![]() |
Plagegeister aller Art und deren Bekämpfung: "Ein kritischer Fehler ist aufgetreten. Windows wird in einer Minute neu gestartet."Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
![]() | #1 |
| ![]() "Ein kritischer Fehler ist aufgetreten. Windows wird in einer Minute neu gestartet." Hey Leute, seit gestern am späten Abend trat bei mir regelmäßig die Meldung: "Ein kritischer Fehler ist aufgetreten. Windows wird in einer Minute neu gestartet. Speichern sie jetzt ihre Daten." Diese Meldung trit kurz nach einem Neustart ein. Wäre nett, wenn mir jemand helfen kann ![]() MBAM Scan: Code:
ATTFilter Malwarebytes' Anti-Malware www.malwarebytes.org Datenbank Version: 5907 Windows 6.1.7600 (Safe Mode) Internet Explorer 8.0.7600.16385 28.02.2011 22:42:49 mbam-log-2011-02-28 (22-42-49).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 164300 Laufzeit: 2 Minute(n), 55 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Code:
ATTFilter OTL logfile created on: 01.03.2011 13:09:29 - Run 1 OTL by OldTimer - Version Folder = C:\Users\jonas\Desktop 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 81,00% Memory free 8,00 Gb Paging File | 7,00 Gb Available in Paging File | 91,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 450,44 Gb Total Space | 65,48 Gb Free Space | 14,54% Space Free | Partition Type: NTFS Computer Name: *** | User Name: jonas | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\jonas\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Modules (SafeList) ========== MOD - C:\Users\jonas\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (EhttpSrv) -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET) SRV:64bit: - (ekrn) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (ESET) SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.) SRV:64bit: - (lxdo_device) -- C:\Windows\SysNative\lxdocoms.exe ( ) SRV:64bit: - (lxdoCATSCustConnectService) -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\lxdoserv.exe () SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe () SRV - (TeamViewer5) -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH) SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.) SRV - (ePowerSvc) -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Acer Incorporated) SRV - (NTI IScheduleSvc) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.) SRV - (MWLService) -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe () SRV - (IGBASVC) -- C:\Program Files (x86)\Acer Bio Protection\BASVC.exe (Egis Technology Inc.) SRV - (Greg_Service) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated) SRV - (Fabs) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG) SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (RS_Service) -- C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated) SRV - (Updater Service) -- C:\Programme\Acer\Acer Updater\UpdaterService.exe (Acer) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (IAANTMON) Intel(R) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation) SRV - (AgereModemAudio) -- C:\Programme\LSI SoftModem\agr64svc.exe (LSI Corporation) SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.) SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®) SRV - (lxdo_device) -- C:\Windows\SysWow64\lxdocoms.exe ( ) ========== Driver Services (SafeList) ========== DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.) DRV:64bit: - (eamonm) -- C:\Windows\SysNative\drivers\eamonm.sys (ESET) DRV:64bit: - (ehdrv) -- C:\Windows\SysNative\drivers\ehdrv.sys (ESET) DRV:64bit: - (epfwwfpr) -- C:\Windows\SysNative\drivers\epfwwfpr.sys (ESET) DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation) DRV:64bit: - (FPSensor) EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys) -- C:\Windows\SysNative\drivers\FPSensor.sys (EgisTec) DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys (Duplex Secure Ltd.) DRV:64bit: - (NETw5s64) Intel(R) -- C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation) DRV:64bit: - (YMIDUSBW) Yamaha USB-MIDI Driver (WDM) -- C:\Windows\SysNative\drivers\ymidusbx64.sys (Yamaha Corporation) DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corporation) DRV:64bit: - (hidshim) -- C:\Windows\SysNative\drivers\hidshim.sys (Windows (R) Win 7 DDK provider) DRV:64bit: - (nuvotonhidgeneric) -- C:\Windows\SysNative\drivers\nuvotonhidgeneric.sys (Nuvoton Technology Corporation) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (k57nd60a) Broadcom NetLink (TM) -- C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation) DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) DRV:64bit: - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) -- C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.) DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof () DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) DRV:64bit: - (netw5v64) Intel(R) -- C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation) DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation) DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.) DRV:64bit: - (mwlPSDVDisk) -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.) DRV:64bit: - (mwlPSDFilter) -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.) DRV:64bit: - (mwlPSDNServ) -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.) DRV:64bit: - (ApfiltrService) -- C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.) DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV:64bit: - (NTIDrvr) -- C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.) DRV:64bit: - (UBHelper) -- C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation) DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics, Inc.) DRV:64bit: - (ManyCam) -- C:\Windows\SysNative\drivers\ManyCam_x64.sys (ManyCam LLC.) DRV:64bit: - (VF0350Vid) Live! Cam Video IM (VF0350) -- C:\Windows\SysNative\drivers\V0350Vid.sys (Creative Technology Ltd.) DRV:64bit: - (VF0350Vfx) -- C:\Windows\SysNative\drivers\V0350Vfx.sys (EyePower Games Pte. Ltd.) DRV - (ASPI32) -- C:\Windows\SysWow64\drivers\ASPI32.SYS (Adaptec) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7738&r=27360110z906l03e8z165t6861w29o IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7738&r=27360110z906l03e8z165t6861w29o IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7738&r=27360110z906l03e8z165t6861w29o IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7738&r=27360110z906l03e8z165t6861w29o IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - File not found IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.) IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7738&r=27360110z906l03e8z165t6861w29o IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Ask.com" FF - prefs.js..browser.search.defaultthis.engineName: "Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.openintab: true FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.selectedEngine: "Ask.com" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" FF - prefs.js..extensions.charles.settings.disabled.network.proxy.http: "" FF - prefs.js..extensions.charles.settings.disabled.network.proxy.http_port: 0 FF - prefs.js..extensions.charles.settings.disabled.network.proxy.no_proxies_on: "localhost," FF - prefs.js..extensions.charles.settings.disabled.network.proxy.share_proxy_settings: false FF - prefs.js..extensions.charles.settings.disabled.network.proxy.socks: "" FF - prefs.js..extensions.charles.settings.disabled.network.proxy.socks_port: 0 FF - prefs.js..extensions.charles.settings.disabled.network.proxy.ssl: "" FF - prefs.js..extensions.charles.settings.disabled.network.proxy.ssl_port: 0 FF - prefs.js..extensions.charles.settings.disabled.network.proxy.type: 5 FF - prefs.js..extensions.charles.settings.enabled.network.proxy.http: "" FF - prefs.js..extensions.charles.settings.enabled.network.proxy.http_port: 8888 FF - prefs.js..extensions.charles.settings.enabled.network.proxy.no_proxies_on: "" FF - prefs.js..extensions.charles.settings.enabled.network.proxy.share_proxy_settings: false FF - prefs.js..extensions.charles.settings.enabled.network.proxy.socks: "" FF - prefs.js..extensions.charles.settings.enabled.network.proxy.socks_port: 0 FF - prefs.js..extensions.charles.settings.enabled.network.proxy.ssl: "" FF - prefs.js..extensions.charles.settings.enabled.network.proxy.ssl_port: 8888 FF - prefs.js..extensions.charles.settings.enabled.network.proxy.type: 1 FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1 FF - prefs.js..extensions.enabledItems: {49f3fc85-dcfe-4e42-9301-226ebe658509}:0.6.6 FF - prefs.js..extensions.enabledItems: linky@gemal.dk:3.0.0 FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com: FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.1 FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}: FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}: FF - prefs.js..extensions.enabledItems: toolbar@ask.com: FF - prefs.js..extensions.enabledItems: {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}: FF - prefs.js..extensions.enabledItems: {3e9a3920-1b27-11da-8cd6-0800200c9a66}:3.4.1 FF - prefs.js..extensions.enabledItems: finder@meingutscheincode.de:2.0 FF - prefs.js..extensions.enabledItems: {40c3cc16-7269-4b32-9531-17f2950fb06f}: FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3 FF - prefs.js..extensions.enabledItems: {60c4696a-e4eb-4d2d-9060-38928dd0b6a2}: FF - prefs.js..extensions.enabledItems: {464F169E-ACE1-4C5F-A778-A433A3DABBAE}:1.0 FF - prefs.js..keyword.URL: "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=CLM&o=15427&locale=de_DE&apn_uid=97AC49B1-1AA7-4E43-970F-AD20948253C6&apn_ptnrs=LE&apn_sauid=9C137333-8626-4256-BAD2-E3B016BDB082&apn_dtid=YYYYYYB3DE&q=" FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.02.23 17:49:50 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.02.08 14:59:26 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.02.08 14:59:26 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2011.02.08 14:59:26 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010.09.15 19:31:16 | 000,000,000 | ---D | M] [2010.03.04 20:44:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Extensions [2010.03.04 20:44:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2011.02.28 20:23:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions [2010.09.04 18:59:03 | 000,000,000 | ---D | M] (Charles Autoconfiguration) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{3e9a3920-1b27-11da-8cd6-0800200c9a66} [2010.11.03 04:19:59 | 000,000,000 | ---D | M] (Winload Toolbar) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f} [2011.02.21 16:33:30 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8} [2010.02.21 00:26:57 | 000,000,000 | ---D | M] (LinkChecker) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{49f3fc85-dcfe-4e42-9301-226ebe658509} [2010.11.21 12:09:18 | 000,000,000 | ---D | M] (digitalchocolate Toolbar) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{60c4696a-e4eb-4d2d-9060-38928dd0b6a2} [2010.03.19 10:17:33 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2011.02.21 16:33:19 | 000,000,000 | ---D | M] (iMacros for Firefox) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2010.11.03 04:20:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2010.10.26 22:36:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{9fb7d178-155a-4318-9173-1a8eaaea7fe4} [2010.11.03 04:20:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2010.03.15 15:55:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2011.01.26 18:34:08 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2011.02.21 16:33:17 | 000,000,000 | ---D | M] ("Tab Mix Plus") -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{dc572301-7619-498c-a57d-39143191b318} [2010.02.10 19:22:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2011.01.26 18:34:04 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2011.02.21 16:33:30 | 000,000,000 | ---D | M] (Mein Gutscheincode Finder) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\finder@meingutscheincode.de [2010.01.08 14:42:18 | 000,000,000 | ---D | M] (Layerblock [de]) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\layerblock@jonathan.haas.de [2010.12.04 12:51:05 | 000,000,000 | ---D | M] (Linky) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\linky@gemal.dk [2010.01.08 14:42:18 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\moveplayer@movenetworks.com [2010.01.08 14:42:21 | 000,000,000 | ---D | M] ("PennerBar") -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\pennerbar3@pennergame.de [2010.11.03 04:20:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\sizchip_plugin_17@siz.de [2011.02.21 16:33:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\staged-xpis [2010.10.27 06:08:38 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\toolbar@ask.com [2011.02.21 16:33:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\t6dik2fk.default\extensions\{dc572301-7619-498c-a57d-39143191b318}\modules\extensions [2009.08.15 17:25:19 | 000,002,273 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\ask.xml [2011.02.28 20:13:40 | 000,002,395 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\askcom.xml [2010.03.24 15:13:02 | 000,000,917 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\conduit.xml [2010.06.11 15:05:02 | 000,005,310 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\footiefox.xml [2011.02.28 01:37:19 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-1.xml [2010.09.19 19:31:27 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-10.xml [2010.10.10 21:49:25 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-11.xml [2010.10.23 19:52:44 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-12.xml [2010.10.26 12:58:49 | 000,000,656 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-13.xml [2010.10.27 17:32:22 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-14.xml [2010.10.30 10:29:53 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-15.xml [2010.03.18 16:38:40 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-2.xml [2010.04.02 17:39:27 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-3.xml [2010.04.11 14:31:02 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-4.xml [2010.06.24 08:31:23 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-5.xml [2010.06.24 20:23:22 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-6.xml [2010.07.22 12:21:42 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-7.xml [2010.07.24 21:54:22 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-8.xml [2010.08.01 15:52:04 | 000,000,950 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin-9.xml [2010.02.03 14:37:50 | 000,000,947 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\icqplugin.xml [2009.08.15 17:26:00 | 000,002,267 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\surf-canyon.xml [2009.08.15 17:25:19 | 000,000,567 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\t6dik2fk.default\searchplugins\yahoo.xml [2011.02.28 20:23:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2010.12.02 20:09:12 | 000,000,000 | ---D | M] (VMLoad) -- C:\Program Files (x86)\mozilla firefox\extensions\{464F169E-ACE1-4C5F-A778-A433A3DABBAE} [2010.11.03 04:20:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2009.08.09 00:11:22 | 010,437,264 | ---- | M] (PDFTron Systems Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\PDFNetC.dll [2009.08.09 00:30:36 | 000,107,760 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\ScorchPDFWrapper.dll [2010.11.07 02:02:20 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.11.07 02:02:20 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.11.07 02:02:20 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.11.07 02:02:20 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.11.07 02:02:20 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.09.23 19:54:38 | 000,419,530 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: activate.adobe.com O1 - Hosts: www.007guard.com O1 - Hosts: 007guard.com O1 - Hosts: 008i.com O1 - Hosts: www.008k.com O1 - Hosts: 008k.com O1 - Hosts: www.00hq.com O1 - Hosts: 00hq.com O1 - Hosts: 010402.com O1 - Hosts: www.032439.com O1 - Hosts: 032439.com O1 - Hosts: www.0scan.com O1 - Hosts: 0scan.com O1 - Hosts: 1000gratisproben.com O1 - Hosts: www.1000gratisproben.com O1 - Hosts: 1001namen.com O1 - Hosts: www.1001namen.com O1 - Hosts: 100888290cs.com O1 - Hosts: www.100888290cs.com O1 - Hosts: www.100sexlinks.com O1 - Hosts: 100sexlinks.com O1 - Hosts: 10sek.com O1 - Hosts: www.10sek.com O1 - Hosts: www.1-2005-search.com O1 - Hosts: 1-2005-search.com O1 - Hosts: 14474 more lines... O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll (Google Inc.) O2 - BHO: (VirtualCamera IEMenu Class) - {0246A1A7-820A-469A-85A7-7B7F01EB808C} - C:\Program Files (x86)\VirtualCamera\VirtualCameraMenu.dll (MorningSound Soft) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.) O2 - BHO: (VMLoadHBO Class) - {C17C7688-31D1-46D7-8C9B-5D253E4F5D5E} - C:\Users\jonas\AppData\Roaming\VMLoad\addin\VMLoad.dll (TODO: <Company name>) O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - File not found O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Programme\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe (Acer Incorporated) O4:64bit: - HKLM..\Run: [C:\Windows\system32\V0350Ext.ax] C:\Windows\SysNative\V0350Ext.ax (Creative Technology Ltd.) O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET) O4 - HKLM..\Run: [C:\Windows\SysWOW64\V0350Ext.ax] C:\Windows\SysWOW64\V0350Ext.ax (Creative Technology Ltd.) O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) O4 - HKCU..\Run: [AdobeBridge] File not found O4 - HKLM..\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus DirectShow Filters\DivXDecH264.ax] File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\jonas\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\jonas\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm () O9:64bit: - Extra Button: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe (Egis Technology Inc.) O9:64bit: - Extra 'Tools' menuitem : Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe (Egis Technology Inc.) O9 - Extra Button: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe (Egis Technology Inc.) O9 - Extra 'Tools' menuitem : Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe (Egis Technology Inc.) O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - File not found O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - File not found O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe () O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class) O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Acer\Acer VCM\Skype4COM.dll (Skype Technologies) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{3662bfed-fd58-11de-9f64-00262d62c6aa}\Shell - "" = AutoRun O33 - MountPoints2\{3662bfed-fd58-11de-9f64-00262d62c6aa}\Shell\AutoRun\command - "" = G:\autorun.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O36 - AppCertDlls: lodcetsh - (C:\Windows\system32\dfrgocfg.dll) - File not found O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.02.28 23:02:27 | 000,000,000 | ---D | C] -- C:\_OTL [2011.02.28 23:01:10 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Users\jonas\Desktop\OTL.exe [2011.02.28 20:28:05 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Users\jonas\Desktop\TFC.exe [2011.02.28 19:52:45 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{417D58C2-FD14-4F7D-937B-D2869D39BEEA} [2011.02.28 15:07:48 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{F22BC95F-EA4E-41E4-8B39-C5FC6BB81DC2} [2011.02.27 19:11:06 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{AAAB30EC-AB10-4AB7-A5E0-0F661EA3956F} [2011.02.27 07:11:22 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{7783523A-2BBA-4593-9B6C-9FCBB3084C42} [2011.02.26 11:32:49 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{E2B73917-7E8F-4DA8-9187-3EA053E4586F} [2011.02.25 15:53:59 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{DD2ABF93-6FB4-4586-B225-4AC1FDBF8462} [2011.02.24 12:57:34 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{7B22ED4C-7B4D-452D-B9FF-50E47240C5B9} [2011.02.23 16:14:55 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{B471D6AC-736E-4A9D-A9F6-E3B8E7035B5E} [2011.02.22 13:37:03 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{7612FD48-4A3E-4FA0-8694-2CE2FFA7C88B} [2011.02.21 14:41:42 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{FC2100CD-58FA-40CF-BBBF-403C646B03E3} [2011.02.20 21:20:53 | 000,000,000 | ---D | C] -- C:\Users\jonas\Desktop\F4aoifaBauox11 [2011.02.20 12:14:06 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{CDA67228-1955-45C3-89CE-F28AA60A50D9} [2011.02.20 00:23:42 | 000,000,000 | ---D | C] -- C:\Users\jonas\Desktop\Inception OST [2011.02.20 00:13:28 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{841F6977-EA60-4A68-8A21-B23A59EE460D} [2011.02.19 12:12:49 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{637A95B1-7189-45EE-AD4A-238ECC62E778} [2011.02.18 07:19:08 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{D290686D-33A2-434E-88E6-91BAD3FD9B04} [2011.02.17 14:09:52 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{DC97B21C-7488-4BF7-95DB-55CC614E5A31} [2011.02.16 22:53:16 | 000,000,000 | ---D | C] -- C:\Users\jonas\Desktop\RYL [2011.02.16 22:08:04 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{8F261A3E-CC72-44B5-86C9-3496F43848C3} [2011.02.16 06:13:23 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{1BC929A2-639C-4112-A331-F8CD95565F91} [2011.02.15 13:35:30 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{EF02C8F2-D9D2-4F8C-814E-C4A3A96D77CB} [2011.02.14 20:01:01 | 000,000,000 | ---D | C] -- C:\Users\jonas\Desktop\Deez Nuts - Stay True (2008) by xiro [2011.02.14 14:46:19 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{485FF2E7-DCFA-4AC3-8195-65EBB2A70690} [2011.02.13 13:15:15 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{FAE9F1B8-0179-4ADC-A04F-1A707589E485} [2011.02.13 13:10:58 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{87CAD1F7-5E03-4E6E-8386-884E0E445D86} [2011.02.13 02:00:38 | 000,000,000 | ---D | C] -- C:\Users\jonas\Desktop\Grips_&_Tonic_-_Songs_To_Fuck_Your_Hand_To [2011.02.12 16:11:34 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{04202E6B-BBE7-4847-B543-6007EEF45112} [2011.02.11 07:03:51 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{CC5869F4-3E36-4C31-803F-9B1AA9871C0D} [2011.02.10 18:34:06 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\Native Instruments [2011.02.10 18:29:26 | 000,000,000 | ---D | C] -- C:\Users\jonas\Documents\Native Instruments [2011.02.10 18:29:10 | 000,000,000 | -H-D | C] -- C:\ProgramData\{9B069D1C-ECB9-4D1B-A782-7D5DDA2045D6} [2011.02.10 18:26:11 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Native Instruments [2011.02.10 18:26:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Native Instruments [2011.02.10 18:25:06 | 000,000,000 | -H-D | C] -- C:\ProgramData\{B5F0C192-874D-49A8-88D7-8431E3714756} [2011.02.10 18:24:56 | 000,000,000 | ---D | C] -- C:\Programme\Native Instruments [2011.02.10 18:23:35 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Kore 2 Sample Content [2011.02.10 13:59:40 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{06A28ED4-D385-4CB5-BFDC-4A1CF9F25202} [2011.02.10 06:42:26 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll [2011.02.10 06:42:25 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2011.02.10 06:42:25 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll [2011.02.10 06:42:25 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2011.02.10 06:42:25 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2011.02.10 06:42:24 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll [2011.02.10 06:42:24 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2011.02.10 06:42:24 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2011.02.10 06:42:24 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll [2011.02.10 06:42:24 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll [2011.02.10 06:42:23 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec [2011.02.10 06:42:23 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe [2011.02.10 06:42:23 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe [2011.02.10 06:42:22 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec [2011.02.10 06:41:48 | 005,510,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2011.02.10 06:41:47 | 001,739,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll [2011.02.10 06:41:46 | 003,901,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2011.02.10 06:41:45 | 003,957,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2011.02.10 06:41:42 | 000,852,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2011.02.10 06:41:42 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2011.02.10 06:41:42 | 000,612,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2011.02.10 06:41:37 | 000,366,080 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll [2011.02.10 06:41:37 | 000,294,400 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll [2011.02.10 06:41:37 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll [2011.02.10 06:41:36 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll [2011.02.09 15:51:35 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{EF35C5A1-02BC-464E-A49F-E7D518917C9C} [2011.02.08 19:04:15 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{6188D897-D05B-4552-AC95-857267A4B83A} [2011.02.08 15:03:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2011.02.08 15:02:14 | 000,000,000 | ---D | C] -- C:\Programme\iTunes [2011.02.08 15:02:14 | 000,000,000 | ---D | C] -- C:\Programme\iPod [2011.02.08 14:59:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime [2011.02.08 14:58:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime [2011.02.08 14:57:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update [2011.02.08 07:03:17 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{292898A1-C8E1-436D-A87A-C5D27E5FCAF9} [2011.02.07 14:53:40 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{F2DC2312-7AEC-482D-AD7D-FCA2ABDD8C46} [2011.02.06 15:29:51 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{803D5B24-3160-41B6-9DAA-68EDF1703DFE} [2011.02.06 15:29:09 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{8D67124C-0283-4861-BED3-6483E8D0F1E3} [2011.02.05 12:56:28 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{C8207AE7-5D78-4052-9A72-4164A903B3EA} [2011.02.04 07:00:37 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{F08A20A3-975C-491A-8642-1619D7F81AA8} [2011.02.03 14:23:05 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{AB619811-B66B-49A2-B4B2-9F09D28D6C9B} [2011.02.02 15:29:03 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{F42A1260-AB51-42F3-BF2B-F29E415EDF43} [2011.02.01 14:22:21 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{2D35A686-59C3-457B-84AA-DECEB944B87B} [2011.02.01 05:02:41 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{BE825509-A3E0-4E70-A79A-65B5193BC901} [2011.01.31 15:26:56 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{72527545-0CC4-4ADF-A0A5-1EE69880F5E3} [2010.08.01 15:48:39 | 008,408,392 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 3.6.8.exe [2010.02.24 19:58:50 | 000,360,448 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdoinpa.dll [2010.02.24 19:58:50 | 000,339,968 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdoiesc.dll [2010.02.24 19:58:49 | 000,643,072 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdopmui.dll [2010.02.24 19:58:48 | 001,069,056 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdoserv.dll [2010.02.24 19:58:48 | 000,954,368 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdousb1.dll [2010.02.24 19:58:48 | 000,569,344 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdolmpm.dll [2010.02.24 19:58:48 | 000,315,392 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdoih.exe [2010.02.24 19:58:48 | 000,053,248 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdoprox.dll [2010.02.24 19:58:47 | 000,851,968 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdocomc.dll [2010.02.24 19:58:47 | 000,663,552 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdohbn3.dll [2010.02.24 19:58:47 | 000,589,824 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdocoms.exe [2010.02.24 19:58:47 | 000,364,544 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdocomm.dll [2010.02.24 19:58:47 | 000,360,448 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdocfg.exe [2009.10.29 06:58:47 | 000,036,136 | ---- | C] (Oberon Media) -- C:\ProgramData\FullRemove.exe ========== Files - Modified Within 30 Days ========== [2011.03.01 12:57:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.03.01 12:57:28 | 3217,235,968 | -HS- | M] () -- C:\hiberfil.sys [2011.03.01 07:22:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011.03.01 07:20:01 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011.03.01 07:15:40 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2011.03.01 07:15:40 | 000,643,628 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2011.03.01 07:15:40 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2011.03.01 07:15:40 | 000,126,188 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2011.03.01 07:15:40 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2011.02.28 23:01:15 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\jonas\Desktop\OTL.exe [2011.02.28 22:50:41 | 333,519,872 | ---- | M] () -- C:\Windows\MEMORY.DMP [2011.02.28 20:28:07 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Users\jonas\Desktop\TFC.exe [2011.02.28 17:37:15 | 403,025,419 | ---- | M] () -- C:\Users\jonas\Desktop\Modern.Combat.2.Black.Pegasus-v1.0.0Dexter420.ipa [2011.02.28 16:26:28 | 208,907,171 | ---- | M] () -- C:\Users\jonas\Desktop\Modern_Combat_Sandstorm_1.4.6.us.ipa [2011.02.28 16:05:18 | 009,159,308 | ---- | M] () -- C:\Users\jonas\Desktop\Tiny_Wings-v1.0-most_uniQue.ipa [2011.02.27 21:08:19 | 000,050,127 | ---- | M] () -- C:\Users\jonas\Desktop\183485_139702002763650_100001715539835_259654_5427464_n.jpg [2011.02.27 21:00:56 | 002,184,037 | ---- | M] () -- C:\Users\jonas\Desktop\P1180101.png [2011.02.27 20:22:09 | 000,075,348 | ---- | M] () -- C:\Users\jonas\Desktop\2957.jpg [2011.02.26 18:19:58 | 004,205,633 | ---- | M] () -- C:\Users\jonas\Desktop\Sir Mix Alot - Baby Got Back (I Like Big Butts).mp3 [2011.02.26 18:13:16 | 005,610,507 | ---- | M] () -- C:\Users\jonas\Desktop\Corona - Rhythm Of The Night (Electro Flo Rida Remix).mp3 [2011.02.24 07:23:10 | 004,803,871 | ---- | M] () -- C:\Users\jonas\Desktop\SILLA - DEEPTHROAT (HD) "SILLA INSTINKT".mp3 [2011.02.24 07:23:10 | 004,580,681 | ---- | M] () -- C:\Users\jonas\Desktop\Silla feat JokA MoTrip - Killa 16barsde Videopremiere.mp3 [2011.02.23 21:06:44 | 000,439,525 | ---- | M] () -- C:\Users\jonas\Desktop\176583_130301003706774_126543854082489_164998_5235299_o.png [2011.02.22 07:02:21 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011.02.22 07:02:21 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011.02.20 00:23:02 | 071,795,359 | ---- | M] () -- C:\Users\jonas\Desktop\Inception OST.zip [2011.02.17 15:28:07 | 003,838,987 | ---- | M] () -- C:\Users\jonas\Desktop\5xL Beats - no Regrets.mp3 [2011.02.14 19:59:22 | 075,567,366 | ---- | M] () -- C:\Users\jonas\Desktop\Deez Nuts - Stay True (2008) by xiro.rar [2011.02.13 22:07:50 | 003,074,539 | ---- | M] () -- C:\Users\jonas\Desktop\Fard - Yaa Siippiii (16bars.de Exclusive).mp3 [2011.02.12 16:39:55 | 003,473,906 | ---- | M] () -- C:\Users\jonas\Desktop\Let Them Fail - Cleansation.mp3 [2011.02.12 16:37:56 | 002,669,382 | ---- | M] () -- C:\Users\jonas\Desktop\BEFORE I FORSAKE - Breaking Boundaries feat. Pablo Sanchez (Billy The Kid).mp3 [2011.02.12 16:37:37 | 000,000,220 | ---- | M] () -- C:\Users\jonas\.swfinfo [2011.02.12 16:35:58 | 027,295,250 | ---- | M] () -- C:\Users\jonas\Desktop\1-01 payday.aac [2011.02.12 16:35:37 | 026,239,405 | ---- | M] () -- C:\Users\jonas\Desktop\1-03 forward.aac [2011.02.12 16:35:34 | 023,229,698 | ---- | M] () -- C:\Users\jonas\Desktop\1-02 sick humanity.aac [2011.02.12 16:06:27 | 002,969,848 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2011.02.10 18:29:09 | 000,001,038 | ---- | M] () -- C:\Users\Public\Desktop\Kore Player.lnk [2011.02.10 18:24:59 | 000,001,063 | ---- | M] () -- C:\Users\Public\Desktop\Service Center.lnk [2011.02.08 15:03:23 | 000,001,787 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2011.02.08 14:59:19 | 000,001,849 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk ========== Files Created - No Company Name ========== [2011.02.28 16:04:47 | 208,907,171 | ---- | C] () -- C:\Users\jonas\Desktop\Modern_Combat_Sandstorm_1.4.6.us.ipa [2011.02.28 16:04:27 | 009,159,308 | ---- | C] () -- C:\Users\jonas\Desktop\Tiny_Wings-v1.0-most_uniQue.ipa [2011.02.28 15:59:41 | 403,025,419 | ---- | C] () -- C:\Users\jonas\Desktop\Modern.Combat.2.Black.Pegasus-v1.0.0Dexter420.ipa [2011.02.27 21:08:17 | 000,050,127 | ---- | C] () -- C:\Users\jonas\Desktop\183485_139702002763650_100001715539835_259654_5427464_n.jpg [2011.02.27 21:00:10 | 002,184,037 | ---- | C] () -- C:\Users\jonas\Desktop\P1180101.png [2011.02.27 20:22:03 | 000,075,348 | ---- | C] () -- C:\Users\jonas\Desktop\2957.jpg [2011.02.26 18:18:55 | 004,205,633 | ---- | C] () -- C:\Users\jonas\Desktop\Sir Mix Alot - Baby Got Back (I Like Big Butts).mp3 [2011.02.26 18:12:33 | 005,610,507 | ---- | C] () -- C:\Users\jonas\Desktop\Corona - Rhythm Of The Night (Electro Flo Rida Remix).mp3 [2011.02.23 21:06:41 | 000,439,525 | ---- | C] () -- C:\Users\jonas\Desktop\176583_130301003706774_126543854082489_164998_5235299_o.png [2011.02.23 20:47:15 | 004,803,871 | ---- | C] () -- C:\Users\jonas\Desktop\SILLA - DEEPTHROAT (HD) "SILLA INSTINKT".mp3 [2011.02.23 19:45:36 | 004,580,681 | ---- | C] () -- C:\Users\jonas\Desktop\Silla feat JokA MoTrip - Killa 16barsde Videopremiere.mp3 [2011.02.20 00:16:42 | 071,795,359 | ---- | C] () -- C:\Users\jonas\Desktop\Inception OST.zip [2011.02.17 15:28:03 | 003,838,987 | ---- | C] () -- C:\Users\jonas\Desktop\5xL Beats - no Regrets.mp3 [2011.02.14 19:49:56 | 075,567,366 | ---- | C] () -- C:\Users\jonas\Desktop\Deez Nuts - Stay True (2008) by xiro.rar [2011.02.13 22:07:48 | 003,074,539 | ---- | C] () -- C:\Users\jonas\Desktop\Fard - Yaa Siippiii (16bars.de Exclusive).mp3 [2011.02.12 16:39:41 | 003,473,906 | ---- | C] () -- C:\Users\jonas\Desktop\Let Them Fail - Cleansation.mp3 [2011.02.12 16:37:34 | 002,669,382 | ---- | C] () -- C:\Users\jonas\Desktop\BEFORE I FORSAKE - Breaking Boundaries feat. Pablo Sanchez (Billy The Kid).mp3 [2011.02.12 16:34:54 | 026,239,405 | ---- | C] () -- C:\Users\jonas\Desktop\1-03 forward.aac [2011.02.12 16:34:41 | 023,229,698 | ---- | C] () -- C:\Users\jonas\Desktop\1-02 sick humanity.aac [2011.02.12 16:34:33 | 027,295,250 | ---- | C] () -- C:\Users\jonas\Desktop\1-01 payday.aac [2011.02.10 18:29:09 | 000,001,038 | ---- | C] () -- C:\Users\Public\Desktop\Kore Player.lnk [2011.02.10 18:24:59 | 000,001,063 | ---- | C] () -- C:\Users\Public\Desktop\Service Center.lnk [2011.02.08 15:03:23 | 000,001,787 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2011.02.08 14:59:19 | 000,001,849 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk [2010.11.23 20:09:47 | 000,200,704 | ---- | C] () -- C:\Windows\PLFSetI.exe [2010.11.13 21:43:43 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll [2010.11.13 21:43:43 | 000,020,480 | ---- | C] () -- C:\Windows\USB_VIDEO_REG.exe [2010.11.13 21:43:43 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini [2010.09.04 14:59:26 | 001,970,176 | ---- | C] () -- C:\Windows\SysWow64\d3dx9.dll [2010.04.20 17:13:01 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2010.04.20 17:12:58 | 000,075,064 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2010.04.20 17:12:56 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini [2010.04.10 12:25:54 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll [2010.03.26 14:23:17 | 000,000,051 | ---- | C] () -- C:\Windows\SysWow64\SYNSOPOS.exe.cfg [2010.03.23 19:32:33 | 000,106,496 | ---- | C] () -- C:\Windows\FixUVC.exe [2010.02.24 21:02:03 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\SYNSOPOS.exe [2010.02.24 19:59:50 | 000,028,672 | ---- | C] () -- C:\Windows\hookdllX.dll [2010.02.24 19:59:50 | 000,011,776 | ---- | C] () -- C:\Windows\SysWow64\pmsbfn32.dll [2010.02.24 19:58:50 | 000,385,024 | ---- | C] () -- C:\Windows\SysWow64\lxdocomx.dll [2010.02.24 19:58:50 | 000,348,160 | ---- | C] () -- C:\Windows\SysWow64\lxdoinst.dll [2010.02.09 17:23:29 | 000,125,532 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat [2010.01.21 17:14:57 | 000,000,280 | ---- | C] () -- C:\Users\jonas\AppData\Roaming\wklnhst.dat [2010.01.10 21:57:42 | 000,037,888 | ---- | C] () -- C:\Windows\SysWow64\AVIwrap.dll [2010.01.10 21:57:38 | 000,073,216 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2010.01.10 21:57:35 | 000,105,472 | ---- | C] () -- C:\Windows\SysWow64\OggDS.dll [2010.01.10 21:57:35 | 000,092,672 | ---- | C] () -- C:\Windows\SysWow64\vorbis.dll [2010.01.10 21:57:34 | 000,090,624 | ---- | C] () -- C:\Windows\SysWow64\vorbisenc.dll [2010.01.10 21:57:34 | 000,021,504 | ---- | C] () -- C:\Windows\SysWow64\ogg.dll [2010.01.10 21:57:31 | 000,132,096 | ---- | C] () -- C:\Windows\SysWow64\libavcodec.dll [2010.01.10 21:57:31 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\libmpeg2_ff.dll [2010.01.10 21:57:31 | 000,008,704 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll [2010.01.10 21:57:28 | 000,077,664 | ---- | C] () -- C:\Windows\SysWow64\IR21_R.DLL [2010.01.10 21:57:27 | 000,019,968 | ---- | C] () -- C:\Windows\SysWow64\Iyvu9_32.dll [2010.01.10 21:57:26 | 000,180,736 | ---- | C] () -- C:\Windows\SysWow64\vfcodec.dll [2010.01.10 21:57:25 | 000,202,240 | ---- | C] () -- C:\Windows\SysWow64\XviD.dll [2010.01.10 21:57:08 | 000,039,936 | ---- | C] () -- C:\Windows\SysWow64\mp4fil32.dll [2010.01.09 22:56:33 | 000,000,981 | ---- | C] () -- C:\Windows\eReg.dat [2010.01.08 14:34:45 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2009.11.23 19:44:57 | 000,001,948 | ---- | C] () -- C:\Windows\WPatchProgress.ini [2009.11.23 11:34:06 | 000,000,033 | ---- | C] () -- C:\Windows\LaunApp.ini [2009.10.28 18:54:34 | 000,000,193 | ---- | C] () -- C:\Windows\Prelaunch.ini [2009.10.28 18:54:34 | 000,000,168 | ---- | C] () -- C:\Windows\WisLangCode.ini [2009.10.28 18:54:34 | 000,000,147 | ---- | C] () -- C:\Windows\WisPriority.ini [2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT [2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat [2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 22:59:36 | 000,982,196 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin [2009.07.13 22:59:36 | 000,139,824 | ---- | C] () -- C:\Windows\SysWow64\igfcg500.bin [2009.07.13 22:59:36 | 000,097,448 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin [2009.07.13 22:59:35 | 000,417,344 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin [2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat ========== Alternate Data Streams ========== @Alternate Data Stream - 1274 bytes -> C:\ProgramData\Microsoft:Eti4Lp73XAEcyt1TIJxifY69y5 @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:0B9176C0 @Alternate Data Stream - 1058 bytes -> C:\ProgramData\Microsoft:BAy27Zaxle2qZDYWfj < End of report > Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:21:36, on 01.03.2011 Platform: Unknown Windows (WinNT 6.01.3504) MSIE: Internet Explorer v8.00 (8.00.7600.16722) Boot mode: Safe mode with network support Running processes: C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Users\jonas\Desktop\OTL.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe C:\Program Files (x86)\iTunes\iTunes.exe C:\Program Files (x86)\Last.fm\LastFM.exe C:\Program Files (x86)\Last.fm\iPodScrobbler.exe C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7738&r=27360110z906l03e8z165t6861w29o R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7738&r=27360110z906l03e8z165t6861w29o R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7738&r=27360110z906l03e8z165t6861w29o R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll O2 - BHO: VirtualCamera IEMenu Class - {0246A1A7-820A-469A-85A7-7B7F01EB808C} - C:\Program Files (x86)\VirtualCamera\VirtualCameraMenu.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll O2 - BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll O2 - BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll O2 - BHO: VMLoadBHO - {C17C7688-31D1-46D7-8C9B-5D253E4F5D5E} - C:\Users\jonas\AppData\Roaming\VMLoad\addin\VMLoad.dll O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (file missing) O3 - Toolbar: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [C:\Windows\SysWOW64\V0350Ext.ax] C:\Windows\system32\RegSvr32.exe /s C:\Windows\SysWOW64\V0350Ext.ax O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" O4 - HKLM\..\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus DirectShow Filters\DivXDecH264.ax] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus DirectShow Filters\DivXDecH264.ax",DllRegisterServer O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST') O4 - Global Startup: Acer VCM.lnk = ? O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\jonas\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html O9 - Extra button: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe O9 - Extra 'Tools' menuitem: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe (file missing) O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe (file missing) O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O13 - Gopher Prefix: O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Acer\Acer VCM\Skype4COM.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe (file missing) O23 - Service: EgisTec Service (IGBASVC) - Egis Technology Inc. - C:\Program Files (x86)\Acer Bio Protection\BASVC.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: lxdoCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\x64\3\\lxdoserv.exe O23 - Service: lxdo_device - - C:\Windows\system32\lxdocoms.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 14517 bytes |
![]() | #2 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() "Ein kritischer Fehler ist aufgetreten. Windows wird in einer Minute neu gestartet." machst du onlinebanking /einkäufe oder sonst was wichtiges mit dem pc?
__________________ |
![]() | #3 |
| ![]() "Ein kritischer Fehler ist aufgetreten. Windows wird in einer Minute neu gestartet." Ich überprüfe ab undzu meinen Kontostand, übers Internet. Ansonsten eher weniger. Wieso, muss ich angst um mein Konto haben?
__________________![]() |
![]() | #4 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() "Ein kritischer Fehler ist aufgetreten. Windows wird in einer Minute neu gestartet." ja ich sehe hier malware die es auf solche zugangsdaten abgesehen hatt. wenn du von diesem pc aus wieder aufs banking zugreifen willst muss er neu aufgesetzt werden und ich erkläre dir wie man ihn absichert.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
![]() | #5 |
| ![]() "Ein kritischer Fehler ist aufgetreten. Windows wird in einer Minute neu gestartet." was meinst du mit "aufsetzen"? formatieren? -.- das hasse ich, aber wenn der dann wieder ordentlich funktionsfähig ist, okay. |
![]() | #6 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() "Ein kritischer Fehler ist aufgetreten. Windows wird in einer Minute neu gestartet." genau formatieren. ich werde dir ne anleitung geben, wie gesagt, falls gewünscht, in der wird auch ein backup programm enthalten sein. mit einem backup programm erstellst du ein genaues abbild der festplatte. beim nächsten trojaner nimmst du dieses und kannst in 5 - 10 minuten ein sauberes komplett eingerichtetes system zurück spielen. aber sichere erst mal die daten und dann gehts los.
__________________ --> "Ein kritischer Fehler ist aufgetreten. Windows wird in einer Minute neu gestartet." |
![]() | #7 |
| ![]() "Ein kritischer Fehler ist aufgetreten. Windows wird in einer Minute neu gestartet." okay, mach ich eben. |
![]() | #8 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() "Ein kritischer Fehler ist aufgetreten. Windows wird in einer Minute neu gestartet." ok. das ist zwar viel arbeit, aber es lohnt sich, bei rückfragen, melden bitte formatiere dann. so wie es sich angehört hatt, weist du wies geht, deswegen erkläre ichs nicht weiter. danach instaliere benötigte treiber. dann gehe auf windows updates, lasse nach updates suchen und instaliere sie, auch das servicepack 1. unter einstellungen so auswählen, dass updates automatisch instaliert werden. du solltest nur noch als eingeschrenkter nutzer arbeiten , das admin konto ist nur für instalationen gedacht. klicke start, tippe unter suchen (ausführen) systemsteuerung. wähle dort Benutzerkonten hinzufügen/entfernen. wähle "neues konto erstellen" Wähle standard benutzer. die uac sollte auf maximum stehen. klicke auf start, ausführen (suchen) tippe uac enter nachfrage bestätigen, regler auf höchste stufe. so ist es schwiriger heimlich etwas auf dem pc zu instalieren. die konten sollten mit einem passwort geschützt werden. dazu auf konto endern klicken und passwörter vergeben. die folgenden konfigurationen als administrator durchführen http://www.trojaner-board.de/96344-a...-rechners.html
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
![]() |
Themen zu "Ein kritischer Fehler ist aufgetreten. Windows wird in einer Minute neu gestartet." |
.dll, adblock, alternate, antivirus, bho, bonjour, c:\windows\system32\rundll32.exe, conduit, converter, egui.exe, ekrn.exe, error, eset nod32, explorer, fehler, firefox, format, hijackthis, home, iastor.sys, location, locker, logfile, monitor, mozilla, mozilla thunderbird, mp3, mywinlocker, neustart, nvidia, oldtimer, otl.exe, plug-in, programdata, realtek, registry, rundll, safer networking, scan, searchplugins, security, software, sptd.sys, start menu, syswow64, webcheck, windows, winload toolbar |