Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. (https://www.trojaner-board.de/105818-vermute-virus-installation-exe-datei-100-sicherer-quelle.html)

DPK 05.12.2011 00:31

vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle.
 
Hallo,

ich habe vor ca4 Tagen eine datei installiert und habe seither perfomanceprobleme. (rechner reagiert lagsamer als zuvor und verschiede spiele stützen aus unerfindlichen gründen ab. meist ohne Fehlermeldung)

ich habe win7 ultimate und verwende Avira (Avira findet nach einem vollständigem scan jedoch nichts.)

ich habe mich an die Anleitung gehalten und mit defogger meine vituellen CDlaufwerke deaktiviert und nicht wieder aktiviert.

nach 14 stunden musste ich meinen rechner abschalten aber gema war noch nicht ganz fertig.
gema war gerade beim ordner:
C:\Windows\winsxs als ich den rechner abschalten musste. ich habe das log vorher noch gespeichert.

gema meinte zudem das VC5SecS.exe vllt ein rootkick sein könnte.
Laut googlesuche gehört diese datei zu VitualCD, einem laufwerkemulationsprogramm das ich verwende.

mfg DPK

hier das OTL log:

OTL logfile created on: 03.12.2011 16:54:15 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\wind_of_pain\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy

3,25 Gb Total Physical Memory | 2,14 Gb Available Physical Memory | 65,90% Memory free
6,50 Gb Paging File | 5,41 Gb Available in Paging File | 83,33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 35,13 Gb Total Space | 4,55 Gb Free Space | 12,96% Space Free | Partition Type: NTFS
Drive D: | 461,04 Gb Total Space | 48,05 Gb Free Space | 10,42% Space Free | Partition Type: NTFS
Drive E: | 100,00 Gb Total Space | 3,90 Gb Free Space | 3,90% Space Free | Partition Type: NTFS
Drive F: | 7,77 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF

Computer Name: PAINKEEPER | User Name: wind_of_pain | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\wind_of_pain\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Uniblue\RegistryBooster\rbmonitor.exe (Uniblue Systems Limited)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Programme\HHVcdV5Sys\VC5SecS.exe (H+H Software GmbH)


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (npggsvc) -- C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (VC5SecS) -- C:\Program Files\HHVcdV5Sys\VC5SecS.exe (H+H Software GmbH)


========== Driver Services (SafeList) ==========

DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (AtiHDAudioService) -- C:\Windows\System32\drivers\AtihdW73.sys (Advanced Micro Devices)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) -- C:\Windows\System32\drivers\L1E62x86.sys (Atheros Communications, Inc.)
DRV - (LUsbFilt) -- C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) -- C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (Mkd2kfNt) -- C:\Windows\System32\drivers\Mkd2kfNT.sys ()
DRV - (Mkd2Nadr) -- C:\Windows\System32\drivers\Mkd2Nadr.sys ()
DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
DRV - (vbev5mp) -- C:\Windows\System32\drivers\VBEV5MP.sys (H+H Software GmbH)
DRV - (tandpl) -- C:\Windows\System32\drivers\tandpl.sys ()
DRV - (enodpl) -- C:\Windows\System32\drivers\enodpl.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = my.daemon-search.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D6 78 7D 97 60 6F CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: firegestures@xuldev.org:1.6.3
FF - prefs.js..extensions.enabledItems: trackmenot@mrl.nyu.edu:0.6.723
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.0.2
FF - prefs.js..extensions.enabledItems: btpersonas@brandthunder.com:1.1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.10 07:37:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.09.16 22:05:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011.08.21 16:40:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2010.08.19 22:03:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Extensions
[2010.08.19 22:03:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.11.29 11:43:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Firefox\Profiles\15e639cc.default\extensions
[2011.11.18 00:15:18 | 000,000,000 | ---D | M] ("Personas Interactive Theme Engine") -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Firefox\Profiles\15e639cc.default\extensions\btpersonas@brandthunder.com
[2011.02.27 01:22:06 | 000,002,071 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\absearch-search.xml
[2010.03.18 19:11:59 | 000,000,873 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\conduit.xml
[2011.02.18 22:01:35 | 000,002,059 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\daemon-search.xml
[2010.01.07 08:26:56 | 000,000,526 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\yahoo.xml
[2011.11.10 16:11:19 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\WIND_OF_PAIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\15E639CC.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) -- C:\USERS\WIND_OF_PAIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\15E639CC.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011.11.10 07:37:14 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.05.04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.11.10 07:37:12 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.11.10 07:37:12 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.11.10 07:37:12 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.11.10 07:37:12 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.11.10 07:37:12 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.11.10 07:37:12 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml

O1 HOSTS File: ([2010.08.24 23:00:13 | 000,000,950 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 193.178.171.175 www.wienerlinien.at
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A4E33D05-3FC0-499D-AF69-F6B5EE3D5DD1}: DhcpNameServer = 10.0.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{ad8fb8b6-dcda-11de-b995-002215fd5cbc}\Shell - "" = AutoRun
O33 - MountPoints2\{ad8fb8b6-dcda-11de-b995-002215fd5cbc}\Shell\AutoRun\command - "" = G:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {47B3BDBB-F2AE-4B55-95C8-921C25DB3B76} - .NET Framework
ActiveX: {49C187D7-91E1-459E-9759-2925384BD397} - .NET Framework
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5A604D2C-E968-429B-8327-62B5CE52126D} - .NET Framework
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {9793EDE2-499E-4A14-8220-523691D8F91B} - .NET Framework
ActiveX: {A59B76D1-5E3B-4893-BB7F-AF69B2570A73} - .NET Framework
ActiveX: {BFA2E378-31D9-4595-AFA9-CA19E610DC0F} - .NET Framework
ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CE4BC71D-A88B-4943-BB3D-AF9C0E7D4387} - .NET Framework
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {FE600E50-2C69-46D5-ACAA-2B617006245C} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SetPointII.lnk - C:\Programme\Logitech\SetPoint II\SetPointII.exe - (Logitech Inc.)
MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip - - File not found
MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^DAEMON Tools Lite.lnk - C:\Programme\DAEMON Tools Lite\DTLite.exe - (DT Soft Ltd)
MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Produktregistrierung.lnk - C:\Programme\Common Files\Logishrd\eReg\SetPoint\eReg.exe - (Leader Technologies/Logitech)
MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Mozilla Thunderbird.lnk - C:\Programme\Mozilla Thunderbird\thunderbird.exe - (Mozilla Messaging)
MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Skype.lnk - - File not found
MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: avgnt - hkey= - key= - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
MsConfig - StartUpReg: Kernel and Hardware Abstraction Layer - hkey= - key= - C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
MsConfig - StartUpReg: Skype - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig - StartUpReg: StartCCC - hkey= - key= - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig - StartUpReg: VC5Player - hkey= - key= - C:\Programme\HHVcdV5Sys\VC5Play.exe (H+H Software GmbH)
MsConfig - StartUpReg: WinampAgent - hkey= - key= - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
MsConfig - State: "startup" - 1

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011.12.03 16:23:50 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\wind_of_pain\Desktop\OTL.exe
[2011.11.30 15:09:13 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\Desktop\Neuer Ordner
[2011.11.29 19:47:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[2011.11.29 19:47:31 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2011.11.29 19:42:59 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\Desktop\backups
[2011.11.29 19:23:12 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Roaming\Uniblue
[2011.11.29 19:22:50 | 000,000,000 | -H-D | C] -- C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2011.11.29 19:15:17 | 000,939,368 | ---- | C] (Macromedia, Inc.) -- C:\Windows\System32\flash.ocx
[2011.11.29 19:14:27 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Local\PackageAware
[2011.11.12 01:37:28 | 002,339,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.11.05 13:30:47 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2011.11.05 13:29:13 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Roaming\uTorrent
[2011.11.05 13:29:13 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Local\uTorrent
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011.12.03 16:55:25 | 000,019,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.03 16:55:25 | 000,019,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.03 16:50:19 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2011.12.03 16:49:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.03 16:49:14 | 2616,500,224 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.03 16:47:40 | 000,000,020 | ---- | M] () -- C:\Users\wind_of_pain\defogger_reenable
[2011.12.03 16:47:03 | 000,050,477 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Defogger.exe
[2011.12.03 16:23:54 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\wind_of_pain\Desktop\OTL.exe
[2011.11.30 14:25:30 | 000,001,979 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\HFv21.SC2Bank
[2011.11.19 07:39:05 | 000,694,232 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2011.11.19 07:39:05 | 000,693,256 | ---- | M] () -- C:\Windows\System32\perfh00A.dat
[2011.11.19 07:39:05 | 000,690,994 | ---- | M] () -- C:\Windows\System32\perfh013.dat
[2011.11.19 07:39:05 | 000,689,528 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2011.11.19 07:39:05 | 000,688,910 | ---- | M] () -- C:\Windows\System32\perfh010.dat
[2011.11.19 07:39:05 | 000,679,144 | ---- | M] () -- C:\Windows\System32\prfh0816.dat
[2011.11.19 07:39:05 | 000,675,760 | ---- | M] () -- C:\Windows\System32\perfh019.dat
[2011.11.19 07:39:05 | 000,663,606 | ---- | M] () -- C:\Windows\System32\prfh0416.dat
[2011.11.19 07:39:05 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.11.19 07:39:05 | 000,631,982 | ---- | M] () -- C:\Windows\System32\perfh00E.dat
[2011.11.19 07:39:05 | 000,622,946 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2011.11.19 07:39:05 | 000,617,370 | ---- | M] () -- C:\Windows\System32\perfh01D.dat
[2011.11.19 07:39:05 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.11.19 07:39:05 | 000,610,004 | ---- | M] () -- C:\Windows\System32\perfh01F.dat
[2011.11.19 07:39:05 | 000,551,572 | ---- | M] () -- C:\Windows\System32\perfh008.dat
[2011.11.19 07:39:05 | 000,461,974 | ---- | M] () -- C:\Windows\System32\perfh006.dat
[2011.11.19 07:39:05 | 000,448,388 | ---- | M] () -- C:\Windows\System32\perfh014.dat
[2011.11.19 07:39:05 | 000,434,288 | ---- | M] () -- C:\Windows\System32\perfh001.dat
[2011.11.19 07:39:05 | 000,433,190 | ---- | M] () -- C:\Windows\System32\perfh00B.dat
[2011.11.19 07:39:05 | 000,399,538 | ---- | M] () -- C:\Windows\System32\perfh012.dat
[2011.11.19 07:39:05 | 000,388,320 | ---- | M] () -- C:\Windows\System32\perfh011.dat
[2011.11.19 07:39:05 | 000,377,672 | ---- | M] () -- C:\Windows\System32\prfh0404.dat
[2011.11.19 07:39:05 | 000,361,570 | ---- | M] () -- C:\Windows\System32\prfh0804.dat
[2011.11.19 07:39:05 | 000,353,324 | ---- | M] () -- C:\Windows\System32\perfh00D.dat
[2011.11.19 07:39:05 | 000,148,112 | ---- | M] () -- C:\Windows\System32\perfc00E.dat
[2011.11.19 07:39:05 | 000,136,864 | ---- | M] () -- C:\Windows\System32\perfc00A.dat
[2011.11.19 07:39:05 | 000,134,642 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2011.11.19 07:39:05 | 000,133,554 | ---- | M] () -- C:\Windows\System32\prfc0816.dat
[2011.11.19 07:39:05 | 000,132,742 | ---- | M] () -- C:\Windows\System32\perfc013.dat
[2011.11.19 07:39:05 | 000,132,318 | ---- | M] () -- C:\Windows\System32\perfc019.dat
[2011.11.19 07:39:05 | 000,129,942 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2011.11.19 07:39:05 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.11.19 07:39:05 | 000,127,896 | ---- | M] () -- C:\Windows\System32\prfc0416.dat
[2011.11.19 07:39:05 | 000,126,946 | ---- | M] () -- C:\Windows\System32\perfc010.dat
[2011.11.19 07:39:05 | 000,123,542 | ---- | M] () -- C:\Windows\System32\perfc01D.dat
[2011.11.19 07:39:05 | 000,121,590 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2011.11.19 07:39:05 | 000,121,328 | ---- | M] () -- C:\Windows\System32\perfc01F.dat
[2011.11.19 07:39:05 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc011.dat
[2011.11.19 07:39:05 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.11.19 07:39:05 | 000,104,478 | ---- | M] () -- C:\Windows\System32\perfc012.dat
[2011.11.19 07:39:05 | 000,104,050 | ---- | M] () -- C:\Windows\System32\prfc0804.dat
[2011.11.19 07:39:05 | 000,099,136 | ---- | M] () -- C:\Windows\System32\prfc0404.dat
[2011.11.19 07:39:05 | 000,089,238 | ---- | M] () -- C:\Windows\System32\perfc008.dat
[2011.11.19 07:39:05 | 000,081,950 | ---- | M] () -- C:\Windows\System32\perfc00B.dat
[2011.11.19 07:39:05 | 000,079,606 | ---- | M] () -- C:\Windows\System32\perfc006.dat
[2011.11.19 07:39:05 | 000,078,786 | ---- | M] () -- C:\Windows\System32\perfc001.dat
[2011.11.19 07:39:05 | 000,076,898 | ---- | M] () -- C:\Windows\System32\perfc014.dat
[2011.11.19 07:39:05 | 000,068,896 | ---- | M] () -- C:\Windows\System32\perfc00D.dat
[2011.11.18 08:54:56 | 004,157,452 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate Part 2 (Beethoven) Moonlight Sonata.mp3
[2011.11.17 07:43:32 | 002,712,973 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate (Ludwig van Beethoven) Moonlight Sonata.mp3
[2011.11.12 09:23:29 | 000,289,720 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.11.07 09:26:14 | 000,939,368 | ---- | M] (Macromedia, Inc.) -- C:\Windows\System32\flash.ocx
[2011.11.06 12:32:25 | 001,169,064 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\My Little Pony - Rainbow Dash - Youre Gonna Go Far Kid.mp3
[2011.11.06 10:06:12 | 001,743,820 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Erasure - always.mp3
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.12.03 16:47:26 | 000,000,020 | ---- | C] () -- C:\Users\wind_of_pain\defogger_reenable
[2011.12.03 16:47:02 | 000,050,477 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Defogger.exe
[2011.11.30 11:06:42 | 000,001,979 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\HFv21.SC2Bank
[2011.11.29 19:23:13 | 000,000,346 | ---- | C] () -- C:\Windows\tasks\RegistryBooster.job
[2011.11.18 08:48:00 | 004,157,452 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate Part 2 (Beethoven) Moonlight Sonata.mp3
[2011.11.17 07:39:32 | 002,712,973 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate (Ludwig van Beethoven) Moonlight Sonata.mp3
[2011.11.06 12:30:48 | 001,169,064 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\My Little Pony - Rainbow Dash - Youre Gonna Go Far Kid.mp3
[2011.11.06 10:04:47 | 001,743,820 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Erasure - always.mp3
[2011.10.20 06:42:23 | 000,007,621 | ---- | C] () -- C:\Users\wind_of_pain\AppData\Local\Resmon.ResmonCfg
[2011.09.14 10:47:40 | 000,053,760 | ---- | C] () -- C:\Windows\System32\OVDecode.dll
[2011.08.26 15:34:14 | 000,239,869 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2011.05.10 20:10:14 | 000,003,929 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2011.03.31 18:03:33 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011.02.18 22:38:36 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010.02.23 02:17:04 | 000,767,328 | ---- | C] () -- C:\Windows\System32\kdfinj.dll
[2010.02.23 02:12:44 | 000,131,072 | ---- | C] () -- C:\Windows\System32\drivers\Mkd2kfNT.sys
[2010.02.23 02:12:44 | 000,079,104 | ---- | C] () -- C:\Windows\System32\drivers\Mkd2Nadr.sys
[2010.02.19 14:36:01 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2010.02.14 18:11:19 | 000,007,552 | ---- | C] () -- C:\Windows\System32\drivers\enodpl.sys
[2010.02.14 18:11:19 | 000,004,736 | ---- | C] () -- C:\Windows\System32\drivers\tandpl.sys
[2010.01.17 03:09:12 | 000,388,320 | ---- | C] () -- C:\Windows\System32\perfh011.dat
[2010.01.17 03:09:12 | 000,141,988 | ---- | C] () -- C:\Windows\System32\perfi011.dat
[2010.01.17 03:09:12 | 000,106,190 | ---- | C] () -- C:\Windows\System32\perfc011.dat
[2010.01.17 03:09:12 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd011.dat
[2010.01.17 03:02:11 | 000,551,572 | ---- | C] () -- C:\Windows\System32\perfh008.dat
[2010.01.17 03:02:11 | 000,369,984 | ---- | C] () -- C:\Windows\System32\perfi008.dat
[2010.01.17 03:02:11 | 000,089,238 | ---- | C] () -- C:\Windows\System32\perfc008.dat
[2010.01.17 03:02:11 | 000,045,182 | ---- | C] () -- C:\Windows\System32\perfd008.dat
[2010.01.17 02:58:33 | 000,610,004 | ---- | C] () -- C:\Windows\System32\perfh01F.dat
[2010.01.17 02:58:33 | 000,285,034 | ---- | C] () -- C:\Windows\System32\perfi01F.dat
[2010.01.17 02:58:33 | 000,121,328 | ---- | C] () -- C:\Windows\System32\perfc01F.dat
[2010.01.17 02:58:33 | 000,037,160 | ---- | C] () -- C:\Windows\System32\perfd01F.dat
[2010.01.17 02:55:17 | 000,631,982 | ---- | C] () -- C:\Windows\System32\perfh00E.dat
[2010.01.17 02:55:17 | 000,287,518 | ---- | C] () -- C:\Windows\System32\perfi00E.dat
[2010.01.17 02:55:17 | 000,148,112 | ---- | C] () -- C:\Windows\System32\perfc00E.dat
[2010.01.17 02:55:17 | 000,048,094 | ---- | C] () -- C:\Windows\System32\perfd00E.dat
[2010.01.17 02:51:58 | 000,679,144 | ---- | C] () -- C:\Windows\System32\prfh0816.dat
[2010.01.17 02:51:58 | 000,336,656 | ---- | C] () -- C:\Windows\System32\prfi0816.dat
[2010.01.17 02:51:58 | 000,133,554 | ---- | C] () -- C:\Windows\System32\prfc0816.dat
[2010.01.17 02:51:58 | 000,040,548 | ---- | C] () -- C:\Windows\System32\prfd0816.dat
[2010.01.17 02:48:49 | 000,690,994 | ---- | C] () -- C:\Windows\System32\perfh013.dat
[2010.01.17 02:48:49 | 000,341,322 | ---- | C] () -- C:\Windows\System32\perfi013.dat
[2010.01.17 02:48:49 | 000,132,742 | ---- | C] () -- C:\Windows\System32\perfc013.dat
[2010.01.17 02:48:49 | 000,043,068 | ---- | C] () -- C:\Windows\System32\perfd013.dat
[2010.01.17 02:45:11 | 000,461,974 | ---- | C] () -- C:\Windows\System32\perfh006.dat
[2010.01.17 02:45:11 | 000,306,636 | ---- | C] () -- C:\Windows\System32\perfi006.dat
[2010.01.17 02:45:11 | 000,079,606 | ---- | C] () -- C:\Windows\System32\perfc006.dat
[2010.01.17 02:45:11 | 000,039,236 | ---- | C] () -- C:\Windows\System32\perfd006.dat
[2010.01.17 02:40:31 | 000,617,370 | ---- | C] () -- C:\Windows\System32\perfh01D.dat
[2010.01.17 02:40:31 | 000,294,764 | ---- | C] () -- C:\Windows\System32\perfi01D.dat
[2010.01.17 02:40:31 | 000,123,542 | ---- | C] () -- C:\Windows\System32\perfc01D.dat
[2010.01.17 02:40:31 | 000,037,052 | ---- | C] () -- C:\Windows\System32\perfd01D.dat
[2010.01.13 22:23:59 | 000,693,256 | ---- | C] () -- C:\Windows\System32\perfh00A.dat
[2010.01.13 22:23:59 | 000,689,528 | ---- | C] () -- C:\Windows\System32\perfh015.dat
[2010.01.13 22:23:59 | 000,675,760 | ---- | C] () -- C:\Windows\System32\perfh019.dat
[2010.01.13 22:23:59 | 000,663,606 | ---- | C] () -- C:\Windows\System32\prfh0416.dat
[2010.01.13 22:23:59 | 000,434,288 | ---- | C] () -- C:\Windows\System32\perfh001.dat
[2010.01.13 22:23:59 | 000,341,432 | ---- | C] () -- C:\Windows\System32\perfi00A.dat
[2010.01.13 22:23:59 | 000,337,158 | ---- | C] () -- C:\Windows\System32\perfi015.dat
[2010.01.13 22:23:59 | 000,336,704 | ---- | C] () -- C:\Windows\System32\perfi019.dat
[2010.01.13 22:23:59 | 000,323,154 | ---- | C] () -- C:\Windows\System32\prfi0416.dat
[2010.01.13 22:23:59 | 000,289,060 | ---- | C] () -- C:\Windows\System32\perfi001.dat
[2010.01.13 22:23:59 | 000,136,864 | ---- | C] () -- C:\Windows\System32\perfc00A.dat
[2010.01.13 22:23:59 | 000,134,642 | ---- | C] () -- C:\Windows\System32\perfc015.dat
[2010.01.13 22:23:59 | 000,132,318 | ---- | C] () -- C:\Windows\System32\perfc019.dat
[2010.01.13 22:23:59 | 000,127,896 | ---- | C] () -- C:\Windows\System32\prfc0416.dat
[2010.01.13 22:23:59 | 000,078,786 | ---- | C] () -- C:\Windows\System32\perfc001.dat
[2010.01.13 22:23:59 | 000,042,056 | ---- | C] () -- C:\Windows\System32\perfd001.dat
[2010.01.13 22:23:59 | 000,041,390 | ---- | C] () -- C:\Windows\System32\perfd00A.dat
[2010.01.13 22:23:59 | 000,039,446 | ---- | C] () -- C:\Windows\System32\perfd019.dat
[2010.01.13 22:23:59 | 000,038,710 | ---- | C] () -- C:\Windows\System32\perfd015.dat
[2010.01.13 22:23:59 | 000,038,536 | ---- | C] () -- C:\Windows\System32\prfd0416.dat
[2010.01.12 22:41:22 | 000,353,324 | ---- | C] () -- C:\Windows\System32\perfh00D.dat
[2010.01.12 22:41:22 | 000,229,316 | ---- | C] () -- C:\Windows\System32\perfi00D.dat
[2010.01.12 22:41:22 | 000,068,896 | ---- | C] () -- C:\Windows\System32\perfc00D.dat
[2010.01.12 22:41:22 | 000,032,166 | ---- | C] () -- C:\Windows\System32\perfd00D.dat
[2010.01.12 22:33:42 | 000,688,910 | ---- | C] () -- C:\Windows\System32\perfh010.dat
[2010.01.12 22:33:42 | 000,335,478 | ---- | C] () -- C:\Windows\System32\perfi010.dat
[2010.01.12 22:33:42 | 000,126,946 | ---- | C] () -- C:\Windows\System32\perfc010.dat
[2010.01.12 22:33:42 | 000,037,534 | ---- | C] () -- C:\Windows\System32\perfd010.dat
[2010.01.12 22:28:09 | 000,377,672 | ---- | C] () -- C:\Windows\System32\prfh0404.dat
[2010.01.12 22:28:09 | 000,117,840 | ---- | C] () -- C:\Windows\System32\prfi0404.dat
[2010.01.12 22:28:09 | 000,099,136 | ---- | C] () -- C:\Windows\System32\prfc0404.dat
[2010.01.12 22:28:09 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0404.dat
[2010.01.12 22:24:53 | 000,399,538 | ---- | C] () -- C:\Windows\System32\perfh012.dat
[2010.01.12 22:24:53 | 000,157,694 | ---- | C] () -- C:\Windows\System32\perfi012.dat
[2010.01.12 22:24:53 | 000,104,478 | ---- | C] () -- C:\Windows\System32\perfc012.dat
[2010.01.12 22:24:53 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd012.dat
[2010.01.12 22:21:08 | 000,694,232 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
[2010.01.12 22:21:08 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
[2010.01.12 22:21:08 | 000,129,942 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
[2010.01.12 22:21:08 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
[2010.01.12 22:17:10 | 000,622,946 | ---- | C] () -- C:\Windows\System32\perfh005.dat
[2010.01.12 22:17:10 | 000,292,004 | ---- | C] () -- C:\Windows\System32\perfi005.dat
[2010.01.12 22:17:10 | 000,121,590 | ---- | C] () -- C:\Windows\System32\perfc005.dat
[2010.01.12 22:17:10 | 000,036,232 | ---- | C] () -- C:\Windows\System32\perfd005.dat
[2010.01.12 22:12:15 | 000,433,190 | ---- | C] () -- C:\Windows\System32\perfh00B.dat
[2010.01.12 22:12:15 | 000,279,790 | ---- | C] () -- C:\Windows\System32\perfi00B.dat
[2010.01.12 22:12:15 | 000,081,950 | ---- | C] () -- C:\Windows\System32\perfc00B.dat
[2010.01.12 22:12:15 | 000,038,258 | ---- | C] () -- C:\Windows\System32\perfd00B.dat
[2010.01.12 22:09:09 | 000,361,570 | ---- | C] () -- C:\Windows\System32\prfh0804.dat
[2010.01.12 22:09:09 | 000,111,310 | ---- | C] () -- C:\Windows\System32\prfi0804.dat
[2010.01.12 22:09:09 | 000,104,050 | ---- | C] () -- C:\Windows\System32\prfc0804.dat
[2010.01.12 22:09:09 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0804.dat
[2010.01.12 21:58:54 | 000,448,388 | ---- | C] () -- C:\Windows\System32\perfh014.dat
[2010.01.12 21:58:54 | 000,298,300 | ---- | C] () -- C:\Windows\System32\perfi014.dat
[2010.01.12 21:58:54 | 000,076,898 | ---- | C] () -- C:\Windows\System32\perfc014.dat
[2010.01.12 21:58:54 | 000,036,156 | ---- | C] () -- C:\Windows\System32\perfd014.dat
[2009.12.08 12:14:42 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009.11.29 12:25:00 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.11.27 13:39:40 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009.07.14 09:47:43 | 000,653,928 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 09:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 09:47:43 | 000,129,800 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 09:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 05:33:53 | 000,289,720 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 03:05:48 | 000,615,810 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 03:05:48 | 000,106,190 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 01:55:09 | 000,587,776 | ---- | C] () -- C:\Windows\System32\hpotscl1.dll
[2009.07.14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2004.08.13 09:56:20 | 000,005,810 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
[1997.11.17 17:13:16 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*. >
[2009.11.27 13:51:21 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2011.09.21 21:55:09 | 000,000,000 | ---D | M] -- C:\5301b5d6b61d5e9fd4431d67
[2011.07.06 14:14:32 | 000,000,000 | ---D | M] -- C:\ATI
[2009.11.27 13:36:56 | 000,000,000 | -HSD | M] -- C:\Boot
[2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2009.11.27 13:48:40 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2010.06.09 23:40:05 | 000,000,000 | ---D | M] -- C:\FrozenSynapse
[2009.07.14 03:37:05 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2011.11.29 19:47:31 | 000,000,000 | R--D | M] -- C:\Program Files
[2011.12.03 16:49:13 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2009.11.27 13:48:40 | 000,000,000 | -HSD | M] -- C:\Programme
[2009.11.27 13:48:40 | 000,000,000 | -HSD | M] -- C:\Recovery
[2011.12.03 16:58:07 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2009.11.27 13:51:09 | 000,000,000 | R--D | M] -- C:\Users
[2011.10.24 18:26:18 | 000,000,000 | ---D | M] -- C:\Windows

< %PROGRAMFILES%\*.exe >

< %LOCALAPPDATA%\*.exe >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.manifest /3 >


< MD5 for: AFD.SYS >
[2011.04.25 03:35:40 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=0DB7A48388D54D154EBEC120461A0FCD -- C:\Windows\System32\drivers\afd.sys
[2011.04.25 03:35:40 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=0DB7A48388D54D154EBEC120461A0FCD -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16802_none_d81220b5bf827af7\afd.sys
[2010.11.20 09:40:03 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=1151FD4FB0216CFED887BFDE29EBD516 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17514_none_d9efac7dbcaf385b\afd.sys
[2011.04.25 03:18:03 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=9EBBBA55060F786F0FCAA3893BFA2806 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17603_none_d9f97e05bca8003a\afd.sys
[2011.04.25 03:27:23 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=C114AB7A1550D42EA1700FFD4179CF5A -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.20951_none_d864ad9ad8c98d1f\afd.sys
[2011.04.25 04:24:09 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=C427F91A748CD342A2B3F9278D9FD6A5 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.21712_none_da774a9ad5cea29e\afd.sys
[2009.07.14 00:12:38 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=DDC040FDB01EF1712A6B13E52AFB104C -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16385_none_d7be98b5bfc0b4c1\afd.sys

< MD5 for: EXPLORER.EXE >
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: REGEDIT.EXE >
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\x86_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_f4050b883d2c3c08\regedit.exe

< MD5 for: USERINIT.EXE >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WININIT.EXE >
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe

< MD5 for: WINLOGON.EXE >
[2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe
[2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010.11.20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-03 14:43:03

< End of report >

cosinus 05.12.2011 14:24

Zitat:

ich habe vor ca4 Tagen eine datei installiert und habe seither perfomanceprobleme.
Hat das einen Grund warum du Sinn, Zweck, Name und Quelle dieser Datei nicht genauer erwähnst? http://cheesebuerger.de/images/midi/froehlich/a048.gif

DPK 05.12.2011 15:10

verzeihung. kein spezieller grund. ich scheine es einfach vergessen zu haben :(

folgende Datei wurde installiert
hxxp://www.filehippo.com/download_hijackthis/
sinn: log an einen freund schicken, der mir aber doch nicht helfen konnte. Davor hat mich nur instesesiert, warum gewisse Programme sporadisch abstützen, danach wurde es häufiger.

Vor diesem Zeitpunkt wurden von mir keine bewussten änderungen des systems durchgeführt (nur das automatische windowsupdate und avira) und das problem bestand in der jetzigen Form zu diesem Zeitpunkt auch nicht.

cosinus 05.12.2011 15:46

Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


DPK 06.12.2011 19:20

hier die logs von malwarebytes und ESET:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8316

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

05.12.2011 20:11:44
mbam-log-2011-12-05 (20-11-44).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Durchsuchte Objekte: 641918
Laufzeit: 2 Stunde(n), 19 Minute(n), 21 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
---------------------------------------------
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=e9608af7ce6f3d41bb3fa53a0add7e54
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-12-05 11:38:08
# local_time=2011-12-06 12:38:08 (+0100, Mitteleuropäische Zeit)
# country="Austria"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=1797 16775165 100 94 193691 59657866 100044 0
# compatibility_mode=5893 16776573 100 94 27392 74748636 0 0
# compatibility_mode=8192 67108863 100 0 3661 3661 0 0
# scanned=506078
# found=27
# cleaned=0
# scan_time=10843
C:\$Recycle.Bin\S-1-5-21-3012151111-3320611238-1688054739-1001\$R9I841H.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\$Recycle.Bin\S-1-5-21-3012151111-3320611238-1688054739-1001\$RCMD0QA.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Uniblue\RegistryBooster\Launcher.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Uniblue\RegistryBooster\rbnotifier.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Uniblue\RegistryBooster\rb_move_serial.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Uniblue\RegistryBooster\rb_ubm.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\mia945C.tmp\data\OFFLINE\89292046\B152136D\Launcher.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\mia945C.tmp\data\OFFLINE\89292046\B152136D\rbmonitor.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\mia945C.tmp\data\OFFLINE\89292046\B152136D\rbnotifier.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\mia945C.tmp\data\OFFLINE\89292046\B152136D\rb_move_serial.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\mia945C.tmp\data\OFFLINE\89292046\B152136D\rb_ubm.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\mia945C.tmp\data\OFFLINE\89292046\B152136D\registrybooster.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\mia99D9.tmp\data\OFFLINE\89292046\B152136D\Launcher.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\mia99D9.tmp\data\OFFLINE\89292046\B152136D\rbmonitor.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\mia99D9.tmp\data\OFFLINE\89292046\B152136D\rbnotifier.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\mia99D9.tmp\data\OFFLINE\89292046\B152136D\rb_move_serial.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\mia99D9.tmp\data\OFFLINE\89292046\B152136D\rb_ubm.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\mia99D9.tmp\data\OFFLINE\89292046\B152136D\registrybooster.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\miaA78E.tmp\data\OFFLINE\89292046\B152136D\Launcher.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\miaA78E.tmp\data\OFFLINE\89292046\B152136D\rbmonitor.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\miaA78E.tmp\data\OFFLINE\89292046\B152136D\rbnotifier.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\miaA78E.tmp\data\OFFLINE\89292046\B152136D\rb_move_serial.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\miaA78E.tmp\data\OFFLINE\89292046\B152136D\rb_ubm.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\wind_of_pain\AppData\Local\Temp\miaA78E.tmp\data\OFFLINE\89292046\B152136D\registrybooster.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
${Memory} Win32/RegistryBooster application 00000000000000000000000000000000 I

cosinus 06.12.2011 19:28

Zitat:

C:\Program Files\Uniblue\RegistryBooster\Launcher.exe Win32/RegistryBooster
Finger weg von Registry-Cleanern!!

Die Registry ist das Hirn des Systems. Funktioniert das Hirn nicht, funktioniert der Rest nicht mehr wirklich.
Wir lesen oft genug von Hilfesuchenden, dass deren System nach der Nutzung von Registry Cleanern nicht mehr startet.
  • Wie soll der Cleaner zu 100% wissen ob der Eintrag benötigt wird oder nicht ?
  • Es ist vollkommen egal ob ein paar verwaiste Registry Einträge am System sind oder nicht.
  • Auch die dauernd angepriesene Beschleunigung des Systems ist nur bedingt wahr. Du würdest es nicht merken.

Ein sogenanntes False Positive von einem Cleaner kann auch dein System unbootbar machen.
Zerstörst Du die Registry, zerstörst Du Windows.

DPK 06.12.2011 23:12

aha ... danke für deine Mühe.
Gibt es etwas das ich gegen die von diesem Programm verursachten Änderungen tun kann, oder muss ich mein System neu aufsetzen?

cosinus 07.12.2011 12:22

Mach bitte ein neues OTL-Log. Poste es in CODE-Tags!

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT



Alle Zeitangaben in WEZ +1. Es ist jetzt 21:38 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131