Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Backdoor:Win32/Cbot.B - Trojan:Win32/FakeSysdef (https://www.trojaner-board.de/98501-backdoor-win32-cbot-b-trojan-win32-fakesysdef.html)

Basti7 30.04.2011 00:52

Backdoor:Win32/Cbot.B - Trojan:Win32/FakeSysdef
 
Guten Abend,

mein Computer hat sich leider mit dem oben genannten Virus infiziert, welcher mit Microsoft Security Essentials erstmals bei mir gefunden wurde. Die Symtome waren kritische Fehlermeldungen der Festplatte, automatische Neustarts, fehlende Dateien u.ä.. Danach habe ich Kaspersky Internet Security 2011 installiert und einmal die Vollständige Untersuchung durchlaufen lassen. Log-datei folgt:

Gelöscht (31)
23.04.2011 18:40:43 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd c:\documents and settings\basti\appdata\local\microsoft\windows\temporary internet files\content.ie5\k3ev2445\readme[1].exe Hoch
23.04.2011 18:40:43 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\Users\Basti\AppData\Local\Microsoft\Windows\TEMPORARY INTERNET FILES\Content.IE5\K3EV2445\README[1].EXE Hoch
23.04.2011 18:40:43 Gelöscht trojanisches Programm Trojan.Win32.Diple.mnw c:\documents and settings\basti\appdata\local\microsoft\windows\temporary internet files\content.ie5\wf8zvmaj\contacts[1].exe Hoch
23.04.2011 18:40:43 Gelöscht trojanisches Programm Trojan.Win32.Diple.mnw C:\Users\Basti\AppData\Local\Microsoft\Windows\TEMPORARY INTERNET FILES\Content.IE5\WF8ZVMAJ\CONTACTS[1].EXE Hoch
23.04.2011 16:14:42 Gelöscht trojanisches Programm Exploit.JS.Pdfka.dnv c:\documents and settings\basti\appdata\local\mozilla\firefox\profiles\la5trnmw.default\cache\0\a4\d5aa2d01 Hoch
23.04.2011 16:14:42 Gelöscht trojanisches Programm Exploit.JS.Pdfka.dnv c:\documents and settings\basti\appdata\local\mozilla\firefox\profiles\la5trnmw.default\cache\0\a4\d5aa2d01//data0003 Hoch
23.04.2011 14:53:12 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{845239EA-D759-43AF-71A3-2880CF516600}-readme[1].exe Hoch
23.04.2011 14:53:12 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{845239EA-D759-43AF-71A3-2880CF516600}-readme[1].exe//PE-Crypt.XorPE Hoch
23.04.2011 15:01:16 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{3CEEC6D0-5C04-542E-8197-7F0BB063B074}-readme[1].exe Hoch
23.04.2011 15:01:16 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{3CEEC6D0-5C04-542E-8197-7F0BB063B074}-readme[1].exe//PE-Crypt.XorPE Hoch
23.04.2011 15:12:19 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{AA81FB8F-53DB-F38A-D7C1-656D7393F22A}-readme[1].exe Hoch
23.04.2011 15:12:19 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{AA81FB8F-53DB-F38A-D7C1-656D7393F22A}-readme[1].exe//PE-Crypt.XorPE Hoch
23.04.2011 15:21:49 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{F706058F-0220-F4AD-4F36-A3863340334B}-readme[1].exe Hoch
23.04.2011 15:21:49 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{F706058F-0220-F4AD-4F36-A3863340334B}-readme[1].exe//PE-Crypt.XorPE Hoch
23.04.2011 15:32:35 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{C731EB9A-CF4C-9C08-78E5-892A56BD1A57}-readme[1].exe Hoch
23.04.2011 15:32:35 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{C731EB9A-CF4C-9C08-78E5-892A56BD1A57}-readme[1].exe//PE-Crypt.XorPE Hoch
23.04.2011 15:42:57 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{6D69A830-27A2-AF02-BF4A-EEF3925A8ABD}-readme[1].exe Hoch
23.04.2011 15:42:57 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{6D69A830-27A2-AF02-BF4A-EEF3925A8ABD}-readme[1].exe//PE-Crypt.XorPE Hoch
23.04.2011 15:54:21 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{A357CB58-3805-713D-DCD3-F65A261B2E63}-readme[1].exe Hoch
23.04.2011 15:54:21 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{A357CB58-3805-713D-DCD3-F65A261B2E63}-readme[1].exe//PE-Crypt.XorPE Hoch
23.04.2011 16:05:26 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{551660B8-E5B6-73C0-C48F-D03DDC7D48BB}-readme[1].exe Hoch
23.04.2011 16:05:26 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{551660B8-E5B6-73C0-C48F-D03DDC7D48BB}-readme[1].exe//PE-Crypt.XorPE Hoch
23.04.2011 18:40:43 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00D092C1_crypt_copy.tmp Hoch
23.04.2011 16:14:41 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{9FF91A4A-4152-522E-F825-CCE5C03BA3BD}-readme[1].exe Hoch
23.04.2011 16:14:41 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{9FF91A4A-4152-522E-F825-CCE5C03BA3BD}-readme[1].exe//PE-Crypt.XorPE Hoch
24.04.2011 04:57:42 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00DC7DEA_CRYPT_COPY.TMP Hoch
24.04.2011 04:57:42 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd c:\documents and settings\all users\kaspersky lab\avp11\temp\crypt\00dc7dea_crypt_copy.tmp Hoch
24.04.2011 04:48:01 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\Documents and Settings\All Users\Microsoft\Microsoft Antimalware\LocalCopy\{CD25C2EB-5D1D-8811-07A9-4AAAC8D2A477}-00D092C1_crypt_copy.tmp Hoch
24.04.2011 04:48:01 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd C:\Documents and Settings\All Users\Microsoft\Microsoft Antimalware\LocalCopy\{CD25C2EB-5D1D-8811-07A9-4AAAC8D2A477}-00D092C1_crypt_copy.tmp//PE-Crypt.XorPE Hoch
24.04.2011 05:52:33 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd c:\documents and settings\all users\microsoft\microsoft antimalware\localcopy\{e2aaa517-3f58-0f1c-f5c7-7c18fdba2d8b}-00dc7dea_crypt_copy.tmp Hoch
24.04.2011 05:52:33 Gelöscht trojanisches Programm Backdoor.Win32.Gbot.ahd c:\documents and settings\all users\microsoft\microsoft antimalware\localcopy\{e2aaa517-3f58-0f1c-f5c7-7c18fdba2d8b}-00dc7dea_crypt_copy.tmp//PE-Crypt.XorPE Hoch



Danach hatte ich allerdings immernoch kein Zugriff auf meine Dateien auf der Festplatte. Sie zeigt an 2,2 Gb Speicherplatz frei von 250 Gb, aber die Dateiordner sind leer.

Also hab ich noch den CCleaner laufen lassen , mit wenig Erfolg, und heute abend noch Malewarebytes`Anti-Malware ( Quickscan). Logdatei folgt:


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6475

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

29.04.2011 23:09:20
mbam-log-2011-04-29 (23-09-20).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 152188
Laufzeit: 9 Minute(n), 7 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 1
Infizierte Dateien: 3

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell.Gen) -> Value: Shell -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
c:\Users\Basti\AppData\Roaming\microsoft\Windows\start menu\Programs\windows recovery (Trojan.FakeAV) -> Quarantined and deleted successfully.

Infizierte Dateien:
c:\Users\Basti\Desktop\windows recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
c:\Users\Basti\AppData\Roaming\microsoft\Windows\start menu\Programs\windows recovery\uninstall windows recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
c:\Users\Basti\AppData\Roaming\microsoft\Windows\start menu\Programs\windows recovery\windows recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.



Nun weiß ich nicht weiter, denn nach dem Neustart, habe ich noch immer kein Zugriff mehr auf Dateien auf der Festplatte. Ich wäre sehr dankbar für Hilfe.

cosinus 30.04.2011 04:20

Hallo und :hallo:

Bitte routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!

Danach OTL:

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.

Basti7 30.04.2011 13:59

Hallo ,

keine älteren logs von Malwarebytes, da die oben gepostete die erste war

ok hier die erste OTL logfile:OTL Logfile:
Code:

OTL logfile created on: 30.04.2011 14:41:24 - Run 1
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\Basti\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 53,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 76,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 224,04 Gb Total Space | 0,63 Gb Free Space | 0,28% Space Free | Partition Type: NTFS
Drive D: | 8,84 Gb Total Space | 0,90 Gb Free Space | 10,21% Space Free | Partition Type: NTFS
 
Computer Name: BASTI-PC | User Name: Basti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Basti\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Programme\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
PRC - c:\Programme\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\stacsv.exe (IDT, Inc.)
PRC - C:\Programme\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\WINDOWS\SMINST\BLService.exe ()
PRC - C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Basti\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (NisSrv) -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (AVP) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
SRV - (STacSV) -- C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\stacsv.exe (IDT, Inc.)
SRV - (Recovery Service for Windows) -- C:\WINDOWS\SMINST\BLService.exe ()
SRV - (AESTFilters) -- C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (ezSharedSvc) -- C:\WINDOWS\System32\ezsvc7.dll (EasyBits Sofware AS)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (MpKsl0a3149b9) -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{864ABE7B-DD99-49CF-9BC2-F985DDC9BD91}\MpKsl0a3149b9.sys (Microsoft Corporation)
DRV - (KLIF) -- C:\WINDOWS\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (NisDrv) -- C:\WINDOWS\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) -- C:\WINDOWS\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (kl2) -- C:\WINDOWS\System32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (KL1) -- C:\Windows\system32\DRIVERS\kl1.sys (Kaspersky Lab ZAO)
DRV - (jumi) -- C:\WINDOWS\System32\drivers\jumi.sys (Windows (R) Win 7 DDK provider)
DRV - (KLIM6) -- C:\WINDOWS\System32\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV - (klmouflt) -- C:\WINDOWS\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (atikmdag) -- C:\WINDOWS\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (nmwcdc) -- C:\WINDOWS\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (upperdev) -- C:\WINDOWS\System32\drivers\usbser_lowerflt.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (nmwcd) -- C:\WINDOWS\System32\drivers\ccdcmb.sys (Nokia)
DRV - (AtiPcie) ATI PCI Express (3GIO) -- C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV - (athr) -- C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (STHDA) -- C:\WINDOWS\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (JMCR) -- C:\WINDOWS\System32\drivers\jmcr.sys (JMicron Technology Corp.)
DRV - (hpdskflt) -- C:\Windows\system32\DRIVERS\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (Accelerometer) -- C:\WINDOWS\System32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (RTL8169) -- C:\WINDOWS\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (enecir) -- C:\WINDOWS\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV - (nmwcdcj) -- C:\WINDOWS\System32\drivers\nmwcdcj.sys (Nokia)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (NVENETFD) -- C:\WINDOWS\System32\drivers\nvm60x32.sys (NVIDIA Corporation)
DRV - (M9207) -- C:\WINDOWS\System32\drivers\M9207BDA.sys (Animation Technologies Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = HP | MSN
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = HP | MSN
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = HP | MSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = HP | MSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} -  File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:63354
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://de.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {2f17f610-5e97-4fed-828f-9940b7b577a4}:1.6.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 63354
FF - prefs.js..network.proxy.type: 4
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "chrome://browser-region/locale/region.properties"
 
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.04.08 01:50:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.04.08 01:50:19 | 000,000,000 | ---D | M]
 
[2010.05.05 00:04:43 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Basti\AppData\Roaming\mozilla\Extensions
[2011.04.08 22:17:36 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions
[2010.12.11 22:57:51 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.12.11 22:57:51 | 000,000,000 | -H-D | M] (TV-Fox) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{2f17f610-5e97-4fed-828f-9940b7b577a4}
[2011.04.08 01:50:35 | 000,000,000 | -H-D | M] (Yahoo! Toolbar) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.04.08 22:17:36 | 000,000,000 | -H-D | M] (Zynga Community Toolbar) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010.11.18 20:04:53 | 000,000,000 | -H-D | M] ("DVDVideoSoft Menu") -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.08.18 00:16:29 | 000,003,915 | -H-- | M] () -- C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\la5trnmw.default\searchplugins\sweetim.xml
[2011.04.23 13:16:57 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.05.06 03:00:51 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.09.21 13:06:38 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.10.23 22:41:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010.12.21 15:53:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.02.22 18:31:21 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.04.23 13:16:57 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru
[2011.04.23 13:16:51 | 000,000,000 | ---D | M] (Modul zur Link-Untersuchung) -- C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
[2011.04.08 01:50:21 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\distribution\extensions
[2011.04.08 01:50:21 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Programme\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
File not found (No name found) --
[2010.05.06 03:00:51 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.09.21 13:06:38 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.10.23 22:41:59 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010.12.21 15:53:45 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.02.22 18:31:21 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\BASTI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LA5TRNMW.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}.XPI
[2010.01.01 10:00:00 | 000,135,168 | ---- | M] (Mozilla Foundation) -- C:\Programme\Mozilla Firefox\components\browsercomps.dll
[2011.02.02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (AOL Toolbar BHO) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Programme\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O8 - Extra context menu item: &AOL Toolbar-Suche - C:\ProgramData\AOL\ieToolbar\resources\de-DE\local\search.html ()
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Basti\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm ()
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\mzvkbd3.dll (Kaspersky Lab ZAO)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\kloehk.dll (Kaspersky Lab ZAO)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\Windows\system32\klogon.dll - C:\WINDOWS\System32\klogon.dll (Kaspersky Lab ZAO)
O24 - Desktop WallPaper: C:\Users\Basti\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Basti\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{fa6320cf-676c-11e0-8804-001eec82335e}\Shell - "" = AutoRun
O33 - MountPoints2\{fa6320cf-676c-11e0-8804-001eec82335e}\Shell\AutoRun\command - "" = F:\laucher.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.04.29 22:56:05 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Roaming\Malwarebytes
[2011.04.29 22:55:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.04.29 22:55:54 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.04.29 22:55:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.04.29 22:55:48 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.04.29 22:55:47 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.04.29 03:01:34 | 000,000,000 | ---D | C] -- C:\864b01153e3fdf37d2b00c296bc673
[2011.04.28 16:44:32 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2011.04.28 16:44:31 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2011.04.28 01:46:20 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011.04.28 01:03:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.04.28 01:03:04 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2011.04.27 18:58:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autorun Angel
[2011.04.27 18:58:39 | 000,000,000 | ---D | C] -- C:\Programme\Autorun Angel
[2011.04.27 18:33:25 | 000,000,000 | ---D | C] -- C:\Users\Basti\Desktop\Neuer Ordner (5)
[2011.04.25 20:05:18 | 000,000,000 | ---D | C] -- C:\Users\Basti\Desktop\druck 2
[2011.04.25 20:02:59 | 000,000,000 | ---D | C] -- C:\Users\Basti\Desktop\Druck
[2011.04.25 00:47:29 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\Hewlett-Packard
[2011.04.23 13:16:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2011
[2011.04.23 13:12:11 | 000,000,000 | ---D | C] -- C:\Programme\Kaspersky Lab
[2011.04.23 13:12:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2011.04.23 13:11:27 | 000,488,536 | ---- | C] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys
[2011.04.23 04:51:40 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Security Client
[2011.04.22 19:11:58 | 000,000,000 | -H-D | C] -- C:\ProgramData\Kaspersky Lab Setup Files
[2011.04.15 16:35:26 | 000,000,000 | -H-D | C] -- C:\Users\Basti\Desktop\wildhagen
[2011.04.14 19:59:26 | 000,292,864 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2011.04.14 19:59:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2011.04.14 19:59:20 | 001,161,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
[2011.04.14 19:59:20 | 001,136,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
[2011.04.14 19:58:51 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
[2011.04.14 19:58:34 | 000,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2011.04.14 19:58:34 | 000,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2011.04.14 19:58:33 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011.04.14 19:58:33 | 000,389,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2011.04.14 19:58:32 | 000,467,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011.04.14 19:58:32 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011.04.14 19:58:32 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll
[2011.04.14 19:58:32 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011.04.14 19:58:31 | 001,383,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.04.14 19:58:31 | 000,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2011.04.14 19:58:25 | 002,040,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.04.14 19:58:21 | 000,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2011.04.14 19:58:20 | 000,512,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011.04.12 15:02:01 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2011.04.11 19:58:49 | 000,000,000 | -H-D | C] -- C:\Users\Basti\Desktop\mitchfilme
 
========== Files - Modified Within 30 Days ==========
 
[2011.04.30 14:28:41 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{4AD6CB10-A3E1-46A1-808C-09598B52C3FE}.job
[2011.04.30 14:23:46 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.04.30 14:23:39 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.04.30 14:23:38 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.04.30 14:23:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.04.30 14:23:12 | 3218,956,288 | -HS- | M] () -- C:\hiberfil.sys
[2011.04.30 03:45:11 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011.04.30 03:23:05 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.04.28 01:20:32 | 000,321,648 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.04.28 01:12:03 | 000,227,880 | ---- | M] () -- C:\Users\Basti\Documents\cc_20110428_011136.reg
[2011.04.28 01:03:06 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.04.25 21:13:22 | 003,778,334 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.04.25 21:13:21 | 003,159,740 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.04.25 21:13:20 | 010,855,478 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.04.25 21:13:19 | 003,511,250 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.04.23 13:59:11 | 000,115,267 | ---- | M] () -- C:\Windows\System32\drivers\klin.dat
[2011.04.23 13:59:11 | 000,097,859 | ---- | M] () -- C:\Windows\System32\drivers\klick.dat
[2011.04.23 13:43:30 | 000,002,461 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011.04.23 13:42:50 | 000,002,413 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.04.23 13:11:27 | 000,488,536 | ---- | M] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys
[2011.04.23 04:57:23 | 000,000,136 | -H-- | M] () -- C:\ProgramData\~38788872r
[2011.04.23 04:57:23 | 000,000,120 | -H-- | M] () -- C:\ProgramData\~38788872
[2011.04.23 04:53:51 | 000,002,154 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011.04.23 01:45:14 | 000,000,392 | -H-- | M] () -- C:\ProgramData\38788872
[2011.04.22 17:07:24 | 000,000,400 | -H-- | M] () -- C:\ProgramData\32694024
[2011.04.18 21:08:45 | 000,076,800 | -H-- | M] () -- C:\Users\Basti\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.08 01:50:24 | 000,000,846 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
 
========== Files Created - No Company Name ==========
 
[2011.04.28 01:11:42 | 000,227,880 | ---- | C] () -- C:\Users\Basti\Documents\cc_20110428_011136.reg
[2011.04.28 01:03:06 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.04.23 13:16:30 | 000,115,267 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2011.04.23 13:16:30 | 000,097,859 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2011.04.23 04:53:51 | 000,002,154 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011.04.23 04:51:54 | 000,001,808 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011.04.23 04:39:06 | 000,000,136 | -H-- | C] () -- C:\ProgramData\~38788872r
[2011.04.23 04:39:06 | 000,000,120 | -H-- | C] () -- C:\ProgramData\~38788872
[2011.04.23 01:43:04 | 000,000,392 | -H-- | C] () -- C:\ProgramData\38788872
[2011.04.22 17:04:00 | 000,000,400 | -H-- | C] () -- C:\ProgramData\32694024
[2011.04.08 01:50:24 | 000,000,858 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011.03.24 01:04:04 | 000,003,036 | -H-- | C] () -- C:\Users\Basti\AppData\Roaming\FA10.BAD
[2010.12.15 01:08:11 | 000,000,032 | -H-- | C] () -- C:\ProgramData\ezsid.dat
[2010.06.19 22:58:57 | 000,006,944 | -H-- | C] () -- C:\Users\Basti\AppData\Local\d3d9caps.dat
[2010.05.13 01:00:54 | 000,000,048 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.05.06 01:29:33 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010.05.06 01:29:33 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010.05.05 00:29:31 | 000,076,800 | -H-- | C] () -- C:\Users\Basti\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.04 22:32:18 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.05.04 22:23:36 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2009.09.09 18:01:40 | 000,027,675 | ---- | C] () -- C:\Windows\System32\drivers\klopp.dat
[2008.06.13 14:22:34 | 010,855,478 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008.06.13 14:22:34 | 003,511,250 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008.06.13 14:22:34 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008.06.13 14:22:34 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2008.06.13 06:26:13 | 000,000,428 | ---- | C] () -- C:\Windows\System32\ezdigsgn.dat
[2008.06.13 04:37:30 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2008.05.09 00:14:22 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008.05.08 23:44:14 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2008.03.06 12:40:54 | 000,168,883 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2008.03.04 21:02:00 | 000,090,112 | ---- | C] () -- C:\Windows\System32\atibrtmon.exe
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,321,648 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 003,778,334 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 003,159,740 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2001.11.14 12:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll

< End of report >

--- --- ---


die 2. :OTL Logfile:
Code:

OTL Extras logfile created on: 30.04.2011 14:41:24 - Run 1
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\Basti\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 53,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 76,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 224,04 Gb Total Space | 0,63 Gb Free Space | 0,28% Space Free | Partition Type: NTFS
Drive D: | 8,84 Gb Total Space | 0,90 Gb Free Space | 10,21% Space Free | Partition Type: NTFS
 
Computer Name: BASTI-PC | User Name: Basti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{390FDDFF-EF67-4737-B8E0-EA459D10D674}" = lport=1900 | protocol=17 | dir=in | name=upnp udp |
"{47CF0B76-29E5-4098-9D49-AB7AD760EF8B}" = lport=2869 | protocol=6 | dir=in | name=upnp tcp |
"{70394606-052D-4445-A0E2-504EA9BE6773}" = lport=5720 | protocol=6 | dir=in | name=jumi controller |
"{93AFF6C4-7149-491A-A96A-5220A9CCDBC6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D57F8FA2-CDB0-4CFC-88C5-64F2C9148370}" = lport=5720 | protocol=17 | dir=in | name=jumi controller |
"{F8C2C574-D99D-430F-A375-48383F42C869}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00386B0E-E60B-4763-85C3-6AE8E24046CD}" = protocol=6 | dir=in | app=c:\program files\icq7.1\aolload.exe |
"{0067DAF3-1C01-4C8B-94AF-549DB32C87B6}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{1857EA28-CE2F-4F8F-9729-935A0A548933}" = protocol=17 | dir=in | app=c:\program files\icq7.1\aolload.exe |
"{1C22899A-2084-4C77-A338-4E40104960FB}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{22B407AF-FF1B-456B-AD45-253CA2A7BA65}" = protocol=6 | dir=in | app=c:\program files\icq7.1\icq.exe |
"{24CAD22B-55BF-4F23-9C68-C5C415011A99}" = protocol=6 | dir=in | app=c:\program files\icq7.1\icq.exe |
"{4195F7A7-E32A-41A2-B62F-ACE256EB86AA}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{4B7D9142-CAD8-4805-B133-6F37A4696303}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{535352B5-A1CD-4492-B05C-D4EE5E0B66D3}" = protocol=6 | dir=in | app=c:\program files\icq7.1\aolload.exe |
"{5CC5A98B-5871-4539-AB5E-0F1059C56772}" = protocol=6 | dir=in | app=c:\program files\icq7.1\aolload.exe |
"{5EE8A8EC-8224-456E-A5E6-46CFAF788E1A}" = protocol=6 | dir=in | app=c:\program files\icq7.1\icq.exe |
"{682182BE-F3E2-49A2-A51F-0AAC2ACE24EF}" = protocol=17 | dir=in | app=c:\program files\icq7.1\icq.exe |
"{6DA91C7E-DDE1-4AA9-ADDF-F7C4E2489EC8}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7D8735E9-3030-4A72-AE05-3817D9C73D5C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{84D36AB3-DE1F-4E94-A6E2-B31020CA3A9E}" = protocol=17 | dir=in | app=c:\program files\icq7.1\aolload.exe |
"{885F55C5-03ED-4D6F-9F22-2279879BFFCA}" = protocol=6 | dir=in | app=c:\users\basti\downloads\sweetimsetup.exe |
"{92FF157B-E949-4E6D-90FF-19ABC57931B5}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{9448A383-4532-4490-B01C-FC00C41A4EB0}" = protocol=17 | dir=in | app=c:\users\basti\downloads\sweetimsetup.exe |
"{9B0E36E0-F4B1-46C0-B609-617B5FDCD92F}" = protocol=17 | dir=in | app=c:\program files\icq7.1\icq.exe |
"{BA39CC57-A502-4CB5-9224-E413A2392940}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{C1883AA0-0674-4BBE-A38E-AAAAC4DECEC8}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{D09209F8-5421-4BC5-994E-E26B14BB3D7C}" = protocol=17 | dir=in | app=c:\program files\icq7.1\aolload.exe |
"{DF8986D1-8419-4A41-9E61-BEB4361E19CF}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{ED304D21-5BFF-4B46-A306-2975CABDED9E}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{F18B79DF-A2D0-4C75-85F4-7D3288392A6C}" = protocol=17 | dir=in | app=c:\program files\icq7.1\icq.exe |
"TCP Query User{3FCB5B01-5ECF-409E-90CF-A6712E4234DB}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{59755C47-70D7-4654-BA3F-C433320287B0}C:\program files\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{828A9AA7-9118-4AB9-9E30-F75FE60C5743}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{17E23771-08DB-4BCB-B8BF-B4AE0E4819B6}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{753EB430-636F-45B7-9637-25B88B1749E5}C:\program files\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe |
"UDP Query User{7777D222-58AC-4DBB-B91C-9716644BC673}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01B10898-0693-5E45-8C0B-CB4B0C2CB5C9}" = CCC Help Spanish
"{01E71682-7A62-31B6-2E19-82C4C2C410C3}" = CCC Help Korean
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.6200
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{05F5ADF7-B9BF-E5AC-FDA4-C412C150763F}" = Catalyst Control Center Localization Greek
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0892BA56-B55A-EA45-74A7-C728BEFCEE4A}" = Catalyst Control Center Localization Norwegian
"{0BCE001B-D952-7242-1378-6B3188B7CDB6}" = Catalyst Control Center Localization Swedish
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{111CE1DA-F2B6-B449-8BDC-BFA807EEF343}" = Catalyst Control Center Localization Thai
"{1550A772-F3DF-9DCA-70E4-5BA5FEDBDDEE}" = CCC Help Norwegian
"{1B835521-00CB-B242-2072-DA41AE7E9F11}" = CCC Help Turkish
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{210F3CE3-C716-416C-99AE-7151A0968BF2}_is1" = Autorun Angel 1.0.30
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{246771C5-5589-C809-90A3-95D380CAEB0C}" = CCC Help Dutch
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216020F0}" = Java(TM) 6 Update 20
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 24
"{279DB581-239C-4E13-97F8-0F48E40BE75C}" = Windows Live Messenger
"{2ACA4FB1-A1DB-BACF-05D8-9F654ED1F6F9}" = CCC Help Danish
"{30DAA715-5032-40F9-A0AE-95C9AEBB3E3F}" = HP QuickTouch 1.00 D2
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{335901DF-7FC7-76E9-AEFB-3BD15D5C1B8E}" = Catalyst Control Center Localization German
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 D3
"{37F36B08-76D1-58D0-0B62-C873B3F1E04A}" = Catalyst Control Center Graphics Full Existing
"{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{3FA93E4C-CB3B-4B25-B091-9DB0FCC56A74}" = Catalyst Control Center - Branding
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{43519E32-0AC9-ACBF-0AC9-000CEDEBCAFB}" = CCC Help Russian
"{440EE84D-A37A-E283-D538-0A4E94AC6243}" = Catalyst Control Center Localization Dutch
"{456B2B42-C082-8B6F-923C-2C8920ECF559}" = Catalyst Control Center Localization Czech
"{48382386-BA53-3B91-668C-DE3F4969C00C}" = ccc-core-static
"{49521D72-2856-C7B9-F54E-26B116606B0D}" = Catalyst Control Center Localization Hungarian
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50C5DCCD-C82F-3D45-AAC8-1E094717FF9B}" = CCC Help Czech
"{51E5C397-0AA0-48DD-9CB6-7259AFFDFB0A}" = HP Easy Setup - Frontend
"{54F98E59-AC27-F6D6-8DF3-29E38BB1AFF9}" = Catalyst Control Center Localization Korean
"{57921C23-454B-1B45-6C32-B1A8BFC76875}" = Catalyst Control Center Localization French
"{582287DA-0806-4AC0-BF19-C15E3A466034}" = LightScribe System Software  1.12.33.2
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{5C9B4046-4B37-3595-7BAF-1FFF58F2BA88}" = Catalyst Control Center Core Implementation
"{61C2601F-D1F4-6CC3-858B-80A54A1C1360}" = CCC Help Greek
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6E25BE3B-8E16-3A78-2BA7-1482A2D4743F}" = CCC Help English
"{6F26A541-E756-4C24-A36B-EFD3C6217EAF}" = CCC Help German
"{71BFC818-0CED-42D6-9C87-5142918957EE}" = ICQ7.1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7491471D-DA69-6E11-623D-F3BCAF65F922}" = CCC Help Italian
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{7782916E-3D46-4F1F-AC4B-3FB9D17049F4}" = Microsoft Antimalware Service DE-DE Language Pack
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{789EC9D6-5A0D-3CCA-957D-D0523BDE1638}" = ATI Catalyst Install Manager
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{7F82D79D-81EF-DC6C-69FF-A45C282B1986}" = CCC Help Swedish
"{81ACE059-6894-21DE-E3AB-E8D6AF38B5C4}" = Catalyst Control Center Localization Portuguese
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{8572742E-08EA-FCEF-458A-4CE90851E804}" = Catalyst Control Center Localization Russian
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{859B9BCA-5376-4566-9F88-C6C9DAA7A925}" = Microsoft Security Client DE-DE Language Pack
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista
"{8D8ABD26-50FA-2D1B-2B3D-72DEF1E800D0}" = ccc-utility
"{8F0CFF10-034C-EE7E-3B2D-8C7F117BB3A6}" = Catalyst Control Center Localization Finnish
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9075DF27-7C34-D2D5-4E66-970E0E99E320}" = Catalyst Control Center Graphics Light
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{9858B284-0ACC-3EB1-BBF7-B0D1A5D0C2FD}" = CCC Help Japanese
"{9A85A260-CC99-8DA9-0D03-60C12BE82189}" = CCC Help Polish
"{9D6C29FF-850B-9425-7B34-B21526874121}" = Catalyst Control Center Graphics Previews Vista
"{9E2CCD5E-1990-4EF2-9B61-32F0BBACC29B}" = HP Active Support Library
"{9EBF6795-816C-06EB-BF29-06317FD5A730}" = Catalyst Control Center Localization Chinese Standard
"{9F2D3FB4-895E-A9F2-5B3A-118EDCE4E409}" = CCC Help Chinese Traditional
"{A2F6EEA0-DBCD-2389-BA8D-9A16DB60FAD8}" = Catalyst Control Center Graphics Full New
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5CE7175-080D-49AC-B5A3-E7E3502428F5}" = HP Wireless Assistant
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5737DB-03C3-1526-F31E-D45A588D8459}" = Catalyst Control Center Localization Japanese
"{ADBFC909-D682-10E2-43C6-790F25FA3296}" = CCC Help Finnish
"{B16DA0F8-26BC-4FFC-9363-1D9F3E6C3E21}" = HP Customer Experience Enhancements
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B5DA1D7B-9494-A847-F185-EE4B8C48D905}" = CCC Help Hungarian
"{B8169E45-8E23-430B-91D1-EC64540C8ED0}" = HP User Guides 0103
"{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver
"{BD2CC796-A584-9399-098A-2C2F291ABD1A}" = Catalyst Control Center Localization Spanish
"{C05A2E05-73A2-2672-7B82-59F3932AF6AD}" = CCC Help Thai
"{C1C9D5E7-761D-817F-DBF2-1E77E20121BB}" = CCC Help Portuguese
"{C39B346D-1E0D-CB23-CAC5-78CD5CBB495A}" = Catalyst Control Center Localization Italian
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C5E794F3-2EAC-CA94-79ED-1E3E3267F40B}" = CCC Help Chinese Standard
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{C9690E1F-06A0-559B-37D2-B573DA95CA54}" = Catalyst Control Center Localization Danish
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB71A20E-B1B4-4562-81FA-33E1DBD0342F}" = ProtectSmart Hard Drive Protection
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF217146-C889-3CB8-1490-07DA0DDB1318}" = CCC Help French
"{D68147A7-E42F-DA4B-209A-38CCC53702EC}" = Catalyst Control Center Localization Chinese Traditional
"{DFFC0648-BC4B-47D1-93D2-6CA6B9457641}" = OpenOffice.org 3.2
"{E333CA5F-00ED-4EEF-90E5-6A33A8FE969F}" = HP Help and Support
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F7D7E6EA-2B25-ABB1-0F4A-F39764C2D15B}" = Skins
"{FAF0230B-8A11-8052-AFC9-5DB998020FD5}" = Catalyst Control Center Localization Polish
"{FC7C3B82-C7CB-125A-23FE-EE268799F5E3}" = Catalyst Control Center Localization Turkish
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AIM_6" = AIM
"AOL Toolbar" = AOL Toolbar 5.0
"CCleaner" = CCleaner
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 4.0 (x86 de)" = Mozilla Firefox 4.0 (x86 de)
"PokerStars" = PokerStars
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Uninstall_is1" = Uninstall 1.0.0.1
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.0.5
"WildTangent hp Master Uninstall" = My HP Games
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 23.04.2011 23:24:21 | Computer Name = Basti-PC | Source = LoadPerf | ID = 3012
Description =
 
Error - 23.04.2011 23:24:21 | Computer Name = Basti-PC | Source = LoadPerf | ID = 3011
Description =
 
Error - 24.04.2011 01:27:30 | Computer Name = Basti-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 24.04.2011 01:33:46 | Computer Name = Basti-PC | Source = LoadPerf | ID = 3012
Description =
 
Error - 24.04.2011 01:33:47 | Computer Name = Basti-PC | Source = LoadPerf | ID = 3012
Description =
 
Error - 24.04.2011 01:33:47 | Computer Name = Basti-PC | Source = LoadPerf | ID = 3011
Description =
 
Error - 24.04.2011 11:10:47 | Computer Name = Basti-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 24.04.2011 11:18:06 | Computer Name = Basti-PC | Source = LoadPerf | ID = 3012
Description =
 
Error - 24.04.2011 11:18:06 | Computer Name = Basti-PC | Source = LoadPerf | ID = 3012
Description =
 
Error - 24.04.2011 11:18:06 | Computer Name = Basti-PC | Source = LoadPerf | ID = 3011
Description =
 
[ Media Center Events ]
Error - 09.05.2010 17:16:54 | Computer Name = Basti-PC | Source = ehRecvr | ID = 3
Description =
 
Error - 09.05.2010 17:17:12 | Computer Name = Basti-PC | Source = ehRecvr | ID = 3
Description =
 
Error - 09.05.2010 17:17:13 | Computer Name = Basti-PC | Source = ehRecvr | ID = 3
Description =
 
Error - 13.02.2011 18:34:27 | Computer Name = Basti-PC | Source = ehRecvr | ID = 3
Description =
 
Error - 13.02.2011 18:34:42 | Computer Name = Basti-PC | Source = ehRecvr | ID = 4
Description =
 
[ System Events ]
Error - 29.04.2011 06:52:39 | Computer Name = Basti-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 29.04.2011 16:07:38 | Computer Name = Basti-PC | Source = HTTP | ID = 15016
Description =
 
Error - 29.04.2011 16:08:11 | Computer Name = Basti-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 29.04.2011 17:00:33 | Computer Name = Basti-PC | Source = VDS Dynamic Provider | ID = 16908298
Description =
 
Error - 29.04.2011 17:11:57 | Computer Name = Basti-PC | Source = HTTP | ID = 15016
Description =
 
Error - 29.04.2011 17:12:59 | Computer Name = Basti-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 29.04.2011 17:14:50 | Computer Name = Basti-PC | Source = Microsoft Antimalware | ID = 3002
Description = Fehler in %%860-Echtzeitschutzfunktion.    Funktion: %%835    Fehlercode:
0x80004005    Fehlerbeschreibung: Unbekannter Fehler      Ursache: %%842
 
Error - 30.04.2011 08:23:36 | Computer Name = Basti-PC | Source = HTTP | ID = 15016
Description =
 
Error - 30.04.2011 08:24:49 | Computer Name = Basti-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 30.04.2011 08:26:49 | Computer Name = Basti-PC | Source = VDS Dynamic Provider | ID = 16908298
Description =
 
 
< End of report >

--- --- ---

Basti7 30.04.2011 19:34

Seitdem ich gerade neu startete, befinden sich die Ordner und Dateien wieder auf dem Desktop und der Festplatte, allerdings sind alle, bei den Eigenschaften, auf versteckt eingestellt. Außerdem sind jetz auf der Festplatte etliche neue Ordner zu finden, auf die ich keinen Zugriff habe. :confused:

Basti7 30.04.2011 23:26

Datenbank Version: 6480

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

01.05.2011 00:22:21
mbam-log-2011-05-01 (00-22-21).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Durchsuchte Objekte: 337871
Laufzeit: 2 Stunde(n), 19 Minute(n), 2 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)



noch die letzte logdatei des Vollscans mit Malwarebytes.

cosinus 01.05.2011 14:22

Sagmal läuft bei dir Kaspersky IS und Microsoft Security Essentials gleichzeitig?! Sowas macht man nicht! Man sollte nur eins dieser beiden Programme installiert haben! Da ich von Suites grundsätzlich abrate, würde ich dir empfehlen Kaspersky IS zu deinstallieren! mach das und danch bitte frische OTL-Logs auf diese Art:

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Basti7 01.05.2011 17:04

Kaspersky deinstalliert, danke für den Hinweis.

hier der OTL.TxtOTL Logfile:
Code:

OTL logfile created on: 01.05.2011 17:29:32 - Run 2
OTL by OldTimer - Version 3.2.22.3    Folder = c:\Users\Basti\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 66,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 84,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 224,04 Gb Total Space | 1,52 Gb Free Space | 0,68% Space Free | Partition Type: NTFS
Drive D: | 8,84 Gb Total Space | 0,90 Gb Free Space | 10,21% Space Free | Partition Type: NTFS
 
Computer Name: BASTI-PC | User Name: Basti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - c:\Users\Basti\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Programme\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
PRC - c:\Programme\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\stacsv.exe (IDT, Inc.)
PRC - C:\Programme\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\WINDOWS\SMINST\BLService.exe ()
PRC - C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
 
 
========== Modules (SafeList) ==========
 
MOD - c:\Users\Basti\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (NisSrv) -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (WinHttpAutoProxySvc) -- winhttp.dll (Microsoft Corporation)
SRV - (STacSV) -- C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\stacsv.exe (IDT, Inc.)
SRV - (Recovery Service for Windows) -- C:\WINDOWS\SMINST\BLService.exe ()
SRV - (AESTFilters) -- C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (ezSharedSvc) -- C:\WINDOWS\System32\ezsvc7.dll (EasyBits Sofware AS)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (MpKsle9fcf5a7) -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D6D0CB9E-5D18-428D-BFBB-395754A19FC4}\MpKsle9fcf5a7.sys (Microsoft Corporation)
DRV - (NisDrv) -- C:\WINDOWS\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) -- C:\WINDOWS\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (jumi) -- C:\WINDOWS\System32\drivers\jumi.sys (Windows (R) Win 7 DDK provider)
DRV - (atikmdag) -- C:\WINDOWS\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (nmwcdc) -- C:\WINDOWS\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (upperdev) -- C:\WINDOWS\System32\drivers\usbser_lowerflt.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (nmwcd) -- C:\WINDOWS\System32\drivers\ccdcmb.sys (Nokia)
DRV - (AtiPcie) ATI PCI Express (3GIO) -- C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV - (athr) -- C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (STHDA) -- C:\WINDOWS\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (JMCR) -- C:\WINDOWS\System32\drivers\jmcr.sys (JMicron Technology Corp.)
DRV - (hpdskflt) -- C:\Windows\system32\DRIVERS\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (Accelerometer) -- C:\WINDOWS\System32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (RTL8169) -- C:\WINDOWS\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (enecir) -- C:\WINDOWS\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV - (nmwcdcj) -- C:\WINDOWS\System32\drivers\nmwcdcj.sys (Nokia)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (NVENETFD) -- C:\WINDOWS\System32\drivers\nvm60x32.sys (NVIDIA Corporation)
DRV - (M9207) -- C:\WINDOWS\System32\drivers\M9207BDA.sys (Animation Technologies Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = HP | MSN
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = HP | MSN
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = HP | MSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = HP | MSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} -  File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:63354
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://de.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {2f17f610-5e97-4fed-828f-9940b7b577a4}:1.6.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 63354
FF - prefs.js..network.proxy.type: 4
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "chrome://browser-region/locale/region.properties"
 
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.04.08 01:50:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.04.08 01:50:19 | 000,000,000 | ---D | M]
 
[2010.05.05 00:04:43 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Basti\AppData\Roaming\mozilla\Extensions
[2011.04.08 22:17:36 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions
[2010.12.11 22:57:51 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.12.11 22:57:51 | 000,000,000 | -H-D | M] (TV-Fox) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{2f17f610-5e97-4fed-828f-9940b7b577a4}
[2011.04.08 01:50:35 | 000,000,000 | -H-D | M] (Yahoo! Toolbar) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.04.08 22:17:36 | 000,000,000 | -H-D | M] (Zynga Community Toolbar) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010.11.18 20:04:53 | 000,000,000 | -H-D | M] ("DVDVideoSoft Menu") -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.08.18 00:16:29 | 000,003,915 | -H-- | M] () -- C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\la5trnmw.default\searchplugins\sweetim.xml
[2011.05.01 17:12:33 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.05.06 03:00:51 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.09.21 13:06:38 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.10.23 22:41:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010.12.21 15:53:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.02.22 18:31:21 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.04.08 01:50:21 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\distribution\extensions
[2011.04.08 01:50:21 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Programme\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
File not found (No name found) --
[2010.05.06 03:00:51 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.09.21 13:06:38 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.10.23 22:41:59 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010.12.21 15:53:45 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.02.22 18:31:21 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\BASTI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LA5TRNMW.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}.XPI
[2010.01.01 10:00:00 | 000,135,168 | ---- | M] (Mozilla Foundation) -- C:\Programme\Mozilla Firefox\components\browsercomps.dll
[2011.02.02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (AOL Toolbar BHO) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Programme\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O8 - Extra context menu item: &AOL Toolbar-Suche - C:\ProgramData\AOL\ieToolbar\resources\de-DE\local\search.html ()
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Basti\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Basti\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Basti\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{fa6320cf-676c-11e0-8804-001eec82335e}\Shell - "" = AutoRun
O33 - MountPoints2\{fa6320cf-676c-11e0-8804-001eec82335e}\Shell\AutoRun\command - "" = F:\laucher.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
NetSvcs: ezSharedSvc - C:\WINDOWS\System32\ezsvc7.dll (EasyBits Sofware AS)
 
MsConfig - StartUpReg: ICQ - hkey= - key= - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
MsConfig - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files\MSN Messenger\msnmsgr.exe (Microsoft Corporation)
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MsMpSvc - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: MsMpSvc - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 10.1
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\System32\Microsoft
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 10.1
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - C:\WINDOWS\System32\Microsoft
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
 
Drivers32: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi - wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi3 - wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - midimap.dll (Microsoft Corporation)
Drivers32: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer3 - wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - sirenacm.dll (Microsoft Corp.)
Drivers32: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32: wave - wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave3 - wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - msacm32.drv (Microsoft Corporation)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.04.29 22:56:05 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Roaming\Malwarebytes
[2011.04.29 22:55:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.04.29 22:55:54 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.04.29 22:55:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.04.29 22:55:48 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.04.29 22:55:47 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.04.29 03:01:34 | 000,000,000 | ---D | C] -- C:\864b01153e3fdf37d2b00c296bc673
[2011.04.28 01:46:20 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011.04.28 01:03:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.04.28 01:03:04 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2011.04.27 18:58:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autorun Angel
[2011.04.27 18:58:39 | 000,000,000 | ---D | C] -- C:\Programme\Autorun Angel
[2011.04.27 18:33:25 | 000,000,000 | ---D | C] -- C:\Users\Basti\Desktop\Neuer Ordner (5)
[2011.04.25 20:05:18 | 000,000,000 | ---D | C] -- C:\Users\Basti\Desktop\druck 2
[2011.04.25 20:02:59 | 000,000,000 | ---D | C] -- C:\Users\Basti\Desktop\Druck
[2011.04.25 00:47:29 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\Hewlett-Packard
[2011.04.23 04:51:40 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Security Client
[2011.04.22 19:11:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab Setup Files
[2011.04.15 16:35:26 | 000,000,000 | -H-D | C] -- C:\Users\Basti\Desktop\wildhagen
[2011.04.12 15:02:01 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2011.04.11 19:58:49 | 000,000,000 | -H-D | C] -- C:\Users\Basti\Desktop\mitchfilme
 
========== Files - Modified Within 30 Days ==========
 
[2011.05.01 17:23:06 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.05.01 17:19:28 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.05.01 17:19:25 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.05.01 17:19:25 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.05.01 17:19:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.05.01 17:19:10 | 3218,956,288 | -HS- | M] () -- C:\hiberfil.sys
[2011.05.01 17:17:40 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011.05.01 16:52:20 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{4AD6CB10-A3E1-46A1-808C-09598B52C3FE}.job
[2011.04.30 20:42:01 | 000,076,800 | -H-- | M] () -- C:\Users\Basti\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.28 01:20:32 | 000,321,648 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.04.28 01:12:03 | 000,227,880 | ---- | M] () -- C:\Users\Basti\Documents\cc_20110428_011136.reg
[2011.04.28 01:03:06 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.04.25 21:13:22 | 003,778,334 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.04.25 21:13:21 | 003,159,740 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.04.25 21:13:20 | 010,855,478 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.04.25 21:13:19 | 003,511,250 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.04.23 13:43:30 | 000,002,461 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011.04.23 13:42:50 | 000,002,413 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.04.23 04:57:23 | 000,000,136 | -H-- | M] () -- C:\ProgramData\~38788872r
[2011.04.23 04:57:23 | 000,000,120 | -H-- | M] () -- C:\ProgramData\~38788872
[2011.04.23 04:53:51 | 000,002,154 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011.04.23 01:45:14 | 000,000,392 | -H-- | M] () -- C:\ProgramData\38788872
[2011.04.22 17:07:24 | 000,000,400 | -H-- | M] () -- C:\ProgramData\32694024
[2011.04.08 01:50:24 | 000,000,846 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
 
========== Files Created - No Company Name ==========
 
[2011.04.28 01:11:42 | 000,227,880 | ---- | C] () -- C:\Users\Basti\Documents\cc_20110428_011136.reg
[2011.04.28 01:03:06 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.04.23 04:53:51 | 000,002,154 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011.04.23 04:51:54 | 000,001,808 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011.04.23 04:39:06 | 000,000,136 | -H-- | C] () -- C:\ProgramData\~38788872r
[2011.04.23 04:39:06 | 000,000,120 | -H-- | C] () -- C:\ProgramData\~38788872
[2011.04.23 01:43:04 | 000,000,392 | -H-- | C] () -- C:\ProgramData\38788872
[2011.04.22 17:04:00 | 000,000,400 | -H-- | C] () -- C:\ProgramData\32694024
[2011.04.08 01:50:24 | 000,000,858 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011.03.24 01:04:04 | 000,003,036 | -H-- | C] () -- C:\Users\Basti\AppData\Roaming\FA10.BAD
[2010.12.15 01:08:11 | 000,000,032 | -H-- | C] () -- C:\ProgramData\ezsid.dat
[2010.06.19 22:58:57 | 000,006,944 | -H-- | C] () -- C:\Users\Basti\AppData\Local\d3d9caps.dat
[2010.05.13 01:00:54 | 000,000,048 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.05.06 01:29:33 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010.05.06 01:29:33 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010.05.05 00:29:31 | 000,076,800 | -H-- | C] () -- C:\Users\Basti\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.04 22:32:18 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.05.04 22:23:36 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008.06.13 14:22:34 | 010,855,478 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008.06.13 14:22:34 | 003,511,250 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008.06.13 14:22:34 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008.06.13 14:22:34 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2008.06.13 06:26:13 | 000,000,428 | ---- | C] () -- C:\Windows\System32\ezdigsgn.dat
[2008.06.13 04:37:30 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2008.05.09 00:14:22 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008.05.08 23:44:14 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2008.03.06 12:40:54 | 000,168,883 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2008.03.04 21:02:00 | 000,090,112 | ---- | C] () -- C:\Windows\System32\atibrtmon.exe
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,321,648 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 003,778,334 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 003,159,740 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2001.11.14 12:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
 
========== LOP Check ==========
 
[2010.11.18 20:04:53 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.06.06 01:16:15 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Facebook
[2010.11.26 03:23:46 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\ICQ
[2011.01.05 19:34:52 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\OpenOffice.org
[2011.05.01 17:17:40 | 000,032,606 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT
[2011.05.01 16:52:20 | 000,000,418 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{4AD6CB10-A3E1-46A1-808C-09598B52C3FE}.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.05.11 22:57:02 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Adobe
[2010.07.13 19:21:32 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Apple Computer
[2010.05.04 22:58:58 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\ATI
[2010.06.21 02:18:50 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\CyberLink
[2011.04.10 23:01:29 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\dvdcss
[2010.11.18 20:04:53 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.06.06 01:16:15 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Facebook
[2010.06.10 23:41:49 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\GTek
[2010.05.04 22:59:34 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Hewlett-Packard
[2010.11.25 19:21:18 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\HP
[2010.11.26 03:23:46 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\ICQ
[2010.05.04 22:58:19 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Identities
[2010.05.04 22:56:17 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Macromedia
[2011.04.29 22:56:05 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Malwarebytes
[2006.11.02 14:37:34 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Media Center Programs
[2011.04.24 07:14:26 | 000,000,000 | --SD | M] -- C:\Users\Basti\AppData\Roaming\Microsoft
[2010.05.05 00:04:43 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Mozilla
[2011.01.05 19:34:52 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\OpenOffice.org
[2011.02.28 08:58:02 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Skype
[2011.02.28 09:08:45 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\skypePM
[2010.05.04 22:59:04 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Symantec
[2011.05.01 04:02:18 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\vlc
 
< %APPDATA%\*.exe /s >
[2010.06.06 01:16:15 | 000,050,354 | -H-- | M] (Facebook, Inc.) -- C:\Users\Basti\AppData\Roaming\Facebook\uninstall.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\System32\drivers\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.06.13 14:27:27 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\WINDOWS\System32\drivers\atapi.sys
[2008.06.13 14:27:27 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys
[2008.06.13 14:27:27 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.06.13 14:27:27 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\WINDOWS\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\WINDOWS\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2007.01.12 22:30:08 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Programme\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\WINDOWS\System32\drivers\iaStorV.sys
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\WINDOWS\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.21 04:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\WINDOWS\System32\netlogon.dll
[2008.01.21 04:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\WINDOWS\System32\drivers\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\WINDOWS\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 04:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\WINDOWS\System32\scecli.dll
[2008.01.21 04:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\WINDOWS\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
[2008.01.21 04:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\user32.dll
[2008.01.21 04:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\WINDOWS\System32\userinit.exe
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\WINDOWS\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 04:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\WINDOWS\System32\wininit.exe
[2008.01.21 04:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\WINDOWS\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 04:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\WINDOWS\System32\winlogon.exe
[2008.01.21 04:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\WINDOWS\System32\drivers\ws2ifsl.sys
[2008.01.21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\WINDOWS\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.10.24 21:25:38 | 000,043,392 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\drivers\MpNWMon.sys
 
< %systemroot%\System32\config\*.sav >
[2008.01.21 05:14:18 | 016,846,848 | ---- | M] () -- C:\WINDOWS\System32\config\COMPONENTS.SAV
[2008.01.21 05:14:08 | 000,106,496 | ---- | M] () -- C:\WINDOWS\System32\config\DEFAULT.SAV
[2008.01.21 05:14:18 | 000,020,480 | ---- | M] () -- C:\WINDOWS\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\WINDOWS\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\WINDOWS\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---

Basti7 01.05.2011 17:04

Kaspersky deinstalliert, danke für den Hinweis.

hier der OTL.Txt
OTL Logfile:
Code:

OTL logfile created on: 01.05.2011 17:29:32 - Run 2
OTL by OldTimer - Version 3.2.22.3    Folder = c:\Users\Basti\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 66,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 84,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 224,04 Gb Total Space | 1,52 Gb Free Space | 0,68% Space Free | Partition Type: NTFS
Drive D: | 8,84 Gb Total Space | 0,90 Gb Free Space | 10,21% Space Free | Partition Type: NTFS
 
Computer Name: BASTI-PC | User Name: Basti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - c:\Users\Basti\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Programme\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
PRC - c:\Programme\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\stacsv.exe (IDT, Inc.)
PRC - C:\Programme\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\WINDOWS\SMINST\BLService.exe ()
PRC - C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
 
 
========== Modules (SafeList) ==========
 
MOD - c:\Users\Basti\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (NisSrv) -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (WinHttpAutoProxySvc) -- winhttp.dll (Microsoft Corporation)
SRV - (STacSV) -- C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\stacsv.exe (IDT, Inc.)
SRV - (Recovery Service for Windows) -- C:\WINDOWS\SMINST\BLService.exe ()
SRV - (AESTFilters) -- C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (ezSharedSvc) -- C:\WINDOWS\System32\ezsvc7.dll (EasyBits Sofware AS)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (MpKsle9fcf5a7) -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D6D0CB9E-5D18-428D-BFBB-395754A19FC4}\MpKsle9fcf5a7.sys (Microsoft Corporation)
DRV - (NisDrv) -- C:\WINDOWS\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) -- C:\WINDOWS\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (jumi) -- C:\WINDOWS\System32\drivers\jumi.sys (Windows (R) Win 7 DDK provider)
DRV - (atikmdag) -- C:\WINDOWS\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (nmwcdc) -- C:\WINDOWS\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (upperdev) -- C:\WINDOWS\System32\drivers\usbser_lowerflt.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (nmwcd) -- C:\WINDOWS\System32\drivers\ccdcmb.sys (Nokia)
DRV - (AtiPcie) ATI PCI Express (3GIO) -- C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV - (athr) -- C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (STHDA) -- C:\WINDOWS\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (JMCR) -- C:\WINDOWS\System32\drivers\jmcr.sys (JMicron Technology Corp.)
DRV - (hpdskflt) -- C:\Windows\system32\DRIVERS\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (Accelerometer) -- C:\WINDOWS\System32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (RTL8169) -- C:\WINDOWS\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (enecir) -- C:\WINDOWS\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV - (nmwcdcj) -- C:\WINDOWS\System32\drivers\nmwcdcj.sys (Nokia)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (NVENETFD) -- C:\WINDOWS\System32\drivers\nvm60x32.sys (NVIDIA Corporation)
DRV - (M9207) -- C:\WINDOWS\System32\drivers\M9207BDA.sys (Animation Technologies Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = HP | MSN
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = HP | MSN
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = HP | MSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = HP | MSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} -  File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:63354
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://de.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {2f17f610-5e97-4fed-828f-9940b7b577a4}:1.6.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 63354
FF - prefs.js..network.proxy.type: 4
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "chrome://browser-region/locale/region.properties"
 
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.04.08 01:50:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.04.08 01:50:19 | 000,000,000 | ---D | M]
 
[2010.05.05 00:04:43 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Basti\AppData\Roaming\mozilla\Extensions
[2011.04.08 22:17:36 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions
[2010.12.11 22:57:51 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.12.11 22:57:51 | 000,000,000 | -H-D | M] (TV-Fox) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{2f17f610-5e97-4fed-828f-9940b7b577a4}
[2011.04.08 01:50:35 | 000,000,000 | -H-D | M] (Yahoo! Toolbar) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.04.08 22:17:36 | 000,000,000 | -H-D | M] (Zynga Community Toolbar) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010.11.18 20:04:53 | 000,000,000 | -H-D | M] ("DVDVideoSoft Menu") -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\la5trnmw.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.08.18 00:16:29 | 000,003,915 | -H-- | M] () -- C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\la5trnmw.default\searchplugins\sweetim.xml
[2011.05.01 17:12:33 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.05.06 03:00:51 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.09.21 13:06:38 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.10.23 22:41:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010.12.21 15:53:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.02.22 18:31:21 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.04.08 01:50:21 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\distribution\extensions
[2011.04.08 01:50:21 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Programme\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
File not found (No name found) --
[2010.05.06 03:00:51 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.09.21 13:06:38 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.10.23 22:41:59 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010.12.21 15:53:45 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.02.22 18:31:21 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\BASTI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LA5TRNMW.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}.XPI
[2010.01.01 10:00:00 | 000,135,168 | ---- | M] (Mozilla Foundation) -- C:\Programme\Mozilla Firefox\components\browsercomps.dll
[2011.02.02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (AOL Toolbar BHO) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Programme\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O8 - Extra context menu item: &AOL Toolbar-Suche - C:\ProgramData\AOL\ieToolbar\resources\de-DE\local\search.html ()
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Basti\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Basti\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Basti\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{fa6320cf-676c-11e0-8804-001eec82335e}\Shell - "" = AutoRun
O33 - MountPoints2\{fa6320cf-676c-11e0-8804-001eec82335e}\Shell\AutoRun\command - "" = F:\laucher.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
NetSvcs: ezSharedSvc - C:\WINDOWS\System32\ezsvc7.dll (EasyBits Sofware AS)
 
MsConfig - StartUpReg: ICQ - hkey= - key= - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
MsConfig - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files\MSN Messenger\msnmsgr.exe (Microsoft Corporation)
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MsMpSvc - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: MsMpSvc - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 10.1
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\System32\Microsoft
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 10.1
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - C:\WINDOWS\System32\Microsoft
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
 
Drivers32: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi - wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi3 - wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - midimap.dll (Microsoft Corporation)
Drivers32: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer3 - wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - sirenacm.dll (Microsoft Corp.)
Drivers32: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32: wave - wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave3 - wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - msacm32.drv (Microsoft Corporation)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.04.29 22:56:05 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Roaming\Malwarebytes
[2011.04.29 22:55:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.04.29 22:55:54 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.04.29 22:55:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.04.29 22:55:48 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.04.29 22:55:47 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.04.29 03:01:34 | 000,000,000 | ---D | C] -- C:\864b01153e3fdf37d2b00c296bc673
[2011.04.28 01:46:20 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011.04.28 01:03:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.04.28 01:03:04 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2011.04.27 18:58:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autorun Angel
[2011.04.27 18:58:39 | 000,000,000 | ---D | C] -- C:\Programme\Autorun Angel
[2011.04.27 18:33:25 | 000,000,000 | ---D | C] -- C:\Users\Basti\Desktop\Neuer Ordner (5)
[2011.04.25 20:05:18 | 000,000,000 | ---D | C] -- C:\Users\Basti\Desktop\druck 2
[2011.04.25 20:02:59 | 000,000,000 | ---D | C] -- C:\Users\Basti\Desktop\Druck
[2011.04.25 00:47:29 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\Hewlett-Packard
[2011.04.23 04:51:40 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Security Client
[2011.04.22 19:11:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab Setup Files
[2011.04.15 16:35:26 | 000,000,000 | -H-D | C] -- C:\Users\Basti\Desktop\wildhagen
[2011.04.12 15:02:01 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2011.04.11 19:58:49 | 000,000,000 | -H-D | C] -- C:\Users\Basti\Desktop\mitchfilme
 
========== Files - Modified Within 30 Days ==========
 
[2011.05.01 17:23:06 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.05.01 17:19:28 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.05.01 17:19:25 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.05.01 17:19:25 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.05.01 17:19:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.05.01 17:19:10 | 3218,956,288 | -HS- | M] () -- C:\hiberfil.sys
[2011.05.01 17:17:40 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011.05.01 16:52:20 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{4AD6CB10-A3E1-46A1-808C-09598B52C3FE}.job
[2011.04.30 20:42:01 | 000,076,800 | -H-- | M] () -- C:\Users\Basti\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.28 01:20:32 | 000,321,648 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.04.28 01:12:03 | 000,227,880 | ---- | M] () -- C:\Users\Basti\Documents\cc_20110428_011136.reg
[2011.04.28 01:03:06 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.04.25 21:13:22 | 003,778,334 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.04.25 21:13:21 | 003,159,740 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.04.25 21:13:20 | 010,855,478 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.04.25 21:13:19 | 003,511,250 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.04.23 13:43:30 | 000,002,461 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011.04.23 13:42:50 | 000,002,413 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.04.23 04:57:23 | 000,000,136 | -H-- | M] () -- C:\ProgramData\~38788872r
[2011.04.23 04:57:23 | 000,000,120 | -H-- | M] () -- C:\ProgramData\~38788872
[2011.04.23 04:53:51 | 000,002,154 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011.04.23 01:45:14 | 000,000,392 | -H-- | M] () -- C:\ProgramData\38788872
[2011.04.22 17:07:24 | 000,000,400 | -H-- | M] () -- C:\ProgramData\32694024
[2011.04.08 01:50:24 | 000,000,846 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
 
========== Files Created - No Company Name ==========
 
[2011.04.28 01:11:42 | 000,227,880 | ---- | C] () -- C:\Users\Basti\Documents\cc_20110428_011136.reg
[2011.04.28 01:03:06 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.04.23 04:53:51 | 000,002,154 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011.04.23 04:51:54 | 000,001,808 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011.04.23 04:39:06 | 000,000,136 | -H-- | C] () -- C:\ProgramData\~38788872r
[2011.04.23 04:39:06 | 000,000,120 | -H-- | C] () -- C:\ProgramData\~38788872
[2011.04.23 01:43:04 | 000,000,392 | -H-- | C] () -- C:\ProgramData\38788872
[2011.04.22 17:04:00 | 000,000,400 | -H-- | C] () -- C:\ProgramData\32694024
[2011.04.08 01:50:24 | 000,000,858 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011.03.24 01:04:04 | 000,003,036 | -H-- | C] () -- C:\Users\Basti\AppData\Roaming\FA10.BAD
[2010.12.15 01:08:11 | 000,000,032 | -H-- | C] () -- C:\ProgramData\ezsid.dat
[2010.06.19 22:58:57 | 000,006,944 | -H-- | C] () -- C:\Users\Basti\AppData\Local\d3d9caps.dat
[2010.05.13 01:00:54 | 000,000,048 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.05.06 01:29:33 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010.05.06 01:29:33 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010.05.05 00:29:31 | 000,076,800 | -H-- | C] () -- C:\Users\Basti\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.04 22:32:18 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.05.04 22:23:36 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008.06.13 14:22:34 | 010,855,478 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008.06.13 14:22:34 | 003,511,250 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008.06.13 14:22:34 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008.06.13 14:22:34 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2008.06.13 06:26:13 | 000,000,428 | ---- | C] () -- C:\Windows\System32\ezdigsgn.dat
[2008.06.13 04:37:30 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2008.05.09 00:14:22 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008.05.08 23:44:14 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2008.03.06 12:40:54 | 000,168,883 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2008.03.04 21:02:00 | 000,090,112 | ---- | C] () -- C:\Windows\System32\atibrtmon.exe
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,321,648 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 003,778,334 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 003,159,740 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2001.11.14 12:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
 
========== LOP Check ==========
 
[2010.11.18 20:04:53 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.06.06 01:16:15 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Facebook
[2010.11.26 03:23:46 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\ICQ
[2011.01.05 19:34:52 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\OpenOffice.org
[2011.05.01 17:17:40 | 000,032,606 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT
[2011.05.01 16:52:20 | 000,000,418 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{4AD6CB10-A3E1-46A1-808C-09598B52C3FE}.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.05.11 22:57:02 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Adobe
[2010.07.13 19:21:32 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Apple Computer
[2010.05.04 22:58:58 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\ATI
[2010.06.21 02:18:50 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\CyberLink
[2011.04.10 23:01:29 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\dvdcss
[2010.11.18 20:04:53 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.06.06 01:16:15 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Facebook
[2010.06.10 23:41:49 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\GTek
[2010.05.04 22:59:34 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Hewlett-Packard
[2010.11.25 19:21:18 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\HP
[2010.11.26 03:23:46 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\ICQ
[2010.05.04 22:58:19 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Identities
[2010.05.04 22:56:17 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Macromedia
[2011.04.29 22:56:05 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Malwarebytes
[2006.11.02 14:37:34 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Media Center Programs
[2011.04.24 07:14:26 | 000,000,000 | --SD | M] -- C:\Users\Basti\AppData\Roaming\Microsoft
[2010.05.05 00:04:43 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Mozilla
[2011.01.05 19:34:52 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\OpenOffice.org
[2011.02.28 08:58:02 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Skype
[2011.02.28 09:08:45 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\skypePM
[2010.05.04 22:59:04 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\Symantec
[2011.05.01 04:02:18 | 000,000,000 | -H-D | M] -- C:\Users\Basti\AppData\Roaming\vlc
 
< %APPDATA%\*.exe /s >
[2010.06.06 01:16:15 | 000,050,354 | -H-- | M] (Facebook, Inc.) -- C:\Users\Basti\AppData\Roaming\Facebook\uninstall.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\System32\drivers\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.06.13 14:27:27 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\WINDOWS\System32\drivers\atapi.sys
[2008.06.13 14:27:27 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys
[2008.06.13 14:27:27 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.06.13 14:27:27 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\WINDOWS\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\WINDOWS\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2007.01.12 22:30:08 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Programme\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\WINDOWS\System32\drivers\iaStorV.sys
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\WINDOWS\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.21 04:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\WINDOWS\System32\netlogon.dll
[2008.01.21 04:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\WINDOWS\System32\drivers\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\WINDOWS\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 04:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\WINDOWS\System32\scecli.dll
[2008.01.21 04:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\WINDOWS\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
[2008.01.21 04:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\user32.dll
[2008.01.21 04:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\WINDOWS\System32\userinit.exe
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\WINDOWS\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 04:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\WINDOWS\System32\wininit.exe
[2008.01.21 04:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\WINDOWS\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 04:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\WINDOWS\System32\winlogon.exe
[2008.01.21 04:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\WINDOWS\System32\drivers\ws2ifsl.sys
[2008.01.21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\WINDOWS\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.10.24 21:25:38 | 000,043,392 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\drivers\MpNWMon.sys
 
< %systemroot%\System32\config\*.sav >
[2008.01.21 05:14:18 | 016,846,848 | ---- | M] () -- C:\WINDOWS\System32\config\COMPONENTS.SAV
[2008.01.21 05:14:08 | 000,106,496 | ---- | M] () -- C:\WINDOWS\System32\config\DEFAULT.SAV
[2008.01.21 05:14:18 | 000,020,480 | ---- | M] () -- C:\WINDOWS\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\WINDOWS\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\WINDOWS\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---

Basti7 01.05.2011 17:36

war alles richtig, außer daß ichs aus versehen 2 mal gepostet hab, wie ich grade erst bemerkt habe?

Basti7 01.05.2011 21:28

hallo Arne,

ich guck alle paar Stunden mal rein:kaffee:

cosinus 02.05.2011 11:30

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:63354
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 63354
FF - prefs.js..network.proxy.type: 4
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{fa6320cf-676c-11e0-8804-001eec82335e}\Shell - "" = AutoRun
O33 - MountPoints2\{fa6320cf-676c-11e0-8804-001eec82335e}\Shell\AutoRun\command - "" = F:\laucher.exe
1.04.23 04:39:06 | 000,000,136 | -H-- | C] () -- C:\ProgramData\~38788872r
[2011.04.23 04:39:06 | 000,000,120 | -H-- | C] () -- C:\ProgramData\~38788872
[2011.04.23 01:43:04 | 000,000,392 | -H-- | C] () -- C:\ProgramData\38788872
[2011.04.22 17:04:00 | 000,000,400 | -H-- | C] () -- C:\ProgramData\32694024
[2011.03.24 01:04:04 | 000,003,036 | -H-- | C] () -- C:\Users\Basti\AppData\Roaming\FA10.BAD
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Basti7 02.05.2011 13:57

Hi Arne,

All processes killed
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Prefs.js: "127.0.0.1" removed from network.proxy.http
Prefs.js: 63354 removed from network.proxy.http_port
Prefs.js: 4 removed from network.proxy.type
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fa6320cf-676c-11e0-8804-001eec82335e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fa6320cf-676c-11e0-8804-001eec82335e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fa6320cf-676c-11e0-8804-001eec82335e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fa6320cf-676c-11e0-8804-001eec82335e}\ not found.
File F:\laucher.exe not found.
C:\ProgramData\~38788872 moved successfully.
C:\ProgramData\38788872 moved successfully.
C:\ProgramData\32694024 moved successfully.
C:\Users\Basti\AppData\Roaming\FA10.BAD moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Basti
->Temp folder emptied: 9104275 bytes
->Temporary Internet Files folder emptied: 3703186 bytes
->Java cache emptied: 1184334 bytes
->FireFox cache emptied: 73414378 bytes
->Flash cache emptied: 3429 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 116748 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 84,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 05022011_145113

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Basti7 02.05.2011 14:02

soll ich den Virenscanner (Microsoft Security Essentials) deaktiviert lassen?

Meine Ordner sind wieder alle verschwunden, was mich ein wenig nervös macht...

cosinus 02.05.2011 15:12

Ja Virenscanner erstmal deaktivieren.

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Vista und 7 User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

Basti7 02.05.2011 15:32

2011/05/02 16:29:06.0373 2572 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/05/02 16:29:06.0794 2572 ================================================================================
2011/05/02 16:29:06.0794 2572 SystemInfo:
2011/05/02 16:29:06.0794 2572
2011/05/02 16:29:06.0794 2572 OS Version: 6.0.6001 ServicePack: 1.0
2011/05/02 16:29:06.0794 2572 Product type: Workstation
2011/05/02 16:29:06.0794 2572 ComputerName: BASTI-PC
2011/05/02 16:29:06.0795 2572 UserName: Basti
2011/05/02 16:29:06.0795 2572 Windows directory: C:\Windows
2011/05/02 16:29:06.0795 2572 System windows directory: C:\Windows
2011/05/02 16:29:06.0795 2572 Processor architecture: Intel x86
2011/05/02 16:29:06.0795 2572 Number of processors: 2
2011/05/02 16:29:06.0795 2572 Page size: 0x1000
2011/05/02 16:29:06.0795 2572 Boot type: Normal boot
2011/05/02 16:29:06.0795 2572 ================================================================================
2011/05/02 16:29:07.0428 2572 Initialize success
2011/05/02 16:29:11.0080 5380 ================================================================================
2011/05/02 16:29:11.0080 5380 Scan started
2011/05/02 16:29:11.0080 5380 Mode: Manual;
2011/05/02 16:29:11.0081 5380 ================================================================================
2011/05/02 16:29:20.0431 5380 Accelerometer (3b10711ad8656c097e0d16a41b29c54c) C:\Windows\system32\DRIVERS\Accelerometer.sys
2011/05/02 16:29:20.0636 5380 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys
2011/05/02 16:29:20.0748 5380 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/05/02 16:29:20.0897 5380 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/05/02 16:29:20.0967 5380 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/05/02 16:29:21.0010 5380 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/05/02 16:29:21.0228 5380 AFD (763e172a55177e478cb419f88fd0ba03) C:\Windows\system32\drivers\afd.sys
2011/05/02 16:29:21.0307 5380 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/05/02 16:29:21.0449 5380 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/05/02 16:29:21.0528 5380 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/05/02 16:29:21.0617 5380 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/05/02 16:29:21.0690 5380 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/05/02 16:29:21.0747 5380 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/05/02 16:29:21.0813 5380 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
2011/05/02 16:29:21.0953 5380 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/05/02 16:29:22.0044 5380 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/05/02 16:29:22.0148 5380 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/05/02 16:29:22.0257 5380 atapi (0d83c87a801a3dfcd1bf73893fe7518c) C:\Windows\system32\drivers\atapi.sys
2011/05/02 16:29:22.0487 5380 athr (600efe56f37adbd65a0fb076b50d1b8d) C:\Windows\system32\DRIVERS\athr.sys
2011/05/02 16:29:22.0824 5380 atikmdag (2dc63afb58a1b166cf1d1b5a9f144135) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/05/02 16:29:23.0139 5380 AtiPcie (5a1465ad2e7c1bc39cda12a355329096) C:\Windows\system32\DRIVERS\AtiPcie.sys
2011/05/02 16:29:23.0323 5380 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys
2011/05/02 16:29:23.0417 5380 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/05/02 16:29:23.0516 5380 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/05/02 16:29:23.0685 5380 bowser (8153396d5551276227fa146900f734e6) C:\Windows\system32\DRIVERS\bowser.sys
2011/05/02 16:29:23.0757 5380 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/05/02 16:29:23.0802 5380 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/05/02 16:29:23.0917 5380 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/05/02 16:29:23.0978 5380 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/05/02 16:29:24.0025 5380 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/05/02 16:29:24.0088 5380 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/05/02 16:29:24.0165 5380 BthEnum (cce53afc28347cc18ea139972e5b5e5a) C:\Windows\system32\DRIVERS\BthEnum.sys
2011/05/02 16:29:24.0253 5380 BTHMODEM (5ffa6988ff9597986ff2ada736cc90c0) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/05/02 16:29:24.0339 5380 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
2011/05/02 16:29:24.0433 5380 BTHPORT (ac8a1689d5efc4d214201155a78d8f4b) C:\Windows\system32\Drivers\BTHport.sys
2011/05/02 16:29:24.0493 5380 BTHUSB (288c1f74e3e2eed6c7b54eb3aac70856) C:\Windows\system32\Drivers\BTHUSB.sys
2011/05/02 16:29:24.0670 5380 btwaudio (99aeea7cefdfc6e4151a8f620d682088) C:\Windows\system32\drivers\btwaudio.sys
2011/05/02 16:29:24.0802 5380 btwavdt (195872e48a7fb01f8bc9b800f70f4054) C:\Windows\system32\drivers\btwavdt.sys
2011/05/02 16:29:24.0921 5380 btwrchid (0724e7d6c9b6a289eddda33fa8176e80) C:\Windows\system32\DRIVERS\btwrchid.sys
2011/05/02 16:29:25.0102 5380 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/05/02 16:29:25.0225 5380 cdrom (1ec25cea0de6ac4718bf89f9e1778b57) C:\Windows\system32\DRIVERS\cdrom.sys
2011/05/02 16:29:25.0314 5380 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
2011/05/02 16:29:25.0485 5380 CLFS (465745561c832b29f7c48b488aab3842) C:\Windows\system32\CLFS.sys
2011/05/02 16:29:25.0954 5380 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/05/02 16:29:26.0051 5380 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/05/02 16:29:26.0178 5380 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2011/05/02 16:29:26.0231 5380 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/05/02 16:29:26.0315 5380 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/05/02 16:29:26.0450 5380 DfsC (9e635ae5e8ad93e2b5989e2e23679f97) C:\Windows\system32\Drivers\dfsc.sys
2011/05/02 16:29:26.0837 5380 disk (64109e623abd6955c8fb110b592e68b7) C:\Windows\system32\drivers\disk.sys
2011/05/02 16:29:27.0055 5380 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/05/02 16:29:27.0213 5380 DXGKrnl (85f33880b8cfb554bd3d9ccdb486845a) C:\Windows\System32\drivers\dxgkrnl.sys
2011/05/02 16:29:27.0332 5380 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/05/02 16:29:27.0478 5380 Ecache (dd2cd259d83d8b72c02c5f2331ff9d68) C:\Windows\system32\drivers\ecache.sys
2011/05/02 16:29:27.0584 5380 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/05/02 16:29:27.0698 5380 enecir (4cd6b056c5fd9e97c06fe74c81479517) C:\Windows\system32\DRIVERS\enecir.sys
2011/05/02 16:29:27.0758 5380 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/05/02 16:29:27.0892 5380 exfat (0d858eb20589a34efb25695acaa6aa2d) C:\Windows\system32\drivers\exfat.sys
2011/05/02 16:29:28.0013 5380 fastfat (3c489390c2e2064563727752af8eab9e) C:\Windows\system32\drivers\fastfat.sys
2011/05/02 16:29:28.0109 5380 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/05/02 16:29:28.0184 5380 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/05/02 16:29:28.0255 5380 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/05/02 16:29:28.0310 5380 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/05/02 16:29:28.0359 5380 FltMgr (05ea53afe985443011e36dab07343b46) C:\Windows\system32\drivers\fltmgr.sys
2011/05/02 16:29:28.0463 5380 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/05/02 16:29:28.0624 5380 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/05/02 16:29:28.0954 5380 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/05/02 16:29:29.0306 5380 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2011/05/02 16:29:29.0653 5380 HDAudBus (c87b1ee051c0464491c1a7b03fa0bc99) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/05/02 16:29:30.0032 5380 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/05/02 16:29:30.0545 5380 HidIr (5a87127718873bd7f3bd7ac42b951d8e) C:\Windows\system32\DRIVERS\hidir.sys
2011/05/02 16:29:31.0758 5380 HidUsb (3c64042b95e583b366ba4e5d2450235e) C:\Windows\system32\drivers\hidusb.sys
2011/05/02 16:29:32.0253 5380 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/05/02 16:29:32.0347 5380 hpdskflt (24f3f496c18efc234777723a67a85f81) C:\Windows\system32\DRIVERS\hpdskflt.sys
2011/05/02 16:29:32.0658 5380 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
2011/05/02 16:29:33.0086 5380 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
2011/05/02 16:29:33.0344 5380 HSF_DPV (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
2011/05/02 16:29:33.0723 5380 HTTP (96e241624c71211a79c84f50a8e71cab) C:\Windows\system32\drivers\HTTP.sys
2011/05/02 16:29:34.0022 5380 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/05/02 16:29:34.0152 5380 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/05/02 16:29:34.0259 5380 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/05/02 16:29:34.0350 5380 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/05/02 16:29:34.0680 5380 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/05/02 16:29:35.0137 5380 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/05/02 16:29:35.0433 5380 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/05/02 16:29:36.0104 5380 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/05/02 16:29:36.0347 5380 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/05/02 16:29:36.0663 5380 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/05/02 16:29:36.0823 5380 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/05/02 16:29:37.0683 5380 iScsiPrt (f247eec28317f6c739c16de420097301) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/05/02 16:29:38.0266 5380 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/05/02 16:29:38.0369 5380 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/05/02 16:29:38.0469 5380 JMCR (dedb6cc1b166928a8f3f68def1766db0) C:\Windows\system32\DRIVERS\jmcr.sys
2011/05/02 16:29:38.0580 5380 jumi (ee894427ac0b2b2c2c8b32cb78357dae) C:\Windows\system32\DRIVERS\jumi.sys
2011/05/02 16:29:38.0635 5380 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/05/02 16:29:38.0678 5380 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/05/02 16:29:38.0774 5380 KSecDD (7a0cf7908b6824d6a2a1d313e5ae3dca) C:\Windows\system32\Drivers\ksecdd.sys
2011/05/02 16:29:38.0877 5380 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/05/02 16:29:38.0948 5380 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/05/02 16:29:39.0011 5380 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/05/02 16:29:39.0067 5380 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/05/02 16:29:39.0160 5380 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/05/02 16:29:39.0543 5380 M9207 (8e1cf9133d32751848e4856359c10621) C:\Windows\system32\DRIVERS\M9207BDA.sys
2011/05/02 16:29:39.0940 5380 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/05/02 16:29:40.0434 5380 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/05/02 16:29:40.0718 5380 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/05/02 16:29:40.0941 5380 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/05/02 16:29:41.0348 5380 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/05/02 16:29:41.0800 5380 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/05/02 16:29:42.0323 5380 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/05/02 16:29:42.0827 5380 MpFilter (7e34bfa1a7b60bba1da03d677f16cd63) C:\Windows\system32\DRIVERS\MpFilter.sys
2011/05/02 16:29:43.0296 5380 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/05/02 16:29:44.0115 5380 MpKsl2aa47320 (5f53edfead46fa7adb78eee9ecce8fdf) c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CA4F610B-8554-4819-9F87-A07676D91B2E}\MpKsl2aa47320.sys
2011/05/02 16:29:44.0775 5380 MpNWMon (f32e2d6a1640a469a9ed4f1929a4a861) C:\Windows\system32\DRIVERS\MpNWMon.sys
2011/05/02 16:29:50.0550 5380 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/05/02 16:29:51.0070 5380 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/05/02 16:29:51.0109 5380 MRxDAV (ae3de84536b6799d2267443cec8edbb9) C:\Windows\system32\drivers\mrxdav.sys
2011/05/02 16:29:51.0203 5380 mrxsmb (cc752d233ef39875ca6885d9415ba869) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/05/02 16:29:51.0265 5380 mrxsmb10 (9049dddd4bd27d43d82f5968f1da76e4) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/05/02 16:29:51.0365 5380 mrxsmb20 (91dc069b6831ef564e7d8c97eaf0343e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/05/02 16:29:51.0418 5380 msahci (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys
2011/05/02 16:29:51.0487 5380 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/05/02 16:29:51.0555 5380 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/05/02 16:29:51.0625 5380 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/05/02 16:29:51.0873 5380 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/05/02 16:29:51.0931 5380 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/05/02 16:29:52.0026 5380 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/05/02 16:29:52.0100 5380 MsRPC (b5614aecb05a9340aa0fb55bf561cc63) C:\Windows\system32\drivers\MsRPC.sys
2011/05/02 16:29:52.0160 5380 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/05/02 16:29:52.0213 5380 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/05/02 16:29:52.0272 5380 Mup (6dfd1d322de55b0b7db7d21b90bec49c) C:\Windows\system32\Drivers\mup.sys
2011/05/02 16:29:52.0344 5380 NativeWifiP (3c21ce48ff529bb73dadb98770b54025) C:\Windows\system32\DRIVERS\nwifi.sys
2011/05/02 16:29:52.0428 5380 NDIS (9bdc71790fa08f0a0b5f10462b1bd0b1) C:\Windows\system32\drivers\ndis.sys
2011/05/02 16:29:53.0399 5380 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/05/02 16:29:53.0816 5380 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/05/02 16:29:53.0914 5380 NdisWan (3d14c3b3496f88890d431e8aa022a411) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/05/02 16:29:53.0961 5380 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/05/02 16:29:54.0182 5380 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/05/02 16:29:54.0270 5380 netbt (7c5fee5b1c5728507cd96fb4a13e7a02) C:\Windows\system32\DRIVERS\netbt.sys
2011/05/02 16:29:54.0375 5380 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/05/02 16:29:54.0457 5380 NisDrv (17e2c08c5ecfbe94a7c67b1c275ee9d9) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
2011/05/02 16:29:54.0767 5380 nmwcd (c82f4cc10ad315b6d6bcb14d0a7cad66) C:\Windows\system32\drivers\ccdcmb.sys
2011/05/02 16:29:54.0844 5380 nmwcdc (60ef5f5621d7832f00a3f190a0c905e2) C:\Windows\system32\drivers\ccdcmbo.sys
2011/05/02 16:29:54.0935 5380 nmwcdcj (9c9ff3ec04021234d6f440acbd3b70c1) C:\Windows\system32\drivers\nmwcdcj.sys
2011/05/02 16:29:55.0006 5380 Npfs (ecb5003f484f9ed6c608d6d6c7886cbb) C:\Windows\system32\drivers\Npfs.sys
2011/05/02 16:29:55.0092 5380 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/05/02 16:29:55.0330 5380 Ntfs (b4effe29eb4f15538fd8a9681108492d) C:\Windows\system32\drivers\Ntfs.sys
2011/05/02 16:29:55.0400 5380 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/05/02 16:29:55.0470 5380 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/05/02 16:29:55.0577 5380 NVENETFD (1657f3fbd9061526c14ff37e79306f98) C:\Windows\system32\DRIVERS\nvm60x32.sys
2011/05/02 16:29:55.0664 5380 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/05/02 16:29:55.0755 5380 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/05/02 16:29:55.0834 5380 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/05/02 16:29:56.0013 5380 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/05/02 16:29:56.0165 5380 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/05/02 16:29:56.0244 5380 partmgr (3b38467e7c3daed009dfe359e17f139f) C:\Windows\system32\drivers\partmgr.sys
2011/05/02 16:29:56.0299 5380 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/05/02 16:29:56.0359 5380 pci (01b94418deb235dff777cc80076354b4) C:\Windows\system32\drivers\pci.sys
2011/05/02 16:29:56.0485 5380 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
2011/05/02 16:29:56.0539 5380 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2011/05/02 16:29:56.0642 5380 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/05/02 16:29:56.0801 5380 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/05/02 16:29:56.0869 5380 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\DRIVERS\processr.sys
2011/05/02 16:29:56.0952 5380 PSched (bfef604508a0ed1eae2a73e872555ffb) C:\Windows\system32\DRIVERS\pacer.sys
2011/05/02 16:29:57.0031 5380 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/05/02 16:29:57.0079 5380 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/05/02 16:29:57.0123 5380 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/05/02 16:29:57.0183 5380 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/05/02 16:29:57.0228 5380 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/05/02 16:29:57.0265 5380 RasPppoe (3e9d9b048107b40d87b97df2e48e0744) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/05/02 16:29:57.0374 5380 RasSstp (a7d141684e9500ac928a772ed8e6b671) C:\Windows\system32\DRIVERS\rassstp.sys
2011/05/02 16:29:57.0461 5380 rdbss (6e1c5d0457622f9ee35f683110e93d14) C:\Windows\system32\DRIVERS\rdbss.sys
2011/05/02 16:29:57.0519 5380 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/05/02 16:29:57.0590 5380 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2011/05/02 16:29:57.0620 5380 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/05/02 16:29:57.0681 5380 RDPWD (e1c18f4097a5abcec941dc4b2f99db7e) C:\Windows\system32\drivers\RDPWD.sys
2011/05/02 16:29:57.0742 5380 RFCOMM (23f486726da7a9b2f3ec7326421a9c36) C:\Windows\system32\DRIVERS\rfcomm.sys
2011/05/02 16:29:57.0797 5380 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/05/02 16:29:57.0864 5380 RTL8169 (abbe0f54ba3a378262c9cb86cf7d91f8) C:\Windows\system32\DRIVERS\Rtlh86.sys
2011/05/02 16:29:57.0985 5380 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/05/02 16:29:58.0146 5380 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
2011/05/02 16:29:58.0201 5380 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/05/02 16:29:58.0258 5380 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/05/02 16:29:58.0333 5380 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/05/02 16:29:58.0368 5380 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/05/02 16:29:58.0498 5380 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/05/02 16:29:58.0582 5380 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/05/02 16:29:58.0627 5380 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/05/02 16:29:58.0685 5380 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/05/02 16:29:58.0773 5380 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/05/02 16:29:58.0809 5380 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/05/02 16:29:58.0851 5380 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/05/02 16:29:58.0912 5380 Smb (031e6bcd53c9b2b9ace111eafec347b6) C:\Windows\system32\DRIVERS\smb.sys
2011/05/02 16:29:58.0969 5380 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/05/02 16:29:59.0050 5380 srv (2252aef839b1093d16761189f45af885) C:\Windows\system32\DRIVERS\srv.sys
2011/05/02 16:29:59.0142 5380 srv2 (96512f4a30b741e7d33a7936b9abbc20) C:\Windows\system32\DRIVERS\srv2.sys
2011/05/02 16:29:59.0245 5380 srvnet (1c69e33e0e23626da5a34ca5ba0dd990) C:\Windows\system32\DRIVERS\srvnet.sys
2011/05/02 16:29:59.0426 5380 STHDA (5e71b3635d5f96d23eee1da92b85c850) C:\Windows\system32\DRIVERS\stwrt.sys
2011/05/02 16:29:59.0532 5380 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/05/02 16:29:59.0668 5380 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/05/02 16:29:59.0705 5380 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/05/02 16:29:59.0759 5380 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/05/02 16:29:59.0833 5380 SynTP (bf7aa84d5af0faa0978c840e63b17dbf) C:\Windows\system32\DRIVERS\SynTP.sys
2011/05/02 16:30:00.0018 5380 Tcpip (6216a954ed7045b62880a92d6c9b9fc7) C:\Windows\system32\drivers\tcpip.sys
2011/05/02 16:30:00.0167 5380 Tcpip6 (6216a954ed7045b62880a92d6c9b9fc7) C:\Windows\system32\DRIVERS\tcpip.sys
2011/05/02 16:30:00.0259 5380 tcpipreg (d4a2e4a4b011f3a883af77315a5ae76b) C:\Windows\system32\drivers\tcpipreg.sys
2011/05/02 16:30:00.0314 5380 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/05/02 16:30:00.0377 5380 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/05/02 16:30:00.0415 5380 tdx (d09276b1fab033ce1d40dcbdf303d10f) C:\Windows\system32\DRIVERS\tdx.sys
2011/05/02 16:30:00.0560 5380 TermDD (a048056f5e1a96a9bf3071b91741a5aa) C:\Windows\system32\DRIVERS\termdd.sys
2011/05/02 16:30:00.0659 5380 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/05/02 16:30:00.0735 5380 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/05/02 16:30:00.0784 5380 tunnel (6042505ff6fa9ac1ef7684d0e03b6940) C:\Windows\system32\DRIVERS\tunnel.sys
2011/05/02 16:30:00.0832 5380 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/05/02 16:30:00.0886 5380 udfs (8b5088058fa1d1cd897a2113ccff6c58) C:\Windows\system32\DRIVERS\udfs.sys
2011/05/02 16:30:00.0968 5380 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/05/02 16:30:01.0090 5380 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/05/02 16:30:01.0128 5380 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/05/02 16:30:01.0169 5380 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/05/02 16:30:01.0209 5380 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/05/02 16:30:01.0314 5380 upperdev (bb16932a4189e82d6c455042c11849b6) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
2011/05/02 16:30:01.0377 5380 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys
2011/05/02 16:30:01.0422 5380 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/05/02 16:30:01.0573 5380 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/05/02 16:30:01.0641 5380 usbehci (cebe90821810e76320155beba722fcf9) C:\Windows\system32\DRIVERS\usbehci.sys
2011/05/02 16:30:01.0722 5380 usbhub (cc6b28e4ce39951357963119ce47b143) C:\Windows\system32\DRIVERS\usbhub.sys
2011/05/02 16:30:01.0781 5380 usbohci (7bdb7b0e7d45ac0402d78b90789ef47c) C:\Windows\system32\DRIVERS\usbohci.sys
2011/05/02 16:30:01.0865 5380 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys
2011/05/02 16:30:01.0979 5380 usbser (a96191470581a7091420d25ecd444502) C:\Windows\system32\DRIVERS\usbser.sys
2011/05/02 16:30:02.0059 5380 USBSTOR (87ba6b83c5d19b69160968d07d6e2982) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/05/02 16:30:02.0138 5380 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/05/02 16:30:02.0184 5380 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
2011/05/02 16:30:02.0276 5380 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/05/02 16:30:02.0367 5380 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/05/02 16:30:02.0443 5380 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2011/05/02 16:30:02.0560 5380 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2011/05/02 16:30:02.0662 5380 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/05/02 16:30:02.0741 5380 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/05/02 16:30:02.0917 5380 volmgrx (98f5ffe6316bd74e9e2c97206c190196) C:\Windows\system32\drivers\volmgrx.sys
2011/05/02 16:30:02.0973 5380 volsnap (d8b4a53dd2769f226b3eb374374987c9) C:\Windows\system32\drivers\volsnap.sys
2011/05/02 16:30:03.0026 5380 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2011/05/02 16:30:03.0110 5380 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/05/02 16:30:03.0232 5380 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/02 16:30:03.0266 5380 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/02 16:30:03.0568 5380 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2011/05/02 16:30:03.0682 5380 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/05/02 16:30:04.0152 5380 winachsf (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
2011/05/02 16:30:04.0619 5380 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/05/02 16:30:04.0964 5380 WpdUsb (0cec23084b51b8288099eb710224e955) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/05/02 16:30:05.0098 5380 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/05/02 16:30:05.0300 5380 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/05/02 16:30:05.0439 5380 ================================================================================
2011/05/02 16:30:05.0440 5380 Scan finished
2011/05/02 16:30:05.0440 5380 ================================================================================


schon mal der Report

ich starte jetzt unhide.exe



Bin echt gespannt :)

Basti7 02.05.2011 15:40

unhide abgeschlossen und Daten sind wieder sichtbar.

soweit schonmal vielen, vielen Dank.
gehts noch weiter?

cosinus 02.05.2011 15:50

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Basti7 02.05.2011 16:38

so ein Mist : habe alles augeführt und nach dem neustart ist mein Laptop( vielleicht zu heiß geworden?) ausgegangen, und zwar beim erstellen der text datei :

ComboFix 11-05-01.04 - Basti 02.05.2011 17:09:45.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.49.1031.18.3069.1750 [GMT 2:00]
ausgeführt von:: C:\Users\Basti\Desktop\cofi.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

soll ich die schritte nochmal durchgehen bzw combofix nochmal starten?

Basti7 02.05.2011 17:45

Combofix Logfile:
Code:

ComboFix 11-05-01.04 - Basti 02.05.2011  18:25:46.3.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6001.1.1252.49.1031.18.3069.1887 [GMT 2:00]
ausgeführt von:: c:\users\Basti\Desktop\cofi.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-04-02 bis 2011-05-02  ))))))))))))))))))))))))))))))
.
.
2011-05-02 16:34 . 2011-05-02 16:34        --------        d-----w-        c:\users\Basti\AppData\Local\temp
2011-05-02 16:34 . 2011-05-02 16:34        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-05-02 15:41 . 2011-04-18 07:15        7071056        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2B6ED82E-EE30-4BC3-83D2-3C9B06D0476D}\mpengine.dll
2011-05-02 12:51 . 2011-05-02 12:51        --------        d-----w-        C:\_OTL
2011-04-29 20:56 . 2011-04-29 20:56        --------        d-----w-        c:\users\Basti\AppData\Roaming\Malwarebytes
2011-04-29 20:55 . 2010-12-20 16:09        38224        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-29 20:55 . 2011-04-29 20:55        --------        d-----w-        c:\programdata\Malwarebytes
2011-04-29 20:55 . 2010-12-20 16:08        20952        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-04-29 20:55 . 2011-04-29 20:55        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2011-04-29 01:01 . 2011-04-29 01:01        --------        d-----w-        C:\864b01153e3fdf37d2b00c296bc673
2011-04-28 14:44 . 2011-03-03 14:56        28672        ----a-w-        c:\windows\system32\Apphlpdm.dll
2011-04-28 14:44 . 2011-03-03 13:01        4240384        ----a-w-        c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-27 23:03 . 2011-04-27 23:03        --------        d-----w-        c:\program files\CCleaner
2011-04-27 16:58 . 2011-04-27 16:58        --------        d-----w-        c:\program files\Autorun Angel
2011-04-24 22:47 . 2011-04-24 22:47        --------        d-----w-        c:\users\Basti\AppData\Local\Hewlett-Packard
2011-04-24 22:39 . 2011-04-18 07:15        7071056        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-04-23 11:43 . 2011-04-23 11:43        --------        d-----w-        c:\users\Default\AppData\Roaming\Apple Computer
2011-04-23 11:43 . 2011-04-23 11:43        --------        d-----w-        c:\users\Default\AppData\Local\Apple Computer
2011-04-23 09:33 . 2011-04-23 09:33        --------        d-----w-        c:\users\Default\AppData\Local\Microsoft Help
2011-04-23 03:50 . 2010-11-30 09:43        439632        ------w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{833E3C26-5181-43A0-B116-3A6D25999A37}\gapaengine.dll
2011-04-23 02:51 . 2011-04-23 02:53        --------        d-----w-        c:\program files\Microsoft Security Client
2011-04-22 17:11 . 2011-05-01 15:16        --------        d-----w-        c:\programdata\Kaspersky Lab Setup Files
2011-04-22 12:42 . 2011-04-11 07:04        7071056        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{DD666115-A1E9-4B59-BE2B-A1A96B8996FD}\mpengine.dll
2011-04-14 17:59 . 2011-02-16 15:29        34304        ----a-w-        c:\windows\system32\atmlib.dll
2011-04-14 17:59 . 2011-02-16 13:24        292864        ----a-w-        c:\windows\system32\atmfd.dll
2011-04-14 17:59 . 2011-02-22 12:52        213504        ----a-w-        c:\windows\system32\drivers\mrxsmb10.sys
2011-04-14 17:59 . 2011-02-22 12:52        79360        ----a-w-        c:\windows\system32\drivers\mrxsmb20.sys
2011-04-14 17:59 . 2011-02-22 12:51        105984        ----a-w-        c:\windows\system32\drivers\mrxsmb.sys
2011-04-14 17:59 . 2011-02-22 12:51        69632        ----a-w-        c:\windows\system32\drivers\bowser.sys
2011-04-14 17:59 . 2011-03-10 16:12        1161728        ----a-w-        c:\windows\system32\mfc42u.dll
2011-04-14 17:59 . 2011-03-10 16:12        1136640        ----a-w-        c:\windows\system32\mfc42.dll
2011-04-14 17:59 . 2011-02-18 13:31        304640        ----a-w-        c:\windows\system32\drivers\srv.sys
2011-04-14 17:59 . 2011-02-18 13:31        146432        ----a-w-        c:\windows\system32\drivers\srv2.sys
2011-04-14 17:59 . 2011-02-18 13:31        102400        ----a-w-        c:\windows\system32\drivers\srvnet.sys
2011-04-14 17:57 . 2011-03-03 10:49        2409784        ----a-w-        c:\program files\Windows Mail\OESpamFilter.dat
2011-04-12 13:02 . 2011-04-12 13:02        --------        d-----w-        c:\windows\system32\EventProviders
2011-04-07 23:50 . 2010-01-01 08:00        135168        ----a-w-        c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-04-07 23:50 . 2011-03-08 23:36        49152        ----a-w-        c:\program files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components\XPATLCOM.dll
2011-04-07 23:50 . 2010-01-01 08:00        8704        ----a-w-        c:\program files\Mozilla Firefox\mozalloc.dll
2011-04-07 23:50 . 2010-01-01 08:00        774144        ----a-w-        c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-04-07 23:50 . 2010-01-01 08:00        720896        ----a-w-        c:\program files\Mozilla Firefox\libGLESv2.dll
2011-04-07 23:50 . 2010-01-01 08:00        1974616        ----a-w-        c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-04-07 23:50 . 2010-01-01 08:00        1892184        ----a-w-        c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-04-07 23:50 . 2010-01-01 08:00        1867776        ----a-w-        c:\program files\Mozilla Firefox\mozjs.dll
2011-04-07 23:50 . 2010-01-01 08:00        135168        ----a-w-        c:\program files\Mozilla Firefox\libEGL.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-03 14:56 . 2011-04-28 14:44        173056        ----a-w-        c:\windows\apppatch\AcXtrnal.dll
2011-03-03 14:56 . 2011-04-28 14:44        459776        ----a-w-        c:\windows\apppatch\AcSpecfc.dll
2011-03-03 14:56 . 2011-04-28 14:44        2153984        ----a-w-        c:\windows\apppatch\AcGenral.dll
2011-03-03 14:56 . 2011-04-28 14:44        541696        ----a-w-        c:\windows\apppatch\AcLayers.dll
2011-02-02 20:40 . 2010-05-06 01:00        472808        ----a-w-        c:\windows\system32\deployJava1.dll
2010-01-01 08:00 . 2011-04-07 23:50        135168        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-01 554288]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
.
c:\users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-1-16 727592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2011-01-05 08:18        133432        ----a-w-        c:\program files\ICQ7.1\ICQ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2007-01-19 10:55        5674352        ----a-w-        c:\program files\MSN Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R1 MpKsl2aa47320;MpKsl2aa47320;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CA4F610B-8554-4819-9F87-A07676D91B2E}\MpKsl2aa47320.sys [x]
R1 MpKsl2bc25f13;MpKsl2bc25f13;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4C690F24-9248-496F-8A71-9857976DD880}\MpKsl2bc25f13.sys [x]
R1 MpKsl605b82a4;MpKsl605b82a4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4C690F24-9248-496F-8A71-9857976DD880}\MpKsl605b82a4.sys [x]
R1 MpKsl91d2fe12;MpKsl91d2fe12;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D6D0CB9E-5D18-428D-BFBB-395754A19FC4}\MpKsl91d2fe12.sys [x]
R1 MpKslbbca455d;MpKslbbca455d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EACB07E9-977D-4BC1-8F99-AB480491753A}\MpKslbbca455d.sys [x]
R1 MpKslf3bdd319;MpKslf3bdd319;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EACB07E9-977D-4BC1-8F99-AB480491753A}\MpKslf3bdd319.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-20 136176]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-20 136176]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 M9207;LifeView M9207 USB Digital TV BOX;c:\windows\system32\DRIVERS\M9207BDA.sys [2005-09-23 36096]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_9a642328\aestsrv.exe [2008-02-12 73728]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-18 19456]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-03-26 341328]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-01-24 52736]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-04-11 84240]
S3 jumi;%Jumi%;c:\windows\system32\DRIVERS\jumi.sys [2010-06-03 13112]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs        REG_MULTI_SZ          BthServ
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 12:06        451872        ----a-w-        c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2011-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-20 10:07]
.
2011-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-20 10:07]
.
2011-05-02 c:\windows\Tasks\User_Feed_Synchronization-{4AD6CB10-A3E1-46A1-808C-09598B52C3FE}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=83&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=83&bd=Pavilion&pf=cnnb
IE: &AOL Toolbar-Suche - c:\programdata\AOL\ieToolbar\resources\de-DE\local\search.html
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Free YouTube Download - c:\users\Basti\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
FF - ProfilePath - c:\users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\la5trnmw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://de.yahoo.com/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{EEE6C35D-6118-11DC-9C72-001320C79847} - c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKLM-Run-SysTrayApp - %ProgramFiles%\IDT\WDM\sttray.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2011-05-02 18:34
Windows 6.0.6001 Service Pack 1 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(5064)
c:\windows\system32\btmmhook.dll
.
Zeit der Fertigstellung: 2011-05-02  18:37:16
ComboFix-quarantined-files.txt  2011-05-02 16:37
.
Vor Suchlauf: 1.535.115.264 Bytes frei
Nach Suchlauf: 1.430.265.856 Bytes frei
.
- - End Of File - - 7386F274D42B0F53E6EF4EDBEC7533A1

--- --- ---

cosinus 02.05.2011 19:32

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.


Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

Basti7 02.05.2011 19:51

GMER funktioniert nicht und schließt dann automatisch, daher geh ich dann jetzt zu OSAM über:kaffee:

Basti7 02.05.2011 20:02

Ich kann die OSAM RAR Datei irgendwie nicht entpacken. So als wenn ich kein geeignetes Programm dafür hätte.

wie entpacke ich das hxxp://www2.online-solutions.ru/en/download_file.php?p=131115 ?

Entschuldige, hab grade so gar keinen Durchblick.

cosinus 02.05.2011 20:44

WinRAR oder 7zip nutzen!

Basti7 02.05.2011 21:41

:) danke.
OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
Online Solutions. Complex Protection for Information Systems
Saved at 22:39:29 on 02.05.2011

OS: Windows Vista Home Premium Edition Service Pack 1 (Build 6001), 32-bit
Default Browser: Mozilla Corporation Firefox 4.0

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"hpaccelerometercp.CPL" - "Hewlett-Packard Corporation" - C:\Windows\system32\hpaccelerometercp.CPL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"ProtectSmart Hard Drive Protection" - "Hewlett-Packard Corporation" - C:\Windows\system32\hpaccelerometercp.CPL
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"catchme" (catchme) - ? - C:\Users\Basti\AppData\Local\Temp\catchme.sys  (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"MpKsl2aa47320" (MpKsl2aa47320) - ? - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CA4F610B-8554-4819-9F87-A07676D91B2E}\MpKsl2aa47320.sys  (File not found)
"MpKsl2bc25f13" (MpKsl2bc25f13) - ? - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4C690F24-9248-496F-8A71-9857976DD880}\MpKsl2bc25f13.sys  (File not found)
"MpKsl605b82a4" (MpKsl605b82a4) - ? - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4C690F24-9248-496F-8A71-9857976DD880}\MpKsl605b82a4.sys  (File not found)
"MpKsl91d2fe12" (MpKsl91d2fe12) - ? - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D6D0CB9E-5D18-428D-BFBB-395754A19FC4}\MpKsl91d2fe12.sys  (File not found)
"MpKslbbca455d" (MpKslbbca455d) - ? - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{EACB07E9-977D-4BC1-8F99-AB480491753A}\MpKslbbca455d.sys  (File not found)
"MpKslf3bdd319" (MpKslf3bdd319) - ? - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{EACB07E9-977D-4BC1-8F99-AB480491753A}\MpKslf3bdd319.sys  (File not found)

[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{10880D85-AAD9-4558-ABDC-2AB1552D831F} "LightScribe Control Panel" - "Hewlett-Packard Company" - "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{09A47860-11B0-4DA5-AFA5-26D86198A780} "EPP" - "Microsoft Corporation" - c:\PROGRA~1\MICROS~4\shellext.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -  (File not found | COM-object registry key not found)
{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} "Meine freigegebenen Ordner" - "Microsoft Corporation" - C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\ONFILTER.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - ? -  (File not found | COM-object registry key not found)
{7F67036B-66F1-411A-AD85-759FB9C5B0DB} "ShellViewRTF" - "XSS" - C:\Windows\System32\ShellvRTF.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - ? - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "AOL Toolbar" - "AOL LLC" - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} "Java Plug-in 1.6.0_05" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
"ICQ7.1" - "ICQ, LLC." - C:\Program Files\ICQ7.1\ICQ.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{DE9C389F-3316-41A7-809B-AA305ED9D922} "AOL Toolbar" - "AOL LLC" - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{7C554162-8CB7-45A4-B8F4-8EA1C75885F9} "AOL Toolbar BHO" - "AOL LLC" - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"OpenOffice.org 3.2.lnk" - ? - C:\Program Files\OpenOffice.org 3\program\quickstart.exe  (Shortcut exists | File found, but it contains no detailed information | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"BTTray.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"LightScribe Control Panel" - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"HP Health Check Scheduler" - "Hewlett-Packard" - c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
"HP Software Update" - "Hewlett-Packard" - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
"hpWirelessAssistant" - "Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"Malwarebytes' Anti-Malware (reboot)" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
"MSC" - "Microsoft Corporation" - "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"OnScreenDisplay" - " Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
"QlbCtrl.exe" - " Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"UCam_Menu" - "CyberLink Corp." - "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243" (NisSrv) - "Microsoft Corporation" - c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
"@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Com4QLBEx" (Com4QLBEx) - "Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Easybits Shared Services for Windows" (ezSharedSvc) - "EasyBits Sofware AS" - C:\Windows\System32\ezsvc7.dll
"GameConsoleService" (GameConsoleService) - "WildTangent, Inc." - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"HP Health Check Service" (HP Health Check Service) - "Hewlett-Packard" - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
"hpqwmiex" (hpqwmiex) - "Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Antimalware Service" (MsMpSvc) - "Microsoft Corporation" - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Recovery Service for Windows" (Recovery Service for Windows) - ? - C:\Windows\SMINST\BLService.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---
If You have questions or want to get some help, You can visit Online Solutions :: Index

Basti7 02.05.2011 21:45

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 1 (build 6001), 32-bit
Base Board Manufacturer: Hewlett-Packard
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dv7 Notebook PC
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 202):
0x82013000 \SystemRoot\system32\ntkrnlpa.exe
0x823CC000 \SystemRoot\system32\hal.dll
0x8040C000 \SystemRoot\system32\kdcom.dll
0x80414000 \SystemRoot\system32\PSHED.dll
0x80425000 \SystemRoot\system32\BOOTVID.dll
0x8042D000 \SystemRoot\system32\CLFS.SYS
0x8046E000 \SystemRoot\system32\CI.dll
0x8054E000 \SystemRoot\system32\drivers\Wdf01000.sys
0x805CA000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80608000 \SystemRoot\system32\drivers\acpi.sys
0x8064E000 \SystemRoot\system32\drivers\WMILIB.SYS
0x80657000 \SystemRoot\system32\drivers\msisadrv.sys
0x8065F000 \SystemRoot\system32\drivers\pci.sys
0x80686000 \SystemRoot\system32\drivers\isapnp.sys
0x80695000 \SystemRoot\system32\drivers\mpio.sys
0x806B1000 \SystemRoot\System32\drivers\partmgr.sys
0x806C0000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x806C3000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x806CD000 \SystemRoot\system32\drivers\volmgr.sys
0x806DC000 \SystemRoot\System32\drivers\volmgrx.sys
0x80726000 \SystemRoot\system32\drivers\intelide.sys
0x8072D000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x8073B000 \SystemRoot\system32\drivers\pciide.sys
0x80742000 \SystemRoot\system32\drivers\aliide.sys
0x80749000 \SystemRoot\system32\drivers\amdide.sys
0x80750000 \SystemRoot\system32\drivers\cmdide.sys
0x80758000 \SystemRoot\System32\drivers\mountmgr.sys
0x80768000 \SystemRoot\system32\drivers\msdsm.sys
0x80782000 \SystemRoot\system32\drivers\nvraid.sys
0x8079D000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x807BE000 \SystemRoot\system32\drivers\viaide.sys
0x82601000 \SystemRoot\system32\drivers\iastorv.sys
0x826A2000 \SystemRoot\system32\drivers\atapi.sys
0x826AA000 \SystemRoot\system32\drivers\ataport.SYS
0x826C8000 \SystemRoot\system32\drivers\lsi_scsi.sys
0x826E2000 \SystemRoot\system32\drivers\storport.sys
0x82723000 \SystemRoot\system32\drivers\nvstor.sys
0x82730000 \SystemRoot\system32\drivers\msahci.sys
0x8273A000 \SystemRoot\system32\drivers\hpcisss.sys
0x82745000 \SystemRoot\system32\drivers\adp94xx.sys
0x827AF000 \SystemRoot\system32\drivers\adpahci.sys
0x807C6000 \SystemRoot\system32\drivers\adpu160m.sys
0x805D7000 \SystemRoot\system32\drivers\SCSIPORT.SYS
0x8A807000 \SystemRoot\system32\drivers\adpu320.sys
0x8A82D000 \SystemRoot\system32\drivers\djsvs.sys
0x8A841000 \SystemRoot\system32\drivers\arc.sys
0x8A857000 \SystemRoot\system32\drivers\arcsas.sys
0x8A86D000 \SystemRoot\system32\drivers\elxstor.sys
0x8A901000 \SystemRoot\system32\drivers\i2omp.sys
0x8A90B000 \SystemRoot\system32\drivers\iirsp.sys
0x8A91B000 \SystemRoot\system32\drivers\iteatapi.sys
0x8A927000 \SystemRoot\system32\drivers\iteraid.sys
0x8A933000 \SystemRoot\system32\drivers\lsi_fc.sys
0x8A94D000 \SystemRoot\system32\drivers\lsi_sas.sys
0x8A965000 \SystemRoot\system32\drivers\megasas.sys
0x8AA09000 \SystemRoot\system32\drivers\megasr.sys
0x8AAC0000 \SystemRoot\system32\drivers\mraid35x.sys
0x8AACB000 \SystemRoot\system32\drivers\nfrd960.sys
0x8AC07000 \SystemRoot\system32\drivers\ql2300.sys
0x8AD3F000 \SystemRoot\system32\drivers\ql40xx.sys
0x8AD94000 \SystemRoot\system32\drivers\sisraid2.sys
0x8ADA1000 \SystemRoot\system32\drivers\sisraid4.sys
0x8ADB6000 \SystemRoot\system32\drivers\symc8xx.sys
0x8ADC2000 \SystemRoot\system32\drivers\sym_hi.sys
0x8ADCD000 \SystemRoot\system32\drivers\sym_u3.sys
0x8AAD9000 \SystemRoot\system32\drivers\uliahci.sys
0x8ADD8000 \SystemRoot\system32\drivers\ulsata.sys
0x8AB15000 \SystemRoot\system32\drivers\ulsata2.sys
0x8AB41000 \SystemRoot\system32\drivers\vsmraid.sys
0x8AB62000 \SystemRoot\system32\drivers\fltmgr.sys
0x8AB94000 \SystemRoot\system32\drivers\fileinfo.sys
0x8A96F000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8AE08000 \SystemRoot\system32\drivers\ndis.sys
0x8AF13000 \SystemRoot\system32\drivers\msrpc.sys
0x8AF3E000 \SystemRoot\system32\drivers\NETIO.SYS
0x8B00C000 \SystemRoot\System32\drivers\tcpip.sys
0x8B0F6000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8B209000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B318000 \SystemRoot\system32\drivers\wd.sys
0x8B320000 \SystemRoot\system32\drivers\volsnap.sys
0x8B359000 \SystemRoot\System32\Drivers\spldr.sys
0x8B361000 \SystemRoot\system32\drivers\sbp2port.sys
0x8B376000 \SystemRoot\System32\Drivers\mup.sys
0x8B385000 \SystemRoot\System32\drivers\ecache.sys
0x8B3AC000 \SystemRoot\system32\DRIVERS\hpdskflt.sys
0x8B3B5000 \SystemRoot\system32\drivers\disk.sys
0x8B3C6000 \SystemRoot\system32\DRIVERS\AtiPcie.sys
0x8B3CE000 \SystemRoot\system32\drivers\crcdisk.sys
0x8B111000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8B200000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8B11C000 \SystemRoot\system32\DRIVERS\processr.sys
0x9EC04000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x9F0D3000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x9F172000 \SystemRoot\System32\drivers\watchdog.sys
0x9F17F000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x9F191000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x9F1A1000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x9F1AF000 \SystemRoot\system32\DRIVERS\jmcr.sys
0x9F809000 \SystemRoot\system32\DRIVERS\athr.sys
0x9F8ED000 \SystemRoot\system32\DRIVERS\Rtlh86.sys
0x9F90E000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x9F926000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x9F92C000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x9F936000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x9F974000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x9F983000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x9F996000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
0x9F99B000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x9F9A6000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x9F9D5000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x9F9D7000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x9F9E2000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x9F9E6000 \SystemRoot\system32\DRIVERS\enecir.sys
0x9F1C4000 \SystemRoot\system32\DRIVERS\Accelerometer.sys
0x9F800000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x9F9FE000 \SystemRoot\system32\DRIVERS\jumi.sys
0x9F1CF000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x9F1DF000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8B12B000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x9F1E6000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8B159000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x9F1F1000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8B170000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8B193000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8B1A2000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8B1B6000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8B1CB000 \SystemRoot\system32\DRIVERS\termdd.sys
0x9F1FC000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8AF78000 \SystemRoot\system32\DRIVERS\ks.sys
0x8B1DB000 \SystemRoot\system32\DRIVERS\circlass.sys
0x8B1E9000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8B1F3000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8AFA2000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8B000000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8AFD6000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x8AFDF000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8ABA4000 \SystemRoot\system32\drivers\HdAudio.sys
0xA2405000 \SystemRoot\system32\drivers\portcls.sys
0xA2432000 \SystemRoot\system32\drivers\drmk.sys
0xA2457000 \SystemRoot\system32\DRIVERS\stwrt.sys
0xA24B8000 \SystemRoot\system32\DRIVERS\hidir.sys
0xA24C3000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0xA24EA000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xA24F3000 \SystemRoot\System32\Drivers\Null.SYS
0xA24FA000 \SystemRoot\System32\Drivers\Beep.SYS
0xA2501000 \SystemRoot\System32\drivers\vga.sys
0xA250D000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0xA252E000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xA2536000 \SystemRoot\system32\drivers\rdpencdd.sys
0xA253E000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xA2555000 \SystemRoot\System32\Drivers\usbvideo.sys
0xA2576000 \SystemRoot\System32\Drivers\Msfs.SYS
0xA2581000 \SystemRoot\System32\Drivers\Npfs.SYS
0xA258F000 \SystemRoot\System32\DRIVERS\rasacd.sys
0xA2598000 \SystemRoot\system32\DRIVERS\tdx.sys
0xA25AE000 \SystemRoot\system32\DRIVERS\smb.sys
0xA260E000 \SystemRoot\system32\drivers\afd.sys
0xA2656000 \SystemRoot\System32\DRIVERS\netbt.sys
0xA2688000 \SystemRoot\system32\DRIVERS\pacer.sys
0xA269E000 \SystemRoot\system32\DRIVERS\netbios.sys
0xA26AC000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xA26BF000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xA26FB000 \SystemRoot\System32\Drivers\BTHUSB.sys
0xA2708000 \SystemRoot\System32\Drivers\bthport.sys
0xA2788000 \SystemRoot\system32\drivers\nsiproxy.sys
0xA279B000 \SystemRoot\system32\DRIVERS\BdaSup.SYS
0xA279E000 \SystemRoot\System32\Drivers\dfsc.sys
0xA27B5000 \SystemRoot\system32\DRIVERS\rfcomm.sys
0xA27DE000 \SystemRoot\system32\DRIVERS\BthEnum.sys
0xA25C2000 \SystemRoot\system32\DRIVERS\bthpan.sys
0xA2801000 \SystemRoot\system32\drivers\btwavdt.sys
0xA2868000 \SystemRoot\system32\drivers\btwaudio.sys
0xA28E8000 \SystemRoot\system32\DRIVERS\btwrchid.sys
0xA28EB000 \SystemRoot\System32\Drivers\crashdmp.sys
0xA28F8000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0xA2903000 \SystemRoot\System32\Drivers\dump_msahci.sys
0xAA460000 \SystemRoot\System32\win32k.sys
0xA290D000 \SystemRoot\System32\drivers\Dxapi.sys
0xA2917000 \SystemRoot\system32\DRIVERS\monitor.sys
0xAA680000 \SystemRoot\System32\TSDDD.dll
0xAA6A0000 \SystemRoot\System32\cdd.dll
0xA2926000 \SystemRoot\system32\drivers\luafv.sys
0xA2941000 \SystemRoot\system32\drivers\spsys.sys
0xA29F0000 \SystemRoot\system32\DRIVERS\lltdio.sys
0xAC809000 \SystemRoot\system32\DRIVERS\nwifi.sys
0xAC833000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xAC83D000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xAC850000 \SystemRoot\system32\drivers\HTTP.sys
0xAC8BD000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xAC8DA000 \SystemRoot\system32\DRIVERS\bowser.sys
0xAC8F3000 \SystemRoot\System32\drivers\mpsdrv.sys
0xAC908000 \SystemRoot\system32\drivers\mrxdav.sys
0xAC928000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xAC947000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xAC980000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xAC998000 \SystemRoot\System32\DRIVERS\srv2.sys
0xB0A0D000 \SystemRoot\System32\DRIVERS\srv.sys
0xB0A74000 \SystemRoot\system32\drivers\peauth.sys
0xB0B52000 \SystemRoot\System32\Drivers\secdrv.SYS
0xB0B5C000 \SystemRoot\System32\drivers\tcpipreg.sys
0xB0B68000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x77480000 \WINDOWS\System32\ntdll.dll

Processes (total 81):
0 System Idle Process
4 System
448 C:\WINDOWS\System32\smss.exe
580 csrss.exe
640 C:\WINDOWS\System32\wininit.exe
656 csrss.exe
688 C:\WINDOWS\System32\services.exe
700 C:\WINDOWS\System32\lsass.exe
708 C:\WINDOWS\System32\lsm.exe
852 C:\WINDOWS\System32\svchost.exe
888 C:\WINDOWS\System32\winlogon.exe
960 C:\WINDOWS\System32\svchost.exe
1000 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
1092 C:\WINDOWS\System32\Ati2evxx.exe
1116 C:\WINDOWS\System32\svchost.exe
1148 C:\WINDOWS\System32\svchost.exe
1192 C:\WINDOWS\System32\svchost.exe
1204 C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\stacsv.exe
1292 C:\WINDOWS\System32\audiodg.exe
1500 C:\WINDOWS\System32\SLsvc.exe
1536 C:\WINDOWS\System32\svchost.exe
1616 C:\WINDOWS\System32\Ati2evxx.exe
1672 C:\WINDOWS\System32\hpservice.exe
1764 C:\WINDOWS\System32\svchost.exe
1972 C:\WINDOWS\System32\dwm.exe
2024 C:\WINDOWS\explorer.exe
2032 C:\WINDOWS\System32\wlanext.exe
384 C:\WINDOWS\System32\spoolsv.exe
12 C:\WINDOWS\System32\svchost.exe
568 C:\WINDOWS\System32\taskeng.exe
1796 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1560 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
2080 C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
2148 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
2172 C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_9a642328\AEstSrv.exe
2188 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
2200 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
2240 C:\Program Files\Bonjour\mDNSResponder.exe
2248 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
2260 C:\WINDOWS\System32\svchost.exe
2304 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
2476 C:\WINDOWS\System32\svchost.exe
2544 C:\WINDOWS\SMINST\BLService.exe
2552 C:\Program Files\iTunes\iTunesHelper.exe
2612 C:\Program Files\Common Files\Java\Java Update\jusched.exe
2632 C:\WINDOWS\System32\taskeng.exe
2656 C:\Program Files\Microsoft Security Client\msseces.exe
2708 C:\Program Files\CyberLink\Shared Files\RichVideo.exe
2776 C:\Program Files\Windows Sidebar\sidebar.exe
2880 C:\WINDOWS\System32\svchost.exe
2904 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
2984 C:\WINDOWS\System32\svchost.exe
3036 C:\WINDOWS\System32\SearchIndexer.exe
3108 C:\WINDOWS\ehome\ehtray.exe
3228 C:\Program Files\Windows Media Player\wmpnscfg.exe
3332 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
3504 C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
3624 WmiPrvSE.exe
3652 C:\Program Files\OpenOffice.org 3\program\soffice.exe
3780 C:\Program Files\OpenOffice.org 3\program\soffice.bin
3916 C:\WINDOWS\ehome\ehmsas.exe
3980 C:\Program Files\Windows Media Player\wmpnetwk.exe
4064 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
1440 C:\WINDOWS\ehome\ehsched.exe
2212 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
3100 C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
2964 C:\Program Files\iPod\bin\iPodService.exe
3544 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
2992 C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
4216 C:\WINDOWS\ehome\ehrecvr.exe
4904 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
5672 C:\Users\Basti\Downloads\osam.exe
5688 C:\WINDOWS\System32\SearchProtocolHost.exe
6108 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
4716 C:\WINDOWS\System32\wuauclt.exe
5832 C:\WINDOWS\System32\notepad.exe
3720 C:\Program Files\Mozilla Firefox\firefox.exe
1660 C:\WINDOWS\System32\SearchFilterHost.exe
4856 C:\WINDOWS\explorer.exe
2960 C:\Users\Basti\Desktop\MBRCheck.exe
4896 C:\WINDOWS\System32\conime.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000038`02700000 (NTFS)

PhysicalDrive0 Model Number: WDCWD2500BEVS-60UST0, Rev: 01.01A01

Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 08F21ADD893776C287CC68A3558F8D095B50ED3C


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!

Basti7 02.05.2011 21:56

Entschuldige daß es so lang gedauert hat, mein Rechner geht neuerdings einfach aus zwischendurch...

cosinus 02.05.2011 21:57

Wir sollten den MBR manuell fixen. Sichere für den Fall der Fälle alle wichtigen Daten.

Hast Du noch andere Betriebssysteme außer Vista installiert?
Wenn nicht: Schau mal hier => Vista Notfall/Recovery-CD 32-Bit - Dr. Windows

Lad das iso runter, brenn es zB mit ImgBurn per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten).

Falls Du eine normale Vista-Installations-DVD hast, brauchst Du das o.g. Image nicht sondern kannst einfach von der Vista-DVD booten.

Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen. Erstell danach wieder neue Logs mit MBRCheck und wenn es geht GMER.

Basti7 02.05.2011 22:30

hm ja das wird ein weilchen dauern und ich hoffe mein laptop geht nicht wieder aus mittendrin..:glaskugel:

Basti7 04.05.2011 15:52

Hi Arne,
also bei mir hat so gut wie nix geklappt. Hab mir das Iso runtergeladen, aber mein computer war nicht fähig es zu brennen (weiß leider nicht genau warum, vermute es liegt am Laufwerk bzw Brenner). Eine Vista-Installations-Dvd hab ich ,glaube ich, nicht. Außer es geht auch mit den beiden Backup dvd, welche ich direkt nach der erstinstallation gebrannt habe. geht das?

entschuldige meine Computerunfähigkeit...

cosinus 04.05.2011 16:02

Wenn du nicht weißt warum, wie kommst du auf den Brenner?
Wie du ein Image brennst ist dir bekannt?

Basti7 04.05.2011 16:41

hm ja, ich dachte zumindest ich hätte alles richtig gemacht, aber ich bin nu mehr als unsicher.


ich zeig dir mal die Logs der Versuche:

; //****************************************\\
; ImgBurn Version 2.5.5.0 - Log
; Dienstag, 03 Mai 2011, 23:33:20
; \\****************************************//
;
;
I 23:32:40 ImgBurn Version 2.5.5.0 started!
I 23:32:40 Microsoft Windows Vista Home Premium Edition (6.0, Build 6001 : Service Pack 1)
I 23:32:40 Total Physical Memory: 3.142.744 KB - Available: 2.149.328 KB
I 23:32:40 Initialising SPTI...
I 23:32:40 Searching for SCSI / ATAPI devices...
I 23:32:49 Close Request Acknowledged
I 23:32:49 Closing Down...
I 23:33:20 -> Drive 1 - Info: TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 23:33:20 Found 1 DVD±RW/RAM!
I 23:33:20 Shutting down SPTI...
I 23:33:20 ImgBurn closed!
;
;
; //****************************************\\
; ImgBurn Version 2.5.5.0 - Log
; Dienstag, 03 Mai 2011, 18:56:08
; \\****************************************//
;
;
I 18:30:47 ImgBurn Version 2.5.5.0 started!
I 18:30:47 Microsoft Windows Vista Home Premium Edition (6.0, Build 6001 : Service Pack 1)
I 18:30:47 Total Physical Memory: 3.142.744 KB - Available: 1.753.332 KB
I 18:30:47 Initialising SPTI...
I 18:30:47 Searching for SCSI / ATAPI devices...
I 18:30:47 -> Drive 1 - Info: TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 18:30:47 Found 1 DVD±RW/RAM!
I 18:31:01 Operation Started!
I 18:31:01 Source File: C:\Users\Basti\Desktop\vista_recover_x86.iso
I 18:31:01 Source File Sectors: 73.642 (MODE1/2048)
I 18:31:01 Source File Size: 150.818.816 bytes
I 18:31:01 Source File Volume Identifier: LRMCFRE_DE_DVD
I 18:31:01 Source File Volume Set Identifier: cbafc000MS UDFBridge
I 18:31:01 Source File Application Identifier: OSCDIMG 2.54 (01/01/2005 TM)
I 18:31:01 Source File Implementation Identifier: Microsoft CDIMAGE UDF
I 18:31:01 Source File File System(s): ISO9660 (Bootable); UDF (1.50)
I 18:31:01 Destination Device: [3:0:0] TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 18:31:01 Destination Media Type: DVD+R (Disc ID: RICOHJPN-R03-04) (Speeds: 3x; 4x; 6x; 8x)
I 18:31:01 Destination Media Sectors: 2.295.104
I 18:31:01 Write Mode: DVD
I 18:31:01 Write Type: DAO
I 18:31:01 Write Speed: MAX
I 18:31:01 DVD+R Reserve Track: No
I 18:31:01 Link Size: Auto
I 18:31:01 Lock Volume: Yes
I 18:31:01 Test Mode: No
I 18:31:01 OPC: No
I 18:31:01 BURN-Proof: Enabled
I 18:31:01 Write Speed Successfully Set! - Effective: 11.080 KB/s (8x)
I 18:31:01 Book Type Setting: N/A (Reason: Unzulässige Funktion.)
I 18:31:02 Filling Buffer... (40 MB)
I 18:31:05 Writing LeadIn...
I 18:31:24 Writing Session 1 of 1... (1 Track, LBA: 0 - 73641)
I 18:31:24 Writing Track 1 of 1... (MODE1/2048, LBA: 0 - 73641)
I 18:31:58 Synchronising Cache...
I 18:32:11 Closing Track...
I 18:32:22 Finalising Disc...
I 18:34:02 Exporting Graph Data...
I 18:34:02 Graph Data File: C:\Users\Basti\AppData\Roaming\ImgBurn\Graph Data Files\TSSTcorp_CDDVDW_TS-L633L_0400_DIENSTAG-3-MAI-2011_18-31_RICOHJPN-R03-04_MAX.ibg
I 18:34:02 Export Successfully Completed!
I 18:34:02 Operation Successfully Completed! - Duration: 00:03:01
I 18:34:02 Average Write Rate: 4.463 KB/s (3.2x) - Maximum Write Rate: 5.016 KB/s (3.6x)
I 18:34:02 Cycling Tray before Verify...
W 18:34:15 Waiting for device to become ready...
I 18:34:54 Device Ready!
E 18:34:54 CompareImageFileLayouts Failed! - Session Count Not Equal (1/0)
E 18:34:54 Verify Failed! - Reason: Layouts do not match.
I 18:35:14 Operation Started!
I 18:35:14 Source File: C:\Users\Basti\Desktop\vista_recover_x86.iso
I 18:35:14 Source File Sectors: 73.642 (MODE1/2048)
I 18:35:14 Source File Size: 150.818.816 bytes
I 18:35:14 Source File Volume Identifier: LRMCFRE_DE_DVD
I 18:35:14 Source File Volume Set Identifier: cbafc000MS UDFBridge
I 18:35:14 Source File Application Identifier: OSCDIMG 2.54 (01/01/2005 TM)
I 18:35:14 Source File Implementation Identifier: Microsoft CDIMAGE UDF
I 18:35:14 Source File File System(s): ISO9660 (Bootable); UDF (1.50)
I 18:35:14 Destination Device: [3:0:0] TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 18:35:14 Destination Media Type: DVD+R (Disc ID: RICOHJPN-R03-04) (Speeds: 3x; 4x; 6x; 8x)
I 18:35:14 Destination Media Sectors: 2.295.104
I 18:35:14 Write Mode: DVD
I 18:35:14 Write Type: DAO
I 18:35:14 Write Speed: MAX
I 18:35:14 DVD+R Reserve Track: No
I 18:35:14 Link Size: Auto
I 18:35:14 Lock Volume: Yes
I 18:35:14 Test Mode: No
I 18:35:14 OPC: No
I 18:35:14 BURN-Proof: Enabled
I 18:35:14 Write Speed Successfully Set! - Effective: 11.080 KB/s (8x)
I 18:35:14 Book Type Setting: N/A (Reason: Unzulässige Funktion.)
I 18:35:15 Filling Buffer... (40 MB)
I 18:35:17 Writing LeadIn...
I 18:35:35 Writing Session 1 of 1... (1 Track, LBA: 0 - 73641)
I 18:35:35 Writing Track 1 of 1... (MODE1/2048, LBA: 0 - 73641)
I 18:36:08 Synchronising Cache...
I 18:36:11 Closing Track...
I 18:36:14 Finalising Disc...
I 18:37:45 Exporting Graph Data...
I 18:37:45 Graph Data File: C:\Users\Basti\AppData\Roaming\ImgBurn\Graph Data Files\TSSTcorp_CDDVDW_TS-L633L_0400_DIENSTAG-3-MAI-2011_18-35_RICOHJPN-R03-04_MAX.ibg
I 18:37:45 Export Successfully Completed!
I 18:37:45 Operation Successfully Completed! - Duration: 00:02:31
I 18:37:45 Average Write Rate: 4.602 KB/s (3.3x) - Maximum Write Rate: 5.021 KB/s (3.6x)
I 18:37:45 Cycling Tray before Verify...
I 18:38:31 Device Ready!
I 18:44:27 Operation Started!
I 18:44:27 Source Device: [3:0:0] TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 18:44:27 Source Media Type: DVD+RW
I 18:44:27 Image File: C:\Users\Basti\Desktop\vista_recover_x86.iso
I 18:44:27 Image File Sectors: 73.642 (MODE1/2048)
I 18:44:27 Image File Size: 150.818.816 bytes
I 18:44:27 Image File Volume Identifier: LRMCFRE_DE_DVD
I 18:44:27 Image File Volume Set Identifier: cbafc000MS UDFBridge
I 18:44:27 Image File Application Identifier: OSCDIMG 2.54 (01/01/2005 TM)
I 18:44:27 Image File Implementation Identifier: Microsoft CDIMAGE UDF
I 18:44:27 Image File File System(s): ISO9660 (Bootable); UDF (1.50)
I 18:44:27 Read Speed (Data/Audio): MAX / MAX
I 18:44:28 Verifying Session 1 of 1... (1 Track, LBA: 0 - 73641)
I 18:44:28 Verifying Track 1 of 1... (MODE1/2048, LBA: 0 - 73641)
W 18:44:28 Waiting for device to become ready...
I 18:44:58 Device ready!
I 18:44:58 Verifying Sectors...
W 18:45:07 Failed to Read Sector 0 - Reason: Timeout on Logical Unit
W 18:45:10 Retrying (1)...
W 18:45:19 Retry Failed - Reason: Timeout on Logical Unit
W 18:45:21 Retrying (2)...
W 18:45:30 Retry Failed - Reason: Timeout on Logical Unit
W 18:45:34 Failed to Read Sector 0 - Reason: Timeout on Logical Unit
W 18:45:42 Failed to Read Sector 1 - Reason: Timeout on Logical Unit
W 18:45:46 Failed to Read Sector 1 - Reason: Timeout on Logical Unit
W 18:45:55 Failed to Read Sector 2 - Reason: Timeout on Logical Unit
W 18:45:58 Retrying (1)...
W 18:46:06 Retry Failed - Reason: Timeout on Logical Unit
W 18:46:10 Retrying (2)...
W 18:46:18 Retry Failed - Reason: Timeout on Logical Unit
W 18:48:47 Failed to Read Sector 2 - Reason: Timeout on Logical Unit
W 18:48:58 Failed to Read Sector 3 - Reason: Timeout on Logical Unit
E 18:55:23 Failed to Read Sector 3 - Reason: Timeout on Logical Unit
E 18:55:23 Failed to Verify Sectors!
I 18:55:25 Exporting Graph Data...
I 18:55:25 Graph Data File: C:\Users\Basti\AppData\Roaming\ImgBurn\Graph Data Files\TSSTcorp_CDDVDW_TS-L633L_0400_DIENSTAG-3-MAI-2011_18-35_RICOHJPN-R03-04_MAX.ibg
I 18:55:25 Export Successfully Completed!
E 18:55:25 Operation Failed! - Duration: 00:10:56
I 18:55:25 Average Verify Rate: 0 KB/s (0.0x) - Maximum Verify Rate: 0 KB/s (0.0x)
I 18:56:08 Close Request Acknowledged
I 18:56:08 Closing Down...
I 18:56:08 Shutting down SPTI...
I 18:56:08 ImgBurn closed!
;
;
; //****************************************\\
; ImgBurn Version 2.5.5.0 - Log
; Dienstag, 03 Mai 2011, 18:29:50
; \\****************************************//
;
;
I 18:19:02 ImgBurn Version 2.5.5.0 started!
I 18:19:02 Microsoft Windows Vista Home Premium Edition (6.0, Build 6001 : Service Pack 1)
I 18:19:02 Total Physical Memory: 3.142.744 KB - Available: 1.798.064 KB
I 18:19:02 Initialising SPTI...
I 18:19:02 Searching for SCSI / ATAPI devices...
I 18:19:02 -> Drive 1 - Info: TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 18:19:02 Found 1 DVD±RW/RAM!
E 18:21:53 User attempted to burn an image file in 'Build' mode.
I 18:22:21 Operation Started!
I 18:22:21 Source File: C:\Users\Basti\Desktop\vista_recover_x86.iso
I 18:22:21 Source File Sectors: 73.642 (MODE1/2048)
I 18:22:21 Source File Size: 150.818.816 bytes
I 18:22:21 Source File Volume Identifier: LRMCFRE_DE_DVD
I 18:22:21 Source File Volume Set Identifier: cbafc000MS UDFBridge
I 18:22:21 Source File Application Identifier: OSCDIMG 2.54 (01/01/2005 TM)
I 18:22:21 Source File Implementation Identifier: Microsoft CDIMAGE UDF
I 18:22:21 Source File File System(s): ISO9660 (Bootable); UDF (1.50)
I 18:22:21 Destination Device: [3:0:0] TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 18:22:21 Destination Media Type: DVD+R (Disc ID: RICOHJPN-R03-04) (Speeds: 3x; 4x; 6x; 8x)
I 18:22:21 Destination Media Sectors: 2.295.104
I 18:22:21 Write Mode: DVD
I 18:22:21 Write Type: DAO
I 18:22:21 Write Speed: MAX
I 18:22:21 DVD+R Reserve Track: No
I 18:22:21 Link Size: Auto
I 18:22:21 Lock Volume: Yes
I 18:22:21 Test Mode: No
I 18:22:21 OPC: No
I 18:22:21 BURN-Proof: Enabled
I 18:22:24 Write Speed Successfully Set! - Effective: 11.080 KB/s (8x)
I 18:22:24 Book Type Setting: N/A (Reason: Unzulässige Funktion.)
I 18:22:25 Filling Buffer... (40 MB)
I 18:22:29 Writing LeadIn...
I 18:22:47 Writing Session 1 of 1... (1 Track, LBA: 0 - 73641)
I 18:22:47 Writing Track 1 of 1... (MODE1/2048, LBA: 0 - 73641)
I 18:23:20 Synchronising Cache...
I 18:23:23 Closing Track...
I 18:23:26 Finalising Disc...
I 18:24:57 Exporting Graph Data...
I 18:24:57 Graph Data File: C:\Users\Basti\AppData\Roaming\ImgBurn\Graph Data Files\TSSTcorp_CDDVDW_TS-L633L_0400_DIENSTAG-3-MAI-2011_18-22_RICOHJPN-R03-04_MAX.ibg
I 18:24:57 Export Successfully Completed!
I 18:24:57 Operation Successfully Completed! - Duration: 00:02:36
I 18:24:57 Average Write Rate: 4.463 KB/s (3.2x) - Maximum Write Rate: 5.046 KB/s (3.6x)
I 18:24:57 Cycling Tray before Verify...
W 18:25:34 Waiting for device to become ready...
I 18:25:47 Device Ready!
I 18:27:00 Operation Started!
I 18:27:00 Source Device: [3:0:0] TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 18:27:00 Source Media Type: DVD+RW
I 18:27:00 Image File: C:\Users\Basti\Desktop\vista_recover_x86.iso
I 18:27:00 Image File Sectors: 73.642 (MODE1/2048)
I 18:27:00 Image File Size: 150.818.816 bytes
I 18:27:00 Image File Volume Identifier: LRMCFRE_DE_DVD
I 18:27:00 Image File Volume Set Identifier: cbafc000MS UDFBridge
I 18:27:00 Image File Application Identifier: OSCDIMG 2.54 (01/01/2005 TM)
I 18:27:00 Image File Implementation Identifier: Microsoft CDIMAGE UDF
I 18:27:00 Image File File System(s): ISO9660 (Bootable); UDF (1.50)
I 18:27:00 Read Speed (Data/Audio): MAX / MAX
I 18:27:02 Verifying Session 1 of 1... (1 Track, LBA: 0 - 73641)
I 18:27:02 Verifying Track 1 of 1... (MODE1/2048, LBA: 0 - 73641)
W 18:27:02 Waiting for device to become ready...
I 18:27:50 Device ready!
I 18:27:51 Verifying Sectors...
W 18:27:59 Failed to Read Sector 0 - Reason: Timeout on Logical Unit
W 18:28:06 Retrying (1)...
W 18:28:15 Retry Failed - Reason: Timeout on Logical Unit
E 18:28:20 Failed to Read Sector 0 - Reason: Timeout on Logical Unit
E 18:28:20 Failed to Verify Sectors!
I 18:28:20 Exporting Graph Data...
I 18:28:20 Graph Data File: C:\Users\Basti\AppData\Roaming\ImgBurn\Graph Data Files\TSSTcorp_CDDVDW_TS-L633L_0400_DIENSTAG-3-MAI-2011_18-22_RICOHJPN-R03-04_MAX.ibg
I 18:28:20 Export Successfully Completed!
E 18:28:20 Operation Failed! - Duration: 00:01:19
I 18:28:20 Average Verify Rate: N/A - Maximum Verify Rate: N/A
I 18:29:43 Close Request Acknowledged
I 18:29:43 Closing Down...
I 18:29:50 Shutting down SPTI...
I 18:29:50 ImgBurn closed!
;
;
; //****************************************\\
; ImgBurn Version 2.5.5.0 - Log
; Dienstag, 03 Mai 2011, 01:04:05
; \\****************************************//
;
;
I 01:00:29 ImgBurn Version 2.5.5.0 started!
I 01:00:29 Microsoft Windows Vista Home Premium Edition (6.0, Build 6001 : Service Pack 1)
I 01:00:29 Total Physical Memory: 3.142.744 KB - Available: 2.136.800 KB
I 01:00:29 Initialising SPTI...
I 01:00:29 Searching for SCSI / ATAPI devices...
I 01:00:29 -> Drive 1 - Info: TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 01:00:29 Found 1 DVD±RW/RAM!
I 01:04:05 Close Request Acknowledged
I 01:04:05 Closing Down...
I 01:04:05 Shutting down SPTI...
I 01:04:05 ImgBurn closed!
;
;
; //****************************************\\
; ImgBurn Version 2.5.5.0 - Log
; Dienstag, 03 Mai 2011, 01:00:19
; \\****************************************//
;
;
I 00:58:12 ImgBurn Version 2.5.5.0 started!
I 00:58:12 Microsoft Windows Vista Home Premium Edition (6.0, Build 6001 : Service Pack 1)
I 00:58:12 Total Physical Memory: 3.142.744 KB - Available: 2.141.972 KB
I 00:58:12 Initialising SPTI...
I 00:58:12 Searching for SCSI / ATAPI devices...
I 00:58:13 -> Drive 1 - Info: TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 00:58:13 Found 1 DVD±RW/RAM!
I 01:00:19 Close Request Acknowledged
I 01:00:19 Closing Down...
I 01:00:19 Shutting down SPTI...
I 01:00:19 ImgBurn closed!
;
;
; //****************************************\\
; ImgBurn Version 2.5.5.0 - Log
; Dienstag, 03 Mai 2011, 00:55:09
; \\****************************************//
;
;
I 00:52:17 ImgBurn Version 2.5.5.0 started!
I 00:52:17 Microsoft Windows Vista Home Premium Edition (6.0, Build 6001 : Service Pack 1)
I 00:52:17 Total Physical Memory: 3.142.744 KB - Available: 1.991.648 KB
I 00:52:17 Initialising SPTI...
I 00:52:17 Searching for SCSI / ATAPI devices...
I 00:52:21 -> Drive 1 - Info: TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 00:52:21 Found 1 DVD±RW/RAM!
I 00:55:09 Close Request Acknowledged
I 00:55:09 Closing Down...
I 00:55:09 Shutting down SPTI...
I 00:55:09 ImgBurn closed!
;
;
; //****************************************\\
; ImgBurn Version 2.5.5.0 - Log
; Dienstag, 03 Mai 2011, 00:36:01
; \\****************************************//
;
;
I 00:27:43 ImgBurn Version 2.5.5.0 started!
I 00:27:43 Microsoft Windows Vista Home Premium Edition (6.0, Build 6001 : Service Pack 1)
I 00:27:43 Total Physical Memory: 3.142.744 KB - Available: 1.758.384 KB
I 00:27:43 Initialising SPTI...
I 00:27:43 Searching for SCSI / ATAPI devices...
I 00:27:46 -> Drive 1 - Info: TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 00:27:46 Found 1 DVD±RW/RAM!
I 00:28:56 Operation Started!
I 00:28:56 Source File: C:\Users\Basti\AppData\Local\Temp\vista_recover_x86.iso
I 00:28:56 Source File Sectors: 73.642 (MODE1/2048)
I 00:28:56 Source File Size: 150.818.816 bytes
I 00:28:56 Source File Volume Identifier: LRMCFRE_DE_DVD
I 00:28:56 Source File Volume Set Identifier: cbafc000MS UDFBridge
I 00:28:57 Source File Application Identifier: OSCDIMG 2.54 (01/01/2005 TM)
I 00:28:57 Source File Implementation Identifier: Microsoft CDIMAGE UDF
I 00:28:57 Source File File System(s): ISO9660 (Bootable); UDF (1.50)
I 00:28:57 Destination Device: [3:0:0] TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 00:28:57 Destination Media Type: DVD+R (Disc ID: RICOHJPN-R03-04) (Speeds: 3x; 4x; 6x; 8x)
I 00:28:57 Destination Media Sectors: 2.295.104
I 00:28:57 Write Mode: DVD
I 00:28:57 Write Type: DAO
I 00:28:57 Write Speed: MAX
I 00:28:57 DVD+R Reserve Track: No
I 00:28:57 Link Size: Auto
I 00:28:57 Lock Volume: Yes
I 00:28:57 Test Mode: No
I 00:28:57 OPC: No
I 00:28:57 BURN-Proof: Enabled
I 00:28:59 Write Speed Successfully Set! - Effective: 11.080 KB/s (8x)
I 00:28:59 Book Type Setting: N/A (Reason: Unzulässige Funktion.)
I 00:29:01 Filling Buffer... (40 MB)
I 00:29:04 Writing LeadIn...
I 00:29:22 Writing Session 1 of 1... (1 Track, LBA: 0 - 73641)
I 00:29:22 Writing Track 1 of 1... (MODE1/2048, LBA: 0 - 73641)
I 00:29:56 Synchronising Cache...
I 00:30:09 Closing Track...
I 00:30:21 Finalising Disc...
I 00:32:01 Exporting Graph Data...
I 00:32:01 Graph Data File: C:\Users\Basti\AppData\Roaming\ImgBurn\Graph Data Files\TSSTcorp_CDDVDW_TS-L633L_0400_DIENSTAG-3-MAI-2011_00-28_RICOHJPN-R03-04_MAX.ibg
I 00:32:01 Export Successfully Completed!
I 00:32:01 Operation Successfully Completed! - Duration: 00:03:04
I 00:32:01 Average Write Rate: 4.463 KB/s (3.2x) - Maximum Write Rate: 5.016 KB/s (3.6x)
I 00:32:01 Cycling Tray before Verify...
W 00:33:01 Waiting for device to become ready...
I 00:33:25 Device Ready!
E 00:33:25 CompareImageFileLayouts Failed! - Session Count Not Equal (1/0)
E 00:33:25 Verify Failed! - Reason: Layouts do not match.
I 00:36:01 Close Request Acknowledged
I 00:36:01 Closing Down...
I 00:36:01 Shutting down SPTI...
I 00:36:01 ImgBurn closed!
;
;
; //****************************************\\
; ImgBurn Version 2.5.5.0 - Log
; Montag, 02 Mai 2011, 23:29:23
; \\****************************************//
;
;
I 23:28:50 ImgBurn Version 2.5.5.0 started!
I 23:28:50 Microsoft Windows Vista Home Premium Edition (6.0, Build 6001 : Service Pack 1)
I 23:28:50 Total Physical Memory: 3.142.744 KB - Available: 1.923.328 KB
I 23:28:50 Initialising SPTI...
I 23:28:50 Searching for SCSI / ATAPI devices...
I 23:28:50 -> Drive 1 - Info: TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 23:28:50 Found 1 DVD±RW/RAM!
I 23:29:23 Close Request Acknowledged
I 23:29:23 Closing Down...
I 23:29:23 Shutting down SPTI...
I 23:29:23 ImgBurn closed!
;
;
; //****************************************\\
; ImgBurn Version 2.5.5.0 - Log
; Montag, 02 Mai 2011, 23:27:22
; \\****************************************//
;
;
I 23:27:13 ImgBurn Version 2.5.5.0 started!
I 23:27:13 Microsoft Windows Vista Home Premium Edition (6.0, Build 6001 : Service Pack 1)
I 23:27:13 Total Physical Memory: 3.142.744 KB - Available: 1.926.744 KB
I 23:27:13 Initialising SPTI...
I 23:27:13 Searching for SCSI / ATAPI devices...
I 23:27:13 -> Drive 1 - Info: TSSTcorp CDDVDW TS-L633L 0400 (E:) (ATA)
I 23:27:13 Found 1 DVD±RW/RAM!
I 23:27:22 Close Request Acknowledged
I 23:27:22 Closing Down...
I 23:27:22 Shutting down SPTI...
I 23:27:22 ImgBurn closed!





d.h.: wie ich mich kenne, weiß ichs eher nicht:sleepy:

cosinus 04.05.2011 17:57

So brennt man ein Image => http://www.trojaner-board.de/82533-d...ml#post8806518

Basti7 04.05.2011 19:16

Danke Arne!
bin erst übermorgen wieder da und dann berichte ich dir.
Gruß
Basti


Alle Zeitangaben in WEZ +1. Es ist jetzt 12:57 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131