|
Plagegeister aller Art und deren Bekämpfung: Mein Pc läuft nicht mehr richtig.Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.10.2010, 13:34 | #1 |
| Mein Pc läuft nicht mehr richtig. Guten Tag.Es geht darum,ich bin jetzt aussem Urlaub wieder gekommen.Wahr knapp zwei wochen nicht am pc und als ich dan wieder mal online wahr konnte ich nicht mehr mit Google was suchen.dort stand dan immer das mein computer automatisiert sei und ich müsste bestätigen das ich ein Mensch sei.Das andere Problemm ist,wenn ich Starcraft2 spiele ist mein Pc auf einmal total langsam und das Spiel zeigt an das ich die anderen Anwendungen ausschalten soll,obwohl nichts an ist.Das wahr vorher nicht. Hier einmal das von malwarebytes Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4905 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 22.10.2010 08:57:24 mbam-log-2010-10-22 (08-57-24).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|H:\|J:\|K:\|) Durchsuchte Objekte: 334896 Laufzeit: 9 Stunde(n), 4 Minute(n), 21 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 8 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: D:\Autorun.inf (Worm.Agent.H) -> Delete on reboot. C:\Users\dusty\AppData\Local\Xenocode\Sandbox\Eclipse\0.0.1.0\2010.01.18T09.33\Native\STUBEXE\7.1.280\@PROGRAMFILES@\Internet Explorer\iexplore.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully. C:\Users\dusty\AppData\Local\Xenocode\Sandbox\Eclipse\0.0.1.0\2010.01.18T09.33\Virtual\STUBEXE\7.1.280\@DESKTOPCOMMON@\Eclipse.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully. C:\Users\dusty\AppData\Local\Xenocode\Sandbox\Eclipse\0.0.2.0\2010.03.29T04.09\Native\STUBEXE\7.1.280\@PROGRAMFILES@\Internet Explorer\iexplore.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully. C:\Users\dusty\AppData\Local\Xenocode\Sandbox\Eclipse\0.0.2.0\2010.03.29T04.09\Virtual\STUBEXE\7.1.280\@DESKTOP@\Eclipse.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully. C:\Users\dusty\AppData\Local\Xenocode\Sandbox\Updater\1.0.0.0\2010.05.10T06.09\Virtual\STUBEXE\7.1.280\@APPDIR@\Updater.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully. C:\Users\patrick\AppData\Local\Xenocode\Sandbox\Eclipse\0.0.1.0\2010.01.18T09.33\Virtual\STUBEXE\7.1.280\@DESKTOPCOMMON@\Eclipse.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully. C:\Users\patrick\AppData\Local\Xenocode\Sandbox\Eclipse\0.0.2.0\2010.03.29T04.09\Virtual\STUBEXE\7.1.280\@DESKTOP@\Eclipse.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully.OTL Logfile: Code:
ATTFilter OTL logfile created on: 22.10.2010 13:56:19 - Run 3 OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\dusty\Downloads\MFTools 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 64,00% Memory free 8,00 Gb Paging File | 6,00 Gb Available in Paging File | 80,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 923,02 Gb Total Space | 484,65 Gb Free Space | 52,51% Space Free | Partition Type: NTFS Drive D: | 7,38 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: DUSTY-PC Current User Name: dusty Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: On Skip Microsoft Files: On File Age = 90 Days Output = Standard Quick Scan ========== Processes (SafeList) ========== PRC - [2010.09.02 18:04:47 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\dusty\Downloads\MFTools\OTL.exe PRC - [2010.07.03 10:43:28 | 000,075,064 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2010.06.28 09:20:30 | 000,173,352 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe PRC - [2010.04.16 22:12:28 | 003,872,080 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe PRC - [2010.04.16 18:36:42 | 000,026,480 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe PRC - [2010.02.26 02:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe PRC - [2009.05.19 12:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe PRC - [2009.03.20 02:02:00 | 001,904,640 | ---- | M] (AVM Berlin) -- C:\Program Files (x86)\avmwlanstick\WLanGUI.exe PRC - [2009.03.20 02:02:00 | 000,368,640 | ---- | M] (AVM Berlin) -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe PRC - [2009.03.05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe PRC - [2009.02.26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe ========== Modules (SafeList) ========== MOD - [2010.09.02 18:04:47 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\dusty\Downloads\MFTools\OTL.exe MOD - [2010.08.21 07:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll MOD - [2009.07.14 03:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx ========== Win32 Services (SafeList) ========== SRV:64bit: - File not found [Auto | Running] -- C:\windows\SysNative\PnkBstrA.exe -- (PnkBstrA) SRV:64bit: - File not found [Auto | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE) SRV:64bit: - [2010.08.26 03:57:14 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2009.08.18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV:64bit: - [2009.08.10 23:41:38 | 000,093,336 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1d\RpcAgentSrv.exe -- (SandraAgentSrv) SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2010.08.27 09:00:18 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2010.07.03 10:43:28 | 000,075,064 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2010.06.28 09:20:30 | 000,173,352 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5) SRV - [2010.04.28 07:44:02 | 000,704,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe -- (fsssvc) SRV - [2010.03.18 14:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64) SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010.02.26 02:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe -- (N360) SRV - [2009.05.19 12:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort) SRV - [2009.03.20 02:02:00 | 000,368,640 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe -- (AVM WLAN Connection Service) SRV - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService) ========== Driver Services (SafeList) ========== DRV:64bit: - [2010.08.26 05:37:26 | 007,767,040 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag) DRV:64bit: - [2010.08.26 05:37:26 | 007,767,040 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2010.08.26 03:20:56 | 000,279,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2010.07.15 14:47:42 | 000,116,240 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2010.07.08 14:42:53 | 000,173,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent) DRV:64bit: - [2010.05.06 11:21:46 | 000,125,456 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV:64bit: - [2010.05.06 06:01:59 | 000,451,120 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\symtdiv.sys -- (SYMTDIv) DRV:64bit: - [2010.04.29 07:03:51 | 000,150,064 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\ironx64.sys -- (SymIRON) DRV:64bit: - [2010.04.27 08:32:22 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:64bit: - [2010.04.27 08:32:21 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:64bit: - [2010.04.22 05:02:20 | 000,221,232 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\symefa64.sys -- (SymEFA) DRV:64bit: - [2010.04.22 04:29:51 | 000,505,392 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\srtsp64.sys -- (SRTSP) DRV:64bit: - [2010.04.22 04:29:51 | 000,032,304 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\srtspx64.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL) DRV:64bit: - [2010.04.12 16:32:55 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:64bit: - [2010.02.26 02:22:52 | 000,615,040 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\cchpx64.sys -- (ccHP) DRV:64bit: - [2009.11.16 18:33:38 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf) DRV:64bit: - [2009.11.05 23:15:40 | 000,291,328 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2009.10.15 05:50:05 | 000,433,200 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\symds64.sys -- (SymDS) DRV:64bit: - [2009.08.09 23:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone) DRV:64bit: - [2009.08.07 23:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1d\WNt500x64\Sandra.sys -- (SANDRA) DRV:64bit: - [2009.07.14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2009.07.14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.06.10 22:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs) DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009.05.19 00:17:08 | 000,034,152 | R--- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:64bit: - [2009.03.20 02:02:00 | 000,460,800 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\fwlanusb.sys -- (FWLANUSB) DRV:64bit: - [2009.03.20 02:02:00 | 000,014,120 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avmeject.sys -- (avmeject) DRV - [2010.10.19 22:36:20 | 000,476,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20101020.001\IDSviA64.sys -- (IDSVia64) DRV - [2010.10.12 19:07:09 | 001,804,336 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20101021.025\EX64.SYS -- (NAVEX15) DRV - [2010.10.12 19:07:09 | 000,117,808 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20101021.025\ENG64.SYS -- (NAVENG) DRV - [2010.09.01 00:57:03 | 000,954,928 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20101001.001\BHDrvx64.sys -- (BHDrvx64) DRV - [2010.07.07 01:00:00 | 000,475,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl) DRV - [2010.07.07 01:00:00 | 000,132,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv) DRV - [2007.02.07 20:27:46 | 000,014,104 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | Boot | Running] -- C:\windows\SysWOW64\speedfan.sys -- (speedfan) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.hyrican.de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "" FF - prefs.js..browser.search.defaultenginename: "" FF - prefs.js..browser.search.defaultthis.engineName: "Winload Customized Web Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.order.1: "" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/firefox?client=firefox-a&rls=org.mozilla:de:official" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: piclens@cooliris.com:1.12.0.36949 FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.3.5 FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:3.3.5 FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2 FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.48.3 FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0 FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010.07.09 09:03:37 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010.07.08 14:43:30 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.10.20 13:42:41 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.10.20 13:42:41 | 000,000,000 | ---D | M] [2010.04.23 12:02:03 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\mozilla\Extensions [2010.10.22 10:23:09 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions [2010.10.19 00:44:13 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} [2010.09.23 08:48:04 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE} [2010.09.10 16:18:40 | 000,000,000 | ---D | M] (WOT) -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2010.10.15 09:14:10 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010.08.18 22:58:44 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010.07.29 22:52:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3} [2010.06.24 12:38:23 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\piclens@cooliris.com [2010.06.24 12:38:23 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\piclens@cooliris.com-trash [2010.09.10 16:18:36 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\smarterwiki@wikiatic.com [2010.04.23 13:21:41 | 000,002,251 | ---- | M] () -- C:\Users\dusty\AppData\Roaming\Mozilla\FireFox\Profiles\78redm0s.default\searchplugins\askcom.xml [2010.03.24 16:13:02 | 000,000,917 | ---- | M] () -- C:\Users\dusty\AppData\Roaming\Mozilla\FireFox\Profiles\78redm0s.default\searchplugins\conduit.xml [2010.06.08 12:03:12 | 000,001,620 | ---- | M] () -- C:\Users\dusty\AppData\Roaming\Mozilla\FireFox\Profiles\78redm0s.default\searchplugins\mozilla-add-ons.xml [2010.06.08 11:40:46 | 000,001,115 | ---- | M] () -- C:\Users\dusty\AppData\Roaming\Mozilla\FireFox\Profiles\78redm0s.default\searchplugins\rapidshare-filefinder.xml [2010.10.22 10:23:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2010.06.24 17:56:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010.08.15 10:06:19 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010.10.18 11:02:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2010.09.15 04:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2010.04.01 18:54:38 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.04.01 18:54:38 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.04.01 18:54:38 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.04.01 18:54:38 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.04.01 18:54:38 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.09.07 15:36:07 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) O2:64bit: - BHO: (Windows Live ID-Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found. O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files (x86)\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coIEPlg.dll (Symantec Corporation) O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\IPSBHO.DLL (Symantec Corporation) O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coIEPlg.dll (Symantec Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coIEPlg.dll (Symantec Corporation) O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [AVMWlanClient] C:\Program Files (x86)\avmwlanstick\wlangui.exe (AVM Berlin) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKCU..\Run: [Eraser RiskMonitor] C:\Program Files (x86)\East-Tec Eraser 2010\Launch.exe File not found O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - Startup: C:\Users\dusty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files (x86)\ERUNT\AUTOBACK.EXE () O4 - Startup: C:\Users\dusty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0 O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\dusty\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\dusty\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm () O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O30:64bit: - LSA: Security Packages - (livessp) - C:\windows\SysNative\livessp.dll (Microsoft Corporation) O30 - LSA: Security Packages - (livessp) - C:\windows\SysWow64\livessp.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008.05.08 17:37:40 | 000,587,992 | R--- | M] (Stardock Entertainment, Inc.) - D:\autorun.exe -- [ UDF ] O32 - AutoRun File - [2010.07.08 14:34:26 | 000,000,081 | R--- | M] () - D:\Autorun.inf -- [ UDF ] O32 - AutoRun File - [2008.05.21 21:53:55 | 000,002,680 | R--- | M] () - D:\AutorunText.txt -- [ UDF ] O33 - MountPoints2\{5bd39de3-0f11-11df-a982-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{5bd39de3-0f11-11df-a982-806e6f6e6963}\Shell\AutoRun\command - "" = D:\0data\cbs.exe -- [2010.08.04 13:35:31 | 003,418,112 | R--- | M] () O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* MsConfig:64bit - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) MsConfig:64bit - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) MsConfig:64bit - StartUpReg: Steam - hkey= - key= - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) MsConfig:64bit - State: "services" - Reg Error: Key error. MsConfig:64bit - State: "startup" - Reg Error: Key error. Drivers32:64bit: aux - wdmaud.drv (Microsoft Corporation) Drivers32:64bit: aux1 - wdmaud.drv (Microsoft Corporation) Drivers32:64bit: aux2 - wdmaud.drv (Microsoft Corporation) Drivers32:64bit: midi - wdmaud.drv (Microsoft Corporation) Drivers32:64bit: midi1 - wdmaud.drv (Microsoft Corporation) Drivers32:64bit: midi2 - wdmaud.drv (Microsoft Corporation) Drivers32:64bit: midimapper - midimap.dll (Microsoft Corporation) Drivers32:64bit: mixer - wdmaud.drv (Microsoft Corporation) Drivers32:64bit: mixer1 - wdmaud.drv (Microsoft Corporation) Drivers32:64bit: mixer2 - wdmaud.drv (Microsoft Corporation) Drivers32:64bit: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation) Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32:64bit: msacm.msadpcm - msadp32.acm (Microsoft Corporation) Drivers32:64bit: msacm.msg711 - msg711.acm (Microsoft Corporation) Drivers32:64bit: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation) Drivers32:64bit: vidc.i420 - iyuv_32.dll (Microsoft Corporation) Drivers32:64bit: vidc.iyuv - iyuv_32.dll (Microsoft Corporation) Drivers32:64bit: vidc.mrle - msrle32.dll (Microsoft Corporation) Drivers32:64bit: vidc.msvc - msvidc32.dll (Microsoft Corporation) Drivers32:64bit: vidc.uyvy - msyuv.dll (Microsoft Corporation) Drivers32:64bit: vidc.yuy2 - msyuv.dll (Microsoft Corporation) Drivers32:64bit: vidc.yvu9 - tsbyuv.dll (Microsoft Corporation) Drivers32:64bit: vidc.yvyu - msyuv.dll (Microsoft Corporation) Drivers32:64bit: wave - wdmaud.drv (Microsoft Corporation) Drivers32:64bit: wave1 - wdmaud.drv (Microsoft Corporation) Drivers32:64bit: wave2 - wdmaud.drv (Microsoft Corporation) Drivers32:64bit: wavemapper - msacm32.drv (Microsoft Corporation) Drivers32: aux - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation) Drivers32: aux1 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation) Drivers32: aux2 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation) Drivers32: midi - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation) Drivers32: midi1 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation) Drivers32: midi2 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation) Drivers32: midimapper - C:\windows\SysWow64\midimap.dll (Microsoft Corporation) Drivers32: mixer - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation) Drivers32: mixer1 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation) Drivers32: mixer2 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation) Drivers32: msacm.imaadpcm - C:\windows\SysWow64\imaadp32.acm (Microsoft Corporation) Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.msadpcm - C:\windows\SysWow64\msadp32.acm (Microsoft Corporation) Drivers32: msacm.msg711 - C:\windows\SysWow64\msg711.acm (Microsoft Corporation) Drivers32: msacm.msgsm610 - C:\windows\SysWow64\msgsm32.acm (Microsoft Corporation) Drivers32: msacm.siren - C:\windows\SysWow64\sirenacm.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.) Drivers32: VIDC.FMVC - C:\windows\SysWow64\fmcodec.DLL (Fox Magic Software) Drivers32: vidc.i420 - C:\windows\SysWow64\iyuv_32.dll (Microsoft Corporation) Drivers32: vidc.iyuv - C:\windows\SysWow64\iyuv_32.dll (Microsoft Corporation) Drivers32: vidc.mrle - C:\windows\SysWow64\msrle32.dll (Microsoft Corporation) Drivers32: vidc.msvc - C:\windows\SysWow64\msvidc32.dll (Microsoft Corporation) Drivers32: vidc.uyvy - C:\windows\SysWow64\msyuv.dll (Microsoft Corporation) Drivers32: vidc.yuy2 - C:\windows\SysWow64\msyuv.dll (Microsoft Corporation) Drivers32: vidc.yvu9 - C:\windows\SysWow64\tsbyuv.dll (Microsoft Corporation) Drivers32: vidc.yvyu - C:\windows\SysWow64\msyuv.dll (Microsoft Corporation) Drivers32: wave - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation) Drivers32: wave1 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation) Drivers32: wave2 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation) Drivers32: wavemapper - C:\windows\SysWow64\msacm32.drv (Microsoft Corporation) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 90 Days ========== [2010.10.22 13:52:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT [2010.10.22 10:12:04 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI [2010.10.22 09:54:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies [2010.10.22 09:54:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies [2010.10.21 01:28:13 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\EAST Technologies [2010.10.21 01:26:22 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP [2010.10.20 19:35:12 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysWow64\drivers\mbamswissarmy.sys [2010.10.13 10:51:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe [2010.10.13 10:51:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe [2010.09.27 21:35:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Ubisoft [2010.09.27 14:31:59 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Ironclad Games [2010.09.27 14:31:42 | 000,000,000 | -H-D | C] -- C:\ProgramData\{A4B500C8-F3EB-4AD9-9762-515CCA35FD16} [2010.09.27 14:13:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Kalypso [2010.09.27 14:12:35 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Stardock [2010.09.26 14:24:15 | 000,000,000 | ---D | C] -- C:\windows\Minidump [2010.09.24 12:49:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nobilis [2010.09.20 18:56:46 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\PhotoFiltre [2010.09.20 18:56:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PhotoFiltre [2010.09.13 16:06:48 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\NCSoft [2010.09.13 11:56:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\City of Heroes [2010.09.11 12:40:41 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\XMedia Recode [2010.09.11 12:01:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XMedia Recode [2010.09.11 11:22:00 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\Any Video Converter [2010.09.11 11:21:46 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\AnvSoft [2010.09.11 11:21:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AnvSoft [2010.09.11 11:07:54 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\Xilisoft Corporation [2010.09.11 11:07:52 | 000,000,000 | ---D | C] -- C:\Users\dusty\Application Data [2010.09.09 19:24:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies [2010.09.09 19:23:57 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies [2010.09.09 10:08:11 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\Opera [2010.09.09 10:08:11 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Opera [2010.09.09 10:08:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera [2010.09.08 21:54:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winload [2010.09.07 16:00:48 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com [2010.09.07 16:00:40 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE [2010.09.07 08:57:44 | 000,000,000 | ---D | C] -- C:\_OTL [2010.09.06 22:49:55 | 000,000,000 | ---D | C] -- C:\Darkfall [Beta] [2010.09.05 01:41:19 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Team_Horizon [2010.09.04 17:48:50 | 000,000,000 | R--D | C] -- C:\Users\Public\Documents\Videos [2010.09.02 20:58:05 | 000,000,000 | -HSD | C] -- C:\windows\SysWow64\%APPDATA% [2010.09.02 19:19:13 | 000,000,000 | ---D | C] -- C:\windows\ERDNT [2010.09.02 18:06:50 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\Malwarebytes [2010.09.02 18:06:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.09.02 18:06:33 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys [2010.09.02 18:06:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010.09.01 15:53:12 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\My Downloads [2010.09.01 15:53:03 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\GetRightToGo [2010.08.26 03:57:50 | 000,462,336 | ---- | C] (AMD) -- C:\windows\SysNative\atieclxx.exe [2010.08.26 03:57:14 | 000,203,264 | ---- | C] (AMD) -- C:\windows\SysNative\atiesrxx.exe [2010.08.26 03:56:06 | 000,120,320 | ---- | C] (AMD) -- C:\windows\SysNative\atitmm64.dll [2010.08.26 03:55:50 | 000,421,376 | ---- | C] (ATI Technologies, Inc.) -- C:\windows\SysNative\atipdl64.dll [2010.08.26 03:55:42 | 000,356,352 | ---- | C] (ATI Technologies, Inc.) -- C:\windows\SysWow64\atipdlxx.dll [2010.08.26 03:55:32 | 000,278,528 | ---- | C] (ATI Technologies, Inc.) -- C:\windows\SysWow64\Oemdspif.dll [2010.08.26 03:55:28 | 000,012,288 | ---- | C] (AMD) -- C:\windows\SysNative\atimuixx.dll [2010.08.26 03:55:22 | 000,059,392 | ---- | C] (ATI Technologies, Inc.) -- C:\windows\SysNative\atiedu64.dll [2010.08.26 03:55:18 | 000,043,520 | ---- | C] (ATI Technologies, Inc.) -- C:\windows\SysWow64\ati2edxx.dll [2010.08.25 23:35:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR [2010.08.24 23:11:56 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\Mael [2010.08.24 23:08:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HxD [2010.08.17 20:06:01 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\Datel [2010.08.15 20:21:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Google [2010.08.15 10:06:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2010.08.11 23:55:17 | 000,000,000 | -H-D | C] -- C:\windows\PIF [2010.08.04 18:25:08 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Deployment [2010.08.04 18:25:08 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Apps [2010.08.02 22:55:55 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\o_TRiPPiNz_LTD [2010.08.02 18:21:43 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\kevin_MountPt [2010.08.02 16:50:42 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Xenocode [2010.08.02 16:50:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xenocode [2010.08.01 22:57:33 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\Neuer Ordner [2010.08.01 22:52:33 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\E00002B9FA4D6428_MountPt [2010.08.01 22:34:44 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\hg pornoarzt_MountPt [2010.07.31 09:17:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\mp3Tag 5 [2010.07.30 11:49:14 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\DVDVideoSoftIEHelpers [2010.07.27 08:47:38 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\StarCraft II [2010.07.27 08:47:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\StarCraft II [2010.07.27 08:47:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment [2010.07.26 12:26:36 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\Extras [6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] ========== Files - Modified Within 90 Days ========== [2010.10.22 13:58:15 | 000,015,568 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2010.10.22 13:58:15 | 000,015,568 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2010.10.22 13:57:59 | 001,209,278 | ---- | M] () -- C:\windows\SysNative\drivers\N360x64\0403000.005\Cat.DB [2010.10.22 13:57:57 | 008,126,464 | -HS- | M] () -- C:\Users\dusty\NTUSER.DAT [2010.10.22 13:53:05 | 000,001,111 | ---- | M] () -- C:\Users\dusty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2010.10.22 13:51:00 | 000,065,536 | ---- | M] () -- C:\windows\SysNative\Ikeext.etl [2010.10.22 13:50:55 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT [2010.10.22 13:50:52 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat [2010.10.22 13:50:41 | 3218,939,904 | -HS- | M] () -- C:\hiberfil.sys [2010.10.22 13:49:48 | 004,128,830 | -H-- | M] () -- C:\Users\dusty\AppData\Local\IconCache.db [2010.10.22 13:46:34 | 000,001,014 | ---- | M] () -- C:\Users\dusty\Contacts\Desktop\MFTools - Verknüpfung.lnk [2010.10.22 05:05:09 | 001,498,506 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI [2010.10.22 05:05:09 | 000,653,928 | ---- | M] () -- C:\windows\SysNative\perfh007.dat [2010.10.22 05:05:09 | 000,615,810 | ---- | M] () -- C:\windows\SysNative\perfh009.dat [2010.10.22 05:05:09 | 000,129,800 | ---- | M] () -- C:\windows\SysNative\perfc007.dat [2010.10.22 05:05:09 | 000,106,190 | ---- | M] () -- C:\windows\SysNative\perfc009.dat [2010.10.21 21:12:20 | 000,079,152 | ---- | M] () -- C:\Users\dusty\AppData\Local\GDIPFONTCACHEV1.DAT [2010.10.21 21:11:41 | 000,343,752 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT [2010.10.21 21:08:51 | 000,004,788 | ---- | M] () -- C:\Users\dusty\Documents\cc 21.010.2010.reg [2010.10.21 21:07:41 | 000,037,600 | ---- | M] () -- C:\Users\dusty\Documents\cc_20101021_210638.reg [2010.10.20 18:00:28 | 000,000,819 | ---- | M] () -- C:\Users\dusty\Contacts\Desktop\Xbox 360 - Verknüpfung.lnk [2010.10.20 16:51:01 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2010.10.10 12:52:49 | 000,000,439 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts.ics [2010.09.21 00:01:15 | 000,000,172 | ---- | M] () -- C:\windows\SysNative\drivers\N360x64\0403000.005\isolate.ini [2010.09.13 16:55:13 | 000,002,560 | ---- | M] () -- C:\windows\_MSRSTRT.EXE [2010.09.11 12:01:58 | 000,001,074 | ---- | M] () -- C:\Users\Public\Desktop\XMedia Recode.lnk [2010.09.11 11:21:50 | 000,001,147 | ---- | M] () -- C:\Users\dusty\Contacts\Desktop\Any Video Converter.lnk [2010.09.07 15:36:07 | 000,000,098 | ---- | M] () -- C:\windows\SysNative\drivers\etc\Hosts [2010.09.02 17:13:58 | 000,051,976 | ---- | M] () -- C:\Users\dusty\Documents\cc_20100902_171333.reg [2010.08.26 04:01:34 | 000,076,216 | ---- | M] () -- C:\windows\SysNative\atiapfxx.blb [2010.08.26 03:57:50 | 000,462,336 | ---- | M] (AMD) -- C:\windows\SysNative\atieclxx.exe [2010.08.26 03:57:14 | 000,203,264 | ---- | M] (AMD) -- C:\windows\SysNative\atiesrxx.exe [2010.08.26 03:56:06 | 000,120,320 | ---- | M] (AMD) -- C:\windows\SysNative\atitmm64.dll [2010.08.26 03:55:50 | 000,421,376 | ---- | M] (ATI Technologies, Inc.) -- C:\windows\SysNative\atipdl64.dll [2010.08.26 03:55:42 | 000,356,352 | ---- | M] (ATI Technologies, Inc.) -- C:\windows\SysWow64\atipdlxx.dll [2010.08.26 03:55:32 | 000,278,528 | ---- | M] (ATI Technologies, Inc.) -- C:\windows\SysWow64\Oemdspif.dll [2010.08.26 03:55:28 | 000,012,288 | ---- | M] (AMD) -- C:\windows\SysNative\atimuixx.dll [2010.08.26 03:55:22 | 000,059,392 | ---- | M] (ATI Technologies, Inc.) -- C:\windows\SysNative\atiedu64.dll [2010.08.26 03:55:18 | 000,043,520 | ---- | M] (ATI Technologies, Inc.) -- C:\windows\SysWow64\ati2edxx.dll [2010.08.26 03:30:40 | 000,583,888 | ---- | M] () -- C:\windows\SysNative\atiumd6a.cap [2010.08.26 03:27:58 | 000,057,344 | ---- | M] (AMD) -- C:\windows\SysNative\coinst.dll [2010.08.26 03:25:36 | 000,583,888 | ---- | M] () -- C:\windows\SysWow64\atiumdva.cap [2010.08.15 20:28:54 | 000,000,020 | -HS- | M] () -- C:\Users\dusty\ntuser.ini [2010.08.15 19:26:58 | 000,110,326 | ---- | M] () -- C:\Users\dusty\Documents\SICHERUNG 15.08.reg [2010.08.06 18:34:14 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf [2010.08.02 10:38:00 | 000,021,866 | ---- | M] () -- C:\windows\atiogl.xml [2010.07.29 10:26:39 | 000,000,064 | ---- | M] () -- C:\ProgramData\sandra.ldb [2010.07.26 12:26:36 | 000,000,124 | ---- | M] () -- C:\Users\dusty\Documents\Visit GameTuts.url [6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.10.22 13:53:05 | 000,001,111 | ---- | C] () -- C:\Users\dusty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2010.10.22 13:46:34 | 000,001,014 | ---- | C] () -- C:\Users\dusty\Contacts\Desktop\MFTools - Verknüpfung.lnk [2010.10.21 21:08:48 | 000,004,788 | ---- | C] () -- C:\Users\dusty\Documents\cc 21.010.2010.reg [2010.10.21 21:06:41 | 000,037,600 | ---- | C] () -- C:\Users\dusty\Documents\cc_20101021_210638.reg [2010.10.20 18:00:28 | 000,000,819 | ---- | C] () -- C:\Users\dusty\Contacts\Desktop\Xbox 360 - Verknüpfung.lnk [2010.10.09 18:32:29 | 000,065,536 | ---- | C] () -- C:\windows\SysNative\Ikeext.etl [2010.09.13 16:55:12 | 000,002,560 | ---- | C] () -- C:\windows\_MSRSTRT.EXE [2010.09.11 12:01:58 | 000,001,074 | ---- | C] () -- C:\Users\Public\Desktop\XMedia Recode.lnk [2010.09.11 11:21:50 | 000,001,147 | ---- | C] () -- C:\Users\dusty\Contacts\Desktop\Any Video Converter.lnk [2010.09.02 17:13:38 | 000,051,976 | ---- | C] () -- C:\Users\dusty\Documents\cc_20100902_171333.reg [2010.08.26 04:01:34 | 000,076,216 | ---- | C] () -- C:\windows\SysNative\atiapfxx.blb [2010.08.26 03:30:40 | 000,583,888 | ---- | C] () -- C:\windows\SysNative\atiumd6a.cap [2010.08.26 03:25:36 | 000,583,888 | ---- | C] () -- C:\windows\SysWow64\atiumdva.cap [2010.08.15 20:28:54 | 000,000,020 | -HS- | C] () -- C:\Users\dusty\ntuser.ini [2010.08.15 19:25:31 | 000,110,326 | ---- | C] () -- C:\Users\dusty\Documents\SICHERUNG 15.08.reg [2010.08.06 18:34:14 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf [2010.08.02 10:38:00 | 000,021,866 | ---- | C] () -- C:\windows\atiogl.xml [2010.07.31 09:17:02 | 000,335,872 | ---- | C] () -- C:\windows\SysWow64\m4atag.dll [2010.07.29 10:26:38 | 000,000,064 | ---- | C] () -- C:\ProgramData\sandra.ldb [2010.05.31 15:49:27 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010.05.01 13:37:04 | 013,045,760 | ---- | C] () -- C:\ProgramData\sandra.mda [2010.05.01 13:26:19 | 000,000,133 | ---- | C] () -- C:\Users\dusty\AppData\Roaming\burnaware.ini [2010.04.26 16:01:01 | 000,005,120 | ---- | C] () -- C:\Users\dusty\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.04.08 21:22:13 | 000,000,000 | ---- | C] () -- C:\Users\dusty\AppData\Roaming\wklnhst.dat [2010.04.02 17:17:34 | 000,179,091 | ---- | C] () -- C:\windows\SysWow64\xlive.dll.cat [2009.11.16 18:33:38 | 000,053,299 | ---- | C] () -- C:\windows\SysWow64\pthreadVC.dll [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll [2009.06.07 13:27:20 | 000,073,728 | ---- | C] () -- C:\windows\SysWow64\vbzlib1.dll ========== LOP Check ========== [2010.07.08 14:51:19 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\1&1 [2010.06.03 11:12:07 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\AceBIT [2010.09.11 11:21:46 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\AnvSoft [2010.07.01 10:03:20 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Ashampoo [2010.06.02 13:57:02 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Blender Foundation [2010.05.01 13:12:09 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Canneverbe Limited [2010.06.14 09:47:13 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Command and Conquer 4 [2010.04.12 15:30:48 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\COMPUTERBILD-Abzockschutz [2010.04.12 16:54:33 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\DAEMON Tools Lite [2010.08.17 20:06:01 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Datel [2010.04.25 17:39:12 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\DeepBurner [2010.07.30 11:49:14 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\DVDVideoSoftIEHelpers [2010.10.21 22:10:22 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\EAST Technologies [2010.04.23 11:40:22 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\FinalMediaPlayer [2010.04.26 15:12:44 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\FreeVideoConverter [2010.07.01 17:06:44 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\GameTuts [2010.09.01 15:54:54 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\GetRightToGo [2010.09.21 15:28:34 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\ICQ [2010.08.24 23:11:56 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Mael [2010.07.22 16:24:45 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\OpenCandy [2010.09.09 10:08:11 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Opera [2010.09.20 18:59:16 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\PhotoFiltre [2010.08.06 20:04:54 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\TeamViewer [2010.05.26 08:18:22 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\The Creative Assembly [2010.05.04 08:38:43 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Tific [2010.06.14 13:07:49 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Tropico 3 [2010.07.22 16:25:15 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Uniblue [2010.04.27 09:20:36 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\uTorrent [2010.09.11 12:40:41 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\XMedia Recode [2010.08.05 23:21:47 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* > [2010.10.22 13:50:41 | 3218,939,904 | -HS- | M] () -- C:\hiberfil.sys [2006.12.02 00:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll [2010.10.22 13:50:49 | 4291,919,872 | -HS- | M] () -- C:\pagefile.sys < %systemroot%\system32\*.wt > < %systemroot%\system32\*.ruy > < %systemroot%\Fonts\*.com > [2009.07.14 07:32:31 | 000,026,040 | ---- | M] () -- C:\windows\Fonts\GlobalMonospace.CompositeFont [2009.07.14 07:32:31 | 000,026,489 | ---- | M] () -- C:\windows\Fonts\GlobalSansSerif.CompositeFont [2009.07.14 07:32:31 | 000,029,779 | ---- | M] () -- C:\windows\Fonts\GlobalSerif.CompositeFont [2009.07.14 07:32:31 | 000,043,318 | ---- | M] () -- C:\windows\Fonts\GlobalUserInterface.CompositeFont < %systemroot%\Fonts\*.dll > < %systemroot%\Fonts\*.ini > [2009.06.10 22:49:50 | 000,000,065 | ---- | M] () -- C:\windows\Fonts\desktop.ini < %systemroot%\Fonts\*.ini2 > < %systemroot%\system32\spool\prtprocs\w32x86\*.* > < %systemroot%\REPAIR\*.bak1 > < %systemroot%\REPAIR\*.ini > < %systemroot%\system32\*.jpg > < %systemroot%\*.scr > [2010.04.17 01:45:28 | 000,307,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR < %systemroot%\*._sy > < %APPDATA%\Adobe\Update\*.* > < %ALLUSERSPROFILE%\Favorites\*.* > < %APPDATA%\Microsoft\*.* > < %PROGRAMFILES%\*.* > [2009.07.14 06:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini < %APPDATA%\Update\*.* > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\system32\user32.dll /md5 > [2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll < %systemroot%\system32\ws2_32.dll /md5 > [2009.07.14 03:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\SysWOW64\ws2_32.dll < %systemroot%\system32\ws2help.dll /md5 > [2009.07.14 03:11:26 | 000,004,608 | ---- | M] (Microsoft Corporation) MD5=808AABDF9337312195CAFF76D1804786 -- C:\Windows\SysWOW64\ws2help.dll < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > ========== Alternate Data Streams ========== @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C97C8631 < End of report > |
Themen zu Mein Pc läuft nicht mehr richtig. |
adblock, alternate, backdoor.bifrose, bho, components, computer, converter, defender, error, explorer, firefox, firefox problem, format, googel, google, home, home premium, icq, iexplore.exe, intrusion prevention, langsam, location, logfile, microsoft, mp3, oldtimer, pc läuft, plug-in, problem beim spielen, programdata, realtek, registry, safer networking, searchplugins, security, senden, server, sptd.sys, start menu, stick, suche, superantispyware, symantec, syswow64, webcheck |