desktop\scarlet weather rhapsody\th123.exe" = protocol=6 | dir=in | app=c:\users\***\desktop\scarlet weather rhapsody\th123.exe | "TCP Query User{A091B801-EAE8-4293-BE79-489CCEF7E0FB}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | "TCP Query User{A1CB1B07-0288-4FD5-9B20-76438670EA75}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "TCP Query User{C7D3DC60-A6E7-4AB9-8A15-E7A177B06FB3}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "TCP Query User{D84AE58A-3917-4432-92EB-66270A89BA08}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "TCP Query User{DF6C3344-3E0C-4D99-ABF3-8651BD457753}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe | "TCP Query User{E77D49BB-CC80-42F5-8FF2-E73948D0AFB9}C:\program files\qip\qip.exe" = protocol=6 | dir=in | app=c:\program files\qip\qip.exe | "TCP Query User{F2E0E5FB-7D8F-47FC-8F71-FDDCD4AF73CF}C:\program files\ws_ftp\ws_ftp95.exe" = protocol=6 | dir=in | app=c:\program files\ws_ftp\ws_ftp95.exe | "UDP Query User{069E868A-0FDB-4756-A9A3-8FBE1B3C3F75}C:\users\***\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\***\program files\dna\btdna.exe | "UDP Query User{132E3D5A-59DF-414C-9778-386C0095004D}C:\program files\ws_ftp\ws_ftp95.exe" = protocol=17 | dir=in | app=c:\program files\ws_ftp\ws_ftp95.exe | "UDP Query User{1EEA91A7-68A0-4E35-B54D-0142683BA7DB}C:\users\***\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\***\program files\dna\btdna.exe | "UDP Query User{3A90542E-A543-4EE0-8220-12F62315BECA}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |

[... extensive firewall rules and registry entries omitted for brevity ...]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator ![]() | #8 |
| ![]() PC fährt runter und ist lahmer als sonst! Sorry erstmal, ich wollte nicht pushen, sonder nur mal danke sagen für die Hilfe bis hier hin. Da ich aber doch einige Probleme habe, die ich im Moment nicht lösen kann (z.B. funktioniert Java nicht mehr), und es immer schlimmer wird, werde ich demnächst mein System neu aufsetzen. Und zwar kommt dann XP statt Vista drauf. Darf ich dann, wenn ich alles neu gemacht habe meine neuen Logs hier rein posten? Damit ich sicher sein kann dass alles wieder sauber ist? Oder soll ich einen neuen Thread eröffnen? |
#9
PC fährt runter und ist lahmer als sonst!

Wann willst Du formatieren? Wenn Du das heute oder morgen schon machst erspar ich mir die Auswertungen!
PC fährt runter und ist lahmer als sonst!

Also ich denke morgen werde ich spätestens formatieren! Sorry für den Stress, trotzdem aber danke!
PC fährt runter und ist lahmer als sonst!

So! System ist neu aufgesetzt und alles läuft wieder wunderbar. Ich hoffe natürlich ich bin die Schädlinge los...

Ist Jemand bereit sich die Mühe ein letztes Mal zu machen und die Logs anzugucken? Ich wäre wirklich unheimlich erleichtert =)

OTL:
ATTFilter
OTL logfile created on: 19.10.2010 12:35:46 - Run 1
OTL by OldTimer - Version Folder = C:\Users\***\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)

[... OTL log output truncated for brevity ...] #12
PC fährt runter und ist lahmer als sonst!

Wenn Du formatiert hast, gibt es eigentlich keinen Anlass Logs auszuwerten...

Man formatiert und setzt neu auf, um die Schädlinge sicher loszuwerden und auch um keine Logs auswerten zu müssen
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #13 |
PC fährt runter und ist lahmer als sonst!

Na das ist doch mal gut zu hören

Dann bedanke ich mich bei allen! Macht weiter so, ihr seid eine tolle Truppe hier!
