Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Dateien nach Windows Diagnostic

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 24.03.2011, 15:52   #1
0815User
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



Hallo,

ich hatte vor einigen Tagen den Trojaner "Windows Diagnostic" auf meinem Pc. Konnte ihn mit der guten Anleitung hier aus dem Forum schnell entfernen. Allerdings werden jetzt sämtliche Dateien, die unter meinem Benutzer gespeichert waren, nicht mehr angezeigt. Ich habe bereits die anderen Threads zu diesem Thema gelesen, dachte nur ich erstell ein eigenes Thema damit man nicht durcheinanderkommt. Habe schon den Malwarebytes und OTL Scan durchgeführt.

Hier sind die Logs:

Der allerste Malwarebytes-Scan (Quickscan) :

Zitat:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6133

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

22.03.2011 19:06:41
mbam-log-2011-03-22 (19-06-41).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 160645
Laufzeit: 13 Minute(n), 11 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 1
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 7

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\Software\Schmidt-Pro (Trojan.Agent) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SSFdrVXAOXpQ (Trojan.FakeAlert) -> Value: SSFdrVXAOXpQ -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\programdata\ssfdrvxaoxpq.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\programdata\42983176.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\Users\Volker\AppData\Local\Temp\a55c.exe (Rogue.Installer) -> Quarantined and deleted successfully.
c:\Users\Volker\AppData\Local\Temp\comver.dll (Adware.GameSpyArcade) -> Quarantined and deleted successfully.
c:\Users\Volker\AppData\Local\Temp\H8SRT631.tmp (Rootkit.TDSS.Gen) -> Quarantined and deleted successfully.
c:\Users\Volker\AppData\Local\Temp\df8e.exe (Rootkit.TDSS.Gen) -> Quarantined and deleted successfully.
c:\programdata\sysreserve.ini (Malware.Trace) -> Quarantined and deleted successfully.

Malwarebytes-Vollscan:

Zitat:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6133

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

23.03.2011 16:54:20
mbam-log-2011-03-23 (16-54-20).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 376180
Laufzeit: 2 Stunde(n), 3 Minute(n), 13 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 3

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\program files\Visions\updater.exe (Trojan.Dropper.PGen) -> Quarantined and deleted successfully.
c:\program files\Visions\Visions.exe (Trojan.Dropper.PGen) -> Quarantined and deleted successfully.
c:\Users\Volker\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\MM1UCOSB\calc[1].exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

OTL-Scan

OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 24.03.2011 15:29:17 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Volker\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 53,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 76,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144,09 Gb Total Space | 4,14 Gb Free Space | 2,87% Space Free | Partition Type: NTFS
Drive D: | 144,00 Gb Total Space | 104,19 Gb Free Space | 72,35% Space Free | Partition Type: NTFS
 
Computer Name: VOLKER-PC | User Name: Volker | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Volker\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Programme\Steam\Steam.exe (Valve Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Programme\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10c.exe (Adobe Systems, Inc.)
PRC - C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
PRC - C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
PRC - C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics)
PRC - C:\Windows\System32\M-AudioTaskBarIcon.exe (Avid Technology, Inc.)
PRC - C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe (SAMSUNG Electronics co., LTD.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Programme\Internet Explorer\ieuser.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Programme\Syncrosoft\POS\H2O\cledx.exe (Team H2O)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Volker\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (EvtEng) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV - (RegSrvc) -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV - (Samsung Update Plus) -- C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe ()
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (BcmSqlStartupSvc) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NETw5v32) Intel(R) -- C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (VMC302) -- C:\Windows\System32\drivers\vmc302.sys (Vimicro Corporation)
DRV - (MAUSBFTP) Service for M-Audio Fast Track Pro (WDM) -- C:\Windows\System32\drivers\mausb.sys (Avid Technology, Inc.)
DRV - (NETw3v32) Intel(R) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (KMDFMEMIO) -- C:\Windows\System32\drivers\KMDFMEMIO.sys (SAMSUNG ELECTRONICS CO., LTD.)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (bcm4sbxp) -- C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (CLEDX) -- C:\Windows\System32\drivers\cledx.sys (Team H2O)
DRV - (tandpl) -- C:\Windows\System32\drivers\tandpl.sys ()
DRV - (enodpl) -- C:\Windows\System32\drivers\enodpl.sys ()
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Programme\DVDVideoSoft\tbDVD1.dll (Conduit Ltd.)
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\URLSearchHook: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Programme\DVDVideoSoft\tbDVD1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=13"
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.5
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6778
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
 
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009.12.06 12:59:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.15 22:10:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.03.15 22:10:22 | 000,000,000 | ---D | M]
 
[2008.11.14 20:43:54 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Volker\AppData\Roaming\mozilla\Extensions
[2011.03.22 22:24:20 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Volker\AppData\Roaming\mozilla\Firefox\Profiles\84p4wq7f.default\extensions
[2009.09.03 15:13:51 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Volker\AppData\Roaming\mozilla\Firefox\Profiles\84p4wq7f.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.12.17 18:50:24 | 000,000,000 | -H-D | M] ("DVDVideoSoft Menu") -- C:\Users\Volker\AppData\Roaming\mozilla\Firefox\Profiles\84p4wq7f.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2009.12.06 17:38:19 | 000,000,000 | -H-D | M] (DVDVideoSoft Toolbar) -- C:\Users\Volker\AppData\Roaming\mozilla\Firefox\Profiles\84p4wq7f.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
[2009.12.07 21:15:03 | 000,000,873 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\conduit.xml
[2011.03.18 17:08:55 | 000,000,950 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin-1.xml
[2011.03.15 22:10:45 | 000,000,950 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin-10.xml
[2009.08.18 21:34:11 | 000,000,950 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin-2.xml
[2009.09.22 14:23:18 | 000,000,950 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin-3.xml
[2009.11.01 10:29:41 | 000,000,950 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin-4.xml
[2009.12.30 22:03:23 | 000,000,950 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin-5.xml
[2010.01.15 23:21:37 | 000,000,950 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin-6.xml
[2010.03.04 21:28:56 | 000,000,950 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin-7.xml
[2010.04.05 09:39:42 | 000,000,950 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin-8.xml
[2011.03.08 22:29:41 | 000,000,950 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin-9.xml
[2008.03.31 08:52:00 | 000,000,168 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin.gif
[2008.03.31 08:52:00 | 000,000,618 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin.src
[2009.07.24 00:03:06 | 000,000,944 | -H-- | M] () -- C:\Users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\searchplugins\icqplugin.xml
[2011.01.13 17:42:01 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2008.11.14 20:56:10 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Programme\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009.07.15 14:44:41 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.01.13 17:42:02 | 000,000,000 | ---D | M] (Skype extension) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2009.12.06 12:59:16 | 000,000,000 | ---D | M] (HP Smart Web Printing) -- C:\PROGRAM FILES\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON3
[2009.07.15 14:44:41 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
[2011.01.13 17:42:02 | 000,000,000 | ---D | M] (Skype extension) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{AB2CE124-6272-4B12-94A9-7303C7397BD1}
[2010.09.18 10:12:22 | 000,238,776 | ---- | M] (Pando Networks) -- C:\Programme\Mozilla Firefox\plugins\npPandoWebInst.dll
[2011.01.26 15:33:41 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2011.01.26 15:33:41 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2011.01.26 15:33:41 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2011.01.26 15:33:41 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2011.01.26 15:33:41 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found
O2 - BHO: (DVDVideoSoftTB Toolbar) - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Programme\DVDVideoSoft\tbDVD1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Programme\DVDVideoSoft\tbDVD1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} - C:\Programme\DVDVideoSoft\tbDVD1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [H2O] C:\Programme\Syncrosoft\POS\H2O\cledx.exe (Team H2O)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [M-Audio Taskbar Icon] C:\Windows\System32\M-AudioTaskBarIcon.exe (Avid Technology, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Pando Media Booster] C:\Programme\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [Steam] c:\program files\steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Volker\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Volker\Pictures\rage-against-the-machine.jpg
O24 - Desktop BackupWallPaper: C:\Users\Volker\Pictures\rage-against-the-machine.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{d48be40b-ad63-11dd-9b40-001377a9fd0e}\Shell - "" = AutoRun
O33 - MountPoints2\{d48be40b-ad63-11dd-9b40-001377a9fd0e}\Shell\AutoRun\command - "" = G:\LaunchU3.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.03.24 15:27:30 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Volker\Desktop\OTL.exe
[2011.03.22 18:52:33 | 000,000,000 | -H-D | C] -- C:\Users\Volker\AppData\Roaming\Malwarebytes
[2011.03.22 18:52:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.03.22 18:52:05 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.03.22 18:51:57 | 000,000,000 | -H-D | C] -- C:\ProgramData\Malwarebytes
[2011.03.22 18:51:53 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.03.22 18:51:53 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.03.21 21:49:11 | 000,000,000 | -H-D | C] -- C:\Users\Volker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Diagnostic
[2011.03.09 17:43:52 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2011.03.09 17:43:52 | 000,323,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2011.03.09 17:43:51 | 000,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2011.03.09 17:43:51 | 000,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbeio.dll
[2011.02.27 17:30:50 | 000,000,000 | -H-D | C] -- C:\Users\Volker\AppData\Roaming\Softland
[2011.02.27 17:30:48 | 000,022,856 | ---- | C] (Softland) -- C:\Windows\System32\dopdfmn7.dll
[2011.02.27 17:30:48 | 000,019,784 | ---- | C] (Softland) -- C:\Windows\System32\dopdfmi7.dll
[2011.02.27 17:30:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\doPDF 7
[2011.02.23 22:52:08 | 000,000,000 | ---D | C] -- C:\Windows\System32\WindowsPowerShell
[2011.02.23 22:49:48 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrsmgr.dll
[2011.02.23 22:49:37 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrs.exe
[2011.02.23 22:49:37 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrshost.exe
[2011.02.23 22:49:37 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsmprovhost.exe
[2011.02.23 22:49:36 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsmplpxy.dll
[2011.02.23 22:49:36 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrssrv.dll
[2011.02.23 22:49:35 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wevtfwd.dll
[2011.02.23 22:49:35 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wecutil.exe
[2011.02.23 22:49:35 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wecapi.dll
[2011.02.23 22:49:35 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmRes.dll
[2011.02.23 22:49:34 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pwrshplugin.dll
[2011.02.23 22:49:28 | 000,252,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSManMigrationPlugin.dll
[2011.02.23 22:49:28 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSManHTTPConfig.exe
[2011.02.23 22:49:28 | 000,241,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrscmd.dll
[2011.02.23 22:49:28 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmWmiPl.dll
[2011.02.23 22:49:28 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmAuto.dll
[2006.11.24 06:14:44 | 000,139,264 | ---- | C] ( ) -- C:\Windows\System32\MACSSDK_wiz.dll
[2006.11.24 06:14:44 | 000,126,976 | ---- | C] ( ) -- C:\Windows\System32\MACSSDK.dll
 
========== Files - Modified Within 30 Days ==========
 
[2011.03.24 15:27:34 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Volker\Desktop\OTL.exe
[2011.03.24 15:22:38 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.03.24 15:22:38 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.03.24 15:22:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.03.24 15:22:29 | 3215,572,992 | -HS- | M] () -- C:\hiberfil.sys
[2011.03.23 21:44:38 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011.03.23 20:11:10 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{E7D34EEB-CE6E-4564-990F-66D07FE2E827}.job
[2011.03.23 16:58:48 | 000,000,680 | ---- | M] () -- C:\Users\Volker\AppData\Local\d3d9caps.dat
[2011.03.22 20:58:29 | 000,204,864 | ---- | M] () -- C:\Users\Volker\Desktop\DataRecovery_EN_2.4.6.zip
[2011.03.22 18:52:07 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.03.22 18:38:46 | 000,000,096 | -H-- | M] () -- C:\ProgramData\~42983176
[2011.03.22 18:38:45 | 000,000,128 | -H-- | M] () -- C:\ProgramData\~42983176r
[2011.03.22 18:38:41 | 000,198,500 | -H-- | M] () -- C:\ProgramData\nvModes.001
[2011.03.22 18:36:54 | 000,198,500 | -H-- | M] () -- C:\ProgramData\nvModes.dat
[2011.03.22 16:34:04 | 000,000,384 | -H-- | M] () -- C:\ProgramData\42983176
[2011.03.21 21:49:19 | 000,000,587 | -H-- | M] () -- C:\Users\Volker\Desktop\Windows Diagnostic.lnk
[2011.03.20 20:35:57 | 000,701,496 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.03.20 20:35:57 | 000,656,092 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.03.20 20:35:57 | 000,157,758 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.03.20 20:35:57 | 000,128,040 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.03.17 15:25:45 | 000,137,656 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011.02.27 18:30:14 | 000,005,213 | -H-- | M] () -- C:\Users\Volker\Documents\Wedekind - Jungen und Mädchen.pdf
 
========== Files Created - No Company Name ==========
 
[2011.03.23 16:58:48 | 000,000,680 | ---- | C] () -- C:\Users\Volker\AppData\Local\d3d9caps.dat
[2011.03.22 20:58:23 | 000,204,864 | ---- | C] () -- C:\Users\Volker\Desktop\DataRecovery_EN_2.4.6.zip
[2011.03.22 18:52:07 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.03.21 21:49:21 | 000,000,128 | -H-- | C] () -- C:\ProgramData\~42983176r
[2011.03.21 21:49:19 | 000,000,587 | -H-- | C] () -- C:\Users\Volker\Desktop\Windows Diagnostic.lnk
[2011.03.21 21:49:19 | 000,000,096 | -H-- | C] () -- C:\ProgramData\~42983176
[2011.03.21 21:49:02 | 000,000,384 | -H-- | C] () -- C:\ProgramData\42983176
[2011.02.27 18:30:12 | 000,005,213 | -H-- | C] () -- C:\Users\Volker\Documents\Wedekind - Jungen und Mädchen.pdf
[2011.02.27 17:30:48 | 000,007,549 | ---- | C] () -- C:\Windows\System32\dopdf7.ctm
[2011.02.23 22:49:29 | 000,201,184 | ---- | C] () -- C:\Windows\System32\winrm.vbs
[2011.02.23 22:49:29 | 000,004,675 | ---- | C] () -- C:\Windows\System32\wsmanconfig_schema.xml
[2011.02.23 22:49:29 | 000,002,426 | ---- | C] () -- C:\Windows\System32\WsmTxt.xsl
[2010.11.22 13:56:41 | 000,007,552 | ---- | C] () -- C:\Windows\System32\drivers\enodpl.sys
[2010.11.22 13:56:41 | 000,004,736 | ---- | C] () -- C:\Windows\System32\drivers\tandpl.sys
[2010.11.07 20:19:14 | 000,115,598 | ---- | C] () -- C:\Windows\GXTranscoder v2 Uninstaller.exe
[2010.03.07 17:28:34 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll
[2010.02.22 14:28:48 | 000,000,094 | -H-- | C] () -- C:\Users\Volker\AppData\Local\fusioncache.dat
[2009.12.06 12:48:13 | 000,176,844 | ---- | C] () -- C:\Windows\hphins33.dat
[2009.10.18 14:05:53 | 000,021,840 | ---- | C] () -- C:\Windows\System32\SIntfNT.dll
[2009.10.18 14:05:53 | 000,017,212 | ---- | C] () -- C:\Windows\System32\SIntf32.dll
[2009.10.18 14:05:53 | 000,012,067 | ---- | C] () -- C:\Windows\System32\SIntf16.dll
[2009.10.18 10:53:12 | 000,000,218 | ---- | C] () -- C:\Windows\SIERRA.INI
[2009.05.22 10:32:14 | 000,000,586 | ---- | C] () -- C:\Windows\hphmdl33.dat
[2009.04.24 15:26:08 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2008.12.27 15:58:54 | 000,010,752 | -H-- | C] () -- C:\Users\Volker\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.12.15 14:52:18 | 000,069,632 | R--- | C] () -- C:\Windows\System32\xmltok.dll
[2008.12.15 14:52:18 | 000,036,864 | R--- | C] () -- C:\Windows\System32\xmlparse.dll
[2008.11.14 20:50:22 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2008.11.03 19:02:28 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2008.11.03 19:02:28 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008.11.02 12:33:38 | 000,271,360 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2008.11.02 12:33:31 | 000,018,048 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2008.07.09 07:09:20 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2008.07.08 15:50:18 | 000,000,684 | ---- | C] () -- C:\Windows\HotFixList.ini
[2008.07.08 15:39:09 | 000,198,500 | -H-- | C] () -- C:\ProgramData\nvModes.dat
[2008.07.08 15:39:09 | 000,198,500 | -H-- | C] () -- C:\ProgramData\nvModes.001
[2008.07.08 15:32:17 | 000,307,200 | ---- | C] () -- C:\Windows\SetDisplayResolution.exe
[2008.07.08 15:31:32 | 000,000,135 | R--- | C] () -- C:\Windows\System32\lngEng.ini
[2008.07.08 15:31:32 | 000,000,117 | ---- | C] () -- C:\Windows\System32\lngKor.ini
[2008.07.08 15:18:03 | 000,040,960 | ---- | C] () -- C:\Windows\System32\IhDEV.exe
[2008.07.08 15:18:02 | 000,024,576 | ---- | C] () -- C:\Windows\System32\IhINF.exe
[2008.07.08 13:54:14 | 000,701,496 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008.07.08 13:54:14 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008.07.08 13:54:14 | 000,157,758 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008.07.08 13:54:14 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2008.07.08 13:45:50 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008.02.09 17:03:07 | 000,024,576 | ---- | C] () -- C:\Windows\System32\drivers\Marker.exe
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2007.02.26 08:49:12 | 006,139,774 | ---- | C] () -- C:\Windows\System32\imagine digital freedom.dat
[2007.02.15 08:51:02 | 000,274,432 | ---- | C] () -- C:\Windows\System32\NDADLL.dll
[2006.11.29 09:00:30 | 000,045,056 | ---- | C] () -- C:\Windows\System32\MAWebControl.exe
[2006.11.29 09:00:28 | 000,307,200 | ---- | C] () -- C:\Windows\System32\LDBGenWizView.dll
[2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:47:37 | 000,416,336 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:33:01 | 000,656,092 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,128,040 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:25:21 | 000,061,440 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.10.09 02:01:28 | 000,061,440 | ---- | C] () -- C:\Windows\System32\AVSAudioWideStereoDMO.dll
[2003.08.07 20:01:50 | 000,237,568 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2001.11.14 04:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
 
< End of report >
         
--- --- ---




und noch der OTL-"Extra"scan:

OTL Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 24.03.2011 15:29:17 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Volker\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 53,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 76,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144,09 Gb Total Space | 4,14 Gb Free Space | 2,87% Space Free | Partition Type: NTFS
Drive D: | 144,00 Gb Total Space | 104,19 Gb Free Space | 72,35% Space Free | Partition Type: NTFS
 
Computer Name: VOLKER-PC | User Name: Volker | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0267F2ED-F55F-4222-A168-C3A66000B727}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{03B73A41-25B4-4AF8-81AC-9F482E8F570F}" = rport=2869 | protocol=6 | dir=out | app=system | 
"{17C9712C-B0FF-4DE2-8825-DACFF07A2A6D}" = lport=445 | protocol=6 | dir=in | app=system | 
"{182C21C7-1B21-4F5D-A637-A457FCECD69D}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{1ACC8B81-4A32-4952-B23E-3B83139AA64F}" = lport=138 | protocol=17 | dir=in | app=system | 
"{1E12C77C-05FD-449A-B56F-0A7FC6FEA8D9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{20000877-69F7-4346-B4CE-B9E1BB47C55E}" = rport=138 | protocol=17 | dir=out | app=system | 
"{2677158A-5F0E-4049-969B-0CF2018C79DB}" = rport=445 | protocol=6 | dir=out | app=system | 
"{29CB5780-5F94-4108-99E4-BE6F3D1CD409}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{2A47494D-9827-4A09-AEE8-9168A3EC50A7}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{2DA7B5CC-6D87-4517-AFFE-E4B5004E2B5D}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | 
"{3FD0B431-FA3C-48C4-97FD-5484C4111559}" = rport=137 | protocol=17 | dir=out | app=system | 
"{46DF001A-8BE4-463B-AF6B-BF164F24AE1E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{499568A5-6A44-43D1-AE00-2238D62EECC1}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{4AE5F0AC-6218-4050-8764-AF2FD8AC3332}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{5A5CACB9-A9DC-4CA0-8C73-6ADEB81F3B58}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{6C935AC1-6182-4ACC-88AD-0FC28844D6B0}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{7687E6B6-E017-46FA-96A3-1ECF2812665A}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | 
"{8159A1F7-6C3E-4A98-9D24-02FAB54323C4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{948D0367-5367-484B-88BE-1D5E794F11FE}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{AE900CAA-AE97-4901-99B5-B257444AAB8C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{AF7AD8F8-67F3-4F7A-9860-BD3B5CAB48F8}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{B209ACD2-D6B6-40F5-8360-B09E3F90A5CC}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{B4B35BCD-4451-4BE2-8083-D775F40B5F0A}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{B879C000-54AF-4B31-8DD2-F5C5E78D58FE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{B90197B0-98B8-4132-BB41-BF493DD0CD59}" = lport=139 | protocol=6 | dir=in | app=system | 
"{C644570E-17B8-4601-A65F-E80EE9425ABE}" = lport=137 | protocol=17 | dir=in | app=system | 
"{C7AEDA38-0D3C-491D-8638-F59B96CCE3BC}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{C99B974B-B26C-4D77-B2EA-94D15AFC333F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{D1BD2BCD-3029-47C5-BC79-8A13820B7CBA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{E0F18376-F1E7-4603-81C9-6688EDF26ACA}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | 
"{E65B31E3-71BB-4136-A2A1-05418D2DAD4C}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{E912E8C0-725B-4AAE-89C4-D664C62E8944}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{FA5FB8EC-E43D-4AB6-A6C7-152E25CD3DA6}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{FC0AEC55-BED7-4381-B956-96A224A80686}" = rport=139 | protocol=6 | dir=out | app=system | 
"{FD1DEDDA-7061-40D0-8D78-21E1414C4D24}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{005BB5EE-A7FD-455C-93CA-4A4B3FE91F63}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe | 
"{01A11BC5-936F-4A94-8562-DBBA1CB53A3E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe | 
"{043D666F-5981-476B-B9F8-0AFBC107ABAC}" = protocol=17 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe | 
"{04EFE0C2-D3A6-42A3-B6B2-85C234E96591}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{050F0DE3-1182-4B4F-960C-AACF6650A0B3}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx10.exe | 
"{068FFCF1-B68C-4591-AF45-CC12FEC20A4B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe | 
"{10FC9E7C-1692-41A6-9885-B39C299CE912}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe | 
"{12FFE344-EB6E-4D67-B2D7-303550DD7D20}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\trackmania nations forever\tmforeverlauncher.exe | 
"{17AF0867-48C6-427E-BDA7-9D31F1141A23}" = protocol=6 | dir=in | app=d:\spiele\turbine download manager\turbinenetworkservice.exe | 
"{1F04F4AA-56FC-4955-AA79-35BF422EFD05}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{23B245F5-6C15-49FB-B05E-AC7CEA833046}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{244006FE-AE75-4410-B3B0-2058DE2F1972}" = protocol=17 | dir=in | app=c:\program files\unreal tournament 3\binaries\ut3.exe | 
"{25EBFEDD-2F22-4A4E-BCC7-99DC9A30C4D7}" = protocol=6 | dir=in | app=d:\spiele\game.dat | 
"{27B03D3D-22B0-4BE7-9644-639913DD3CA7}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\xvofferx\sourcesdk\bin\sdklauncher.exe | 
"{28B2793F-F1CE-49BB-A61A-784F75FA96F5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{291D306C-48AA-4223-B4A4-5D53D8E45FDD}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{29CF5B6F-4CE6-4E72-8B3C-3A579FBF3B89}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{2EF13111-67CF-41C9-AE5E-88E758CDBBCC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{317BA270-0DC9-4A1F-9492-ED0B2B1CCAAE}" = protocol=6 | dir=in | app=c:\program files\electronic arts\die schlacht um mittelerde ii\game.dat | 
"{31A4C225-DBF4-4735-9957-1CCB6C6AD544}" = protocol=17 | dir=in | app=d:\spiele\turbine download manager\turbinemessageservice.exe | 
"{31D2E30E-4393-41CB-A2BF-36FB0B76DB6E}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe | 
"{34BF32A3-00D9-4617-AD3F-335224F61389}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\xvofferx\sourcesdk\bin\sdklauncher.exe | 
"{35A3779F-1D36-4A27-B8DA-0771AF95C0DF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{44B78938-6BD2-47D0-9A76-3787164BBD15}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | 
"{4682EE64-28A1-4948-B789-C0B2A1776ABC}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe | 
"{4968FD53-7DEA-4B47-B5E8-1C3AB04DC28E}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe | 
"{4ACBE741-F8EA-4BF0-B4BA-907029212B80}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{4D6C392C-A335-4C72-AD76-CF3A02C1CBAF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{4ECD6139-75EB-4DCC-BAC8-190D176B13D4}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{4F2170C1-ADB8-43FE-B583-39D8643ACF86}" = protocol=17 | dir=in | app=c:\program files\electronic arts\die schlacht um mittelerde ii\game.dat | 
"{55BD5398-7EE3-4802-AA3C-FF9B47F1C8CD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe | 
"{5AE82062-F363-4968-8EB2-1773E90F2D10}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{5D17D80C-BDA6-4060-A9DA-E7300D088DFC}" = protocol=17 | dir=in | app=d:\spiele\turbine download manager\turbinenetworkservice.exe | 
"{67776A70-289C-46F8-8937-28F39FF9F11C}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{6779FCAE-5815-46CF-89C3-D6A107FAA6AC}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{68B5EFF0-B2E5-42AD-99CD-AACDB7AD1584}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{6C708175-E552-40D1-A8A6-13CFD9899760}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{6FEC7324-116C-4FED-A19F-10AAAE7A42A1}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | 
"{747C7C60-3385-444B-A61F-B2DC0A64CA15}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe | 
"{74B11514-A4A6-4787-8C73-87D3EEB83B23}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{7A430E69-AF3F-47B1-B508-D9E1B7BD397D}" = protocol=17 | dir=in | app=c:\users\volker\appdata\roaming\dropbox\bin\dropbox.exe | 
"{7AD050A3-0258-43D0-9B6B-087FAD75663B}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe | 
"{82F3AFDC-98E5-4134-91FD-293ABAD13028}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe | 
"{834F2472-3D8F-4628-9A41-100A7B403E76}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe | 
"{8BF64F90-1B25-4311-98ED-FEF0757282BE}" = protocol=6 | dir=in | app=d:\spiele\turbine download manager\turbinemessageservice.exe | 
"{8D42CA55-1180-472D-B9CF-C83FD2C87A4D}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe | 
"{8D72A2AF-6F15-48E7-B545-D2DDD2DF6E8B}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{8DD04263-45E2-41A8-9623-C9321C556E59}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{8FB359F1-7E7A-4731-B47C-EB6DA8019717}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{9080FC1B-F9F6-43C4-B892-AA36809B2D59}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{90BFE075-12F3-4A0E-9252-87F4A954D382}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{911B9C3B-5B33-4EE8-9080-E681880109EE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{9149E7E3-77B6-41F6-9B77-657511ECA177}" = protocol=6 | dir=in | app=c:\sierra\empire earth\launcher.exe | 
"{956E1B4E-AA14-4F4B-8F8B-49EE3545D954}" = protocol=17 | dir=in | app=d:\spiele\turbine download manager\turbinenetworkservice.exe | 
"{98A218E2-2EFA-4708-A83B-CD8DEC773758}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{A30BB79A-404A-419E-B690-68F07F905ED7}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | 
"{A44581E9-D8AF-4E35-8A6D-E407FF9B37C6}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe | 
"{A659754E-C3BD-47C3-B055-96D6C202A59C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\trackmania nations forever\tmforeverlauncher.exe | 
"{A84369CD-0104-4B15-8913-CA12E78DB191}" = protocol=6 | dir=in | app=c:\program files\unreal tournament 3\binaries\ut3.exe | 
"{AC0EB358-85BB-4B8A-8309-506EB7D14E86}" = protocol=6 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe | 
"{AEC25E14-65BA-46F9-85AE-AA289C794FDD}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe | 
"{B7FAD1A2-8404-4D59-8DF3-1229EDBD343D}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx10.exe | 
"{B95ECCFA-2AA3-4DC1-97A7-2293C5133B2F}" = protocol=6 | dir=in | app=c:\users\volker\appdata\roaming\dropbox\bin\dropbox.exe | 
"{BCAEFB36-3651-49CF-84C7-69E6D6F17BC4}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | 
"{BE642298-A92E-4BCF-B4A9-A6AE42F47F40}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{C0EFC0EF-34F2-4CB4-B3E0-02C29AD98489}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe | 
"{C1CFFAB8-557C-4764-B700-36DD09E8967C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe | 
"{C391A9E0-CD46-4995-A139-E3AFE4729C3C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe | 
"{C66F4A61-B793-4E5F-B23E-4C19537BD4E0}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe | 
"{C81F6994-D1FC-4B20-B7EC-10620BA1DE98}" = protocol=17 | dir=in | app=d:\spiele\game.dat | 
"{C8D5BCCE-8812-4C57-9301-042EA6D48875}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{CBC9BD84-0C84-4A04-8644-C2AAF6246113}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe | 
"{CCE47FE5-D80C-43A2-82BE-C99E4CBA864F}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe | 
"{D4630B38-C219-4317-9F26-D4B87669A3B1}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{D5A3EA54-194F-456F-A10E-90088E860DF9}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{D8C3F067-B27D-45E2-A984-533AD8CC39DB}" = protocol=6 | dir=out | app=system | 
"{DB73A8FD-6C43-43A8-B58D-5CFF82840D62}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{DCCE7AF5-CF65-44F9-A732-55A24ADAD347}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe | 
"{E269C668-B0B9-4675-A228-5F2858C61695}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe | 
"{E7198A34-60FE-46AA-B7DF-1683767B32B9}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | 
"{E75CBF35-506F-418D-825D-14AC26E40972}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe | 
"{E80F188E-DA5E-4C72-AFF3-7EA21EDE168A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe | 
"{EB957EEF-94A4-4020-BB7B-ACC9DE1BB266}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{F0D09E8D-961E-47DD-B12C-45F99C1B0091}" = protocol=6 | dir=in | app=d:\spiele\turbine download manager\turbinenetworkservice.exe | 
"{F15E31F3-8B0E-4127-BF12-3897E6358C30}" = protocol=17 | dir=in | app=c:\sierra\empire earth\launcher.exe | 
"{F1ED2C0F-5CE5-4FB3-B056-6D1F3F408B86}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe | 
"{FAFE2374-C706-47F8-8B66-7AFC7356CA01}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{FD1BB9F0-1DB4-4496-B70D-774E8E7C284F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe | 
"{FFE802C9-B147-4651-9BE1-5B48A6CDC045}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | 
"TCP Query User{03FA3D87-2896-4213-A6FA-7E0978BA6C20}D:\spiele\starcraft ii\starcraft ii.exe" = protocol=6 | dir=in | app=d:\spiele\starcraft ii\starcraft ii.exe | 
"TCP Query User{09DE31C5-F330-4E54-B94A-78F9E7FCFE10}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe | 
"TCP Query User{19508545-4C62-4BBB-BF56-9B8127B88520}C:\users\volker\appdata\local\microsoft\windows\temporary internet files\content.ie5\q9ipxton\download[1].exe" = protocol=6 | dir=in | app=c:\users\volker\appdata\local\microsoft\windows\temporary internet files\content.ie5\q9ipxton\download[1].exe | 
"TCP Query User{1D495106-B35F-4437-BB2A-FB890B08E87C}C:\program files\steam\steamapps\xvofferx\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\xvofferx\team fortress 2\hl2.exe | 
"TCP Query User{264635D8-EF67-4459-A0FD-459ADE1204E8}C:\world of padman\wop.exe" = protocol=6 | dir=in | app=c:\world of padman\wop.exe | 
"TCP Query User{349A854A-8E3E-4507-AB18-010222F67C6C}C:\world of padman\wop.exe" = protocol=6 | dir=in | app=c:\world of padman\wop.exe | 
"TCP Query User{3F5C3B5A-DD1C-43B2-8971-9026CB1E9013}C:\program files\microsoft games\age of empires\empires.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires\empires.exe | 
"TCP Query User{4C153B2B-D0B3-42D7-91EC-A9E43E99A2BF}D:\spiele\xiii\system\xiii.exe" = protocol=6 | dir=in | app=d:\spiele\xiii\system\xiii.exe | 
"TCP Query User{54295BCF-7525-454A-9466-915C7DCD7940}D:\spiele\project nomads\run\bin\win32\nomads.exe" = protocol=6 | dir=in | app=d:\spiele\project nomads\run\bin\win32\nomads.exe | 
"TCP Query User{637517CC-DCCC-48F8-8519-0EDEDB65E761}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | 
"TCP Query User{666F6F05-E297-41AF-B5DF-02560AED7E68}C:\program files\steam\steamapps\xvofferx\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\xvofferx\team fortress 2\hl2.exe | 
"TCP Query User{6D49F42B-CB54-4B9A-90D3-42B524509CED}C:\users\volker\appdata\local\microsoft\windows\temporary internet files\content.ie5\3ksfy8lr\download[1].exe" = protocol=6 | dir=in | app=c:\users\volker\appdata\local\microsoft\windows\temporary internet files\content.ie5\3ksfy8lr\download[1].exe | 
"TCP Query User{78F8790C-822A-4637-9439-8C1296162BCB}D:\spiele\urbanterror\iourbanterror.exe" = protocol=6 | dir=in | app=d:\spiele\urbanterror\iourbanterror.exe | 
"TCP Query User{808EDB7D-1877-4D69-9C31-AAD62B3F7C93}C:\program files\lucasarts\star wars battlefront ii\gamedata\battlefrontii.exe" = protocol=6 | dir=in | app=c:\program files\lucasarts\star wars battlefront ii\gamedata\battlefrontii.exe | 
"TCP Query User{90D3767B-0E18-426C-99D3-D573B0FAFA00}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe | 
"TCP Query User{97469048-8702-4913-A33A-5D67C1CCE71E}C:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe | 
"TCP Query User{9AEFAA7C-1D03-4CC3-A2A1-B5331CFA3DC2}D:\spiele\warsow 0.5\warsow_x86.exe" = protocol=6 | dir=in | app=d:\spiele\warsow 0.5\warsow_x86.exe | 
"TCP Query User{A64209FE-E9BF-4CE9-A423-D33860113E4B}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe | 
"TCP Query User{B2E01D1E-6B9B-4E2C-83B5-69305DAB7F53}C:\program files\padworld entertainment\world of padman 1.5\wop.exe" = protocol=6 | dir=in | app=c:\program files\padworld entertainment\world of padman 1.5\wop.exe | 
"TCP Query User{B4E92274-5A67-4EC4-A373-D3B72071D90E}D:\spiele\urbanterror\iourbanterror.exe" = protocol=6 | dir=in | app=d:\spiele\urbanterror\iourbanterror.exe | 
"TCP Query User{B95623C8-F7FC-41D7-A912-BBEDC71FE53C}D:\spiele\metin2\metin2.bin" = protocol=6 | dir=in | app=d:\spiele\metin2\metin2.bin | 
"TCP Query User{BB94A176-F48C-4581-810F-08D889F9CC71}C:\users\volker\desktop\mod. vers\stronghold crusader.exe" = protocol=6 | dir=in | app=c:\users\volker\desktop\mod. vers\stronghold crusader.exe | 
"TCP Query User{BE6F3F95-D781-4C5A-8AC4-6495273E6061}D:\spiele\xiii\system\xiii.exe" = protocol=6 | dir=in | app=d:\spiele\xiii\system\xiii.exe | 
"TCP Query User{BFA6AA61-1FED-4604-9125-C60893DDB430}C:\program files\icq7.2\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"TCP Query User{C516006E-9850-4925-A64B-F8E4607D8F5A}D:\spiele\metin2\metin2client.bin" = protocol=6 | dir=in | app=d:\spiele\metin2\metin2client.bin | 
"TCP Query User{C9A14C0A-AA60-4469-A63A-CDD7E3C9ABA4}C:\sierra\empire earth\empire earth.exe" = protocol=6 | dir=in | app=c:\sierra\empire earth\empire earth.exe | 
"TCP Query User{D1334010-FE21-45A0-9917-0D830A2E0CF6}D:\spiele\starcraft ii\versions\base17326\sc2.exe" = protocol=6 | dir=in | app=d:\spiele\starcraft ii\versions\base17326\sc2.exe | 
"TCP Query User{DF32B924-ACCF-430B-A6AB-7EE5844D0243}C:\sierra\empire earth\empire earth.exe" = protocol=6 | dir=in | app=c:\sierra\empire earth\empire earth.exe | 
"TCP Query User{E28E1D8C-FA53-4BCD-A9D2-8C09424DA7CC}D:\spiele\ddo\dndclient.exe" = protocol=6 | dir=in | app=d:\spiele\ddo\dndclient.exe | 
"TCP Query User{E3E8BC19-4742-4E85-8648-B4B09A5C0815}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe | 
"TCP Query User{F30DD47F-B20E-4BE1-8953-10E8C5A94632}C:\users\volker\appdata\local\microsoft\windows\temporary internet files\content.ie5\c37e1kzn\sc2-wingsofliberty-enus-demo-installer-downloader[1].exe" = protocol=6 | dir=in | app=c:\users\volker\appdata\local\microsoft\windows\temporary internet files\content.ie5\c37e1kzn\sc2-wingsofliberty-enus-demo-installer-downloader[1].exe | 
"TCP Query User{F6B734C7-C911-4664-8FF9-F99A88351074}D:\spiele\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=d:\spiele\starcraft ii\support\blizzarddownloader.exe | 
"TCP Query User{F9376274-578B-44A4-84F2-3DB9932463C4}C:\program files\metin2_germany\metin2.bin" = protocol=6 | dir=in | app=c:\program files\metin2_germany\metin2.bin | 
"TCP Query User{FC43D0FD-3C82-423D-9669-74764A608D48}C:\program files\metin2_germany\metin2.bin" = protocol=6 | dir=in | app=c:\program files\metin2_germany\metin2.bin | 
"TCP Query User{FCDFB046-E3DF-44C4-880F-5B254B5367F4}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | 
"UDP Query User{08F45A15-EC68-4488-AF67-EEE74534A78E}C:\users\volker\appdata\local\microsoft\windows\temporary internet files\content.ie5\3ksfy8lr\download[1].exe" = protocol=17 | dir=in | app=c:\users\volker\appdata\local\microsoft\windows\temporary internet files\content.ie5\3ksfy8lr\download[1].exe | 
"UDP Query User{21A628B6-A5B6-48FF-84EB-2C31F61854B7}D:\spiele\ddo\dndclient.exe" = protocol=17 | dir=in | app=d:\spiele\ddo\dndclient.exe | 
"UDP Query User{2280E565-E24A-49D5-A8F5-E3A4E548B8EC}C:\program files\metin2_germany\metin2.bin" = protocol=17 | dir=in | app=c:\program files\metin2_germany\metin2.bin | 
"UDP Query User{2FFDF01D-3F44-455E-B883-8A39478CC746}D:\spiele\xiii\system\xiii.exe" = protocol=17 | dir=in | app=d:\spiele\xiii\system\xiii.exe | 
"UDP Query User{3397CE13-71FC-4EB3-8B2E-2E8F31D404A1}D:\spiele\starcraft ii\starcraft ii.exe" = protocol=17 | dir=in | app=d:\spiele\starcraft ii\starcraft ii.exe | 
"UDP Query User{3ADA5E22-FD4F-4434-BA6A-1C597C630847}C:\users\volker\appdata\local\microsoft\windows\temporary internet files\content.ie5\q9ipxton\download[1].exe" = protocol=17 | dir=in | app=c:\users\volker\appdata\local\microsoft\windows\temporary internet files\content.ie5\q9ipxton\download[1].exe | 
"UDP Query User{3BA22DEF-91B5-43FE-8187-0312FDD4ED71}C:\program files\icq7.2\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"UDP Query User{4C8F074F-749F-4CE9-9C7E-6197795E2E81}C:\sierra\empire earth\empire earth.exe" = protocol=17 | dir=in | app=c:\sierra\empire earth\empire earth.exe | 
"UDP Query User{52523B16-6B07-4A56-A14D-E91FDDCF9C82}C:\program files\lucasarts\star wars battlefront ii\gamedata\battlefrontii.exe" = protocol=17 | dir=in | app=c:\program files\lucasarts\star wars battlefront ii\gamedata\battlefrontii.exe | 
"UDP Query User{579D8D4F-5042-4DE1-88A2-D6E52069A73E}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe | 
"UDP Query User{6147CEAF-2773-41C2-ADC7-6549475DAC9A}C:\program files\steam\steamapps\xvofferx\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\xvofferx\team fortress 2\hl2.exe | 
"UDP Query User{669372A8-FA33-4828-B588-D8A1AF2DBE53}C:\users\volker\appdata\local\microsoft\windows\temporary internet files\content.ie5\c37e1kzn\sc2-wingsofliberty-enus-demo-installer-downloader[1].exe" = protocol=17 | dir=in | app=c:\users\volker\appdata\local\microsoft\windows\temporary internet files\content.ie5\c37e1kzn\sc2-wingsofliberty-enus-demo-installer-downloader[1].exe | 
"UDP Query User{6753A0F3-9079-4CE7-A497-CF984C8C4862}C:\world of padman\wop.exe" = protocol=17 | dir=in | app=c:\world of padman\wop.exe | 
"UDP Query User{67F6DB2C-A68B-4EB2-A3CD-8B2E8D5E822A}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe | 
"UDP Query User{6EDEB0A3-6309-4E34-97DB-FE340B8A11DF}D:\spiele\urbanterror\iourbanterror.exe" = protocol=17 | dir=in | app=d:\spiele\urbanterror\iourbanterror.exe | 
"UDP Query User{71FC3027-2AA8-4A50-85C2-8B7DF0BDCD6B}C:\program files\microsoft games\age of empires\empires.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires\empires.exe | 
"UDP Query User{75F6A091-2B01-4FAC-B58E-AF604DB87B39}D:\spiele\metin2\metin2.bin" = protocol=17 | dir=in | app=d:\spiele\metin2\metin2.bin | 
"UDP Query User{7755CF80-EB0F-407B-9B84-A73E9A6EC5A8}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe | 
"UDP Query User{8C47A3A0-8F6E-48A3-A0A8-ACF0F0134E4C}C:\program files\metin2_germany\metin2.bin" = protocol=17 | dir=in | app=c:\program files\metin2_germany\metin2.bin | 
"UDP Query User{94826A63-1CF3-4794-80B8-E8C470B09154}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe | 
"UDP Query User{961720B7-FC0C-4439-BF4D-76E0E6399378}D:\spiele\xiii\system\xiii.exe" = protocol=17 | dir=in | app=d:\spiele\xiii\system\xiii.exe | 
"UDP Query User{9D4C57F6-D525-4935-B2F4-4A72F562514A}C:\sierra\empire earth\empire earth.exe" = protocol=17 | dir=in | app=c:\sierra\empire earth\empire earth.exe | 
"UDP Query User{AF037537-EDD2-490D-978B-D1EF5EEB904B}C:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe | 
"UDP Query User{B91A6E74-6EAD-4A28-8DD8-F9070E72BF74}D:\spiele\project nomads\run\bin\win32\nomads.exe" = protocol=17 | dir=in | app=d:\spiele\project nomads\run\bin\win32\nomads.exe | 
"UDP Query User{BE3AC010-4F4B-4290-92DA-94373991AEE4}D:\spiele\urbanterror\iourbanterror.exe" = protocol=17 | dir=in | app=d:\spiele\urbanterror\iourbanterror.exe | 
"UDP Query User{C8CB0EF0-BC7B-4722-B465-4C67D597185F}D:\spiele\warsow 0.5\warsow_x86.exe" = protocol=17 | dir=in | app=d:\spiele\warsow 0.5\warsow_x86.exe | 
"UDP Query User{CDE0BCB6-1454-4051-B7E4-B3994BA91CF9}C:\users\volker\desktop\mod. vers\stronghold crusader.exe" = protocol=17 | dir=in | app=c:\users\volker\desktop\mod. vers\stronghold crusader.exe | 
"UDP Query User{D24C3B81-175E-4D2D-B633-053830F0CB4B}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe | 
"UDP Query User{D4FFC692-69EB-42A6-96C7-AABDF6800AC4}D:\spiele\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=d:\spiele\starcraft ii\support\blizzarddownloader.exe | 
"UDP Query User{D55CF884-A369-4EFE-B977-09E812A261A8}D:\spiele\starcraft ii\versions\base17326\sc2.exe" = protocol=17 | dir=in | app=d:\spiele\starcraft ii\versions\base17326\sc2.exe | 
"UDP Query User{DDBDEF57-2F4E-4BC3-9693-0A13EC922834}C:\program files\steam\steamapps\xvofferx\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\xvofferx\team fortress 2\hl2.exe | 
"UDP Query User{E7EF1EA9-0C9B-4D8D-AED1-C5C19B64B5AE}C:\world of padman\wop.exe" = protocol=17 | dir=in | app=c:\world of padman\wop.exe | 
"UDP Query User{F1036172-B550-40F3-A18C-458F2D1CBEF3}D:\spiele\metin2\metin2client.bin" = protocol=17 | dir=in | app=d:\spiele\metin2\metin2client.bin | 
"UDP Query User{F58B75A8-ECB7-4E40-9EE3-07701A8BB298}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe | 
"UDP Query User{FEE68FB5-CEA2-4145-89D1-96ECF029EF6A}C:\program files\padworld entertainment\world of padman 1.5\wop.exe" = protocol=17 | dir=in | app=c:\program files\padworld entertainment\world of padman 1.5\wop.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1
"{00AF10C1-44BD-4862-9D7F-24E6BA3E87FD}" = imagine digital freedom - Samsung
"{028ED9C4-25EE-4DEE-9CF4-91034BC89B18}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.6300
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04983D37-2202-4295-94A2-8B547C66133F}" = Atheros WLAN Client
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution III
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{2447500B-22D7-47BD-9B13-1A927F43A267}" = Empire Earth
"{24508D50-EB8F-4FE6-B69D-B4935D8745EF}_is1" = Warsow 0.5
"{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}" = Die Schlacht um Mittelerde™ II
"{2BD2FA21-B51D-4F01-94A7-AC16737B2163}" = Adobe Flash Player 10 ActiveX
"{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox
"{2CD0168D-FBBC-4667-8810-105CB6EC6348}" = HP Deskjet D1600 Printer Driver Software 13.0 Rel .6
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Samsung Magic Doctor
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{36BEAD11-8577-49AD-9250-E06A50AE87B0}" = Microsoft SOAP Toolkit 2.0 SP2
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D374523-CFDE-461A-827E-2A102E2AB365}" = Star Wars Battlefront II
"{3E67F68D-3797-4B6A-B02C-27BC98DFEBDA}" = Fast Track Pro
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{42BC0474-6E50-464A-8183-5E3D32E41B1B}" = XIII
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{45235788-142C-44BE-8A4D-DDE9A84492E5}" = AGEIA PhysX v7.09.13
"{452473D3-1D26-4E61-8060-3B216620D60C}_is1" = Fahren Lernen Offline 1.2
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4cb9f93c-9edc-4be9-ae61-af128ddbecfa}" = Business Contact Manager für Outlook 2007 SP2
"{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{5727583F-3530-45FD-B09E-7E1CB6C135AD}" = DJ_SF_06_D1600_SW_Min
"{628C3D50-F524-4C49-A958-672CE7953756}" = Der Herr der Ringe® - Die Eroberung™
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{66D6F3BD-CA23-41A4-9FA3-96B26B32528C}" = Command & Conquer The First Decade
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Easy Battery Manager
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{71A51B09-E7D3-11DB-A386-005056C00008}" = Vimicro UVC Camera
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7FB12670-0F93-4E1E-B2F5-4F339199A03A}" = Microsoft SQL Server Native Client
"{804F1285-8CBF-408D-8CDC-D4D40003B2E4}" = PlayCamera
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{849A32C3-E75A-4791-9B11-E568BA3525A4}" = Microsoft SQL Server VSS Writer
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_PROHYBRIDR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_PROHYBRIDR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_PROHYBRIDR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90A40407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{99E862CC-6F69-4D39-99AA-DBF71BF3B585}" = OpenOffice.org 3.1
"{9FE15B75-8AD9-4A6F-A57A-7E7C03C4CBEB}" = StarOffice 8
"{A6C2D216-9DAE-43F9-8EFF-F0445E973F52}_is1" = GW-Value
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1031-7B44-A81000000003}" = Adobe Reader 8.1.0 - Deutsch
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B1CBE507-887F-4CAE-A84C-9E0F6C81B870}" = StarOffice 8 Product Update 12
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BA5F3E0E-8F3E-47BD-88E4-AD3EB5225F51}" = Intel(R) PROSet/Wireless WiFi-Software
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7CB214-DB11-4B5D-A6AF-3B4ED47C68B7}" = Microsoft Game Studios Common Redistributables Pack 1
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{EAE8CF06-28CA-4213-839C-A32817A47E00}" = D1600
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}" = iTunes
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"7-Zip" = 7-Zip 4.57
"AC3Filter" = AC3Filter (remove only)
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"Audacity_is1" = Audacity 1.2.6
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BestPractice" = BestPractice (remove only)
"Business Contact Manager" = Business Contact Manager für Outlook 2007 SP2
"doPDF 7 printer_is1" = doPDF 7.2 printer
"DVDVideoSoft Toolbar" = DVDVideoSoft Toolbar
"DynaGeo_is1" = DynaGeo 3.0f
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.31
"GameSpy Arcade" = GameSpy Arcade
"Gothic II" = Gothic II
"Guild Wars" = GUILD WARS
"GuildWars Visions_is1" = GuildWars Visions v1.08
"Guitar Pro 5_is1" = Guitar Pro 5.2
"GXTranscoder v2" = GXTranscoder v2
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"ICQToolbar" = ICQ Toolbar
"iDump" = iDump (Backing up your iPod)
"InstallShield_{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"InstallShield_{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Metin2_is1" = Metin2
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"Mumble" = Mumble and Murmur
"MuPAD Pro 4.0_is1" = MuPAD Pro 4.0.6
"Niki" = Niki
"NVIDIA Drivers" = NVIDIA Drivers
"PROHYBRIDR" = 2007 Microsoft Office system
"ProInst" = Intel PROSet Wireless
"Project Nomads" = Project Nomads
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"Shop for HP Supplies" = Shop for HP Supplies
"StarCraft II" = StarCraft II
"Steam App 11020" = TrackMania Nations Forever
"Steam App 211" = Source SDK
"Steam App 220" = Half-Life 2
"Steam App 310" = Team Fortress 2 Dedicated Server
"Steam App 35420" = Killing Floor Mod: Defence Alliance 2
"Steam App 380" = Half-Life 2: Episode One
"Steam App 400" = Portal
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 440" = Team Fortress 2
"Steam App 630" = Alien Swarm
"SyncroSoft Emu" = SyncroSoft Emu (Remove only)
"Syncrosoft's License Control" = Syncrosofts Lizenz Kontrolle
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"Uninstall_is1" = Uninstall 1.0.0.1
"Urban Terror_is1" = Urban Terror 4.1
"VCam 3.1_is1" = VCam 3.1.1
"World of Padman" = World of Padman
"World of Padman 1.5" = World of Padman 1.5
"Xfire" = Xfire (remove only)
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 17.12.2010 01:50:26 | Computer Name = Volker-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 18.12.2010 07:33:04 | Computer Name = Volker-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 18.12.2010 07:33:15 | Computer Name = Volker-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 18.12.2010 07:33:15 | Computer Name = Volker-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 18.12.2010 07:34:09 | Computer Name = Volker-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 18.12.2010 07:34:14 | Computer Name = Volker-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung cledx.exe, Version 0.3.1412.777, Zeitstempel
0x427ec9c6, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000,
Ausnahmecode 0xc0000005, Fehleroffset 0x004605d2, Prozess-ID 0x524, Anwendungsstartzeit
01cb9ea76b72d760.
 
Error - 18.12.2010 07:38:14 | Computer Name = Volker-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 18.12.2010 07:38:16 | Computer Name = Volker-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 18.12.2010 07:38:16 | Computer Name = Volker-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 18.12.2010 07:38:17 | Computer Name = Volker-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
[ System Events ]
Error - 23.03.2011 11:56:04 | Computer Name = Volker-PC | Source = HTTP | ID = 15016
Description = 
 
Error - 23.03.2011 11:56:39 | Computer Name = Volker-PC | Source = ipnathlp | ID = 34001
Description = ICS_IPV6 konnte den IPv6-Stapel nicht konfigurieren.
 
Error - 23.03.2011 11:56:39 | Computer Name = Volker-PC | Source = ipnathlp | ID = 30013
Description = Die DHCP-Zuweisung wurde für IP-Adresse 192.168.2.101 deaktiviert,
da die IP-Adresse außerhalb des Bereichs 192.168.0.0/255.255.255.0 liegt, von der
die Adressen DHCP-Clients zu gewiesen werden. Ändern Sie den Bereich, sodass die
IP-Adresse mit einbezogen wird, oder ändern Sie die IP-Adresse, sodass sie innerhalb
dieses Bereichs liegt, um die DHCP-Zuweisung zu aktivieren.
 
Error - 23.03.2011 11:57:50 | Computer Name = Volker-PC | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 23.03.2011 15:07:47 | Computer Name = Volker-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description = 
 
Error - 24.03.2011 10:22:37 | Computer Name = Volker-PC | Source = HTTP | ID = 15016
Description = 
 
Error - 24.03.2011 10:22:55 | Computer Name = Volker-PC | Source = ipnathlp | ID = 34001
Description = ICS_IPV6 konnte den IPv6-Stapel nicht konfigurieren.
 
Error - 24.03.2011 10:22:55 | Computer Name = Volker-PC | Source = ipnathlp | ID = 30013
Description = Die DHCP-Zuweisung wurde für IP-Adresse 192.168.2.101 deaktiviert,
da die IP-Adresse außerhalb des Bereichs 192.168.0.0/255.255.255.0 liegt, von der
die Adressen DHCP-Clients zu gewiesen werden. Ändern Sie den Bereich, sodass die
IP-Adresse mit einbezogen wird, oder ändern Sie die IP-Adresse, sodass sie innerhalb
dieses Bereichs liegt, um die DHCP-Zuweisung zu aktivieren.
 
Error - 24.03.2011 10:24:16 | Computer Name = Volker-PC | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 24.03.2011 10:26:37 | Computer Name = Volker-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description = 
 
 
< End of report >
         
--- --- ---



Ich hoffe mir kann jemand helfen,

mfg.

Alt 24.03.2011, 19:01   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:
ATTFilter
:OTL
[2011.03.21 21:49:21 | 000,000,128 | -H-- | C] () -- C:\ProgramData\~42983176r
[2011.03.21 21:49:19 | 000,000,587 | -H-- | C] () -- C:\Users\Volker\Desktop\Windows Diagnostic.lnk
[2011.03.21 21:49:19 | 000,000,096 | -H-- | C] () -- C:\ProgramData\~42983176
[2011.03.21 21:49:02 | 000,000,384 | -H-- | C] () -- C:\ProgramData\42983176
[2011.03.21 21:49:11 | 000,000,000 | -H-D | C] -- C:\Users\Volker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Diagnostic
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{d48be40b-ad63-11dd-9b40-001377a9fd0e}\Shell - "" = AutoRun
O33 - MountPoints2\{d48be40b-ad63-11dd-9b40-001377a9fd0e}\Shell\AutoRun\command - "" = G:\LaunchU3.exe
O4 - HKLM..\Run: [H2O] C:\Programme\Syncrosoft\POS\H2O\cledx.exe (Team H2O)
:Commands
[purity]
[resethosts]
[emptytemp]
         
Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.
__________________

__________________

Alt 24.03.2011, 21:54   #3
0815User
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



Erledigt:

All processes killed
========== OTL ==========
C:\ProgramData\~42983176r moved successfully.
C:\Users\Volker\Desktop\Windows Diagnostic.lnk moved successfully.
C:\ProgramData\~42983176 moved successfully.
C:\ProgramData\42983176 moved successfully.
C:\Users\Volker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Diagnostic folder moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d48be40b-ad63-11dd-9b40-001377a9fd0e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d48be40b-ad63-11dd-9b40-001377a9fd0e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d48be40b-ad63-11dd-9b40-001377a9fd0e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d48be40b-ad63-11dd-9b40-001377a9fd0e}\ not found.
File G:\LaunchU3.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\H2O deleted successfully.
C:\Programme\Syncrosoft\POS\H2O\cledx.exe moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Volker
->Temp folder emptied: 641973220 bytes
->Temporary Internet Files folder emptied: 3114846490 bytes
->Java cache emptied: 50194478 bytes
->FireFox cache emptied: 85755362 bytes
->Google Chrome cache emptied: 5946098 bytes
->Flash cache emptied: 141139 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 725009512 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 4.410,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 03242011_214330

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...
__________________

Alt 24.03.2011, 22:27   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 25.03.2011, 17:27   #5
0815User
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



soweit sogut...
Combofix Logfile:
Code:
ATTFilter
ComboFix 11-03-24.06 - Volker 25.03.2011  17:12:45.1.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.49.1031.18.3066.1976 [GMT 1:00]
ausgeführt von:: c:\users\Volker\Desktop\cofi.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((   Dateien erstellt von 2011-02-25 bis 2011-03-25  ))))))))))))))))))))))))))))))
.
.
2011-03-25 16:18 . 2011-03-25 16:18	--------	d-----w-	c:\users\Volker\AppData\Local\temp
2011-03-25 16:18 . 2011-03-25 16:18	--------	d-----w-	c:\users\Default\AppData\Local\temp
2011-03-25 15:53 . 2011-03-25 15:53	--------	d-----w-	c:\program files\CCleaner
2011-03-25 15:39 . 2011-03-15 04:05	6792528	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{867D9914-71EB-4981-8795-A6CAA04F4954}\mpengine.dll
2011-03-24 20:43 . 2011-03-24 20:43	--------	d-----w-	C:\_OTL
2011-03-22 17:52 . 2011-03-22 17:52	--------	d--h--w-	c:\users\Volker\AppData\Roaming\Malwarebytes
2011-03-22 17:52 . 2010-12-20 17:09	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-22 17:51 . 2011-03-22 17:51	--------	d--h--w-	c:\programdata\Malwarebytes
2011-03-22 17:51 . 2011-03-22 17:52	--------	d-----w-	c:\program files\Malwarebytes' Anti-Malware
2011-03-22 17:51 . 2010-12-20 17:08	20952	----a-w-	c:\windows\system32\drivers\mbam.sys
2011-03-09 16:43 . 2010-12-29 17:41	323072	----a-w-	c:\windows\system32\sbe.dll
2011-03-09 16:43 . 2010-12-29 17:41	429056	----a-w-	c:\windows\system32\EncDec.dll
2011-03-09 16:43 . 2010-12-29 17:41	153088	----a-w-	c:\windows\system32\sbeio.dll
2011-03-09 16:43 . 2010-12-29 17:39	177664	----a-w-	c:\windows\system32\mpg2splt.ax
2011-03-09 16:43 . 2010-12-17 16:43	2067456	----a-w-	c:\windows\system32\mstscax.dll
2011-03-09 16:43 . 2010-12-17 15:06	677888	----a-w-	c:\windows\system32\mstsc.exe
2011-02-27 16:30 . 2011-02-27 16:30	--------	d--h--w-	c:\users\Volker\AppData\Roaming\Softland
2011-02-27 16:30 . 2010-12-02 08:00	22856	----a-w-	c:\windows\system32\dopdfmn7.dll
2011-02-27 16:30 . 2010-12-02 08:00	19784	----a-w-	c:\windows\system32\dopdfmi7.dll
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-17 14:25 . 2010-05-22 17:09	137656	----a-w-	c:\windows\system32\drivers\avipbb.sys
2011-02-02 17:11 . 2009-10-08 12:15	222080	------w-	c:\windows\system32\MpSigStub.exe
2011-01-08 07:50 . 2011-02-09 13:01	34304	----a-w-	c:\windows\system32\atmlib.dll
2011-01-08 05:57 . 2011-02-09 13:01	292352	----a-w-	c:\windows\system32\atmfd.dll
2010-12-31 13:25 . 2011-02-09 13:02	2038784	----a-w-	c:\windows\system32\win32k.sys
2010-12-28 14:57 . 2011-01-12 20:33	409600	----a-w-	c:\windows\system32\odbc32.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\tbDVD1.dll" [2010-08-21 2736736]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
2010-08-21 00:34	2736736	----a-w-	c:\program files\DVDVideoSoft\tbDVD1.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\tbDVD1.dll" [2010-08-21 2736736]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}"= "c:\program files\DVDVideoSoft\tbDVD1.dll" [2010-08-21 2736736]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Steam"="c:\program files\steam\steam.exe" [2010-11-17 1242448]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-09-18 2937528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-08 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-08 92704]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-17 6111232]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-10-26 1029416]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-10 40048]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-04 281768]
"NetFxUpdate_v1.1.4322"="c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe" [2004-08-10 106496]
"M-Audio Taskbar Icon"="c:\windows\System32\M-AudioTaskBarIcon.exe" [2008-05-15 356864]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-2-12 723496]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 MAUSBFTP;Service for M-Audio Fast Track Pro (WDM);c:\windows\system32\DRIVERS\mausb.sys [2008-03-11 143624]
R3 NETw5v32;Intel(R) Wireless WiFi Link Adaptertreiber für Windows Vista 32-Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-05-20 3663360]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-11-04 135336]
S2 KMDFMEMIO;SAMSUNG Kernel Driver;c:\windows\system32\DRIVERS\kmdfmemio.sys [2007-05-23 13312]
S3 CLEDX;Team H2O CLEDX service;c:\windows\system32\DRIVERS\cledx.sys [2005-05-09 33792]
S3 VMC302;Vimicro Camera Service VMC302;c:\windows\system32\Drivers\VMC302.sys [2008-04-05 242560]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs	REG_MULTI_SZ   	BthServ
HPZ12	REG_MULTI_SZ   	Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt	REG_MULTI_SZ   	hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-03-17 08:56	451872	----a-w-	c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2011-03-24 c:\windows\Tasks\User_Feed_Synchronization-{E7D34EEB-CE6E-4564-990F-66D07FE2E827}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube to MP3 Converter - c:\users\Volker\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Volker\AppData\Roaming\Mozilla\Firefox\Profiles\84p4wq7f.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q=
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: HP Smart Web Printing: smartwebprinting@hp.com - c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF - Ext: HP Smart Web Printing: smartwebprinting@hp.com - c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-03-25 17:18
Windows 6.0.6001 Service Pack 1 NTFS
.
Scanne versteckte Prozesse... 
.
Scanne versteckte Autostarteinträge... 
.
Scanne versteckte Dateien... 
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-798057435-2566236125-1246601167-1003\Software\SecuROM\License information*]
"datasecu"=hex:f8,1b,47,0e,b1,2f,d9,f2,71,e6,6a,64,90,16,c2,30,0a,60,23,de,fb,
   dd,ba,b4,6c,f9,92,f2,e7,fd,9d,f4,60,ee,53,86,c6,c3,e2,48,e5,b6,42,f7,2c,d2,\
"rkeysecu"=hex:aa,f1,6c,38,8c,19,c3,04,f7,af,c1,06,38,56,d0,15
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(3984)
c:\windows\system32\btmmhook.dll
.
Zeit der Fertigstellung: 2011-03-25  17:20:44
ComboFix-quarantined-files.txt  2011-03-25 16:20
.
Vor Suchlauf: 6 Verzeichnis(se), 10.726.989.824 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 10.344.407.040 Bytes frei
.
- - End Of File - - A1EBFB7AC5E327F1FC5D8EB0B3D1FB3F
         
--- --- ---


Alt 25.03.2011, 18:30   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html
__________________
--> Dateien nach Windows Diagnostic

Alt 25.03.2011, 19:12   #7
0815User
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



OMG, sieht so aus als wäre alles wieder da!! Tausend Dank. Ist iwie komisch, jemandem ,den man nicht kennt, einfach zu vertrauen und alles zu tun was er sagt, aber hat ja alles funktioniert. Danke.

der scan hat nichts gefunden, hier trotzdem nochmal die Log:

Zitat:
2011/03/25 19:08:54.0139 6048 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/03/25 19:08:54.0522 6048 ================================================================================
2011/03/25 19:08:54.0522 6048 SystemInfo:
2011/03/25 19:08:54.0523 6048
2011/03/25 19:08:54.0523 6048 OS Version: 6.0.6001 ServicePack: 1.0
2011/03/25 19:08:54.0523 6048 Product type: Workstation
2011/03/25 19:08:54.0523 6048 ComputerName: VOLKER-PC
2011/03/25 19:08:54.0523 6048 UserName: Volker
2011/03/25 19:08:54.0523 6048 Windows directory: C:\Windows
2011/03/25 19:08:54.0523 6048 System windows directory: C:\Windows
2011/03/25 19:08:54.0523 6048 Processor architecture: Intel x86
2011/03/25 19:08:54.0523 6048 Number of processors: 2
2011/03/25 19:08:54.0523 6048 Page size: 0x1000
2011/03/25 19:08:54.0523 6048 Boot type: Normal boot
2011/03/25 19:08:54.0523 6048 ================================================================================
2011/03/25 19:08:55.0116 6048 Initialize success
2011/03/25 19:09:01.0478 4688 ================================================================================
2011/03/25 19:09:01.0478 4688 Scan started
2011/03/25 19:09:01.0478 4688 Mode: Manual;
2011/03/25 19:09:01.0478 4688 ================================================================================
2011/03/25 19:09:02.0602 4688 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys
2011/03/25 19:09:02.0798 4688 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/03/25 19:09:03.0002 4688 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/03/25 19:09:03.0121 4688 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/03/25 19:09:03.0193 4688 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/03/25 19:09:03.0553 4688 AFD (763e172a55177e478cb419f88fd0ba03) C:\Windows\system32\drivers\afd.sys
2011/03/25 19:09:03.0859 4688 AgereSoftModem (ce91b158fa490cf4c4d487a4130f4660) C:\Windows\system32\DRIVERS\AGRSM.sys
2011/03/25 19:09:04.0024 4688 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/03/25 19:09:04.0058 4688 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/03/25 19:09:04.0126 4688 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/03/25 19:09:04.0238 4688 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/03/25 19:09:04.0283 4688 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/03/25 19:09:04.0351 4688 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/03/25 19:09:04.0393 4688 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
2011/03/25 19:09:04.0776 4688 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/03/25 19:09:05.0136 4688 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/03/25 19:09:05.0529 4688 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/03/25 19:09:05.0740 4688 atapi (2d9c903dc76a66813d350a562de40ed9) C:\Windows\system32\drivers\atapi.sys
2011/03/25 19:09:05.0921 4688 athr (91e15b0a1d6f7b99ace55d04c6d1544a) C:\Windows\system32\DRIVERS\athr.sys
2011/03/25 19:09:06.0336 4688 atksgt (6e996cf8459a2594e0e9609d0e34d41f) C:\Windows\system32\DRIVERS\atksgt.sys
2011/03/25 19:09:06.0656 4688 avgntflt (47b879406246ffdced59e18d331a0e7d) C:\Windows\system32\DRIVERS\avgntflt.sys
2011/03/25 19:09:06.0739 4688 avipbb (5fedef54757b34fb611b9ec8fb399364) C:\Windows\system32\DRIVERS\avipbb.sys
2011/03/25 19:09:06.0855 4688 bcm4sbxp (08015d34f6fdd0b355805bad978497c3) C:\Windows\system32\DRIVERS\bcm4sbxp.sys
2011/03/25 19:09:06.0929 4688 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/03/25 19:09:07.0169 4688 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/03/25 19:09:07.0585 4688 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2011/03/25 19:09:07.0825 4688 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/03/25 19:09:07.0905 4688 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/03/25 19:09:08.0217 4688 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/03/25 19:09:08.0343 4688 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/03/25 19:09:08.0440 4688 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/03/25 19:09:08.0576 4688 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/03/25 19:09:08.0695 4688 BthEnum (da7b195275bda7f8fcf79b40e0f45dde) C:\Windows\system32\DRIVERS\BthEnum.sys
2011/03/25 19:09:08.0951 4688 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/03/25 19:09:09.0099 4688 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
2011/03/25 19:09:09.0307 4688 BTHPORT (671134053d59e23704f08db19f11e10b) C:\Windows\system32\Drivers\BTHport.sys
2011/03/25 19:09:09.0410 4688 BTHUSB (93d7007e2c660dfcca6ae72622740b14) C:\Windows\system32\Drivers\BTHUSB.sys
2011/03/25 19:09:09.0651 4688 btwaudio (3ea1a20dc0ca1ad23e7aa8c37a91bcd1) C:\Windows\system32\drivers\btwaudio.sys
2011/03/25 19:09:09.0703 4688 btwavdt (195872e48a7fb01f8bc9b800f70f4054) C:\Windows\system32\drivers\btwavdt.sys
2011/03/25 19:09:10.0068 4688 btwrchid (0724e7d6c9b6a289eddda33fa8176e80) C:\Windows\system32\DRIVERS\btwrchid.sys
2011/03/25 19:09:10.0257 4688 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/03/25 19:09:10.0309 4688 cdrom (1ec25cea0de6ac4718bf89f9e1778b57) C:\Windows\system32\DRIVERS\cdrom.sys
2011/03/25 19:09:10.0387 4688 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2011/03/25 19:09:10.0545 4688 CLEDX (b53f9635457b56dcffef750e18aec6cb) C:\Windows\system32\DRIVERS\cledx.sys
2011/03/25 19:09:10.0744 4688 CLFS (465745561c832b29f7c48b488aab3842) C:\Windows\system32\CLFS.sys
2011/03/25 19:09:10.0855 4688 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/03/25 19:09:10.0945 4688 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/03/25 19:09:11.0019 4688 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2011/03/25 19:09:11.0125 4688 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/03/25 19:09:11.0263 4688 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/03/25 19:09:11.0402 4688 DfsC (9e635ae5e8ad93e2b5989e2e23679f97) C:\Windows\system32\Drivers\dfsc.sys
2011/03/25 19:09:11.0496 4688 disk (64109e623abd6955c8fb110b592e68b7) C:\Windows\system32\drivers\disk.sys
2011/03/25 19:09:11.0626 4688 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
2011/03/25 19:09:11.0697 4688 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2011/03/25 19:09:11.0791 4688 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
2011/03/25 19:09:11.0892 4688 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/03/25 19:09:12.0053 4688 DXGKrnl (85f33880b8cfb554bd3d9ccdb486845a) C:\Windows\System32\drivers\dxgkrnl.sys
2011/03/25 19:09:12.0207 4688 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/03/25 19:09:12.0323 4688 Ecache (dd2cd259d83d8b72c02c5f2331ff9d68) C:\Windows\system32\drivers\ecache.sys
2011/03/25 19:09:12.0459 4688 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/03/25 19:09:12.0716 4688 enodpl (b4556f3d468c8dcb0b259d9d866cd4c4) C:\Windows\system32\drivers\enodpl.sys
2011/03/25 19:09:12.0896 4688 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/03/25 19:09:13.0100 4688 exfat (0d858eb20589a34efb25695acaa6aa2d) C:\Windows\system32\drivers\exfat.sys
2011/03/25 19:09:13.0167 4688 fastfat (3c489390c2e2064563727752af8eab9e) C:\Windows\system32\drivers\fastfat.sys
2011/03/25 19:09:13.0291 4688 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/03/25 19:09:13.0368 4688 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/03/25 19:09:13.0406 4688 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/03/25 19:09:13.0514 4688 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/03/25 19:09:13.0638 4688 FltMgr (05ea53afe985443011e36dab07343b46) C:\Windows\system32\drivers\fltmgr.sys
2011/03/25 19:09:13.0768 4688 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/03/25 19:09:13.0858 4688 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/03/25 19:09:13.0921 4688 GEARAspiWDM (ab8a6a87d9d7255c3884d5b9541a6e80) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/03/25 19:09:14.0004 4688 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2011/03/25 19:09:14.0145 4688 HDAudBus (c87b1ee051c0464491c1a7b03fa0bc99) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/03/25 19:09:14.0200 4688 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/03/25 19:09:14.0427 4688 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/03/25 19:09:14.0508 4688 HidUsb (854ca287ab7faf949617a788306d967e) C:\Windows\system32\DRIVERS\hidusb.sys
2011/03/25 19:09:14.0640 4688 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/03/25 19:09:14.0779 4688 HTTP (96e241624c71211a79c84f50a8e71cab) C:\Windows\system32\drivers\HTTP.sys
2011/03/25 19:09:14.0931 4688 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/03/25 19:09:15.0028 4688 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/03/25 19:09:15.0479 4688 ialm (496db78e6a0c4c44023d9a92b4a7ac31) C:\Windows\system32\DRIVERS\igdkmd32.sys
2011/03/25 19:09:15.0843 4688 iaStor (f263a9036f8897ffa2ae54685e03ad60) C:\Windows\system32\DRIVERS\iaStor.sys
2011/03/25 19:09:16.0156 4688 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/03/25 19:09:16.0532 4688 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/03/25 19:09:17.0025 4688 IntcAzAudAddService (ffd2b3bc042596abe785d3c15f51ab46) C:\Windows\system32\drivers\RTKVHDA.sys
2011/03/25 19:09:17.0348 4688 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/03/25 19:09:17.0701 4688 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/03/25 19:09:17.0832 4688 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/03/25 19:09:17.0967 4688 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/03/25 19:09:18.0148 4688 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/03/25 19:09:18.0391 4688 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/03/25 19:09:18.0523 4688 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/03/25 19:09:18.0701 4688 iScsiPrt (f247eec28317f6c739c16de420097301) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/03/25 19:09:18.0822 4688 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/03/25 19:09:18.0880 4688 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/03/25 19:09:18.0914 4688 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/03/25 19:09:19.0012 4688 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/03/25 19:09:19.0158 4688 KMDFMEMIO (ebc507f129df8f0e0ca270dcfc0cf87f) C:\Windows\system32\DRIVERS\kmdfmemio.sys
2011/03/25 19:09:19.0704 4688 KSecDD (7a0cf7908b6824d6a2a1d313e5ae3dca) C:\Windows\system32\Drivers\ksecdd.sys
2011/03/25 19:09:19.0862 4688 lirsgt (975b6cf65f44e95883f3855bae8cecaf) C:\Windows\system32\DRIVERS\lirsgt.sys
2011/03/25 19:09:19.0960 4688 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/03/25 19:09:20.0033 4688 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/03/25 19:09:20.0586 4688 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/03/25 19:09:20.0783 4688 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/03/25 19:09:20.0853 4688 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/03/25 19:09:21.0006 4688 MAUSBFTP (a07af79cac2b923d65d51eaad5dafc69) C:\Windows\system32\DRIVERS\mausb.sys
2011/03/25 19:09:21.0854 4688 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/03/25 19:09:22.0188 4688 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/03/25 19:09:22.0341 4688 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/03/25 19:09:22.0418 4688 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/03/25 19:09:22.0487 4688 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/03/25 19:09:22.0702 4688 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/03/25 19:09:22.0743 4688 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/03/25 19:09:23.0163 4688 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/03/25 19:09:23.0641 4688 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/03/25 19:09:23.0997 4688 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/03/25 19:09:24.0035 4688 MRxDAV (ae3de84536b6799d2267443cec8edbb9) C:\Windows\system32\drivers\mrxdav.sys
2011/03/25 19:09:24.0295 4688 mrxsmb (7afc42e60432fd1014f5342f2b1b1f74) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/03/25 19:09:24.0381 4688 mrxsmb10 (8a75752ae17924f65452746674b14b78) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/03/25 19:09:24.0509 4688 mrxsmb20 (f4d0f3252e651f02be64984ffa738394) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/03/25 19:09:24.0571 4688 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2011/03/25 19:09:24.0617 4688 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/03/25 19:09:24.0795 4688 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/03/25 19:09:24.0858 4688 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/03/25 19:09:25.0048 4688 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/03/25 19:09:25.0129 4688 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/03/25 19:09:25.0487 4688 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/03/25 19:09:25.0706 4688 MsRPC (b5614aecb05a9340aa0fb55bf561cc63) C:\Windows\system32\drivers\MsRPC.sys
2011/03/25 19:09:25.0729 4688 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/03/25 19:09:25.0922 4688 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/03/25 19:09:25.0958 4688 Mup (6dfd1d322de55b0b7db7d21b90bec49c) C:\Windows\system32\Drivers\mup.sys
2011/03/25 19:09:26.0142 4688 NativeWifiP (3c21ce48ff529bb73dadb98770b54025) C:\Windows\system32\DRIVERS\nwifi.sys
2011/03/25 19:09:26.0334 4688 NDIS (9bdc71790fa08f0a0b5f10462b1bd0b1) C:\Windows\system32\drivers\ndis.sys
2011/03/25 19:09:26.0777 4688 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/03/25 19:09:27.0245 4688 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/03/25 19:09:27.0571 4688 NdisWan (3d14c3b3496f88890d431e8aa022a411) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/03/25 19:09:27.0783 4688 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/03/25 19:09:27.0818 4688 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/03/25 19:09:27.0899 4688 netbt (7c5fee5b1c5728507cd96fb4a13e7a02) C:\Windows\system32\DRIVERS\netbt.sys
2011/03/25 19:09:28.0365 4688 NETw3v32 (35d5458d9a1b26b2005abffbf4c1c5e7) C:\Windows\system32\DRIVERS\NETw3v32.sys
2011/03/25 19:09:29.0093 4688 NETw5v32 (0b214c6a4728f085fb64a29ed9c4de94) C:\Windows\system32\DRIVERS\NETw5v32.sys
2011/03/25 19:09:29.0637 4688 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/03/25 19:09:29.0830 4688 Npfs (ecb5003f484f9ed6c608d6d6c7886cbb) C:\Windows\system32\drivers\Npfs.sys
2011/03/25 19:09:29.0882 4688 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/03/25 19:09:30.0295 4688 Ntfs (b4effe29eb4f15538fd8a9681108492d) C:\Windows\system32\drivers\Ntfs.sys
2011/03/25 19:09:30.0678 4688 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/03/25 19:09:30.0761 4688 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/03/25 19:09:31.0199 4688 nvlddmkm (440690da4358d9682dbcc56da7d419ab) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/03/25 19:09:31.0562 4688 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/03/25 19:09:31.0632 4688 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/03/25 19:09:31.0808 4688 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/03/25 19:09:32.0268 4688 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/03/25 19:09:32.0564 4688 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/03/25 19:09:32.0836 4688 partmgr (3b38467e7c3daed009dfe359e17f139f) C:\Windows\system32\drivers\partmgr.sys
2011/03/25 19:09:33.0080 4688 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/03/25 19:09:33.0371 4688 pci (01b94418deb235dff777cc80076354b4) C:\Windows\system32\drivers\pci.sys
2011/03/25 19:09:33.0732 4688 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
2011/03/25 19:09:34.0064 4688 pcmcia (b7c5a8769541900f6dfa6fe0c5e4d513) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/03/25 19:09:34.0442 4688 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/03/25 19:09:34.0742 4688 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/03/25 19:09:34.0972 4688 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
2011/03/25 19:09:35.0359 4688 PSched (bfef604508a0ed1eae2a73e872555ffb) C:\Windows\system32\DRIVERS\pacer.sys
2011/03/25 19:09:35.0936 4688 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/03/25 19:09:36.0252 4688 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/03/25 19:09:36.0763 4688 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/03/25 19:09:37.0102 4688 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/03/25 19:09:37.0293 4688 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/03/25 19:09:37.0380 4688 RasPppoe (3e9d9b048107b40d87b97df2e48e0744) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/03/25 19:09:37.0601 4688 RasSstp (a7d141684e9500ac928a772ed8e6b671) C:\Windows\system32\DRIVERS\rassstp.sys
2011/03/25 19:09:37.0935 4688 rdbss (6e1c5d0457622f9ee35f683110e93d14) C:\Windows\system32\DRIVERS\rdbss.sys
2011/03/25 19:09:38.0119 4688 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/03/25 19:09:38.0172 4688 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2011/03/25 19:09:38.0779 4688 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/03/25 19:09:39.0111 4688 RDPWD (e1c18f4097a5abcec941dc4b2f99db7e) C:\Windows\system32\drivers\RDPWD.sys
2011/03/25 19:09:39.0327 4688 RFCOMM (10536b0ad6f416fc7f1149977c28ccdc) C:\Windows\system32\DRIVERS\rfcomm.sys
2011/03/25 19:09:39.0694 4688 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/03/25 19:09:40.0168 4688 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/03/25 19:09:40.0365 4688 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
2011/03/25 19:09:40.0667 4688 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/03/25 19:09:41.0143 4688 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/03/25 19:09:41.0289 4688 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/03/25 19:09:41.0348 4688 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/03/25 19:09:41.0929 4688 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/03/25 19:09:42.0139 4688 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/03/25 19:09:42.0168 4688 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/03/25 19:09:42.0206 4688 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/03/25 19:09:42.0249 4688 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/03/25 19:09:42.0509 4688 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/03/25 19:09:42.0706 4688 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/03/25 19:09:42.0833 4688 Smb (031e6bcd53c9b2b9ace111eafec347b6) C:\Windows\system32\DRIVERS\smb.sys
2011/03/25 19:09:42.0951 4688 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/03/25 19:09:43.0141 4688 srv (5754e8bae40943871d0ab9becbf335e8) C:\Windows\system32\DRIVERS\srv.sys
2011/03/25 19:09:43.0787 4688 srv2 (d47b09ff7d28ee44d728f57c2d1fab86) C:\Windows\system32\DRIVERS\srv2.sys
2011/03/25 19:09:44.0170 4688 srvnet (32d52290341a740881521e118106acd6) C:\Windows\system32\DRIVERS\srvnet.sys
2011/03/25 19:09:44.0439 4688 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
2011/03/25 19:09:44.0757 4688 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/03/25 19:09:45.0129 4688 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/03/25 19:09:45.0439 4688 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/03/25 19:09:45.0734 4688 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/03/25 19:09:46.0128 4688 SynTP (451e8037e2eb6da6bdf0a66f65d1810b) C:\Windows\system32\DRIVERS\SynTP.sys
2011/03/25 19:09:46.0368 4688 tandpl (126d7b3b4c7b724491c604060e1f4e14) C:\Windows\system32\drivers\tandpl.sys
2011/03/25 19:09:46.0980 4688 Tcpip (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\drivers\tcpip.sys
2011/03/25 19:09:47.0642 4688 Tcpip6 (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\DRIVERS\tcpip.sys
2011/03/25 19:09:47.0902 4688 tcpipreg (d4a2e4a4b011f3a883af77315a5ae76b) C:\Windows\system32\drivers\tcpipreg.sys
2011/03/25 19:09:47.0957 4688 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/03/25 19:09:48.0010 4688 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/03/25 19:09:48.0096 4688 tdx (d09276b1fab033ce1d40dcbdf303d10f) C:\Windows\system32\DRIVERS\tdx.sys
2011/03/25 19:09:48.0132 4688 TermDD (a048056f5e1a96a9bf3071b91741a5aa) C:\Windows\system32\DRIVERS\termdd.sys
2011/03/25 19:09:48.0545 4688 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/03/25 19:09:48.0755 4688 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/03/25 19:09:48.0821 4688 tunnel (6042505ff6fa9ac1ef7684d0e03b6940) C:\Windows\system32\DRIVERS\tunnel.sys
2011/03/25 19:09:49.0228 4688 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/03/25 19:09:49.0437 4688 udfs (8b5088058fa1d1cd897a2113ccff6c58) C:\Windows\system32\DRIVERS\udfs.sys
2011/03/25 19:09:49.0741 4688 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/03/25 19:09:50.0025 4688 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/03/25 19:09:50.0242 4688 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/03/25 19:09:50.0479 4688 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/03/25 19:09:50.0711 4688 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/03/25 19:09:50.0885 4688 USBAAPL (c1ca131f4e3ed63d6bc89a35ffad4cda) C:\Windows\system32\Drivers\usbaapl.sys
2011/03/25 19:09:51.0103 4688 usbaudio (292a25bb75a568ae2c67169ba2c6365a) C:\Windows\system32\drivers\usbaudio.sys
2011/03/25 19:09:51.0626 4688 usbccgp (a7cd5b4adea26765cab06bdab7b07b13) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/03/25 19:09:52.0108 4688 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/03/25 19:09:52.0578 4688 usbehci (686d4188ae36254c3008b71fedacadf3) C:\Windows\system32\DRIVERS\usbehci.sys
2011/03/25 19:09:52.0888 4688 usbhub (4e42f665a658f08d153f7fffe7c83806) C:\Windows\system32\DRIVERS\usbhub.sys
2011/03/25 19:09:53.0186 4688 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2011/03/25 19:09:53.0481 4688 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2011/03/25 19:09:53.0661 4688 USBSTOR (87ba6b83c5d19b69160968d07d6e2982) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/03/25 19:09:53.0693 4688 usbuhci (40f95a3d6d50d82f947f1d167c2ec39d) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/03/25 19:09:54.0097 4688 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
2011/03/25 19:09:54.0403 4688 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/03/25 19:09:54.0726 4688 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/03/25 19:09:54.0827 4688 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2011/03/25 19:09:54.0981 4688 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2011/03/25 19:09:55.0260 4688 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/03/25 19:09:55.0551 4688 VMC302 (2b0970a8c0a65874eff4aa436e651d85) C:\Windows\system32\Drivers\VMC302.sys
2011/03/25 19:09:55.0774 4688 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/03/25 19:09:56.0141 4688 volmgrx (98f5ffe6316bd74e9e2c97206c190196) C:\Windows\system32\drivers\volmgrx.sys
2011/03/25 19:09:56.0413 4688 volsnap (d8b4a53dd2769f226b3eb374374987c9) C:\Windows\system32\drivers\volsnap.sys
2011/03/25 19:09:56.0545 4688 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2011/03/25 19:09:56.0601 4688 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/03/25 19:09:56.0651 4688 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/03/25 19:09:56.0675 4688 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/03/25 19:09:56.0957 4688 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2011/03/25 19:09:57.0189 4688 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/03/25 19:09:57.0870 4688 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
2011/03/25 19:09:58.0011 4688 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/03/25 19:09:58.0083 4688 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/03/25 19:09:58.0160 4688 yukonwlh (04e268adfc81964c49dc0c082d520f7e) C:\Windows\system32\DRIVERS\yk60x86.sys
2011/03/25 19:10:00.0752 4688 ================================================================================
2011/03/25 19:10:00.0752 4688 Scan finished
2011/03/25 19:10:00.0752 4688 ================================================================================

Alt 26.03.2011, 17:43   #8
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.


Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 30.03.2011, 14:18   #9
0815User
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



Ok hier sind schon mal GMER:

GMER Logfile:
Code:
ATTFilter
GMER 1.0.15.15570 - hxxp://www.gmer.net
Rootkit scan 2011-03-30 14:51:25
Windows 6.0.6001 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.FB4O
Running: 2brlxhp2.exe; Driver: C:\Users\Volker\AppData\Local\Temp\ufdiypoc.sys


---- Kernel code sections - GMER 1.0.15 ----

.text  C:\Windows\system32\DRIVERS\nvlddmkm.sys                                                         section is writeable [0x8E404340, 0x3E9407, 0xE8000020]
.text  C:\Windows\system32\DRIVERS\atksgt.sys                                                           section is writeable [0x9F5DE300, 0x3ACC8, 0xE8000020]
.text  C:\Windows\system32\DRIVERS\lirsgt.sys                                                           section is writeable [0x9F623300, 0x1B7E, 0xE8000020]

---- Registry - GMER 1.0.15 ----

Reg    HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002787923ce                      
Reg    HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00027879245e                      
Reg    HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0002787923ce (not active ControlSet)  
Reg    HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00027879245e (not active ControlSet)  

---- EOF - GMER 1.0.15 ----
         
--- --- ---


und OSAM:

OSAM Logfile:
Code:
ATTFilter
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 15:16:38 on 30.03.2011

OS: Windows Vista Home Premium Edition Service Pack 1 (Build 6001), 32-bit
Default Browser: Microsoft Corporation Internet Explorer 7.00.6000.16386

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"iproset.cpl" - "Intel(R) Corporation" - C:\Windows\system32\iproset.cpl
"PhysX.cpl" - ? - C:\Windows\system32\PhysX.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL
"Pando" - "Pando Networks" - C:\Program Files\Pando Networks\Media Booster\PMB.cpl
"PROSet Tools" - "Intel(R) Corporation" - C:\Windows\System32\iPROSet.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys  (File found, but it contains no detailed information)
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\Users\Volker\AppData\Local\Temp\catchme.sys  (File not found)
"EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys  (File not found)
"enodpl" (enodpl) - ? - C:\Windows\System32\drivers\enodpl.sys  (File found, but it contains no detailed information)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys  (File found, but it contains no detailed information)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"tandpl" (tandpl) - ? - C:\Windows\System32\drivers\tandpl.sys  (File found, but it contains no detailed information)
"Team H2O CLEDX service" (CLEDX) - "Team H2O" - C:\Windows\System32\DRIVERS\cledx.sys
"ufdiypoc" (ufdiypoc) - ? - C:\Users\Volker\AppData\Local\Temp\ufdiypoc.sys  (Hidden registry entry, rootkit activity | File not found)

[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{10880D85-AAD9-4558-ABDC-2AB1552D831F} "LightScribe Control Panel" - "Hewlett-Packard Company" - "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -   (File not found | COM-object registry key not found)
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -   (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -   (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{00020d75-0000-0000-c000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -   (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{555D4D79-4BD2-4094-A395-CFC534424A05} "HP Smart Web Printing" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "DVDVideoSoftTB Toolbar" - "Conduit Ltd." - C:\Program Files\DVDVideoSoft\tbDVD1.dll
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBarLayout" - ? -   (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )-----
{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} "DVDVideoSoftTB Toolbar" - "Conduit Ltd." - C:\Program Files\DVDVideoSoft\tbDVD1.dll
{855F3B16-6D32-4fe6-8A56-BBB695989046} "ICQToolBar" - "ICQ" - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
 "{855F3B16-6D32-4fe6-8A56-BBB695989046}" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{DDE87865-83C5-48c4-8357-2F5B1AA84522} "HP Smart Web Printing ein- oder ausblenden" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
"ICQ7.2" - "ICQ, LLC." - C:\Program Files\ICQ7.2\ICQ.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} "DVDVideoSoftTB Toolbar" - "Conduit Ltd." - C:\Program Files\DVDVideoSoft\tbDVD1.dll
{855F3B16-6D32-4fe6-8A56-BBB695989046} "ICQToolBar" - "ICQ" - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} "DVDVideoSoftTB Toolbar" - "Conduit Ltd." - C:\Program Files\DVDVideoSoft\tbDVD1.dll
{0347C33E-8762-4905-BF09-768834316C61} "HP Print Enhancer" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} "HP Smart BHO Class" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - ? - C:\Program Files\Java\jre6\bin\jp2ssv.dll  (File not found)
{02478D38-C3F9-4efb-9B51-7695ECA05670} "{02478D38-C3F9-4efb-9B51-7695ECA05670}" - ? -   (File not found | COM-object registry key not found)

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Volker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"HP Digital Imaging Monitor.lnk" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe  (Shortcut exists | File exists)
"BTTray.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Pando Media Booster" - ? - C:\Program Files\Pando Networks\Media Booster\PMB.exe
"Steam" - "Valve Corporation" - "c:\program files\steam\steam.exe" -silent
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"HP Software Update" - "Hewlett-Packard" - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"LanguageShortcut" - ? - "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
"M-Audio Taskbar Icon" - "Avid Technology, Inc." - C:\Windows\System32\M-AudioTaskBarIcon.exe
"Malwarebytes' Anti-Malware (reboot)" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
"NetFxUpdate_v1.1.4322" - "Microsoft" - "C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe" 1 v1.1.4322 GAC + NI NID
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"RemoteControl" - "Cyberlink Corp." - "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"doPDF 7 Monitor" - "Softland" - C:\Windows\system32\dopdfmn7.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Bonjour-Dienst" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
"HP CUE DeviceDiscovery Service" (hpqddsvc) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
"hpqcxs08" (hpqcxs08) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
"Intel® PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
"Intel® PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"Samsung Update Plus" (Samsung Update Plus) - ? - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe  (File found, but it contains no detailed information)
"SQL Server (MSSMLBIZ)" (MSSQL$MSSMLBIZ) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
"SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
"SQL Server-Browser" (SQLBrowser) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
"SQL Server-Startdienst für Business Contact Manager" (BcmSqlStartupSvc) - "Microsoft Corporation" - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files\Common Files\Steam\SteamService.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===
         
--- --- ---

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru[/QUOTE]


und hier mbrcheck:

Zitat:
MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 1 (build 6001), 32-bit
Base Board Manufacturer: SAMSUNG ELECTRONICS CO., LTD.
BIOS Manufacturer: Phoenix Technologies Ltd.
System Manufacturer: SAMSUNG ELECTRONICS CO., LTD.
System Product Name: R510/P510
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 144):
0x82407000 \SystemRoot\system32\ntoskrnl.exe
0x827B2000 \SystemRoot\system32\hal.dll
0x8A00A000 \SystemRoot\system32\kdcom.dll
0x8A012000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8A072000 \SystemRoot\system32\PSHED.dll
0x8A083000 \SystemRoot\system32\BOOTVID.dll
0x8A08B000 \SystemRoot\system32\CLFS.SYS
0x8A0CC000 \SystemRoot\system32\CI.dll
0x8A1AC000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8A228000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8A235000 \SystemRoot\system32\drivers\acpi.sys
0x8A27B000 \SystemRoot\system32\drivers\WMILIB.SYS
0x8A284000 \SystemRoot\system32\drivers\msisadrv.sys
0x8A28C000 \SystemRoot\system32\drivers\pci.sys
0x8A2B3000 \SystemRoot\System32\drivers\partmgr.sys
0x8A2C2000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x8A2C5000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8A2CF000 \SystemRoot\system32\drivers\volmgr.sys
0x8A2DE000 \SystemRoot\System32\drivers\volmgrx.sys
0x8A328000 \SystemRoot\System32\drivers\mountmgr.sys
0x8A402000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x8A4D2000 \SystemRoot\system32\drivers\atapi.sys
0x8A4DA000 \SystemRoot\system32\drivers\ataport.SYS
0x8A4F8000 \SystemRoot\system32\drivers\fltmgr.sys
0x8A52A000 \SystemRoot\system32\drivers\fileinfo.sys
0x8A53A000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8A5AB000 \SystemRoot\system32\drivers\ndis.sys
0x8A6B6000 \SystemRoot\system32\drivers\msrpc.sys
0x8A6E1000 \SystemRoot\system32\drivers\NETIO.SYS
0x8A80F000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8A91E000 \SystemRoot\system32\drivers\volsnap.sys
0x8A957000 \SystemRoot\System32\Drivers\spldr.sys
0x8A95F000 \SystemRoot\System32\Drivers\mup.sys
0x8A96E000 \SystemRoot\System32\drivers\ecache.sys
0x8A995000 \SystemRoot\system32\drivers\disk.sys
0x8A9A6000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8A9C7000 \SystemRoot\system32\drivers\crcdisk.sys
0x8AAAD000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8AAB8000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8E404000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8EB31000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8EBD0000 \SystemRoot\System32\drivers\watchdog.sys
0x8EBDD000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8AAC1000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8EBE8000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8AAFF000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8AB11000 \SystemRoot\system32\DRIVERS\athr.sys
0x8A71B000 \SystemRoot\system32\DRIVERS\yk60x86.sys
0x8EBF7000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8ABD0000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8ABE3000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8A767000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8EBFB000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8ABEE000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8A795000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8EBFD000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8A800000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8A7AD000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8A338000 \SystemRoot\system32\DRIVERS\storport.sys
0x8A7DB000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8A7E6000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8A379000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8A384000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8A3A7000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8A3B6000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8A3CA000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8A3DF000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8E400000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8EC03000 \SystemRoot\system32\DRIVERS\ks.sys
0x8EC2D000 \SystemRoot\system32\DRIVERS\cledx.sys
0x8EC3B000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8EC45000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8EC52000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8EC86000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8EC97000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x8EE97000 \SystemRoot\system32\drivers\portcls.sys
0x8EEC4000 \SystemRoot\system32\drivers\drmk.sys
0x8EEE9000 \SystemRoot\system32\drivers\HdAudio.sys
0x8EF28000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8EF31000 \SystemRoot\System32\Drivers\Null.SYS
0x8EF38000 \SystemRoot\System32\Drivers\Beep.SYS
0x8EF48000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8EF4F000 \SystemRoot\System32\drivers\vga.sys
0x8EF5B000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8EF7C000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8EF84000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8EF8C000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8EF97000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8EFA5000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8F40A000 \SystemRoot\System32\drivers\tcpip.sys
0x8F4F3000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8F50E000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8F524000 \SystemRoot\system32\DRIVERS\smb.sys
0x8F538000 \SystemRoot\system32\drivers\afd.sys
0x8F580000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8F5B2000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8F5C8000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8F5D6000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8F5DF000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8F5EF000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8F602000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x8F608000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8F644000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8F64C000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8F656000 \SystemRoot\System32\Drivers\dfsc.sys
0x8F66D000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8F684000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x8F6AA000 \SystemRoot\System32\Drivers\VMC302.sys
0x8F6E6000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8F6F3000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x97020000 \SystemRoot\System32\win32k.sys
0x8F7C3000 \SystemRoot\System32\drivers\Dxapi.sys
0x8F7CD000 \SystemRoot\system32\DRIVERS\monitor.sys
0x97240000 \SystemRoot\System32\TSDDD.dll
0x97260000 \SystemRoot\System32\cdd.dll
0x8F7DC000 \SystemRoot\system32\drivers\luafv.sys
0x8EFAE000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x8F7F7000 \SystemRoot\system32\DRIVERS\kmdfmemio.sys
0x8A9D0000 \SystemRoot\system32\drivers\spsys.sys
0x8EFC3000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x8EFD3000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x8F400000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x8AA7F000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9F408000 \SystemRoot\system32\drivers\HTTP.sys
0x9F475000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9F492000 \SystemRoot\system32\DRIVERS\bowser.sys
0x9F4AB000 \SystemRoot\System32\drivers\mpsdrv.sys
0x9F4C0000 \SystemRoot\system32\drivers\mrxdav.sys
0x9F4E0000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9F4FF000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x9F538000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9F550000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9F578000 \SystemRoot\System32\DRIVERS\srv.sys
0x9F5DE000 \SystemRoot\system32\DRIVERS\atksgt.sys
0x9F621000 \SystemRoot\System32\drivers\enodpl.sys
0x9F623000 \SystemRoot\system32\DRIVERS\lirsgt.sys
0x9F628000 \SystemRoot\system32\drivers\peauth.sys
0x9F706000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9F710000 \SystemRoot\System32\drivers\tandpl.sys
0x9F712000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9F71E000 \SystemRoot\system32\DRIVERS\ipnat.sys
0x9F744000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x9F75A000 \??\C:\Users\Volker\AppData\Local\Temp\ufdiypoc.sys
0x77890000 \Windows\System32\ntdll.dll

Processes (total 82):
0 System Idle Process
4 System
492 C:\Windows\System32\smss.exe
568 csrss.exe
620 C:\Windows\System32\wininit.exe
632 csrss.exe
664 C:\Windows\System32\services.exe
676 C:\Windows\System32\lsass.exe
684 C:\Windows\System32\lsm.exe
832 C:\Windows\System32\svchost.exe
904 C:\Windows\System32\nvvsvc.exe
932 C:\Windows\System32\svchost.exe
968 C:\Windows\System32\svchost.exe
1020 C:\Windows\System32\svchost.exe
1048 C:\Windows\System32\svchost.exe
1080 C:\Windows\System32\svchost.exe
1144 C:\Windows\System32\audiodg.exe
1176 C:\Windows\System32\SLsvc.exe
1216 C:\Windows\System32\svchost.exe
1308 C:\Windows\System32\winlogon.exe
1376 C:\Windows\System32\svchost.exe
1552 C:\Windows\System32\rundll32.exe
1676 C:\Windows\System32\taskeng.exe
1732 C:\Windows\System32\spoolsv.exe
1764 C:\Program Files\Avira\AntiVir Desktop\sched.exe
1780 C:\Windows\System32\svchost.exe
320 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
336 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
356 C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
424 C:\Program Files\Bonjour\mDNSResponder.exe
508 C:\Windows\System32\svchost.exe
524 C:\Program Files\Intel\WiFi\bin\EvtEng.exe
1364 C:\Windows\System32\svchost.exe
1516 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
1880 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
2108 C:\Windows\System32\svchost.exe
2252 C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
2280 C:\Program Files\CyberLink\Shared Files\RichVideo.exe
2384 C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
2400 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
2516 C:\Windows\System32\svchost.exe
2596 C:\Windows\System32\svchost.exe
2620 C:\Windows\System32\SearchIndexer.exe
3144 C:\Windows\System32\alg.exe
4048 C:\Program Files\Windows Media Player\wmpnetwk.exe
1632 C:\Windows\System32\dwm.exe
3572 C:\Windows\System32\taskeng.exe
3600 C:\Windows\explorer.exe
3736 C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
3772 C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
3840 C:\Windows\System32\taskeng.exe
2248 C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
3836 C:\Windows\System32\rundll32.exe
4008 C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
4012 C:\Windows\RtHDVCpl.exe
3368 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3552 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
3336 C:\Program Files\iTunes\iTunesHelper.exe
2572 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
2612 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
2488 C:\Windows\System32\M-AudioTaskBarIcon.exe
3280 C:\Program Files\Windows Sidebar\sidebar.exe
1152 C:\Program Files\Pando Networks\Media Booster\PMB.exe
2972 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
3320 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
3196 C:\Program Files\Windows Media Player\wmpnscfg.exe
1584 C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
4100 C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
4200 C:\Windows\System32\wuauclt.exe
4276 C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
4372 C:\Program Files\iPod\bin\iPodService.exe
4828 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
5564 C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
4320 taskeng.exe
4564 C:\Program Files\Internet Explorer\ieuser.exe
4992 C:\Program Files\Internet Explorer\iexplore.exe
5212 C:\Windows\System32\Macromed\Flash\FlashUtil10c.exe
3252 C:\Windows\System32\SearchProtocolHost.exe
5688 C:\Windows\System32\SearchFilterHost.exe
1332 dllhost.exe
4236 dllhost.exe
1156 C:\Users\Volker\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`80100000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000026`85d00000 (NTFS)

PhysicalDrive0 Model Number: HitachiHTS543232L9A300, Rev: FB4OC40C

Size Device Name MBR Status
--------------------------------------------
298 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 898F3CF28E8EC7228D29035E39B672E205D702F2


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!

Geändert von 0815User (30.03.2011 um 15:13 Uhr)

Alt 30.03.2011, 15:38   #10
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



Zitat:
"EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys (File not found)
"Team H2O CLEDX service" (CLEDX) - "Team H2O" - C:\Windows\System32\DRIVERS\cledx.sys
Bitte mit OSAM deaktivieren und löschen, beachte dazu die Anleitung von OSAM.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 30.03.2011, 19:29   #11
0815User
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



neues OSAM-Log:

OSAM Logfile:
Code:
ATTFilter
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 20:28:53 on 30.03.2011

OS: Windows Vista Home Premium Edition Service Pack 1 (Build 6001), 32-bit
Default Browser: Microsoft Corporation Internet Explorer 7.00.6000.16386

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"iproset.cpl" - "Intel(R) Corporation" - C:\Windows\system32\iproset.cpl
"PhysX.cpl" - ? - C:\Windows\system32\PhysX.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL
"Pando" - "Pando Networks" - C:\Program Files\Pando Networks\Media Booster\PMB.cpl
"PROSet Tools" - "Intel(R) Corporation" - C:\Windows\System32\iPROSet.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys  (File found, but it contains no detailed information)
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\Users\Volker\AppData\Local\Temp\catchme.sys  (File not found)
"enodpl" (enodpl) - ? - C:\Windows\System32\drivers\enodpl.sys  (File found, but it contains no detailed information)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys  (File found, but it contains no detailed information)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"tandpl" (tandpl) - ? - C:\Windows\System32\drivers\tandpl.sys  (File found, but it contains no detailed information)

[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{10880D85-AAD9-4558-ABDC-2AB1552D831F} "LightScribe Control Panel" - "Hewlett-Packard Company" - "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -   (File not found | COM-object registry key not found)
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -   (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -   (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{00020d75-0000-0000-c000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -   (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{555D4D79-4BD2-4094-A395-CFC534424A05} "HP Smart Web Printing" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "DVDVideoSoftTB Toolbar" - "Conduit Ltd." - C:\Program Files\DVDVideoSoft\tbDVD1.dll
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBarLayout" - ? -   (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )-----
{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} "DVDVideoSoftTB Toolbar" - "Conduit Ltd." - C:\Program Files\DVDVideoSoft\tbDVD1.dll
{855F3B16-6D32-4fe6-8A56-BBB695989046} "ICQToolBar" - "ICQ" - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
 "{855F3B16-6D32-4fe6-8A56-BBB695989046}" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{DDE87865-83C5-48c4-8357-2F5B1AA84522} "HP Smart Web Printing ein- oder ausblenden" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
"ICQ7.2" - "ICQ, LLC." - C:\Program Files\ICQ7.2\ICQ.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} "DVDVideoSoftTB Toolbar" - "Conduit Ltd." - C:\Program Files\DVDVideoSoft\tbDVD1.dll
{855F3B16-6D32-4fe6-8A56-BBB695989046} "ICQToolBar" - "ICQ" - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} "DVDVideoSoftTB Toolbar" - "Conduit Ltd." - C:\Program Files\DVDVideoSoft\tbDVD1.dll
{0347C33E-8762-4905-BF09-768834316C61} "HP Print Enhancer" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} "HP Smart BHO Class" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - ? - C:\Program Files\Java\jre6\bin\jp2ssv.dll  (File not found)
{02478D38-C3F9-4efb-9B51-7695ECA05670} "{02478D38-C3F9-4efb-9B51-7695ECA05670}" - ? -   (File not found | COM-object registry key not found)

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Volker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"HP Digital Imaging Monitor.lnk" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe  (Shortcut exists | File exists)
"BTTray.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Pando Media Booster" - ? - C:\Program Files\Pando Networks\Media Booster\PMB.exe
"Steam" - "Valve Corporation" - "c:\program files\steam\steam.exe" -silent
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"HP Software Update" - "Hewlett-Packard" - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"LanguageShortcut" - ? - "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
"M-Audio Taskbar Icon" - "Avid Technology, Inc." - C:\Windows\System32\M-AudioTaskBarIcon.exe
"Malwarebytes' Anti-Malware (reboot)" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
"NetFxUpdate_v1.1.4322" - "Microsoft" - "C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe" 1 v1.1.4322 GAC + NI NID
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"RemoteControl" - "Cyberlink Corp." - "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"doPDF 7 Monitor" - "Softland" - C:\Windows\system32\dopdfmn7.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Bonjour-Dienst" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
"HP CUE DeviceDiscovery Service" (hpqddsvc) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
"hpqcxs08" (hpqcxs08) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
"Intel® PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
"Intel® PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"Samsung Update Plus" (Samsung Update Plus) - ? - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe  (File found, but it contains no detailed information)
"SQL Server (MSSMLBIZ)" (MSSQL$MSSMLBIZ) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
"SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
"SQL Server-Browser" (SQLBrowser) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
"SQL Server-Startdienst für Business Contact Manager" (BcmSqlStartupSvc) - "Microsoft Corporation" - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files\Common Files\Steam\SteamService.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===
         
--- --- ---

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru[/QUOTE]

Alt 30.03.2011, 19:47   #12
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



Ok. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 31.03.2011, 16:43   #13
0815User
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



SASW:

Zitat:
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 03/31/2011 at 05:29 PM

Application Version : 4.50.1002

Core Rules Database Version : 6720
Trace Rules Database Version: 4532

Scan type : Complete Scan
Total Scan Time : 02:18:12

Memory items scanned : 698
Memory threats detected : 0
Registry items scanned : 9793
Registry threats detected : 0
File items scanned : 193488
File threats detected : 6

Adware.Tracking Cookie
C:\Users\Volker\AppData\Roaming\Microsoft\Windows\Cookies\volker@ad.zanox[2].txt
C:\Users\Volker\AppData\Roaming\Microsoft\Windows\Cookies\volker@webmasterplan[1].txt
C:\Users\Volker\AppData\Roaming\Microsoft\Windows\Cookies\volker@maniapub.trackmania[2].txt
C:\Users\Volker\AppData\Roaming\Microsoft\Windows\Cookies\volker@doubleclick[1].txt
C:\Users\Volker\AppData\Roaming\Microsoft\Windows\Cookies\volker@zanox[2].txt
s0.2mdn.net [ C:\Users\Volker\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\XXUXM5T9 ]
Malwarebytes:

Zitat:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6224

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

31.03.2011 14:58:54
mbam-log-2011-03-31 (14-58-54).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 347610
Laufzeit: 1 Stunde(n), 34 Minute(n), 48 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Alt 31.03.2011, 17:42   #14
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



Sieht ok aus, da wurden nur Cookies gefunden.
Noch Probleme oder weitere Funde in der Zwischenzeit?
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 31.03.2011, 20:35   #15
0815User
 
Dateien nach Windows Diagnostic - Standard

Dateien nach Windows Diagnostic



nein nichts, vielen Dank

Antwort

Themen zu Dateien nach Windows Diagnostic
32 bit, 7-zip, adware.gamespyarcade, antivir, audacity, avgntflt.sys, avira, bho, bonjour, conduit, converter, downloader, error, excel.exe, firefox, flash player, home, iexplore.exe, install.exe, ip-adresse, location, logfile, metin2, microsoft office 2003, microsoft office word, mozilla, mp3, nvlddmkm.sys, office 2007, oldtimer, otl scan, otl.exe, pando media booster, plug-in, programdata, realtek, registry, rootkit.tdss.gen, saver, scan, sched.exe, searchplugins, security, security update, server, shell32.dll, skype.exe, software, start menu, svchost.exe, teamspeak, trojan.dropper.pgen, trojaner, vista, windows, ändern




Ähnliche Themen: Dateien nach Windows Diagnostic


  1. Win 7 - AVG entdeckt Virus - *.sys dateien im windows ordner- Nach Löschung entstehen neue befallene Dateien
    Plagegeister aller Art und deren Bekämpfung - 14.09.2013 (13)
  2. Windows Diagnostic vollständig entfernen
    Plagegeister aller Art und deren Bekämpfung - 03.05.2011 (11)
  3. Nach dem "Windows diagnostic" virus- alle programme wird nicht angezeigt+ skype funzt. nicht
    Plagegeister aller Art und deren Bekämpfung - 24.04.2011 (6)
  4. HDD Diagnostic entfernt,Desktop ist fast leer u. kein Zugriff auf Programme u. Dateien
    Plagegeister aller Art und deren Bekämpfung - 17.04.2011 (36)
  5. Windows Diagnostic - Verzeichnisse unsichtbar
    Plagegeister aller Art und deren Bekämpfung - 06.04.2011 (15)
  6. Windows Diagnostic - richtig entfernt?
    Plagegeister aller Art und deren Bekämpfung - 05.04.2011 (23)
  7. Windows Diagnostic, Daten wiederherstellen
    Log-Analyse und Auswertung - 02.04.2011 (28)
  8. Windows diagnostic Trojaner, Logs
    Log-Analyse und Auswertung - 27.03.2011 (10)
  9. Windows Diagnostic - Opfer -
    Plagegeister aller Art und deren Bekämpfung - 24.03.2011 (6)
  10. Windows Diagnostic Malware entfernen
    Log-Analyse und Auswertung - 24.03.2011 (4)
  11. Windows Diagnostic wirklich entfernt? - Log files
    Plagegeister aller Art und deren Bekämpfung - 24.03.2011 (16)
  12. Windows Diagnostic und Folgen
    Log-Analyse und Auswertung - 24.03.2011 (8)
  13. Windows Diagnostic Desktop Symbole verschunden
    Plagegeister aller Art und deren Bekämpfung - 22.03.2011 (1)
  14. Windows Diagnostic - entfernt oder nicht?
    Log-Analyse und Auswertung - 22.03.2011 (1)
  15. Virus Windows Diagnostic > Alle Dateien gelöscht
    Log-Analyse und Auswertung - 22.03.2011 (1)
  16. Lösung zu Windows Diagnostic - Dateien sind nicht weg!
    Log-Analyse und Auswertung - 22.03.2011 (0)
  17. Windows Diagnostic entfernen
    Anleitungen, FAQs & Links - 18.03.2011 (2)

Zum Thema Dateien nach Windows Diagnostic - Hallo, ich hatte vor einigen Tagen den Trojaner "Windows Diagnostic" auf meinem Pc. Konnte ihn mit der guten Anleitung hier aus dem Forum schnell entfernen. Allerdings werden jetzt sämtliche Dateien, - Dateien nach Windows Diagnostic...
Archiv
Du betrachtest: Dateien nach Windows Diagnostic auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.