Vielen Dank für die Antwort und für das Wilkommen. Kann mich leider erst jetzt melden (habe seit vorgestern 2 junge Kätzchen, und die lassen mir kaum Zeit für den PC)
Unter Windows habe ich nach wie vor nach Systemstart eine Virenmeldung von Antivir, dass ich im Roaming/Temp-Ordner ein Trojaner befindet, nach Löschung, komtt ein neuer (mit anderem Dateinamen)
Hier die geforderten Logs:
Vollscan Malewarebytes Code:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Datenbank Version: 4315
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
16.07.2010 17:56:27
mbam-log-2010-07-16 (17-56-27).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|I:\|K:\|)
Durchsuchte Objekte: 356329
Laufzeit: 1 Stunde(n), 44 Minute(n), 4 Sekunde(n)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 6
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
E:\Documents\Sonstiges\Funny Things\Funny Mails\Exe\***.exe (Joke.VV) -> Quarantined and deleted successfully.
E:\Downloads\install_flash_player.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
E:\Downloads\ZwinkySetup2.3.67.1.ZJman000.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
I:\Sonstiges\run with parameters\rwparam-1.1.1-setup.exe (Malware.Packer) -> Quarantined and deleted successfully.
I:\System\runwithparameters.exe (Malware.Packer) -> Quarantined and deleted successfully.
I:\Internet\Anonymität\proxyi.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. Meldung 1 ist mir klar.. die Dateil besitze ich seit Jahren, und ist leidglich ein kleines Joke-Programm.
Die beiden Dateien in Downloads machen mich stutzig, Antivir hatte damals beim Download nichts festgestellt.
nrevös machen mich die beiden "run with parameters", welche "offensichtlich" in der Explorer-Ansicht (auch unter Linux) überhaupt nicht vorhanden sind...
Hier noch die OLT Logs: Code:
OTL logfile created on: 16.07.2010 18:01:59 - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = E:\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000807 | Country: Schweiz | Language: DES | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 68.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48.73 Gb Total Space | 15.20 Gb Free Space | 31.19% Space Free | Partition Type: NTFS
Drive D: | 112.70 Gb Total Space | 110.44 Gb Free Space | 98.00% Space Free | Partition Type: NTFS
Drive E: | 97.66 Gb Total Space | 89.94 Gb Free Space | 92.10% Space Free | Partition Type: NTFS
Drive F: | 390.62 Gb Total Space | 361.05 Gb Free Space | 92.43% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
Drive H: | 23.05 Gb Total Space | 23.02 Gb Free Space | 99.88% Space Free | Partition Type: UDF
Drive I: | 149.88 Gb Total Space | 75.54 Gb Free Space | 50.40% Space Free | Partition Type: NTFS
Drive K: | 83.01 Gb Total Space | 57.44 Gb Free Space | 69.20% Space Free | Partition Type: NTFS
Computer Name: PC
Current User Name: ***
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - E:\Downloads\OTL.exe (OldTimer Tools)
PRC - D:\Sonstiges\PSI\psi.exe (Secunia)
PRC - C:\Programme\Opera\opera.exe (Opera Software)
PRC - D:\Sonstiges\AUC\AUC Autostart.exe ()
PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Programme\TeamViewer\Version5\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Programme\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft IntelliType Pro\dpupdchk.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - D:\Internet\Team Viewer\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
PRC - D:\Sonstiges\CDBurnerXP\NMSAccessU.exe ()
========== Modules (SafeList) ==========
MOD - E:\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (AUCAutostartWinService) -- D:\Sonstiges\AUC\AUC Autostart.exe ()
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (TeamViewer5) -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (IAStorDataMgrSvc) Intel(R) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (WwanSvc) -- C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) -- C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) -- C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) -- C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) -- C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) -- C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) -- C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) -- C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) -- C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) -- C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) -- C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) -- C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX-Installer (AxInstSV) -- C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) -- C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) -- C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (TeamViewer4) -- D:\Internet\Team Viewer\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (NMSAccessU) -- D:\Sonstiges\CDBurnerXP\NMSAccessU.exe ()
========== Driver Services (SafeList) ==========
DRV - (PSI) -- C:\Windows\System32\drivers\psi_mf.sys (Secunia)
DRV - (KSecPkg) -- C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (dc3d) MS Hardware Device Detection Driver (USB) -- C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (cmdide) -- C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) -- C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) -- C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) -- C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) -- C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) -- C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) -- C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) -- C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) -- C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) -- C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) -- C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) -- C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) -- C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) -- C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) -- C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) -- C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) -- C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) -- C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) -- C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) -- C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) -- C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) -- C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) -- C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) -- C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) -- C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) -- C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) -- C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) -- C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) -- C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) -- C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) -- C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) -- C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) -- C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) -- C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) -- C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) -- C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) -- C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) -- C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) -- C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) -- C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) -- C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (vwififlt) -- C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) -- C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) -- C:\Windows\System32\drivers\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) -- C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) -- C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) -- C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) -- C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) -- C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) -- C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) -- C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) -- C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) -- C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) -- C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) -- C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) -- C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) -- C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (netr73) -- C:\Windows\System32\drivers\netr73.sys (Ralink Technology, Corp.)
DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) -- C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) -- C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (Point32) -- C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (NuidFltr) -- C:\Windows\System32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (VClone) -- C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (RTL8167) -- C:\Windows\System32\drivers\Rt86win7.sys (Realtek Corporation )
DRV - (ElbyCDIO) -- C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (CLBUDFR) -- C:\Windows\System32\drivers\CLBUDFR.sys (CyberLink Corporation.)
DRV - (CLBStor) -- C:\Windows\System32\drivers\CLBStor.sys (Cyberlink Co.,Ltd.)
DRV - (CrystalSysInfo) -- D:\Multimedia\MediaCoder iPod Edition\SysInfo.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://ch.msn.com/default.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-ch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 40 73 E2 08 43 C0 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems: screencaptureelite@plugin:1.0.0.12
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.99
FF - prefs.js..extensions.enabledItems: foxmarks@kei.com:3.7.8
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100503
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.47.4
FF - prefs.js..extensions.enabledItems: {95f24680-9e31-11da-a746-0800200c9a66}:0.1.5.5
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.1
FF - prefs.js..extensions.enabledItems: YoutubeDownloader@PeterOlayev.com:1.4
FF - prefs.js..extensions.enabledItems: {8620c15f-30dc-4dba-a131-7c5d20cf4a29}:2.0.3
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.07.14 17:08:29 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.07.10 16:09:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.07.10 16:09:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\SeaMonkey 2.0.4\extensions\\Components: D:\Internet\Seamonkey\components [2010.07.08 12:33:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\SeaMonkey 2.0.4\extensions\\Plugins: D:\Internet\Seamonkey\plugins [2010.07.08 12:33:51 | 000,000,000 | ---D | M]
[2010.04.15 13:43:59 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Extensions
[2010.03.04 18:42:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.04.15 13:43:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions\{92650c4d-4b8e-4d2a-b7eb-24ecf4f6b63a}
[2010.07.12 20:14:10 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions
[2010.03.04 19:20:41 | 000,000,000 | ---D | M] (Linkification) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2010.03.04 19:20:40 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2010.03.04 19:20:40 | 000,000,000 | ---D | M] (Speed Dial) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010.07.09 14:26:39 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010.04.17 23:08:20 | 000,000,000 | ---D | M] (Nightly Tester Tools) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29}
[2010.03.04 19:20:40 | 000,000,000 | ---D | M] (Update Notifier) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
[2010.05.12 11:30:22 | 000,000,000 | ---D | M] (WOT) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010.04.17 23:09:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{BFB5F154-9212-46F3-B547-AC6106030A54}
[2010.07.12 20:14:07 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.04.09 11:18:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010.07.09 14:26:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010.06.05 12:43:52 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010.07.09 14:26:38 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\foxmarks@kei.com
[2010.04.09 11:18:09 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\screencaptureelite@plugin
[2010.04.16 18:16:24 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\YoutubeDownloader@PeterOlayev.com
[2010.07.16 16:03:16 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions
[2010.07.08 18:06:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2010.04.16 18:13:51 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2010.04.17 13:03:27 | 000,000,000 | ---D | M] (SmoothWheel (mozdev.org)) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}
[2010.07.08 18:06:52 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010.07.15 11:47:14 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.04.15 14:49:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010.06.04 13:30:35 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010.04.15 14:49:33 | 000,000,000 | ---D | M] (MinimizeToTray Plus) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{de1b245c-de57-11da-ba2d-0050c2490048}
[2010.04.15 14:49:27 | 000,000,000 | ---D | M] (WorldIP) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{f36c6cd1-da73-491d-b290-8fc9115bfa55}
[2010.07.15 11:47:14 | 000,000,000 | ---D | M] (Display Mail User Agent) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{F8147CF4-B9E3-445B-AA87-081ED66548F8}
[2010.04.15 14:49:27 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\closy@gemal.dk
[2010.06.04 13:30:35 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\custombuttons@xsms.org
[2010.07.08 18:06:52 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\formhistory@yahoo.com
[2010.07.08 18:06:52 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\inspector@mozilla.org
[2010.07.15 11:47:14 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\QuickPasswords@axelg.com
[2010.02.26 14:23:41 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.07.10 16:09:46 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.07.10 16:09:46 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.07.10 16:09:46 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.07.10 16:09:46 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.07.10 16:09:46 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programme\Hp\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Programme\Hp\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] D:\Internet\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\syscron.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: HP Smart Web Printing ein- oder ausblenden - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Programme\Hp\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008.03.29 01:41:00 | 000,000,039 | ---- | M] () - I:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{10b47047-077c-11df-b041-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{10b47047-077c-11df-b041-806e6f6e6963}\Shell\AutoRun\command - "" = G:\Setup.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010.07.16 17:01:39 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Microsoft Games
[2010.07.16 16:36:38 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft.NET
[2010.07.16 16:08:31 | 000,000,000 | ---D | C] -- C:\Programme\Vertrix 2
[2010.07.15 12:11:06 | 000,000,000 | ---D | C] -- C:\Programme\trend micro
[2010.07.15 12:11:06 | 000,000,000 | ---D | C] -- C:\rsit
[2010.07.15 11:03:16 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes
[2010.07.15 11:03:08 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.07.15 11:03:07 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.07.15 11:03:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.07.15 10:47:37 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2010.07.15 10:47:37 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2010.07.15 10:47:37 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2010.07.15 10:45:00 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2010.07.15 10:44:58 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2010.07.15 10:44:57 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010.07.15 10:44:57 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2010.07.15 10:44:57 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2010.07.15 10:44:54 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2010.07.15 10:44:53 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdri.dll
[2010.07.15 10:44:53 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2010.07.15 10:44:53 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2010.07.15 10:44:49 | 002,326,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2010.07.15 10:44:49 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\asycfilt.dll
[2010.07.15 10:44:47 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010.07.15 10:44:16 | 000,293,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2010.07.15 10:44:16 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2010.07.15 10:40:23 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Intel Corporation
[2010.07.14 17:10:04 | 000,000,000 | ---D | C] -- C:\Intel
[2010.07.14 17:10:02 | 000,000,000 | ---D | C] -- C:\Programme\Intel
[2010.07.14 17:10:02 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\InstallShield
[2010.07.14 17:09:54 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\WinBatch
[2010.07.13 10:48:44 | 000,000,000 | ---D | C] -- e:\Documents\Neu
[2010.07.13 10:48:08 | 000,000,000 | ---D | C] -- e:\Documents\pdf24
[2010.07.09 00:01:59 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\posters
[2010.07.08 23:34:54 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\gtk-2.0
[2010.07.08 23:11:34 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\griffith
[2010.07.08 22:42:34 | 002,945,024 | ---- | C] (hxxp://mediainfo.sourceforge.net) -- C:\Windows\System32\MediaInfo.dll
[2010.07.08 22:42:34 | 000,141,312 | ---- | C] (Info-ZIP) -- C:\Windows\System32\Zip32.dll
[2010.07.08 22:42:34 | 000,102,400 | ---- | C] (Info-ZIP) -- C:\Windows\System32\unzip32.dll
[2010.07.08 22:42:31 | 000,061,440 | -H-- | C] (SynApp GmbH) -- C:\Windows\System32\ErrExplorer.dll
[2010.07.08 22:42:30 | 000,688,640 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmmx01.dll
[2010.07.08 22:42:30 | 000,414,720 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmll1100.lng
[2010.07.08 22:42:30 | 000,349,184 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmll11pw.llx
[2010.07.08 22:42:30 | 000,165,584 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmll11o.ocx
[2010.07.08 22:42:29 | 002,899,968 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmll11.dll
[2010.07.08 22:42:29 | 001,399,296 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmct11.dll
[2010.07.08 22:42:29 | 001,378,304 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmls11.dll
[2010.07.08 22:42:29 | 000,893,952 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmbr11.dll
[2010.07.08 22:42:29 | 000,739,328 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmdw11.dll
[2010.07.08 22:42:29 | 000,684,032 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmll11xl.dll
[2010.07.08 22:42:29 | 000,662,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscomct2.ocx
[2010.07.08 22:42:29 | 000,489,128 | ---- | C] (ComponentOne) -- C:\Windows\System32\Vsflex7.ocx
[2010.07.08 22:42:29 | 000,416,528 | ---- | C] (Microsoft Corporation ) -- C:\Windows\System32\comct332.ocx
[2010.07.08 22:42:29 | 000,351,232 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmpr11.dll
[2010.07.08 22:42:29 | 000,337,920 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmut11.dll
[2010.07.08 22:42:29 | 000,224,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tabctl32.ocx
[2010.07.08 22:42:29 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\stdftde.dll
[2010.07.08 22:42:28 | 001,009,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mschrt20.ocx
[2010.07.08 22:42:28 | 000,438,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSHFLXGD.OCX
[2010.07.08 22:42:28 | 000,166,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msmask32.ocx
[2010.07.08 22:42:28 | 000,152,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comdlg32.ocx
[2010.07.08 22:42:28 | 000,125,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6DE.dll
[2010.07.08 22:42:28 | 000,000,000 | ---D | C] -- C:\ProgramData\M-DVD.Org V2
[2010.07.08 20:16:27 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\AUC
[2010.07.07 16:05:32 | 000,014,904 | ---- | C] (Secunia) -- C:\Windows\System32\drivers\psi_mf.sys
[2010.07.01 14:00:37 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Broad Intelligence
========== Files - Modified Within 30 Days ==========
[2010.07.16 17:59:08 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.07.16 17:59:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.07.16 17:58:58 | 2616,684,544 | -HS- | M] () -- C:\hiberfil.sys
[2010.07.16 17:58:09 | 002,621,440 | -HS- | M] () -- C:\Users\***\NTUSER.DAT
[2010.07.16 17:57:59 | 006,093,368 | -H-- | M] () -- C:\Users\***\AppData\Local\IconCache.db
[2010.07.16 16:38:19 | 002,278,190 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.07.16 16:38:19 | 000,621,350 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.07.16 16:38:19 | 000,008,816 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.07.16 16:03:31 | 000,000,668 | ---- | M] () -- C:\Users\***\Desktop\Waldmeister Sause Winteredition (Gratisversion).lnk
[2010.07.16 15:56:56 | 000,013,440 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.07.16 15:56:56 | 000,013,440 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.07.15 11:53:05 | 000,023,612 | ---- | M] () -- C:\Users\***\Desktop\cab_banane.jpg
[2010.07.15 11:26:42 | 000,303,120 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.07.15 11:03:10 | 000,000,662 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.07.14 17:08:43 | 000,023,687 | ---- | M] () -- C:\Windows\hpqins15.dat
[2010.07.13 10:44:41 | 000,000,722 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2010.07.12 22:45:56 | 000,000,721 | ---- | M] () -- C:\Users\***\Desktop\ABC Amber SeaMonkey Converter.lnk
[2010.07.11 15:09:51 | 000,000,673 | ---- | M] () -- C:\Users\Public\Desktop\Anti-Twin.lnk
[2010.07.09 16:07:07 | 000,000,218 | ---- | M] () -- C:\Users\***\.recently-used.xbel
[2010.07.09 00:02:10 | 000,032,603 | ---- | M] () -- C:\Users\***\Desktop\griffith_list.xml
[2010.07.09 00:01:59 | 000,013,876 | ---- | M] () -- C:\Users\***\Desktop\page_1.htm
[2010.07.09 00:01:59 | 000,001,799 | ---- | M] () -- C:\Users\***\Desktop\gray.css
[2010.07.09 00:00:52 | 000,004,239 | ---- | M] () -- C:\Users\***\Desktop\griffith_simple_list.pdf
[2010.07.08 23:11:23 | 000,000,630 | ---- | M] () -- C:\Users\***\Desktop\Griffith.lnk
[2010.07.08 23:00:50 | 002,064,384 | ---- | M] () -- e:\Documents\M-DVD_Org.db
[2010.07.08 22:42:36 | 000,000,743 | ---- | M] () -- C:\Users\***\Desktop\M-DVD.Org V2.lnk
[2010.07.08 20:18:43 | 000,000,678 | ---- | M] () -- C:\Users\***\Desktop\Magic MP3 Tagger.lnk
[2010.07.08 13:35:44 | 000,000,036 | ---- | M] () -- C:\Users\***\.33a11c88
[2010.07.07 16:05:32 | 000,014,904 | ---- | M] (Secunia) -- C:\Windows\System32\drivers\psi_mf.sys
[2010.06.30 18:04:43 | 000,029,520 | ---- | M] () -- e:\Documents\Gmail - ***.mht
========== Files Created - No Company Name ==========
[2010.07.16 16:03:31 | 000,000,668 | ---- | C] () -- C:\Users\***\Desktop\Waldmeister Sause Winteredition (Gratisversion).lnk
[2010.07.15 11:53:05 | 000,023,612 | ---- | C] () -- C:\Users\***\Desktop\cab_banane.jpg
[2010.07.15 11:03:10 | 000,000,662 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.07.14 17:08:11 | 000,023,687 | ---- | C] () -- C:\Windows\hpqins15.dat
[2010.07.13 10:44:41 | 000,000,722 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2010.07.12 22:45:56 | 000,000,721 | ---- | C] () -- C:\Users\***\Desktop\ABC Amber SeaMonkey Converter.lnk
[2010.07.12 21:18:13 | 000,000,000 | R--- | C] () -- C:\Users\***\AppData\Roaming\IIF1i.txt
[2010.07.11 15:09:51 | 000,000,673 | ---- | C] () -- C:\Users\Public\Desktop\Anti-Twin.lnk
[2010.07.09 16:07:07 | 000,000,218 | ---- | C] () -- C:\Users\***\.recently-used.xbel
[2010.07.09 14:33:27 | 000,029,520 | ---- | C] () -- e:\Documents\Gmail - ***.mht
[2010.07.09 00:02:10 | 000,032,603 | ---- | C] () -- C:\Users\***\Desktop\griffith_list.xml
[2010.07.09 00:01:59 | 000,013,876 | ---- | C] () -- C:\Users\***\Desktop\page_1.htm
[2010.07.09 00:01:59 | 000,001,799 | ---- | C] () -- C:\Users\***\Desktop\gray.css
[2010.07.09 00:00:52 | 000,004,239 | ---- | C] () -- C:\Users\***\Desktop\griffith_simple_list.pdf
[2010.07.08 23:11:23 | 000,000,630 | ---- | C] () -- C:\Users\***\Desktop\Griffith.lnk
[2010.07.08 22:52:40 | 002,064,384 | ---- | C] () -- e:\Documents\M-DVD_Org.db
[2010.07.08 22:42:36 | 000,000,743 | ---- | C] () -- C:\Users\***\Desktop\M-DVD.Org V2.lnk
[2010.07.08 22:42:34 | 000,675,840 | ---- | C] () -- C:\Windows\System32\AudioGenie2.ocx
[2010.07.08 22:42:30 | 001,161,492 | ---- | C] () -- C:\Windows\System32\cmLL1100.chm
[2010.07.08 22:42:30 | 000,425,984 | ---- | C] () -- C:\Windows\System32\cmmx0100.lng
[2010.07.08 20:18:43 | 000,000,678 | ---- | C] () -- C:\Users\***\Desktop\Magic MP3 Tagger.lnk
[2010.07.08 13:35:44 | 000,000,036 | ---- | C] () -- C:\Users\***\.33a11c88
[2010.04.05 17:32:41 | 000,000,295 | ---- | C] () -- C:\Windows\lgfwup.ini
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:D4BB0AD6
@Alternate Data Stream - 213 bytes -> C:\ProgramData\TEMP:35A81752
@Alternate Data Stream - 208 bytes -> C:\ProgramData\TEMP:B1FBA7E1
@Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:66AA0486
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:ED2998F5
< End of report > Und "Extras": Code:
OTL logfile created on: 16.07.2010 18:01:59 - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = E:\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000807 | Country: Schweiz | Language: DES | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 68.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48.73 Gb Total Space | 15.20 Gb Free Space | 31.19% Space Free | Partition Type: NTFS
Drive D: | 112.70 Gb Total Space | 110.44 Gb Free Space | 98.00% Space Free | Partition Type: NTFS
Drive E: | 97.66 Gb Total Space | 89.94 Gb Free Space | 92.10% Space Free | Partition Type: NTFS
Drive F: | 390.62 Gb Total Space | 361.05 Gb Free Space | 92.43% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
Drive H: | 23.05 Gb Total Space | 23.02 Gb Free Space | 99.88% Space Free | Partition Type: UDF
Drive I: | 149.88 Gb Total Space | 75.54 Gb Free Space | 50.40% Space Free | Partition Type: NTFS
Drive K: | 83.01 Gb Total Space | 57.44 Gb Free Space | 69.20% Space Free | Partition Type: NTFS
Computer Name: PC
Current User Name: ***
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - E:\Downloads\OTL.exe (OldTimer Tools)
PRC - D:\Sonstiges\PSI\psi.exe (Secunia)
PRC - C:\Programme\Opera\opera.exe (Opera Software)
PRC - D:\Sonstiges\AUC\AUC Autostart.exe ()
PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Programme\TeamViewer\Version5\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Programme\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft IntelliType Pro\dpupdchk.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - D:\Internet\Team Viewer\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
PRC - D:\Sonstiges\CDBurnerXP\NMSAccessU.exe ()
========== Modules (SafeList) ==========
MOD - E:\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (AUCAutostartWinService) -- D:\Sonstiges\AUC\AUC Autostart.exe ()
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (TeamViewer5) -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (IAStorDataMgrSvc) Intel(R) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (WwanSvc) -- C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) -- C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) -- C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) -- C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) -- C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) -- C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) -- C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) -- C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) -- C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) -- C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) -- C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) -- C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX-Installer (AxInstSV) -- C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) -- C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) -- C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (TeamViewer4) -- D:\Internet\Team Viewer\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (NMSAccessU) -- D:\Sonstiges\CDBurnerXP\NMSAccessU.exe ()
========== Driver Services (SafeList) ==========
DRV - (PSI) -- C:\Windows\System32\drivers\psi_mf.sys (Secunia)
DRV - (KSecPkg) -- C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (dc3d) MS Hardware Device Detection Driver (USB) -- C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (cmdide) -- C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) -- C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) -- C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) -- C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) -- C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) -- C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) -- C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) -- C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) -- C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) -- C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) -- C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) -- C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) -- C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) -- C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) -- C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) -- C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) -- C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) -- C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) -- C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) -- C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) -- C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) -- C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) -- C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) -- C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) -- C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) -- C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) -- C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) -- C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) -- C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) -- C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) -- C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) -- C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) -- C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) -- C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) -- C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) -- C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) -- C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) -- C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) -- C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) -- C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) -- C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (vwififlt) -- C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) -- C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) -- C:\Windows\System32\drivers\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) -- C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) -- C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) -- C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) -- C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) -- C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) -- C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) -- C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) -- C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) -- C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) -- C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) -- C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) -- C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) -- C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (netr73) -- C:\Windows\System32\drivers\netr73.sys (Ralink Technology, Corp.)
DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) -- C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) -- C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (Point32) -- C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (NuidFltr) -- C:\Windows\System32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (VClone) -- C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (RTL8167) -- C:\Windows\System32\drivers\Rt86win7.sys (Realtek Corporation )
DRV - (ElbyCDIO) -- C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (CLBUDFR) -- C:\Windows\System32\drivers\CLBUDFR.sys (CyberLink Corporation.)
DRV - (CLBStor) -- C:\Windows\System32\drivers\CLBStor.sys (Cyberlink Co.,Ltd.)
DRV - (CrystalSysInfo) -- D:\Multimedia\MediaCoder iPod Edition\SysInfo.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://ch.msn.com/default.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-ch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 40 73 E2 08 43 C0 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems: screencaptureelite@plugin:1.0.0.12
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.99
FF - prefs.js..extensions.enabledItems: foxmarks@kei.com:3.7.8
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100503
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.47.4
FF - prefs.js..extensions.enabledItems: {95f24680-9e31-11da-a746-0800200c9a66}:0.1.5.5
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.1
FF - prefs.js..extensions.enabledItems: YoutubeDownloader@PeterOlayev.com:1.4
FF - prefs.js..extensions.enabledItems: {8620c15f-30dc-4dba-a131-7c5d20cf4a29}:2.0.3
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.07.14 17:08:29 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.07.10 16:09:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.07.10 16:09:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\SeaMonkey 2.0.4\extensions\\Components: D:\Internet\Seamonkey\components [2010.07.08 12:33:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\SeaMonkey 2.0.4\extensions\\Plugins: D:\Internet\Seamonkey\plugins [2010.07.08 12:33:51 | 000,000,000 | ---D | M]
[2010.04.15 13:43:59 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Extensions
[2010.03.04 18:42:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.04.15 13:43:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions\{92650c4d-4b8e-4d2a-b7eb-24ecf4f6b63a}
[2010.07.12 20:14:10 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions
[2010.03.04 19:20:41 | 000,000,000 | ---D | M] (Linkification) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2010.03.04 19:20:40 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2010.03.04 19:20:40 | 000,000,000 | ---D | M] (Speed Dial) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010.07.09 14:26:39 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010.04.17 23:08:20 | 000,000,000 | ---D | M] (Nightly Tester Tools) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29}
[2010.03.04 19:20:40 | 000,000,000 | ---D | M] (Update Notifier) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
[2010.05.12 11:30:22 | 000,000,000 | ---D | M] (WOT) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010.04.17 23:09:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{BFB5F154-9212-46F3-B547-AC6106030A54}
[2010.07.12 20:14:07 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.04.09 11:18:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010.07.09 14:26:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010.06.05 12:43:52 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010.07.09 14:26:38 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\foxmarks@kei.com
[2010.04.09 11:18:09 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\screencaptureelite@plugin
[2010.04.16 18:16:24 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\g0dei4ie.default\extensions\YoutubeDownloader@PeterOlayev.com
[2010.07.16 16:03:16 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions
[2010.07.08 18:06:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2010.04.16 18:13:51 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2010.04.17 13:03:27 | 000,000,000 | ---D | M] (SmoothWheel (mozdev.org)) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}
[2010.07.08 18:06:52 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010.07.15 11:47:14 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.04.15 14:49:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010.06.04 13:30:35 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010.04.15 14:49:33 | 000,000,000 | ---D | M] (MinimizeToTray Plus) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{de1b245c-de57-11da-ba2d-0050c2490048}
[2010.04.15 14:49:27 | 000,000,000 | ---D | M] (WorldIP) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{f36c6cd1-da73-491d-b290-8fc9115bfa55}
[2010.07.15 11:47:14 | 000,000,000 | ---D | M] (Display Mail User Agent) -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\{F8147CF4-B9E3-445B-AA87-081ED66548F8}
[2010.04.15 14:49:27 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\closy@gemal.dk
[2010.06.04 13:30:35 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\custombuttons@xsms.org
[2010.07.08 18:06:52 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\formhistory@yahoo.com
[2010.07.08 18:06:52 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\inspector@mozilla.org
[2010.07.15 11:47:14 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\SeaMonkey\Profiles\z48c90l4.default\extensions\QuickPasswords@axelg.com
[2010.02.26 14:23:41 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.07.10 16:09:46 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.07.10 16:09:46 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.07.10 16:09:46 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.07.10 16:09:46 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.07.10 16:09:46 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programme\Hp\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Programme\Hp\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] D:\Internet\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\syscron.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: HP Smart Web Printing ein- oder ausblenden - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Programme\Hp\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008.03.29 01:41:00 | 000,000,039 | ---- | M] () - I:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{10b47047-077c-11df-b041-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{10b47047-077c-11df-b041-806e6f6e6963}\Shell\AutoRun\command - "" = G:\Setup.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010.07.16 17:01:39 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Microsoft Games
[2010.07.16 16:36:38 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft.NET
[2010.07.16 16:08:31 | 000,000,000 | ---D | C] -- C:\Programme\Vertrix 2
[2010.07.15 12:11:06 | 000,000,000 | ---D | C] -- C:\Programme\trend micro
[2010.07.15 12:11:06 | 000,000,000 | ---D | C] -- C:\rsit
[2010.07.15 11:03:16 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes
[2010.07.15 11:03:08 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.07.15 11:03:07 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.07.15 11:03:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.07.15 10:47:37 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2010.07.15 10:47:37 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2010.07.15 10:47:37 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2010.07.15 10:45:00 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2010.07.15 10:44:58 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2010.07.15 10:44:57 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010.07.15 10:44:57 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2010.07.15 10:44:57 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2010.07.15 10:44:54 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2010.07.15 10:44:53 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdri.dll
[2010.07.15 10:44:53 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2010.07.15 10:44:53 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2010.07.15 10:44:49 | 002,326,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2010.07.15 10:44:49 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\asycfilt.dll
[2010.07.15 10:44:47 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010.07.15 10:44:16 | 000,293,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2010.07.15 10:44:16 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2010.07.15 10:40:23 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Intel Corporation
[2010.07.14 17:10:04 | 000,000,000 | ---D | C] -- C:\Intel
[2010.07.14 17:10:02 | 000,000,000 | ---D | C] -- C:\Programme\Intel
[2010.07.14 17:10:02 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\InstallShield
[2010.07.14 17:09:54 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\WinBatch
[2010.07.13 10:48:44 | 000,000,000 | ---D | C] -- e:\Documents\Neu
[2010.07.13 10:48:08 | 000,000,000 | ---D | C] -- e:\Documents\pdf24
[2010.07.09 00:01:59 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\posters
[2010.07.08 23:34:54 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\gtk-2.0
[2010.07.08 23:11:34 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\griffith
[2010.07.08 22:42:34 | 002,945,024 | ---- | C] (hxxp://mediainfo.sourceforge.net) -- C:\Windows\System32\MediaInfo.dll
[2010.07.08 22:42:34 | 000,141,312 | ---- | C] (Info-ZIP) -- C:\Windows\System32\Zip32.dll
[2010.07.08 22:42:34 | 000,102,400 | ---- | C] (Info-ZIP) -- C:\Windows\System32\unzip32.dll
[2010.07.08 22:42:31 | 000,061,440 | -H-- | C] (SynApp GmbH) -- C:\Windows\System32\ErrExplorer.dll
[2010.07.08 22:42:30 | 000,688,640 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmmx01.dll
[2010.07.08 22:42:30 | 000,414,720 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmll1100.lng
[2010.07.08 22:42:30 | 000,349,184 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmll11pw.llx
[2010.07.08 22:42:30 | 000,165,584 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmll11o.ocx
[2010.07.08 22:42:29 | 002,899,968 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmll11.dll
[2010.07.08 22:42:29 | 001,399,296 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmct11.dll
[2010.07.08 22:42:29 | 001,378,304 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmls11.dll
[2010.07.08 22:42:29 | 000,893,952 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmbr11.dll
[2010.07.08 22:42:29 | 000,739,328 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmdw11.dll
[2010.07.08 22:42:29 | 000,684,032 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmll11xl.dll
[2010.07.08 22:42:29 | 000,662,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscomct2.ocx
[2010.07.08 22:42:29 | 000,489,128 | ---- | C] (ComponentOne) -- C:\Windows\System32\Vsflex7.ocx
[2010.07.08 22:42:29 | 000,416,528 | ---- | C] (Microsoft Corporation ) -- C:\Windows\System32\comct332.ocx
[2010.07.08 22:42:29 | 000,351,232 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmpr11.dll
[2010.07.08 22:42:29 | 000,337,920 | ---- | C] (combit GmbH) -- C:\Windows\System32\cmut11.dll
[2010.07.08 22:42:29 | 000,224,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tabctl32.ocx
[2010.07.08 22:42:29 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\stdftde.dll
[2010.07.08 22:42:28 | 001,009,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mschrt20.ocx
[2010.07.08 22:42:28 | 000,438,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSHFLXGD.OCX
[2010.07.08 22:42:28 | 000,166,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msmask32.ocx
[2010.07.08 22:42:28 | 000,152,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comdlg32.ocx
[2010.07.08 22:42:28 | 000,125,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6DE.dll
[2010.07.08 22:42:28 | 000,000,000 | ---D | C] -- C:\ProgramData\M-DVD.Org V2
[2010.07.08 20:16:27 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\AUC
[2010.07.07 16:05:32 | 000,014,904 | ---- | C] (Secunia) -- C:\Windows\System32\drivers\psi_mf.sys
[2010.07.01 14:00:37 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Broad Intelligence
========== Files - Modified Within 30 Days ==========
[2010.07.16 17:59:08 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.07.16 17:59:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.07.16 17:58:58 | 2616,684,544 | -HS- | M] () -- C:\hiberfil.sys
[2010.07.16 17:58:09 | 002,621,440 | -HS- | M] () -- C:\Users\***\NTUSER.DAT
[2010.07.16 17:57:59 | 006,093,368 | -H-- | M] () -- C:\Users\***\AppData\Local\IconCache.db
[2010.07.16 16:38:19 | 002,278,190 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.07.16 16:38:19 | 000,621,350 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.07.16 16:38:19 | 000,008,816 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.07.16 16:03:31 | 000,000,668 | ---- | M] () -- C:\Users\***\Desktop\Waldmeister Sause Winteredition (Gratisversion).lnk
[2010.07.16 15:56:56 | 000,013,440 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.07.16 15:56:56 | 000,013,440 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.07.15 11:53:05 | 000,023,612 | ---- | M] () -- C:\Users\***\Desktop\cab_banane.jpg
[2010.07.15 11:26:42 | 000,303,120 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.07.15 11:03:10 | 000,000,662 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.07.14 17:08:43 | 000,023,687 | ---- | M] () -- C:\Windows\hpqins15.dat
[2010.07.13 10:44:41 | 000,000,722 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2010.07.12 22:45:56 | 000,000,721 | ---- | M] () -- C:\Users\***\Desktop\ABC Amber SeaMonkey Converter.lnk
[2010.07.11 15:09:51 | 000,000,673 | ---- | M] () -- C:\Users\Public\Desktop\Anti-Twin.lnk
[2010.07.09 16:07:07 | 000,000,218 | ---- | M] () -- C:\Users\***\.recently-used.xbel
[2010.07.09 00:02:10 | 000,032,603 | ---- | M] () -- C:\Users\***\Desktop\griffith_list.xml
[2010.07.09 00:01:59 | 000,013,876 | ---- | M] () -- C:\Users\***\Desktop\page_1.htm
[2010.07.09 00:01:59 | 000,001,799 | ---- | M] () -- C:\Users\***\Desktop\gray.css
[2010.07.09 00:00:52 | 000,004,239 | ---- | M] () -- C:\Users\***\Desktop\griffith_simple_list.pdf
[2010.07.08 23:11:23 | 000,000,630 | ---- | M] () -- C:\Users\***\Desktop\Griffith.lnk
[2010.07.08 23:00:50 | 002,064,384 | ---- | M] () -- e:\Documents\M-DVD_Org.db
[2010.07.08 22:42:36 | 000,000,743 | ---- | M] () -- C:\Users\***\Desktop\M-DVD.Org V2.lnk
[2010.07.08 20:18:43 | 000,000,678 | ---- | M] () -- C:\Users\***\Desktop\Magic MP3 Tagger.lnk
[2010.07.08 13:35:44 | 000,000,036 | ---- | M] () -- C:\Users\***\.33a11c88
[2010.07.07 16:05:32 | 000,014,904 | ---- | M] (Secunia) -- C:\Windows\System32\drivers\psi_mf.sys
[2010.06.30 18:04:43 | 000,029,520 | ---- | M] () -- e:\Documents\Gmail - ***.mht
========== Files Created - No Company Name ==========
[2010.07.16 16:03:31 | 000,000,668 | ---- | C] () -- C:\Users\***\Desktop\Waldmeister Sause Winteredition (Gratisversion).lnk
[2010.07.15 11:53:05 | 000,023,612 | ---- | C] () -- C:\Users\***\Desktop\cab_banane.jpg
[2010.07.15 11:03:10 | 000,000,662 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.07.14 17:08:11 | 000,023,687 | ---- | C] () -- C:\Windows\hpqins15.dat
[2010.07.13 10:44:41 | 000,000,722 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2010.07.12 22:45:56 | 000,000,721 | ---- | C] () -- C:\Users\***\Desktop\ABC Amber SeaMonkey Converter.lnk
[2010.07.12 21:18:13 | 000,000,000 | R--- | C] () -- C:\Users\***\AppData\Roaming\IIF1i.txt
[2010.07.11 15:09:51 | 000,000,673 | ---- | C] () -- C:\Users\Public\Desktop\Anti-Twin.lnk
[2010.07.09 16:07:07 | 000,000,218 | ---- | C] () -- C:\Users\***\.recently-used.xbel
[2010.07.09 14:33:27 | 000,029,520 | ---- | C] () -- e:\Documents\Gmail - ***.mht
[2010.07.09 00:02:10 | 000,032,603 | ---- | C] () -- C:\Users\***\Desktop\griffith_list.xml
[2010.07.09 00:01:59 | 000,013,876 | ---- | C] () -- C:\Users\***\Desktop\page_1.htm
[2010.07.09 00:01:59 | 000,001,799 | ---- | C] () -- C:\Users\***\Desktop\gray.css
[2010.07.09 00:00:52 | 000,004,239 | ---- | C] () -- C:\Users\***\Desktop\griffith_simple_list.pdf
[2010.07.08 23:11:23 | 000,000,630 | ---- | C] () -- C:\Users\***\Desktop\Griffith.lnk
[2010.07.08 22:52:40 | 002,064,384 | ---- | C] () -- e:\Documents\M-DVD_Org.db
[2010.07.08 22:42:36 | 000,000,743 | ---- | C] () -- C:\Users\***\Desktop\M-DVD.Org V2.lnk
[2010.07.08 22:42:34 | 000,675,840 | ---- | C] () -- C:\Windows\System32\AudioGenie2.ocx
[2010.07.08 22:42:30 | 001,161,492 | ---- | C] () -- C:\Windows\System32\cmLL1100.chm
[2010.07.08 22:42:30 | 000,425,984 | ---- | C] () -- C:\Windows\System32\cmmx0100.lng
[2010.07.08 20:18:43 | 000,000,678 | ---- | C] () -- C:\Users\***\Desktop\Magic MP3 Tagger.lnk
[2010.07.08 13:35:44 | 000,000,036 | ---- | C] () -- C:\Users\***\.33a11c88
[2010.04.05 17:32:41 | 000,000,295 | ---- | C] () -- C:\Windows\lgfwup.ini
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:D4BB0AD6
@Alternate Data Stream - 213 bytes -> C:\ProgramData\TEMP:35A81752
@Alternate Data Stream - 208 bytes -> C:\ProgramData\TEMP:B1FBA7E1
@Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:66AA0486
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:ED2998F5
< End of report > So vielen Dank schon mal für die Hilfe. Bin nun mit Linux unterwegs und finde mich mit dem GEdanken ab, dass ich vermutlich alle 200 Passwörter wieder erneut umändern muss....
LG |