Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Trojaner TR/kazy.mehm.1 wie nun weiter? otl.txt und extra.txt vorhanden. (https://www.trojaner-board.de/99232-trojaner-tr-kazy-mehm-1-otl-txt-extra-txt-vorhanden.html)

claudia03205 18.05.2011 11:32

Trojaner TR/kazy.mehm.1 wie nun weiter? otl.txt und extra.txt vorhanden.
 
Hallo,
also als erstes muss ich glaube mal erwähnen das ich in sachen pc nicht gerade dolle ahnung habe:) nun gut, auch ich wurde von dem Trojaner kazy.mehm.1 befallen.
symtome wie bei allen, schwarzer bildschirm, tausende warn meldungen, (festplatte beschädigt- daten sichern), und daten verschwunden bzw. versteckt wie ihr hier schreibt.
nach stunden langen belesen hier bei euch im forum habe ich es schonmal geschaft dank der OTl.exe die otl und extra textdatein zu bekommen was sich als äußerst schwiereig rausstellte, weil er jedes mal während des scannen einfach aus ging, beim 8mal ging es dann ohne probleme.

hier nun die datein die er mir ausgespuckt hat.
und wie geht es dann weiter?
ich dank euch für jede antwort mit der ihr mir helfen

otl:OTL Logfile:
Code:

OTL logfile created on: 17.05.2011 21:36:05 - Run 2
OTL by OldTimer - Version 3.2.22.3    Folder = G:\
Windows Vista Home Premium Edition  (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 50,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 75,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 148,10 Gb Total Space | 53,41 Gb Free Space | 36,07% Space Free | Partition Type: NTFS
Drive D: | 73,07 Gb Total Space | 70,25 Gb Free Space | 96,14% Space Free | Partition Type: NTFS
Drive G: | 982,11 Mb Total Space | 611,19 Mb Free Space | 62,23% Space Free | Partition Type: FAT
 
Computer Name: NOTEBOOK | User Name: Necki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - G:\OTL.exe (OldTimer Tools)
PRC - C:\ProgramData\scIeDgaoTLYN.exe (WinTrust)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Program Files\ICQ6Toolbar\ICQ Service.exe ()
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - D:\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
PRC - C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe (Nokia)
PRC - C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Siemens Computers)
PRC - C:\Program Files\Launch Manager\WisLMSvc.exe (Wistron Corp.)
PRC - \\?\C:\Windows\System32\wbem\WMIADAP.EXE ()
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Windows\System32\attrib.exe (Microsoft Corporation)
PRC - C:\Program Files\avmwlanstick\FRITZWLANMini.exe (AVM Berlin GmbH)
 
 
========== Modules (SafeList) ==========
 
MOD - G:\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Automatisches LiveUpdate - Scheduler) --  File not found
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (ICQ Service) -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe ()
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (IGDCTRL) -- C:\Program Files\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (Microsoft Office Groove Audit Service) -- D:\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (TestHandler) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Siemens Computers)
SRV - (WisLMSvc) -- C:\Program Files\Launch Manager\WisLMSvc.exe (Wistron Corp.)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (nvrd32) -- C:\Windows\system32\drivers\nvrd32.sys (NVIDIA Corporation)
DRV - (nvstor32) -- C:\Windows\system32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (JRAID) -- C:\Windows\system32\drivers\jraid.sys (JMicron Technology Corp.)
DRV - (FWLANUSB) -- C:\Windows\System32\drivers\fwlanusb.sys (AVM GmbH)
DRV - (USB28xxBGA) -- C:\Windows\System32\drivers\emBDA.sys (eMPIA Technology, Inc.)
DRV - (USB28xxOEM) -- C:\Windows\System32\drivers\emOEM.sys (eMPIA Technology, Inc.)
DRV - (sfvfs02) StarForce Protection VFS Driver (version 2.x) -- C:\Windows\System32\drivers\sfvfs02.sys (Protection Technology)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (Ser2pl) -- C:\Windows\System32\drivers\ser2pl.sys (Prolific Technology Inc.)
DRV - (Hotkey) -- C:\Windows\System32\drivers\HOTKEY.sys ()
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\1003081933\ICQToolBar.dll (ICQ)
IE - HKLM\..\URLSearchHook: {a51a36e6-31e7-4838-9ff7-76298b527ec0} - C:\Program Files\softonic-Germany\tbsoft.dll (Conduit Ltd.)
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.bearshare.com/de/
IE - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\1003081933\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\URLSearchHook: {a51a36e6-31e7-4838-9ff7-76298b527ec0} - C:\Program Files\softonic-Germany\tbsoft.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://google.de/"
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2.0.0.1
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.6.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
FF - prefs.js..extensions.enabledItems: {a51a36e6-31e7-4838-9ff7-76298b527ec0}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.8&q="
 
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.04.05 22:13:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.04.05 22:13:03 | 000,000,000 | ---D | M]
 
[2008.09.03 15:40:29 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Necki\AppData\Roaming\mozilla\Extensions
[2011.05.17 20:38:46 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Necki\AppData\Roaming\mozilla\Firefox\Profiles\bjx89sl2.default\extensions
[2009.09.03 13:49:26 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Necki\AppData\Roaming\mozilla\Firefox\Profiles\bjx89sl2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.04.07 09:49:44 | 000,000,000 | -H-D | M] ("ICQ Toolbar") -- C:\Users\Necki\AppData\Roaming\mozilla\Firefox\Profiles\bjx89sl2.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.04.07 09:49:46 | 000,000,000 | -H-D | M] (softonic-Germany Community Toolbar) -- C:\Users\Necki\AppData\Roaming\mozilla\Firefox\Profiles\bjx89sl2.default\extensions\{a51a36e6-31e7-4838-9ff7-76298b527ec0}
[2011.04.07 09:49:19 | 000,000,000 | -H-D | M] (Conduit Engine) -- C:\Users\Necki\AppData\Roaming\mozilla\Firefox\Profiles\bjx89sl2.default\extensions\engine@conduit.com
[2011.04.05 22:13:59 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Necki\AppData\Roaming\mozilla\Firefox\Profiles\bjx89sl2.default\extensions\nostmp
[2011.04.20 20:25:49 | 000,000,950 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-1.xml
[2011.04.05 22:14:14 | 000,000,950 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-10.xml
[2009.11.15 10:44:31 | 000,000,950 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-2.xml
[2010.03.07 22:59:01 | 000,000,950 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-3.xml
[2010.03.25 21:35:31 | 000,000,950 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-4.xml
[2010.04.12 21:17:14 | 000,000,950 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-5.xml
[2010.07.25 17:50:10 | 000,000,950 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-6.xml
[2010.11.16 19:48:23 | 000,000,950 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-7.xml
[2011.03.06 22:30:46 | 000,000,950 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-8.xml
[2011.04.05 22:03:19 | 000,000,950 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-9.xml
[2011.03.14 18:08:40 | 000,000,168 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin.gif
[2011.03.14 18:08:40 | 000,000,618 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin.src
[2008.07.10 14:07:28 | 000,000,944 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin.xml
[2011.04.05 22:05:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2008.11.29 11:33:28 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Program Files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.05.04 09:07:43 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011.03.26 10:12:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\USERS\NECKI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BJX89SL2.DEFAULT\EXTENSIONS\{888D99E7-E8B5-46A3-851E-1EC45DA1E644}.XPI
[2011.03.18 19:56:37 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.02.02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (XTTBPos00 Class) - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll (IE Toolbar)
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (UrlHelper Class) - {6D023EBF-70B8-45A6-9ED5-556515FA0FE4} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (UrlHelper Class) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll ()
O2 - BHO: (softonic-Germany Toolbar) - {a51a36e6-31e7-4838-9ff7-76298b527ec0} - C:\Program Files\softonic-Germany\tbsoft.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0744.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0744.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\1003081933\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (softonic-Germany Toolbar) - {a51a36e6-31e7-4838-9ff7-76298b527ec0} - C:\Program Files\softonic-Germany\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare)
O3 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\Toolbar\WebBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\1003081933\ICQToolBar.dll (ICQ)
O3 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\Toolbar\WebBrowser: (softonic-Germany Toolbar) - {A51A36E6-31E7-4838-9FF7-76298B527EC0} - C:\Program Files\softonic-Germany\tbsoft.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\Toolbar\WebBrowser: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [AVMWlanClient] C:\Program Files\avmwlanstick\FRITZWLANMini.exe (AVM Berlin GmbH)
O4 - HKLM..\Run: [CtrlVol]  File not found
O4 - HKLM..\Run: [GrooveMonitor] D:\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron)
O4 - HKLM..\Run: [LaunchAp]  File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe (Nokia)
O4 - HKLM..\Run: [recinfo866] c:\RecInfo\RecInfo.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Wbutton]  File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [FRITZ!protect]  File not found
O4 - HKU\.DEFAULT..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
O4 - HKU\S-1-5-18..\Run: [FRITZ!protect]  File not found
O4 - HKU\S-1-5-18..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000..\Run: [scIeDgaoTLYN] C:\ProgramData\scIeDgaoTLYN.exe (WinTrust)
O7 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - D:\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Necki\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Necki\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0e8012b0-42d7-11df-9395-0016d38c2282}\Shell - "" = AutoRun
O33 - MountPoints2\{0e8012b0-42d7-11df-9395-0016d38c2282}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{3248e16a-3687-11e0-a014-a33012342dbf}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe
O33 - MountPoints2\{50210559-ac31-11dc-99c0-0016d38c2282}\Shell - "" = AutoRun
O33 - MountPoints2\{50210559-ac31-11dc-99c0-0016d38c2282}\Shell\AutoRun\command - "" = F:\pushinst.exe
O33 - MountPoints2\{e43b64bc-55dd-11de-a9e4-0016d38c2282}\Shell - "" = AutoRun
O33 - MountPoints2\{e43b64bc-55dd-11de-a9e4-0016d38c2282}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FRITZ!DSL Startcenter.lnk - C:\Windows\Installer\{74A929E2-FBD8-4736-A84E-2ABBB2ABADF2}\Icon2457326B4.exe - ()
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - hkey= - key= - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
MsConfig - StartUpReg: ccApp - hkey= - key= -  File not found
MsConfig - StartUpReg: IS CfgWiz - hkey= - key= -  File not found
MsConfig - StartUpReg: NeroFilterCheck - hkey= - key= - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
MsConfig - StartUpReg: osCheck - hkey= - key= -  File not found
MsConfig - StartUpReg: PCSuiteTrayApplication - hkey= - key= - C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe (Nokia)
MsConfig - State: "startup" - 2
MsConfig - State: "services" - 2
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
 
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\Windows\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (hxxp://www.mp3dev.org/)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS hxxp://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIV3 - C:\Windows\System32\DivXc32.dll (Hacked with Joy !)
Drivers32: VIDC.DIV4 - C:\Windows\System32\DivXc32f.dll (Hacked with Joy !)
Drivers32: VIDC.DIVX - C:\Windows\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\Windows\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\Windows\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\Windows\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\System32\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.05.17 16:52:51 | 000,580,608 | -H-- | C] (OldTimer Tools) -- C:\Users\Necki\Desktop\OTL.exe
[2011.04.27 11:07:23 | 000,000,000 | -H-D | C] -- C:\Users\Necki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Recovery
[2011.04.27 10:55:14 | 000,573,440 | -H-- | C] (WinTrust) -- C:\ProgramData\scIeDgaoTLYN.exe
[2011.04.27 08:46:48 | 000,000,000 | -H-D | C] -- C:\Users\Necki\Desktop\0411
[2011.04.22 14:02:07 | 000,000,000 | -H-D | C] -- C:\Users\Necki\Desktop\Schulle
[1 C:\Users\Necki\AppData\Local\*.tmp files -> C:\Users\Necki\AppData\Local\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.05.17 21:35:51 | 000,641,344 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.05.17 21:35:51 | 000,610,142 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.05.17 21:35:51 | 000,116,706 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.05.17 21:35:51 | 000,103,924 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.05.17 21:31:09 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2011.05.17 21:27:26 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.05.17 21:27:21 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.05.17 21:27:21 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.05.17 21:27:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.05.17 21:27:10 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
[2011.05.17 21:24:14 | 000,000,341 | -H-- | M] () -- C:\Users\Necki\Documents\Claudia & Martin - Verknüpfung.lnk
[2011.05.17 20:49:04 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.05.17 17:52:27 | 000,000,336 | -H-- | M] () -- C:\ProgramData\30924576
[2011.05.17 17:52:24 | 000,491,520 | -H-- | M] () -- C:\ProgramData\30924576.VIR
[2011.05.17 16:50:38 | 000,000,344 | -H-- | M] () -- C:\ProgramData\31973152
[2011.05.17 16:50:27 | 000,491,520 | -H-- | M] () -- C:\ProgramData\31973152.VIR
[2011.05.17 16:34:34 | 000,580,608 | -H-- | M] (OldTimer Tools) -- C:\Users\Necki\Desktop\OTL.exe
[2011.05.17 15:16:03 | 000,000,336 | -H-- | M] () -- C:\ProgramData\33546016
[2011.04.27 11:07:23 | 000,000,589 | -H-- | M] () -- C:\Users\Necki\Desktop\Windows Recovery.lnk
[2011.04.27 11:07:18 | 000,000,344 | -H-- | M] () -- C:\ProgramData\31186720
[2011.04.27 10:55:13 | 000,573,440 | -H-- | M] (WinTrust) -- C:\ProgramData\scIeDgaoTLYN.exe
[1 C:\Users\Necki\AppData\Local\*.tmp files -> C:\Users\Necki\AppData\Local\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.05.17 21:24:14 | 000,000,341 | -H-- | C] () -- C:\Users\Necki\Documents\Claudia & Martin - Verknüpfung.lnk
[2011.05.17 17:52:27 | 000,000,336 | -H-- | C] () -- C:\ProgramData\30924576
[2011.05.17 17:52:24 | 000,491,520 | -H-- | C] () -- C:\ProgramData\30924576.VIR
[2011.05.17 16:50:38 | 000,000,344 | -H-- | C] () -- C:\ProgramData\31973152
[2011.05.17 16:50:27 | 000,491,520 | -H-- | C] () -- C:\ProgramData\31973152.VIR
[2011.05.17 15:16:03 | 000,000,336 | -H-- | C] () -- C:\ProgramData\33546016
[2011.04.27 11:07:23 | 000,000,589 | -H-- | C] () -- C:\Users\Necki\Desktop\Windows Recovery.lnk
[2011.04.27 11:07:18 | 000,000,344 | -H-- | C] () -- C:\ProgramData\31186720
[2010.10.06 11:34:33 | 000,045,056 | -H-- | C] () -- C:\Users\Necki\AppData\Roaming\chrtmp
[2010.10.06 11:34:32 | 000,063,877 | -H-- | C] () -- C:\Users\Necki\AppData\Roaming\490020018XSVBvY_ph.jpg
[2010.03.16 23:00:09 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010.03.16 23:00:08 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2010.03.16 23:00:05 | 002,378,752 | ---- | C] () -- C:\Windows\System32\x264vfw.dll
[2010.03.16 23:00:04 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010.03.16 23:00:04 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010.03.16 23:00:03 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2010.03.16 22:59:59 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009.06.07 19:13:06 | 000,000,680 | -H-- | C] () -- C:\Users\Necki\AppData\Local\d3d9caps.dat
[2009.04.19 12:10:09 | 000,007,347 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2009.04.01 16:47:49 | 000,233,472 | R--- | C] () -- C:\Windows\System32\MafiaSetup.exe
[2009.04.01 16:29:46 | 000,233,472 | RH-- | C] () -- C:\Users\Necki\AppData\Roaming\MafiaSetup.exe
[2009.01.20 19:24:07 | 000,097,312 | ---- | C] () -- C:\Windows\System32\drivers\Fwusb1b.bin
[2009.01.13 23:11:20 | 000,000,235 | -H-- | C] () -- C:\Users\Necki\AppData\Roaming\devices.xml
[2009.01.13 23:11:20 | 000,000,012 | -H-- | C] () -- C:\Users\Necki\AppData\Roaming\settings.xml
[2008.11.07 09:43:57 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini
[2008.11.01 13:57:36 | 000,000,552 | -H-- | C] () -- C:\Users\Necki\AppData\Local\d3d8caps.dat
[2008.06.07 22:11:31 | 000,065,536 | ---- | C] () -- C:\Windows\System32\dmcrypto.dll
[2008.06.07 21:47:03 | 000,040,960 | ---- | C] () -- C:\Windows\System32\bdadll.dll
[2008.02.18 01:37:23 | 000,026,340 | -H-- | C] () -- C:\Users\Necki\AppData\Roaming\UserTile.png
[2008.01.08 23:25:55 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2008.01.02 17:57:36 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1409.dll
[2008.01.02 17:47:22 | 001,953,696 | ---- | C] () -- C:\Windows\System32\igklg400.dll
[2008.01.02 17:47:22 | 001,533,360 | ---- | C] () -- C:\Windows\System32\igklg450.dll
[2008.01.02 17:47:22 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2007.12.07 01:49:52 | 000,015,360 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2007.12.03 23:32:15 | 000,210,432 | -H-- | C] () -- C:\Users\Necki\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.10.23 20:12:02 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2007.10.23 20:11:58 | 000,009,867 | ---- | C] () -- C:\Windows\System32\drivers\HOTKEY.sys
[2007.10.23 20:07:19 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1283.dll
[2007.10.23 20:07:18 | 000,910,464 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2006.11.02 17:33:31 | 000,641,344 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 17:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 17:33:31 | 000,116,706 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 17:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,372,096 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 000,610,142 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,103,924 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:25:26 | 000,557,568 | ---- | C] () -- C:\Windows\System32\hpotscl1.dll
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.11.02 09:22:43 | 000,099,999 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2006.11.02 09:22:43 | 000,018,271 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2006.08.11 09:52:02 | 000,012,288 | ---- | C] () -- C:\Windows\System32\EvOnlDiag.dll
[2005.12.07 12:31:00 | 000,202,752 | R--- | C] () -- C:\Windows\System32\CddbCdda.dll
 
========== LOP Check ==========
 
[2009.12.27 15:02:12 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Ashampoo
[2010.10.29 14:25:39 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\FRITZ!
[2009.02.04 16:26:08 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\GARMIN
[2011.04.21 12:45:22 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\ICQ
[2007.12.18 21:20:59 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\ICQ Toolbar
[2008.01.25 00:18:22 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Kazaa Lite
[2008.04.10 21:16:16 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Leadertech
[2011.02.10 21:03:18 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Nokia
[2011.02.10 21:26:50 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Nokia Multimedia Player
[2009.09.25 14:44:37 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\PC Suite
[2009.09.25 15:03:32 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\ROUTE 66 Sync
[2011.05.17 20:53:08 | 000,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2008.09.05 12:54:32 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Adobe
[2009.07.23 21:24:24 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Ahead
[2011.01.02 22:03:51 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Apple Computer
[2009.12.27 15:02:12 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Ashampoo
[2010.10.29 14:25:39 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\FRITZ!
[2009.02.04 16:26:08 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\GARMIN
[2009.01.13 23:45:29 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Hewlett-Packard
[2011.04.21 12:45:22 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\ICQ
[2007.12.18 21:20:59 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\ICQ Toolbar
[2007.12.03 23:16:39 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Identities
[2007.12.18 21:15:54 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\InstallShield
[2008.01.25 00:18:22 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Kazaa Lite
[2008.04.10 21:16:16 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Leadertech
[2007.12.04 18:06:08 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Macromedia
[2006.11.02 14:37:34 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Media Center Programs
[2009.11.17 21:40:53 | 000,000,000 | --SD | M] -- C:\Users\Necki\AppData\Roaming\Microsoft
[2008.09.03 15:40:29 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Mozilla
[2011.02.10 21:03:18 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Nokia
[2011.02.10 21:26:50 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Nokia Multimedia Player
[2009.09.25 14:44:37 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\PC Suite
[2011.04.07 10:13:53 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Real
[2009.09.25 15:03:32 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\ROUTE 66 Sync
[2008.11.09 16:01:00 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\Symantec
[2011.04.13 18:42:27 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\U3
[2007.12.05 18:42:07 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\vlc
[2010.01.06 21:40:56 | 000,000,000 | -H-D | M] -- C:\Users\Necki\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2004.01.26 18:15:29 | 000,233,472 | RH-- | M] () -- C:\Users\Necki\AppData\Roaming\MafiaSetup.exe
[2010.06.27 18:36:00 | 002,568,656 | -H-- | M] (Adobe Systems, Inc.) -- C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
[2007.10.23 09:27:20 | 000,110,592 | -H-- | M] () -- C:\Users\Necki\AppData\Roaming\U3\temp\cleanup.exe
[2008.05.02 10:41:48 | 003,493,888 | -H-- | M] (SanDisk Corporation) -- C:\Users\Necki\AppData\Roaming\U3\temp\Launchpad Removal.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.02.14 21:09:13 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\drivers\atapi.sys
[2008.02.14 21:09:13 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.02.14 21:09:13 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.02.14 21:09:12 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EXPLORER.EXE  >
[2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\explorer.exe
[2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008.10.29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008.10.30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2007.12.19 19:12:22 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2007.12.19 19:12:22 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2008.10.28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006.11.02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
 
< MD5 for: IASTOR.SYS  >
[2007.07.12 16:35:02 | 000,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_ec8a8d1b\iaStor.sys
[2007.03.21 12:58:56 | 000,304,920 | -H-- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\DRIVER\SATA\INTEL1\iaStor.sys
[2007.03.21 12:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\drivers\iaStor.sys
[2007.03.21 12:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_3a63e5a6\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\System32\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
 
< MD5 for: NVSTOR32.SYS  >
[2007.07.02 17:37:08 | 000,110,112 | ---- | M] (NVIDIA Corporation) MD5=703E3A7093B0FAC0EEBADBB8E931ECAF -- C:\Windows\System32\drivers\nvstor32.sys
[2007.07.02 17:37:08 | 000,110,112 | ---- | M] (NVIDIA Corporation) MD5=703E3A7093B0FAC0EEBADBB8E931ECAF -- C:\Windows\System32\DriverStore\FileRepository\nvrd32.inf_bbf77119\nvstor32.sys
 
< MD5 for: SCECLI.DLL  >
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\System32\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2007.10.23 19:12:36 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=9D9F061EDA75425FC67F0365E3467C86 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_cbc258dc896598f1\user32.dll
[2006.11.02 11:46:13 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=E698A5437B89A285ACA3FF022356810A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_cb01aa4570716e5e\user32.dll
[2007.10.23 19:12:36 | 000,633,856 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2007.10.23 19:12:36 | 000,633,856 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_cb39bc5b7047127e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\System32\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
 
< MD5 for: VIAMRAID.SYS  >
[2006.11.08 15:23:52 | 000,102,912 | ---- | M] (VIA Technologies inc,.ltd) MD5=7DC3E1DC6E4F8BE381C31BFEA578412A -- C:\Windows\System32\drivers\viamraid.sys
[2006.11.08 15:23:52 | 000,102,912 | ---- | M] (VIA Technologies inc,.ltd) MD5=7DC3E1DC6E4F8BE381C31BFEA578412A -- C:\Windows\System32\DriverStore\FileRepository\viamraid.inf_74a36694\viamraid.sys
 
< MD5 for: WINLOGON.EXE  >
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\System32\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2006.11.02 10:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\System32\drivers\ws2ifsl.sys
[2006.11.02 10:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2007.10.24 05:02:12 | 006,664,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2007.10.24 05:02:10 | 000,102,400 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2007.10.24 05:02:12 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2007.10.24 05:02:24 | 015,720,448 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2007.10.24 05:02:25 | 006,021,120 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >


extras: OTL EXTRAS Logfile:

Code:

OTL Extras logfile created on: 17.05.2011 21:36:05 - Run 2
OTL by OldTimer - Version 3.2.22.3    Folder = G:\
Windows Vista Home Premium Edition  (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 50,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 75,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 148,10 Gb Total Space | 53,41 Gb Free Space | 36,07% Space Free | Partition Type: NTFS
Drive D: | 73,07 Gb Total Space | 70,25 Gb Free Space | 96,14% Space Free | Partition Type: NTFS
Drive G: | 982,11 Mb Total Space | 611,19 Mb Free Space | 62,23% Space Free | Partition Type: FAT
 
Computer Name: NOTEBOOK | User Name: Necki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
[HKEY_USERS\S-1-5-21-982778272-3740993981-3889600570-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "D:\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "D:\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- D:\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0331F3F2-FB23-462D-849B-D5A86DB9B496}" = lport=137 | protocol=17 | dir=in | app=system |
"{2C541DA6-A49B-41C5-9A5A-F4C2C4981E7F}" = rport=445 | protocol=6 | dir=out | app=system |
"{32C9A739-4A00-4626-8451-D5C14AA61447}" = rport=139 | protocol=6 | dir=out | app=system |
"{3F931AEB-6561-4135-8485-064B9D4CC650}" = lport=445 | protocol=6 | dir=in | app=system |
"{65238714-8B13-422A-95B3-9FB90EB5B967}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{7B229C7A-B0FE-4C05-A929-F6BB513D4AF1}" = rport=137 | protocol=17 | dir=out | app=system |
"{8781AE2E-5984-4A57-8F9E-F74FBD7C5998}" = lport=6004 | protocol=17 | dir=in | app=d:\office12\outlook.exe |
"{9F1797C4-5406-4D98-B7B1-A24EBEEA5809}" = lport=139 | protocol=6 | dir=in | app=system |
"{A66D7B03-1DAE-48F9-91EC-F1A99E6A8BAA}" = rport=138 | protocol=17 | dir=out | app=system |
"{ACC5F1B5-F404-446B-A9E2-6EE21FF0DA20}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{C0ADBE91-F352-4E5A-874B-F78F6A422D60}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{D20EF011-03E9-4C3F-947A-BEF074314582}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F5B11897-AE8D-4982-82EB-71CF3F1913C2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{FBB4CE3F-AA12-49DC-BF02-FDD63F9EB286}" = lport=138 | protocol=17 | dir=in | app=system |
"{FE53A108-04A9-448A-9217-14AEF6FB7E5D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03953DA4-75DC-4D92-AF73-F214191533CD}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{08DB4710-561B-4BF8-AFFE-CE1ED0602F82}" = protocol=6 | dir=in | app=d:\office12\onenote.exe |
"{0BE52CA1-D43A-4682-9004-FFD2CB35822F}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{1142DDDA-9A29-4765-957F-E65F1C4ABB61}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2BD15EF4-9BC0-40F9-BC83-B7B63F812F38}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{2D8C3EA5-4B7E-438C-A92D-BD21DCCFABD2}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{3646B75B-9601-40E3-B867-44E4119C1140}" = protocol=6 | dir=in | app=d:\office12\groove.exe |
"{3A660990-52BA-4E98-ABA6-52EACD34DA80}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{3CF7B0C3-ECEE-466D-872B-88C155324C39}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{432466BB-3E77-42D5-9085-E88396E66128}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{4A3028C5-B170-4862-90C1-F9617E842C2D}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{4C2B03EC-40EE-43CB-B4CA-688A76AD1DDB}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{560C28F9-2F33-4B79-A8C3-2D3A11B3C591}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{68A7830C-5C65-4814-BA52-1CE671D35175}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{6EDC86E5-E2B0-4233-B5C8-430CC6335A03}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{787B8640-B814-40EA-9406-583BCC8E89BF}" = protocol=17 | dir=in | app=d:\office12\onenote.exe |
"{8D9B277E-3C90-43BD-A0B8-4FC68ED927A7}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{91DA3E93-9EF8-4626-896A-C15A6B3A20F1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{9E272209-625D-4280-9AD8-AFBD64F2F8A8}" = protocol=17 | dir=in | app=c:\program files\fritz!dsl\igdctrl.exe |
"{A4AA6A1D-9E2F-433E-979F-3630DC4C2A76}" = protocol=6 | dir=in | app=c:\program files\fritz!dsl\fboxupd.exe |
"{ABDA7FC3-384B-4164-A1CF-E47667FB7889}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{B2CDF60B-1044-4D91-96F5-E4C318D16689}" = protocol=6 | dir=in | app=d:\program files\gamespy arcade\aphex.exe |
"{B6030C41-432E-4C15-81CB-C342E41DF5A3}" = protocol=17 | dir=in | app=c:\program files\fritz!dsl\webwaigd.exe |
"{B6EA7854-2403-408D-97FE-CC775B73C288}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{BAC55136-899F-4DDB-A1CE-958436726093}" = protocol=17 | dir=in | app=d:\office12\groove.exe |
"{C45F59E5-DD30-474A-B6D7-1C8DE06636E5}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{CFD2A2BF-F1C2-41F5-98B2-FA3A81754022}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{D35645D0-C0E4-41A2-91C9-A7CF9F884856}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{DBFA2459-B98E-4806-9F9F-3B85989374E6}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{DF5A5D01-B4D9-4857-85BD-E4ECC69A8376}" = protocol=17 | dir=in | app=d:\program files\gamespy arcade\aphex.exe |
"{EB8ECE9D-6677-4AFA-9548-606FE66ED13F}" = protocol=6 | dir=in | app=c:\program files\fritz!dsl\igdctrl.exe |
"{ED0EBA92-7DA3-4DAC-8945-5144F3D186FD}" = protocol=6 | dir=in | app=c:\program files\fritz!dsl\webwaigd.exe |
"{FE5E4394-0EC5-4A55-A1D4-FB0BEAEBCF8E}" = protocol=17 | dir=in | app=c:\program files\fritz!dsl\fboxupd.exe |
"TCP Query User{17F7556E-E785-4B0D-84DB-04387CB39DAB}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"TCP Query User{296AA8AF-FF54-453A-8539-BF58247C7510}D:\icq6\icq.exe" = protocol=6 | dir=in | app=d:\icq6\icq.exe |
"TCP Query User{454BD3F0-D9AB-4438-8C37-B734639EE9DC}D:\icq6.5\icq.exe" = protocol=6 | dir=in | app=d:\icq6.5\icq.exe |
"TCP Query User{87517AF5-5813-4CA3-B23E-BE2B40671A28}C:\program files\route 66\route 66 sync\route66sync.exe" = protocol=6 | dir=in | app=c:\program files\route 66\route 66 sync\route66sync.exe |
"TCP Query User{8CF00E60-8CD0-4A79-BFDC-FFD367FEC26E}C:\users\necki\desktop\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=c:\users\necki\desktop\call of duty 2\cod2mp_s.exe |
"TCP Query User{95A36810-62DB-4C80-B578-C7778C5B44AF}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{AD2075E3-943E-46B2-B217-7D10E3FA2C6F}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{BA37DEA4-8269-4D83-9773-4443421E0A67}D:\icq6\icq.exe" = protocol=6 | dir=in | app=d:\icq6\icq.exe |
"TCP Query User{BBB20D30-B36E-4B1D-A237-3544A418C5A6}D:\kazaa lite\clean.kmd" = protocol=6 | dir=in | app=d:\kazaa lite\clean.kmd |
"TCP Query User{DE1FC057-A4CD-4118-A866-E33A42FCC6D4}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"TCP Query User{F0A624E6-3973-4ABF-AB74-EB2AD7F6A860}H:\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=h:\call of duty 2\cod2mp_s.exe |
"TCP Query User{F53BFFAF-625D-4EE5-81E8-AEFA5A49D8CF}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{1FDABDCB-826E-4D13-8B13-746131C01C9D}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"UDP Query User{21BBE808-A9E9-4324-B2BA-F58E67CFFBC2}D:\icq6\icq.exe" = protocol=17 | dir=in | app=d:\icq6\icq.exe |
"UDP Query User{39ED43C9-8579-4806-B9F1-BA341B64C553}D:\icq6.5\icq.exe" = protocol=17 | dir=in | app=d:\icq6.5\icq.exe |
"UDP Query User{4399AAE5-47F0-489E-9B73-E461A0FDE872}H:\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=h:\call of duty 2\cod2mp_s.exe |
"UDP Query User{4E04E2FF-B6F8-43E4-A3DC-F1D588EAC2CA}C:\users\necki\desktop\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=c:\users\necki\desktop\call of duty 2\cod2mp_s.exe |
"UDP Query User{7E3D38EB-5342-4D02-B252-18D392FA68C3}D:\kazaa lite\clean.kmd" = protocol=17 | dir=in | app=d:\kazaa lite\clean.kmd |
"UDP Query User{A904AE54-3162-4395-BD01-FB37791210AD}D:\icq6\icq.exe" = protocol=17 | dir=in | app=d:\icq6\icq.exe |
"UDP Query User{BCAEB68F-EADE-4FDE-A820-1F19DE2B01AA}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"UDP Query User{C26B7D1A-A6BB-4A6E-93BC-EC33829A6EE4}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{CBFF9007-9C00-4655-A541-6ABC8E5A3021}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{D4877576-8C3A-4D9F-A899-CDDAF9B97FDD}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{DF83BC9E-17D3-4C1E-8BA9-0CC3CCC2F869}C:\program files\route 66\route 66 sync\route66sync.exe" = protocol=17 | dir=in | app=c:\program files\route 66\route 66 sync\route66sync.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 24
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{4216D328-0FE8-48B8-85B8-BD300E6F080F}" = Nokia Connectivity Cable Driver
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52210D57-0B1F-4681-90DD-8659DF4BCC40}" = Moorhuhn Remake
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{68E9B173-BC4D-4FFF-812D-32D79BE370AD}" = Nokia PC Suite
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74A929E2-FBD8-4736-A84E-2ABBB2ABADF2}" = AVM FRITZ!DSL
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{88EB38EF-4D2C-436D-ABD3-56B232674062}" = ICQ7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FBC9407-713D-4B8A-98D2-57210DA56049}" = MSN Toolbar
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007
"{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90170407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{94D66D71-12F0-48A5-B46A-D4B835A0F1B7}" = FirstSteps Diagnostics
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4C534E-431F-4A17-97D4-D1682B19A054}" = Emergency4
"{A20A58C4-6784-4B4B-86CC-94E2E3671031}" = Nero 7 Premium
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-A81200000003}" = Adobe Reader 8.1.2 - Deutsch
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0846526-66DD-4DC9-A02C-98F9A2806812}" = Launch Manager V1.4.9
"{D4AEC53C-1720-41D9-B6D7-6A60DE62D444}" = PC Connectivity Solution
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6970FBD-809A-4C51-BAB3-D94A04C6C8E7}" = Garmin Communicator Plugin
"504244733D18C8F63FF584AEB290E3904E791693" = Windows-Treiberpaket - Nokia pccsmcfd  (08/22/2008 7.0.0.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BearShare MediaBar" = MediaBar 2.0
"conduitEngine" = Conduit Engine
"Cradle of Rome" = Cradle of Rome (remove only)
"Deer Hunter 2004_is1" = Deer Hunter 2004 - Legendary Hunting
"EAX Unified" = EAX Unified
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Google Updater" = Google Updater
"Grand Theft Auto" = Grand Theft Auto
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"ICQToolbar" = ICQ Toolbar
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.8.3
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 4.0 (x86 de)" = Mozilla Firefox 4.0 (x86 de)
"Poker Superstars II" = Poker Superstars II (remove only)
"softonic-Germany Toolbar" = softonic-Germany Toolbar
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VideoLAN VLC media player 0.8.6d
"WBFS Manager 3.0" = WBFS Manager 3.0
"WinRAR archiver" = WinRAR
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-982778272-3740993981-3889600570-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"b996e812c4b1deb0" = ROUTE 66 Sync
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 17.05.2011 15:41:11 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 17.05.2011 15:43:13 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 17.05.2011 15:45:15 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 17.05.2011 15:47:16 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 17.05.2011 15:49:18 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 17.05.2011 15:51:20 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 17.05.2011 15:53:21 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 17.05.2011 15:55:23 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 17.05.2011 15:57:24 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 17.05.2011 15:59:24 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
[ OSession Events ]
Error - 19.11.2009 10:35:39 | Computer Name = Notebook | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6514.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1833
 seconds with 720 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 17.05.2011 15:10:05 | Computer Name = Notebook | Source = Service Control Manager | ID = 7000
Description =
 
Error - 17.05.2011 15:10:05 | Computer Name = Notebook | Source = Service Control Manager | ID = 7026
Description =
 
Error - 17.05.2011 15:22:40 | Computer Name = Notebook | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 17.05.2011 um 21:18:43 unerwartet heruntergefahren.
 
Error - 17.05.2011 15:23:52 | Computer Name = Notebook | Source = Service Control Manager | ID = 7000
Description =
 
Error - 17.05.2011 15:23:52 | Computer Name = Notebook | Source = Service Control Manager | ID = 7026
Description =
 
Error - 17.05.2011 15:26:57 | Computer Name = Notebook | Source = Application Popup | ID = 875
Description = Treiber sfvfs02.sys konnte nicht geladen werden.
 
Error - 17.05.2011 15:26:57 | Computer Name = Notebook | Source = Application Popup | ID = 875
Description = Treiber sfdrv01.sys konnte nicht geladen werden.
 
Error - 17.05.2011 15:27:15 | Computer Name = Notebook | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 17.05.2011 um 21:25:32 unerwartet heruntergefahren.
 
Error - 17.05.2011 15:29:03 | Computer Name = Notebook | Source = Service Control Manager | ID = 7000
Description =
 
Error - 17.05.2011 15:29:03 | Computer Name = Notebook | Source = Service Control Manager | ID = 7026
Description =
 
 
< End of report >


cosinus 18.05.2011 13:15

Gibt es noch weitere Logs von Malwarebytes? Wenn ja bitte alle posten, die in Malwarebytes im Reiter Logdateien sichtbar sind.


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Vista und 7 User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

claudia03205 18.05.2011 15:40

Hallo,
danke schonmal, habe unhide geladen, nun habe ich ein schwarzes fenster, mit please be patient while your files are made visible again. ist das bis hier hin richtig? datein waren auch kurz zu sehen auf desktop.

nun muss ich malwarebytes runterladen und das ergebnis aus diesen scan posten ja?

mfg

claudia03205 18.05.2011 15:44

hallo, danke schonmal.
habe unhide geladen, gestartet und meine symbole sind für kurze zeit aufm desktop sichtbar aber dann wieder weg:( dann kommt your files should now be visible

und was ist malwarebyte? das runterladen und dort auch ein scann machen?

mfg

claudia03205 18.05.2011 16:34

so , das kam beim malwarebytes raus
habe quick scan gemacht war das richtich, also nur c: hat er durchsucht, mein pc hat aber festplatte c: und d:?


Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 5363

Windows 6.0.6000
Internet Explorer 7.0.6000.17037

18.05.2011 17:24:49
mbam-log-2011-05-18 (17-24-34).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 152070
Laufzeit: 11 Minute(n), 44 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 6
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{055FD26D-3A88-4e15-963D-DC8493744B1D} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{77D6DDFA-7834-4541-B2B3-A8B0FB0E3924} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\ToolBand.XTTBPos00.1 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\ToolBand.XTTBPos00 (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{055FD26D-3A88-4E15-963D-DC8493744B1D} (Trojan.BHO) -> No action taken.

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\program files\icqtoolbar\toolbaru.dll (Trojan.BHO) -> No action taken.


cosinus 18.05.2011 20:11

1.) Hast du Malwarebytes nicht aktualisiert, das nachholen über den Updatebutton
2.) Möchste ich danach einen Vollscan sehen
3.) alle Funde entfernen lassen

claudia03205 18.05.2011 21:49

so habe das neuste update, vers. 6611 und vollscan läuft seid 19min und zeigt schon 5 funde . danach die log datei datei wieder posten?

cosinus 18.05.2011 21:54

Ja, Funde alle entfernen, das Log dann hier posten

claudia03205 18.05.2011 23:01

so hier nun die log datei

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6611

Windows 6.0.6000
Internet Explorer 7.0.6000.17037

18.05.2011 23:57:49
mbam-log-2011-05-18 (23-57-49).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 289969
Laufzeit: 1 Stunde(n), 25 Minute(n), 36 Sekunde(n)

Infizierte Speicherprozesse: 2
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 1
Infizierte Dateien: 7

Infizierte Speicherprozesse:
c:\programdata\sciedgaotlyn.exe (Trojan.FakeAlert) -> 2344 -> Unloaded process successfully.
c:\programdata\32366368.exe (Trojan.FakeAlert) -> 2560 -> Unloaded process successfully.

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\scIeDgaoTLYN (Trojan.FakeAlert) -> Value: scIeDgaoTLYN -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
c:\Users\Necki\AppData\Roaming\microsoft\Windows\start menu\Programs\windows recovery (Trojan.FakeAV) -> Quarantined and deleted successfully.

Infizierte Dateien:
c:\programdata\sciedgaotlyn.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\programdata\32366368.exe (Trojan.FakeAlert) -> Delete on reboot.
c:\programdata\30924576.VIR (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\programdata\31973152.VIR (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Necki\Desktop\windows recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
c:\Users\Necki\AppData\Roaming\microsoft\Windows\start menu\Programs\windows recovery\uninstall windows recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
c:\Users\Necki\AppData\Roaming\microsoft\Windows\start menu\Programs\windows recovery\windows recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.


claudia03205 18.05.2011 23:16

es tat sich was fehlermeldungen sind weg und symbole sind wieder da nur noch der desktop ist schwarz.

mfg
Claudia

cosinus 19.05.2011 09:08

Zitat:

wieder da nur noch der desktop ist schwarz.
Einfach das Hintergrundbild manuell neu einstellen.
Ist das Startmenü vollständig?

Zitat:

O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B9
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6
O3 - HKLM\..\Toolbar: (softonic-Germany Toolbar)
O3 - HKLM\..\Toolbar: (BearShare MediaBar) - {D3
Hm, was willst du mit diesen komischen Toolbars auf dem Rechner? Am besten alles entfernen wo Toolbar steht, was in der Systemsteuerung unter Software bzw. Programme und Funktionen zu sehen ist und bei zukünftigen Programminstallation immer die benutzerdefinierte Methode anklicken, damit man bei der Installation mögliche Toolbars abwählen kann.
Deinstalliere bei der Gelegenheit auch alle anderen unnötigen Programme über die Systemsteuerung.

claudia03205 19.05.2011 09:23

Hallo, ja keine ahnung was das für toolbars sind, sag ja soviel ahnung hab ich net:).
es ist nur wenn ich auf start bzw windowszeichen links unten in der tastkleiste drücke, das die linke spalte leer ist aber gehe ich auf "alle programme" zeigt er alles an.
ist das problem jetzt beseitigt und kann den rechner wieder voll nutzen oder sollte ich ihn mal komplett formatieren und windows neu aufspielen?
mfg und schonmal nen dickes dankeschön bis hier her.

LG
Claudia

cosinus 19.05.2011 09:54

Deinstallier wie gesagt alle Toolbars. Dann gehts weiter, mach danach ein frisches OTL-Log.

claudia03205 19.05.2011 11:43

so hier nochml die OTL Scan ergebnisse.

otl: OTL Logfile:

Code:

OTL logfile created on: 19.05.2011 12:13:11 - Run 3
OTL by OldTimer - Version 3.2.22.3    Folder = G:\
Windows Vista Home Premium Edition  (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 45,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 148,10 Gb Total Space | 54,12 Gb Free Space | 36,54% Space Free | Partition Type: NTFS
Drive D: | 73,07 Gb Total Space | 70,25 Gb Free Space | 96,14% Space Free | Partition Type: NTFS
Drive G: | 982,11 Mb Total Space | 603,11 Mb Free Space | 61,41% Space Free | Partition Type: FAT
 
Computer Name: NOTEBOOK | User Name: Necki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - G:\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - D:\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
PRC - C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Siemens Computers)
PRC - C:\Program Files\Launch Manager\WisLMSvc.exe (Wistron Corp.)
PRC - \\?\C:\Windows\System32\wbem\WMIADAP.EXE ()
PRC - C:\Program Files\avmwlanstick\FRITZWLANMini.exe (AVM Berlin GmbH)
 
 
========== Modules (SafeList) ==========
 
MOD - G:\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Automatisches LiveUpdate - Scheduler) --  File not found
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (Microsoft Office Groove Audit Service) -- D:\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (TestHandler) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Siemens Computers)
SRV - (WisLMSvc) -- C:\Program Files\Launch Manager\WisLMSvc.exe (Wistron Corp.)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (nvrd32) -- C:\Windows\system32\drivers\nvrd32.sys (NVIDIA Corporation)
DRV - (nvstor32) -- C:\Windows\system32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (JRAID) -- C:\Windows\system32\drivers\jraid.sys (JMicron Technology Corp.)
DRV - (FWLANUSB) -- C:\Windows\System32\drivers\fwlanusb.sys (AVM GmbH)
DRV - (USB28xxBGA) -- C:\Windows\System32\drivers\emBDA.sys (eMPIA Technology, Inc.)
DRV - (USB28xxOEM) -- C:\Windows\System32\drivers\emOEM.sys (eMPIA Technology, Inc.)
DRV - (sfvfs02) StarForce Protection VFS Driver (version 2.x) -- C:\Windows\System32\drivers\sfvfs02.sys (Protection Technology)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (Ser2pl) -- C:\Windows\System32\drivers\ser2pl.sys (Prolific Technology Inc.)
DRV - (Hotkey) -- C:\Windows\System32\drivers\HOTKEY.sys ()
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.bearshare.com/de/
IE - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\URLSearchHook: {a51a36e6-31e7-4838-9ff7-76298b527ec0} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://google.de/"
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2.0.0.1
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.6.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
FF - prefs.js..extensions.enabledItems: {a51a36e6-31e7-4838-9ff7-76298b527ec0}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.8&q="
 
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.04.05 22:13:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.05.19 10:36:56 | 000,000,000 | ---D | M]
 
[2008.09.03 15:40:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Necki\AppData\Roaming\mozilla\Extensions
[2011.05.17 20:38:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Necki\AppData\Roaming\mozilla\Firefox\Profiles\bjx89sl2.default\extensions
[2009.09.03 13:49:26 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Necki\AppData\Roaming\mozilla\Firefox\Profiles\bjx89sl2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.04.07 09:49:44 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Necki\AppData\Roaming\mozilla\Firefox\Profiles\bjx89sl2.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.04.07 09:49:46 | 000,000,000 | ---D | M] (softonic-Germany Community Toolbar) -- C:\Users\Necki\AppData\Roaming\mozilla\Firefox\Profiles\bjx89sl2.default\extensions\{a51a36e6-31e7-4838-9ff7-76298b527ec0}
[2011.04.07 09:49:19 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Necki\AppData\Roaming\mozilla\Firefox\Profiles\bjx89sl2.default\extensions\engine@conduit.com
[2011.04.05 22:13:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Necki\AppData\Roaming\mozilla\Firefox\Profiles\bjx89sl2.default\extensions\nostmp
[2011.04.20 20:25:49 | 000,000,950 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-1.xml
[2011.04.05 22:14:14 | 000,000,950 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-10.xml
[2009.11.15 10:44:31 | 000,000,950 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-2.xml
[2010.03.07 22:59:01 | 000,000,950 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-3.xml
[2010.03.25 21:35:31 | 000,000,950 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-4.xml
[2010.04.12 21:17:14 | 000,000,950 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-5.xml
[2010.07.25 17:50:10 | 000,000,950 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-6.xml
[2010.11.16 19:48:23 | 000,000,950 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-7.xml
[2011.03.06 22:30:46 | 000,000,950 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-8.xml
[2011.04.05 22:03:19 | 000,000,950 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin-9.xml
[2011.03.14 18:08:40 | 000,000,168 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin.gif
[2011.03.14 18:08:40 | 000,000,618 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin.src
[2008.07.10 14:07:28 | 000,000,944 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\searchplugins\icqplugin.xml
[2011.04.05 22:05:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2008.11.29 11:33:28 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Program Files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.05.04 09:07:43 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011.03.26 10:12:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\USERS\NECKI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BJX89SL2.DEFAULT\EXTENSIONS\{888D99E7-E8B5-46A3-851E-1EC45DA1E644}.XPI
[2011.03.18 19:56:37 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.02.02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (UrlHelper Class) - {6D023EBF-70B8-45A6-9ED5-556515FA0FE4} -  File not found
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\Toolbar\WebBrowser: (no name) - {A51A36E6-31E7-4838-9FF7-76298B527EC0} - No CLSID value found.
O3 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [AVMWlanClient] C:\Program Files\avmwlanstick\FRITZWLANMini.exe (AVM Berlin GmbH)
O4 - HKLM..\Run: [CtrlVol]  File not found
O4 - HKLM..\Run: [GrooveMonitor] D:\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron)
O4 - HKLM..\Run: [LaunchAp]  File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [recinfo866] c:\RecInfo\RecInfo.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Wbutton]  File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [PcSync]  File not found
O4 - HKU\S-1-5-18..\Run: [PcSync]  File not found
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O7 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - D:\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Necki\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Necki\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0e8012b0-42d7-11df-9395-0016d38c2282}\Shell - "" = AutoRun
O33 - MountPoints2\{0e8012b0-42d7-11df-9395-0016d38c2282}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{3248e16a-3687-11e0-a014-a33012342dbf}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe
O33 - MountPoints2\{50210559-ac31-11dc-99c0-0016d38c2282}\Shell - "" = AutoRun
O33 - MountPoints2\{50210559-ac31-11dc-99c0-0016d38c2282}\Shell\AutoRun\command - "" = F:\pushinst.exe
O33 - MountPoints2\{e43b64bc-55dd-11de-a9e4-0016d38c2282}\Shell - "" = AutoRun
O33 - MountPoints2\{e43b64bc-55dd-11de-a9e4-0016d38c2282}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FRITZ!DSL Startcenter.lnk -  - File not found
MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - hkey= - key= - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
MsConfig - StartUpReg: ccApp - hkey= - key= -  File not found
MsConfig - StartUpReg: IS CfgWiz - hkey= - key= -  File not found
MsConfig - StartUpReg: Malwarebytes' Anti-Malware (reboot) - hkey= - key= - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
MsConfig - StartUpReg: NeroFilterCheck - hkey= - key= - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
MsConfig - StartUpReg: osCheck - hkey= - key= -  File not found
MsConfig - StartUpReg: PCSuiteTrayApplication - hkey= - key= -  File not found
MsConfig - State: "startup" - 2
MsConfig - State: "services" - 2
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
 
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\Windows\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (hxxp://www.mp3dev.org/)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS hxxp://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIV3 - C:\Windows\System32\DivXc32.dll (Hacked with Joy !)
Drivers32: VIDC.DIV4 - C:\Windows\System32\DivXc32f.dll (Hacked with Joy !)
Drivers32: VIDC.DIVX - C:\Windows\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\Windows\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\Windows\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\Windows\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\System32\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.05.19 11:47:58 | 000,000,000 | ---D | C] -- C:\Users\Necki\Desktop\Trojaner
[2011.05.19 10:36:36 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2011.05.18 16:58:08 | 000,000,000 | ---D | C] -- C:\Users\Necki\AppData\Roaming\Malwarebytes
[2011.05.18 16:57:28 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.05.18 16:57:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.05.18 16:57:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.05.18 16:57:04 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.05.18 16:57:02 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[1 C:\Users\Necki\AppData\Local\*.tmp files -> C:\Users\Necki\AppData\Local\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.05.19 12:14:11 | 000,641,344 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.05.19 12:14:11 | 000,610,142 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.05.19 12:14:11 | 000,116,706 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.05.19 12:14:11 | 000,103,924 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.05.19 11:49:04 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.05.19 11:46:21 | 000,003,072 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.05.19 11:46:21 | 000,003,072 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.05.19 11:16:11 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2011.05.19 10:46:28 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.05.19 10:46:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.05.19 10:46:15 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
[2011.05.19 10:36:57 | 000,001,893 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2011.05.19 10:29:27 | 000,211,456 | ---- | M] () -- C:\Users\Necki\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.05.19 10:18:35 | 000,000,864 | ---- | M] () -- C:\Users\Necki\Desktop\Mozilla Firefox.lnk
[2011.05.17 22:04:49 | 000,000,344 | ---- | M] () -- C:\ProgramData\32366368
[2011.05.17 21:24:14 | 000,000,341 | ---- | M] () -- C:\Users\Necki\Documents\Claudia & Martin - Verknüpfung.lnk
[2011.05.17 17:52:27 | 000,000,336 | ---- | M] () -- C:\ProgramData\30924576
[2011.05.17 16:50:38 | 000,000,344 | ---- | M] () -- C:\ProgramData\31973152
[2011.05.17 15:16:03 | 000,000,336 | ---- | M] () -- C:\ProgramData\33546016
[2011.05.16 12:39:18 | 001,795,364 | ---- | M] () -- C:\Users\Necki\Desktop\SDC11325.JPG
[2011.04.27 11:07:18 | 000,000,344 | ---- | M] () -- C:\ProgramData\31186720
[1 C:\Users\Necki\AppData\Local\*.tmp files -> C:\Users\Necki\AppData\Local\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.05.19 10:36:57 | 000,001,893 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2011.05.19 10:36:56 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 8.lnk
[2011.05.19 10:31:13 | 001,795,364 | ---- | C] () -- C:\Users\Necki\Desktop\SDC11325.JPG
[2011.05.19 10:18:35 | 000,000,864 | ---- | C] () -- C:\Users\Necki\Desktop\Mozilla Firefox.lnk
[2011.05.17 22:04:49 | 000,000,344 | ---- | C] () -- C:\ProgramData\32366368
[2011.05.17 21:24:14 | 000,000,341 | ---- | C] () -- C:\Users\Necki\Documents\Claudia & Martin - Verknüpfung.lnk
[2011.05.17 17:52:27 | 000,000,336 | ---- | C] () -- C:\ProgramData\30924576
[2011.05.17 16:50:38 | 000,000,344 | ---- | C] () -- C:\ProgramData\31973152
[2011.05.17 15:16:03 | 000,000,336 | ---- | C] () -- C:\ProgramData\33546016
[2011.04.27 11:07:18 | 000,000,344 | ---- | C] () -- C:\ProgramData\31186720
[2010.10.06 11:34:33 | 000,045,056 | ---- | C] () -- C:\Users\Necki\AppData\Roaming\chrtmp
[2010.10.06 11:34:32 | 000,063,877 | ---- | C] () -- C:\Users\Necki\AppData\Roaming\490020018XSVBvY_ph.jpg
[2010.03.16 23:00:09 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010.03.16 23:00:08 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2010.03.16 23:00:05 | 002,378,752 | ---- | C] () -- C:\Windows\System32\x264vfw.dll
[2010.03.16 23:00:04 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010.03.16 23:00:04 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010.03.16 23:00:03 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2010.03.16 22:59:59 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009.06.07 19:13:06 | 000,000,680 | ---- | C] () -- C:\Users\Necki\AppData\Local\d3d9caps.dat
[2009.04.19 12:10:09 | 000,007,347 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2009.04.01 16:47:49 | 000,233,472 | R--- | C] () -- C:\Windows\System32\MafiaSetup.exe
[2009.04.01 16:29:46 | 000,233,472 | R--- | C] () -- C:\Users\Necki\AppData\Roaming\MafiaSetup.exe
[2009.01.20 19:24:07 | 000,097,312 | ---- | C] () -- C:\Windows\System32\drivers\Fwusb1b.bin
[2009.01.13 23:11:20 | 000,000,235 | ---- | C] () -- C:\Users\Necki\AppData\Roaming\devices.xml
[2009.01.13 23:11:20 | 000,000,012 | ---- | C] () -- C:\Users\Necki\AppData\Roaming\settings.xml
[2008.11.07 09:43:57 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini
[2008.11.01 13:57:36 | 000,000,552 | ---- | C] () -- C:\Users\Necki\AppData\Local\d3d8caps.dat
[2008.06.07 22:11:31 | 000,065,536 | ---- | C] () -- C:\Windows\System32\dmcrypto.dll
[2008.06.07 21:47:03 | 000,040,960 | ---- | C] () -- C:\Windows\System32\bdadll.dll
[2008.02.18 01:37:23 | 000,026,340 | ---- | C] () -- C:\Users\Necki\AppData\Roaming\UserTile.png
[2008.01.08 23:25:55 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2008.01.02 17:57:36 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1409.dll
[2008.01.02 17:47:22 | 001,953,696 | ---- | C] () -- C:\Windows\System32\igklg400.dll
[2008.01.02 17:47:22 | 001,533,360 | ---- | C] () -- C:\Windows\System32\igklg450.dll
[2008.01.02 17:47:22 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2007.12.07 01:49:52 | 000,015,360 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2007.12.03 23:32:15 | 000,211,456 | ---- | C] () -- C:\Users\Necki\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.10.23 20:12:02 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2007.10.23 20:11:58 | 000,009,867 | ---- | C] () -- C:\Windows\System32\drivers\HOTKEY.sys
[2007.10.23 20:07:19 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1283.dll
[2007.10.23 20:07:18 | 000,910,464 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2006.11.02 17:33:31 | 000,641,344 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 17:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 17:33:31 | 000,116,706 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 17:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,372,096 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 000,610,142 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,103,924 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:25:26 | 000,557,568 | ---- | C] () -- C:\Windows\System32\hpotscl1.dll
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.11.02 09:22:43 | 000,099,999 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2006.11.02 09:22:43 | 000,018,271 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2006.08.11 09:52:02 | 000,012,288 | ---- | C] () -- C:\Windows\System32\EvOnlDiag.dll
 
========== LOP Check ==========
 
[2009.12.27 15:02:12 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Ashampoo
[2010.10.29 14:25:39 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\FRITZ!
[2009.02.04 16:26:08 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\GARMIN
[2011.04.21 12:45:22 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\ICQ
[2007.12.18 21:20:59 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\ICQ Toolbar
[2008.01.25 00:18:22 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Kazaa Lite
[2008.04.10 21:16:16 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Leadertech
[2011.02.10 21:03:18 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Nokia
[2011.02.10 21:26:50 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Nokia Multimedia Player
[2009.09.25 14:44:37 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\PC Suite
[2009.09.25 15:03:32 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\ROUTE 66 Sync
[2011.05.19 10:45:33 | 000,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2008.09.05 12:54:32 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Adobe
[2009.07.23 21:24:24 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Ahead
[2011.01.02 22:03:51 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Apple Computer
[2009.12.27 15:02:12 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Ashampoo
[2010.10.29 14:25:39 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\FRITZ!
[2009.02.04 16:26:08 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\GARMIN
[2009.01.13 23:45:29 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Hewlett-Packard
[2011.04.21 12:45:22 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\ICQ
[2007.12.18 21:20:59 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\ICQ Toolbar
[2007.12.03 23:16:39 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Identities
[2007.12.18 21:15:54 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\InstallShield
[2008.01.25 00:18:22 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Kazaa Lite
[2008.04.10 21:16:16 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Leadertech
[2007.12.04 18:06:08 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Macromedia
[2011.05.18 16:58:08 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Malwarebytes
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Media Center Programs
[2009.11.17 21:40:53 | 000,000,000 | --SD | M] -- C:\Users\Necki\AppData\Roaming\Microsoft
[2008.09.03 15:40:29 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Mozilla
[2011.02.10 21:03:18 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Nokia
[2011.02.10 21:26:50 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Nokia Multimedia Player
[2009.09.25 14:44:37 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\PC Suite
[2011.04.07 10:13:53 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Real
[2009.09.25 15:03:32 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\ROUTE 66 Sync
[2008.11.09 16:01:00 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\Symantec
[2011.04.13 18:42:27 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\U3
[2007.12.05 18:42:07 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\vlc
[2010.01.06 21:40:56 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2004.01.26 18:15:29 | 000,233,472 | R--- | M] () -- C:\Users\Necki\AppData\Roaming\MafiaSetup.exe
[2010.06.27 18:36:00 | 002,568,656 | ---- | M] (Adobe Systems, Inc.) -- C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
[2007.10.23 09:27:20 | 000,110,592 | ---- | M] () -- C:\Users\Necki\AppData\Roaming\U3\temp\cleanup.exe
[2008.05.02 10:41:48 | 003,493,888 | ---- | M] (SanDisk Corporation) -- C:\Users\Necki\AppData\Roaming\U3\temp\Launchpad Removal.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.02.14 21:09:13 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\drivers\atapi.sys
[2008.02.14 21:09:13 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.02.14 21:09:13 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.02.14 21:09:12 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EXPLORER.EXE  >
[2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\explorer.exe
[2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008.10.29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008.10.30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2007.12.19 19:12:22 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2007.12.19 19:12:22 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2008.10.28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006.11.02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
 
< MD5 for: IASTOR.SYS  >
[2007.07.12 16:35:02 | 000,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_ec8a8d1b\iaStor.sys
[2007.03.21 12:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\DRIVER\SATA\INTEL1\iaStor.sys
[2007.03.21 12:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\drivers\iaStor.sys
[2007.03.21 12:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_3a63e5a6\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\System32\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
 
< MD5 for: NVSTOR32.SYS  >
[2007.07.02 17:37:08 | 000,110,112 | ---- | M] (NVIDIA Corporation) MD5=703E3A7093B0FAC0EEBADBB8E931ECAF -- C:\Windows\System32\drivers\nvstor32.sys
[2007.07.02 17:37:08 | 000,110,112 | ---- | M] (NVIDIA Corporation) MD5=703E3A7093B0FAC0EEBADBB8E931ECAF -- C:\Windows\System32\DriverStore\FileRepository\nvrd32.inf_bbf77119\nvstor32.sys
 
< MD5 for: SCECLI.DLL  >
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\System32\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2007.10.23 19:12:36 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=9D9F061EDA75425FC67F0365E3467C86 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_cbc258dc896598f1\user32.dll
[2006.11.02 11:46:13 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=E698A5437B89A285ACA3FF022356810A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_cb01aa4570716e5e\user32.dll
[2007.10.23 19:12:36 | 000,633,856 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2007.10.23 19:12:36 | 000,633,856 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_cb39bc5b7047127e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\System32\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
 
< MD5 for: VIAMRAID.SYS  >
[2006.11.08 15:23:52 | 000,102,912 | ---- | M] (VIA Technologies inc,.ltd) MD5=7DC3E1DC6E4F8BE381C31BFEA578412A -- C:\Windows\System32\drivers\viamraid.sys
[2006.11.08 15:23:52 | 000,102,912 | ---- | M] (VIA Technologies inc,.ltd) MD5=7DC3E1DC6E4F8BE381C31BFEA578412A -- C:\Windows\System32\DriverStore\FileRepository\viamraid.inf_74a36694\viamraid.sys
 
< MD5 for: WINLOGON.EXE  >
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\System32\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2006.11.02 10:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\System32\drivers\ws2ifsl.sys
[2006.11.02 10:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2007.10.24 05:02:12 | 006,664,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2007.10.24 05:02:10 | 000,102,400 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2007.10.24 05:02:12 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2007.10.24 05:02:24 | 015,720,448 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2007.10.24 05:02:25 | 006,021,120 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

extras: OTL EXTRAS Logfile:

Code:

OTL Extras logfile created on: 19.05.2011 12:13:11 - Run 3
OTL by OldTimer - Version 3.2.22.3    Folder = G:\
Windows Vista Home Premium Edition  (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 45,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 148,10 Gb Total Space | 54,12 Gb Free Space | 36,54% Space Free | Partition Type: NTFS
Drive D: | 73,07 Gb Total Space | 70,25 Gb Free Space | 96,14% Space Free | Partition Type: NTFS
Drive G: | 982,11 Mb Total Space | 603,11 Mb Free Space | 61,41% Space Free | Partition Type: FAT
 
Computer Name: NOTEBOOK | User Name: Necki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
[HKEY_USERS\S-1-5-21-982778272-3740993981-3889600570-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "D:\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "D:\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- D:\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0331F3F2-FB23-462D-849B-D5A86DB9B496}" = lport=137 | protocol=17 | dir=in | app=system |
"{2C541DA6-A49B-41C5-9A5A-F4C2C4981E7F}" = rport=445 | protocol=6 | dir=out | app=system |
"{32C9A739-4A00-4626-8451-D5C14AA61447}" = rport=139 | protocol=6 | dir=out | app=system |
"{3F931AEB-6561-4135-8485-064B9D4CC650}" = lport=445 | protocol=6 | dir=in | app=system |
"{65238714-8B13-422A-95B3-9FB90EB5B967}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{7B229C7A-B0FE-4C05-A929-F6BB513D4AF1}" = rport=137 | protocol=17 | dir=out | app=system |
"{8781AE2E-5984-4A57-8F9E-F74FBD7C5998}" = lport=6004 | protocol=17 | dir=in | app=d:\office12\outlook.exe |
"{9F1797C4-5406-4D98-B7B1-A24EBEEA5809}" = lport=139 | protocol=6 | dir=in | app=system |
"{A66D7B03-1DAE-48F9-91EC-F1A99E6A8BAA}" = rport=138 | protocol=17 | dir=out | app=system |
"{ACC5F1B5-F404-446B-A9E2-6EE21FF0DA20}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{C0ADBE91-F352-4E5A-874B-F78F6A422D60}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{D20EF011-03E9-4C3F-947A-BEF074314582}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F5B11897-AE8D-4982-82EB-71CF3F1913C2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{FBB4CE3F-AA12-49DC-BF02-FDD63F9EB286}" = lport=138 | protocol=17 | dir=in | app=system |
"{FE53A108-04A9-448A-9217-14AEF6FB7E5D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03953DA4-75DC-4D92-AF73-F214191533CD}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{08DB4710-561B-4BF8-AFFE-CE1ED0602F82}" = protocol=6 | dir=in | app=d:\office12\onenote.exe |
"{0BE52CA1-D43A-4682-9004-FFD2CB35822F}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{1142DDDA-9A29-4765-957F-E65F1C4ABB61}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2BD15EF4-9BC0-40F9-BC83-B7B63F812F38}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{2D8C3EA5-4B7E-438C-A92D-BD21DCCFABD2}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{3646B75B-9601-40E3-B867-44E4119C1140}" = protocol=6 | dir=in | app=d:\office12\groove.exe |
"{3A660990-52BA-4E98-ABA6-52EACD34DA80}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{3CF7B0C3-ECEE-466D-872B-88C155324C39}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{432466BB-3E77-42D5-9085-E88396E66128}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{4A3028C5-B170-4862-90C1-F9617E842C2D}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{4C2B03EC-40EE-43CB-B4CA-688A76AD1DDB}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{560C28F9-2F33-4B79-A8C3-2D3A11B3C591}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{68A7830C-5C65-4814-BA52-1CE671D35175}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{6EDC86E5-E2B0-4233-B5C8-430CC6335A03}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{787B8640-B814-40EA-9406-583BCC8E89BF}" = protocol=17 | dir=in | app=d:\office12\onenote.exe |
"{8D9B277E-3C90-43BD-A0B8-4FC68ED927A7}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{91DA3E93-9EF8-4626-896A-C15A6B3A20F1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{ABDA7FC3-384B-4164-A1CF-E47667FB7889}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{B2CDF60B-1044-4D91-96F5-E4C318D16689}" = protocol=6 | dir=in | app=d:\program files\gamespy arcade\aphex.exe |
"{B6EA7854-2403-408D-97FE-CC775B73C288}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{BAC55136-899F-4DDB-A1CE-958436726093}" = protocol=17 | dir=in | app=d:\office12\groove.exe |
"{C45F59E5-DD30-474A-B6D7-1C8DE06636E5}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{CFD2A2BF-F1C2-41F5-98B2-FA3A81754022}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{D35645D0-C0E4-41A2-91C9-A7CF9F884856}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{DBFA2459-B98E-4806-9F9F-3B85989374E6}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{DF5A5D01-B4D9-4857-85BD-E4ECC69A8376}" = protocol=17 | dir=in | app=d:\program files\gamespy arcade\aphex.exe |
"TCP Query User{17F7556E-E785-4B0D-84DB-04387CB39DAB}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"TCP Query User{296AA8AF-FF54-453A-8539-BF58247C7510}D:\icq6\icq.exe" = protocol=6 | dir=in | app=d:\icq6\icq.exe |
"TCP Query User{454BD3F0-D9AB-4438-8C37-B734639EE9DC}D:\icq6.5\icq.exe" = protocol=6 | dir=in | app=d:\icq6.5\icq.exe |
"TCP Query User{87517AF5-5813-4CA3-B23E-BE2B40671A28}C:\program files\route 66\route 66 sync\route66sync.exe" = protocol=6 | dir=in | app=c:\program files\route 66\route 66 sync\route66sync.exe |
"TCP Query User{8CF00E60-8CD0-4A79-BFDC-FFD367FEC26E}C:\users\necki\desktop\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=c:\users\necki\desktop\call of duty 2\cod2mp_s.exe |
"TCP Query User{95A36810-62DB-4C80-B578-C7778C5B44AF}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{AD2075E3-943E-46B2-B217-7D10E3FA2C6F}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{BA37DEA4-8269-4D83-9773-4443421E0A67}D:\icq6\icq.exe" = protocol=6 | dir=in | app=d:\icq6\icq.exe |
"TCP Query User{BBB20D30-B36E-4B1D-A237-3544A418C5A6}D:\kazaa lite\clean.kmd" = protocol=6 | dir=in | app=d:\kazaa lite\clean.kmd |
"TCP Query User{DE1FC057-A4CD-4118-A866-E33A42FCC6D4}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"TCP Query User{F0A624E6-3973-4ABF-AB74-EB2AD7F6A860}H:\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=h:\call of duty 2\cod2mp_s.exe |
"TCP Query User{F53BFFAF-625D-4EE5-81E8-AEFA5A49D8CF}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{1FDABDCB-826E-4D13-8B13-746131C01C9D}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"UDP Query User{21BBE808-A9E9-4324-B2BA-F58E67CFFBC2}D:\icq6\icq.exe" = protocol=17 | dir=in | app=d:\icq6\icq.exe |
"UDP Query User{39ED43C9-8579-4806-B9F1-BA341B64C553}D:\icq6.5\icq.exe" = protocol=17 | dir=in | app=d:\icq6.5\icq.exe |
"UDP Query User{4399AAE5-47F0-489E-9B73-E461A0FDE872}H:\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=h:\call of duty 2\cod2mp_s.exe |
"UDP Query User{4E04E2FF-B6F8-43E4-A3DC-F1D588EAC2CA}C:\users\necki\desktop\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=c:\users\necki\desktop\call of duty 2\cod2mp_s.exe |
"UDP Query User{7E3D38EB-5342-4D02-B252-18D392FA68C3}D:\kazaa lite\clean.kmd" = protocol=17 | dir=in | app=d:\kazaa lite\clean.kmd |
"UDP Query User{A904AE54-3162-4395-BD01-FB37791210AD}D:\icq6\icq.exe" = protocol=17 | dir=in | app=d:\icq6\icq.exe |
"UDP Query User{BCAEB68F-EADE-4FDE-A820-1F19DE2B01AA}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"UDP Query User{C26B7D1A-A6BB-4A6E-93BC-EC33829A6EE4}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{CBFF9007-9C00-4655-A541-6ABC8E5A3021}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{D4877576-8C3A-4D9F-A899-CDDAF9B97FDD}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{DF83BC9E-17D3-4C1E-8BA9-0CC3CCC2F869}C:\program files\route 66\route 66 sync\route66sync.exe" = protocol=17 | dir=in | app=c:\program files\route 66\route 66 sync\route66sync.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 24
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52210D57-0B1F-4681-90DD-8659DF4BCC40}" = Moorhuhn Remake
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{88EB38EF-4D2C-436D-ABD3-56B232674062}" = ICQ7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007
"{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90170407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{94D66D71-12F0-48A5-B46A-D4B835A0F1B7}" = FirstSteps Diagnostics
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4C534E-431F-4A17-97D4-D1682B19A054}" = Emergency4
"{A20A58C4-6784-4B4B-86CC-94E2E3671031}" = Nero 7 Premium
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-A82000000003}" = Adobe Reader 8.2.0 - Deutsch
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0846526-66DD-4DC9-A02C-98F9A2806812}" = Launch Manager V1.4.9
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Cradle of Rome" = Cradle of Rome (remove only)
"EAX Unified" = EAX Unified
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Google Updater" = Google Updater
"Grand Theft Auto" = Grand Theft Auto
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.8.3
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 4.0 (x86 de)" = Mozilla Firefox 4.0 (x86 de)
"Poker Superstars II" = Poker Superstars II (remove only)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VideoLAN VLC media player 0.8.6d
"WBFS Manager 3.0" = WBFS Manager 3.0
"WinRAR archiver" = WinRAR
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 19.05.2011 06:10:14 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 19.05.2011 06:12:14 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 19.05.2011 06:14:14 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 19.05.2011 06:16:14 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 19.05.2011 06:18:15 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 19.05.2011 06:20:15 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 19.05.2011 06:22:15 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 19.05.2011 06:24:15 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 19.05.2011 06:26:15 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
Error - 19.05.2011 06:28:15 | Computer Name = Notebook | Source = Windows Search Service | ID = 3090
Description =
 
[ OSession Events ]
Error - 19.11.2009 10:35:39 | Computer Name = Notebook | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6514.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1833
 seconds with 720 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 18.05.2011 18:18:58 | Computer Name = Notebook | Source = Service Control Manager | ID = 7026
Description =
 
Error - 19.05.2011 02:13:08 | Computer Name = Notebook | Source = Application Popup | ID = 875
Description = Treiber sfvfs02.sys konnte nicht geladen werden.
 
Error - 19.05.2011 02:13:08 | Computer Name = Notebook | Source = Application Popup | ID = 875
Description = Treiber sfdrv01.sys konnte nicht geladen werden.
 
Error - 19.05.2011 02:14:47 | Computer Name = Notebook | Source = Service Control Manager | ID = 7000
Description =
 
Error - 19.05.2011 02:14:47 | Computer Name = Notebook | Source = Service Control Manager | ID = 7026
Description =
 
Error - 19.05.2011 04:46:00 | Computer Name = Notebook | Source = Application Popup | ID = 875
Description = Treiber sfvfs02.sys konnte nicht geladen werden.
 
Error - 19.05.2011 04:46:00 | Computer Name = Notebook | Source = Application Popup | ID = 875
Description = Treiber sfdrv01.sys konnte nicht geladen werden.
 
Error - 19.05.2011 04:47:40 | Computer Name = Notebook | Source = Service Control Manager | ID = 7000
Description =
 
Error - 19.05.2011 04:47:40 | Computer Name = Notebook | Source = Service Control Manager | ID = 7026
Description =
 
Error - 19.05.2011 04:52:20 | Computer Name = Notebook | Source = Service Control Manager | ID = 7022
Description =
 
 
< End of report >


cosinus 19.05.2011 14:27

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\Toolbar\WebBrowser: (no name) - {A51A36E6-31E7-4838-9FF7-76298B527EC0} - No CLSID value found.
O3 - HKU\S-1-5-21-982778272-3740993981-3889600570-1000\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
O4 - HKLM..\Run: [CtrlVol]  File not found
O4 - HKLM..\Run: [LaunchAp]  File not found
O4 - HKLM..\Run: [Wbutton]  File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [PcSync]  File not found
O4 - HKU\S-1-5-18..\Run: [PcSync]  File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0e8012b0-42d7-11df-9395-0016d38c2282}\Shell - "" = AutoRun
O33 - MountPoints2\{0e8012b0-42d7-11df-9395-0016d38c2282}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{3248e16a-3687-11e0-a014-a33012342dbf}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe
O33 - MountPoints2\{50210559-ac31-11dc-99c0-0016d38c2282}\Shell - "" = AutoRun
O33 - MountPoints2\{50210559-ac31-11dc-99c0-0016d38c2282}\Shell\AutoRun\command - "" = F:\pushinst.exe
O33 - MountPoints2\{e43b64bc-55dd-11de-a9e4-0016d38c2282}\Shell - "" = AutoRun
O33 - MountPoints2\{e43b64bc-55dd-11de-a9e4-0016d38c2282}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
[2011.05.17 22:04:49 | 000,000,344 | ---- | C] () -- C:\ProgramData\32366368
[2011.05.17 17:52:27 | 000,000,336 | ---- | C] () -- C:\ProgramData\30924576
[2011.05.17 16:50:38 | 000,000,344 | ---- | C] () -- C:\ProgramData\31973152
[2011.05.17 15:16:03 | 000,000,336 | ---- | C] () -- C:\ProgramData\33546016
[2011.04.27 11:07:18 | 000,000,344 | ---- | C] () -- C:\ProgramData\31186720
[2007.12.18 21:20:59 | 000,000,000 | ---D | M] -- C:\Users\Necki\AppData\Roaming\ICQ Toolbar
:Commands
[purity]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

claudia03205 19.05.2011 14:50

so habe ich gemacht, nach dem neustart war dann dieses fenster offen.

Code:

========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll moved successfully.
Registry value HKEY_USERS\S-1-5-21-982778272-3740993981-3889600570-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found.
Registry value HKEY_USERS\S-1-5-21-982778272-3740993981-3889600570-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.
Registry value HKEY_USERS\S-1-5-21-982778272-3740993981-3889600570-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A51A36E6-31E7-4838-9FF7-76298B527EC0} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A51A36E6-31E7-4838-9FF7-76298B527EC0}\ not found.
Registry value HKEY_USERS\S-1-5-21-982778272-3740993981-3889600570-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CtrlVol deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\LaunchAp deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Wbutton deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Defender deleted successfully.
File move failed. C:\Program Files\Windows Defender\MSASCui.exe scheduled to be moved on reboot.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\PcSync deleted successfully.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\PcSync not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e8012b0-42d7-11df-9395-0016d38c2282}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0e8012b0-42d7-11df-9395-0016d38c2282}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e8012b0-42d7-11df-9395-0016d38c2282}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0e8012b0-42d7-11df-9395-0016d38c2282}\ not found.
File G:\LaunchU3.exe -a not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3248e16a-3687-11e0-a014-a33012342dbf}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3248e16a-3687-11e0-a014-a33012342dbf}\ not found.
File F:\InstallTomTomHOME.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{50210559-ac31-11dc-99c0-0016d38c2282}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50210559-ac31-11dc-99c0-0016d38c2282}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{50210559-ac31-11dc-99c0-0016d38c2282}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50210559-ac31-11dc-99c0-0016d38c2282}\ not found.
File F:\pushinst.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e43b64bc-55dd-11de-a9e4-0016d38c2282}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e43b64bc-55dd-11de-a9e4-0016d38c2282}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e43b64bc-55dd-11de-a9e4-0016d38c2282}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e43b64bc-55dd-11de-a9e4-0016d38c2282}\ not found.
File G:\LaunchU3.exe -a not found.
C:\ProgramData\32366368 moved successfully.
C:\ProgramData\30924576 moved successfully.
C:\ProgramData\31973152 moved successfully.
C:\ProgramData\33546016 moved successfully.
C:\ProgramData\31186720 moved successfully.
C:\Users\Necki\AppData\Roaming\ICQ Toolbar folder moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.22.3 log created on 05192011_154307

Files\Folders moved on Reboot...
File move failed. C:\Program Files\Windows Defender\MSASCui.exe scheduled to be moved on reboot.

Registry entries deleted on Reboot...


cosinus 19.05.2011 15:02

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - also beide Haken setzen, auf Start scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

http://www.trojaner-board.de/attachm...rnen-start.png


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Vista und 7 User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

claudia03205 19.05.2011 15:09

so gemacht, nichts gefunden schrieb er,
auf meine datein kann ich wieder zugreifen ist soweit i das einschätzen kann alles wieder da.

Code:

2011/05/19 16:05:01.0881 3952        TDSS rootkit removing tool 2.5.1.0 May 13 2011 13:20:29
2011/05/19 16:05:02.0102 3952        ================================================================================
2011/05/19 16:05:02.0102 3952        SystemInfo:
2011/05/19 16:05:02.0102 3952       
2011/05/19 16:05:02.0102 3952        OS Version: 6.0.6000 ServicePack: 0.0
2011/05/19 16:05:02.0102 3952        Product type: Workstation
2011/05/19 16:05:02.0102 3952        ComputerName: NOTEBOOK
2011/05/19 16:05:02.0103 3952        UserName: Necki
2011/05/19 16:05:02.0103 3952        Windows directory: C:\Windows
2011/05/19 16:05:02.0103 3952        System windows directory: C:\Windows
2011/05/19 16:05:02.0103 3952        Processor architecture: Intel x86
2011/05/19 16:05:02.0103 3952        Number of processors: 2
2011/05/19 16:05:02.0103 3952        Page size: 0x1000
2011/05/19 16:05:02.0103 3952        Boot type: Normal boot
2011/05/19 16:05:02.0103 3952        ================================================================================
2011/05/19 16:05:02.0551 3952        Initialize success
2011/05/19 16:05:21.0062 2172        ================================================================================
2011/05/19 16:05:21.0062 2172        Scan started
2011/05/19 16:05:21.0062 2172        Mode: Manual;
2011/05/19 16:05:21.0062 2172        ================================================================================
2011/05/19 16:05:21.0577 2172        ACPI            (84fc6df81212d16be5c4f441682feccc) C:\Windows\system32\drivers\acpi.sys
2011/05/19 16:05:21.0718 2172        adp94xx        (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
2011/05/19 16:05:21.0920 2172        adpahci        (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
2011/05/19 16:05:22.0061 2172        adpu160m        (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
2011/05/19 16:05:22.0279 2172        adpu320        (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
2011/05/19 16:05:22.0451 2172        AFD            (5d24caf8efd924a875698ff28384db8b) C:\Windows\system32\drivers\afd.sys
2011/05/19 16:05:22.0607 2172        agp440          (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys
2011/05/19 16:05:22.0778 2172        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/05/19 16:05:22.0934 2172        aliide          (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
2011/05/19 16:05:23.0075 2172        amdagp          (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
2011/05/19 16:05:23.0200 2172        amdide          (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
2011/05/19 16:05:23.0402 2172        AmdK7          (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
2011/05/19 16:05:23.0558 2172        AmdK8          (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
2011/05/19 16:05:23.0761 2172        arc            (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
2011/05/19 16:05:23.0995 2172        arcsas          (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
2011/05/19 16:05:24.0416 2172        AsyncMac        (e86cf7ce67d5de898f27ef884dc357d8) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/05/19 16:05:24.0650 2172        atapi          (b35cfcef838382ab6490b321c87edf17) C:\Windows\system32\drivers\atapi.sys
2011/05/19 16:05:24.0838 2172        athr            (b0c272def210b149c0bfa0d85600ce4b) C:\Windows\system32\DRIVERS\athr.sys
2011/05/19 16:05:24.0962 2172        avgio          (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys
2011/05/19 16:05:25.0150 2172        avgntflt        (14fe36d8f2c6a2435275338d061a0b66) C:\Windows\system32\DRIVERS\avgntflt.sys
2011/05/19 16:05:25.0352 2172        avipbb          (6d52060b59e7d79cd2a044b6add1f1ef) C:\Windows\system32\DRIVERS\avipbb.sys
2011/05/19 16:05:25.0649 2172        Beep            (ac3dd1708b22761ebd7cbe14dcc3b5d7) C:\Windows\system32\drivers\Beep.sys
2011/05/19 16:05:25.0914 2172        bowser          (913cd06fbe9105ce6077e90fd4418561) C:\Windows\system32\DRIVERS\bowser.sys
2011/05/19 16:05:26.0179 2172        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/05/19 16:05:26.0351 2172        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/05/19 16:05:26.0569 2172        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/05/19 16:05:26.0710 2172        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/05/19 16:05:26.0788 2172        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/05/19 16:05:26.0928 2172        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/05/19 16:05:27.0146 2172        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/05/19 16:05:27.0302 2172        cdfs            (6c3a437fc873c6f6a4fc620b6888cb86) C:\Windows\system32\DRIVERS\cdfs.sys
2011/05/19 16:05:27.0458 2172        cdrom          (8d1866e61af096ae8b582454f5e4d303) C:\Windows\system32\DRIVERS\cdrom.sys
2011/05/19 16:05:27.0677 2172        circlass        (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
2011/05/19 16:05:27.0786 2172        CLFS            (1b84fd0937d3b99af9ba38ddff3daf54) C:\Windows\system32\CLFS.sys
2011/05/19 16:05:28.0004 2172        CmBatt          (ed97ad3df1b9005989eaf149bf06c821) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/05/19 16:05:28.0145 2172        cmdide          (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
2011/05/19 16:05:28.0348 2172        Compbatt        (722936afb75a7f509662b69b5632f48a) C:\Windows\system32\DRIVERS\compbatt.sys
2011/05/19 16:05:28.0519 2172        crcdisk        (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
2011/05/19 16:05:28.0628 2172        Crusoe          (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
2011/05/19 16:05:28.0909 2172        DfsC            (a7179de59ae269ab70345527894ccd7c) C:\Windows\system32\Drivers\dfsc.sys
2011/05/19 16:05:29.0190 2172        disk            (841af4c4d41d3e3b2f244e976b0f7963) C:\Windows\system32\drivers\disk.sys
2011/05/19 16:05:29.0611 2172        drmkaud        (ee472cd2c01f6f8e8aa1fa06ffef61b6) C:\Windows\system32\drivers\drmkaud.sys
2011/05/19 16:05:29.0923 2172        DXGKrnl        (b95202efd0464d226e7542c1e319c028) C:\Windows\System32\drivers\dxgkrnl.sys
2011/05/19 16:05:30.0251 2172        E1G60          (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/05/19 16:05:30.0516 2172        Ecache          (0efc7531b936ee57fdb4e837664c509f) C:\Windows\system32\drivers\ecache.sys
2011/05/19 16:05:30.0734 2172        elxstor        (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
2011/05/19 16:05:31.0015 2172        fastfat        (84a317cb0b3954d3768cdcd018dbf670) C:\Windows\system32\drivers\fastfat.sys
2011/05/19 16:05:31.0187 2172        fdc            (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
2011/05/19 16:05:31.0280 2172        FileInfo        (65773d6115c037ffd7ef8280ae85eb9d) C:\Windows\system32\drivers\fileinfo.sys
2011/05/19 16:05:31.0327 2172        Filetrace      (c226dd0de060745f3e042f58dcf78402) C:\Windows\system32\drivers\filetrace.sys
2011/05/19 16:05:31.0390 2172        flpydisk        (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/05/19 16:05:31.0436 2172        FltMgr          (a6a8da7ae4d53394ab22ac3ab6d3f5d3) C:\Windows\system32\drivers\fltmgr.sys
2011/05/19 16:05:31.0483 2172        Fs_Rec          (66a078591208baa210c7634b11eb392c) C:\Windows\system32\drivers\Fs_Rec.sys
2011/05/19 16:05:31.0561 2172        FWLANUSB        (ecb814c5d07839843aa5c3a1ee3ba8f3) C:\Windows\system32\DRIVERS\fwlanusb.sys
2011/05/19 16:05:31.0624 2172        gagp30kx        (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
2011/05/19 16:05:31.0686 2172        GEARAspiWDM    (ab8a6a87d9d7255c3884d5b9541a6e80) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2011/05/19 16:05:31.0920 2172        HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2011/05/19 16:05:32.0029 2172        HDAudBus        (0db613a7e427b5663563677796fd5258) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/05/19 16:05:32.0060 2172        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/05/19 16:05:32.0107 2172        HidIr          (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/05/19 16:05:32.0170 2172        HidUsb          (01e7971e9f4bd6ac6a08db52d0ea0418) C:\Windows\system32\DRIVERS\hidusb.sys
2011/05/19 16:05:32.0248 2172        Hotkey          (8b566ea71d5b76157a9cdb78f25a5731) C:\Windows\system32\drivers\Hotkey.sys
2011/05/19 16:05:32.0294 2172        HpCISSs        (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
2011/05/19 16:05:32.0388 2172        HTTP            (ea24fe637d974a8a31bc650f478e3533) C:\Windows\system32\drivers\HTTP.sys
2011/05/19 16:05:32.0450 2172        i2omp          (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
2011/05/19 16:05:32.0544 2172        i8042prt        (1c9ee072baa3abb460b91d7ee9152660) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/05/19 16:05:32.0606 2172        iaStor          (997e8f5939f2d12cd9f2e6b395724c16) C:\Windows\system32\DRIVERS\iaStor.sys
2011/05/19 16:05:32.0716 2172        iaStorV        (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
2011/05/19 16:05:32.0996 2172        igfx            (c134e69ce901422d1f2d7ea8d69098fe) C:\Windows\system32\DRIVERS\igdkmd32.sys
2011/05/19 16:05:33.0652 2172        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/05/19 16:05:33.0870 2172        IntcAzAudAddService (90a10b39896040b3154613c11c932aeb) C:\Windows\system32\drivers\RTKVHDA.sys
2011/05/19 16:05:34.0229 2172        intelide        (988981c840084f480ba9e3319cebde1b) C:\Windows\system32\drivers\intelide.sys
2011/05/19 16:05:34.0369 2172        intelppm        (ce44cc04262f28216dd4341e9e36a16f) C:\Windows\system32\DRIVERS\intelppm.sys
2011/05/19 16:05:34.0541 2172        IpFilterDriver  (880c6f86cc3f551b8fea2c11141268c0) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/05/19 16:05:34.0759 2172        IPMIDRV        (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
2011/05/19 16:05:34.0790 2172        IPNAT          (10077c35845101548037df04fd1a420b) C:\Windows\system32\DRIVERS\ipnat.sys
2011/05/19 16:05:34.0868 2172        IRENUM          (a82f328f4792304184642d6d397bb1e3) C:\Windows\system32\drivers\irenum.sys
2011/05/19 16:05:34.0931 2172        isapnp          (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
2011/05/19 16:05:34.0978 2172        iScsiPrt        (4dca456d4d5723f8fa9c6760d240b0df) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/05/19 16:05:35.0118 2172        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/05/19 16:05:35.0321 2172        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/05/19 16:05:35.0508 2172        JRAID          (c1632fe31d1824a43dea29725312e3fa) C:\Windows\system32\drivers\jraid.sys
2011/05/19 16:05:35.0726 2172        kbdclass        (b076b2ab806b3f696dab21375389101c) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/05/19 16:05:35.0773 2172        kbdhid          (d2600cb17b7408b4a83f231dc9a11ac3) C:\Windows\system32\drivers\kbdhid.sys
2011/05/19 16:05:35.0851 2172        KSecDD          (0a829977b078dea11641fc2af87ceade) C:\Windows\system32\Drivers\ksecdd.sys
2011/05/19 16:05:35.0945 2172        lltdio          (fd015b4f95daa2b712f0e372a116fbad) C:\Windows\system32\DRIVERS\lltdio.sys
2011/05/19 16:05:36.0007 2172        LSI_FC          (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
2011/05/19 16:05:36.0085 2172        LSI_SAS        (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
2011/05/19 16:05:36.0163 2172        LSI_SCSI        (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
2011/05/19 16:05:36.0210 2172        luafv          (42885bb44b6e065b8575a8dd6c430c52) C:\Windows\system32\drivers\luafv.sys
2011/05/19 16:05:36.0257 2172        megasas        (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
2011/05/19 16:05:36.0335 2172        Modem          (21755967298a46fb6adfec9db6012211) C:\Windows\system32\drivers\modem.sys
2011/05/19 16:05:36.0382 2172        monitor        (7446e104a5fe5987ca9e4983fbac4f97) C:\Windows\system32\DRIVERS\monitor.sys
2011/05/19 16:05:36.0428 2172        mouclass        (5fba13c1a1841b0885d316ed3589489d) C:\Windows\system32\DRIVERS\mouclass.sys
2011/05/19 16:05:36.0475 2172        mouhid          (b569b5c5d3bde545df3a6af512cccdba) C:\Windows\system32\DRIVERS\mouhid.sys
2011/05/19 16:05:36.0506 2172        MountMgr        (01f1e5a3e4877c931cbb31613fec16a6) C:\Windows\system32\drivers\mountmgr.sys
2011/05/19 16:05:36.0553 2172        mpio            (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
2011/05/19 16:05:36.0584 2172        mpsdrv          (6e7a7f0c1193ee5648443fe2d4b789ec) C:\Windows\system32\drivers\mpsdrv.sys
2011/05/19 16:05:36.0662 2172        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/05/19 16:05:36.0709 2172        MRxDAV          (1d8828b98ee309d65e006f0829e280e5) C:\Windows\system32\drivers\mrxdav.sys
2011/05/19 16:05:36.0803 2172        mrxsmb          (8af705ce1bb907932157fab821170f27) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/05/19 16:05:36.0881 2172        mrxsmb10        (47e13ab23371be3279eef22bbfa2c1be) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/05/19 16:05:36.0928 2172        mrxsmb20        (90b3fc7bd6b3d7ee7635debba2187f66) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/05/19 16:05:36.0990 2172        msahci          (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys
2011/05/19 16:05:37.0037 2172        msdsm          (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
2011/05/19 16:05:37.0099 2172        Msfs            (729eafefd4e7417165f353a18dbe947d) C:\Windows\system32\drivers\Msfs.sys
2011/05/19 16:05:37.0162 2172        msisadrv        (5f454a16a5146cd91a176d70f0cfa3ec) C:\Windows\system32\drivers\msisadrv.sys
2011/05/19 16:05:37.0208 2172        MSKSSRV        (892cedefa7e0ffe7be8da651b651d047) C:\Windows\system32\drivers\MSKSSRV.sys
2011/05/19 16:05:37.0255 2172        MSPCLOCK        (ae2cb1da69b2676b4cee2a501af5871c) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/05/19 16:05:37.0286 2172        MSPQM          (f910da84fa90c44a3addb7cd874463fd) C:\Windows\system32\drivers\MSPQM.sys
2011/05/19 16:05:37.0318 2172        MsRPC          (84571c0ae07647ba38d493f5f0015df7) C:\Windows\system32\drivers\MsRPC.sys
2011/05/19 16:05:37.0364 2172        mssmbios        (4385c80ede885e25492d408cad91bd6f) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/05/19 16:05:37.0396 2172        MSTEE          (c826dd1373f38afd9ca46ec3c436a14e) C:\Windows\system32\drivers\MSTEE.sys
2011/05/19 16:05:37.0442 2172        Mup            (fa7aa70050cf5e2d15de00941e5665e5) C:\Windows\system32\Drivers\mup.sys
2011/05/19 16:05:37.0505 2172        NativeWifiP    (6da4a0fc7c0e83df0cb3cfd0a514c3bc) C:\Windows\system32\DRIVERS\nwifi.sys
2011/05/19 16:05:37.0598 2172        NDIS            (227c11e1e7cf6ef8afb2a238d209760c) C:\Windows\system32\drivers\ndis.sys
2011/05/19 16:05:37.0661 2172        NdisTapi        (81659cdcbd0f9a9e07e6878ad8c78d3f) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/05/19 16:05:37.0692 2172        Ndisuio        (5de5ee546bf40838ebe0e01cb629df64) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/05/19 16:05:37.0739 2172        NdisWan        (397402adcbb8946223a1950101f6cd94) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/05/19 16:05:37.0786 2172        NDProxy        (1b24fa907af283199a81b3bb37e5e526) C:\Windows\system32\drivers\NDProxy.sys
2011/05/19 16:05:37.0848 2172        NetBIOS        (356dbb9f98e8dc1028dd3092fceeb877) C:\Windows\system32\DRIVERS\netbios.sys
2011/05/19 16:05:37.0879 2172        netbt          (e3a168912e7eefc3bd3b814720d68b41) C:\Windows\system32\DRIVERS\netbt.sys
2011/05/19 16:05:38.0035 2172        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/05/19 16:05:38.0113 2172        Npfs            (4f9832beb9fafd8ceb0e541f1323b26e) C:\Windows\system32\drivers\Npfs.sys
2011/05/19 16:05:38.0207 2172        nsiproxy        (b488dfec274de1fc9d653870ef2587be) C:\Windows\system32\drivers\nsiproxy.sys
2011/05/19 16:05:38.0300 2172        Ntfs            (37430aa7a66d7a63407adc2c0d05e9f6) C:\Windows\system32\drivers\Ntfs.sys
2011/05/19 16:05:38.0410 2172        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/05/19 16:05:38.0456 2172        Null            (ec5efb3c60f1b624648344a328bce596) C:\Windows\system32\drivers\Null.sys
2011/05/19 16:05:38.0534 2172        nvraid          (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
2011/05/19 16:05:38.0581 2172        nvrd32          (ed399014a8029de02ba5ae01da8cc9ee) C:\Windows\system32\drivers\nvrd32.sys
2011/05/19 16:05:38.0628 2172        nvstor          (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
2011/05/19 16:05:38.0675 2172        nvstor32        (703e3a7093b0fac0eebadbb8e931ecaf) C:\Windows\system32\drivers\nvstor32.sys
2011/05/19 16:05:38.0722 2172        nv_agp          (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
2011/05/19 16:05:38.0846 2172        ohci1394        (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
2011/05/19 16:05:38.0940 2172        Parport        (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/05/19 16:05:38.0987 2172        partmgr        (555a5b2c8022983bc7467bc925b222ee) C:\Windows\system32\drivers\partmgr.sys
2011/05/19 16:05:39.0034 2172        Parvdm          (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/05/19 16:05:39.0080 2172        pci            (1085d75657807e0e8b32f9e19a1647c3) C:\Windows\system32\drivers\pci.sys
2011/05/19 16:05:39.0127 2172        pciide          (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys
2011/05/19 16:05:39.0205 2172        pcmcia          (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2011/05/19 16:05:39.0283 2172        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/05/19 16:05:39.0470 2172        PptpMiniport    (c04dec5ace67c5247b150c4223970bb7) C:\Windows\system32\DRIVERS\raspptp.sys
2011/05/19 16:05:39.0517 2172        Processor      (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
2011/05/19 16:05:39.0595 2172        PSched          (2c8bae55247c4e09352e870292e4d1ab) C:\Windows\system32\DRIVERS\pacer.sys
2011/05/19 16:05:39.0658 2172        ql2300          (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
2011/05/19 16:05:39.0751 2172        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/05/19 16:05:39.0798 2172        QWAVEdrv        (d2b3e2b7426dc23e185fbc73c8936c12) C:\Windows\system32\drivers\qwavedrv.sys
2011/05/19 16:05:39.0845 2172        RasAcd          (bd7b30f55b3649506dd8b3d38f571d2a) C:\Windows\system32\DRIVERS\rasacd.sys
2011/05/19 16:05:39.0892 2172        Rasl2tp        (68b0019fee429ec49d29017af937e482) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/05/19 16:05:39.0938 2172        RasPppoe        (ccf4e9c6cbbac81437f88cb2ae0b6c96) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/05/19 16:05:39.0985 2172        rdbss          (54129c5d9581bbec8bd1ebd3ba813f47) C:\Windows\system32\DRIVERS\rdbss.sys
2011/05/19 16:05:40.0032 2172        RDPCDD          (794585276b5d7fca9f3fc15543f9f0b9) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/05/19 16:05:40.0094 2172        rdpdr          (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
2011/05/19 16:05:40.0157 2172        RDPENCDD        (980b56e2e273e19d3a9d72d5c420f008) C:\Windows\system32\drivers\rdpencdd.sys
2011/05/19 16:05:40.0204 2172        RDPWD          (e2afac98fc6ca2ad2d09f2de1bc71ad9) C:\Windows\system32\drivers\RDPWD.sys
2011/05/19 16:05:40.0297 2172        rspndr          (97e939d2128fec5d5a3e6e79b290a2f4) C:\Windows\system32\DRIVERS\rspndr.sys
2011/05/19 16:05:40.0360 2172        RTL8169        (3d2b6520699d1dcd5a13f9e7cad62199) C:\Windows\system32\DRIVERS\Rtlh86.sys
2011/05/19 16:05:40.0422 2172        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/05/19 16:05:40.0500 2172        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/05/19 16:05:40.0578 2172        Ser2pl          (fd245689004356aa2928b678736b9abd) C:\Windows\system32\DRIVERS\ser2pl.sys
2011/05/19 16:05:40.0625 2172        Serenum        (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\DRIVERS\serenum.sys
2011/05/19 16:05:40.0672 2172        Serial          (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/05/19 16:05:40.0734 2172        sermouse        (450accd77ec5cea720c1cdb9e26b953b) C:\Windows\system32\DRIVERS\sermouse.sys
2011/05/19 16:05:40.0828 2172        sfdrv01        (4c0d673281178cb496011a2e28571fc8) C:\Windows\system32\drivers\sfdrv01.sys
2011/05/19 16:05:40.0874 2172        sffdisk        (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys
2011/05/19 16:05:40.0921 2172        sffp_mmc        (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
2011/05/19 16:05:40.0968 2172        sffp_sd        (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys
2011/05/19 16:05:41.0015 2172        sfhlp02        (15be2b5e4dc5b8623cf167720682abc9) C:\Windows\system32\drivers\sfhlp02.sys
2011/05/19 16:05:41.0046 2172        sfloppy        (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/05/19 16:05:41.0108 2172        sfvfs02        (d5a7e09d2c6a702809e49190d52adc9f) C:\Windows\system32\drivers\sfvfs02.sys
2011/05/19 16:05:41.0155 2172        sisagp          (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys
2011/05/19 16:05:41.0202 2172        SiSRaid2        (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
2011/05/19 16:05:41.0249 2172        SiSRaid4        (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
2011/05/19 16:05:41.0327 2172        Smb            (ac0d90738adb51a6fd12ff00874a2162) C:\Windows\system32\DRIVERS\smb.sys
2011/05/19 16:05:41.0405 2172        spldr          (426f9b029aa9162ceccf65369457d046) C:\Windows\system32\drivers\spldr.sys
2011/05/19 16:05:41.0498 2172        srv            (038579c35f7cad4a4bbf735dbf83277d) C:\Windows\system32\DRIVERS\srv.sys
2011/05/19 16:05:41.0530 2172        srv2            (6971a757af8cb5e2cbcbb76cc530db6c) C:\Windows\system32\DRIVERS\srv2.sys
2011/05/19 16:05:41.0561 2172        srvnet          (9e1a4603b874eebce0298113951abefb) C:\Windows\system32\DRIVERS\srvnet.sys
2011/05/19 16:05:41.0623 2172        ssmdrv          (5ec550b8952882ee856b862cf648522d) C:\Windows\system32\DRIVERS\ssmdrv.sys
2011/05/19 16:05:41.0670 2172        swenum          (1379bdb336f8158c176a465e30759f57) C:\Windows\system32\DRIVERS\swenum.sys
2011/05/19 16:05:41.0732 2172        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/05/19 16:05:41.0764 2172        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/05/19 16:05:41.0810 2172        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/05/19 16:05:41.0904 2172        SynTP          (db835c324cd488a86e9bfc2c3fd29cd8) C:\Windows\system32\DRIVERS\SynTP.sys
2011/05/19 16:05:42.0044 2172        Tcpip          (2c1f7005aa3b62721bfdb307bd5f5010) C:\Windows\system32\drivers\tcpip.sys
2011/05/19 16:05:42.0122 2172        Tcpip6          (2c1f7005aa3b62721bfdb307bd5f5010) C:\Windows\system32\DRIVERS\tcpip.sys
2011/05/19 16:05:42.0169 2172        tcpipreg        (5ce0c4a7b12d0067dad527d72b68c726) C:\Windows\system32\drivers\tcpipreg.sys
2011/05/19 16:05:42.0216 2172        TDPIPE          (964248aef49c31fa6a93201a73ffaf50) C:\Windows\system32\drivers\tdpipe.sys
2011/05/19 16:05:42.0263 2172        TDTCP          (7d2c1ae1648a60fce4aa0f7982e419d3) C:\Windows\system32\drivers\tdtcp.sys
2011/05/19 16:05:42.0294 2172        tdx            (ab4fde8af4a0270a46a001c08cbce1c2) C:\Windows\system32\DRIVERS\tdx.sys
2011/05/19 16:05:42.0341 2172        TermDD          (2c549bd9dd091fbfaa0a2a48e82ec2fb) C:\Windows\system32\DRIVERS\termdd.sys
2011/05/19 16:05:42.0606 2172        tssecsrv        (29f0eca726f0d51f7e048bdb0b372f29) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/05/19 16:05:42.0840 2172        tunmp          (65e953bc0084d44498b51f59784d2a82) C:\Windows\system32\DRIVERS\tunmp.sys
2011/05/19 16:05:42.0918 2172        tunnel          (4a39bda5e0fd30bdf4884f9d33ae6105) C:\Windows\system32\DRIVERS\tunnel.sys
2011/05/19 16:05:42.0980 2172        uagp35          (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
2011/05/19 16:05:43.0027 2172        udfs            (6348da98707ceda8a0dfb05820e17732) C:\Windows\system32\DRIVERS\udfs.sys
2011/05/19 16:05:43.0074 2172        uliagpkx        (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
2011/05/19 16:05:43.0121 2172        uliahci        (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
2011/05/19 16:05:43.0183 2172        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/05/19 16:05:43.0214 2172        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/05/19 16:05:43.0261 2172        umbus          (3fb78f1d1dd86d87bececd9dffa24dd9) C:\Windows\system32\DRIVERS\umbus.sys
2011/05/19 16:05:43.0339 2172        USB28xxBGA      (675cce4a8df14aa0b3c3e23424853c50) C:\Windows\system32\DRIVERS\emBDA.sys
2011/05/19 16:05:43.0386 2172        USB28xxOEM      (548ff2d95ba0793a79ec679081313974) C:\Windows\system32\DRIVERS\emOEM.sys
2011/05/19 16:05:43.0448 2172        usbaudio        (f6bf998ae33e3fb6c7d27f0560f1173f) C:\Windows\system32\drivers\usbaudio.sys
2011/05/19 16:05:43.0511 2172        usbccgp        (03b01e8dbd2da2b49157b7e51912aaf2) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/05/19 16:05:43.0558 2172        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/05/19 16:05:43.0636 2172        usbehci        (2f83363f98484f8edaf49f9b41520d14) C:\Windows\system32\DRIVERS\usbehci.sys
2011/05/19 16:05:43.0682 2172        usbhub          (14d2a4dcd92c0b3368667aed6893463d) C:\Windows\system32\DRIVERS\usbhub.sys
2011/05/19 16:05:43.0729 2172        usbohci        (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2011/05/19 16:05:43.0760 2172        usbprint        (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\DRIVERS\usbprint.sys
2011/05/19 16:05:43.0823 2172        usbscan        (b1f95285c08ddfe00c0b955462637ec7) C:\Windows\system32\DRIVERS\usbscan.sys
2011/05/19 16:05:43.0885 2172        usbser          (c0488cc01a1c686b08a3d360c7f50324) C:\Windows\system32\drivers\usbser.sys
2011/05/19 16:05:43.0916 2172        USBSTOR        (7887ce56934e7f104e98c975f47353c5) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/05/19 16:05:44.0010 2172        usbuhci        (7747b902f6b7d0096f9c2bf55d3247f1) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/05/19 16:05:44.0072 2172        vga            (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/05/19 16:05:44.0119 2172        VgaSave        (17a8f877314e4067f8c8172cc6d9101c) C:\Windows\System32\drivers\vga.sys
2011/05/19 16:05:44.0166 2172        viaagp          (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
2011/05/19 16:05:44.0197 2172        ViaC7          (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
2011/05/19 16:05:44.0244 2172        viaide          (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
2011/05/19 16:05:44.0275 2172        viamraid        (7dc3e1dc6e4f8be381c31bfea578412a) C:\Windows\system32\drivers\viamraid.sys
2011/05/19 16:05:44.0322 2172        volmgr          (103e84c95832d0ed93507997cc7b54e8) C:\Windows\system32\drivers\volmgr.sys
2011/05/19 16:05:44.0369 2172        volmgrx        (294da8d3f965f6a8db934a83c7b461ff) C:\Windows\system32\drivers\volmgrx.sys
2011/05/19 16:05:44.0416 2172        volsnap        (80dc0c9bcb579ed9815001a4d37cbfd5) C:\Windows\system32\drivers\volsnap.sys
2011/05/19 16:05:44.0462 2172        vsmraid        (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
2011/05/19 16:05:44.0525 2172        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/05/19 16:05:44.0556 2172        Wanarp          (6798c1209a53b5a0ded8d437c45145ff) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/19 16:05:44.0587 2172        Wanarpv6        (6798c1209a53b5a0ded8d437c45145ff) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/19 16:05:44.0634 2172        Wd              (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
2011/05/19 16:05:44.0743 2172        Wdf01000        (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/05/19 16:05:44.0946 2172        WmiAcpi        (17eac0d023a65fa9b02114cc2baacad5) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/05/19 16:05:45.0055 2172        WpdUsb          (2d27171b16a577ef14c1273668753485) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/05/19 16:05:45.0118 2172        ws2ifsl        (84620aecdcfd2a7a14e6263927d8c0ed) C:\Windows\system32\drivers\ws2ifsl.sys
2011/05/19 16:05:45.0227 2172        WudfPf          (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
2011/05/19 16:05:45.0305 2172        WUDFRd          (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/05/19 16:05:45.0430 2172        ================================================================================
2011/05/19 16:05:45.0430 2172        Scan finished
2011/05/19 16:05:45.0430 2172        ================================================================================


cosinus 19.05.2011 15:16

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

claudia03205 19.05.2011 15:42

so auch das hab ich geschaft, puhh sind ganzschöne schritte die man hier so macht und dann ich noch als unwissende:)

Code:

ComboFix 11-05-18.04 - Necki 19.05.2011  16:28:38.1.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6000.0.1252.49.1031.18.2038.1201 [GMT 2:00]
ausgeführt von:: c:\users\Necki\Desktop\cofi.exe.exe
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\firststeps\FirstSteps.exe
c:\users\Necki\AppData\Roaming\chrtmp
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-04-19 bis 2011-05-19  ))))))))))))))))))))))))))))))
.
.
2011-05-19 14:36 . 2011-05-19 14:36        --------        d-----w-        c:\users\Necki\AppData\Local\temp
2011-05-19 13:43 . 2011-05-19 13:43        --------        d-----w-        C:\_OTL
2011-05-18 14:58 . 2011-05-18 14:58        --------        d-----w-        c:\users\Necki\AppData\Roaming\Malwarebytes
2011-05-18 14:57 . 2010-12-20 16:09        38224        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-18 14:57 . 2011-05-18 14:57        --------        d-----w-        c:\programdata\Malwarebytes
2011-05-18 14:57 . 2010-12-20 16:08        20952        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-05-18 14:57 . 2011-05-18 14:57        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2011-05-18 14:16 . 2011-05-18 14:16        1186056        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-05-17 15:54 . 2011-05-17 15:54        0        ----a-w-        c:\users\Necki\AppData\Local\BIT4EEB.tmp
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-18 17:56 . 2011-04-05 20:05        142296        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-10 1232896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"recinfo866"="c:\recinfo\RecInfo.exe" [2007-06-06 2768896]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-17 102400]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 4669440]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2007-07-26 192512]
"GrooveMonitor"="d:\office12\GrooveMonitor.exe" [2008-10-25 31072]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-02 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-02 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-02 133656]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"AVMWlanClient"="c:\program files\avmwlanstick\FRITZWLANMini.exe" [2006-03-01 327680]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FRITZ!DSL Startcenter.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Startcenter.lnk
backup=c:\windows\pss\FRITZ!DSL Startcenter.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 13:57        948672        ----a-r-        c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-18 06:58        40368        ----a-w-        c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 07:27        153136        ----a-w-        c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2010-12-20 16:08        963976        ----a-w-        c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57        153136        ----a-w-        c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 Automatisches LiveUpdate - Scheduler;Automatisches LiveUpdate - Scheduler;c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [x]
R2 gupdate1c9e48843394e20;Google Update Service (gupdate1c9e48843394e20);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-03 133104]
R3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\DRIVERS\fwlanusb.sys [2006-02-23 264704]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-03 133104]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-06-09 108289]
S3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [2006-11-17 118784]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - KLMD25
*Deregistered* - klmd25
.
Inhalt des "geplante Tasks" Ordners
.
2011-05-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-03 20:15]
.
2011-05-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-03 20:16]
.
2011-05-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-03 20:16]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.bearshare.com/de/
IE: Nach Microsoft E&xel exportieren - d:\office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Necki\AppData\Roaming\Mozilla\Firefox\Profiles\bjx89sl2.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://google.de/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.8&q=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{a51a36e6-31e7-4838-9ff7-76298b527ec0} - (no file)
BHO-{6D023EBF-70B8-45A6-9ED5-556515FA0FE4} - c:\program files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-IS CfgWiz - c:\program files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe
MSConfigStartUp-osCheck - c:\program files\Norton Internet Security\osCheck.exe
MSConfigStartUp-PCSuiteTrayApplication - c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
AddRemove-Cradle of Rome - c:\big fish games\Cradle of Rome\Uninstall.exe
AddRemove-Poker Superstars II - c:\big fish games\Poker Superstars II\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-05-19 16:36
Windows 6.0.6000  NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-05-19  16:39:00
ComboFix-quarantined-files.txt  2011-05-19 14:38
.
Vor Suchlauf: 20 Verzeichnis(se), 59.218.034.688 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 60.269.211.648 Bytes frei
.
- - End Of File - - 432286102F19EFAFB530BD22478F8C6B


cosinus 19.05.2011 18:43

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.


Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

claudia03205 19.05.2011 20:20

hier schonmla osam

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 21:20:09 on 19.05.2011

OS: Windows Vista Home Premium Edition (Build 6000), 32-bit
Default Browser: Mozilla Corporation Firefox 4.0

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Software Updater.job" - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - D:\Office12\MLCFG32.CPL
"Nero BurnRights" - "Nero AG" - C:\Program Files\Nero\Nero 7\Nero Toolkit\NeroBurnRights.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgio" (avgio) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\Users\Necki\AppData\Local\Temp\catchme.sys  (File not found)
"Hotkey" (Hotkey) - ? - C:\Windows\system32\drivers\Hotkey.sys  (File found, but it contains no detailed information)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"StarForce Protection Environment Driver (version 1.x)" (sfdrv01) - "Protection Technology" - C:\Windows\System32\drivers\sfdrv01.sys
"StarForce Protection Helper Driver (version 2.x)" (sfhlp02) - "Protection Technology" - C:\Windows\System32\drivers\sfhlp02.sys
"StarForce Protection VFS Driver (version 2.x)" (sfvfs02) - "Protection Technology" - C:\Windows\System32\drivers\sfvfs02.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{7D4D6379-F301-4311-BEBA-E26EB0561882} "NeroDigitalColumnHandler Class" - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{88FED34C-F0CA-4636-A375-3CB6248B04CD} "Local Groove Web Services Protocol" - "Microsoft Corporation" - D:\Office12\GrooveSystemServices.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - D:\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - D:\Office12\ONFILTER.DLL
{00020d75-0000-0000-c000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - D:\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2} "NeroCoverEdLiveIcons Class" - "Nero AG" - C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll
{B327765E-D724-4347-8B16-78AE18552FC3} "NeroDigitalIconHandler Class" - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
{7F1CF152-04F8-453A-B34C-E609530A9DC8} "NeroDigitalPropSheetHandler Class" - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} "Nokia Phone Browser" - ? - C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll  (File not found)
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - D:\Office12\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} "Java Plug-in 1.6.0_05" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - D:\Office12\ONBttnIE.dll
"ICQ7" - "ICQ, LLC." - C:\Program Files\ICQ7.0\ICQ.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - D:\Office12\REFIEBAR.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - D:\Office12\GrooveShellExtensions.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Necki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"AVMWlanClient" - "AVM Berlin GmbH" - C:\Program Files\avmwlanstick\FRITZWLANMini.exe
"GrooveMonitor" - "Microsoft Corporation" - "D:\Office12\GrooveMonitor.exe"
"HotkeyApp" - "Wistron" - "C:\Program Files\Launch Manager\HotkeyApp.exe"
"NeroFilterCheck" - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"recinfo866" - ? - c:\RecInfo\RecInfo.exe
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"hpzsnt07" - "HP" - C:\Windows\system32\hpzsnt07.dll
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Automatisches LiveUpdate - Scheduler" (Automatisches LiveUpdate - Scheduler) - ? - "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"  (File not found)
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Fujitsu Siemens Computers Diagnostic Testhandler" (TestHandler) - "Fujitsu Siemens Computers" - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate1c9e48843394e20)" (gupdate1c9e48843394e20) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Microsoft Office Groove Audit Service" (Microsoft Office Groove Audit Service) - "Microsoft Corporation" - D:\Office12\GrooveAuditService.exe
"NBService" (NBService) - "Nero AG" - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"WisLMSvc" (WisLMSvc) - "Wistron Corp." - C:\Program Files\Launch Manager\WisLMSvc.exe

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


claudia03205 19.05.2011 20:25

Code:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:                       
Windows Version:                Windows Vista Home Premium Edition
Windows Information:                (build 6000), 32-bit
Base Board Manufacturer:        FUJITSU SIEMENS
BIOS Manufacturer:                Phoenix Technologies LTD
System Manufacturer:                FUJITSU SIEMENS
System Product Name:                AMILO Li 2727
Logical Drives Mask:                0x0000001c

Kernel Drivers (total 136):
  0x82400000 \SystemRoot\system32\ntkrnlpa.exe
  0x827A1000 \SystemRoot\system32\hal.dll
  0x802C6000 \SystemRoot\system32\kdcom.dll
  0x80266000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
  0x8025D000 \SystemRoot\system32\PSHED.dll
  0x80255000 \SystemRoot\system32\BOOTVID.dll
  0x8021A000 \SystemRoot\system32\CLFS.SYS
  0x8051F000 \SystemRoot\system32\CI.dll
  0x804AE000 \SystemRoot\system32\drivers\Wdf01000.sys
  0x8020C000 \SystemRoot\system32\drivers\WDFLDR.SYS
  0x8046B000 \SystemRoot\system32\drivers\acpi.sys
  0x80203000 \SystemRoot\system32\drivers\WMILIB.SYS
  0x80463000 \SystemRoot\system32\drivers\msisadrv.sys
  0x8043E000 \SystemRoot\system32\drivers\pci.sys
  0x8042F000 \SystemRoot\system32\drivers\volmgr.sys
  0x80200000 \SystemRoot\system32\DRIVERS\compbatt.sys
  0x80425000 \SystemRoot\system32\DRIVERS\BATTC.SYS
  0x80415000 \SystemRoot\System32\drivers\mountmgr.sys
  0x8040E000 \SystemRoot\system32\drivers\intelide.sys
  0x80400000 \SystemRoot\system32\drivers\PCIIDEX.SYS
  0x807E7000 \SystemRoot\system32\drivers\nvraid.sys
  0x807C6000 \SystemRoot\system32\drivers\CLASSPNP.SYS
  0x8077C000 \SystemRoot\System32\drivers\volmgrx.sys
  0x806B5000 \SystemRoot\system32\DRIVERS\iaStor.sys
  0x806AD000 \SystemRoot\system32\drivers\atapi.sys
  0x8068F000 \SystemRoot\system32\drivers\ataport.SYS
  0x80671000 \SystemRoot\system32\drivers\vsmraid.sys
  0x80631000 \SystemRoot\system32\drivers\storport.sys
  0x80600000 \SystemRoot\system32\drivers\fltmgr.sys
  0x823F0000 \SystemRoot\system32\drivers\fileinfo.sys
  0x822EC000 \SystemRoot\system32\drivers\ndis.sys
  0x822C1000 \SystemRoot\system32\drivers\msrpc.sys
  0x82288000 \SystemRoot\system32\drivers\NETIO.SYS
  0x87EF8000 \SystemRoot\System32\Drivers\Ntfs.sys
  0x8221E000 \SystemRoot\System32\Drivers\ksecdd.sys
  0x87EC2000 \SystemRoot\system32\drivers\volsnap.sys
  0x82216000 \SystemRoot\System32\Drivers\spldr.sys
  0x87EBA000 \SystemRoot\System32\drivers\sfhlp02.sys
  0x87E99000 \SystemRoot\System32\drivers\partmgr.sys
  0x87E8A000 \SystemRoot\System32\Drivers\mup.sys
  0x87E65000 \SystemRoot\System32\drivers\ecache.sys
  0x87E54000 \SystemRoot\system32\drivers\disk.sys
  0x87E4B000 \SystemRoot\system32\drivers\crcdisk.sys
  0x8A636000 \SystemRoot\system32\DRIVERS\tunnel.sys
  0x89179000 \SystemRoot\system32\DRIVERS\tunmp.sys
  0x89182000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
  0x8A628000 \SystemRoot\system32\DRIVERS\intelppm.sys
  0x8BBB3000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
  0x8BB14000 \SystemRoot\System32\drivers\dxgkrnl.sys
  0x8A61B000 \SystemRoot\System32\drivers\watchdog.sys
  0x8A610000 \SystemRoot\system32\DRIVERS\usbuhci.sys
  0x8BAD7000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
  0x8A602000 \SystemRoot\system32\DRIVERS\usbehci.sys
  0x8A78D000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
  0x8BA1E000 \SystemRoot\system32\DRIVERS\athr.sys
  0x8A727000 \SystemRoot\system32\DRIVERS\CmBatt.sys
  0x8A77A000 \SystemRoot\system32\DRIVERS\i8042prt.sys
  0x8A76F000 \SystemRoot\system32\DRIVERS\kbdclass.sys
  0x8C3D3000 \SystemRoot\system32\DRIVERS\SynTP.sys
  0x88C57000 \SystemRoot\system32\DRIVERS\USBD.SYS
  0x8A7F5000 \SystemRoot\system32\DRIVERS\mouclass.sys
  0x8BA06000 \SystemRoot\system32\DRIVERS\cdrom.sys
  0x88C39000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
  0x8C3A8000 \SystemRoot\system32\DRIVERS\msiscsi.sys
  0x8C39D000 \SystemRoot\system32\DRIVERS\TDI.SYS
  0x8C386000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
  0x8C37B000 \SystemRoot\system32\DRIVERS\ndistapi.sys
  0x8C358000 \SystemRoot\system32\DRIVERS\ndiswan.sys
  0x88898000 \SystemRoot\system32\DRIVERS\raspppoe.sys
  0x8C345000 \SystemRoot\system32\DRIVERS\raspptp.sys
  0x8C31E000 \SystemRoot\system32\DRIVERS\termdd.sys
  0x82200000 \SystemRoot\system32\DRIVERS\swenum.sys
  0x8C2F4000 \SystemRoot\system32\DRIVERS\ks.sys
  0x8A641000 \SystemRoot\system32\DRIVERS\mssmbios.sys
  0x8C32D000 \SystemRoot\system32\DRIVERS\umbus.sys
  0x8C210000 \SystemRoot\system32\DRIVERS\usbhub.sys
  0x88D50000 \SystemRoot\System32\Drivers\NDProxy.SYS
  0x8C64B000 \SystemRoot\system32\drivers\RTKVHDA.sys
  0x8C503000 \SystemRoot\system32\drivers\portcls.sys
  0x8C4DE000 \SystemRoot\system32\drivers\drmk.sys
  0x891EE000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
  0x89090000 \SystemRoot\System32\Drivers\Null.SYS
  0x89097000 \SystemRoot\System32\Drivers\Beep.SYS
  0x8C204000 \SystemRoot\System32\drivers\vga.sys
  0x8C4BD000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
  0x890EC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
  0x890F4000 \SystemRoot\system32\drivers\rdpencdd.sys
  0x8C33A000 \SystemRoot\System32\Drivers\Msfs.SYS
  0x8C48F000 \SystemRoot\System32\Drivers\Npfs.SYS
  0x888A7000 \SystemRoot\System32\DRIVERS\rasacd.sys
  0x8C92A000 \SystemRoot\System32\drivers\tcpip.sys
  0x8C436000 \SystemRoot\System32\drivers\fwpkclnt.sys
  0x8C421000 \SystemRoot\system32\DRIVERS\tdx.sys
  0x8C40D000 \SystemRoot\system32\DRIVERS\smb.sys
  0x8C604000 \SystemRoot\system32\drivers\afd.sys
  0x8C8F8000 \SystemRoot\System32\DRIVERS\netbt.sys
  0x8C8E2000 \SystemRoot\system32\DRIVERS\pacer.sys
  0x8C8D4000 \SystemRoot\system32\DRIVERS\netbios.sys
  0x8C8C1000 \SystemRoot\system32\DRIVERS\wanarp.sys
  0x8906E000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
  0x8C886000 \SystemRoot\system32\DRIVERS\rdbss.sys
  0x8C254000 \SystemRoot\system32\drivers\nsiproxy.sys
  0x88C30000 \SystemRoot\System32\Drivers\Hotkey.SYS
  0x8C86F000 \SystemRoot\System32\Drivers\dfsc.sys
  0x8C853000 \SystemRoot\system32\DRIVERS\avipbb.sys
  0x88C49000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
  0x8C530000 \SystemRoot\System32\Drivers\crashdmp.sys
  0x8A64B000 \SystemRoot\System32\Drivers\dump_iaStor.sys
  0x91A00000 \SystemRoot\System32\win32k.sys
  0x8C25E000 \SystemRoot\System32\drivers\Dxapi.sys
  0x90162000 \SystemRoot\system32\DRIVERS\monitor.sys
  0xA5800000 \SystemRoot\System32\TSDDD.dll
  0xA5810000 \SystemRoot\System32\cdd.dll
  0xA694A000 \SystemRoot\system32\drivers\luafv.sys
  0xA6876000 \SystemRoot\system32\DRIVERS\avgntflt.sys
  0xA685C000 \SystemRoot\system32\drivers\WudfPf.sys
  0x88DD0000 \SystemRoot\system32\DRIVERS\lltdio.sys
  0xA8778000 \SystemRoot\system32\DRIVERS\nwifi.sys
  0x8C272000 \SystemRoot\system32\DRIVERS\ndisuio.sys
  0xA68F7000 \SystemRoot\system32\DRIVERS\rspndr.sys
  0xA866B000 \SystemRoot\system32\drivers\HTTP.sys
  0xA8610000 \SystemRoot\System32\DRIVERS\srvnet.sys
  0xA8FE7000 \SystemRoot\system32\DRIVERS\bowser.sys
  0xA8FD3000 \SystemRoot\System32\drivers\mpsdrv.sys
  0xA8FB3000 \SystemRoot\system32\drivers\mrxdav.sys
  0xA8F95000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
  0xA8F5C000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
  0xA8F4A000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
  0xA8F26000 \SystemRoot\System32\DRIVERS\srv2.sys
  0xA8ED5000 \SystemRoot\System32\DRIVERS\srv.sys
  0xA9172000 \SystemRoot\system32\drivers\spsys.sys
  0xA6A62000 \SystemRoot\system32\drivers\peauth.sys
  0x8C2C2000 \SystemRoot\System32\Drivers\secdrv.SYS
  0xAA354000 \SystemRoot\System32\drivers\tcpipreg.sys
  0xA9032000 \SystemRoot\system32\DRIVERS\cdfs.sys
  0x77D60000 \Windows\System32\ntdll.dll

Processes (total 60):
      0 System Idle Process
      4 System
    424 C:\Windows\System32\smss.exe
    492 csrss.exe
    536 C:\Windows\System32\wininit.exe
    548 csrss.exe
    584 C:\Windows\System32\services.exe
    596 C:\Windows\System32\lsass.exe
    604 C:\Windows\System32\lsm.exe
    680 C:\Windows\System32\winlogon.exe
    796 C:\Windows\System32\svchost.exe
    872 C:\Windows\System32\svchost.exe
    1020 C:\Windows\System32\svchost.exe
    1044 C:\Windows\System32\svchost.exe
    1064 C:\Windows\System32\svchost.exe
    1132 C:\Windows\System32\audiodg.exe
    1160 C:\Windows\System32\SLsvc.exe
    1240 C:\Windows\System32\svchost.exe
    1428 C:\Windows\System32\svchost.exe
    1600 C:\Windows\System32\spoolsv.exe
    1624 C:\Program Files\Avira\AntiVir Desktop\sched.exe
    1636 C:\Windows\System32\svchost.exe
    1908 C:\Windows\System32\dwm.exe
    1944 C:\Windows\explorer.exe
    1960 C:\Windows\System32\taskeng.exe
    276 C:\Windows\System32\taskeng.exe
    296 C:\Program Files\Google\Update\GoogleUpdate.exe
    500 C:\Program Files\Synaptics\SynTP\SynTPStart.exe
    1304 C:\Windows\RtHDVCpl.exe
    580 C:\Program Files\Launch Manager\HotkeyApp.exe
    556 D:\Office12\GrooveMonitor.exe
    1264 C:\Windows\System32\igfxtray.exe
    1852 C:\Windows\System32\hkcmd.exe
    1860 C:\Windows\System32\igfxpers.exe
    1356 C:\Windows\System32\igfxsrvc.exe
    1516 C:\Program Files\avmwlanstick\FRITZWLANMini.exe
    1172 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    1820 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    1176 C:\Windows\ehome\ehtray.exe
    1192 C:\Program Files\Windows Sidebar\sidebar.exe
    2064 C:\Windows\ehome\ehmsas.exe
    2228 C:\Program Files\Windows Sidebar\sidebar.exe
    2432 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    2480 C:\Windows\System32\svchost.exe
    2668 C:\Windows\System32\svchost.exe
    2720 C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe
    2792 C:\Windows\System32\svchost.exe
    2844 C:\Windows\System32\SearchIndexer.exe
    3384 C:\Windows\System32\taskeng.exe
    3412 C:\Program Files\Launch Manager\WisLMSvc.exe
    3576 WmiPrvSE.exe
    3704 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    3956 C:\Program Files\Mozilla Firefox\firefox.exe
    3852 C:\Windows\System32\wbem\unsecapp.exe
    3900 C:\Program Files\Mozilla Firefox\plugin-container.exe
    3224 C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32Info.exe
    1276 dllhost.exe
    3456 dllhost.exe
    2924 C:\Users\Necki\Desktop\MBRCheck.exe
    2664 C:\Windows\System32\conime.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`ee100000  (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000027`f4300000  (NTFS)

PhysicalDrive0 Model Number: WDCWD2500BEVS-22UST0, Rev: 01.01A01

      Size  Device Name          MBR Status
  --------------------------------------------
    232 GB  \\.\PhysicalDrive0  Windows 2008 MBR code detected
            SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


Done!


man ist das kompliziert, hätte ich nicht einfach meine paar daten jetzt runter ziehen können und den rechner dann formatiern können oder wäre das problem damit nicht weg?

mfg

cosinus 19.05.2011 21:13

Sieht ok aus, wir sind auch fast durch.
GMER ging nicht?

Wenn GMER nicht will mit den Kontrollscans weitermachen:

Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

claudia03205 19.05.2011 22:19

ne das ging net , gut also mache ich nochmal mit malwarebytes ein vollscan und mit dem anderen superantispyware , das wird ja bestimmt 2-3h in anspruch nehmen, werden das dann morgen posten das schaffe ich heute net mher.

gruß,
claudia

claudia03205 20.05.2011 00:24

so das mit superantisyeware habe i noch gemacht, das programm ist vieleicht mal scheiße durchzusehen.

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 05/20/2011 at 01:18 AM

Application Version : 4.52.1000

Core Rules Database Version : 7091
Trace Rules Database Version: 4903

Scan type      : Complete Scan
Total Scan Time : 01:50:19

Memory items scanned      : 622
Memory threats detected  : 0
Registry items scanned    : 9302
Registry threats detected : 0
File items scanned        : 130445
File threats detected    : 42

Adware.Tracking Cookie
        C:\Users\Necki\AppData\Roaming\Microsoft\Windows\Cookies\necki@atwola[1].txt
        C:\Users\Necki\AppData\Roaming\Microsoft\Windows\Cookies\necki@advertising[2].txt
        C:\Users\Necki\AppData\Roaming\Microsoft\Windows\Cookies\necki@tacoda.at.atwola[1].txt
        C:\Users\Necki\AppData\Roaming\Microsoft\Windows\Cookies\necki@at.atwola[2].txt
        C:\Users\Necki\AppData\Roaming\Microsoft\Windows\Cookies\necki@cdn.at.atwola[1].txt
        C:\Users\Necki\AppData\Roaming\Microsoft\Windows\Cookies\necki@ar.atwola[1].txt
        cdn1.eyewonder.com [ C:\Users\Necki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        media.mtvnservices.com [ C:\Users\Necki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        spe.atdmt.com [ C:\Users\Necki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        static.youporn.com [ C:\Users\Necki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        adserver.freenet.de [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        akamai.smartadserver.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        atdmt.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        banners.securedataimages.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        bc.youporn.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        broadcast.piximedia.fr [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        cdn1.eyewonder.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        cdn5.specificclick.net [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        ds.serving-sys.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        ec.atdmt.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        files.youporn.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        googleads.g.doubleclick.net [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        ia.media-imdb.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        imagesrv.adition.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        macromedia.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        media.kyte.tv [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        media.mtvnservices.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        media.scanscout.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        media01.kyte.tv [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        media1.break.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        msnbcmedia.msn.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        oddcast.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        s0.2mdn.net [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        secure-us.imrworldwide.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        serving-sys.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        spe.atdmt.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        static.youporn.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        vht.tradedoubler.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        www.porntube.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        www.rfporn.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        www.secmedia.de [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]
        youporn.videobox.com [ C:\Users\Necki\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RR9FAP77 ]


cosinus 20.05.2011 09:16

Und das andere Log?

claudia03205 20.05.2011 09:22

hallo,
das andere mache ich jetzt.

claudia03205 20.05.2011 10:41

so hier nun die andere mit geupdateter neuer version.

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6624

Windows 6.0.6000
Internet Explorer 7.0.6000.17037

20.05.2011 11:35:45
mbam-log-2011-05-20 (11-35-45).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 284720
Laufzeit: 1 Stunde(n), 2 Minute(n), 20 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


cosinus 20.05.2011 11:16

Sieht ok aus, da wurden nur Cookies gefunden.
Noch Probleme oder weitere Funde in der Zwischenzeit?

claudia03205 20.05.2011 11:23

nein keine funde, rechner arbeitet auch wieder schön schnell, bloß eins ist noch, das wenn ich start drücke links alles leer ist, muss man bestimmt erst wieder was einstellen oder?
und welche software zur abwehr in zukunft sollte ich nutzen?

mfg

cosinus 20.05.2011 11:27

Durch die Infektion wurde dein Startmenü leergefegt, bei mir bisher bekannten Varianten verschiebt der Schädling alle Verknüpfungen nach %tmp%\smtmp

Eigentlich sollte unhide die Verküpfungen selbst zurück an die richtige Stelle kopieren. Wenn nicht, mach es selbst.

Deine Verknüpfungen sollten jetzt hier sein:

C:\Users\[DEIN_NAME]\AppData\Local\Temp\smtmp

Sie müssen passend nach

C:\ProgramData\Microsoft\Windows\Start Menu\Programs

kopiert werden.

claudia03205 21.05.2011 08:10

guten morgen,
bei C:\Users\[DEIN_NAME]\AppData\Local\Temp\smtmp waren drei ordner drinne "1 2 3" hab die kopiert war bestimmt falsch wa, weil es immer nich nicht geht.

lg
Claudia

cosinus 21.05.2011 13:13

Ja, innerhalb dieser Unterordner musst du schauen - deswegen hab ich ja auch geschrieben "passend" kopieren.

claudia03205 22.05.2011 19:56

hallo, aso gut werd ich schon irgenwie hinbekommen.
so nun bin ich ja wieder trojaner befreit und welches programm hilft mir in zukunft dagegen? zurzeit nutzte ich ja avira zur viren abwähr.

mfg
Claudia

cosinus 23.05.2011 09:42

Zitat:

so nun bin ich ja wieder trojaner befreit und welches programm hilft mir in zukunft dagegen? zurzeit nutzte ich ja avira zur viren abwähr.
Verabschiede dich von dem Gedanken, dass ein Virenscanner vor jedem Schädling hilft. Der Virenscanner ist nur eine Art Sicherheitsgurt, auch bei angelegtem Sicherheitsgut darf man die Verkehrsregeln nicht missachten.

Halte Dich am besten grob an diese fünf Regeln:

1) Sei misstrauisch im Internet und v.a. bei unbekannten E-Mails, sei vorsichtig bei der Herausgabe persönlicher Daten!!
2) Halte Windows und alle verwendeten Programme immer aktuell
3) Führe regelmäßig Backups auf externe Medien durch
4) Arbeite mit eingeschränkten Rechten
5) Nutze sichere Programme wie zB Opera oder Firefox zum Surfen statt den IE, zum Mailen Thunderbird statt Outlook Express - E-Mails nur als reinen text anzeigen lassen

Alles noch genauer erklärt steht hier => Kompromittierung unvermeidbar?


Rechner ansonsten wieder komplett ok?

claudia03205 23.05.2011 15:38

Hallo,

alles klar danke für alles nochmal. der rechner ist soweit okay bis auf das startmenü das immernoch leer ist, aber das werd ich noch rausbekommen ;)

lg claudia

cosinus 23.05.2011 19:03

Wie gesagt muss das passend nach "C:\ProgramData\Microsoft\Windows\Start Menu\Programs" zurückkopiert werden.


Dann wären wir durch! :abklatsch:

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update



PDF-Reader aktualisieren
Dein Adobe Reader ist nicht aktuell, was ein großes Sicherheitsrisiko darstellt. Du solltest daher besser die alte Version über Systemsteuerung => Software deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst.

Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 15:03 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131