Shinichi | 19.04.2011 19:14 | Hallo M-K-D-B,
das genannte Problem ist jediglich bei Firefox vorhanden und tritt nicht bei meinem Internet Exproler auf.
Wenn ich mir die geblockten, bzw. das gelockte Programm ansehe, wird mir angezeigt, dass es sich hierbei um Malwarebytes' Anti-Malwarehandelt.
Die genannten Programme habe ich ohne Probleme löschen können, ich habe diese wohl unbewusst installieren lassen, wenn ich davon ausgehe, dass sie mir bei den Firefox Updates angegeben wurden. Ich werde demnächst mehr darauf achtgeben.
Bei der Datei von Megavideo handelt es sich um einen Teil eines Videos, welches ich wohl mal bei dem Versuch etwas anzusehen gedownloadet habe, soll ich es einfach löschen? Es treten keine der genannten Probleme auf, wenn ich es ausführe.
Hier die gwünschten Links: Zitat:
hxxp://www.virustotal.com/file-scan/report.html?id=3278d7329ac8ca6d1b0df8f2dd4c6d74de4395c6d77a77e236d7efb78be20eb2-1303232294
hxxp://www.virustotal.com/file-scan/report.html?id=9d064cdabd47fd34d726d2e115e1f4c78706a8da7c09cf3ba6374c5f7b5922c1-1303232432
| OTL Logfile: Code:
OTL logfile created on: 19.04.2011 19:23:44 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Melissa\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 50,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 70,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144,29 Gb Total Space | 51,00 Gb Free Space | 35,35% Space Free | Partition Type: NTFS
Drive D: | 144,04 Gb Total Space | 142,65 Gb Free Space | 99,04% Space Free | Partition Type: NTFS
Drive G: | 298,01 Gb Total Space | 126,61 Gb Free Space | 42,49% Space Free | Partition Type: FAT32
Drive J: | 931,28 Gb Total Space | 43,52 Gb Free Space | 4,67% Space Free | Partition Type: FAT32
Computer Name: ASSIGAMMELKEKS | User Name: Melissa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Melissa\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Programme\Replay Media Catcher\FLVSrvc.exe (Applian Technologies, Inc.)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - D:\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Programme\T-Online\WLAN-Access Finder\ToWLaAcF.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
PRC - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
PRC - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
PRC - C:\Programme\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe (CyberLink)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe ()
PRC - C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis2\sc_watch.exe (Deutsche Telekom AG)
PRC - C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis2\profilemgr.exe (Deutsche Telekom AG)
PRC - C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis2\kernel.exe (Deutsche Telekom AG)
PRC - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe ()
PRC - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
PRC - C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
PRC - C:\Programme\Common Files\Marmiko Shared\MWLaMaS.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
PRC - C:\Programme\T-Online\T-Online_Software_6\Notifier\Notifier.exe (fun communications GmbH, hxxp://www.fun.de)
PRC - C:\Programme\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.00\WlanCU.exe ()
========== Modules (SafeList) ==========
MOD - C:\Users\Melissa\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (ACDaemon) -- C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AdobeActiveFileMonitor7.0) -- D:\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (eDataSecurity Service) -- C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
SRV - (Acer HomeMedia Connect Service) -- C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe (CyberLink)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (eSettingsService) -- C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe ()
SRV - (AcerMemUsageCheckService) -- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe ()
SRV - (eRecoveryService) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
SRV - (StarWindServiceAE) -- C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
========== Driver Services (SafeList) ==========
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (taphss) -- C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\System32\drivers\sfdrv01.sys (Protection Technology (StarForce))
DRV - (hcw95rc) -- C:\Windows\System32\drivers\hcw95rc.sys (Hauppauge Computer Works, Inc.)
DRV - (hcw95bda) -- C:\Windows\System32\drivers\hcw95bda.sys (Hauppauge Computer Works, Inc.)
DRV - (zntport) -- C:\Windows\System32\drivers\zntport.sys (Zeal SoftStudio)
DRV - (tvicport) -- C:\Windows\System32\drivers\TVicPort.sys (EnTech Taiwan)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (RTHDMIAzAudService) -- C:\Windows\System32\drivers\RtHDMIV.sys (Realtek Semiconductor Corp.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (sfvfs02) StarForce Protection VFS Driver (version 2.x) -- C:\Windows\System32\drivers\sfvfs02.sys (Protection Technology (StarForce))
DRV - (int15) -- C:\Acer\Empowering Technology\eRecovery\int15.sys ()
DRV - (Afc) -- C:\Windows\System32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (MTOnlPktAlyX) -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
DRV - (sfsync02) StarForce Protection Synchronization Driver (version 2.x) -- C:\Windows\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\System32\drivers\sfhlp02.sys (Protection Technology (StarForce))
DRV - (SIS163u) -- C:\Windows\System32\drivers\SiS163u.sys (SiS Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.intl.acer.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=1&o=vp32&d=1008&m=aspire_l5100
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=1&o=vp32&d=1008&m=aspire_l5100
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=1&o=vp32&d=1008&m=aspire_l5100
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=827316"
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..browser.startup.homepage: "google.de"
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
FF - prefs.js..extensions.enabledItems: illimitux@illimitux.net:4.0
FF - prefs.js..extensions.enabledItems: radiobar@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: searchrecs@veoh.com:1.5.2
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.2
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {ecdee021-0d17-467f-a1ff-c7a115230949}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: web@veoh.com:1.4
FF - prefs.js..extensions.enabledItems: ffxtlbr@babylon.com:1.1.3
FF - prefs.js..keyword.URL: "hxxp://search.babylon.com/?babsrc=SP_ss&mntrId=98cfdf4f00000000000000ff982a88c7&tlver=1.4.19.19&instlRef=sst&ss=1&affID=17395&q="
FF - HKLM\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\2.bin
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.04.12 18:27:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.03.24 10:54:47 | 000,000,000 | ---D | M]
[2009.01.19 23:00:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Melissa\AppData\Roaming\mozilla\Extensions
[2011.04.18 23:00:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions
[2010.07.09 10:27:20 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.03.14 11:54:26 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010.10.04 10:31:37 | 000,000,000 | ---D | M] (DVDVideoSoftTB Toolbar) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010.10.26 15:04:48 | 000,000,000 | ---D | M] (DigitalPowered Toolbar) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\{b317125e-2f10-4388-bf1f-2c31c6cd89ed}
[2011.03.30 18:22:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\{b317125e-2f10-4388-bf1f-2c31c6cd89ed}-trash
[2011.01.25 12:30:40 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011.01.19 14:45:37 | 000,000,000 | ---D | M] (softonic-de3 Community Toolbar) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}
[2010.10.04 10:31:38 | 000,000,000 | ---D | M] (free-downloads.net Toolbar) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\{ecdee021-0d17-467f-a1ff-c7a115230949}
[2011.01.25 12:30:48 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\engine@conduit.com
[2011.03.29 14:50:56 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\ffxtlbr@babylon.com
[2010.03.28 22:07:49 | 000,000,000 | ---D | M] (Illimitux) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\illimitux@illimitux.net
[2010.01.30 16:48:09 | 000,000,000 | ---D | M] (RadioBar Toolbar) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\radiobar@toolbar
[2010.02.07 02:10:02 | 000,000,000 | ---D | M] (Veoh Video Compass) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\searchrecs@veoh.com
[2011.01.25 12:30:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Melissa\AppData\Roaming\mozilla\Firefox\Profiles\ne30dex4.default\extensions\staged-xpis
[2010.08.09 11:29:22 | 000,000,873 | ---- | M] () -- C:\Users\Melissa\AppData\Roaming\Mozilla\Firefox\Profiles\ne30dex4.default\searchplugins\conduit.xml
[2011.04.06 22:52:20 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.02.16 21:00:29 | 000,000,000 | ---D | M] (VMLoad) -- C:\Programme\Mozilla Firefox\extensions\{464F169E-ACE1-4C5F-A778-A433A3DABBAE}
[2009.08.15 23:40:15 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009.12.06 21:44:35 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD\FIREFOX\EXT
[2009.01.20 12:30:15 | 000,000,000 | ---D | M] (Veoh Web Player Video Finder) -- C:\PROGRAM FILES\VEOH NETWORKS\VEOHWEBPLAYER\FFVIDEOFINDER
[2008.09.04 02:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npbittorrent.dll
[2010.05.25 18:09:48 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npwachk.dll
[2011.03.06 00:27:43 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2011.03.06 00:27:43 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2011.03.06 00:27:43 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2011.03.06 00:27:43 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2011.03.06 00:27:43 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programme\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programme\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID-Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (VMLoadHBO Class) - {C17C7688-31D1-46D7-8C9B-5D253E4F5D5E} - C:\Users\Melissa\AppData\Roaming\VMLoad\addin\VMLoad.dll (TODO: <Company name>)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programme\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Acer Tour Reminder] File not found
O4 - HKLM..\Run: [Apanel] File not found
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [Ask and Record FLV Service] C:\Program Files\Replay Media Catcher\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PCMMediaSharing] C:\Programme\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] c:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe (Acer Inc.)
O4 - HKCU..\Run: [chknelog] File not found
O4 - HKCU..\Run: [cxlacuxatx.exe] File not found
O4 - HKCU..\Run: [T-Online_Software_6\WLAN-Access Finder] C:\Program Files\T-Online\WLAN-Access Finder\ToWLaAcF.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Secret City - {D401C3A2-12EF-4D1D-A086-F3AB10B565BF} - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - File not found
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file:///C:/Windows/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Programme\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Melissa\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Melissa\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006.11.03 12:58:30 | 000,000,038 | -H-- | M] () - G:\AUTORUN.FCB -- [ FAT32 ]
O32 - AutoRun File - [2009.08.10 15:40:34 | 000,000,103 | ---- | M] () - J:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{26f0f3d0-e677-11dd-b932-0040f4b7a179}\Shell - "" = AutoRun
O33 - MountPoints2\{26f0f3d0-e677-11dd-b932-0040f4b7a179}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL H:\DVR/AutoRun.exe start.exe
O33 - MountPoints2\{2736ac1d-cde0-11de-9b03-0040f4b7a179}\Shell - "" = AutoRun
O33 - MountPoints2\{2736ac1d-cde0-11de-9b03-0040f4b7a179}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL H:\DVR/AutoRun.exe start.exe
O33 - MountPoints2\{5560534d-38b7-11de-87b8-0040f4b7a179}\Shell - "" = AutoRun
O33 - MountPoints2\{5560534d-38b7-11de-87b8-0040f4b7a179}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL H:\DVR/AutoRun.exe start.exe
O33 - MountPoints2\{b06dce6f-5cdc-11de-919f-0040f4b7a179}\Shell - "" = AutoRun
O33 - MountPoints2\{b06dce6f-5cdc-11de-919f-0040f4b7a179}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\DVR/AutoRun.exe start.exe
O33 - MountPoints2\{cd3199c9-e665-11dd-9066-001fe23aea48}\Shell\AutoRun\command - "" = G:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk - - File not found
MsConfig - StartUpFolder: C:^Users^Melissa^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk - C:\Programme\OpenOffice.org 3\program\quickstart.exe - ()
MsConfig - StartUpReg: Acer Empowering Technology Monitor - hkey= - key= - C:\Acer\Empowering Technology\SysMonitor.exe ()
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: AlcoholAutomount - hkey= - key= - C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - D:\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
MsConfig - StartUpReg: InfoCockpit - hkey= - key= - C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: mcagent_exe - hkey= - key= - File not found
MsConfig - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg: TkBellExe - hkey= - key= - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
MsConfig - StartUpReg: VeohPlugin - hkey= - key= - C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
MsConfig - StartUpReg: Windows Defender - hkey= - key= - File not found
MsConfig - State: "startup" - 2
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011.04.17 21:57:10 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.04.17 21:55:23 | 000,000,000 | ---D | C] -- C:\Programme\ERUNT
[2011.04.17 21:55:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011.04.17 21:30:47 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\Melissa\Desktop\Erunt-setup.exe
[2011.04.17 21:30:47 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Users\Melissa\Desktop\TFC.exe
[2011.04.17 20:51:30 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Melissa\Desktop\OTL.exe
[2011.04.15 15:11:24 | 000,000,000 | ---D | C] -- C:\Users\Melissa\AppData\Roaming\Malwarebytes
[2011.04.15 15:11:18 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.04.15 15:11:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.04.15 15:11:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.04.15 15:11:13 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.04.15 15:11:13 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.04.13 12:51:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
[2011.04.13 12:51:30 | 000,000,000 | ---D | C] -- C:\Programme\Defraggler
[2011.04.13 12:36:09 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2011.04.02 12:27:47 | 000,000,000 | ---D | C] -- C:\Users\Melissa\AppData\Roaming\Xois
[2011.04.02 12:27:47 | 000,000,000 | ---D | C] -- C:\Users\Melissa\AppData\Roaming\Iwnevo
[2009.01.19 22:11:52 | 000,016,384 | ---- | C] ( ) -- C:\Windows\System32\ClearEvent.exe
[2008.09.30 06:55:45 | 000,049,152 | ---- | C] ( ) -- C:\Windows\INTEROP.IWSHRUNTIMELIBRARY.DLL
========== Files - Modified Within 30 Days ==========
[2011.04.19 19:14:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.04.19 19:14:00 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.04.19 18:52:55 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.04.19 18:52:54 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.04.19 18:52:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.04.19 18:52:25 | 1878,515,712 | -HS- | M] () -- C:\hiberfil.sys
[2011.04.19 18:49:41 | 000,002,560 | ---- | M] () -- C:\Windows\_MSRSTRT.EXE
[2011.04.18 22:19:25 | 000,040,005 | ---- | M] () -- C:\Users\Melissa\Desktop\Malvada.odt
[2011.04.18 21:24:54 | 000,674,344 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.04.18 21:24:54 | 000,634,202 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.04.18 21:24:54 | 000,146,028 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.04.18 21:24:54 | 000,119,766 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.04.18 15:52:08 | 000,244,736 | ---- | M] () -- C:\Users\Melissa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.17 21:55:23 | 000,000,737 | ---- | M] () -- C:\Users\Melissa\Desktop\NTREGOPT.lnk
[2011.04.17 21:55:23 | 000,000,718 | ---- | M] () -- C:\Users\Melissa\Desktop\ERUNT.lnk
[2011.04.17 21:39:24 | 000,301,568 | ---- | M] () -- C:\Users\Melissa\Desktop\g2m3e4r.exe
[2011.04.17 21:39:23 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\Melissa\Desktop\Erunt-setup.exe
[2011.04.17 21:39:18 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Users\Melissa\Desktop\TFC.exe
[2011.04.17 21:39:17 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Melissa\Desktop\OTL.exe
[2011.04.17 21:28:35 | 000,377,280 | ---- | M] () -- C:\Users\Melissa\Desktop\Load.exe
[2011.04.17 10:17:49 | 000,000,456 | ---- | M] () -- C:\Windows\tasks\Driver Robot.job
[2011.04.16 11:30:08 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
[2011.04.16 11:30:08 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
[2011.04.16 11:30:00 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2011.04.15 15:11:18 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.04.15 03:30:24 | 000,328,032 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.04.13 12:51:32 | 000,001,706 | ---- | M] () -- C:\Users\Public\Desktop\Defraggler.lnk
[2011.04.11 20:43:57 | 092,643,550 | ---- | M] () -- C:\Users\Melissa\Documents\Megavideo.com - 2828C2AF60C2BB..C2AB5BNeverAlone5DC2BB..C2ABC2B4C2AF2929.flv
[2011.04.06 22:35:33 | 000,000,054 | ---- | M] () -- C:\Windows\mpsettings.ini
========== Files Created - No Company Name ==========
[2011.04.19 18:49:40 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2011.04.18 21:23:54 | 000,040,005 | ---- | C] () -- C:\Users\Melissa\Desktop\Malvada.odt
[2011.04.17 21:55:23 | 000,000,737 | ---- | C] () -- C:\Users\Melissa\Desktop\NTREGOPT.lnk
[2011.04.17 21:55:23 | 000,000,718 | ---- | C] () -- C:\Users\Melissa\Desktop\ERUNT.lnk
[2011.04.17 21:30:47 | 000,301,568 | ---- | C] () -- C:\Users\Melissa\Desktop\g2m3e4r.exe
[2011.04.17 21:28:35 | 000,377,280 | ---- | C] () -- C:\Users\Melissa\Desktop\Load.exe
[2011.04.16 11:30:00 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2011.04.15 15:11:18 | 000,000,910 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.04.13 12:51:32 | 000,001,706 | ---- | C] () -- C:\Users\Public\Desktop\Defraggler.lnk
[2011.04.11 20:43:58 | 092,643,550 | ---- | C] () -- C:\Users\Melissa\Documents\Megavideo.com - 2828C2AF60C2BB..C2AB5BNeverAlone5DC2BB..C2ABC2B4C2AF2929.flv
[2011.04.06 22:35:33 | 000,000,054 | ---- | C] () -- C:\Windows\mpsettings.ini
[2010.08.13 11:30:19 | 000,000,118 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2010.06.22 15:21:30 | 000,000,000 | ---- | C] () -- C:\Users\Melissa\AppData\Roaming\chrtmp
[2010.06.14 19:12:53 | 000,000,130 | ---- | C] () -- C:\Windows\System32\rpireica.bin
[2009.11.12 20:27:13 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2009.11.12 20:27:13 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2009.11.12 20:27:08 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009.11.12 20:27:07 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009.11.12 20:27:06 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009.11.09 19:19:44 | 000,000,000 | ---- | C] () -- C:\Windows\System32\swunilog.ini
[2009.11.04 23:47:55 | 000,237,568 | ---- | C] () -- C:\Windows\System32\rmc_rtspdl.dll
[2009.09.24 06:17:18 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.09.24 06:17:17 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.02 06:57:23 | 000,007,268 | ---- | C] () -- C:\Users\Melissa\AppData\Local\d3d9caps.dat
[2009.07.02 13:51:39 | 000,006,550 | ---- | C] () -- C:\Windows\jautoexp.dat
[2009.02.10 19:22:57 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib
[2009.01.28 20:46:28 | 000,000,096 | ---- | C] () -- C:\Users\Melissa\AppData\Roaming\wklnhst.dat
[2009.01.20 13:05:11 | 000,000,399 | ---- | C] () -- C:\Windows\vtplus32.ini
[2009.01.20 13:05:01 | 000,149,504 | ---- | C] () -- C:\Windows\System32\UNWISE.EXE
[2009.01.20 13:04:31 | 000,032,295 | ---- | C] () -- C:\Windows\Irremote.ini
[2009.01.20 13:04:21 | 000,065,536 | ---- | C] () -- C:\Windows\System32\dmcrypto.dll
[2009.01.20 13:03:53 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2009.01.20 13:03:53 | 000,000,135 | ---- | C] () -- C:\Windows\ODBC.INI
[2009.01.20 13:03:51 | 000,163,840 | ---- | C] () -- C:\Windows\System32\hcwChDB.dll
[2009.01.20 13:02:53 | 000,006,315 | ---- | C] () -- C:\Windows\HCWPNP.INI
[2009.01.20 00:02:56 | 000,244,736 | ---- | C] () -- C:\Users\Melissa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.01.19 23:11:52 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009.01.19 22:39:59 | 000,000,095 | ---- | C] () -- C:\Users\Melissa\AppData\Local\fusioncache.dat
[2009.01.19 22:11:52 | 000,016,384 | ---- | C] () -- C:\Windows\System32\LauncheRyAgentUser.exe
[2008.11.06 18:37:32 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2008.11.06 18:33:02 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
[2008.10.07 09:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008.10.07 09:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008.10.06 06:48:51 | 000,000,044 | ---- | C] () -- C:\Windows\Acer(Normal).ini
[2008.10.06 06:48:51 | 000,000,042 | ---- | C] () -- C:\Windows\Acer(Wide).ini
[2008.01.21 09:15:58 | 000,674,344 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008.01.21 09:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008.01.21 09:15:58 | 000,146,028 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008.01.21 09:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2007.04.11 19:30:48 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll
[2007.04.11 17:09:20 | 000,000,734 | ---- | C] () -- C:\Windows\generic.ini
[2007.04.11 17:09:20 | 000,000,125 | ---- | C] () -- C:\Windows\Alaunch.ini
[2007.04.11 17:07:33 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2007.04.11 17:07:33 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2007.04.11 17:07:32 | 000,144,773 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2007.04.11 09:20:03 | 000,015,656 | ---- | C] () -- C:\Windows\System32\drivers\int15_64.sys
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,328,032 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 000,634,202 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,119,766 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2005.01.06 15:04:00 | 000,049,152 | ---- | C] () -- C:\Windows\System32\unwlsdrv.exe
[2001.12.26 15:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001.09.03 22:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001.07.30 15:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001.07.23 21:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll
[1997.06.14 13:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll
========== LOP Check ==========
[2007.04.11 08:32:30 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Acer GameZone Console
[2011.04.11 21:09:32 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Any Video Converter
[2009.11.13 18:01:01 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Blitware
[2009.01.29 23:08:16 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Canneverbe_Limited
[2011.03.13 18:28:27 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\CD Art Display
[2009.06.30 18:35:13 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\DAEMON Tools Lite
[2009.11.05 23:11:46 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\InterTrust
[2011.04.13 11:25:24 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Iwnevo
[2010.09.24 00:16:01 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Leadertech
[2010.05.20 00:30:37 | 000,000,000 | -HSD | M] -- C:\Users\Melissa\AppData\Roaming\lowsec
[2009.04.25 11:37:51 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\OpenOffice.org
[2009.01.19 22:37:18 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\T-Online
[2009.03.04 20:54:32 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Template
[2009.11.13 18:08:33 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Uniblue
[2010.11.05 14:59:03 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\uTorrent
[2011.04.06 22:58:40 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\VMLoad
[2010.10.29 10:35:47 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\WindSolutions
[2011.04.07 21:04:14 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Xois
[2011.04.17 10:17:49 | 000,000,456 | ---- | M] () -- C:\Windows\Tasks\Driver Robot.job
[2011.04.19 18:51:09 | 000,032,584 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2009.03.12 11:45:19 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN
[2009.06.11 05:14:37 | 000,000,000 | ---D | M] -- C:\Acer
[2009.01.19 22:13:37 | 000,000,000 | ---D | M] -- C:\AcerSW
[2007.04.11 17:09:19 | 000,000,000 | ---D | M] -- C:\Book
[2009.11.10 21:12:29 | 000,000,000 | -HSD | M] -- C:\Boot
[2006.11.02 15:02:03 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2009.01.19 22:06:56 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2011.03.01 20:58:07 | 000,000,000 | ---D | M] -- C:\Downloads
[2007.04.11 17:09:19 | 000,000,000 | ---D | M] -- C:\DRV
[2011.03.20 23:13:44 | 000,000,000 | ---D | M] -- C:\DVDVideoSoft
[2009.06.20 13:57:42 | 000,000,000 | ---D | M] -- C:\FPC
[2011.04.06 22:47:18 | 000,000,000 | ---D | M] -- C:\Hotspot Shield
[2009.04.19 12:12:49 | 000,000,000 | ---D | M] -- C:\L10SAVES
[2009.01.20 19:55:41 | 000,000,000 | ---D | M] -- C:\MyVideos
[2008.01.21 04:32:31 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2011.04.19 18:52:24 | 000,000,000 | R--D | M] -- C:\Programme
[2011.04.15 18:09:39 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2009.01.19 22:06:56 | 000,000,000 | -HSD | M] -- C:\Programme
[2011.04.19 19:25:07 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2009.11.10 20:15:06 | 000,000,000 | ---D | M] -- C:\temp
[2011.04.13 13:08:49 | 000,000,000 | R--D | M] -- C:\Users
[2011.04.19 18:49:40 | 000,000,000 | ---D | M] -- C:\Windows
< %PROGRAMFILES%\*.exe >
< %PROGRAMFILES%\*. >
[2009.11.05 23:29:48 | 000,000,000 | ---D | M] -- C:\Programme\802.11 Wireless LAN
[2007.04.11 08:55:19 | 000,000,000 | ---D | M] -- C:\Programme\Acer Arcade Live
[2011.04.06 23:01:43 | 000,000,000 | ---D | M] -- C:\Programme\Acer GameZone
[2008.10.06 06:48:50 | 000,000,000 | ---D | M] -- C:\Programme\Acer Incorporated
[2007.04.11 09:03:35 | 000,000,000 | ---D | M] -- C:\Programme\Activation Assistant for the 2007 Microsoft Office suites
[2010.11.30 15:00:09 | 000,000,000 | ---D | M] -- C:\Programme\Activision
[2011.03.02 18:02:07 | 000,000,000 | ---D | M] -- C:\Programme\Adobe
[2009.04.03 17:01:27 | 000,000,000 | ---D | M] -- C:\Programme\Adobe Media Player
[2009.08.15 11:23:35 | 000,000,000 | ---D | M] -- C:\Programme\AGEIA Technologies
[2009.03.16 16:01:10 | 000,000,000 | ---D | M] -- C:\Programme\Alcohol Soft
[2009.02.10 19:29:03 | 000,000,000 | ---D | M] -- C:\Programme\Altova
[2009.01.20 00:28:26 | 000,000,000 | ---D | M] -- C:\Programme\Any Video Converter
[2010.10.29 12:09:04 | 000,000,000 | ---D | M] -- C:\Programme\Apple Software Update
[2010.05.21 16:39:32 | 000,000,000 | ---D | M] -- C:\Programme\ArcSoft
[2007.04.11 08:26:39 | 000,000,000 | ---D | M] -- C:\Programme\ATI
[2007.04.11 08:28:28 | 000,000,000 | ---D | M] -- C:\Programme\ATI Technologies
[2010.02.04 11:31:00 | 000,000,000 | ---D | M] -- C:\Programme\Avira
[2010.09.29 12:44:40 | 000,000,000 | ---D | M] -- C:\Programme\AVS4YOU
[2009.08.12 21:52:51 | 000,000,000 | ---D | M] -- C:\Programme\Baphomets Fluch II
[2009.05.02 20:48:50 | 000,000,000 | ---D | M] -- C:\Programme\BearShare Applications
[2011.04.06 22:40:26 | 000,000,000 | ---D | M] -- C:\Programme\BitTorrent
[2010.10.29 12:05:32 | 000,000,000 | ---D | M] -- C:\Programme\Bonjour
[2011.04.13 12:42:18 | 000,000,000 | ---D | M] -- C:\Programme\Common Files
[2009.02.20 20:04:41 | 000,000,000 | ---D | M] -- C:\Programme\coolspot AG
[2011.04.12 18:24:19 | 000,000,000 | ---D | M] -- C:\Programme\Counter-Strike 1.6 V40
[2007.04.11 08:49:57 | 000,000,000 | ---D | M] -- C:\Programme\CyberLink
[2009.06.29 22:29:01 | 000,000,000 | ---D | M] -- C:\Programme\DAEMON Tools Toolbar
[2011.04.13 12:51:32 | 000,000,000 | ---D | M] -- C:\Programme\Defraggler
[2007.04.11 09:33:20 | 000,000,000 | ---D | M] -- C:\Programme\DIFX
[2011.04.12 18:25:40 | 000,000,000 | ---D | M] -- C:\Programme\DivX
[2009.06.07 12:58:42 | 000,000,000 | ---D | M] -- C:\Programme\DNA
[2011.04.12 18:37:39 | 000,000,000 | ---D | M] -- C:\Programme\DVDVideoSoft
[2011.04.12 18:33:02 | 000,000,000 | ---D | M] -- C:\Programme\EA GAMES
[2009.02.10 19:22:07 | 000,000,000 | ---D | M] -- C:\Programme\Elaborate Bytes
[2011.03.15 00:37:58 | 000,000,000 | ---D | M] -- C:\Programme\Enterbrain
[2011.04.17 21:55:34 | 000,000,000 | ---D | M] -- C:\Programme\ERUNT
[2007.04.11 09:28:48 | 000,000,000 | ---D | M] -- C:\Programme\eSobi
[2009.01.19 22:06:56 | 000,000,000 | -HSD | M] -- C:\Programme\Gemeinsame Dateien
[2011.04.13 12:41:21 | 000,000,000 | ---D | M] -- C:\Programme\Google
[2010.05.10 19:23:25 | 000,000,000 | ---D | M] -- C:\Programme\id Software
[2011.04.06 23:15:34 | 000,000,000 | -H-D | M] -- C:\Programme\InstallShield Installation Information
[2011.04.17 10:18:51 | 000,000,000 | ---D | M] -- C:\Programme\Internet Explorer
[2010.10.29 15:52:02 | 000,000,000 | ---D | M] -- C:\Programme\iPod
[2010.10.29 15:53:41 | 000,000,000 | ---D | M] -- C:\Programme\iTunes
[2009.08.15 23:39:20 | 000,000,000 | ---D | M] -- C:\Programme\Java
[2009.11.12 20:27:49 | 000,000,000 | ---D | M] -- C:\Programme\K-Lite Codec Pack
[2011.04.15 15:11:19 | 000,000,000 | ---D | M] -- C:\Programme\Malwarebytes' Anti-Malware
[2009.04.13 18:10:27 | 000,000,000 | ---D | M] -- C:\Programme\Maxis
[2011.04.13 12:06:14 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft
[2010.01.07 21:50:55 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft Games
[2011.04.13 12:11:48 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft Office
[2011.03.03 04:21:51 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft Silverlight
[2009.11.24 17:16:22 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft SQL Server Compact Edition
[2009.11.24 17:18:27 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft Sync Framework
[2011.04.13 12:11:44 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft Works
[2011.04.13 12:11:48 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft.NET
[2010.08.13 19:38:07 | 000,000,000 | ---D | M] -- C:\Programme\Movie Maker
[2010.12.16 04:16:14 | 000,000,000 | ---D | M] -- C:\Programme\Movie Maker 2.6
[2009.09.27 11:25:48 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla ActiveX Control v1.7.12
[2011.03.24 10:54:47 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Programme\MSBuild
[2010.01.02 16:37:31 | 000,000,000 | ---D | M] -- C:\Programme\MSECache
[2009.01.19 23:07:22 | 000,000,000 | ---D | M] -- C:\Programme\MSXML 4.0
[2009.04.25 11:34:53 | 000,000,000 | ---D | M] -- C:\Programme\OpenOffice.org 3
[2010.10.29 12:11:45 | 000,000,000 | ---D | M] -- C:\Programme\QuickTime
[2009.12.06 21:43:34 | 000,000,000 | ---D | M] -- C:\Programme\Real
[2007.04.11 09:10:23 | 000,000,000 | ---D | M] -- C:\Programme\Realtek
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Programme\Reference Assemblies
[2009.11.04 23:51:16 | 000,000,000 | ---D | M] -- C:\Programme\Replay Media Catcher
[2009.02.20 20:16:50 | 000,000,000 | ---D | M] -- C:\Programme\SecretCity 3DChat
[2010.11.05 14:40:18 | 000,000,000 | ---D | M] -- C:\Programme\Sid Meier's Civilization V
[2009.01.21 16:55:16 | 000,000,000 | ---D | M] -- C:\Programme\SiteAdvisor
[2009.03.11 18:22:28 | 000,000,000 | ---D | M] -- C:\Programme\T-Online
[2009.11.13 18:08:29 | 000,000,000 | ---D | M] -- C:\Programme\Uniblue
[2006.11.02 15:01:55 | 000,000,000 | -H-D | M] -- C:\Programme\Uninstall Information
[2010.11.04 13:11:26 | 000,000,000 | ---D | M] -- C:\Programme\Vampire The Masquerade - Redemption
[2009.01.20 12:30:11 | 000,000,000 | ---D | M] -- C:\Programme\Veoh Networks
[2009.01.20 00:27:01 | 000,000,000 | ---D | M] -- C:\Programme\VideoLAN
[2011.04.06 22:58:38 | 000,000,000 | ---D | M] -- C:\Programme\VMLoad
[2009.01.20 16:02:24 | 000,000,000 | ---D | M] -- C:\Programme\vtplus
[2010.02.03 13:45:57 | 000,000,000 | ---D | M] -- C:\Programme\Winamp
[2009.11.10 21:04:26 | 000,000,000 | ---D | M] -- C:\Programme\Windows Calendar
[2009.11.10 21:04:23 | 000,000,000 | ---D | M] -- C:\Programme\Windows Collaboration
[2009.11.10 21:04:12 | 000,000,000 | ---D | M] -- C:\Programme\Windows Defender
[2009.11.10 21:04:23 | 000,000,000 | ---D | M] -- C:\Programme\Windows Journal
[2009.11.24 17:19:00 | 000,000,000 | ---D | M] -- C:\Programme\Windows Live
[2009.06.16 18:36:12 | 000,000,000 | ---D | M] -- C:\Programme\Windows Live SkyDrive
[2011.04.15 03:26:46 | 000,000,000 | ---D | M] -- C:\Programme\Windows Mail
[2010.10.15 18:51:56 | 000,000,000 | ---D | M] -- C:\Programme\Windows Media Player
[2009.01.19 22:06:56 | 000,000,000 | ---D | M] -- C:\Programme\Windows NT
[2009.11.10 21:04:19 | 000,000,000 | ---D | M] -- C:\Programme\Windows Photo Gallery
[2009.11.18 18:56:06 | 000,000,000 | ---D | M] -- C:\Programme\Windows Portable Devices
[2009.11.10 21:04:24 | 000,000,000 | ---D | M] -- C:\Programme\Windows Sidebar
[2009.01.20 12:44:14 | 000,000,000 | ---D | M] -- C:\Programme\WinRAR
[2009.09.30 14:13:24 | 000,000,000 | ---D | M] -- C:\Programme\WinTV
[2008.10.06 06:46:53 | 000,000,000 | ---D | M] -- C:\Programme\YUAN
< %LOCALAPPDATA%\*.exe >
< %systemroot%\*. /mp /s >
< C:\Users\Melissa\AppData\Roaming\Xois /S >
< C:\Users\Melissa\AppData\Roaming\Iwnevo /S >
< MD5 for: EXPLORER.EXE >
[2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008.10.29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008.10.30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008.10.28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008.01.21 04:24:24 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: USERINIT.EXE >
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
< MD5 for: WININIT.EXE >
[2008.01.21 04:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.21 04:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
< MD5 for: WINLOGON.EXE >
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 04:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-19 08:25:48
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:E36F5B57
@Alternate Data Stream - 48 bytes -> C:\Windows:857B1D3CE2BFC36F
< End of report > --- --- ---
GMER Logfile: Code:
GMER 1.0.15.15570 - hxxp://www.gmer.net
Rootkit scan 2011-04-19 20:00:44
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-7 WDC_WD3200AAJS-22B4A0 rev.01.03A01
Running: g2m3e4r.exe; Driver: C:\Users\Melissa\AppData\Local\Temp\pwtcauoc.sys
---- System - GMER 1.0.15 ----
SSDT 888D8ABC ZwCreateThread
SSDT 888D8AA8 ZwOpenProcess
SSDT 888D8AAD ZwOpenThread
SSDT 888D8AB7 ZwTerminateProcess
INT 0x51 ? 844C4BF8
INT 0x61 ? 844C4BF8
INT 0x62 ? 85E32F00
INT 0x72 ? 85E32F00
INT 0x82 ? 85E32F00
INT 0x92 ? 85E32F00
INT 0xB2 ? 844C4BF8
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 221 824C29A4 4 Bytes [BC, 8A, 8D, 88]
.text ntkrnlpa.exe!KeSetEvent + 3F1 824C2B74 4 Bytes [A8, 8A, 8D, 88]
.text ntkrnlpa.exe!KeSetEvent + 40D 824C2B90 4 Bytes [AD, 8A, 8D, 88]
.text ntkrnlpa.exe!KeSetEvent + 621 824C2DA4 4 Bytes [B7, 8A, 8D, 88]
? System32\Drivers\spmm.sys Das System kann den angegebenen Pfad nicht finden. !
.text USBPORT.SYS!DllUnload 8DB1141B 5 Bytes JMP 85E324E0
.text atsecl1w.SYS 8DB75000 22 Bytes [82, 73, 7D, 82, 6C, 72, 7D, ...]
.text atsecl1w.SYS 8DB75017 137 Bytes [00, 32, 97, B1, 82, 3D, 95, ...]
.text atsecl1w.SYS 8DB750A1 43 Bytes [F0, 4B, 82, 74, E6, 45, 82, ...]
.text atsecl1w.SYS 8DB750CE 10 Bytes [00, 00, 00, 00, 00, 00, 02, ...]
.text atsecl1w.SYS 8DB750DA 12 Bytes [00, 00, 02, 00, 00, 00, 24, ...]
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\Explorer.EXE[1576] SHELL32.dll!SHGetFolderPathAndSubDirW + 81C5 760BB37C 4 Bytes [50, 26, 00, 10] {PUSH EAX; ADD ES:[EAX], DL}
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 84E5A1F8
Device \FileSystem\fastfat \FatCdrom 87036500
Device \Driver\volmgr \Device\VolMgrControl 844C61F8
Device \Driver\netbt \Device\NetBT_Tcpip_{47A7ADE3-B642-4C17-9D29-3899857D60D3} 86C321F8
Device \Driver\usbohci \Device\USBPDO-0 85E7E1F8
Device \Driver\PCI_PNP1468 \Device\00000051 spmm.sys
Device \Driver\usbohci \Device\USBPDO-1 85E7E1F8
Device \Driver\usbohci \Device\USBPDO-2 85E7E1F8
Device \Driver\usbohci \Device\USBPDO-3 85E7E1F8
Device \Driver\netbt \Device\NetBT_Tcpip_{489A8CC2-652A-4F88-A6E8-FAF429845542} 86C321F8
Device \Driver\usbohci \Device\USBPDO-4 85E7E1F8
Device \Driver\usbehci \Device\USBPDO-5 85E7D1F8
Device \Driver\volmgr \Device\HarddiskVolume1 844C61F8
Device \Driver\volmgr \Device\HarddiskVolume2 844C61F8
Device \Driver\cdrom \Device\CdRom0 85E8F500
Device \Driver\atapi \Device\Ide\IdePort0 84E591F8
Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 84E591F8
Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort2 84E591F8
Device \Driver\atapi \Device\Ide\IdePort2 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort3 84E591F8
Device \Driver\atapi \Device\Ide\IdePort3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP2T1L0-3 84E591F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T1L0-3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-7 84E591F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-7 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\volmgr \Device\HarddiskVolume3 844C61F8
Device \Driver\cdrom \Device\CdRom1 85E8F500
Device \Driver\volmgr \Device\HarddiskVolume4 844C61F8
Device \Driver\volmgr \Device\HarddiskVolume5 844C61F8
Device \Driver\volmgr \Device\HarddiskVolume6 844C61F8
Device \Driver\USBSTOR \Device\00000069 85E2F1F8
Device \Driver\USBSTOR \Device\00000069 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\sptd \Device\2650615477 spmm.sys
Device \Driver\netbt \Device\NetBt_Wins_Export 86C321F8
Device \Driver\USBSTOR \Device\00000077 85E2F1F8
Device \Driver\USBSTOR \Device\00000077 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\USBSTOR \Device\00000078 85E2F1F8
Device \Driver\USBSTOR \Device\00000078 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\Smb \Device\NetbiosSmb 86CEC1F8
Device \Driver\netbt \Device\NetBT_Tcpip_{68B68306-FE2F-4B37-BC10-4ABC839E99FD} 86C321F8
Device \Driver\iScsiPrt \Device\RaidPort0 85F381F8
Device \Driver\USBSTOR \Device\0000006a 85E2F1F8
Device \Driver\USBSTOR \Device\0000006a sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\usbohci \Device\USBFDO-0 85E7E1F8
Device \Driver\usbohci \Device\USBFDO-1 85E7E1F8
Device \Driver\USBSTOR \Device\0000006e 85E2F1F8
Device \Driver\USBSTOR \Device\0000006e sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\usbohci \Device\USBFDO-2 85E7E1F8
Device \Driver\USBSTOR \Device\0000006f 85E2F1F8
Device \Driver\USBSTOR \Device\0000006f sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\usbohci \Device\USBFDO-3 85E7E1F8
Device \Driver\usbohci \Device\USBFDO-4 85E7E1F8
Device \Driver\usbehci \Device\USBFDO-5 85E7D1F8
Device \Driver\atsecl1w \Device\Scsi\atsecl1w1Port5Path0Target0Lun0 85F361F8
Device \Driver\atsecl1w \Device\Scsi\atsecl1w1Port5Path0Target0Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atsecl1w \Device\Scsi\atsecl1w1 85F361F8
Device \Driver\atsecl1w \Device\Scsi\atsecl1w1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \FileSystem\fastfat \Fat 87036500
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
Device \FileSystem\cdfs \Cdfs 86BE81F8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC9 0xEC 0x0A 0x2D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xF9 0xA7 0x70 0x12 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xEE 0xA5 0x84 0x6C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xE5 0x96 0xCF 0xD5 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x68 0x4B 0xD6 0x47 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x65 0xD4 0x37 0x8B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC9 0xEC 0x0A 0x2D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xF9 0xA7 0x70 0x12 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xEE 0xA5 0x84 0x6C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xE5 0x96 0xCF 0xD5 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x68 0x4B 0xD6 0x47 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x65 0xD4 0x37 0x8B ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update@OfflineDetectionPending 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E897DF62-4ADE-08CB-C801-BCB81C0CEA07}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E897DF62-4ADE-08CB-C801-BCB81C0CEA07}@hapjlkfbdnghfncc 0x6B 0x61 0x62 0x67 ...
---- EOF - GMER 1.0.15 ---- --- --- ---
Vielen lieben Dank,
Gruß
Shinichi |