Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Internet Explorer und co öffnet ständig Seiten (https://www.trojaner-board.de/86713-internet-explorer-co-oeffnet-staendig-seiten.html)

Bianca28 02.06.2010 22:44

Internet Explorer und co öffnet ständig Seiten
 
Guten Abend, zum einen ich weiß das es dieses Problem schon ein paar mal gibt aber ich möchhte da nicht in die Lösungen reinpfuschen von daher mach ich ein neues Thema auf. :-)
Zum Glück bin ich nicht die einzige mit dem Problem so konnte ich mich schonmal ein wenig informieren.
Ach ja ich bin nicht wirklich ein PC spezi, also seid bitte Nachsichtig mit mir. :-)
So nun zum Problem:
Seit einiger Zeit öffnen sich bei mir immer wieder zusätzliche Internet Seite. Allerdings von deinem Browser den ich nicht kenne. Es steht auch kein Browsername da sondern nur so ein paar bunte Zeichen. Bisher hat mich das nicht groß gestört denn das war nur wenn ich eh meinen Browser (Firefox) offen hatte und rum surfte.
Seit heute allerdings macht das auch der IE und das auf sehr penetrante Art und weise und auch wenn ich absolut nichts offen habe.
Gerade bei spielen nervt es kollosal da immer die Spiele unterbrochen werden :-(
Ich habe mein Virenprogramm (Antivir) laufen lassen aber nicht wirklich was gefunden. Dann lies ich QuickStore laufen und habe da alles gelösch wie es in einem älteren Beitrag hier beschrieben wird. Bracht nur in sofern was, das die Abstände der Pop ups sich um ein paar Minuten vergrößert haben. Momentan lass ich eScan laufen und er hat schon ein paar Sachen gefunden aber ich weiß nicht ob das auch wirklich was ist. Ich poste die bisher gefunden gleichhier. Ich muss den Scan dann pausieren lassen da ich nur einen Laptop habe und der eh schon schnell heiß. Ich schalt ihn aber nicht aus sondern heut nacht nur auf Stand By. Morgen lass ich den Scan weiterlaufen. Viellecht kann schon jemand was mit dem gefunden anfangen.
Vielen Dank schonmal!!!!!

02 Jun 2010 21:42:20 - **********************************************************

02 Jun 2010 21:42:20 - eScan Anti Virus & Spyware Toolkit Utility.

02 Jun 2010 21:42:20 - Copyright © MicroWorld Technologies

02 Jun 2010 21:42:20 - **********************************************************

02 Jun 2010 21:42:20 - Source: C:\Users\bianca\Desktop\Downloads\mwav.exe

02 Jun 2010 21:42:20 - Version 12.0.26 (C:\USERS\BIANCA\APPDATA\LOCAL\TEMP\MEXETMP.EX~)

02 Jun 2010 21:42:20 - Log File: C:\Users\bianca\AppData\Local\Temp\MWAV.LOG

02 Jun 2010 21:42:20 - MWAV Registered: TRUE

02 Jun 2010 21:42:20 - User Account: bianca (Administrator Mode)

02 Jun 2010 21:42:20 - OS Type: Windows Workstation

02 Jun 2010 21:42:20 - OS: Windows Vista [OS Install Date: 24 Dec 2007 21:25:27]

02 Jun 2010 21:42:20 - Ver: Personal Service Pack 2 (Build 6002)

02 Jun 2010 21:42:20 - System Up Time: 59 Minutes, 37 Seconds



02 Jun 2010 21:42:20 - Windows Root Folder: C:\Windows

02 Jun 2010 21:42:20 - Windows Sys32 Folder: C:\Windows\system32

02 Jun 2010 21:42:20 - DHCP NameServer: 192.168.2.1

02 Jun 2010 21:42:20 - Interface0 DHCPNameServer: 192.168.2.1

02 Jun 2010 21:42:20 - Local Fixed Drives: c:\,e:\

02 Jun 2010 21:42:20 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)

02 Jun 2010 21:42:20 - [CREATED ZIP FILE: C:\Users\bianca\AppData\Local\Temp\pinfect.zip]



02 Jun 2010 21:42:20 - ****** Files/Folders created/modified during last fortnight in Windows and ROOT Folder ******

02 Jun 2010 21:42:36 - C:\Windows\system32\CE6AF3E6A1.sys (8), 29-Dec-2007 [HSR] [Added C:\Windows\system32\CE6AF3E6A1.sys to ZIP FILE]

02 Jun 2010 21:42:43 - C:\Windows\system32\D3DCompiler_42.dll (1974616), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:42:44 - C:\Windows\system32\d3dcsx_42.dll (5501792), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:42:44 - C:\Windows\system32\d3dx11_42.dll (235344), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:42:50 - C:\Windows\system32\deployJava1.dll (411368), 02-Jun-2010, Sun Microsystems, Inc., Java(TM) Platform SE 6 U20

02 Jun 2010 21:44:19 - C:\Windows\system32\tzres.dll (2048), 26-May-2010, Microsoft Corporation, Betriebssystem Microsoft® Windows®

02 Jun 2010 21:44:34 - C:\Windows\system32\X3DAudio1_5.dll (23376), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\xactengine3_2.dll (238088), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\xactengine3_3.dll (235856), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\xactengine3_5.dll (238936), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\XAPOFX1_1.dll (68616), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\XAPOFX1_2.dll (70992), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\XAPOFX1_3.dll (69464), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\XAudio2_2.dll (509448), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\XAudio2_3.dll (514384), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\XAudio2_5.dll (515416), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\BACKUP.65854536.mexe.com (2353736), 02-Jun-2010, MicroWorld Technologies Inc., MicroWorld AntiVirus Toolkit Utility (MWAV)

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\bdc.exe (91904), 02-Jun-2010, MicroWorld Tech, eScan

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\bdfltlib2k.dll (231944), 02-Jun-2010, MicroWorld Technologies Inc., eScan for Windows

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\clean.bat (11), 02-Jun-2010 [Added C:\Users\bianca\AppData\Local\Temp\clean.bat to ZIP FILE]

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\download.exe (934920), 02-Jun-2010, MicroWorld Technologies Inc., eScan

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\encdec.dll (120328), 02-Jun-2010, MicroWorld Technologies Inc., eScan/MailScan/eConceal

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\erootdrv.sys (13832), 02-Jun-2010, MicroWorld Technologies Inc., eScan/MWAV

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\mexe.com (2476616), 02-Jun-2010, MicroWorld Technologies Inc., MicroWorld AntiVirus Toolkit Utility (MWAV)

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\msvclnt.dll (236040), 02-Jun-2010, MicroWorld Technologies Inc., MailScan

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\MWAVSCAN.COM (2353736), 02-Jun-2010, MicroWorld Technologies Inc., MicroWorld AntiVirus Toolkit Utility (MWAV)

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\plugins.htm (3498), 02-Jun-2010 [Added C:\Users\bianca\AppData\Local\Temp\plugins.htm to ZIP FILE]

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\red32.dll (10248), 02-Jun-2010, Microsoft Corporation, Microsoft® Windows® Operating System

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\reload.exe (154632), 02-Jun-2010, MicroWorld Technologies Inc., eScan for Windows

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\setpriv.exe (64008), 02-Jun-2010, MicroWorld Technologies Inc, eScan AntiVirus Toolkit Utility

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\sshnas21.dll (241152), 02-Jun-2010 [Added C:\Users\bianca\AppData\Local\Temp\sshnas21.dll to ZIP FILE]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\unregx.exe (61960), 02-Jun-2010, MicroWorld Technologies Inc, MicroWorld AntiVirus Toolkit Utility

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\UPDLL10.DLL (845320), 25-May-2010, MicroWorld Technologies Inc., eScan/MailScan/MWAV

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\viewtcp.exe (573960), 02-Jun-2010, MicroWorld Technologies Inc., ViewTCP

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\Xg1.exe (181248), 02-Jun-2010 [Added C:\Users\bianca\AppData\Local\Temp\Xg1.exe to ZIP FILE]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\Xg6.exe (200704), 02-Jun-2010 [Added C:\Users\bianca\AppData\Local\Temp\Xg6.exe to ZIP FILE]



02 Jun 2010 21:44:49 - C:\Windows\Fonts, 02-Nov-2006 [SR] [Folder]

02 Jun 2010 21:44:49 - C:\Windows\ftpcache, 19-Apr-2008 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Windows\logo_1.exe, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Windows\Media, 02-Nov-2006 [SR] [Folder]

02 Jun 2010 21:44:49 - C:\Windows\msdownld.tmp, 16-Apr-2007 [H] [Folder]

02 Jun 2010 21:44:49 - C:\Windows\RUNDL132.EXE, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Windows\VDLL.DLL, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Windows\system32\Microsoft, 02-Nov-2006 [S] [Folder]

02 Jun 2010 21:44:49 - C:\Windows\system32\runouce.exe, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Boot, 13-Apr-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Config.Msi, 02-Jun-2010 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Documents and Settings, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Dokumente und Einstellungen, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData, 02-Nov-2006 [H] [Folder]

02 Jun 2010 21:44:49 - C:\Programme, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\AVCBack, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\div4162.tmp, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\FtpTemp, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\FtpTempF, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\IM, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\Log, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\plugins, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\tmp00007fd8, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Roaming\Avira, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Roaming\Microsoft, 24-Dec-2007 [S] [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Roaming\QuickStoresToolbar, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Roaming\SecuROM, 11-Jan-2008 [HR] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Anwendungsdaten, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Application Data, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\CanonBJ, 21-Jul-2008 [H] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Desktop, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\DivX, 30-May-2010 [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Documents, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Dokumente, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\FarmFrenzy3_Russia, 28-May-2010 [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Favoriten, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Microsoft, 02-Nov-2006 [S] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\MicroWorld, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Start Menu, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Startmenü, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Templates, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Vorlagen, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\..\Boot, 13-Apr-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\..\Config.Msi, 02-Jun-2010 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\..\Documents and Settings, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\..\Dokumente und Einstellungen, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\..\ProgramData, 02-Nov-2006 [H] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\..\Programme, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Alawar Entertainment, 28-May-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\ClearProg, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Creative Installation Information, 21-Feb-2008 [H] [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Games, 31-May-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Gemeinsame Dateien, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Ubisoft, 01-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Xfire, 09-Jan-2008 [S] [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Common Files\MicroWorld, 02-Jun-2010 [Folder]



02 Jun 2010 21:44:49 - *********************************************************************************************



02 Jun 2010 21:44:49 - Command Line Options Given: /xsign

02 Jun 2010 21:44:58 - Latest Date of files inside MWAV: Wed Jun 2 21:52:41 2010.

02 Jun 2010 21:44:58 - Plugins FileCount: 681 Sign Version: 7.31986

02 Jun 2010 21:44:59 - Loading/Creating FileScan Database C:\ProgramData\MicroWorld\MWAV\ESCANDBX.MDB [Log: C:\Users\bianca\AppData\Local\Temp\ESCANDB.LOG]

02 Jun 2010 21:45:00 - Loaded/Created FileScan Database...

02 Jun 2010 21:45:00 - Loading AV Library [DB]...

02 Jun 2010 21:45:06 - AV Library Loaded [DB-DIRECT].

02 Jun 2010 21:45:06 - MWAV doing self scanning...

02 Jun 2010 21:45:07 - MWAV files are clean.
02 Jun 2010 21:45:12 - Virus Database Date: 02 Jun 2010
02 Jun 2010 21:45:12 - Virus Database Count: 6121217

02 Jun 2010 21:45:35 - **********************************************************
02 Jun 2010 21:45:35 - eScan Anti Virus & Spyware Toolkit Utility.
02 Jun 2010 21:45:35 - Copyright © MicroWorld Technologies
02 Jun 2010 21:45:35 -
02 Jun 2010 21:45:35 - Support: support@escanav.com
02 Jun 2010 21:45:35 - Web: hxxp://www.escanav.com
02 Jun 2010 21:45:35 - **********************************************************
02 Jun 2010 21:45:35 - Version 12.0.26[DB] (C:\USERS\BIANCA\APPDATA\LOCAL\TEMP\MEXETMP.EX~)
02 Jun 2010 21:45:35 - Log File: C:\Users\bianca\AppData\Local\Temp\MWAV.LOG
02 Jun 2010 21:45:35 - User Account: bianca (Administrator Mode)
02 Jun 2010 21:45:35 - Windows Root Folder: C:\Windows
02 Jun 2010 21:45:35 - Windows Sys32 Folder: C:\Windows\system32
02 Jun 2010 21:45:35 - OS: Windows Vista [OS Install Date: 24 Dec 2007 21:25:27]
02 Jun 2010 21:45:35 - Ver: Personal Service Pack 2 (Build 6002)
02 Jun 2010 21:45:35 - Latest Date of files inside MWAV: Wed Jun 2 21:52:41 2010.
02 Jun 2010 21:45:35 - Plugins FileCount: 681 Sign Version: 7.31986

02 Jun 2010 21:45:43 - Options Selected by User:
02 Jun 2010 21:45:43 - Memory Check: Enabled
02 Jun 2010 21:45:43 - Registry Check: Enabled
02 Jun 2010 21:45:43 - StartUp Folder Check: Disabled
02 Jun 2010 21:45:43 - System Folder Check: Disabled
02 Jun 2010 21:45:43 - Services Check: Enabled
02 Jun 2010 21:45:43 - Scan Spyware: Disabled
02 Jun 2010 21:45:43 - Drive Check: Disabled
02 Jun 2010 21:45:43 - All Drive Check :Enabled
02 Jun 2010 21:45:43 - Folder Check: Disabled
02 Jun 2010 21:45:43 - SCAN: All_Files
02 Jun 2010 21:45:43 - MWAV Mode: Only Scan files (Do Not Clean)


02 Jun 2010 21:45:45 - ***** Scanning Memory Files *****
02 Jun 2010 21:46:40 - Scanning File C:\Users\bianca\AppData\Local\mutbihpv.exe
02 Jun 2010 21:46:40 - File C:\Users\bianca\AppData\Local\mutbihpv.exe infected by "Gen:Variant.NaviPromo.2 (DB)" Virus! Action Taken: No Action Taken.


02 Jun 2010 21:46:50 - ***** Scanning Registry Files *****
02 Jun 2010 21:46:51 - ERROR!!! Invalid Entry = hxxp://www.webtip.ch/cgi-bin/toshiba/tracker_url_de.pl?hxxp://www.ebay.de/ (in key HKLM\Software\Microsoft\Internet Explorer\Extensions\{C08CAF1D-C0A3-40D5-9970-06D067EAC017}). No Action Taken.
02 Jun 2010 21:47:00 - Invalid Entry DLLName = igfxdev.dll (in key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui). Action Taken: Deleting Registry Key igfxcui.
02 Jun 2010 21:47:02 - ERROR!!! Invalid Entry IgfxTray = C:\Windows\system32\igfxtray.exe (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:02 - ERROR!!! Invalid Entry HotKeysCmds = C:\Windows\system32\hkcmd.exe (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:02 - ERROR!!! Invalid Entry Persistence = C:\Windows\system32\igfxpers.exe (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:02 - ERROR!!! Invalid Entry HWSetup = \HWSetup.exe hwSetUP (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:02 - ERROR!!! Invalid Entry NDSTray.exe = NDSTray.exe (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:03 - ERROR!!! Invalid Entry Performance Center = C:\Program Files\Ascentive\Performance Center\APCMain.exe -m (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:03 - Invalid DLL [C:\Users\bianca\AppData\Local\Temp\efcBusQh.dll] in entry [MSServer=rundll32.exe C:\Users\bianca\AppData\Local\Temp\efcBusQh.dll,#1]
02 Jun 2010 21:47:03 - ERROR!!! Invalid Entry MSServer = C:\Windows\system32\rundll32.exe (in key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:03 - ERROR!!! Invalid Entry Host Process = C:\Users\bianca\svchost.exe (in key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:03 - Invalid DLL [C:\Users\bianca\AppData\Local\Temp\jkkHxVlM.dll] in entry [cmds=rundll32.exe C:\Users\bianca\AppData\Local\Temp\jkkHxVlM.dll,c]
02 Jun 2010 21:47:03 - ERROR!!! Invalid Entry cmds = C:\Windows\system32\rundll32.exe (in key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:07 - Scanning File c:\users\bianca\appdata\local\mutbihpv.exe
02 Jun 2010 21:47:07 - File c:\users\bianca\appdata\local\mutbihpv.exe infected by "Gen:Variant.NaviPromo.2 (DB)" Virus! Action Taken: No Action Taken.


02 Jun 2010 21:47:08 - ***** Scanning Service Files *****
02 Jun 2010 21:47:10 - ERROR!!! Invalid Entry "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" in HKLM\SYSTEM\CurrentControlSet\Services\Automatisches LiveUpdate - Scheduler. Action Taken: No Action Taken.
02 Jun 2010 21:47:10 - ERROR!!! Invalid Entry \SystemRoot\system32\drivers\blbdrive.sys in HKLM\SYSTEM\CurrentControlSet\Services\blbdrive. Action Taken: No Action Taken.
02 Jun 2010 21:47:24 - ERROR!!! Invalid Entry \??\C:\Users\bianca\AppData\Local\Temp\gkmixern.sys in HKLM\SYSTEM\CurrentControlSet\Services\gkmixern. Action Taken: No Action Taken.
02 Jun 2010 21:47:25 - ERROR!!! Invalid Entry system32\DRIVERS\igdkmd32.sys in HKLM\SYSTEM\CurrentControlSet\Services\igfx. Action Taken: No Action Taken.
02 Jun 2010 21:47:30 - ERROR!!! Invalid Entry \??\C:\Windows\system32\drivers\PDNMp50.sys in HKLM\SYSTEM\CurrentControlSet\Services\PDNMp50. Action Taken: No Action Taken.
02 Jun 2010 21:47:30 - ERROR!!! Invalid Entry \??\C:\Windows\system32\drivers\PDNSp50.sys in HKLM\SYSTEM\CurrentControlSet\Services\PDNSp50. Action Taken: No Action Taken.
02 Jun 2010 21:47:34 - C:\Windows\system32\Drivers\sptd.sys not Scanned. Possibly password protected...
02 Jun 2010 21:47:36 - ERROR!!! Invalid Entry c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe in HKLM\SYSTEM\CurrentControlSet\Services\TOSHIBA Bluetooth Service. Action Taken: No Action Taken.
02 Jun 2010 21:47:36 - ERROR!!! Invalid Entry system32\DRIVERS\TpChoice.sys in HKLM\SYSTEM\CurrentControlSet\Services\TpChoice. Action Taken: No Action Taken.

02 Jun 2010 21:47:41 - ***** Scanning All Drives *****
02 Jun 2010 21:47:41 - Scanning C:\ Drive
02 Jun 2010 21:50:15 - C:\Boot\BCD not Scanned. Possibly password protected...
02 Jun 2010 21:50:15 - C:\Boot\BCD.LOG not Scanned. Possibly password protected...
02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMCoreA.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMCoreA.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMCoreB.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMCoreB.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMCoreC.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMCoreC.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMCoreD.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMCoreD.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMCoreE.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMCoreE.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMDataServicesA.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMDataServicesA.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMDataServicesB.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMDataServicesB.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMDataServicesC.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMDataServicesC.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMDataServicesD.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMDataServicesD.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMDataServicesE.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMDataServicesE.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreA.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreA.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreB.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreB.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreC.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreC.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreD.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreD.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreE.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreE.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreF.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreF.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreG.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreG.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreH.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreH.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreI.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreI.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreJ.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreJ.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:57 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMSearchA.dll
02 Jun 2010 21:55:57 - File C:\Program Files\Common Files\Nero\Lib\NMSearchA.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:57 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMSearchB.dll
02 Jun 2010 21:55:57 - File C:\Program Files\Common Files\Nero\Lib\NMSearchB.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:57 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMSearchC.dll
02 Jun 2010 21:55:57 - File C:\Program Files\Common Files\Nero\Lib\NMSearchC.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:57 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMSearchD.dll
02 Jun 2010 21:55:57 - File C:\Program Files\Common Files\Nero\Lib\NMSearchD.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:57 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMSearchE.dll
02 Jun 2010 21:55:57 - File C:\Program Files\Common Files\Nero\Lib\NMSearchE.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:56:43 - C:\Program Files\DAEMON Tools\SetupDTSB.exe not Scanned. Possibly password protected...
02 Jun 2010 22:27:13 - ScanFile took 6.96 Secs [C:\Program Files\Vuze\plugins\azemp\vuzeplayer.exe]...

02 Jun 2010 22:29:24 - Scanning File C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4915192e.qua
02 Jun 2010 22:29:24 - File C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4915192e.qua infected by "Gen:Adware.Heur.hq1@Rm!VmBji (DB)" Virus! Action Taken: No Action Taken.

Bianca28 03.06.2010 10:50

Guten morgen. Der Scan ist jetzt vollstäündig durchgelaufen: Hier die Log Files:


02 Jun 2010 21:42:20 - **********************************************************

02 Jun 2010 21:42:20 - eScan Anti Virus & Spyware Toolkit Utility.

02 Jun 2010 21:42:20 - Copyright © MicroWorld Technologies

02 Jun 2010 21:42:20 - **********************************************************

02 Jun 2010 21:42:20 - Source: C:\Users\bianca\Desktop\Downloads\mwav.exe

02 Jun 2010 21:42:20 - Version 12.0.26 (C:\USERS\BIANCA\APPDATA\LOCAL\TEMP\MEXETMP.EX~)

02 Jun 2010 21:42:20 - Log File: C:\Users\bianca\AppData\Local\Temp\MWAV.LOG

02 Jun 2010 21:42:20 - MWAV Registered: TRUE

02 Jun 2010 21:42:20 - User Account: bianca (Administrator Mode)

02 Jun 2010 21:42:20 - OS Type: Windows Workstation

02 Jun 2010 21:42:20 - OS: Windows Vista [OS Install Date: 24 Dec 2007 21:25:27]

02 Jun 2010 21:42:20 - Ver: Personal Service Pack 2 (Build 6002)

02 Jun 2010 21:42:20 - System Up Time: 59 Minutes, 37 Seconds



02 Jun 2010 21:42:20 - Windows Root Folder: C:\Windows

02 Jun 2010 21:42:20 - Windows Sys32 Folder: C:\Windows\system32

02 Jun 2010 21:42:20 - DHCP NameServer: 192.168.2.1

02 Jun 2010 21:42:20 - Interface0 DHCPNameServer: 192.168.2.1

02 Jun 2010 21:42:20 - Local Fixed Drives: c:\,e:\

02 Jun 2010 21:42:20 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)

02 Jun 2010 21:42:20 - [CREATED ZIP FILE: C:\Users\bianca\AppData\Local\Temp\pinfect.zip]



02 Jun 2010 21:42:20 - ****** Files/Folders created/modified during last fortnight in Windows and ROOT Folder ******

02 Jun 2010 21:42:36 - C:\Windows\system32\CE6AF3E6A1.sys (8), 29-Dec-2007 [HSR] [Added C:\Windows\system32\CE6AF3E6A1.sys to ZIP FILE]

02 Jun 2010 21:42:43 - C:\Windows\system32\D3DCompiler_42.dll (1974616), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:42:44 - C:\Windows\system32\d3dcsx_42.dll (5501792), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:42:44 - C:\Windows\system32\d3dx11_42.dll (235344), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:42:50 - C:\Windows\system32\deployJava1.dll (411368), 02-Jun-2010, Sun Microsystems, Inc., Java(TM) Platform SE 6 U20

02 Jun 2010 21:44:19 - C:\Windows\system32\tzres.dll (2048), 26-May-2010, Microsoft Corporation, Betriebssystem Microsoft® Windows®

02 Jun 2010 21:44:34 - C:\Windows\system32\X3DAudio1_5.dll (23376), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\xactengine3_2.dll (238088), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\xactengine3_3.dll (235856), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\xactengine3_5.dll (238936), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\XAPOFX1_1.dll (68616), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\XAPOFX1_2.dll (70992), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\XAPOFX1_3.dll (69464), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\XAudio2_2.dll (509448), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\XAudio2_3.dll (514384), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:35 - C:\Windows\system32\XAudio2_5.dll (515416), 02-Jun-2010, Microsoft Corporation, Microsoft® DirectX for Windows®

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\BACKUP.65854536.mexe.com (2353736), 02-Jun-2010, MicroWorld Technologies Inc., MicroWorld AntiVirus Toolkit Utility (MWAV)

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\bdc.exe (91904), 02-Jun-2010, MicroWorld Tech, eScan

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\bdfltlib2k.dll (231944), 02-Jun-2010, MicroWorld Technologies Inc., eScan for Windows

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\clean.bat (11), 02-Jun-2010 [Added C:\Users\bianca\AppData\Local\Temp\clean.bat to ZIP FILE]

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\download.exe (934920), 02-Jun-2010, MicroWorld Technologies Inc., eScan

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\encdec.dll (120328), 02-Jun-2010, MicroWorld Technologies Inc., eScan/MailScan/eConceal

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\erootdrv.sys (13832), 02-Jun-2010, MicroWorld Technologies Inc., eScan/MWAV

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\mexe.com (2476616), 02-Jun-2010, MicroWorld Technologies Inc., MicroWorld AntiVirus Toolkit Utility (MWAV)

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\msvclnt.dll (236040), 02-Jun-2010, MicroWorld Technologies Inc., MailScan

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\MWAVSCAN.COM (2353736), 02-Jun-2010, MicroWorld Technologies Inc., MicroWorld AntiVirus Toolkit Utility (MWAV)

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\plugins.htm (3498), 02-Jun-2010 [Added C:\Users\bianca\AppData\Local\Temp\plugins.htm to ZIP FILE]

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\red32.dll (10248), 02-Jun-2010, Microsoft Corporation, Microsoft® Windows® Operating System

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\reload.exe (154632), 02-Jun-2010, MicroWorld Technologies Inc., eScan for Windows

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\setpriv.exe (64008), 02-Jun-2010, MicroWorld Technologies Inc, eScan AntiVirus Toolkit Utility

02 Jun 2010 21:44:48 - C:\Users\bianca\AppData\Local\Temp\sshnas21.dll (241152), 02-Jun-2010 [Added C:\Users\bianca\AppData\Local\Temp\sshnas21.dll to ZIP FILE]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\unregx.exe (61960), 02-Jun-2010, MicroWorld Technologies Inc, MicroWorld AntiVirus Toolkit Utility

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\UPDLL10.DLL (845320), 25-May-2010, MicroWorld Technologies Inc., eScan/MailScan/MWAV

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\viewtcp.exe (573960), 02-Jun-2010, MicroWorld Technologies Inc., ViewTCP

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\Xg1.exe (181248), 02-Jun-2010 [Added C:\Users\bianca\AppData\Local\Temp\Xg1.exe to ZIP FILE]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\Xg6.exe (200704), 02-Jun-2010 [Added C:\Users\bianca\AppData\Local\Temp\Xg6.exe to ZIP FILE]



02 Jun 2010 21:44:49 - C:\Windows\Fonts, 02-Nov-2006 [SR] [Folder]

02 Jun 2010 21:44:49 - C:\Windows\ftpcache, 19-Apr-2008 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Windows\logo_1.exe, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Windows\Media, 02-Nov-2006 [SR] [Folder]

02 Jun 2010 21:44:49 - C:\Windows\msdownld.tmp, 16-Apr-2007 [H] [Folder]

02 Jun 2010 21:44:49 - C:\Windows\RUNDL132.EXE, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Windows\VDLL.DLL, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Windows\system32\Microsoft, 02-Nov-2006 [S] [Folder]

02 Jun 2010 21:44:49 - C:\Windows\system32\runouce.exe, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Boot, 13-Apr-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Config.Msi, 02-Jun-2010 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Documents and Settings, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Dokumente und Einstellungen, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData, 02-Nov-2006 [H] [Folder]

02 Jun 2010 21:44:49 - C:\Programme, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\AVCBack, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\div4162.tmp, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\FtpTemp, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\FtpTempF, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\IM, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\Log, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\plugins, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Local\Temp\tmp00007fd8, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Roaming\Avira, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Roaming\Microsoft, 24-Dec-2007 [S] [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Roaming\QuickStoresToolbar, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Users\bianca\AppData\Roaming\SecuROM, 11-Jan-2008 [HR] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Anwendungsdaten, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Application Data, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\CanonBJ, 21-Jul-2008 [H] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Desktop, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\DivX, 30-May-2010 [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Documents, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Dokumente, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\FarmFrenzy3_Russia, 28-May-2010 [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Favoriten, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Microsoft, 02-Nov-2006 [S] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\MicroWorld, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Start Menu, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Startmenü, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Templates, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\Vorlagen, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\..\Boot, 13-Apr-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\..\Config.Msi, 02-Jun-2010 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\..\Documents and Settings, 02-Nov-2006 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\..\Dokumente und Einstellungen, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\..\ProgramData, 02-Nov-2006 [H] [Folder]

02 Jun 2010 21:44:49 - C:\ProgramData\..\Programme, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Alawar Entertainment, 28-May-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\ClearProg, 02-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Creative Installation Information, 21-Feb-2008 [H] [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Games, 31-May-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Gemeinsame Dateien, 24-Dec-2007 [HS] [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Ubisoft, 01-Jun-2010 [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Xfire, 09-Jan-2008 [S] [Folder]

02 Jun 2010 21:44:49 - C:\Program Files\Common Files\MicroWorld, 02-Jun-2010 [Folder]



02 Jun 2010 21:44:49 - *********************************************************************************************



02 Jun 2010 21:44:49 - Command Line Options Given: /xsign

02 Jun 2010 21:44:58 - Latest Date of files inside MWAV: Wed Jun 2 21:52:41 2010.

02 Jun 2010 21:44:58 - Plugins FileCount: 681 Sign Version: 7.31986

02 Jun 2010 21:44:59 - Loading/Creating FileScan Database C:\ProgramData\MicroWorld\MWAV\ESCANDBX.MDB [Log: C:\Users\bianca\AppData\Local\Temp\ESCANDB.LOG]

02 Jun 2010 21:45:00 - Loaded/Created FileScan Database...

02 Jun 2010 21:45:00 - Loading AV Library [DB]...

02 Jun 2010 21:45:06 - AV Library Loaded [DB-DIRECT].

02 Jun 2010 21:45:06 - MWAV doing self scanning...

02 Jun 2010 21:45:07 - MWAV files are clean.
02 Jun 2010 21:45:12 - Virus Database Date: 02 Jun 2010
02 Jun 2010 21:45:12 - Virus Database Count: 6121217

02 Jun 2010 21:45:35 - **********************************************************
02 Jun 2010 21:45:35 - eScan Anti Virus & Spyware Toolkit Utility.
02 Jun 2010 21:45:35 - Copyright © MicroWorld Technologies
02 Jun 2010 21:45:35 -
02 Jun 2010 21:45:35 - Support: support@escanav.com
02 Jun 2010 21:45:35 - Web: eScan - AntiVirus & Content Security
02 Jun 2010 21:45:35 - **********************************************************
02 Jun 2010 21:45:35 - Version 12.0.26[DB] (C:\USERS\BIANCA\APPDATA\LOCAL\TEMP\MEXETMP.EX~)
02 Jun 2010 21:45:35 - Log File: C:\Users\bianca\AppData\Local\Temp\MWAV.LOG
02 Jun 2010 21:45:35 - User Account: bianca (Administrator Mode)
02 Jun 2010 21:45:35 - Windows Root Folder: C:\Windows
02 Jun 2010 21:45:35 - Windows Sys32 Folder: C:\Windows\system32
02 Jun 2010 21:45:35 - OS: Windows Vista [OS Install Date: 24 Dec 2007 21:25:27]
02 Jun 2010 21:45:35 - Ver: Personal Service Pack 2 (Build 6002)
02 Jun 2010 21:45:35 - Latest Date of files inside MWAV: Wed Jun 2 21:52:41 2010.
02 Jun 2010 21:45:35 - Plugins FileCount: 681 Sign Version: 7.31986

02 Jun 2010 21:45:43 - Options Selected by User:
02 Jun 2010 21:45:43 - Memory Check: Enabled
02 Jun 2010 21:45:43 - Registry Check: Enabled
02 Jun 2010 21:45:43 - StartUp Folder Check: Disabled
02 Jun 2010 21:45:43 - System Folder Check: Disabled
02 Jun 2010 21:45:43 - Services Check: Enabled
02 Jun 2010 21:45:43 - Scan Spyware: Disabled
02 Jun 2010 21:45:43 - Drive Check: Disabled
02 Jun 2010 21:45:43 - All Drive Check :Enabled
02 Jun 2010 21:45:43 - Folder Check: Disabled
02 Jun 2010 21:45:43 - SCAN: All_Files
02 Jun 2010 21:45:43 - MWAV Mode: Only Scan files (Do Not Clean)


02 Jun 2010 21:45:45 - ***** Scanning Memory Files *****
02 Jun 2010 21:46:40 - Scanning File C:\Users\bianca\AppData\Local\mutbihpv.exe
02 Jun 2010 21:46:40 - File C:\Users\bianca\AppData\Local\mutbihpv.exe infected by "Gen:Variant.NaviPromo.2 (DB)" Virus! Action Taken: No Action Taken.


02 Jun 2010 21:46:50 - ***** Scanning Registry Files *****
02 Jun 2010 21:46:51 - ERROR!!! Invalid Entry = Preispiraten.de - Preisvergleich (in key HKLM\Software\Microsoft\Internet Explorer\Extensions\{C08CAF1D-C0A3-40D5-9970-06D067EAC017}). No Action Taken.
02 Jun 2010 21:47:00 - Invalid Entry DLLName = igfxdev.dll (in key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui). Action Taken: Deleting Registry Key igfxcui.
02 Jun 2010 21:47:02 - ERROR!!! Invalid Entry IgfxTray = C:\Windows\system32\igfxtray.exe (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:02 - ERROR!!! Invalid Entry HotKeysCmds = C:\Windows\system32\hkcmd.exe (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:02 - ERROR!!! Invalid Entry Persistence = C:\Windows\system32\igfxpers.exe (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:02 - ERROR!!! Invalid Entry HWSetup = \HWSetup.exe hwSetUP (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:02 - ERROR!!! Invalid Entry NDSTray.exe = NDSTray.exe (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:03 - ERROR!!! Invalid Entry Performance Center = C:\Program Files\Ascentive\Performance Center\APCMain.exe -m (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:03 - Invalid DLL [C:\Users\bianca\AppData\Local\Temp\efcBusQh.dll] in entry [MSServer=rundll32.exe C:\Users\bianca\AppData\Local\Temp\efcBusQh.dll,#1]
02 Jun 2010 21:47:03 - ERROR!!! Invalid Entry MSServer = C:\Windows\system32\rundll32.exe (in key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:03 - ERROR!!! Invalid Entry Host Process = C:\Users\bianca\svchost.exe (in key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:03 - Invalid DLL [C:\Users\bianca\AppData\Local\Temp\jkkHxVlM.dll] in entry [cmds=rundll32.exe C:\Users\bianca\AppData\Local\Temp\jkkHxVlM.dll,c]
02 Jun 2010 21:47:03 - ERROR!!! Invalid Entry cmds = C:\Windows\system32\rundll32.exe (in key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
02 Jun 2010 21:47:07 - Scanning File c:\users\bianca\appdata\local\mutbihpv.exe
02 Jun 2010 21:47:07 - File c:\users\bianca\appdata\local\mutbihpv.exe infected by "Gen:Variant.NaviPromo.2 (DB)" Virus! Action Taken: No Action Taken.


02 Jun 2010 21:47:08 - ***** Scanning Service Files *****
02 Jun 2010 21:47:10 - ERROR!!! Invalid Entry "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" in HKLM\SYSTEM\CurrentControlSet\Services\Automatisches LiveUpdate - Scheduler. Action Taken: No Action Taken.
02 Jun 2010 21:47:10 - ERROR!!! Invalid Entry \SystemRoot\system32\drivers\blbdrive.sys in HKLM\SYSTEM\CurrentControlSet\Services\blbdrive. Action Taken: No Action Taken.
02 Jun 2010 21:47:24 - ERROR!!! Invalid Entry \??\C:\Users\bianca\AppData\Local\Temp\gkmixern.sys in HKLM\SYSTEM\CurrentControlSet\Services\gkmixern. Action Taken: No Action Taken.
02 Jun 2010 21:47:25 - ERROR!!! Invalid Entry system32\DRIVERS\igdkmd32.sys in HKLM\SYSTEM\CurrentControlSet\Services\igfx. Action Taken: No Action Taken.
02 Jun 2010 21:47:30 - ERROR!!! Invalid Entry \??\C:\Windows\system32\drivers\PDNMp50.sys in HKLM\SYSTEM\CurrentControlSet\Services\PDNMp50. Action Taken: No Action Taken.
02 Jun 2010 21:47:30 - ERROR!!! Invalid Entry \??\C:\Windows\system32\drivers\PDNSp50.sys in HKLM\SYSTEM\CurrentControlSet\Services\PDNSp50. Action Taken: No Action Taken.
02 Jun 2010 21:47:34 - C:\Windows\system32\Drivers\sptd.sys not Scanned. Possibly password protected...
02 Jun 2010 21:47:36 - ERROR!!! Invalid Entry c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe in HKLM\SYSTEM\CurrentControlSet\Services\TOSHIBA Bluetooth Service. Action Taken: No Action Taken.
02 Jun 2010 21:47:36 - ERROR!!! Invalid Entry system32\DRIVERS\TpChoice.sys in HKLM\SYSTEM\CurrentControlSet\Services\TpChoice. Action Taken: No Action Taken.

02 Jun 2010 21:47:41 - ***** Scanning All Drives *****
02 Jun 2010 21:47:41 - Scanning C:\ Drive
02 Jun 2010 21:50:15 - C:\Boot\BCD not Scanned. Possibly password protected...
02 Jun 2010 21:50:15 - C:\Boot\BCD.LOG not Scanned. Possibly password protected...
02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMCoreA.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMCoreA.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMCoreB.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMCoreB.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMCoreC.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMCoreC.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMCoreD.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMCoreD.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMCoreE.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMCoreE.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMDataServicesA.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMDataServicesA.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMDataServicesB.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMDataServicesB.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMDataServicesC.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMDataServicesC.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMDataServicesD.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMDataServicesD.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:55 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMDataServicesE.dll
02 Jun 2010 21:55:55 - File C:\Program Files\Common Files\Nero\Lib\NMDataServicesE.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreA.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreA.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreB.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreB.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreC.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreC.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreD.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreD.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreE.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreE.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreF.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreF.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreG.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreG.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreH.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreH.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreI.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreI.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:56 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreJ.dll
02 Jun 2010 21:55:56 - File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreJ.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:57 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMSearchA.dll
02 Jun 2010 21:55:57 - File C:\Program Files\Common Files\Nero\Lib\NMSearchA.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:57 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMSearchB.dll
02 Jun 2010 21:55:57 - File C:\Program Files\Common Files\Nero\Lib\NMSearchB.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:57 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMSearchC.dll
02 Jun 2010 21:55:57 - File C:\Program Files\Common Files\Nero\Lib\NMSearchC.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:57 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMSearchD.dll
02 Jun 2010 21:55:57 - File C:\Program Files\Common Files\Nero\Lib\NMSearchD.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:55:57 - Scanning File C:\Program Files\Common Files\Nero\Lib\NMSearchE.dll
02 Jun 2010 21:55:57 - File C:\Program Files\Common Files\Nero\Lib\NMSearchE.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.

02 Jun 2010 21:56:43 - C:\Program Files\DAEMON Tools\SetupDTSB.exe not Scanned. Possibly password protected...
02 Jun 2010 22:27:13 - ScanFile took 6.96 Secs [C:\Program Files\Vuze\plugins\azemp\vuzeplayer.exe]...

02 Jun 2010 22:29:24 - Scanning File C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4915192e.qua
02 Jun 2010 22:29:24 - File C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4915192e.qua infected by "Gen:Adware.Heur.hq1@Rm!VmBji (DB)" Virus! Action Taken: No Action Taken.

02 Jun 2010 22:29:28 - C:\ProgramData\Avira\AntiVir Desktop\TEMP\avguard.tmp not Scanned. Possibly password protected...
02 Jun 2010 22:31:46 - C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log not Scanned. Possibly password protected...
02 Jun 2010 22:31:47 - C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log not Scanned. Possibly password protected...
02 Jun 2010 22:31:51 - C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb not Scanned. Possibly password protected...
02 Jun 2010 22:31:51 - C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb not Scanned. Possibly password protected...
02 Jun 2010 22:32:24 - INVALID ATTRIBUTES FOR FOLDER [C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB PC Camera ]. IGNORING.
02 Jun 2010 22:40:30 - C:\Users\bianca\AppData\Local\Adobe\Acrobat\8.0\Updater\updater.log not Scanned. Possibly password protected...
02 Jun 2010 22:41:38 - Scanning File C:\Users\bianca\AppData\Local\IM\Identities\{1BF9C0B6-CD0A-43DF-BA2B-29CC48074C61}\Message Store\Attachments\Factura49.zip
02 Jun 2010 22:41:38 - File C:\Users\bianca\AppData\Local\IM\Identities\{1BF9C0B6-CD0A-43DF-BA2B-29CC48074C61}\Message Store\Attachments\Factura49.zip infected by "Gen:Trojan.Heur.bmW@rbTmwAlaf (DB)" Virus! Action Taken: No Action Taken.

02 Jun 2010 22:48:13 - C:\Users\bianca\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 not Scanned. Possibly password protected...
02 Jun 2010 22:49:22 - Scanning File C:\Users\bianca\AppData\Local\mutbihpv.exe
02 Jun 2010 22:49:22 - File C:\Users\bianca\AppData\Local\mutbihpv.exe infected by "Gen:Variant.NaviPromo.2 (DB)" Virus! Action Taken: No Action Taken.

02 Jun 2010 23:01:38 - Scanning File C:\Users\bianca\AppData\Roaming\SecuROM\UserData\???????????p?????????
02 Jun 2010 23:01:38 - ERROR(3)!!! ScanFile fails for C:\Users\bianca\AppData\Roaming\SecuROM\UserData\???????????p?????????
02 Jun 2010 23:01:38 - Scanning File C:\Users\bianca\AppData\Roaming\SecuROM\UserData\???????????p?????????
02 Jun 2010 23:01:38 - ERROR(3)!!! ScanFile fails for C:\Users\bianca\AppData\Roaming\SecuROM\UserData\???????????p?????????
02 Jun 2010 23:06:49 - Scanning File C:\Users\bianca\Desktop\imsodx\iMSDOX-ZooTycoon2003P1_Trainer.exe
02 Jun 2010 23:06:49 - File C:\Users\bianca\Desktop\imsodx\iMSDOX-ZooTycoon2003P1_Trainer.exe infected by "Trojan.Generic.3249375 (DB)" Virus! Action Taken: No Action Taken.

02 Jun 2010 23:08:51 - C:\Users\bianca\ntuser.dat.LOG1 not Scanned. Possibly password protected...
02 Jun 2010 23:16:52 - C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat not Scanned. Possibly password protected...
02 Jun 2010 23:16:52 - C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat not Scanned. Possibly password protected...
02 Jun 2010 23:16:54 - C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 not Scanned. Possibly password protected...
02 Jun 2010 23:16:55 - C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 not Scanned. Possibly password protected...
02 Jun 2010 23:19:04 - C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 not Scanned. Possibly password protected...
02 Jun 2010 23:19:04 - C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 not Scanned. Possibly password protected...
02 Jun 2010 23:19:25 - ScanFile took 12.84 Secs [C:\Windows\System32\atioglxx.dll]...

02 Jun 2010 23:20:21 - C:\Windows\System32\catroot2\edb.log not Scanned. Possibly password protected...
02 Jun 2010 23:20:21 - C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb not Scanned. Possibly password protected...
02 Jun 2010 23:20:21 - C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\COMPONENTS not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\COMPONENTS.LOG1 not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\DEFAULT not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\DEFAULT.LOG1 not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\RegBack\COMPONENTS not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\RegBack\DEFAULT not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\RegBack\SAM not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\RegBack\SECURITY not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\RegBack\SOFTWARE not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\RegBack\SYSTEM not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\SAM not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\SAM.LOG1 not Scanned. Possibly password protected...
02 Jun 2010 23:20:32 - C:\Windows\System32\config\SECURITY not Scanned. Possibly password protected...
02 Jun 2010 23:20:33 - C:\Windows\System32\config\SECURITY.LOG1 not Scanned. Possibly password protected...
02 Jun 2010 23:20:33 - C:\Windows\System32\config\SOFTWARE not Scanned. Possibly password protected...
02 Jun 2010 23:20:33 - C:\Windows\System32\config\SOFTWARE.LOG1 not Scanned. Possibly password protected...
02 Jun 2010 23:20:33 - C:\Windows\System32\config\SOFTWARE.LOG2 not Scanned. Possibly password protected...
02 Jun 2010 23:20:33 - C:\Windows\System32\config\SYSTEM not Scanned. Possibly password protected...
02 Jun 2010 23:20:33 - C:\Windows\System32\config\SYSTEM.LOG1 not Scanned. Possibly password protected...
02 Jun 2010 23:33:05 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl not Scanned. Possibly password protected...
02 Jun 2010 23:33:05 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl not Scanned. Possibly password protected...
02 Jun 2010 23:33:05 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl not Scanned. Possibly password protected...
02 Jun 2010 23:33:05 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl not Scanned. Possibly password protected...
02 Jun 2010 23:33:05 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTkerberos.etl not Scanned. Possibly password protected...
03 Jun 2010 10:48:11 - Scanning E:\ Drive

03 Jun 2010 11:08:58 - ***** Checking for specific ITW Viruses *****

03 Jun 2010 11:08:59 - ***** Scanning complete. *****

03 Jun 2010 11:08:59 - Total Objects Scanned: 207128
03 Jun 2010 11:08:59 - Total Critical Objects: 6
03 Jun 2010 11:08:59 - Total Disinfected Objects: 0
03 Jun 2010 11:08:59 - Total Objects Renamed: 0
03 Jun 2010 11:08:59 - Total Deleted Objects: 0
03 Jun 2010 11:08:59 - Total Errors: 19
03 Jun 2010 11:08:59 - Time Elapsed: 03:10:57
03 Jun 2010 11:08:59 - Virus Database Date: 02 Jun 2010
03 Jun 2010 11:08:59 - Virus Database Count: 6121217

03 Jun 2010 11:08:59 - Scan Completed.

Bianca28 03.06.2010 16:31

Ich nochmal, hier auch mal die Files von OTL. Ich lass einfach mal alles so laufen was ich hier bei den anderen so finde. Aber bitte könnte sich jemand meiner annehmen??
Das wäre super. Vielen Dank nochmal das ihr den LEuten hier so helft. :-)


OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 03.06.2010 15:35:30 - Run 1
OTL by OldTimer - Version 3.2.5.3    Folder = C:\Users\bianca\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 65,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 63,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 5,95 Gb Free Space | 7,98% Space Free | Partition Type: NTFS
Drive D: | 5,59 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 73,06 Gb Total Space | 28,99 Gb Free Space | 39,69% Space Free | Partition Type: NTFS
Drive F: | 612,59 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: BIANCAS-PC
Current User Name: bianca
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "E:\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "E:\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
vbefile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation)
wsffile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- E:\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{068ECC26-936E-4E08-986B-F236C6EED446}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=c:\windows\system32\dfsr.exe |
"{0F47E7C2-3C25-4243-805B-0EF5F7EC145E}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{11615A97-33A5-4D20-8A66-05E0D029E8D1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{27D8E3C6-B5FD-4C9D-A310-8A496E60D5DA}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{2C8D5A6B-44D4-42BE-BB0E-097DB718952F}" = lport=6004 | protocol=17 | dir=in | app=e:\office12\outlook.exe |
"{38E528F4-A8F5-4228-97F5-7D85B6643D34}" = lport=7060 | protocol=6 | dir=in | name=84.17.180.120 |
"{4F994A27-4587-4BE1-8496-7A6180C98E13}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{605F60A4-0B7D-49CC-9D64-659508158668}" = rport=3702 | protocol=17 | dir=out | app=c:\windows\system32\p2phost.exe |
"{64081A96-BFD3-4BDA-99A6-1B91FFCA05FD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6494A7D3-0DFF-4998-AA2D-18BD83360545}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{67BBD2F3-5EDE-4C23-A601-30AD2DB71CC8}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{6D67E2CD-DABE-4262-B5BF-B96538AFC530}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{74DD70FA-649B-4859-91BA-FD2C6EB20035}" = lport=rpc | protocol=6 | dir=in | svc=policyagent | app=c:\windows\system32\svchost.exe |
"{78FF07C0-B66C-4F6E-987A-8D48D247B5C4}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{7D51151B-BFFC-495C-B23C-772353DDFB3F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{80A2FD47-C1AC-4185-ADE3-11FD37761F72}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{86461E19-08ED-480F-9917-DE44C2C7CE56}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8873C567-FF8D-48D6-8A20-0D7227AF4A36}" = lport=3702 | protocol=17 | dir=in | app=c:\windows\system32\p2phost.exe |
"{94131767-186E-4B7E-B583-9B728D785E36}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{954010F2-85C4-41F1-9A6B-1C42B4DBA748}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9EEE41F7-8760-4BF7-BF4D-E62B016A2C8F}" = lport=7100 | protocol=6 | dir=in | name=hxxp://sadk.e-eis.net |
"{AC01D33C-CF3B-4F4B-9983-9C12A09F03CF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C5AEB80B-806F-40C9-AABA-529AFF89BE4A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{CC0C0615-A2C4-47C7-8814-AB26480CAD9F}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=c:\windows\system32\dfsr.exe |
"{CD2C202E-B289-415E-8EF7-2BC05B687632}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CE802640-1225-4839-B20D-25B8A4B5318B}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=c:\windows\system32\svchost.exe |
"{D39C02F2-E980-4176-95C9-AAFE53BD4FFA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DAF1FC81-D611-4942-A68D-C447BD1663E6}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{E3C2771C-4EE6-4472-9D29-8C764FE00575}" = lport=2869 | protocol=6 | dir=in | app=system |
"{ECF4CB68-C710-429A-9146-B3A7FC4767D3}" = lport=80 | protocol=6 | dir=in | app=system |
"{EFEF95CD-A358-4062-B67D-B6C183F193D4}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=c:\windows\system32\svchost.exe |
"{F95320D9-D91C-490B-84F5-9DEE49BD8D44}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03D06829-19BA-4C1A-AE8C-0ACAD7A53EDB}" = protocol=17 | dir=in | app=c:\program files\microsoft games\zoo tycoon 2\zt.exe |
"{03E10E59-805B-4543-99E6-9274C615B11C}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{05F32B33-702B-4E27-A86E-538F5732C364}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{0FC18158-4EC4-43C7-9C02-77DB9116E32F}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{17360FDA-804B-481F-8FDD-2997FD6B08B6}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{188301AB-0905-4A17-ADF4-D2D7ABB3B8E2}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{1A1AC003-2D93-487E-8DCF-E71F18414261}" = protocol=6 | dir=in | app=c:\windows\system32\p2phost.exe |
"{20046A3C-1377-4891-B58B-C63FE1423640}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{3409AE99-BE65-4174-B072-86B5BFD44AF0}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{377504DC-8727-4769-8855-C34388C54EB0}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{37CC9DF4-DE61-4A37-9ECB-72D551F734DE}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{4926188D-A666-47C1-9AFE-DF14B6CB5E1C}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{49285878-59E7-445E-BC76-93AB5E52D898}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{54009EBB-9C8C-4A31-8AAD-3F213024C9A3}" = protocol=6 | dir=in | app=c:\program files\windows collaboration\wincollab.exe |
"{54D655EF-44CC-4582-8B7A-092AD4F459F4}" = protocol=6 | dir=in | app=c:\program files\microsoft games\zoo tycoon 2\zt.exe |
"{5677F59C-E0E6-4CEB-B3A4-1CD97075D842}" = protocol=6 | dir=in | svc=winmgmt | app=c:\windows\system32\svchost.exe |
"{5965D249-4349-4480-B28C-647536C39E47}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{5D3CBCAE-8949-4BFC-BF6E-93A2387E04AA}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{61795B46-C5C4-43F4-941C-9B9350259CA0}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"{6AB9C893-42C5-41F0-A3CB-FD99DEAFA51B}" = protocol=6 | dir=out | app=c:\program files\windows collaboration\wincollab.exe |
"{6EA9A59A-C025-4055-BCA0-18588514B83B}" = protocol=6 | dir=in | app=c:\program files\msi\arcsoft totalmedia\totalmedia.exe |
"{786DEF3E-288C-465B-9E47-02BF1FAC3A07}" = protocol=6 | dir=in | app=c:\windows\system32\wbem\unsecapp.exe |
"{8488A4C0-8E25-4243-9183-B068862EBCAC}" = protocol=17 | dir=in | app=c:\program files\windows collaboration\wincollab.exe |
"{935B27B6-7EBF-4E24-A97B-3CA0874238DC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9E4A50FE-22B3-4F3A-B42A-9C1223A74BAE}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{9F9E35AE-03C7-4FD7-A745-7483C108B25A}" = protocol=6 | dir=out | app=c:\windows\system32\p2phost.exe |
"{9FF3D209-2793-45C6-9C35-3B7A9D5C3A60}" = protocol=6 | dir=in | app=e:\office12\onenote.exe |
"{A087952D-45F7-41B7-83CA-1035B44EBB02}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{A0C7C87C-2D4A-4D23-A7F0-F3670096B63D}" = protocol=6 | dir=in | app=e:\office12\groove.exe |
"{A37B206E-1F21-472E-BD3D-CC2B843E9723}" = protocol=6 | dir=out | svc=winmgmt | app=c:\windows\system32\svchost.exe |
"{A3B0D00E-B998-4F26-A5A7-C5FA90807094}" = protocol=17 | dir=out | app=c:\program files\windows collaboration\wincollab.exe |
"{A4ADFC6F-D9BD-4868-B916-010A6E197EA5}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{ADFA35EB-7C07-43CC-8F32-C8E4B81694E7}" = protocol=17 | dir=in | app=e:\office12\onenote.exe |
"{B1D8115C-0419-48BB-8365-EE5EA4F785CB}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{B9BF67D0-22FF-410E-9FFB-3228630B54F6}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C4BE151B-AEDD-41CC-964C-F45EAD9FB67C}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{C8BC6A8F-4760-408B-80D9-539E0E036380}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{C997DD90-B58E-4774-965E-D6F81F782886}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CDC7560F-7A5A-4E4F-B9C3-31A511438C4E}" = dir=in | app=c:\program files\myspace\im\myspaceim.exe |
"{D20F122D-F1D1-4B26-A582-45E92FEB319C}" = protocol=17 | dir=in | app=e:\office12\groove.exe |
"{D8A29F5D-E135-429A-AAD1-A1551E6C1A2D}" = protocol=6 | dir=in | app=c:\program files\firaxis games\sid meier's civilization 4\civilization4.exe |
"{E4C3F5E1-19B6-4E7F-9786-EE8072D26683}" = protocol=17 | dir=in | app=c:\program files\msi\arcsoft totalmedia\totalmedia.exe |
"{E5718534-DBEA-4688-B91B-92C2406C802E}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{E6C7DD93-33B6-4011-AEE0-6A2900B58207}" = protocol=17 | dir=in | app=c:\program files\firaxis games\sid meier's civilization 4\civilization4.exe |
"{E79E5147-B741-4604-A032-30F9913BE659}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{ECFB19C2-00E8-4EB9-83AE-041AEBC85687}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{EE50654B-A6D8-4931-8A6A-5B10503D3184}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F8BABA07-F01D-4DB5-B207-8F45BE64432E}" = protocol=6 | dir=in | app=c:\windows\system32\plasrv.exe |
"{FCCB2A33-014B-42D3-8B8A-40192567581B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"TCP Query User{0B84E3EE-4F81-4205-BB8F-6FDB8476AC1E}C:\program files\ubisoft\die siedler 7\data\base\_dbg\bin\release\settlers7r.exe" = protocol=6 | dir=in | app=c:\program files\ubisoft\die siedler 7\data\base\_dbg\bin\release\settlers7r.exe |
"TCP Query User{2D3AAFA8-D63E-43C1-AA82-357D71143254}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"TCP Query User{2D90B3DA-EA93-4BE8-B3B4-444F8CEA0E20}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{440A5B37-210D-4F56-8894-0DEB6FA54793}C:\program files\ubisoft\funatics\die siedler ii - die nächste generation\bin\s2dng.exe" = protocol=6 | dir=in | app=c:\program files\ubisoft\funatics\die siedler ii - die nächste generation\bin\s2dng.exe |
"TCP Query User{597E5DD2-68F8-4C41-8A78-3A42E3B9AF16}C:\program files\emcrypt v4.1\emcrypt.exe" = protocol=6 | dir=in | app=c:\program files\emcrypt v4.1\emcrypt.exe |
"TCP Query User{6C1135F6-1B50-4F27-839F-B1CD2556AFDC}E:\die siedler - aufbruch der kulturen\bin\sadk.exe" = protocol=6 | dir=in | app=e:\die siedler - aufbruch der kulturen\bin\sadk.exe |
"TCP Query User{7E8A571D-5806-4D22-808B-C0926C540E9C}C:\program files\wyzo\wyzo.exe" = protocol=6 | dir=in | app=c:\program files\wyzo\wyzo.exe |
"TCP Query User{A6ADB237-0134-438A-9E42-1F2EB2DB4813}C:\program files\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare\bearshare.exe |
"TCP Query User{B02371AE-3DE9-4FAD-9EC6-7EE723522391}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
"TCP Query User{D20FB5F5-C7AB-45B9-93CE-2A1E24911051}C:\program files\web.de\web.de multimessenger\messengr.exe" = protocol=6 | dir=in | app=c:\program files\web.de\web.de multimessenger\messengr.exe |
"TCP Query User{E5B1E14B-B2B9-4B6D-9BB3-D05B42E27272}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{EAA38AAB-7619-4799-9F27-4A3C75186982}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{0390F194-2AB5-409E-9E96-96164E1175FB}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{10E393BE-F339-48B2-8A28-184C561A0CE2}C:\program files\ubisoft\die siedler 7\data\base\_dbg\bin\release\settlers7r.exe" = protocol=17 | dir=in | app=c:\program files\ubisoft\die siedler 7\data\base\_dbg\bin\release\settlers7r.exe |
"UDP Query User{1D600A05-0725-4189-B8FD-83F01DBA540C}C:\program files\ubisoft\funatics\die siedler ii - die nächste generation\bin\s2dng.exe" = protocol=17 | dir=in | app=c:\program files\ubisoft\funatics\die siedler ii - die nächste generation\bin\s2dng.exe |
"UDP Query User{5E8BA695-7B44-4C6A-B6C4-0B813B903271}C:\program files\emcrypt v4.1\emcrypt.exe" = protocol=17 | dir=in | app=c:\program files\emcrypt v4.1\emcrypt.exe |
"UDP Query User{69A9DE51-B116-4AE0-9483-3C1A33708C22}E:\die siedler - aufbruch der kulturen\bin\sadk.exe" = protocol=17 | dir=in | app=e:\die siedler - aufbruch der kulturen\bin\sadk.exe |
"UDP Query User{6C1B4677-FC0A-45DB-A964-BFCE48E84F05}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{6EC6623F-5A63-41F4-8391-BF1BAF93D1AA}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{74BE3A19-567C-4342-993F-1EE00C5C0D8B}C:\program files\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare\bearshare.exe |
"UDP Query User{BCD0A0D6-F200-4830-890B-EFEFA60C1688}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{EE2FB5F8-595B-4349-83E0-6E36AC07D294}C:\program files\web.de\web.de multimessenger\messengr.exe" = protocol=17 | dir=in | app=c:\program files\web.de\web.de multimessenger\messengr.exe |
"UDP Query User{F0CEAA7E-1B98-4E02-B37A-4147782C98F4}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{FD951006-FCD0-41E7-AFE1-3CF3346BDFC9}C:\program files\wyzo\wyzo.exe" = protocol=17 | dir=in | app=c:\program files\wyzo\wyzo.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00004EE8-1E8B-BB10-6588-07DF0D120F6B}" = CCC Help Korean
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02E107FC-1861-FC4A-E80F-07DA9DC5808C}" = Catalyst Control Center Graphics Previews Vista
"{03C55715-3545-2DF8-8C64-2BB877955150}" = Catalyst Control Center Localization Chinese Traditional
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0755396F-D048-8CDD-6AC3-C7C83A6869B5}" = CCC Help Czech
"{08B7B1F9-A8EB-7632-FFC3-04AB5328143B}" = CCC Help Chinese Standard
"{09F52B2B-8B36-130C-5EBD-6E5FFC5FA0B7}" = CCC Help English
"{0E1C53DA-DF86-845A-7BEB-14C4A8E0B150}" = Catalyst Control Center Localization Korean
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{146E206D-7D2C-493A-B431-1F1D16E822AF}" = MobileMe Control Panel
"{15292416-A464-4FBA-BB96-7298EAACFC07}" = Zoo Tycoon 2 - Extinct Animals
"{15382D89-6EF6-4D21-9484-B500F2B10E46}" = PhotoMail Maker
"{15B924BC-AEB2-7E31-F414-1FC7B385846A}" = CCC Help Greek
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{20CFE038-F4CE-0716-DCA0-04BBD67FE5EA}" = CCC Help Turkish
"{2126F5BB-AB90-083F-7AA8-A29D73819DAA}" = CCC Help French
"{22543949-70E8-45D0-A938-F38143EB8BF8}" = Catalyst Control Center - Branding
"{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product Information
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{26E6EA50-532C-8CF3-5EB4-8C8D306EAB58}" = Catalyst Control Center Localization Polish
"{27CD3616-D3B0-834C-89A3-4FC5CEE7374D}" = Catalyst Control Center Graphics Full Existing
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{28912B61-0265-3C33-7EC7-14345AC76E3D}" = CCC Help Hungarian
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie
"{2D06C1FE-8454-5663-D0E9-1C130FD96446}" = Catalyst Control Center Localization Norwegian
"{2FA41EBB-3F5A-35C3-85D6-51EC72A11FBD}" = Google Gears
"{30F9E15A-EE25-6D32-62CE-2E6BEAED3766}" = CCC Help Italian
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java(TM) SE Runtime Environment 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{342A19C7-3335-C02F-F1DD-3A0B49C3D047}" = Catalyst Control Center Localization Greek
"{34EF4F67-A3CE-DAB6-FA06-7C4C59A0D462}" = Catalyst Control Center Localization Swedish
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CE22BE4-E2D3-F0E8-1C52-1B5A5F97B876}" = Catalyst Control Center Localization Turkish
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{400F4990-B111-109A-6B08-E80CB42651AA}" = Catalyst Control Center Localization Danish
"{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}" = ATI Catalyst Install Manager
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{44479884-EB6D-38DA-1D3E-835625E40F7E}" = Catalyst Control Center Graphics Previews Common
"{480CA9F1-17E2-0B15-9684-511C0A083F92}" = Catalyst Control Center Localization Thai
"{4817189D-1785-4627-A33C-39FD90919300}" = Die Sims™ 2 Haustiere
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F31172C-2692-BB28-8F5B-86474CEC5D33}" = Catalyst Control Center Localization Chinese Standard
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{54AAFB71-6DCB-32EB-8F91-DA7643497ED4}" = Catalyst Control Center Localization Spanish
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5D1CB0EC-0CA2-B4FD-2A10-2503A3CF7E46}" = Catalyst Control Center Localization Italian
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5EFE618D-0100-6DE7-9894-5FD057103871}" = Catalyst Control Center Core Implementation
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{63D10FBD-5667-DAD9-0B31-CED873B3F7EF}" = Catalyst Control Center Graphics Light
"{6522C636-B04C-4333-9BEB-9E0C0B6350D6}" = Die Sims™ 2 Küchen- und Bad-Einrichtungs-Accessoires
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6E17F9751-F056-4335-B718-8AF1B1092AFB}" = Die Sims™ 2 IKEA® Home-Accessoires
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = Die Sims 2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74292F90-895A-4FC6-A692-9641532B1B63}" = ArcSoft TotalMedia 3.5
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{7936153F-8D09-BC11-6DC4-1D4DEAB9D680}" = CCC Help Thai
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{816B8A02-76F0-AE47-E28F-0AD114CC261E}" = CCC Help Polish
"{82AB4F83-BBBA-8F04-EE34-11F74E39A4B6}" = Catalyst Control Center Localization German
"{85EBB283-65AF-4C53-9EBE-7C0A232762F7}" = AGEIA PhysX v7.03.21
"{86158699-F584-0DC9-119D-C5A6591090FB}" = CCC Help Chinese Traditional
"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}" = Die Sims™ 2 Freizeit-Spaß
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{88EB38EF-4D2C-436D-ABD3-56B232674062}" = ICQ7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
"{920E3F1A-0B73-807D-EE0E-E6D89D4E5DDE}" = Catalyst Control Center Localization Dutch
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{985AF15E-776F-3CDD-EB92-2DAFF02697FB}" = Skins
"{98CE747E-4948-10B0-BBF0-5981A11114D1}" = Catalyst Control Center Localization Hungarian
"{99F54171-AE4A-579B-1544-5870478FC8F7}" = Catalyst Control Center Graphics Full New
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C916142-C18C-429D-BFED-40094A7E0BEB}" = Die Siedler 7
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{9EDBB857-8028-49CD-B9C9-0B4D10CD1031}" = Nero 8
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A1BAD23B-748C-50FD-CCA9-956C3F54D138}" = CCC Help German
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A6D4234C-CB02-4048-AC3E-AD09404FA35A}" = Emdedded IR Driver
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{ABD82299-8034-4B44-4FDB-3F8971C20575}" = CCC Help Finnish
"{AC76BA86-7AD7-1031-7B44-A81300000003}" = Adobe Reader 8.1.5 - Deutsch
"{AC76BA86-7AD7-1031-7B44-A81300000003}_814" = KB408682
"{ACE07E37-A416-9A6B-D352-C776FFA49493}" = CCC Help Spanish
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2AEC44B-F926-773D-D028-77CADEF8D9D3}" = CCC Help Norwegian
"{B537ACDB-7C56-83B6-034C-A5AF6400F789}" = CCC Help Swedish
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B6F5B704-06D3-4687-90F3-6195304AD755}" = Die Sims™ 2 Apartment-Leben
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{B8AB4511-EECC-9299-45B3-F25F4774F6F2}" = CCC Help Russian
"{BD75C1A0-F0ED-B54A-B49C-3244B47BA803}" = ccc-utility
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C6317675-96CC-D2AE-40F2-698F3DED64B4}" = CCC Help Portuguese
"{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser
"{C7FAEA9E-A14C-D8C9-EEE9-8D43F9E09565}" = Catalyst Control Center Localization Czech
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CC35C434-FFC8-BDD8-44F0-ED0972484C56}" = CCC Help Dutch
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D646CA8B-5227-1598-5E9C-132B2D89A38D}" = Catalyst Control Center Localization Japanese
"{D8E302CB-8517-3E9B-C6C9-E90A21C6EFC5}" = CCC Help Danish
"{DB780B85-B4B5-4864-A49C-9B706B169C93}" = TIPCI
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = Die Sims™ 2 Vier Jahreszeiten
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9-Reihe
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}" = Die Sims™ 2 Party-Accessoires
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0BB634D-B374-A329-EE5D-22C279F92A7F}" = ccc-core-static
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1C1426C-6670-4068-6398-EB490D45979F}" = Catalyst Control Center Localization Portuguese
"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = Die Sims™ 2 Gute Reise
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth
"{F8B5B814-A3BF-F83F-09ED-AED9EE88211A}" = Catalyst Control Center Localization French
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{F927176F-F8F0-FACF-A57E-4F95714B6F00}" = Catalyst Control Center Localization Russian
"{F9466082-90E9-4BE4-92F0-CF0AF195B0CF}" = USB PC Camera
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone-Konfigurationsprogramm
"{FA7BB878-FC13-7548-13D3-18A53381014D}" = CCC Help Japanese
"{FB56EE4D-7CBC-6FDC-E336-52BD269E4CF6}" = Catalyst Control Center Localization Finnish
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"3DSex_Villa_ThriXXX" = 3DSex_Villa_ThriXXX
"8461-7759-5462-8226" = Vuze
"ActiveXControlPad" = Microsoft ActiveX Control Pad
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"ClearProg" = ClearProg 1.6.0 Final
"Diner Dash 5 Boom Collector's Edition H33T" = Diner Dash 5 Boom Collector's Edition H33T
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX-Setup
"Dr. DivX 1.0 Beta" = Dr. DivX 1.0 Beta
"ecmkjc" = Favorit
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Farm Frenzy 3 Russian Roulette 1.0" = Farm Frenzy 3 Russian Roulette 1.0
"Farm Frenzy Pizza Party 1.00" = Farm Frenzy Pizza Party 1.00
"ffdshow_is1" = ffdshow [rev 1828] [2008-01-29]
"Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition 2.0.0.1 (D)
"FotokalenderDigitalPrintLab3" = DigitalPrintLab3
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"IncrediMail" = IncrediMail 2.0
"InstallShield_{15292416-A464-4FBA-BB96-7298EAACFC07}" = Zoo Tycoon 2 - Extinct Animals
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisorkennwort
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{A6D4234C-CB02-4048-AC3E-AD09404FA35A}" = Emdedded IR Driver
"InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"LogonStudio Vista" = LogonStudio Vista
"MAGIX Online Druck Service D" = MAGIX Online Druck Service 2.3.2.0 (D)
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"myphotobook" = myphotobook 3.1
"OfotoEZUpload" = KODAK EASYSHARE Gallery Upload ActiveX Control
"PDF-ShellTools_is1" = PDF-ShellTools 1.0.0.9 Trial
"PhotoMail" = PhotoMail Maker
"Picasa 3" = Picasa 3
"QuickStores-Toolbar_is1" = QuickStores-Toolbar 1.0.0
"RealPlayer 6.0" = RealPlayer
"Rommé 1" = Rommé 1
"SADK" = Die Siedler - Aufbruch der Kulturen
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SysInfo" = Creative Systeminformationen
"T-Online eMail Center Desktop-Startsymbol Fax" = T-Online eMail Center Desktop-Startsymbol Fax 1.0
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"VLC media player" = VideoLAN VLC media player 0.8.1
"Vuze_Remote Toolbar" = Vuze_Remote Toolbar
"WEB.DE SmartSurfer" = WEB.DE SmartSurfer
"WildTangent hp Master Uninstall" = HP Games
"Windows Media Encoder 9" = Windows Media Encoder 9-Reihe
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"Xfire" = Xfire (remove only)
"XP-Games JRE" = XP-Games JRE
"Zoo Tycoon 1.0" = Zoo Tycoon: Complete Collection
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"HappyFoto Bestellsoftware" = HappyFoto Bestellsoftware
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 03.06.2010 08:05:33 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4850321
 
Error - 03.06.2010 08:05:34 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 03.06.2010 08:05:34 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4851397
 
Error - 03.06.2010 08:05:34 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4851397
 
Error - 03.06.2010 08:05:39 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 03.06.2010 08:05:39 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4856108
 
Error - 03.06.2010 08:05:39 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4856108
 
Error - 03.06.2010 08:05:41 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 03.06.2010 08:05:41 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4857933
 
Error - 03.06.2010 08:05:41 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4857933
 
[ System Events ]
Error - 02.06.2010 14:44:46 | Computer Name = biancas-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 02.06.2010 14:44:46 | Computer Name = biancas-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 02.06.2010 14:44:46 | Computer Name = biancas-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 02.06.2010 14:50:35 | Computer Name = biancas-PC | Source = bowser | ID = 8003
Description =
 
Error - 02.06.2010 15:26:39 | Computer Name = biancas-PC | Source = bowser | ID = 8003
Description =
 
Error - 02.06.2010 16:02:38 | Computer Name = biancas-PC | Source = bowser | ID = 8003
Description =
 
Error - 02.06.2010 16:26:37 | Computer Name = biancas-PC | Source = bowser | ID = 8003
Description =
 
Error - 03.06.2010 08:10:17 | Computer Name = biancas-PC | Source = bowser | ID = 8003
Description =
 
Error - 03.06.2010 08:50:19 | Computer Name = biancas-PC | Source = bowser | ID = 8003
Description =
 
Error - 03.06.2010 09:14:20 | Computer Name = biancas-PC | Source = bowser | ID = 8003
Description =
 
 
< End of report >

--- --- ---

Bianca28 04.06.2010 18:52

Darf ich fragen warum mir hier keiner Antwortet?? Hab ich die falschen LogFiles gepostet? ODer was anderes falsch gemacht? Bitte, die Seiten machen sich immernoch auf. mal mehr mal weniger.
Kann mir niemand helfen?

Bianca28 06.06.2010 11:10

Ich nochmal. Bitte warum Antwortet mir niemand????? Seit heute bekomm ich die Virus meldungen kaum noch weg. Es scheinrt sich um ein und den selben zu handeln: TR/Dldr.Renos. und dann immer wieder mit neuen endungen

Bitte, mein Virenprogramm scheint ihm nihct Herr zu werden. Er kommt immer wieder!!!!

Ich wollte auch eigetnlich noch was anhängen aber das ist zu groß. wollt euch zeigen welche Sachen mir mein Programm anzeigt.
Egal es ist immer dieser Renos. Meist mir dem anhang LX.1 oder KF.1960

Bitte helft mir!!!!!

Bianca28 06.06.2010 12:30

hier die Logfiles von Malwarebytes. Er hat 7 gefunden und eines konnte er nicht löschen ich weiß aber nicht welches bitte helft mir. langsam bin ich echt verzweifelt!!!!

MalwareHero 06.06.2010 12:56

Zitat:

Zitat von Bianca28 (Beitrag 530755)
hier die Logfiles von Malwarebytes. Er hat 7 gefunden und eines konnte er nicht löschen ich weiß aber nicht welches bitte helft mir. langsam bin ich echt verzweifelt!!!!

Hallo,

bleib ganz ruhig. Ich helfe dir.

Ich melde mich wieder wenn ich mir die logs durchgeschaut habe.

lg.

MalwareHero 06.06.2010 13:01

Du hast nur das eine log von OTL gepostet. du musst beide posten:

# Wenn der Scan beendet wurde werden 2 Logfiles erstellt

Bianca28 06.06.2010 13:07

DANKE!!! endlich ein lebenszeichen. Ich mach mich gleich auch die Scuhe nach dem 2.
Übrigens habe ich meinen PC neu gestartet nachdem ich Malwarebytes ausgeführt habe und habe es gleich nochmal laufen lassen. Er findet jetzt nichts mehr. Aber dem Frieden trau ich nicht denn gleich nach dem Hochfahren des Laptops kam wieder die meldung von AV das er dieses Renos XL1 wieder gefunden hat...

MalwareHero 06.06.2010 13:14

Zitat:

Zitat von Bianca28 (Beitrag 530764)
Aber dem Frieden trau ich nicht denn gleich nach dem Hochfahren des Laptops kam wieder die meldung von AV das er dieses Renos XL1 wieder gefunden hat...

bei dir ist einiges an Malware/virus am laufen. So schnell lässt sich das nicht entfernen. Poste das fehlende OTL log, das ist zur analyse wichtig.

Bianca28 06.06.2010 13:16

irgendwie fginde ich es nicht. soll ich nochmal alles scannen und dann beide posten?

Bianca28 06.06.2010 13:22

Ich habe jetzt nochmal einen quickscan von OTL ausgeführt und das hat er mir gegeben. zum anhängen ist es zu groß. Ich kopiere es hier rein:

OTL Logfile:
Code:

OTL logfile created on: 06.06.2010 14:13:14 - Run 2
OTL by OldTimer - Version 3.2.5.3    Folder = C:\Users\bianca\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 52,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 70,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 9,41 Gb Free Space | 12,62% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 73,06 Gb Total Space | 28,99 Gb Free Space | 39,69% Space Free | Partition Type: NTFS
Drive F: | 612,59 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: BIANCAS-PC
Current User Name: bianca
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\bianca\Desktop\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
PRC - C:\Programme\IncrediMail\bin\ImApp.exe (IncrediMail, Ltd.)
PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Programme\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Programme\Google\Update\1.2.183.23\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\avcenter.exe (Avira GmbH)
PRC - C:\Programme\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - E:\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\Programme\Synaptics\SynTP\SynToshiba.exe (Synaptics, Inc.)
PRC - C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Programme\WEB.DE\WEB.DE SmartSurfer\SmurfService.exe (United Internet AG)
PRC - C:\Programme\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Programme\Common Files\Nero\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Programme\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Windows\vsnp325.exe ()
PRC - C:\Windows\tsnp325.exe ()
PRC - C:\Programme\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Programme\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Programme\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Programme\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Programme\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Programme\TOSHIBA\Utilities\KeNotify.exe ()
PRC - C:\Windows\Pixart\Pac7302\Monitor.exe (PixArt Imaging Incorporation)
PRC - C:\Windows\System32\BrmfRsmg.exe (Brother Industries, Ltd.)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\bianca\Desktop\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d\msvcr80.dll (Microsoft Corporation)
MOD - C:\Windows\System32\WindowsCodecs.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1\ATL80.dll (Microsoft Corporation)
MOD - C:\Programme\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)
MOD - C:\Windows\System32\SLC.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msshsq.dll (Microsoft Corporation)
MOD - C:\Windows\System32\mssprxy.dll (Microsoft Corporation)
MOD - C:\Windows\System32\EhStorShell.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cscapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - E:\Office12\GrooveUtil.dll (Microsoft Corporation)
MOD - E:\Office12\GrooveSystemServices.dll (Microsoft Corporation)
MOD - E:\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
MOD - E:\Office12\GrooveNew.dll (Microsoft Corporation)
MOD - C:\Windows\System32\thumbcache.dll (Microsoft Corporation)
MOD - C:\Windows\System32\duser.dll (Microsoft Corporation)
MOD - C:\Windows\System32\actxprxy.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (TOSHIBA Bluetooth Service) --  File not found
SRV - (Automatisches LiveUpdate - Scheduler) --  File not found
SRV - (GameConsoleService) -- C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (ACDaemon) -- C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service) -- E:\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (SmartSurferManager) -- C:\Program Files\WEB.DE\WEB.DE SmartSurfer\SmurfService.exe (United Internet AG)
SRV - (TosCoSrv) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (IAANTMON) Intel(R) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (CFSvcs) -- C:\Programme\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (brmfrsmg) -- C:\Windows\System32\BrmfRsmg.exe (Brother Industries, Ltd.)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (TODDSrv) -- C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (FirebirdServerMAGIXInstance) -- C:\Programme\MAGIX\Common\Database\bin\fbserver.exe (MAGIX®)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (AF15BDA) -- C:\Windows\System32\drivers\AF15BDA.sys (AfaTech                  )
DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (mf) -- C:\Windows\System32\drivers\mf.sys (Microsoft Corporation)
DRV - (SVKP) -- C:\Windows\System32\SVKP.sys (AntiCracking)
DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (TVALZ) -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (PAC7302) -- C:\Windows\System32\drivers\PAC7302.SYS (PixArt Imaging Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (SNP325) USB PC Camera (SNPSTD325) -- C:\Windows\System32\drivers\snp325.sys (Sonix Co. Ltd.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (motmodem) -- C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (motccgp) -- C:\Windows\System32\drivers\motccgp.sys (Motorola)
DRV - (CplIR) -- C:\Windows\system32\DRIVERS\CplIR.SYS (COMPAL ELECTRONIC INC.)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (tifm21) -- C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (motccgpfl) -- C:\Windows\System32\drivers\motccgpfl.sys (Motorola)
DRV - (KR10N) -- C:\Windows\system32\drivers\kr10n.sys (TOSHIBA CORPORATION)
DRV - (KR10I) -- C:\Windows\system32\drivers\kr10i.sys (TOSHIBA CORPORATION)
DRV - (MotoSwitchService) -- C:\Windows\System32\drivers\motswch.sys (Motorola)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (Afc) -- C:\Windows\System32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrUsbScn) Brother MFC-Scannertreiber (USB) -- C:\Windows\System32\drivers\BrUsbScn.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) Brother WDM-Treiber (seriell) -- C:\Windows\System32\drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) Brother MFC-nur-Fax-Modem (USB) -- C:\Windows\System32\drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (brfilt) -- C:\Windows\System32\drivers\BrFilt.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (tosrfec) -- C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) -- C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (LPCFilter) -- C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV - (sfsync02) StarForce Protection Synchronization Driver (version 2.x) -- C:\Windows\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\System32\drivers\sfdrv01.sys (Protection Technology (StarForce))
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\System32\drivers\sfhlp02.sys (Protection Technology (StarForce))
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://alice.aol.de
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://msn.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 60 E6 7D F0 A5 F6 CA 01  [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultthis.engineName: "Google Powered Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.startup.homepage: "hxxp://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.36.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.3
FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:2.5.8.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: quickstores@quickstores.de:1.0.0
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q="
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008.11.19 15:48:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2010.03.06 10:02:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.03 09:55:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.05.30 20:09:08 | 000,000,000 | ---D | M]
 
[2008.06.18 19:01:52 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\mozilla\Extensions
[2010.06.05 19:56:52 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\mozilla\Firefox\Profiles\fgkslinf.default\extensions
[2010.04.28 19:37:59 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\bianca\AppData\Roaming\mozilla\Firefox\Profiles\fgkslinf.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.03.31 13:10:14 | 000,000,000 | ---D | M] (Vuze Remote Toolbar) -- C:\Users\bianca\AppData\Roaming\mozilla\Firefox\Profiles\fgkslinf.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2009.10.26 10:12:55 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\mozilla\Firefox\Profiles\fgkslinf.default\extensions\anycolor.pavlos256@gmail.com
[2009.09.07 18:05:26 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\mozilla\Firefox\Profiles\fgkslinf.default\extensions\moveplayer@movenetworks.com
[2010.04.14 09:36:01 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\mozilla\Firefox\Profiles\fgkslinf.default\extensions\personas@christopher.beard
[2010.03.31 14:05:27 | 000,000,903 | ---- | M] () -- C:\Users\bianca\AppData\Roaming\Mozilla\FireFox\Profiles\fgkslinf.default\searchplugins\conduit.xml
[2008.12.12 20:23:54 | 000,002,158 | ---- | M] () -- C:\Users\bianca\AppData\Roaming\Mozilla\FireFox\Profiles\fgkslinf.default\searchplugins\MySpace.xml
[2010.06.05 19:56:52 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.06.02 18:46:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.06.02 21:20:19 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions\quickstores@quickstores.de
[2010.06.02 18:45:23 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.03.12 15:17:29 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.03.12 15:17:29 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.03.12 15:17:29 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.03.12 15:17:29 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.03.12 15:17:29 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programme\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Programme\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [00TCrdMain] C:\Programme\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [GrooveMonitor] E:\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe File not found
O4 - HKLM..\Run: [HSON] C:\Programme\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HWSetup]  File not found
O4 - HKLM..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe File not found
O4 - HKLM..\Run: [KeNotify] C:\Programme\TOSHIBA\Utilities\KeNotify.exe ()
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NDSTray.exe]  File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [PAC7302_Monitor] C:\Windows\Pixart\Pac7302\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe File not found
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SmoothView] C:\Programme\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [snp325] C:\Windows\vsnp325.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (TOSHIBA)
O4 - HKLM..\Run: [Toshiba Registration] C:\Programme\TOSHIBA\Registration\ToshibaRegistration.exe (Toshiba)
O4 - HKLM..\Run: [TPwrMain] C:\Programme\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [tsnp325] C:\Windows\tsnp325.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [MSServer] C:\Users\bianca\AppData\Local\Temp\efcBusQh.DLL File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Die Siedler II - Die nächste Generation.LNK = C:\Program Files\Ubisoft\Funatics\Die Siedler II - Die nächste Generation\bin\RegistrationReminder.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 153
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 153
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - E:\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Gears-Einstellungen - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Programme\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} -  File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\bianca\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
O24 - Desktop BackupWallPaper: C:\Users\bianca\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - E:\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006.08.23 15:07:39 | 000,778,240 | R--- | M] (Funatics Studio alpha Ltd. & Co. KG) - F:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2006.07.17 15:52:00 | 000,000,068 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{bc85d363-b254-11dc-8fdf-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{bc85d363-b254-11dc-8fdf-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Autorun.exe -- [2006.08.23 15:07:39 | 000,778,240 | R--- | M] (Funatics Studio alpha Ltd. & Co. KG)
O33 - MountPoints2\{c0ab97d1-d48b-11dc-977f-001b38ab7ce6}\Shell - "" = AutoRun
O33 - MountPoints2\{c0ab97d1-d48b-11dc-977f-001b38ab7ce6}\Shell\AutoRun\command - "" = D:\autorun.exe -- File not found
O33 - MountPoints2\{c0ab97db-d48b-11dc-977f-001b38ab7ce6}\Shell - "" = AutoRun
O33 - MountPoints2\{c0ab97db-d48b-11dc-977f-001b38ab7ce6}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 90 Days ==========
 
[2010.06.06 13:06:31 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Roaming\Malwarebytes
[2010.06.06 13:05:38 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.06.06 13:05:34 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.06.06 13:05:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.06.06 13:05:33 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2010.06.02 21:41:29 | 000,000,000 | ---D | C] -- C:\Windows\VDLL.DLL
[2010.06.02 21:41:29 | 000,000,000 | ---D | C] -- C:\Windows\System32\runouce.exe
[2010.06.02 21:41:29 | 000,000,000 | ---D | C] -- C:\Windows\RUNDL132.EXE
[2010.06.02 21:41:29 | 000,000,000 | ---D | C] -- C:\Windows\logo_1.exe
[2010.06.02 21:38:30 | 000,034,048 | ---- | C] (MicroWorld Technologies Inc.) -- C:\Windows\System32\eEmpty.exe
[2010.06.02 21:38:26 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\MicroWorld
[2010.06.02 21:38:20 | 000,000,000 | ---D | C] -- C:\ProgramData\MicroWorld
[2010.06.02 21:20:18 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Roaming\QuickStoresToolbar
[2010.06.02 21:20:16 | 000,000,000 | ---D | C] -- C:\Programme\ClearProg
[2010.06.02 20:55:04 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Roaming\Avira
[2010.06.02 18:16:19 | 000,000,000 | ---D | C] -- C:\Users\bianca\Documents\Settlers7
[2010.06.01 15:48:56 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Local\S2
[2010.06.01 14:44:27 | 000,000,000 | ---D | C] -- C:\Programme\Ubisoft
[2010.05.31 21:13:47 | 000,000,000 | ---D | C] -- C:\Programme\Games
[2010.05.30 20:04:56 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2010.05.28 19:25:35 | 000,000,000 | ---D | C] -- C:\ProgramData\FarmFrenzy3_Russia
[2010.05.28 19:25:02 | 000,000,000 | ---D | C] -- C:\Programme\Alawar Entertainment
[2010.05.16 20:14:53 | 000,000,000 | ---D | C] -- C:\Programme\bigup16
[2010.05.16 16:09:52 | 000,000,000 | ---D | C] -- C:\ProgramData\FarmFrenzy3
[2010.05.16 16:09:47 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\AlawarWrapper
[2010.05.16 16:09:47 | 000,000,000 | ---D | C] -- C:\ProgramData\AlawarWrapper
[2010.05.16 12:05:39 | 000,000,000 | ---D | C] -- C:\ProgramData\FarmFrenzy-PizzaParty
[2010.05.10 12:51:41 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Microsoft Games
[2010.05.09 23:18:12 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Roaming\Microsoft Games
[2010.05.09 23:18:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Games
[2010.04.29 11:19:38 | 000,000,000 | ---D | C] -- C:\Programme\iPod
[2010.04.29 11:19:26 | 000,000,000 | ---D | C] -- C:\Programme\iTunes
[2010.04.29 11:15:31 | 000,000,000 | ---D | C] -- C:\Programme\Bonjour
[2010.04.29 10:42:28 | 000,000,000 | ---D | C] -- C:\ProgramData\PhotoMail
[2010.04.29 10:42:27 | 000,000,000 | ---D | C] -- C:\Programme\PhotoMail Maker
[2010.04.27 00:04:42 | 000,353,592 | ---- | C] (DivX, Inc.) -- C:\Windows\System32\DivXControlPanelApplet.cpl
[2010.04.23 18:49:52 | 000,051,992 | ---- | C] (AVIRA GmbH) -- C:\Windows\System32\drivers\avgntdd.sys
[2010.04.23 18:49:52 | 000,017,016 | ---- | C] (AVIRA GmbH) -- C:\Windows\System32\drivers\avgntmgr.sys
[2010.04.09 20:25:31 | 000,000,000 | ---D | C] -- C:\Users\bianca\Desktop\imsodx
[2010.04.07 19:57:06 | 000,000,000 | R--D | C] -- C:\Users\bianca\Pictures
[2010.04.05 17:28:17 | 000,000,000 | ---D | C] -- C:\Users\bianca\Desktop\Sims2
[2010.04.05 14:29:02 | 000,000,000 | ---D | C] -- C:\Users\bianca\Documents\EA Games
[2010.04.05 13:30:11 | 000,695,664 | ---- | C] (Noël Danjou) -- C:\Users\bianca\Desktop\lfwiz.exe
[2010.04.03 09:51:59 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010.04.03 09:48:40 | 000,000,000 | ---D | C] -- C:\Programme\QuickTime
[2010.03.31 18:42:51 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\EA Games
[2010.03.31 13:10:15 | 000,000,000 | ---D | C] -- C:\Programme\Vuze
[2010.03.31 13:10:08 | 000,000,000 | ---D | C] -- C:\Programme\Conduit
[2010.03.31 13:10:06 | 000,000,000 | ---D | C] -- C:\Programme\Vuze_Remote
[2010.03.31 10:22:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010.03.28 21:19:12 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Local\iRinger
[2010.03.28 21:13:19 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Local\Apple_Inc
[2010.03.28 20:35:23 | 000,000,000 | ---D | C] -- C:\Users\bianca\Documents\iPhone Ringtones
[2010.03.14 19:07:37 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee Security Scan
[2010.03.14 19:07:37 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2010.03.14 19:07:30 | 000,000,000 | ---D | C] -- C:\Programme\McAfee Security Scan
[2010.03.14 17:08:06 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Roaming\Wild Tangent
[2010.03.13 23:20:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Kristanix Games
[2010.03.11 22:12:14 | 000,000,000 | ---D | C] -- C:\ProgramData\FarmFrenzy3_Arctica
[2010.03.08 19:59:18 | 000,094,208 | ---- | C] (DivX, Inc.) -- C:\Windows\System32\dpl100.dll
[2008.01.19 17:58:34 | 000,147,456 | ---- | C] ( ) -- C:\Windows\System32\rsnp325.dll
[2008.01.19 17:58:34 | 000,057,344 | ---- | C] ( ) -- C:\Windows\System32\vsnp325.dll
[2008.01.19 17:58:34 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnp325.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 90 Days ==========
 
[2010.06.06 14:14:16 | 005,767,168 | -HS- | M] () -- C:\Users\bianca\NTUSER.DAT
[2010.06.06 14:06:00 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010.06.06 13:38:23 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010.06.06 13:35:58 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2010.06.06 13:35:55 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.06.06 13:35:55 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.06.06 13:35:54 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010.06.06 13:35:52 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.06.06 13:35:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.06.06 13:34:08 | 000,524,288 | -HS- | M] () -- C:\Users\bianca\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010.06.06 13:34:08 | 000,065,536 | -HS- | M] () -- C:\Users\bianca\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010.06.06 13:33:31 | 000,004,616 | ---- | M] () -- C:\Users\bianca\AppData\Local\mutbihpv_navps.dat
[2010.06.06 13:33:19 | 003,656,409 | -H-- | M] () -- C:\Users\bianca\AppData\Local\IconCache.db
[2010.06.06 13:33:00 | 000,003,442 | ---- | M] () -- C:\Users\bianca\AppData\Local\mutbihpv.dat
[2010.06.06 13:05:41 | 000,000,823 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.06.06 10:39:20 | 000,000,092 | ---- | M] () -- C:\Users\bianca\AppData\Local\ecmkjc.bat
[2010.06.04 19:24:50 | 000,000,680 | ---- | M] () -- C:\Users\bianca\AppData\Local\d3d9caps.dat
[2010.06.04 00:27:13 | 000,242,503 | ---- | M] () -- C:\Users\bianca\AppData\Local\mutbihpv_nav.dat
[2010.06.03 17:36:33 | 000,493,613 | ---- | M] () -- C:\Users\bianca\Documents\pinfect.zip
[2010.06.03 11:55:09 | 000,000,052 | ---- | M] () -- C:\Windows\Lic.xxx
[2010.06.02 21:38:29 | 000,034,048 | ---- | M] (MicroWorld Technologies Inc.) -- C:\Windows\System32\eEmpty.exe
[2010.06.02 21:20:19 | 000,000,187 | ---- | M] () -- C:\Users\bianca\Desktop\QuickStores.url
[2010.06.02 21:20:16 | 000,000,821 | ---- | M] () -- C:\Users\Public\Desktop\ClearProg.lnk
[2010.06.01 14:46:29 | 000,001,519 | ---- | M] () -- C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Die Siedler II - Die nächste Generation.LNK
[2010.05.31 21:13:51 | 000,002,010 | ---- | M] () -- C:\Users\bianca\Desktop\Farm Frenzy Pizza Party.lnk
[2010.05.30 20:06:43 | 000,001,976 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2010.05.28 19:25:12 | 000,001,226 | ---- | M] () -- C:\Users\bianca\Desktop\Farm Frenzy 3 Russian Roulette.lnk
[2010.05.24 23:36:55 | 001,418,612 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.05.24 23:36:55 | 000,618,442 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.05.24 23:36:55 | 000,587,178 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010.05.24 23:36:55 | 000,122,648 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.05.24 23:36:55 | 000,101,250 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.05.24 23:12:29 | 000,082,944 | ---- | M] () -- C:\Users\bianca\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.21 11:12:45 | 000,002,078 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2010.05.16 20:15:30 | 000,001,272 | ---- | M] () -- C:\Users\bianca\Desktop\Diner Dash 5 Boom Collector's Edition.lnk
[2010.05.10 15:25:28 | 000,000,575 | ---- | M] () -- C:\Windows\win.ini
[2010.05.10 13:01:21 | 000,001,019 | ---- | M] () -- C:\Users\bianca\Desktop\Spielen.lnk
[2010.05.09 18:01:07 | 000,001,638 | ---- | M] () -- C:\Users\Public\Desktop\Vuze.lnk
[2010.05.06 16:57:18 | 001,156,143 | ---- | M] () -- C:\Users\bianca\Desktop\ANGEBOT_Schütze_Apr1.pdf
[2010.05.03 22:25:03 | 000,209,832 | ---- | M] () -- C:\Users\bianca\Desktop\Englisch test.pdf
[2010.04.29 12:19:24 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.04.29 12:19:14 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.04.29 11:28:25 | 000,407,800 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.04.29 11:20:31 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010.04.29 10:41:09 | 000,001,895 | ---- | M] () -- C:\Users\Public\Desktop\IncrediMail.lnk
[2010.04.27 00:04:42 | 000,353,592 | ---- | M] (DivX, Inc.) -- C:\Windows\System32\DivXControlPanelApplet.cpl
[2010.04.07 13:34:15 | 000,010,845 | ---- | M] () -- C:\Users\bianca\Desktop\Job Center SteglitzBerlin.docx
[2010.04.05 16:54:14 | 000,002,097 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims™ 2 Apartment-Leben.lnk
[2010.03.31 17:45:55 | 000,108,144 | ---- | M] (Sony DADC Austria AG.) -- C:\Windows\System32\CmdLineExt.dll
[2010.03.28 21:17:43 | 003,486,811 | ---- | M] () -- C:\Users\bianca\iRinger_2.6.0.0.exe
[2010.03.17 19:18:23 | 000,001,717 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2010.03.11 23:07:02 | 000,000,162 | -H-- | M] () -- C:\Users\bianca\Desktop\~$Alice.docx
[2010.03.08 19:59:18 | 000,094,208 | ---- | M] (DivX, Inc.) -- C:\Windows\System32\dpl100.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010.06.06 13:05:41 | 000,000,823 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.06.03 11:52:41 | 000,493,613 | ---- | C] () -- C:\Users\bianca\Documents\pinfect.zip
[2010.06.02 21:39:16 | 000,000,052 | ---- | C] () -- C:\Windows\Lic.xxx
[2010.06.02 21:38:30 | 000,000,522 | ---- | C] () -- C:\Windows\System32\Microsoft.VC80.CRT.manifest
[2010.06.02 21:20:19 | 000,000,187 | ---- | C] () -- C:\Users\bianca\Desktop\QuickStores.url
[2010.06.02 21:20:16 | 000,000,821 | ---- | C] () -- C:\Users\Public\Desktop\ClearProg.lnk
[2010.06.02 14:13:28 | 000,242,503 | ---- | C] () -- C:\Users\bianca\AppData\Local\mutbihpv_nav.dat
[2010.06.02 14:13:28 | 000,004,616 | ---- | C] () -- C:\Users\bianca\AppData\Local\mutbihpv_navps.dat
[2010.06.02 14:13:28 | 000,003,442 | ---- | C] () -- C:\Users\bianca\AppData\Local\mutbihpv.dat
[2010.06.01 14:46:29 | 000,001,519 | ---- | C] () -- C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Die Siedler II - Die nächste Generation.LNK
[2010.05.31 21:13:51 | 000,002,010 | ---- | C] () -- C:\Users\bianca\Desktop\Farm Frenzy Pizza Party.lnk
[2010.05.30 20:06:43 | 000,001,976 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2010.05.28 19:25:12 | 000,001,226 | ---- | C] () -- C:\Users\bianca\Desktop\Farm Frenzy 3 Russian Roulette.lnk
[2010.05.21 11:12:45 | 000,002,078 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2010.05.16 20:15:30 | 000,001,272 | ---- | C] () -- C:\Users\bianca\Desktop\Diner Dash 5 Boom Collector's Edition.lnk
[2010.05.10 13:01:21 | 000,001,019 | ---- | C] () -- C:\Users\bianca\Desktop\Spielen.lnk
[2010.05.06 16:57:18 | 001,156,143 | ---- | C] () -- C:\Users\bianca\Desktop\ANGEBOT_Schütze_Apr1.pdf
[2010.05.03 22:25:03 | 000,209,832 | ---- | C] () -- C:\Users\bianca\Desktop\Englisch test.pdf
[2010.04.29 11:20:31 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010.04.07 13:34:14 | 000,010,845 | ---- | C] () -- C:\Users\bianca\Desktop\Job Center SteglitzBerlin.docx
[2010.04.05 16:54:14 | 000,002,097 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims™ 2 Apartment-Leben.lnk
[2010.03.31 13:10:37 | 000,001,638 | ---- | C] () -- C:\Users\Public\Desktop\Vuze.lnk
[2010.03.28 21:17:43 | 003,486,811 | ---- | C] () -- C:\Users\bianca\iRinger_2.6.0.0.exe
[2010.03.14 19:07:34 | 000,001,717 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2010.03.11 23:07:02 | 000,000,162 | -H-- | C] () -- C:\Users\bianca\Desktop\~$Alice.docx
[2010.01.28 20:41:23 | 000,307,200 | ---- | C] () -- C:\Windows\System32\AscSQLite.dll
[2009.10.05 11:44:01 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2008.11.06 18:37:32 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2008.11.06 18:34:00 | 000,000,416 | ---- | C] () -- C:\Windows\System32\dtu100.dll.manifest
[2008.07.19 17:47:14 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2008.05.30 08:44:21 | 000,042,982 | ---- | C] () -- C:\Windows\System32\pddsladp.dll
[2008.04.16 17:35:01 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2008.02.26 12:28:46 | 000,000,027 | ---- | C] () -- C:\Windows\BRMFBIDI.INI
[2008.02.06 10:14:24 | 000,611,064 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2008.02.06 10:14:24 | 000,142,904 | ---- | C] () -- C:\Windows\System32\drivers\sptddrv1.sys
[2008.01.30 17:58:52 | 000,007,680 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2008.01.30 17:58:52 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2008.01.19 17:58:34 | 000,015,498 | ---- | C] () -- C:\Windows\snp325.ini
[2007.12.30 19:56:01 | 000,000,566 | ---- | C] () -- C:\Windows\System32\SP7302.INI
[2007.12.29 13:56:37 | 000,000,008 | RHS- | C] () -- C:\Windows\System32\CE6AF3E6A1.sys
[2007.12.27 12:16:36 | 000,000,403 | ---- | C] () -- C:\Windows\ODBC.INI
[2007.12.25 02:18:30 | 000,278,728 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2007.12.25 02:18:30 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2007.07.12 10:54:33 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2007.07.12 10:26:24 | 000,036,864 | ---- | C] () -- C:\Windows\System32\HWS_Ctrl.dll
[2007.04.16 08:35:21 | 000,006,642 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2007.04.16 08:02:55 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2007.04.16 07:26:26 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2007.04.16 07:26:26 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2007.04.16 07:26:26 | 000,010,146 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2007.04.16 07:26:26 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2007.04.16 07:23:35 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2007.04.16 06:38:28 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1227.dll
[2007.03.26 10:45:18 | 000,071,208 | ---- | C] () -- C:\Windows\System32\PhysXLoader.dll
[2007.02.20 14:59:08 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2007.02.20 14:59:04 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2006.12.05 13:05:06 | 000,114,688 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005.11.23 14:55:42 | 000,024,576 | ---- | C] () -- C:\Windows\System32\SPCtl.dll
[2005.07.22 21:30:20 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll
[2004.03.30 09:15:02 | 000,051,200 | ---- | C] () -- C:\Windows\System32\ThriXXX010205PNG.dll
[2004.03.30 09:15:01 | 000,056,832 | ---- | C] () -- C:\Windows\System32\ThriXXX015003JP2.dll
[2004.03.30 09:15:01 | 000,023,040 | ---- | C] () -- C:\Windows\System32\ThriXXX010104Z.dll
[2003.05.23 12:08:52 | 000,107,008 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2003.05.23 12:08:52 | 000,020,992 | ---- | C] () -- C:\Windows\System32\ogg.dll
 
========== LOP Check ==========
 
[2008.12.10 14:17:04 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\.wyzo
[2008.11.21 19:11:29 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Ancient Quest of Saqqarah_msn
[2010.06.02 19:58:40 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Azureus
[2009.01.23 20:18:23 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\BeachPartyCraze
[2009.04.05 17:37:09 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Boolat Games
[2007.12.25 01:56:35 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\DesktopSMS
[2009.10.29 15:19:31 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\FILEminimizerPictures
[2008.11.13 22:07:53 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Flood Light Games
[2008.04.24 21:18:00 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Gaijin Ent
[2009.03.09 22:48:57 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Gamelab
[2009.03.12 13:44:01 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Go Go Gourmet
[2008.11.12 16:03:55 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Go-Go Gourmet Chef of the Year
[2010.05.30 20:09:40 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\ICQ
[2009.01.12 19:11:58 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\iWin
[2008.07.28 10:49:39 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\LimeWire
[2008.06.01 13:10:20 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Meridian93
[2009.04.09 14:44:24 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\My Games
[2009.03.20 18:45:52 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\MysteryStudio
[2009.01.11 18:05:32 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Oberon Games
[2007.12.25 13:34:49 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\PeerNetworking
[2009.01.12 22:34:17 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\PetShowCraze
[2010.05.16 20:15:44 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\PlayFirst
[2009.01.25 00:02:31 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Pogo Games
[2010.06.02 21:20:19 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\QuickStoresToolbar
[2009.01.02 12:50:02 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Sandlot Games
[2008.05.17 20:54:09 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Sierra Entertainment
[2008.11.07 21:15:46 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\SmartSurfer
[2007.12.30 22:07:19 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\SoundSpectrum
[2007.12.25 00:31:23 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Toshiba
[2010.03.31 13:25:20 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\uTorrent
[2008.11.27 21:01:22 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Valusoft
[2009.01.25 22:31:32 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\ViquaSoft
[2010.03.31 13:42:21 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\WEB.DE
[2008.01.09 16:42:01 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\WEBDE
[2010.03.14 17:08:06 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Wild Tangent
[2009.03.20 17:52:24 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\WildTangent
[2008.06.03 09:37:14 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Zylom
[2010.06.06 13:34:30 | 000,032,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:51387F29
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:3B3A35EC
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:05816AFA
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:753B0F80
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:3AE22B1A
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:38849DE5
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:965253AF
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:E98C5DD9
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:E54FA796
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:41099CE9
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:273A8657
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:61E5F0F7
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:E1982A23
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:4D066AD2
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:87FA5E8A
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:37CE0F2E
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:F65733F1
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:8EEE3BBB
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:765C6A14
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:DAFD38AE
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:92D18A5E
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:0207454C
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:45FE2B4E
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A42A9F39
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:4F636E25
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:3447AB86
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:A94968B5
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:1CB8D545
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:F50F1555
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:8C458D50
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:20DB61D6
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:18AE7C5A
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:A73B0434
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:E1F04E8D
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:1D6686D8
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:C4A1F01E
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:D26DD363
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:26C3D553
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:997E6AF4
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:588B60C7
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5EBA4934
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:33A7CC67
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:E71141D2
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D88D995C
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:5216CD26
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:B14B4A95
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:74699137
< End of report >

--- --- ---

Bianca28 06.06.2010 13:31

ha, jetzt weiß ich was du meintest. Hab nochmal normal gescannt und hier sind beide Files: Extras:

OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 06.06.2010 14:26:03 - Run 2
OTL by OldTimer - Version 3.2.5.3    Folder = C:\Users\bianca\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 50,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 69,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 9,38 Gb Free Space | 12,59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 73,06 Gb Total Space | 28,99 Gb Free Space | 39,69% Space Free | Partition Type: NTFS
Drive F: | 612,59 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: BIANCAS-PC
Current User Name: bianca
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "E:\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "E:\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
vbefile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation)
wsffile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- E:\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{068ECC26-936E-4E08-986B-F236C6EED446}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=c:\windows\system32\dfsr.exe |
"{0F47E7C2-3C25-4243-805B-0EF5F7EC145E}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{11615A97-33A5-4D20-8A66-05E0D029E8D1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{27D8E3C6-B5FD-4C9D-A310-8A496E60D5DA}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{2C8D5A6B-44D4-42BE-BB0E-097DB718952F}" = lport=6004 | protocol=17 | dir=in | app=e:\office12\outlook.exe |
"{38E528F4-A8F5-4228-97F5-7D85B6643D34}" = lport=7060 | protocol=6 | dir=in | name=84.17.180.120 |
"{4F994A27-4587-4BE1-8496-7A6180C98E13}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{605F60A4-0B7D-49CC-9D64-659508158668}" = rport=3702 | protocol=17 | dir=out | app=c:\windows\system32\p2phost.exe |
"{64081A96-BFD3-4BDA-99A6-1B91FFCA05FD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6494A7D3-0DFF-4998-AA2D-18BD83360545}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{67BBD2F3-5EDE-4C23-A601-30AD2DB71CC8}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{6D67E2CD-DABE-4262-B5BF-B96538AFC530}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{74DD70FA-649B-4859-91BA-FD2C6EB20035}" = lport=rpc | protocol=6 | dir=in | svc=policyagent | app=c:\windows\system32\svchost.exe |
"{78FF07C0-B66C-4F6E-987A-8D48D247B5C4}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{7D51151B-BFFC-495C-B23C-772353DDFB3F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{80A2FD47-C1AC-4185-ADE3-11FD37761F72}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{86461E19-08ED-480F-9917-DE44C2C7CE56}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8873C567-FF8D-48D6-8A20-0D7227AF4A36}" = lport=3702 | protocol=17 | dir=in | app=c:\windows\system32\p2phost.exe |
"{94131767-186E-4B7E-B583-9B728D785E36}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{954010F2-85C4-41F1-9A6B-1C42B4DBA748}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9EEE41F7-8760-4BF7-BF4D-E62B016A2C8F}" = lport=7100 | protocol=6 | dir=in | name=hxxp://sadk.e-eis.net |
"{AC01D33C-CF3B-4F4B-9983-9C12A09F03CF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C5AEB80B-806F-40C9-AABA-529AFF89BE4A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{CC0C0615-A2C4-47C7-8814-AB26480CAD9F}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=c:\windows\system32\dfsr.exe |
"{CD2C202E-B289-415E-8EF7-2BC05B687632}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CE802640-1225-4839-B20D-25B8A4B5318B}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=c:\windows\system32\svchost.exe |
"{D39C02F2-E980-4176-95C9-AAFE53BD4FFA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DAF1FC81-D611-4942-A68D-C447BD1663E6}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{E3C2771C-4EE6-4472-9D29-8C764FE00575}" = lport=2869 | protocol=6 | dir=in | app=system |
"{ECF4CB68-C710-429A-9146-B3A7FC4767D3}" = lport=80 | protocol=6 | dir=in | app=system |
"{EFEF95CD-A358-4062-B67D-B6C183F193D4}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=c:\windows\system32\svchost.exe |
"{F95320D9-D91C-490B-84F5-9DEE49BD8D44}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03D06829-19BA-4C1A-AE8C-0ACAD7A53EDB}" = protocol=17 | dir=in | app=c:\program files\microsoft games\zoo tycoon 2\zt.exe |
"{03E10E59-805B-4543-99E6-9274C615B11C}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{05F32B33-702B-4E27-A86E-538F5732C364}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{0FC18158-4EC4-43C7-9C02-77DB9116E32F}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{17360FDA-804B-481F-8FDD-2997FD6B08B6}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{188301AB-0905-4A17-ADF4-D2D7ABB3B8E2}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{1A1AC003-2D93-487E-8DCF-E71F18414261}" = protocol=6 | dir=in | app=c:\windows\system32\p2phost.exe |
"{20046A3C-1377-4891-B58B-C63FE1423640}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{3409AE99-BE65-4174-B072-86B5BFD44AF0}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{377504DC-8727-4769-8855-C34388C54EB0}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{37CC9DF4-DE61-4A37-9ECB-72D551F734DE}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{4926188D-A666-47C1-9AFE-DF14B6CB5E1C}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{49285878-59E7-445E-BC76-93AB5E52D898}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{54009EBB-9C8C-4A31-8AAD-3F213024C9A3}" = protocol=6 | dir=in | app=c:\program files\windows collaboration\wincollab.exe |
"{54D655EF-44CC-4582-8B7A-092AD4F459F4}" = protocol=6 | dir=in | app=c:\program files\microsoft games\zoo tycoon 2\zt.exe |
"{5677F59C-E0E6-4CEB-B3A4-1CD97075D842}" = protocol=6 | dir=in | svc=winmgmt | app=c:\windows\system32\svchost.exe |
"{5965D249-4349-4480-B28C-647536C39E47}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{5D3CBCAE-8949-4BFC-BF6E-93A2387E04AA}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{61795B46-C5C4-43F4-941C-9B9350259CA0}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"{6AB9C893-42C5-41F0-A3CB-FD99DEAFA51B}" = protocol=6 | dir=out | app=c:\program files\windows collaboration\wincollab.exe |
"{6EA9A59A-C025-4055-BCA0-18588514B83B}" = protocol=6 | dir=in | app=c:\program files\msi\arcsoft totalmedia\totalmedia.exe |
"{786DEF3E-288C-465B-9E47-02BF1FAC3A07}" = protocol=6 | dir=in | app=c:\windows\system32\wbem\unsecapp.exe |
"{8488A4C0-8E25-4243-9183-B068862EBCAC}" = protocol=17 | dir=in | app=c:\program files\windows collaboration\wincollab.exe |
"{935B27B6-7EBF-4E24-A97B-3CA0874238DC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9E4A50FE-22B3-4F3A-B42A-9C1223A74BAE}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{9F9E35AE-03C7-4FD7-A745-7483C108B25A}" = protocol=6 | dir=out | app=c:\windows\system32\p2phost.exe |
"{9FF3D209-2793-45C6-9C35-3B7A9D5C3A60}" = protocol=6 | dir=in | app=e:\office12\onenote.exe |
"{A087952D-45F7-41B7-83CA-1035B44EBB02}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{A0C7C87C-2D4A-4D23-A7F0-F3670096B63D}" = protocol=6 | dir=in | app=e:\office12\groove.exe |
"{A37B206E-1F21-472E-BD3D-CC2B843E9723}" = protocol=6 | dir=out | svc=winmgmt | app=c:\windows\system32\svchost.exe |
"{A3B0D00E-B998-4F26-A5A7-C5FA90807094}" = protocol=17 | dir=out | app=c:\program files\windows collaboration\wincollab.exe |
"{A4ADFC6F-D9BD-4868-B916-010A6E197EA5}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{ADFA35EB-7C07-43CC-8F32-C8E4B81694E7}" = protocol=17 | dir=in | app=e:\office12\onenote.exe |
"{B1D8115C-0419-48BB-8365-EE5EA4F785CB}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{B9BF67D0-22FF-410E-9FFB-3228630B54F6}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C4BE151B-AEDD-41CC-964C-F45EAD9FB67C}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{C8BC6A8F-4760-408B-80D9-539E0E036380}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{C997DD90-B58E-4774-965E-D6F81F782886}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CDC7560F-7A5A-4E4F-B9C3-31A511438C4E}" = dir=in | app=c:\program files\myspace\im\myspaceim.exe |
"{D20F122D-F1D1-4B26-A582-45E92FEB319C}" = protocol=17 | dir=in | app=e:\office12\groove.exe |
"{D8A29F5D-E135-429A-AAD1-A1551E6C1A2D}" = protocol=6 | dir=in | app=c:\program files\firaxis games\sid meier's civilization 4\civilization4.exe |
"{E4C3F5E1-19B6-4E7F-9786-EE8072D26683}" = protocol=17 | dir=in | app=c:\program files\msi\arcsoft totalmedia\totalmedia.exe |
"{E5718534-DBEA-4688-B91B-92C2406C802E}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{E6C7DD93-33B6-4011-AEE0-6A2900B58207}" = protocol=17 | dir=in | app=c:\program files\firaxis games\sid meier's civilization 4\civilization4.exe |
"{E79E5147-B741-4604-A032-30F9913BE659}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{ECFB19C2-00E8-4EB9-83AE-041AEBC85687}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{EE50654B-A6D8-4931-8A6A-5B10503D3184}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F8BABA07-F01D-4DB5-B207-8F45BE64432E}" = protocol=6 | dir=in | app=c:\windows\system32\plasrv.exe |
"{FCCB2A33-014B-42D3-8B8A-40192567581B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"TCP Query User{0B84E3EE-4F81-4205-BB8F-6FDB8476AC1E}C:\program files\ubisoft\die siedler 7\data\base\_dbg\bin\release\settlers7r.exe" = protocol=6 | dir=in | app=c:\program files\ubisoft\die siedler 7\data\base\_dbg\bin\release\settlers7r.exe |
"TCP Query User{2D3AAFA8-D63E-43C1-AA82-357D71143254}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"TCP Query User{2D90B3DA-EA93-4BE8-B3B4-444F8CEA0E20}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{440A5B37-210D-4F56-8894-0DEB6FA54793}C:\program files\ubisoft\funatics\die siedler ii - die nächste generation\bin\s2dng.exe" = protocol=6 | dir=in | app=c:\program files\ubisoft\funatics\die siedler ii - die nächste generation\bin\s2dng.exe |
"TCP Query User{597E5DD2-68F8-4C41-8A78-3A42E3B9AF16}C:\program files\emcrypt v4.1\emcrypt.exe" = protocol=6 | dir=in | app=c:\program files\emcrypt v4.1\emcrypt.exe |
"TCP Query User{6C1135F6-1B50-4F27-839F-B1CD2556AFDC}E:\die siedler - aufbruch der kulturen\bin\sadk.exe" = protocol=6 | dir=in | app=e:\die siedler - aufbruch der kulturen\bin\sadk.exe |
"TCP Query User{7E8A571D-5806-4D22-808B-C0926C540E9C}C:\program files\wyzo\wyzo.exe" = protocol=6 | dir=in | app=c:\program files\wyzo\wyzo.exe |
"TCP Query User{A6ADB237-0134-438A-9E42-1F2EB2DB4813}C:\program files\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare\bearshare.exe |
"TCP Query User{B02371AE-3DE9-4FAD-9EC6-7EE723522391}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
"TCP Query User{D20FB5F5-C7AB-45B9-93CE-2A1E24911051}C:\program files\web.de\web.de multimessenger\messengr.exe" = protocol=6 | dir=in | app=c:\program files\web.de\web.de multimessenger\messengr.exe |
"TCP Query User{E5B1E14B-B2B9-4B6D-9BB3-D05B42E27272}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{EAA38AAB-7619-4799-9F27-4A3C75186982}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{0390F194-2AB5-409E-9E96-96164E1175FB}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{10E393BE-F339-48B2-8A28-184C561A0CE2}C:\program files\ubisoft\die siedler 7\data\base\_dbg\bin\release\settlers7r.exe" = protocol=17 | dir=in | app=c:\program files\ubisoft\die siedler 7\data\base\_dbg\bin\release\settlers7r.exe |
"UDP Query User{1D600A05-0725-4189-B8FD-83F01DBA540C}C:\program files\ubisoft\funatics\die siedler ii - die nächste generation\bin\s2dng.exe" = protocol=17 | dir=in | app=c:\program files\ubisoft\funatics\die siedler ii - die nächste generation\bin\s2dng.exe |
"UDP Query User{5E8BA695-7B44-4C6A-B6C4-0B813B903271}C:\program files\emcrypt v4.1\emcrypt.exe" = protocol=17 | dir=in | app=c:\program files\emcrypt v4.1\emcrypt.exe |
"UDP Query User{69A9DE51-B116-4AE0-9483-3C1A33708C22}E:\die siedler - aufbruch der kulturen\bin\sadk.exe" = protocol=17 | dir=in | app=e:\die siedler - aufbruch der kulturen\bin\sadk.exe |
"UDP Query User{6C1B4677-FC0A-45DB-A964-BFCE48E84F05}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{6EC6623F-5A63-41F4-8391-BF1BAF93D1AA}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{74BE3A19-567C-4342-993F-1EE00C5C0D8B}C:\program files\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare\bearshare.exe |
"UDP Query User{BCD0A0D6-F200-4830-890B-EFEFA60C1688}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{EE2FB5F8-595B-4349-83E0-6E36AC07D294}C:\program files\web.de\web.de multimessenger\messengr.exe" = protocol=17 | dir=in | app=c:\program files\web.de\web.de multimessenger\messengr.exe |
"UDP Query User{F0CEAA7E-1B98-4E02-B37A-4147782C98F4}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{FD951006-FCD0-41E7-AFE1-3CF3346BDFC9}C:\program files\wyzo\wyzo.exe" = protocol=17 | dir=in | app=c:\program files\wyzo\wyzo.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00004EE8-1E8B-BB10-6588-07DF0D120F6B}" = CCC Help Korean
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02E107FC-1861-FC4A-E80F-07DA9DC5808C}" = Catalyst Control Center Graphics Previews Vista
"{03C55715-3545-2DF8-8C64-2BB877955150}" = Catalyst Control Center Localization Chinese Traditional
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0755396F-D048-8CDD-6AC3-C7C83A6869B5}" = CCC Help Czech
"{08B7B1F9-A8EB-7632-FFC3-04AB5328143B}" = CCC Help Chinese Standard
"{09F52B2B-8B36-130C-5EBD-6E5FFC5FA0B7}" = CCC Help English
"{0E1C53DA-DF86-845A-7BEB-14C4A8E0B150}" = Catalyst Control Center Localization Korean
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{146E206D-7D2C-493A-B431-1F1D16E822AF}" = MobileMe Control Panel
"{15292416-A464-4FBA-BB96-7298EAACFC07}" = Zoo Tycoon 2 - Extinct Animals
"{15382D89-6EF6-4D21-9484-B500F2B10E46}" = PhotoMail Maker
"{15B924BC-AEB2-7E31-F414-1FC7B385846A}" = CCC Help Greek
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{20CFE038-F4CE-0716-DCA0-04BBD67FE5EA}" = CCC Help Turkish
"{2126F5BB-AB90-083F-7AA8-A29D73819DAA}" = CCC Help French
"{22543949-70E8-45D0-A938-F38143EB8BF8}" = Catalyst Control Center - Branding
"{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product Information
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{26E6EA50-532C-8CF3-5EB4-8C8D306EAB58}" = Catalyst Control Center Localization Polish
"{27CD3616-D3B0-834C-89A3-4FC5CEE7374D}" = Catalyst Control Center Graphics Full Existing
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{28912B61-0265-3C33-7EC7-14345AC76E3D}" = CCC Help Hungarian
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie
"{2D06C1FE-8454-5663-D0E9-1C130FD96446}" = Catalyst Control Center Localization Norwegian
"{2FA41EBB-3F5A-35C3-85D6-51EC72A11FBD}" = Google Gears
"{30F9E15A-EE25-6D32-62CE-2E6BEAED3766}" = CCC Help Italian
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java(TM) SE Runtime Environment 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{342A19C7-3335-C02F-F1DD-3A0B49C3D047}" = Catalyst Control Center Localization Greek
"{34EF4F67-A3CE-DAB6-FA06-7C4C59A0D462}" = Catalyst Control Center Localization Swedish
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CE22BE4-E2D3-F0E8-1C52-1B5A5F97B876}" = Catalyst Control Center Localization Turkish
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{400F4990-B111-109A-6B08-E80CB42651AA}" = Catalyst Control Center Localization Danish
"{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}" = ATI Catalyst Install Manager
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{44479884-EB6D-38DA-1D3E-835625E40F7E}" = Catalyst Control Center Graphics Previews Common
"{480CA9F1-17E2-0B15-9684-511C0A083F92}" = Catalyst Control Center Localization Thai
"{4817189D-1785-4627-A33C-39FD90919300}" = Die Sims™ 2 Haustiere
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F31172C-2692-BB28-8F5B-86474CEC5D33}" = Catalyst Control Center Localization Chinese Standard
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{54AAFB71-6DCB-32EB-8F91-DA7643497ED4}" = Catalyst Control Center Localization Spanish
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5D1CB0EC-0CA2-B4FD-2A10-2503A3CF7E46}" = Catalyst Control Center Localization Italian
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5EFE618D-0100-6DE7-9894-5FD057103871}" = Catalyst Control Center Core Implementation
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{63D10FBD-5667-DAD9-0B31-CED873B3F7EF}" = Catalyst Control Center Graphics Light
"{6522C636-B04C-4333-9BEB-9E0C0B6350D6}" = Die Sims™ 2 Küchen- und Bad-Einrichtungs-Accessoires
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6E17F9751-F056-4335-B718-8AF1B1092AFB}" = Die Sims™ 2 IKEA® Home-Accessoires
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = Die Sims 2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74292F90-895A-4FC6-A692-9641532B1B63}" = ArcSoft TotalMedia 3.5
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{7936153F-8D09-BC11-6DC4-1D4DEAB9D680}" = CCC Help Thai
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{816B8A02-76F0-AE47-E28F-0AD114CC261E}" = CCC Help Polish
"{82AB4F83-BBBA-8F04-EE34-11F74E39A4B6}" = Catalyst Control Center Localization German
"{85EBB283-65AF-4C53-9EBE-7C0A232762F7}" = AGEIA PhysX v7.03.21
"{86158699-F584-0DC9-119D-C5A6591090FB}" = CCC Help Chinese Traditional
"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}" = Die Sims™ 2 Freizeit-Spaß
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{88EB38EF-4D2C-436D-ABD3-56B232674062}" = ICQ7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
"{920E3F1A-0B73-807D-EE0E-E6D89D4E5DDE}" = Catalyst Control Center Localization Dutch
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{985AF15E-776F-3CDD-EB92-2DAFF02697FB}" = Skins
"{98CE747E-4948-10B0-BBF0-5981A11114D1}" = Catalyst Control Center Localization Hungarian
"{99F54171-AE4A-579B-1544-5870478FC8F7}" = Catalyst Control Center Graphics Full New
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C916142-C18C-429D-BFED-40094A7E0BEB}" = Die Siedler 7
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{9EDBB857-8028-49CD-B9C9-0B4D10CD1031}" = Nero 8
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A1BAD23B-748C-50FD-CCA9-956C3F54D138}" = CCC Help German
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A6D4234C-CB02-4048-AC3E-AD09404FA35A}" = Emdedded IR Driver
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{ABD82299-8034-4B44-4FDB-3F8971C20575}" = CCC Help Finnish
"{AC76BA86-7AD7-1031-7B44-A81300000003}" = Adobe Reader 8.1.5 - Deutsch
"{AC76BA86-7AD7-1031-7B44-A81300000003}_814" = KB408682
"{ACE07E37-A416-9A6B-D352-C776FFA49493}" = CCC Help Spanish
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2AEC44B-F926-773D-D028-77CADEF8D9D3}" = CCC Help Norwegian
"{B537ACDB-7C56-83B6-034C-A5AF6400F789}" = CCC Help Swedish
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B6F5B704-06D3-4687-90F3-6195304AD755}" = Die Sims™ 2 Apartment-Leben
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{B8AB4511-EECC-9299-45B3-F25F4774F6F2}" = CCC Help Russian
"{BD75C1A0-F0ED-B54A-B49C-3244B47BA803}" = ccc-utility
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C6317675-96CC-D2AE-40F2-698F3DED64B4}" = CCC Help Portuguese
"{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser
"{C7FAEA9E-A14C-D8C9-EEE9-8D43F9E09565}" = Catalyst Control Center Localization Czech
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CC35C434-FFC8-BDD8-44F0-ED0972484C56}" = CCC Help Dutch
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D646CA8B-5227-1598-5E9C-132B2D89A38D}" = Catalyst Control Center Localization Japanese
"{D8E302CB-8517-3E9B-C6C9-E90A21C6EFC5}" = CCC Help Danish
"{DB780B85-B4B5-4864-A49C-9B706B169C93}" = TIPCI
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = Die Sims™ 2 Vier Jahreszeiten
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9-Reihe
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}" = Die Sims™ 2 Party-Accessoires
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0BB634D-B374-A329-EE5D-22C279F92A7F}" = ccc-core-static
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1C1426C-6670-4068-6398-EB490D45979F}" = Catalyst Control Center Localization Portuguese
"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = Die Sims™ 2 Gute Reise
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth
"{F8B5B814-A3BF-F83F-09ED-AED9EE88211A}" = Catalyst Control Center Localization French
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{F927176F-F8F0-FACF-A57E-4F95714B6F00}" = Catalyst Control Center Localization Russian
"{F9466082-90E9-4BE4-92F0-CF0AF195B0CF}" = USB PC Camera
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone-Konfigurationsprogramm
"{FA7BB878-FC13-7548-13D3-18A53381014D}" = CCC Help Japanese
"{FB56EE4D-7CBC-6FDC-E336-52BD269E4CF6}" = Catalyst Control Center Localization Finnish
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"3DSex_Villa_ThriXXX" = 3DSex_Villa_ThriXXX
"8461-7759-5462-8226" = Vuze
"ActiveXControlPad" = Microsoft ActiveX Control Pad
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"ClearProg" = ClearProg 1.6.0 Final
"Diner Dash 5 Boom Collector's Edition H33T" = Diner Dash 5 Boom Collector's Edition H33T
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX-Setup
"Dr. DivX 1.0 Beta" = Dr. DivX 1.0 Beta
"ecmkjc" = Favorit
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Farm Frenzy 3 Russian Roulette 1.0" = Farm Frenzy 3 Russian Roulette 1.0
"Farm Frenzy Pizza Party 1.00" = Farm Frenzy Pizza Party 1.00
"ffdshow_is1" = ffdshow [rev 1828] [2008-01-29]
"Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition 2.0.0.1 (D)
"FotokalenderDigitalPrintLab3" = DigitalPrintLab3
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"IncrediMail" = IncrediMail 2.0
"InstallShield_{15292416-A464-4FBA-BB96-7298EAACFC07}" = Zoo Tycoon 2 - Extinct Animals
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisorkennwort
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{A6D4234C-CB02-4048-AC3E-AD09404FA35A}" = Emdedded IR Driver
"InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"LogonStudio Vista" = LogonStudio Vista
"MAGIX Online Druck Service D" = MAGIX Online Druck Service 2.3.2.0 (D)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"myphotobook" = myphotobook 3.1
"OfotoEZUpload" = KODAK EASYSHARE Gallery Upload ActiveX Control
"PDF-ShellTools_is1" = PDF-ShellTools 1.0.0.9 Trial
"PhotoMail" = PhotoMail Maker
"Picasa 3" = Picasa 3
"QuickStores-Toolbar_is1" = QuickStores-Toolbar 1.0.0
"RealPlayer 6.0" = RealPlayer
"Rommé 1" = Rommé 1
"SADK" = Die Siedler - Aufbruch der Kulturen
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SysInfo" = Creative Systeminformationen
"T-Online eMail Center Desktop-Startsymbol Fax" = T-Online eMail Center Desktop-Startsymbol Fax 1.0
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"VLC media player" = VideoLAN VLC media player 0.8.1
"Vuze_Remote Toolbar" = Vuze_Remote Toolbar
"WEB.DE SmartSurfer" = WEB.DE SmartSurfer
"WildTangent hp Master Uninstall" = HP Games
"Windows Media Encoder 9" = Windows Media Encoder 9-Reihe
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"Xfire" = Xfire (remove only)
"XP-Games JRE" = XP-Games JRE
"Zoo Tycoon 1.0" = Zoo Tycoon: Complete Collection
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"HappyFoto Bestellsoftware" = HappyFoto Bestellsoftware
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 05.06.2010 13:40:34 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 05.06.2010 13:40:34 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 16240749
 
Error - 05.06.2010 13:40:34 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 16240749
 
Error - 05.06.2010 13:40:35 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 05.06.2010 13:40:35 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 16241763
 
Error - 05.06.2010 13:40:35 | Computer Name = biancas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 16241763
 
Error - 06.06.2010 06:15:01 | Computer Name = biancas-PC | Source = Application Hang | ID = 1002
Description = Programm WINWORD.EXE, Version 12.0.6514.5000 arbeitet nicht mehr mit
 Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet
 "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen
über das Problem zu suchen.  Prozess-ID: 6b0  Anfangszeit: 01cb0560cfe69fa3  Zeitpunkt
 der Beendigung: 0
 
Error - 06.06.2010 07:25:33 | Computer Name = biancas-PC | Source = VSS | ID = 12289
Description =
 
Error - 06.06.2010 07:25:42 | Computer Name = biancas-PC | Source = VSS | ID = 12289
Description =
 
Error - 06.06.2010 07:25:45 | Computer Name = biancas-PC | Source = VSS | ID = 12289
Description =
 
[ System Events ]
Error - 06.06.2010 07:35:43 | Computer Name = biancas-PC | Source = atikmdag | ID = 43034
Description = Unknown EDID version
 
Error - 06.06.2010 07:35:43 | Computer Name = biancas-PC | Source = atikmdag | ID = 43034
Description = Unknown EDID version
 
Error - 06.06.2010 07:35:43 | Computer Name = biancas-PC | Source = atikmdag | ID = 43034
Description = Unknown EDID version
 
Error - 06.06.2010 07:35:56 | Computer Name = biancas-PC | Source = Print | ID = 19
Description = Der Druckspooler konnte den Drucker Canon Inkjet iP4200 nicht unter
 dem Namen Canon Inkjet iP4200 freigeben. Fehler: 2114. Der Drucker kann nicht von
 anderen Benutzern im Netzwerk verwendet werden.
 
Error - 06.06.2010 07:35:58 | Computer Name = biancas-PC | Source = Microsoft-Windows-ResourcePublication | ID = 1002
Description =
 
Error - 06.06.2010 07:36:33 | Computer Name = biancas-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 06.06.2010 07:36:33 | Computer Name = biancas-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 06.06.2010 07:36:33 | Computer Name = biancas-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 06.06.2010 07:36:40 | Computer Name = biancas-PC | Source = DCOM | ID = 10000
Description =
 
Error - 06.06.2010 08:28:34 | Computer Name = biancas-PC | Source = bowser | ID = 8003
Description =
 
 
< End of report >

--- --- ---

MalwareHero 06.06.2010 13:31

Zitat:

Zitat von Bianca28 (Beitrag 530769)
Ich habe jetzt nochmal einen quickscan von OTL ausgeführt und das hat er mir gegeben. zum anhängen ist es zu groß.
--- --- ---

ist ok. ich schaue mir das log an, in der zwischenzeit machst du mal ein Schnellscan mit Dr.Web im abgesicherten Modus. Folge bei dem download und durchführung einfach genau der verlinkten anleitung.
http://www.trojaner-board.de/59299-a...eb-cureit.html

wenn der scanner bei dem schnellscan infektion meldet, mache eine Komplett Scan, der dauert einiges an zeit, ist aber gerade bei dir das beste, da die maschine lieber nicht mit dem internet gerade verbunden sein sollte. Wenn du damit fertig bist gehe wieder online und poste das log.

------------------

Bianca28 06.06.2010 13:32

und der andere. Ich mach auch gleich was du grad gesagt hast.

OTL Logfile:
Code:

OTL logfile created on: 06.06.2010 14:26:03 - Run 2
OTL by OldTimer - Version 3.2.5.3    Folder = C:\Users\bianca\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 50,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 69,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 9,38 Gb Free Space | 12,59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 73,06 Gb Total Space | 28,99 Gb Free Space | 39,69% Space Free | Partition Type: NTFS
Drive F: | 612,59 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: BIANCAS-PC
Current User Name: bianca
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\bianca\Desktop\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
PRC - C:\Programme\IncrediMail\bin\ImApp.exe (IncrediMail, Ltd.)
PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Programme\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Programme\Google\Update\1.2.183.23\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\avcenter.exe (Avira GmbH)
PRC - C:\Programme\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - E:\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\Programme\Synaptics\SynTP\SynToshiba.exe (Synaptics, Inc.)
PRC - C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Programme\WEB.DE\WEB.DE SmartSurfer\SmurfService.exe (United Internet AG)
PRC - C:\Programme\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Programme\Common Files\Nero\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Programme\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Windows\vsnp325.exe ()
PRC - C:\Windows\tsnp325.exe ()
PRC - C:\Programme\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Programme\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Programme\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Programme\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Programme\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Programme\TOSHIBA\Utilities\KeNotify.exe ()
PRC - C:\Windows\Pixart\Pac7302\Monitor.exe (PixArt Imaging Incorporation)
PRC - C:\Windows\System32\BrmfRsmg.exe (Brother Industries, Ltd.)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\bianca\Desktop\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d\msvcr80.dll (Microsoft Corporation)
MOD - C:\Windows\System32\WindowsCodecs.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1\ATL80.dll (Microsoft Corporation)
MOD - C:\Programme\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)
MOD - C:\Windows\System32\SLC.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msshsq.dll (Microsoft Corporation)
MOD - C:\Windows\System32\mssprxy.dll (Microsoft Corporation)
MOD - C:\Windows\System32\EhStorShell.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cscapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - E:\Office12\GrooveUtil.dll (Microsoft Corporation)
MOD - E:\Office12\GrooveSystemServices.dll (Microsoft Corporation)
MOD - E:\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
MOD - E:\Office12\GrooveNew.dll (Microsoft Corporation)
MOD - C:\Windows\System32\thumbcache.dll (Microsoft Corporation)
MOD - C:\Windows\System32\duser.dll (Microsoft Corporation)
MOD - C:\Windows\System32\actxprxy.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (TOSHIBA Bluetooth Service) --  File not found
SRV - (Automatisches LiveUpdate - Scheduler) --  File not found
SRV - (GameConsoleService) -- C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (ACDaemon) -- C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service) -- E:\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (SmartSurferManager) -- C:\Program Files\WEB.DE\WEB.DE SmartSurfer\SmurfService.exe (United Internet AG)
SRV - (TosCoSrv) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (IAANTMON) Intel(R) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (CFSvcs) -- C:\Programme\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (brmfrsmg) -- C:\Windows\System32\BrmfRsmg.exe (Brother Industries, Ltd.)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (TODDSrv) -- C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (FirebirdServerMAGIXInstance) -- C:\Programme\MAGIX\Common\Database\bin\fbserver.exe (MAGIX®)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (AF15BDA) -- C:\Windows\System32\drivers\AF15BDA.sys (AfaTech                  )
DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (mf) -- C:\Windows\System32\drivers\mf.sys (Microsoft Corporation)
DRV - (SVKP) -- C:\Windows\System32\SVKP.sys (AntiCracking)
DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (TVALZ) -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (PAC7302) -- C:\Windows\System32\drivers\PAC7302.SYS (PixArt Imaging Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (SNP325) USB PC Camera (SNPSTD325) -- C:\Windows\System32\drivers\snp325.sys (Sonix Co. Ltd.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (motmodem) -- C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (motccgp) -- C:\Windows\System32\drivers\motccgp.sys (Motorola)
DRV - (CplIR) -- C:\Windows\system32\DRIVERS\CplIR.SYS (COMPAL ELECTRONIC INC.)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (tifm21) -- C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (motccgpfl) -- C:\Windows\System32\drivers\motccgpfl.sys (Motorola)
DRV - (KR10N) -- C:\Windows\system32\drivers\kr10n.sys (TOSHIBA CORPORATION)
DRV - (KR10I) -- C:\Windows\system32\drivers\kr10i.sys (TOSHIBA CORPORATION)
DRV - (MotoSwitchService) -- C:\Windows\System32\drivers\motswch.sys (Motorola)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (Afc) -- C:\Windows\System32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrUsbScn) Brother MFC-Scannertreiber (USB) -- C:\Windows\System32\drivers\BrUsbScn.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) Brother WDM-Treiber (seriell) -- C:\Windows\System32\drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) Brother MFC-nur-Fax-Modem (USB) -- C:\Windows\System32\drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (brfilt) -- C:\Windows\System32\drivers\BrFilt.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (tosrfec) -- C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) -- C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (LPCFilter) -- C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV - (sfsync02) StarForce Protection Synchronization Driver (version 2.x) -- C:\Windows\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\System32\drivers\sfdrv01.sys (Protection Technology (StarForce))
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\System32\drivers\sfhlp02.sys (Protection Technology (StarForce))
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://alice.aol.de
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://msn.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 60 E6 7D F0 A5 F6 CA 01  [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultthis.engineName: "Google Powered Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.startup.homepage: "hxxp://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.36.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.3
FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:2.5.8.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: quickstores@quickstores.de:1.0.0
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q="
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008.11.19 15:48:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2010.03.06 10:02:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.03 09:55:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.05.30 20:09:08 | 000,000,000 | ---D | M]
 
[2008.06.18 19:01:52 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\mozilla\Extensions
[2010.06.05 19:56:52 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\mozilla\Firefox\Profiles\fgkslinf.default\extensions
[2010.04.28 19:37:59 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\bianca\AppData\Roaming\mozilla\Firefox\Profiles\fgkslinf.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.03.31 13:10:14 | 000,000,000 | ---D | M] (Vuze Remote Toolbar) -- C:\Users\bianca\AppData\Roaming\mozilla\Firefox\Profiles\fgkslinf.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2009.10.26 10:12:55 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\mozilla\Firefox\Profiles\fgkslinf.default\extensions\anycolor.pavlos256@gmail.com
[2009.09.07 18:05:26 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\mozilla\Firefox\Profiles\fgkslinf.default\extensions\moveplayer@movenetworks.com
[2010.04.14 09:36:01 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\mozilla\Firefox\Profiles\fgkslinf.default\extensions\personas@christopher.beard
[2010.03.31 14:05:27 | 000,000,903 | ---- | M] () -- C:\Users\bianca\AppData\Roaming\Mozilla\FireFox\Profiles\fgkslinf.default\searchplugins\conduit.xml
[2008.12.12 20:23:54 | 000,002,158 | ---- | M] () -- C:\Users\bianca\AppData\Roaming\Mozilla\FireFox\Profiles\fgkslinf.default\searchplugins\MySpace.xml
[2010.06.05 19:56:52 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.06.02 18:46:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.06.02 21:20:19 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions\quickstores@quickstores.de
[2010.06.02 18:45:23 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.03.12 15:17:29 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.03.12 15:17:29 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.03.12 15:17:29 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.03.12 15:17:29 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.03.12 15:17:29 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programme\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Programme\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [00TCrdMain] C:\Programme\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [GrooveMonitor] E:\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe File not found
O4 - HKLM..\Run: [HSON] C:\Programme\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HWSetup]  File not found
O4 - HKLM..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe File not found
O4 - HKLM..\Run: [KeNotify] C:\Programme\TOSHIBA\Utilities\KeNotify.exe ()
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NDSTray.exe]  File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [PAC7302_Monitor] C:\Windows\Pixart\Pac7302\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe File not found
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SmoothView] C:\Programme\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [snp325] C:\Windows\vsnp325.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (TOSHIBA)
O4 - HKLM..\Run: [Toshiba Registration] C:\Programme\TOSHIBA\Registration\ToshibaRegistration.exe (Toshiba)
O4 - HKLM..\Run: [TPwrMain] C:\Programme\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [tsnp325] C:\Windows\tsnp325.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [MSServer] C:\Users\bianca\AppData\Local\Temp\efcBusQh.DLL File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Die Siedler II - Die nächste Generation.LNK = C:\Program Files\Ubisoft\Funatics\Die Siedler II - Die nächste Generation\bin\RegistrationReminder.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 153
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 153
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - E:\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Gears-Einstellungen - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Programme\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} -  File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\bianca\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
O24 - Desktop BackupWallPaper: C:\Users\bianca\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - E:\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006.08.23 15:07:39 | 000,778,240 | R--- | M] (Funatics Studio alpha Ltd. & Co. KG) - F:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2006.07.17 15:52:00 | 000,000,068 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{bc85d363-b254-11dc-8fdf-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{bc85d363-b254-11dc-8fdf-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Autorun.exe -- [2006.08.23 15:07:39 | 000,778,240 | R--- | M] (Funatics Studio alpha Ltd. & Co. KG)
O33 - MountPoints2\{c0ab97d1-d48b-11dc-977f-001b38ab7ce6}\Shell - "" = AutoRun
O33 - MountPoints2\{c0ab97d1-d48b-11dc-977f-001b38ab7ce6}\Shell\AutoRun\command - "" = D:\autorun.exe -- File not found
O33 - MountPoints2\{c0ab97db-d48b-11dc-977f-001b38ab7ce6}\Shell - "" = AutoRun
O33 - MountPoints2\{c0ab97db-d48b-11dc-977f-001b38ab7ce6}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.06.06 13:06:31 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Roaming\Malwarebytes
[2010.06.06 13:05:38 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.06.06 13:05:34 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.06.06 13:05:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.06.06 13:05:33 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2010.06.03 11:54:38 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TASKMGR.COM
[2010.06.03 11:54:38 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\T.COM
[2010.06.03 11:54:38 | 000,134,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\REGEDIT.COM
[2010.06.03 11:54:38 | 000,134,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\R.COM
[2010.06.02 21:41:29 | 000,000,000 | ---D | C] -- C:\Windows\VDLL.DLL
[2010.06.02 21:41:29 | 000,000,000 | ---D | C] -- C:\Windows\System32\runouce.exe
[2010.06.02 21:41:29 | 000,000,000 | ---D | C] -- C:\Windows\RUNDL132.EXE
[2010.06.02 21:41:29 | 000,000,000 | ---D | C] -- C:\Windows\logo_1.exe
[2010.06.02 21:38:32 | 000,632,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcr80.dll
[2010.06.02 21:38:31 | 000,554,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcp80.dll
[2010.06.02 21:38:30 | 000,034,048 | ---- | C] (MicroWorld Technologies Inc.) -- C:\Windows\System32\eEmpty.exe
[2010.06.02 21:38:26 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\MicroWorld
[2010.06.02 21:38:20 | 000,000,000 | ---D | C] -- C:\ProgramData\MicroWorld
[2010.06.02 21:20:18 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Roaming\QuickStoresToolbar
[2010.06.02 21:20:16 | 000,000,000 | ---D | C] -- C:\Programme\ClearProg
[2010.06.02 20:55:04 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Roaming\Avira
[2010.06.02 18:45:57 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.06.02 18:45:57 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.06.02 18:45:57 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.06.02 18:16:19 | 000,000,000 | ---D | C] -- C:\Users\bianca\Documents\Settlers7
[2010.06.02 17:39:15 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2010.06.02 17:39:14 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2010.06.02 17:39:14 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2010.06.02 17:39:13 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2010.06.02 17:39:13 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2010.06.02 17:39:13 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2010.06.02 17:39:11 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2010.06.02 17:39:10 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_41.dll
[2010.06.02 17:39:10 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_41.dll
[2010.06.02 17:39:10 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_41.dll
[2010.06.02 17:39:09 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll
[2010.06.02 17:39:09 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_4.dll
[2010.06.02 17:39:09 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2010.06.02 17:39:09 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_4.dll
[2010.06.02 17:39:09 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2010.06.02 17:39:09 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_6.dll
[2010.06.02 17:39:08 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll
[2010.06.02 17:39:08 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2010.06.02 17:39:08 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2010.06.02 17:39:07 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2010.06.02 17:39:07 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2010.06.02 17:39:07 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2010.06.02 17:39:07 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2010.06.02 17:39:07 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2010.06.02 17:39:06 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2010.06.02 17:39:06 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2010.06.02 17:39:06 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2010.06.01 15:48:56 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Local\S2
[2010.06.01 14:44:27 | 000,000,000 | ---D | C] -- C:\Programme\Ubisoft
[2010.05.31 21:13:47 | 000,000,000 | ---D | C] -- C:\Programme\Games
[2010.05.30 20:04:56 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2010.05.28 19:25:35 | 000,000,000 | ---D | C] -- C:\ProgramData\FarmFrenzy3_Russia
[2010.05.28 19:25:02 | 000,000,000 | ---D | C] -- C:\Programme\Alawar Entertainment
[2010.05.26 10:46:51 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010.05.16 20:14:53 | 000,000,000 | ---D | C] -- C:\Programme\bigup16
[2010.05.16 16:09:52 | 000,000,000 | ---D | C] -- C:\ProgramData\FarmFrenzy3
[2010.05.16 16:09:47 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\AlawarWrapper
[2010.05.16 16:09:47 | 000,000,000 | ---D | C] -- C:\ProgramData\AlawarWrapper
[2010.05.16 12:05:39 | 000,000,000 | ---D | C] -- C:\ProgramData\FarmFrenzy-PizzaParty
[2010.05.10 12:51:41 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Microsoft Games
[2010.05.09 23:18:12 | 000,000,000 | ---D | C] -- C:\Users\bianca\AppData\Roaming\Microsoft Games
[2010.05.09 23:18:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Games
[2008.01.19 17:58:34 | 000,147,456 | ---- | C] ( ) -- C:\Windows\System32\rsnp325.dll
[2008.01.19 17:58:34 | 000,057,344 | ---- | C] ( ) -- C:\Windows\System32\vsnp325.dll
[2008.01.19 17:58:34 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnp325.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2010.06.06 14:20:33 | 005,767,168 | -HS- | M] () -- C:\Users\bianca\NTUSER.DAT
[2010.06.06 14:06:00 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010.06.06 13:38:23 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010.06.06 13:35:58 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2010.06.06 13:35:55 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.06.06 13:35:55 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.06.06 13:35:54 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010.06.06 13:35:52 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.06.06 13:35:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.06.06 13:34:08 | 000,524,288 | -HS- | M] () -- C:\Users\bianca\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010.06.06 13:34:08 | 000,065,536 | -HS- | M] () -- C:\Users\bianca\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010.06.06 13:33:31 | 000,004,616 | ---- | M] () -- C:\Users\bianca\AppData\Local\mutbihpv_navps.dat
[2010.06.06 13:33:19 | 003,656,409 | -H-- | M] () -- C:\Users\bianca\AppData\Local\IconCache.db
[2010.06.06 13:33:00 | 000,003,442 | ---- | M] () -- C:\Users\bianca\AppData\Local\mutbihpv.dat
[2010.06.06 13:05:41 | 000,000,823 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.06.06 10:39:20 | 000,000,092 | ---- | M] () -- C:\Users\bianca\AppData\Local\ecmkjc.bat
[2010.06.04 19:24:50 | 000,000,680 | ---- | M] () -- C:\Users\bianca\AppData\Local\d3d9caps.dat
[2010.06.04 00:27:13 | 000,242,503 | ---- | M] () -- C:\Users\bianca\AppData\Local\mutbihpv_nav.dat
[2010.06.03 17:36:33 | 000,493,613 | ---- | M] () -- C:\Users\bianca\Documents\pinfect.zip
[2010.06.03 11:55:09 | 000,000,052 | ---- | M] () -- C:\Windows\Lic.xxx
[2010.06.02 21:38:31 | 000,632,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcr80.dll
[2010.06.02 21:38:30 | 000,554,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcp80.dll
[2010.06.02 21:38:29 | 000,034,048 | ---- | M] (MicroWorld Technologies Inc.) -- C:\Windows\System32\eEmpty.exe
[2010.06.02 21:20:19 | 000,000,187 | ---- | M] () -- C:\Users\bianca\Desktop\QuickStores.url
[2010.06.02 21:20:16 | 000,000,821 | ---- | M] () -- C:\Users\Public\Desktop\ClearProg.lnk
[2010.06.02 18:45:21 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010.06.02 18:45:21 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.06.02 18:45:21 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.06.02 18:45:21 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.06.01 14:46:29 | 000,001,519 | ---- | M] () -- C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Die Siedler II - Die nächste Generation.LNK
[2010.05.31 21:13:51 | 000,002,010 | ---- | M] () -- C:\Users\bianca\Desktop\Farm Frenzy Pizza Party.lnk
[2010.05.30 20:06:43 | 000,001,976 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2010.05.28 19:25:12 | 000,001,226 | ---- | M] () -- C:\Users\bianca\Desktop\Farm Frenzy 3 Russian Roulette.lnk
[2010.05.24 23:36:55 | 001,418,612 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.05.24 23:36:55 | 000,618,442 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.05.24 23:36:55 | 000,587,178 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010.05.24 23:36:55 | 000,122,648 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.05.24 23:36:55 | 000,101,250 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.05.24 23:12:29 | 000,082,944 | ---- | M] () -- C:\Users\bianca\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.21 11:12:45 | 000,002,078 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2010.05.16 20:15:30 | 000,001,272 | ---- | M] () -- C:\Users\bianca\Desktop\Diner Dash 5 Boom Collector's Edition.lnk
[2010.05.10 15:25:28 | 000,000,575 | ---- | M] () -- C:\Windows\win.ini
[2010.05.10 13:01:21 | 000,001,019 | ---- | M] () -- C:\Users\bianca\Desktop\Spielen.lnk
[2010.05.09 18:01:07 | 000,001,638 | ---- | M] () -- C:\Users\Public\Desktop\Vuze.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010.06.06 13:05:41 | 000,000,823 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.06.03 11:52:41 | 000,493,613 | ---- | C] () -- C:\Users\bianca\Documents\pinfect.zip
[2010.06.02 21:39:16 | 000,000,052 | ---- | C] () -- C:\Windows\Lic.xxx
[2010.06.02 21:38:30 | 000,000,522 | ---- | C] () -- C:\Windows\System32\Microsoft.VC80.CRT.manifest
[2010.06.02 21:20:19 | 000,000,187 | ---- | C] () -- C:\Users\bianca\Desktop\QuickStores.url
[2010.06.02 21:20:16 | 000,000,821 | ---- | C] () -- C:\Users\Public\Desktop\ClearProg.lnk
[2010.06.02 14:13:28 | 000,242,503 | ---- | C] () -- C:\Users\bianca\AppData\Local\mutbihpv_nav.dat
[2010.06.02 14:13:28 | 000,004,616 | ---- | C] () -- C:\Users\bianca\AppData\Local\mutbihpv_navps.dat
[2010.06.02 14:13:28 | 000,003,442 | ---- | C] () -- C:\Users\bianca\AppData\Local\mutbihpv.dat
[2010.06.01 14:46:29 | 000,001,519 | ---- | C] () -- C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Die Siedler II - Die nächste Generation.LNK
[2010.05.31 21:13:51 | 000,002,010 | ---- | C] () -- C:\Users\bianca\Desktop\Farm Frenzy Pizza Party.lnk
[2010.05.30 20:06:43 | 000,001,976 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2010.05.28 19:25:12 | 000,001,226 | ---- | C] () -- C:\Users\bianca\Desktop\Farm Frenzy 3 Russian Roulette.lnk
[2010.05.21 11:12:45 | 000,002,078 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2010.05.16 20:15:30 | 000,001,272 | ---- | C] () -- C:\Users\bianca\Desktop\Diner Dash 5 Boom Collector's Edition.lnk
[2010.05.10 13:01:21 | 000,001,019 | ---- | C] () -- C:\Users\bianca\Desktop\Spielen.lnk
[2010.01.28 20:41:23 | 000,307,200 | ---- | C] () -- C:\Windows\System32\AscSQLite.dll
[2009.10.05 11:44:01 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2008.11.06 18:37:32 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2008.11.06 18:34:00 | 000,000,416 | ---- | C] () -- C:\Windows\System32\dtu100.dll.manifest
[2008.07.19 17:47:14 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2008.05.30 08:44:21 | 000,042,982 | ---- | C] () -- C:\Windows\System32\pddsladp.dll
[2008.04.16 17:35:01 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2008.02.26 12:28:46 | 000,000,027 | ---- | C] () -- C:\Windows\BRMFBIDI.INI
[2008.02.06 10:14:24 | 000,611,064 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2008.02.06 10:14:24 | 000,142,904 | ---- | C] () -- C:\Windows\System32\drivers\sptddrv1.sys
[2008.01.30 17:58:52 | 000,007,680 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2008.01.30 17:58:52 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2008.01.19 17:58:34 | 000,015,498 | ---- | C] () -- C:\Windows\snp325.ini
[2007.12.30 19:56:01 | 000,000,566 | ---- | C] () -- C:\Windows\System32\SP7302.INI
[2007.12.29 13:56:37 | 000,000,008 | RHS- | C] () -- C:\Windows\System32\CE6AF3E6A1.sys
[2007.12.27 12:16:36 | 000,000,403 | ---- | C] () -- C:\Windows\ODBC.INI
[2007.12.25 02:18:30 | 000,278,728 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2007.12.25 02:18:30 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2007.07.12 10:54:33 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2007.07.12 10:26:24 | 000,036,864 | ---- | C] () -- C:\Windows\System32\HWS_Ctrl.dll
[2007.04.16 08:35:21 | 000,006,642 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2007.04.16 08:02:55 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2007.04.16 07:26:26 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2007.04.16 07:26:26 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2007.04.16 07:26:26 | 000,010,146 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2007.04.16 07:26:26 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2007.04.16 07:23:35 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2007.04.16 06:38:28 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1227.dll
[2007.03.26 10:45:18 | 000,071,208 | ---- | C] () -- C:\Windows\System32\PhysXLoader.dll
[2007.02.20 14:59:08 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2007.02.20 14:59:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2007.02.20 14:59:04 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2006.12.05 13:05:06 | 000,114,688 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005.11.23 14:55:42 | 000,024,576 | ---- | C] () -- C:\Windows\System32\SPCtl.dll
[2005.07.22 21:30:20 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll
[2004.03.30 09:15:02 | 000,051,200 | ---- | C] () -- C:\Windows\System32\ThriXXX010205PNG.dll
[2004.03.30 09:15:01 | 000,056,832 | ---- | C] () -- C:\Windows\System32\ThriXXX015003JP2.dll
[2004.03.30 09:15:01 | 000,023,040 | ---- | C] () -- C:\Windows\System32\ThriXXX010104Z.dll
[2003.05.23 12:08:52 | 000,107,008 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2003.05.23 12:08:52 | 000,020,992 | ---- | C] () -- C:\Windows\System32\ogg.dll
 
========== LOP Check ==========
 
[2008.12.10 14:17:04 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\.wyzo
[2008.11.21 19:11:29 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Ancient Quest of Saqqarah_msn
[2010.06.02 19:58:40 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Azureus
[2009.01.23 20:18:23 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\BeachPartyCraze
[2009.04.05 17:37:09 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Boolat Games
[2007.12.25 01:56:35 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\DesktopSMS
[2009.10.29 15:19:31 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\FILEminimizerPictures
[2008.11.13 22:07:53 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Flood Light Games
[2008.04.24 21:18:00 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Gaijin Ent
[2009.03.09 22:48:57 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Gamelab
[2009.03.12 13:44:01 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Go Go Gourmet
[2008.11.12 16:03:55 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Go-Go Gourmet Chef of the Year
[2010.05.30 20:09:40 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\ICQ
[2009.01.12 19:11:58 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\iWin
[2008.07.28 10:49:39 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\LimeWire
[2008.06.01 13:10:20 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Meridian93
[2009.04.09 14:44:24 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\My Games
[2009.03.20 18:45:52 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\MysteryStudio
[2009.01.11 18:05:32 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Oberon Games
[2007.12.25 13:34:49 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\PeerNetworking
[2009.01.12 22:34:17 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\PetShowCraze
[2010.05.16 20:15:44 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\PlayFirst
[2009.01.25 00:02:31 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Pogo Games
[2010.06.02 21:20:19 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\QuickStoresToolbar
[2009.01.02 12:50:02 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Sandlot Games
[2008.05.17 20:54:09 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Sierra Entertainment
[2008.11.07 21:15:46 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\SmartSurfer
[2007.12.30 22:07:19 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\SoundSpectrum
[2007.12.25 00:31:23 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Toshiba
[2010.03.31 13:25:20 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\uTorrent
[2008.11.27 21:01:22 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Valusoft
[2009.01.25 22:31:32 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\ViquaSoft
[2010.03.31 13:42:21 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\WEB.DE
[2008.01.09 16:42:01 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\WEBDE
[2010.03.14 17:08:06 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Wild Tangent
[2009.03.20 17:52:24 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\WildTangent
[2008.06.03 09:37:14 | 000,000,000 | ---D | M] -- C:\Users\bianca\AppData\Roaming\Zylom
[2010.06.06 13:34:30 | 000,032,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:51387F29
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:3B3A35EC
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:05816AFA
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:753B0F80
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:3AE22B1A
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:38849DE5
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:965253AF
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:E98C5DD9
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:E54FA796
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:41099CE9
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:273A8657
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:61E5F0F7
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:E1982A23
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:4D066AD2
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:87FA5E8A
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:37CE0F2E
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:F65733F1
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:8EEE3BBB
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:765C6A14
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:DAFD38AE
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:92D18A5E
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:0207454C
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:45FE2B4E
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A42A9F39
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:4F636E25
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:3447AB86
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:A94968B5
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:1CB8D545
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:F50F1555
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:8C458D50
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:20DB61D6
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:18AE7C5A
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:A73B0434
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:E1F04E8D
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:1D6686D8
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:C4A1F01E
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:D26DD363
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:26C3D553
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:997E6AF4
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:588B60C7
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5EBA4934
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:33A7CC67
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:E71141D2
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D88D995C
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:5216CD26
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:B14B4A95
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:74699137
< End of report >

--- --- ---

MalwareHero 06.06.2010 13:52

Zitat:

Zitat von Bianca28 (Beitrag 530772)
und der andere. Ich mach auch gleich was du grad gesagt hast.

um in den abgesicherten Modus zu kommen musst du offline gehen und beim Reboot dir F8 taste drücken. wird auch in der anleitung beschrieben. (abgesicherter modus ohne netzwerkverbindung/treiber)

-----------------

Bianca28 06.06.2010 18:18

Also ich schreib mal eben schnell vom Handy. Beim schnell Scan hat er ein was gefunden also lass ich jetzt den kompletten laufen. Das dauert schon ein paar Stunden und ich glaube er braucht auch noch ein paar. Was soll ich machen wenn er fertig ist? Soll ich das loeschen was er findet?

MalwareHero 06.06.2010 18:36

Zitat:

Zitat von Bianca28 (Beitrag 530834)
Also ich schreib mal eben schnell vom Handy. Beim schnell Scan hat er ein was gefunden also lass ich jetzt den kompletten laufen. Das dauert schon ein paar Stunden und ich glaube er braucht auch noch ein paar. Was soll ich machen wenn er fertig ist? Soll ich das loeschen was er findet?

das kannst du in die Quarantäne verschieben lassen. (verschieben, er macht das automatisch)
Poste dann das log zum schluss.

MalwareHero 06.06.2010 18:47

schmeiss gleichzeitig auch noch mal malwarebytes an und mache einen vollscan, dann wird die zeit gut genutzt :-)

Bianca28 07.06.2010 09:50

sooo, also Dr. Web hat mind. 12h gescannt. Ich musste ihn die Nacht laufen lassen.

Eine Datei hatte er gefunden und diese gelöscht weil er sie nicht desinfizieren konnte. aber als ich dann heut morgen den Bericht speichern wollte ist mir alles komplett abgestürtzt und ich musste den PC neustarten. :-(

Aber Malewarebytes hat nichts mehr gefunden. Und beim Laptop sarten kam auch keine Virusmeldung mehr und bisher haben sich auch keine Seiten aufgemacht :-)

MalwareHero 07.06.2010 12:16

Zitat:

Zitat von Bianca28 (Beitrag 530922)

Aber Malewarebytes hat nichts mehr gefunden. Und beim Laptop sarten kam auch keine Virusmeldung mehr und bisher haben sich auch keine Seiten aufgemacht :-)

Gut führe jetzt das durch:

OTL Fix:

* Schliesse alle Programme, deaktiviere den Wächter von Avira und
starte das Programm OTL.
* Kopiere genau den Inhalt im Codefenster (siehe unten) in die leere Textbox von OTL.

Code:

Zitat:

:OTL
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Programme\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [MSServer] C:\Users\bianca\AppData\Local\Temp\efcBusQh.DLL File not found
O9 - Extra Button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - File not found
[2010.06.03 11:54:38 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TASKMGR.COM
[2010.06.03 11:54:38 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\T.COM
[2010.06.03 11:54:38 | 000,134,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\REGEDIT.COM
[2010.06.03 11:54:38 | 000,134,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\R.COM
[2010.06.02 21:41:29 | 000,000,000 | ---D | C] -- C:\Windows\VDLL.DLL
[2010.06.02 21:41:29 | 000,000,000 | ---D | C] -- C:\Windows\System32\runouce.exe
[2010.06.02 21:41:29 | 000,000,000 | ---D | C] -- C:\Windows\RUNDL132.EXE
[2010.06.02 21:41:29 | 000,000,000 | ---D | C] -- C:\Windows\logo_1.exe

:Files
C:\program files\bearshare\bearshare.exe
C:\program files\wyzo\wyzo.exe
C:\Users\bianca\AppData\Local\mutbihpv.exe
C:\Users\bianca\AppData\Local\IM\Identities\{1BF9C0B6-CD0A-43DF-BA2B-29CC48074C61}\Message Store\Attachments\Factura49.zip
C:\Users\bianca\Desktop\imsodx\iMSDOX-ZooTycoon2003P1_Trainer.exe


:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]

* Klicke auf den roten Run Fix Button.
* OTL wird den PC neustarten. Bitte abwarten und das zulassen.
Nach dem Neustart warte bis das Log hochkommt.
* Log posten, (wird auf C:\ gespeichert)

-------------------------------------
> Bitte setze deinen Firewall zurück:
Windows-Firewall zurücksetzen auf Windows 7, Vista und XP ... ScareWare.de


Diese Files bei VT überprüfen VirusTotal - Free Online Virus and Malware Scan log posten wenn was gemeldet wird.

Zitat:

C:\Windows\tsnp325.exe

> Kontrollscan mit Eset Online Scanner: (Vollscan)
ESET Online Scanner - ESET Antivirus Software
poste die ergebnisse.
.........................................

Bianca28 07.06.2010 13:29

Zitat:

> Bitte setze deinen Firewall zurück:
Windows-Firewall zurücksetzen auf Windows 7, Vista und XP ... ScareWare.de
Erledigt!!!


Zitat:

Gut führe jetzt das durch:

OTL Fix:

* Schliesse alle Programme, deaktiviere den Wächter von Avira und
starte das Programm OTL.
* Kopiere genau den Inhalt im Codefenster (siehe unten) in die leere Textbox von OTL.
Erledigt!!

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ deleted successfully.
C:\Programme\Vuze_Remote\tbVuze.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.
File C:\Programme\Vuze_Remote\tbVuze.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ba14329e-9550-4989-b3f2-9732e92d17cc} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.
File C:\Programme\Vuze_Remote\tbVuze.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{965B54B0-71E0-4611-8DE7-F73FA0B20E26} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{965B54B0-71E0-4611-8DE7-F73FA0B20E26}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BA14329E-9550-4989-B3F2-9732E92D17CC} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA14329E-9550-4989-B3F2-9732E92D17CC}\ not found.
File C:\Programme\Vuze_Remote\tbVuze.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
C:\Programme\Adobe\Reader 8.0\Reader\reader_sl.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MSServer deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{C08CAF1D-C0A3-40D5-9970-06D067EAC017}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C08CAF1D-C0A3-40D5-9970-06D067EAC017}\ not found.
C:\Windows\System32\TASKMGR.COM moved successfully.
C:\Windows\System32\T.COM moved successfully.
C:\Windows\REGEDIT.COM moved successfully.
C:\Windows\R.COM moved successfully.
C:\Windows\VDLL.DLL folder moved successfully.
C:\Windows\System32\runouce.exe folder moved successfully.
C:\Windows\RUNDL132.EXE folder moved successfully.
C:\Windows\logo_1.exe folder moved successfully.
========== FILES ==========
File\Folder C:\program files\bearshare\bearshare.exe not found.
File\Folder C:\program files\wyzo\wyzo.exe not found.
File\Folder C:\Users\bianca\AppData\Local\mutbihpv.exe not found.
C:\Users\bianca\AppData\Local\IM\Identities\{1BF9C0B6-CD0A-43DF-BA2B-29CC48074C61}\Message Store\Attachments\Factura49.zip moved successfully.
File\Folder C:\Users\bianca\Desktop\imsodx\iMSDOX-ZooTycoon2003P1_Trainer.exe not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: bianca
->Temp folder emptied: 2004 bytes
->Temporary Internet Files folder emptied: 230566192 bytes
->Java cache emptied: 128687029 bytes
->FireFox cache emptied: 87666536 bytes
->Google Chrome cache emptied: 5883153 bytes
->Apple Safari cache emptied: 33665209 bytes
->Flash cache emptied: 475544 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2813434 bytes
RecycleBin emptied: 1065 bytes

Total Files Cleaned = 467,00 mb


[EMPTYFLASH]

User: bianca
->Flash cache emptied: 0 bytes

User: Default
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.5.3 log created on 06072010_141334

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Zitat:

Diese Files bei VT überprüfen VirusTotal - Free Online Virus and Malware Scan log posten wenn was gemeldet wird.
Erledigt!!!

PS: verstehe nicht wieso das scheinbar schinmal im Mai dort überprüft wurde. Ich habe die Seite noch nie gesehen. Komisch. Naja auf alle Fälle keine Auffälligkeiten!

Datei tsnp325.exe empfangen 2010.05.24 20:04:30 (UTC)
Status: Beendet
Ergebnis: 0/40 (0.00%)

Zitat:

> Kontrollscan mit Eset Online Scanner: (Vollscan)
ESET Online Scanner - ESET Antivirus Software
Mach ich jetzt gleich!

MalwareHero 07.06.2010 14:03

Zitat:

Zitat von Bianca28 (Beitrag 530978)

PS: verstehe nicht wieso das scheinbar schinmal im Mai dort überprüft wurde. Ich habe die Seite noch nie gesehen. Komisch. Naja auf alle Fälle keine Auffälligkeiten!

Das bedeutet nur, das diese Datei schon mal bei VT überprüft wurde, nicht das DU sie dort überprüft hast. ;)

Zitat:

Mach ich jetzt gleich!
Gut. Poste dann das log von ESET.

> Sonst sieht das bisher ganz ok aus. Das Dr.Web 12 Stunden gescant hatte war so nicht vorgesehen und ist etwas merkwürdig. Auf deinem PC war aber auch viel "Müll". OTL hat gerade 467,00 mb ! an unnötigen tmp. Dateien gelöscht. Z.B. mit dem Programm CCleaner kannst du deinen PC in Zukunft schlank halten.

> Bitte lese dir mal diesen Link über Sicherheit im Internet durch und halte dich in der Zukunft daran:
http://www.trojaner-board.de/74052-s...-internet.html

UPDATES SIND WICHTIG! Windows / und andere Software
- Java und Acrobat Reader bitte deinstallieren und mit der neusten Version ersetzen.
Java-Downloads für alle Betriebssysteme - Sun Microsystems
Adobe - Adobe Reader herunterladen - Alle Versionen

> Gleichzeitig mit ESET lasse auch noch mal SuperAntiSpyware drüberlaufen und lösche was gefunden wird.
Anleitung hier: http://www.trojaner-board.de/51871-a...tispyware.html Log posten.

----------------------------------

Bianca28 07.06.2010 16:45

hi, also zuersteinmal ganz doll vielen lieben danke. Ich knuddel dich erstmal virtuel um. Also such dir was wo du weich drauf fallen kannst :-)

ESET läuft noch. (seit 3h) und SUPERAntiSpyware auch noch.

Blöderweise hat ESET was gefunden. Er sagt es wäre möglicherweise eine Variante von Win32/Spy.Agent.Troyaner

Und das andere hat auch was gefunden. Zum einen ein paar Tracking Coockies (ich glaub das war harmlos, oder?) und ein Adware von WhenU. Das ist mir ein begriff damit hab ich schon mal Probleme gehabt.

Ich weiß das ich viel Müll drauf habe (asche auf mein Haupt).
Das Problem ist das ich nie weiß was ich löschen darf und was nicht. :-(

Übrigens, super ist, das jetzt auch die 2 Fehlermeldungen weg sind. Die waren immer beim hochfahren da. Irgendwas stimmte wohl mit 2 .dll dateien nicht.

Bianca28 07.06.2010 17:20

Mann, ich sowas von bescheuert!!!! :mad::mad: ESET ist bendet und was mach ich??? ICh gehe auf benden *grrrr*

Aber ausser dem einen hat er nichts gefunden und hat es auch gleich gelöscht.

Bianca28 07.06.2010 19:03

Hier dir Logs von dem superdingens :-)

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 06/07/2010 at 07:46 PM

Application Version : 4.38.1004

Core Rules Database Version : 5040
Trace Rules Database Version: 2852

Scan type : Quick Scan
Total Scan Time : 02:22:22

Memory items scanned : 904
Memory threats detected : 0
Registry items scanned : 700
Registry threats detected : 1
File items scanned : 137932
File threats detected : 169

Adware.WhenU
HKU\S-1-5-21-1034019143-2737408986-3283157118-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA2325ED-F9EB-4830-8FCE-0BC35B16969B}

Adware.Tracking Cookie
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@momporndaily[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@serving-sys[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@apmebf[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@clickpayz7.91423.blueseek[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.etracker[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@abyssteens[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.youngteenporn[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.nastyteensdesire[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.discount24[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@advertise[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@clicksor[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@freepornet[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@click.revsharecash[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@clickpayz5.91423.blueseek[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.sexpartnerclub[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@maturelikesex[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.matureporno[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@porndad[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@finalteens[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@myniceteen[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@adxpansion[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ad.yieldmanager[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@tribalfusion[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@gostats[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@fullsexmovies[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@interclick[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ads.traffikings[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@tube1sex[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@yadro[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@brightpornstars[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ad.adition[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@track.webgains[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.hardsextube[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ads.watchmygf[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@mediatraffic[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@doubleclick[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@sexpartnerclub[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ad.zanox[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@track.effiliation[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@overture[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@clickpayz1.91485.blueseek[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@invitemedia[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@media6degrees[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@adcloudmedia[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@traffictrack[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@stan1.wivesexposed[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@porn.vidz[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@atdmt[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@fastclick[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@pornmomsxxx[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@clickpayz8.91449.blueseek[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@bluestreak[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ads.cpxcenter[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@zanox[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@onpornstar[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.fullsexmovies[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@trafficholder[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@maturelikesex[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.greatteentube[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@adultmoviegroup[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@adserving.claxon[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.pornorama[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@mediaplex[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@tradedoubler[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@adultfriendfinder[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ads.cnn[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@bs.serving-sys[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@adtech[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ads.quartermedia[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@clickpayz7.91449.blueseek[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@content.yieldmanager[6].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ad.adserver01[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@hardsextube[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@game-advertising-online[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@adfarm1.adition[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@banner.33drugs[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@click.payserve[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@zedo[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.onpornstar[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@track.effiliation[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@videoegg.adbureau[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@clickpayz9.91449.blueseek[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@adbrite[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@banghornymom[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.onpornstar[5].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@xm.xtendmedia[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.tubeporngigs[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@brightpornstars[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ads.easyad[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@go.trafficshop[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@clickpayz3.91423.blueseek[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ads.pubmatic[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@elitewifes[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www1.12finder[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@pornhub[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@teensexmania[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@zanox-affiliate[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.xxxautomat[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@smartadserver[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@amateursexy[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www9.discount24[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@myroitracking[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@greedycunts[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ads.pornostiefn[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@discount24[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@imrworldwide[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@webmasterplan[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@liveperson[5].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@clickpayz4.91485.blueseek[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@momsxxxporn[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ads.medienhaus[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@ads.whaleads[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@content.yieldmanager[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@eas.apm.emediate[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@adserver.hardsextube[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@adserving.favorit-network[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@abyssteens[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@xxxmatch[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@trafficengine[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@counter10.sextracker[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@teensbabylon[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.findstuff[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.madfucktube[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@adultadworld[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@teenandteen[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.protraffic[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@teenpornsexy[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.wildporntube[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@liveperson[6].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@toplist[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@hardsextubepremium[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@galleries1.adult-empire[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.fpctraffic2[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@clickpayz1.91449.blueseek[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@enter.hardsextubepremium[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.agedcunts[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@track.right-ads[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@sextracker[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@18eighteen[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@de.sitestat[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@dev.hardsextube[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@liveperson[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@wivesexposed[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@tour1.xxxmatch[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@fuckmilfholes[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@trafficholder[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.zanox-affiliate[4].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@galleries.adult-empire[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.teenporna[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@clickpayz8.91423.blueseek[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@mollyteens[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@newteeny[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@pornorama[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.bestteensfucking[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@stan.wivesexposed[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.gooteen[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@wt.xxxmatch[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@adecn[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@counter16.sextracker[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.freesex999[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.teensbabylon[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@clickcash[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@www.matureporno[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@galleries.teensexmania[1].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@tracking.quisma[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@server.iad.liveperson[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@2o7[3].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@hot-naked-milfs[2].txt
C:\Users\bianca\AppData\Roaming\Microsoft\Windows\Cookies\bianca@statcounter[1].txt


Das sind ja alles Sex seiten :eek::eek::eek::eek::eek::eek:

MalwareHero 07.06.2010 20:08

Zitat:

Zitat von Bianca28 (Beitrag 531124)
Hier dir Logs von dem superdingens :-)

Die Fünde löschen lassen.

Abschliessende Schritte/Aufräumarbeiten:

> Deinstalliere:

SuperAntiSpyware
Dr.Web (löschen)

> OTL deinstallieren:
Schliesse alle Programme und öffne OTL. Klicke auf "Bereinigung".
Warte geduldig bis sich ein Infofenster öffnet (1-3min) : "Das System benötigt einen Neustart..."
Klicke ok. Der PC startet neu.

> Gehe auf Start > Ausführen > schreibe in das Eingabefeld > cmd > es öffnet sich ein schwarzes Command Fenster, schreibe rein > chkdsk/f
nach der Rückfrage antworte mit J.
Beim nächsten Restart wird der PC auf Fehler überprüft, warte das einfach ab.

> Deaktiviere die Windows Systemwiederherstellung >
Systemwiederherstellung deaktivieren unter Vista - Windows Tipps Tricks Computer PC Hilfe
schalte den PC aus. Restarte nach 2-3 min und aktiviere die Systemwiederherstellung wieder.
----------------------------------
> Rootkit Scan mit Rootrepeal.
Download: http://ad13.geekstogo.com/RootRepeal.zip
entpacken > doppelklicke "rootrepeal.exe" Gehe unten in der Leiste auf Report. Klicke Scan > kreuze alle Scanfenster an > kreuze alle Festplatten an > klicke ok. Nach dem Scan das Log hier abkopieren.

Wenn dieser Scan sauber ist sind wir fertig.

Bianca28 07.06.2010 21:37

Ok, mach ich alles morgen gegen Abend. Muss auch mal wieder arbeiten ;-)

Ich poste dann die Logs.

Wünsch dir noch einen schönen Abend!

Bianca28 08.06.2010 20:21

So, swoeit hab ich alles gemacht. Scannen lass ich ihn über Nacht.

Zitat:

> Gehe auf Start > Ausführen > schreibe in das Eingabefeld > cmd > es öffnet sich ein schwarzes Command Fenster, schreibe rein > chkdsk/f
nach der Rückfrage antworte mit J.
Damit hab ich Probleme. Er sagt ich wäre dafür nicht berechtigt. Ich nutze den Laptop aber allein.

Bianca28 10.06.2010 16:31

Zitat:

Rootkit Scan mit Rootrepeal.
Download: hxxp://ad13.geekstogo.com/RootRepeal.zip
entpacken > doppelklicke "rootrepeal.exe" Gehe unten in der Leiste auf Report. Klicke Scan > kreuze alle Scanfenster an > kreuze alle Festplatten an > klicke ok. Nach dem Scan das Log hier abkopieren.
Leider hab ich auch damit Probleme. Es stürzt laufend ab und die Fehlermeldung kann ich nicht mal sehen da es nur das Kästchen ist und in der Mitte wo normalerweise immer Fehlermelduingen stehen ist es durchsichtig. Also man sieht das was im Hintergrund grad steht.

Aber ansonsten hba ich bisher keine Probleme wieder gehabt.

MalwareHero 10.06.2010 19:25

Zitat:

Zitat von Bianca28 (Beitrag 532070)
Leider hab ich auch damit Probleme.

Aber ansonsten hba ich bisher keine Probleme wieder gehabt.

chkdsk/f so machen:
Check Disk - chkdsk - Vista Forums
(scrolle runter zur anleitung)

GMER nach der Anleitung ausführen. Nichts anklicken wenn er scannt!
http://www.trojaner-board.de/74908-a...t-scanner.html
wenn der streikt dann:
http://www.trojaner-board.de/85306-anleitung-osam.html

----------------


Alle Zeitangaben in WEZ +1. Es ist jetzt 17:49 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19