Mazequax | 04.12.2011 23:20 | http://www.trojaner-board.de/105642-...blockiert.html
der hatte das selbe Problem wie ich und der jenige der ihn beraten hat, meinte er solle einfach nen quick scan machen .. das hab ich jetzt auch gemacht und dabei ist diese OTL Logfile rausgekommen.
oh ich seh grad du hast den ja auch beraten hehehe
OTL Logfile: Code:
OTL logfile created on: 12/4/2011 11:01:44 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Windows Vista (TM) Home Premium Service Pack 2 (Version = 6.0.6002) - Type = System
Internet Explorer (Version = 8.0.6001.19154)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 86.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 97.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 576.17 Gb Total Space | 394.36 Gb Free Space | 68.45% Space Free | Partition Type: NTFS
Drive D: | 19.99 Gb Total Space | 14.04 Gb Free Space | 70.21% Space Free | Partition Type: FAT32
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV - [2010/01/04 14:55:00 | 003,404,560 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2009/03/31 03:39:36 | 000,233,472 | ---- | M] (Teruten) [Auto] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2008/04/07 03:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008/01/20 21:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/20 21:23:24 | 000,365,568 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2008/01/20 21:23:24 | 000,167,936 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand] -- -- (JL2005)
DRV - File not found [Kernel | On_Demand] -- -- (IpInIp)
DRV - File not found [Kernel | On_Demand] -- -- (EagleNT)
DRV - File not found [Kernel | On_Demand] -- -- (catchme)
DRV - [2009/04/10 23:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (winusb)
DRV - [2009/03/31 03:39:36 | 000,036,608 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009/03/20 04:01:26 | 000,121,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2009/03/20 04:01:26 | 000,090,112 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV - [2009/03/20 04:01:26 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV - [2009/03/08 13:36:57 | 000,278,984 | ---- | M] () [Kernel | Auto] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2009/03/07 10:24:17 | 000,025,416 | ---- | M] () [Kernel | Auto] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2008/06/09 00:23:00 | 007,522,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/05/28 10:54:20 | 000,022,072 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbfilter.sys -- (usbfilter)
DRV - [2008/05/06 05:36:34 | 000,171,016 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\ahcix86s.sys -- (ahcix86s)
DRV - [2008/04/28 08:26:42 | 000,014,352 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie) ATI PCI Express (3GIO)
DRV - [2008/02/14 07:56:02 | 000,118,784 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2007/10/11 20:40:14 | 000,010,632 | ---- | M] (Advanced Micro Devices) [Kernel | Boot] -- C:\Windows\System32\drivers\amdide.sys -- (amdide)
DRV - [2007/09/17 09:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2006/09/28 16:41:46 | 000,247,808 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\netr73.sys -- (netr73)
DRV - [2005/01/31 03:20:04 | 000,211,712 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\LV561AV.SYS -- (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2005/01/31 03:12:46 | 000,022,016 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\LVUSBSta.sys -- (LVUSBSta)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Alvin_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\Alvin_ON_C\Software\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\Alvin_ON_C\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\Alvin_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Alvin_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\Gast_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.medion.com/
IE - HKU\Gast_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\Gast_ON_C\Software\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\Gast_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://start.icq.com/"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\System32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fiddlerhook@fiddler2.com: C:\Program Files\Fiddler2\FiddlerHook [2011/09/05 14:09:57 | 000,000,000 | ---D | M]
[2009/03/08 08:29:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alvin\AppData\Roaming\Mozilla\Extensions
[2010/05/01 20:47:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alvin\AppData\Roaming\Mozilla\Firefox\Profiles\b6c2wjlh.default\extensions
[2010/05/01 20:47:47 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Alvin\AppData\Roaming\Mozilla\Firefox\Profiles\b6c2wjlh.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2008/07/10 07:07:28 | 000,000,944 | ---- | M] () -- C:\Users\Alvin\AppData\Roaming\Mozilla\Firefox\Profiles\b6c2wjlh.default\searchplugins\icqplugin.xml
O1 HOSTS File: ([2011/02/11 19:02:29 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (Veoh Video Compass) - {52836EB0-631A-47B1-94A6-61F9D9112DAE} - C:\Program Files\Veoh Networks\Veoh Video Compass\SearchRecsPlugin.dll (Veoh Networks)
O3 - HKU\Gast_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\Gast_ON_C\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O4 - HKLM..\Run: [6zvcaxR5ls4KB9Y] C:\Users\Alvin\AppData\Roaming\hrt54is56ijfgte.exe (creare facce)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [toolbar_eula_launcher] C:\Program Files\GoogleEULA\EULALauncher.exe ( )
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKU\Alvin_ON_C..\Run: [6zvcaxR5ls4KB9Y] C:\Users\Alvin\AppData\Roaming\hrt54is56ijfgte.exe (creare facce)
O4 - HKU\Alvin_ON_C..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKU\Alvin_ON_C..\Run: [kcepiqph] C:\Users\Alvin\AppData\Roaming\msshooksc.dll ()
O4 - HKU\Alvin_ON_C..\Run: [srt6u56us6hty] C:\Users\Alvin\AppData\Roaming\jhds56ud56\dr5j56iud56.exe (creare facce)
O4 - HKU\Alvin_ON_C..\Run: [VeohPlugin] C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
O4 - HKU\Gast_ON_C..\Run: [swg] File not found
O4 - HKU\Gast_ON_C..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Alvin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Kurznotizen.lnk = File not found
O4 - Startup: C:\Users\Alvin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Alvin_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Alvin_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\Alvin_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O7 - HKU\Alvin_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\Alvin_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O7 - HKU\Gast_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Free YouTube Download - C:\Users\Alvin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Alvin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - File not found
O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - File not found
O9 - Extra Button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files\Fiddler2\Fiddler.exe (Eric Lawrence)
O9 - Extra 'Tools' menuitem : Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files\Fiddler2\Fiddler.exe (Eric Lawrence)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (C:\Users\Alvin\AppData\Roaming\hrt54is56ijfgte.exe) - C:\Users\Alvin\AppData\Roaming\hrt54is56ijfgte.exe (creare facce)
O20 - HKU\Alvin_ON_C Winlogon: Shell - (C:\Users\Alvin\AppData\Roaming\hrt54is56ijfgte.exe) - C:\Users\Alvin\AppData\Roaming\hrt54is56ijfgte.exe (creare facce)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/12/03 22:52:24 | 000,095,744 | ---- | C] (Kassl GmbH) -- C:\Users\Alvin\AppData\Roaming\dwlGina3.dll
[2011/12/03 22:23:25 | 000,000,000 | ---D | C] -- C:\Users\Gast\AppData\Roaming\Skype
[2011/12/03 22:13:48 | 000,331,776 | ---- | C] (creare facce) -- C:\Users\Alvin\AppData\Roaming\hrt54is56ijfgte.exe
[2011/12/03 22:13:37 | 000,000,000 | ---D | C] -- C:\Users\Alvin\AppData\Roaming\jhds56ud56
[2011/12/03 20:23:41 | 000,000,000 | ---D | C] -- C:\Users\Alvin\AppData\Roaming\Skype
[2011/12/03 20:23:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/12/03 20:23:35 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2011/12/03 20:23:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2011/12/03 19:37:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/12/03 00:52:16 | 000,000,000 | ---D | C] -- C:\Users\Alvin\AppData\Local\{4208107E-47A5-4981-B0C9-F210957CF071}
[2011/12/03 00:51:54 | 000,000,000 | ---D | C] -- C:\Users\Alvin\AppData\Local\{F4C8E8C4-90CF-44D1-AADE-88E13C6FB9CF}
[2011/12/02 12:51:29 | 000,000,000 | ---D | C] -- C:\Users\Alvin\AppData\Local\{981C4A4D-D41D-4D37-88EC-5AF8238C65DB}
[2011/12/02 12:50:55 | 000,000,000 | ---D | C] -- C:\Users\Alvin\AppData\Local\{B6EBE098-170E-4E7E-8ED0-AE2D43E007D6}
[2011/12/01 15:41:39 | 000,000,000 | ---D | C] -- C:\Users\Alvin\AppData\Local\{400BA241-2FAF-4BB0-9E96-8250656540E6}
[2011/12/01 15:41:28 | 000,000,000 | ---D | C] -- C:\Users\Alvin\AppData\Local\{E4E26512-C514-456C-A8FA-DDDE9421C21E}
[2011/12/01 15:26:32 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2011/12/01 15:23:03 | 000,000,000 | ---D | C] -- C:\Users\Alvin\AppData\Local\Windows Live
[2011/11/20 16:30:32 | 000,000,000 | ---D | C] -- C:\Users\Gast\AppData\Roaming\Malwarebytes
[1 C:\Users\Alvin\AppData\Roaming\*.tmp files -> C:\Users\Alvin\AppData\Roaming\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/04 14:17:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/04 14:13:50 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/04 14:13:45 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/04 14:13:45 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/04 14:13:38 | 3217,268,736 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/04 12:46:47 | 000,718,030 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011/12/04 12:46:47 | 000,646,916 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/12/04 12:46:47 | 000,159,540 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011/12/04 12:46:47 | 000,131,904 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/12/03 23:30:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/03 22:52:24 | 000,095,744 | ---- | M] (Kassl GmbH) -- C:\Users\Alvin\AppData\Roaming\dwlGina3.dll
[2011/12/03 22:23:12 | 000,002,489 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011/12/03 22:23:12 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/12/03 22:13:37 | 000,331,776 | ---- | M] (creare facce) -- C:\Users\Alvin\AppData\Roaming\hrt54is56ijfgte.exe
[2011/12/03 21:40:39 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{167A4143-9482-4B8F-B2F9-AB8D136ADE6A}.job
[2011/12/03 02:53:28 | 000,031,718 | ---- | M] () -- C:\Users\Alvin\Desktop\12-03-2011[1].jpg
[2011/12/02 20:51:33 | 000,001,989 | ---- | M] () -- C:\Users\Alvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Live Messenger.lnk
[2011/12/02 11:28:29 | 000,269,192 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/12/01 18:57:29 | 000,062,861 | ---- | M] () -- C:\Users\Alvin\Desktop\tumblr_lvaplyS5Qh1qcs5luo1_500[1].jpg
[2011/12/01 15:28:19 | 000,001,989 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/12/01 14:06:23 | 000,093,182 | ---- | M] () -- C:\Users\Alvin\Desktop\ad6431b9b49703905279bcf935ce0b81_20293471[2].jpg
[2011/11/28 15:06:36 | 000,001,356 | ---- | M] () -- C:\Users\Alvin\AppData\Local\d3d9caps.dat
[2011/11/20 07:48:31 | 000,053,760 | ---- | M] () -- C:\Users\Alvin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/19 10:18:28 | 000,147,729 | ---- | M] () -- C:\Users\Alvin\Desktop\320206_257211927643403_100000637943513_873119_218387_n[1].jpg
[2011/11/19 10:16:26 | 000,290,097 | ---- | M] () -- C:\Users\Alvin\Desktop\Lina&Moi.jpg
[2011/11/08 00:43:21 | 000,042,535 | ---- | M] () -- C:\Users\Alvin\Desktop\Evolution.pdf
[2011/11/08 00:42:51 | 000,023,521 | ---- | M] () -- C:\Users\Alvin\Desktop\Die Evolution der Finken auf Galapagos - Adaptive Radiation.pdf
[2011/11/08 00:28:57 | 000,067,075 | ---- | M] () -- C:\Users\Alvin\Desktop\Genetik-Zusammenfassung LK.pdf
[2011/11/07 01:09:25 | 000,024,043 | ---- | M] () -- C:\Users\Alvin\Desktop\Hermann Göring.odt
[2011/11/07 01:06:34 | 000,025,113 | ---- | M] () -- C:\Users\Alvin\Desktop\Josef Goebbels.odt
[2011/11/07 00:16:17 | 000,030,708 | ---- | M] () -- C:\Users\Alvin\Desktop\Goebbels.odt
[2011/11/06 09:56:03 | 000,087,672 | ---- | M] () -- C:\Users\Alvin\Desktop\Leitfaden_Referat (Thesenpapier).pdf
[2011/11/06 00:22:02 | 000,034,607 | ---- | M] () -- C:\Users\Alvin\Desktop\joseph-goebbels.zip
[1 C:\Users\Alvin\AppData\Roaming\*.tmp files -> C:\Users\Alvin\AppData\Roaming\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/04 14:13:38 | 3217,268,736 | -HS- | C] () -- C:\hiberfil.sys
[2011/12/03 20:23:36 | 000,002,489 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2011/12/03 02:53:36 | 000,031,718 | ---- | C] () -- C:\Users\Alvin\Desktop\12-03-2011[1].jpg
[2011/12/02 20:51:33 | 000,001,989 | ---- | C] () -- C:\Users\Alvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Live Messenger.lnk
[2011/12/01 18:58:38 | 000,062,861 | ---- | C] () -- C:\Users\Alvin\Desktop\tumblr_lvaplyS5Qh1qcs5luo1_500[1].jpg
[2011/12/01 15:28:19 | 000,001,989 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/12/01 14:06:30 | 000,093,182 | ---- | C] () -- C:\Users\Alvin\Desktop\ad6431b9b49703905279bcf935ce0b81_20293471[2].jpg
[2011/11/19 10:16:26 | 000,290,097 | ---- | C] () -- C:\Users\Alvin\Desktop\Lina&Moi.jpg
[2011/11/19 10:04:22 | 000,147,729 | ---- | C] () -- C:\Users\Alvin\Desktop\320206_257211927643403_100000637943513_873119_218387_n[1].jpg
[2011/11/08 00:43:21 | 000,042,535 | ---- | C] () -- C:\Users\Alvin\Desktop\Evolution.pdf
[2011/11/08 00:42:51 | 000,023,521 | ---- | C] () -- C:\Users\Alvin\Desktop\Die Evolution der Finken auf Galapagos - Adaptive Radiation.pdf
[2011/11/08 00:28:57 | 000,067,075 | ---- | C] () -- C:\Users\Alvin\Desktop\Genetik-Zusammenfassung LK.pdf
[2011/11/07 01:08:22 | 000,024,043 | ---- | C] () -- C:\Users\Alvin\Desktop\Hermann Göring.odt
[2011/11/07 01:04:41 | 000,025,113 | ---- | C] () -- C:\Users\Alvin\Desktop\Josef Goebbels.odt
[2011/11/06 21:35:59 | 000,030,708 | ---- | C] () -- C:\Users\Alvin\Desktop\Goebbels.odt
[2011/11/06 09:56:03 | 000,087,672 | ---- | C] () -- C:\Users\Alvin\Desktop\Leitfaden_Referat (Thesenpapier).pdf
[2011/11/06 00:22:02 | 000,034,607 | ---- | C] () -- C:\Users\Alvin\Desktop\joseph-goebbels.zip
[2011/10/04 12:08:45 | 000,083,968 | RHS- | C] () -- C:\Users\Alvin\AppData\Roaming\msshooksc.dll
[2011/02/11 18:54:50 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/02/11 18:54:50 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/02/11 18:54:50 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011/02/11 18:54:50 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/02/11 18:54:50 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/10/16 19:13:13 | 000,000,164 | ---- | C] () -- C:\Users\Alvin\AppData\Roaming\{701ACAF9-F102-47c2-8907-36246F4DFB51}
[2010/06/08 06:58:31 | 000,000,118 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2010/06/08 06:45:24 | 000,001,356 | ---- | C] () -- C:\Users\Alvin\AppData\Local\d3d9caps.dat
[2010/02/27 06:07:30 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2010/02/27 05:53:04 | 000,036,864 | ---- | C] () -- C:\Windows\System32\LckFldService.exe
[2010/02/04 14:55:47 | 001,970,176 | ---- | C] () -- C:\Windows\System32\d3dx9.dll
[2010/01/20 12:16:08 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2010/01/20 12:16:08 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2009/11/29 12:33:01 | 000,237,568 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2009/11/29 12:33:01 | 000,110,080 | ---- | C] () -- C:\Windows\System32\advd.dll
[2009/11/29 12:33:01 | 000,023,040 | ---- | C] () -- C:\Windows\System32\auth.dll
[2009/11/07 15:22:32 | 000,000,007 | ---- | C] () -- C:\Windows\sbacknt.bin
[2009/09/10 17:54:30 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/10 17:54:30 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/07/08 20:03:02 | 000,058,880 | ---- | C] () -- C:\Windows\System32\bdmpegv.dll
[2009/06/12 13:32:48 | 000,000,092 | ---- | C] () -- C:\Users\Gast\AppData\Local\fusioncache.dat
[2009/04/19 21:28:56 | 000,000,104 | ---- | C] () -- C:\Users\Alvin\AppData\default.pls
[2009/04/18 23:18:38 | 000,053,760 | ---- | C] () -- C:\Users\Alvin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/24 19:52:20 | 000,027,074 | ---- | C] () -- C:\Users\Alvin\AppData\Roaming\UserTile.png
[2009/03/07 10:24:17 | 000,278,984 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2009/03/07 10:24:17 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2009/03/06 16:19:07 | 000,000,093 | ---- | C] () -- C:\Users\Alvin\AppData\Local\fusioncache.dat
[2008/10/09 17:28:40 | 000,718,030 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008/10/09 17:28:40 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008/10/09 17:28:40 | 000,159,540 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008/10/09 17:28:40 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2008/09/16 03:52:16 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2007/10/25 11:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2006/11/02 07:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,269,192 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,646,916 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,131,904 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2005/01/31 01:37:58 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
========== LOP Check ==========
[2011/05/05 16:00:33 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\Ahitm
[2009/12/28 13:49:36 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\com.adobe.example.avatarAirApplication.199ED43C2CFEB351CD0244628B93195D7C58F98C.1
[2009/11/29 12:33:17 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\concept design
[2009/11/22 14:29:03 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\CopyTransPhoto
[2010/10/16 18:55:30 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\Degener
[2011/09/06 09:19:09 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\DVDVideoSoft
[2011/06/13 02:07:39 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/11/19 10:16:26 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\gtk-2.0
[2010/01/24 17:10:59 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\ICQ
[2011/12/03 22:13:49 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\jhds56ud56
[2011/06/09 19:00:00 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\kock
[2009/12/13 17:14:30 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\OpenOffice.org
[2010/01/20 14:04:57 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\PC Suite
[2009/03/06 10:31:24 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\PlayFirst
[2011/05/05 16:06:18 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\Qiylmy
[2010/01/20 12:15:37 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\Samsung
[2009/04/22 15:46:51 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\SharePod
[2009/03/06 16:16:26 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\T-Online
[2011/06/09 23:35:28 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\UAs
[2009/11/07 15:28:05 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\vghd
[2011/10/06 00:06:31 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\Vocup
[2010/02/13 17:29:50 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\WEB.DE
[2009/11/22 14:27:32 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\WindSolutions
[2011/06/09 23:38:03 | 000,000,000 | ---D | M] -- C:\Users\Alvin\AppData\Roaming\xmldm
[2009/03/06 10:05:34 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2010/10/17 17:15:11 | 000,000,000 | ---D | M] -- C:\ProgramData\Degener
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2009/03/06 10:05:34 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2009/03/06 10:05:34 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2010/01/24 17:13:57 | 000,000,000 | ---D | M] -- C:\ProgramData\ICQ
[2009/09/20 17:30:32 | 000,000,000 | ---D | M] -- C:\ProgramData\maxdome
[2010/12/03 20:11:43 | 000,000,000 | ---D | M] -- C:\ProgramData\Nexon
[2010/12/03 20:20:37 | 000,000,000 | ---D | M] -- C:\ProgramData\NexonUS
[2010/01/20 14:04:58 | 000,000,000 | ---D | M] -- C:\ProgramData\PC Suite
[2010/12/03 18:43:08 | 000,000,000 | ---D | M] -- C:\ProgramData\PMB Files
[2009/03/07 21:48:24 | 000,000,000 | ---D | M] -- C:\ProgramData\Sandlot Games
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2009/03/06 10:05:34 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2006/11/02 08:02:04 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2010/02/27 06:22:59 | 000,000,000 | ---D | M] -- C:\ProgramData\TrueCrypt
[2009/03/06 10:05:34 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2010/01/23 11:51:43 | 000,000,000 | ---D | M] -- C:\ProgramData\WildTangent
[2009/11/22 14:27:32 | 000,000,000 | ---D | M] -- C:\ProgramData\WindSolutions
[2010/09/06 15:10:41 | 000,000,000 | ---D | M] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/01 14:50:31 | 000,000,000 | ---D | M] -- C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/22 12:35:31 | 000,000,000 | ---D | M] -- C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/12/04 14:17:39 | 000,032,530 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/12/03 21:40:39 | 000,000,418 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{167A4143-9482-4B8F-B2F9-AB8D136ADE6A}.job
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2010/12/03 20:15:33 | 000,000,000 | ---D | M](C:\Users\Alvin\Documents\?? ???) -- C:\Users\Alvin\Documents\넥슨 플러그
[2010/12/03 20:15:33 | 000,000,000 | ---D | C](C:\Users\Alvin\Documents\?? ???) -- C:\Users\Alvin\Documents\넥슨 플러그
========== Alternate Data Streams ==========
@Alternate Data Stream - 64 bytes -> C:\Users\Alvin\Desktop\Poomsae Taeguk.mp4:TOC.WMV
< End of report > --- --- --- |