Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Win32.Agent.fbx - TrojansC gefunden (https://www.trojaner-board.de/85793-win32-agent-fbx-trojansc-gefunden.html)

juergenheim 05.05.2010 21:02

Win32.Agent.fbx - TrojansC gefunden
 
Hallo, habe mich erst neu registriert, kann sein, dass ich noch etwas unbeholfen wirke.
Ich habe den troaner win32.agent.fxb auf meinem Rechner, derSpybot search and destroy entfernt ihn nicht. deshalb habe ich, wie hier im forum nachgelesen, den Navilog installiert und druchlaufen lassen, ebenso wie die Superantispyware.
Das Scanprotokoll hat folgendes gefunden:

Code:


Scan type : Complete Scan
Total Scan Time : 02:29:34
 
Memory items scanned : 454
Memory threats detected : 2
Registry items scanned : 8720
Registry threats detected : 7
File items scanned : 153514
File threats detected : 308
 
Adware.Vundo/Variant-X32[Header]
    C:\WINDOWS\SYSTEM32\CERTENROLLUI32.DLL
    C:\WINDOWS\SYSTEM32\CERTENROLLUI32.DLL
    HKLM\Software\Classes\CLSID\{02AC876D-EDCD-4323-8A6A-3C34D179411a}
    HKCR\CLSID\{02AC876D-EDCD-4323-8A6A-3C34D179411A}
    HKCR\CLSID\{02AC876D-EDCD-4323-8A6A-3C34D179411A}\InprocServer32
    HKCR\CLSID\{02AC876D-EDCD-4323-8A6A-3C34D179411A}\InprocServer32#ThreadingModel
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02AC876D-EDCD-4323-8A6A-3C34D179411a}
    HKU\S-1-5-21-3395950427-1089180542-3055491895-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02AC876D-EDCD-4323-8A6A-3C34D179411A}
    C:\PROGRAMDATA\CABINET32.DLL
    C:\PROGRAMDATA\CATSRVPS32.DLL
    C:\PROGRAMDATA\CLBCATQ32.DLL
    C:\PROGRAMDATA\CMICRYPTINSTALL32.DLL
    C:\PROGRAMDATA\CNGAUDIT32.DLL
    C:\PROGRAMDATA\CTL3D3232.DLL
    C:\PROGRAMDATA\DDRAW32.DLL
    C:\PROGRAMDATA\DIAGPERF32.DLL
    C:\PROGRAMDATA\DINPUT32.DLL
    C:\PROGRAMDATA\DMDSKRES32.DLL
    C:\PROGRAMDATA\DMSCRIPT32.DLL
    C:\PROGRAMDATA\DMVDSITF32.DLL
    C:\PROGRAMDATA\DOT3GPUI32.DLL
    C:\PROGRAMDATA\DPS32.DLL
    C:\PROGRAMDATA\DRMMGRTN32.DLL
    C:\PROGRAMDATA\DXTMSFT32.DLL
    C:\PROGRAMDATA\FDWSD32.DLL
    C:\PROGRAMDATA\FM2032.DLL
    C:\PROGRAMDATA\FRAMEDYNOS32.DLL
    C:\PROGRAMDATA\FWCFG32.DLL
    C:\PROGRAMDATA\GPTEXT32.DLL
    C:\WINDOWS\SYSTEM32\BLACKBOX32.DLL
    C:\WINDOWS\SYSTEM32\BTHMTPCONTEXTHANDLER32.DLL
    C:\WINDOWS\SYSTEM32\CEWMDM32.DLL
    C:\WINDOWS\SYSTEM32\COMCAT32.DLL
 
Trojan.Downloader-CREW
    C:\PROGRAMDATA\DFSHIM32.DLL
    C:\PROGRAMDATA\DFSHIM32.DLL
 
Trojan.Dropper/ADR-WV
    [RTHDBPL] C:\USERS\JüRGEN\APPDATA\ROAMING\SYSTEMPROC\LSASS.EXE
    C:\USERS\JüRGEN\APPDATA\ROAMING\SYSTEMPROC\LSASS.EXE
 
Adware.Tracking Cookie
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@bs.serving-sys[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@himedia.individuad[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@windowsmedia[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@ad.zanox[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@adfarm1.adition[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@serving-sys[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@www.windowsmedia[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@cdn5.specificclick[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@sonyeurope.112.2o7[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@zanox[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@tracking.quisma[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@www6.addfreestats[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@specificclick[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@unitymedia[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\jürgen@adtech[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@1.sharkadnetwork[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@2o7[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@4stats[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@99counters[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@a.findarticles[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@a2.adserver01[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@a3.adserver01[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@a6.adserver01[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@a7.adserver01[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.ad-srv[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.adc-serv[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.adnet[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.adserver01[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.boreus[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.ebook30[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.i-zone[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.salebroker[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.trackbar[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.tuttoscuola[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.yieldmanager[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.youporngay.videoboxmen[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad.zanox[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad1.chefkoch[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad1.clickhype[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad1.emediate[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ad2.doublepimp[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@adbrite[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@adcentriconline[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@adinterax[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@admarketplace[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads-dev.youporn[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.ad4game[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.adultadvertising[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.ak.facebook[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.cliquemusica.com[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.crowda[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.csn[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.cuisine[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.efm[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.enalquiler[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.esmadrid[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.esmas[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.famdirekt[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.foodbuzz[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.fulldls[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.glispa[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.h1351109.stratoserver[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.heias[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.hitsquad[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.medienhaus[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.mikinimedia[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.planetactive[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.prisacom[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.quartermedia[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.salir[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.shorttail[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.tcmdb[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.thesmokinggun[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.us.e-planning[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.whaleads[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads.youporn[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads1.adultadvertising[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads2.adultadvertising[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads2.infosystems[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ads2.weblogssl[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@adserver.boobfrog[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@adserver.easyadult[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@adserving.favorit-network[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@adsrv.admediate[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@advertise[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@adx.bixee[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@adx.chip[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@alphamalefuckers[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@atdmt[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@axelspringer.122.2o7[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@bd.bigmusclemedia[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@beacon.dmsinsights[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@bookfinder[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@bridge2.admarketplace[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@bs.serving-sys[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@chitika[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@click.mediadome[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@click.orgycash[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@click.superpaysys[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@click.yottacash[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@clicks.falconstudios[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@clicksor[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@collective-media[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@content.yieldmanager[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@content.yieldmanager[3].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@counter.sexsuche[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@countomat[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@cpx.mediascale[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@d.kaizentraffic[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@dc.tremormedia[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@delivery.ads.coupling-media[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@dev.gallerytrafficservice[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@dhdmedia[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@discount24[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@diximedia[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@doubleclick[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@eas.apm.emediate[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@eas4.emediate[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@ecnext.advertserve[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@elintermedio.lasexta[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@epochstats[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@epp.eurostat.ec.europa[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@euros4click[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@eyewonder[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@find.galegroup.com.proxy.queensu[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@findarticles[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@findarticles[3].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@fortunecity[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@freeporngiants[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@fuckovermyex[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@fucktube[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@gayfuckbook[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@gaysexer[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@gaysex[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@gaytrafficbroker[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@gayvodpornos[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@gotgayporn[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@grupogod.112.2o7[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@guj.122.2o7[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@hairyboyz[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@hairystudsvideo[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@hbxtracking.sueddeutsche[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@himedia.individuad[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@hotfuckbook[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@im.banner.t-online[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@imrworldwide[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@in.getclicky[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@interclick[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@invitemedia[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@komtrack[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@komtrack[3].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@komtrack[4].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@loadxl.exelator[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@media.mtvnservices[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@media.photobucket[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@media6degrees[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@mediafiles-express[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@mediametrics.mpsa[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@microsoftmachinetranslation.112.2o7[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@nakedkombat[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@nakedsword[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@oneclickfiles[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@openx.sexsearchcom[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@openxxx.viragemedia[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@pointroll[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@pornorawa[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@porntube[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@prisacom.112.2o7[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@pro-advertise[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@revsci[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@richmedia.yahoo[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@roitracking[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@rts.pgmediaserve[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@secure-media-sf2p.facebook[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@segittur.122.2o7[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@serving-sys[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@sex2ube.dvdtube[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@sex2ube[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@sexgaymes[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@sexo.videosyonkis[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@sonyeurope.112.2o7[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@soundtrackcollector[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@specificmedia[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@stat.novopress[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@stats.paypal[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@terra.112.2o7[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@theclickcheck[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@timeoutcommunications.122.2o7[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@track.effiliation[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@track.effiliation[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@track.webtrekk[10].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@track.webtrekk[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@track.webtrekk[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@track.webtrekk[3].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@track.webtrekk[4].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@track.webtrekk[5].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@track.webtrekk[6].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@track.webtrekk[7].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@track.webtrekk[8].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@track.webtrekk[9].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@tracking.mindshare[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@tracking.quisma[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@tradedoubler[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@traffictrack[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@triptosex[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@tto2.traffictrack[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@uknakedmen[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@unitymedia[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@vodchannels.maleflixxx[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@webmasterplan[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@wrestleandfuck[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@wunderloop.zanox[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.active-tracking[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.ad-track[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.adultadvertising[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.alphamalefuckers[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.exgfsextapes[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.gayfuckbook[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.googleadservices[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.gotgayporn[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.himmedia[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.hornysilver[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.nakedkombat[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.soundtrackcollector[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.traffictrack[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.uknakedmen[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.usenext[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www.zanox-affiliate[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@www9.discount24[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@xm.xtendmedia[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@xxx.falconstudios[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@youporncams[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@youporncocks[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@youporngay.videoboxmen[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@youporngay[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@youporn[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@zanox-affiliate[1].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@zanox[2].txt
    C:\Users\Jürgen\AppData\Roaming\Microsoft\Windows\Cookies\Low\jürgen@zbox.zanox[2].txt
 
Trojan.Dropper/Sys-NV
    C:\PROGRAMDATA\BITSPRX332.DLL
    C:\PROGRAMDATA\BLACKBOX32.DLL
    C:\PROGRAMDATA\BTHMTPCONTEXTHANDLER32.DLL
    C:\PROGRAMDATA\CDDBCLEANROXIO32.DLL
    C:\PROGRAMDATA\CDOSYS32.DLL
    C:\PROGRAMDATA\CFGMGR3232.DLL
    C:\PROGRAMDATA\CMDIAL3232.DLL
    C:\PROGRAMDATA\CMUTIL32.DLL
    C:\PROGRAMDATA\COMSVCS32.DLL
    C:\PROGRAMDATA\CRTDLL32.DLL
    C:\PROGRAMDATA\CRYPTEXT32.DLL
    C:\PROGRAMDATA\CSCAPI32.DLL
    C:\PROGRAMDATA\D3D1032.DLL
    C:\PROGRAMDATA\D3D10_132.DLL
    C:\PROGRAMDATA\D3D832.DLL
    C:\PROGRAMDATA\D3DIM32.DLL
    C:\PROGRAMDATA\D3DX9_2732.DLL
    C:\PROGRAMDATA\DCIMAN3232.DLL
    C:\PROGRAMDATA\DESKADP32.DLL
    C:\PROGRAMDATA\DEVICEPAIRING32.DLL
    C:\PROGRAMDATA\DISPEX32.DLL
    C:\PROGRAMDATA\DMDLGS32.DLL
    C:\PROGRAMDATA\DMLOADER32.DLL
    C:\PROGRAMDATA\DNSRSLVR32.DLL
    C:\PROGRAMDATA\DOT3UI32.DLL
    C:\PROGRAMDATA\DPMODEMX32.DLL
    C:\PROGRAMDATA\DPNET32.DLL
    C:\PROGRAMDATA\DSAUTH32.DLL
    C:\PROGRAMDATA\DSOUND32.DLL
    C:\PROGRAMDATA\DSSEC32.DLL
    C:\PROGRAMDATA\DSWAVE32.DLL
    C:\PROGRAMDATA\DWMAPI32.DLL
    C:\PROGRAMDATA\DXGI32.DLL
    C:\PROGRAMDATA\EAPPCFG32.DLL
    C:\PROGRAMDATA\EAPQEC32.DLL
    C:\PROGRAMDATA\EHSTORAPI32.DLL
    C:\PROGRAMDATA\EHSTORSHELL32.DLL
    C:\PROGRAMDATA\EXPSRV32.DLL
    C:\PROGRAMDATA\FONTSUB32.DLL
    C:\PROGRAMDATA\GCDEF32.DLL
    C:\PROGRAMDATA\GETUNAME32.DLL

Wäre froh, wenn mir jemand helfen könnte bei der auswahl der Dateien, die ich entfernen soll.

Danke im Voraus, Juergen

ausserdem hier noch mein navilog-Protokoll


C:\ (Local Disk) - NTFS - Total:53 Go (Free:13 Go)
D:\ (Local Disk) - NTFS - Total:48 Go (Free:6 Go)
E:\ (USB)
F:\ (CD or DVD)
G:\ (USB)

Vielen Dank im Voraus
habe nochmal den Spybot durchlaufen lassen, er hat nichts mehr gefunden

cosinus 07.05.2010 22:12

Hallo und :hallo:

bitte nen Vollscan mit malwarebytes machen und Log posten. Danach OTL:

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.

juergenheim 08.05.2010 17:37

Vielen Dank erstmal, hier das Log von malwarebytes:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4078

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18904

08.05.2010 18:31:09
mbam-log-2010-05-08 (18-31-09).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 294299
Laufzeit: 1 Stunde(n), 43 Minute(n), 8 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 2
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 5
Infizierte Dateien: 14

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cyweg (Trojan.Agent.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rthdbpl (Trojan.Agent) -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
C:\ProgramData\1118699795 (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Users\Jürgen\AppData\Roaming\SystemProc (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D} (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content (Worm.Prolaco.M) -> Quarantined and deleted successfully.

Infizierte Dateien:
C:\Users\Jürgen\AppData\Local\Temp\2B16.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Jürgen\AppData\Local\Temp\4F7A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Jürgen\AppData\Local\Temp\586C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Jürgen\AppData\Local\Temp\5928.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Jürgen\AppData\Local\Temp\641C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Jürgen\AppData\Local\Temp\7AF0.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Jürgen\AppData\Local\Temp\83F2.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Jürgen\AppData\Local\Temp\87F4.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Jürgen\AppData\Local\Temp\934A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Jürgen\AppData\Roaming\EE38.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Jürgen\Shared\braunwald heart disesae 2010.cracked.FuVo\patch.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul (Worm.Prolaco.M) -> Quarantined and deleted successfully.
:lach::lach::lach::lach:

juergenheim 08.05.2010 18:03

hier jetzt der OTL- Extratext:OTL Extras logfile created on: 08.05.2010 18:49:34 - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\J***n\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 44,00% Memory free
4,00 Gb Paging File | 2,00 Gb Available in Paging File | 57,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 53,79 Gb Total Space | 12,35 Gb Free Space | 22,96% Space Free | Partition Type: NTFS
Drive D: | 48,22 Gb Total Space | 6,59 Gb Free Space | 13,66% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: J***N-PC
Current User Name: J***n
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\ObjectCube\XXX2Burn DVD Wizard\OCDVDAgent.exe" = C:\Program Files\ObjectCube\XXX2Burn DVD Wizard\OCDVDAgent.exe:*:Enabled:ObjectCube Express Agent -- File not found
"C:\Program Files\ObjectCube\XXX2Burn DVD Wizard\AppUpdate.exe" = C:\Program Files\ObjectCube\XXX2Burn DVD Wizard\AppUpdate.exe:*:Enabled:ObjectCube AutoUpdate -- (LightningCD)
"C:\Program Files\ObjectCube\XXX2Burn DVD Wizard\xxx2burn.exe" = C:\Program Files\ObjectCube\XXX2Burn DVD Wizard\xxx2burn.exe:*:Enabled:XXX2Burn DVD Wizard -- (ObjectCube)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{13ECB673-7BC0-4271-9562-BAF3B66440C5}" = lport=25349 | protocol=6 | dir=in | name=bitcomet 25349 tcp |
"{768EF70A-78FA-40BF-BC12-D56D4BAB9BBB}" = lport=25349 | protocol=17 | dir=in | name=bitcomet 25349 udp |
"{78267B21-895F-4D9B-8040-5825757D8C47}" = lport=10243 | protocol=6 | dir=in | app=system |
"{80DED10B-072C-418D-9661-FD2790FEDDA0}" = lport=4662 | protocol=6 | dir=in | name=e-mule |
"{8D0E1481-5CCC-4E33-AA2E-92E4410BE8B1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AB0D5052-3BC5-45FA-810B-B9E9CDEA23F0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B2BB1C07-4F91-4EF6-A9D3-CC6145B53C00}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B82DB9E5-6920-4415-B492-926E0601FCC3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BA12E8D6-C24C-4C80-A77C-39B28C5D96AB}" = lport=4662 | protocol=17 | dir=in | name=e-mule |
"{BE2A47E7-5F53-4085-B0BE-7BA013E7DE6F}" = rport=10243 | protocol=6 | dir=out | app=system |
"{D7D70259-FD7B-428B-A117-C8C87021E90F}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D9DAB374-BE54-42B9-80E2-9C18DA37BD74}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E68451CD-D4C3-43DF-BE7E-82CC56A6CA66}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0DBE3EF4-3E8B-429D-AF47-565AE2E15508}" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"{13B8D299-319C-4641-A69A-C83461E38B4F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1D0679F5-CA4E-4A83-8350-0D48FDF5EC1F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{22FD311E-F15A-4691-AFDC-3BAC10C9599E}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{237BD906-5F47-4285-A7A5-6C7DE8CFE462}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{275B490A-6211-40B9-8955-AC7AE80C24AB}" = protocol=17 | dir=in | app=c:\program files\google\google talk\googletalk.exe |
"{2C81BEB7-B16C-42C1-AF54-5A232482C15D}" = protocol=17 | dir=in | app=c:\program files\360share pro\jre\bin\javaw.exe |
"{35195813-79A8-4B62-9D57-734102732C50}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{445AC2B4-E5FE-4FD5-96CA-E28B9ED3615A}" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"{46354A10-D001-4E6C-B79B-F12126D3CEAB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4C544F68-5479-439A-9E26-A8F21CD2D77F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5181945C-ABB4-456A-B76A-3E70DE4F9539}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{63BB6516-4A67-487B-A9E2-9A39D74DAE1A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{77BE3E79-6E80-4212-8F05-80BBD9E2F270}" = dir=in | app=c:\windows\explorer.exe |
"{78472CFC-0845-43A5-AA4D-52A754E6164A}" = protocol=6 | dir=in | app=c:\program files\360share pro\jre\bin\javaw.exe |
"{7ACC6E87-8C12-4adb-91B7-EFC3F2F4705A}" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"{82722BB1-E629-4E67-8764-36E91CBEB179}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{89A163EE-EB6A-4871-90AC-AEB9BF07A47F}" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"{8C429F73-F721-4675-8F11-52E9785EB897}" = protocol=6 | dir=in | app=c:\program files\google\google talk\googletalk.exe |
"{8F38D7C3-5026-4541-A499-E7F4A869EEF8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{92459C5E-D350-4cba-AA74-C8F989C9336F}" = protocol=17 | dir=out | app=c:\windows\explorer.exe |
"{9D7DB691-4019-432A-AC8F-0823BBAA4AC4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A0ACC783-1CAA-46E0-B6B7-E9CCEF1C2FCE}" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"{B078B2B6-A878-44ff-9BCC-458257924F96}" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"{B1A40E4F-58DB-490f-9D18-55B5194E8BD5}" = protocol=6 | dir=out | app=c:\windows\explorer.exe |
"{BF100E4A-F0E9-446E-953E-AA12359C9703}" = protocol=6 | dir=out | app=system |
"{C3E9B20A-B7E2-4aab-9835-3C548937E46F}" = dir=out | app=c:\windows\explorer.exe |
"{C73E6EB5-5ADD-4C7A-BE34-AC1D62A0F461}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{CF5F932E-041B-43AF-AF09-FD297606215D}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{E80847F7-5304-4DA2-BF83-A175D40DAD1C}" = protocol=6 | dir=in | app=c:\program files\google\google talk\googletalk.exe |
"{EC290D1C-C6F8-4DB8-9609-41D2175ED027}" = protocol=17 | dir=in | app=c:\program files\google\google talk\googletalk.exe |
"{ED0F0C16-B1E5-42F6-B7C9-A8C667AD9495}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F38CD34E-15DC-4A82-AE48-8632147B09E0}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{32D34185-BB6F-416A-8E85-3E4388E1D7E3}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
"TCP Query User{6E8B1EE2-E195-45E4-B812-2C0C67924E21}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{75EE2796-D75F-4BAE-B26B-58131C10EBD8}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"TCP Query User{972830FB-D075-40E9-BFDE-24EA907A7D31}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
"TCP Query User{9DD36FA3-B69B-4AE3-A043-5282EA4C6FAD}C:\program files\bitcomet\bitcomet.exe" = protocol=6 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |
"TCP Query User{BDC329FF-BEB1-4278-910E-6F973ED61C8C}C:\program files\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{C69E8829-F0B9-4BE1-B3ED-9FBB2B92D18B}C:\program files\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{E6AE8E42-59C0-4EA9-A509-1427712F8BD8}C:\program files\bitcomet\bitcomet.exe" = protocol=6 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |
"UDP Query User{0FFC8C61-8F68-4339-94F1-49B6E0179607}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{2F3AEF0A-5309-4E23-AD42-EFC2FA7E7F6D}C:\program files\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe |
"UDP Query User{A10ADE70-7C74-4035-B634-9541069D3B21}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{BC5649C5-9A6A-47C2-9410-70AB3769FF5A}C:\program files\bitcomet\bitcomet.exe" = protocol=17 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |
"UDP Query User{C2638542-ED5B-439C-A7EF-C8979DC7D1B6}C:\program files\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe |
"UDP Query User{D56742BB-827C-4765-9619-13FAFB05F5C2}C:\program files\bitcomet\bitcomet.exe" = protocol=17 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |
"UDP Query User{EEDC5C54-8BA5-4E21-BA6E-33307A92F3BA}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{FBB02CF5-E323-4D36-A4A9-FC87862FF9F7}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{009E7FB7-1775-4D89-8956-F5C9A1C019FC}" = DSD Playback Plug-in
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony Video Shared Library
"{028ED9C4-25EE-4DEE-9CF4-91034BC89B18}" = Microsoft SQL Server 2005 Express Edition (VAIO_VEDB)
"{038A524F-58DB-438A-8391-8F7F0CA14B9E}" = Microsoft® Winter Fun Pack 2004 for Windows® XP
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
"{07D8511D-C9FE-4A93-933F-EAA5C8F20095}" = IDT Audio
"{08C0729E-3E50-11DF-9D81-005056806466}" = Google Earth
"{0AAE6279-45D3-4E87-A8C5-0E6F29BC2C32}" = VAIO Content Importer VAIO Content Exporter
"{0C973594-7DDF-4BD0-84ED-3517F7622037}" = PC Connectivity Solution
"{1417F599-1DBD-4499-9375-B2813E9F890C}" = VAIO Camera Utility
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1BEF9285-5530-426B-A5F1-5836B95C7EB1}" = VAIO Original Screen Saver
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for VAIO
"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{25569723-DC5A-4467-A639-79535BF01B71}" = Adobe Help Center 2.1
"{262118B5-FF30-46C2-BDCA-556EA73792E9}" = VAIO VN-CX1A
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 17
"{26A24AE4-039D-4CA4-87B4-2F83216016F0}" = Java(TM) 6 Update 16
"{2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}" = Wireless Switch Setting Utility
"{2A2FF7F5-6F0E-4A5D-A881-39365E718BD6}" = VAIO Cozy Orange Wallpaper
"{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox
"{2DFB5485-A3EF-4298-9280-4AF80C9F4BE9}" = Microsoft SQL Server VSS Writer
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java(TM) SE Runtime Environment 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{428A6DA3-FD56-44AE-B602-15DCCD6A7515}" = VAIO AV Mode Launcher
"{48820099-ED7D-424B-890C-9A82EF00656D}" = VAIO Update 3
"{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}" = Microsoft Works
"{500162A0-4DD5-460A-BAFD-895AAE48C532}" = VAIO Media Content Collection 6.0
"{500C3FDC-5E5F-485F-BDF5-2C445839CBE0}" =
"{52D02A2B-03D2-4E34-A358-DC5D951FD296}" = Nokia Connectivity Cable Driver
"{530AFAFF-6F0A-48BB-88D0-04F9658322D3}" = Adobe Premiere Elements 3.0.2
"{547DCEC7-DD2A-47E9-82C7-5CF1EAB526DA}" = Microsoft SQL Server Native Client
"{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}" = Nokia PC Suite
"{55B781F0-060E-11D4-99D7-00C04FCCB775}" =
"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 6.0
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 6.0
"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series
"{5E343EF6-D27C-4CFC-9FAE-9AAFB541BCEE}" = VAIO Photo 2007
"{6332AFF1-9D9A-429C-AA03-F82749FA4F49}" = SonicStage Mastering Studio
"{68A69CFF-130D-4CDE-AB0E-7374ECB144C8}" = VAIO Content Importer / VAIO Content Exporter
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6D2576EC-A0E9-418A-A09A-409933A3B6F4}" = VAIO Camera Capture Utility
"{6EACDDF4-4220-49A3-9204-984C86852C3D}" = Adobe Premiere Elements 3.0.2 Templates
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{785EB1D4-ECEC-4195-99B4-73C47E187721}" = VAIO Media Integrated Server 6.0
"{82D5BACA-3619-4D34-99DB-3A65CFB4DA33}" = DSD Direct
"{8C44C027-7B9F-46F1-8FD8-5767403A7CA5}" = AppMon Utility
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel(R) Matrix Storage Manager
"{934A3213-1CB6-4264-84A2-EE080C017BCA}" = VAIO Tender Green Wallpaper
"{97BCD719-6ECB-458F-97D6-F38D2E07375E}" = VAIO Aqua Breeze Wallpaper
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C1C8A04-F8CA-4472-A92D-4288CE32DE86}" = SonicStage Mastering Studio Plug-Ins
"{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management
"{9E407618-D9CD-4F39-9490-9ED45294073D}" = Click to DVD 2.0.05 Menu Data
"{9FA8B5F5-4BDC-4CF4-9202-AA97FF79AE98}" = VAIO Media
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 4.3
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A7B609FB-83D8-4FC3-8477-1BC65ECFE85B}" = Adobe Photoshop Elements 5.0
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A947C2B3-7445-42C4-9063-EE704CACCB22}" = VAIO Hardware Diagnostics
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-1033-F400-BA7E-000000000003}" = Adobe Acrobat 8 Standard - English, Français, Deutsch
"{AC76BA86-7AD7-1031-7B44-A91000000001}" = Adobe Reader 9.1 - Deutsch
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 6.0
"{B0D70EC6-E1CF-4EC3-BE09-FA75470D3902}" = Norton Security Scan
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7FB0C86-41A4-4402-9A33-912C462042A0}" = Roxio Easy Media Creator Home
"{C0FE967C-0F67-2916-1A9C-C8628D45596A}" = Belator Media Player
"{C183A21C-395A-490F-99D4-CCAB35E32859}" =
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
"{DF7DB916-90E5-40F2-9010-B8125EB5FD6F}" = SonicStage Mastering Studio Audio Filter
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E809063C-51A3-4269-8984-D1EB742F2151}" = Click to DVD 2.6.00
"{E89D31F3-7F6C-47A3-8669-0A8DDE27B664}" = VAIO Media Registration Tool
"{EC37A846-53AC-4DA7-98FA-76A4E74AA900}" = Benutzerdefinierte Voreinstellungen für SonicStage Mastering Studio Audio Filter
"{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL
"{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F570A6CC-53ED-4AA9-8B08-551CD3E38D8B}" =
"{FC37C108-821D-4EDE-8F40-D5B497586805}" = VAIO Control Center
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"360Share Pro" = 360Share Pro(remove only)
"504244733D18C8F63FF584AEB290E3904E791693" = Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe Acrobat 8 Standard - English, Français, Deutsch" = Adobe Acrobat 8.1.2 Standard
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Photoshop Elements 5" = Adobe Photoshop Elements 5.0
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"AVS Audio Converter 6.1_is1" = AVS Audio Converter version 6.1
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BitComet" = BitComet 1.03
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"Digitale Bibliothek 4" = Digitale Bibliothek 4
"DVD Shrink_is1" = DVD Shrink 3.2
"E8A6D621B6D3FC5D43C68C549D959DE76EEF5D84" = Windows-Treiberpaket - Nokia Modem (06/01/2009 4.1)
"F779F5541ABD99C95C03B0FD5E3C058B22DA0FF7" = Windows-Treiberpaket - Nokia Modem (06/01/2009 7.01.0.3)
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for VAIO
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"KLiteCodecPack_is1" = K-Lite Codec Pack 5.0.0 (Full)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"Nokia PC Suite" = Nokia PC Suite
"NSSSetup.{B0D70EC6-E1CF-4EC3-BE09-FA75470D3902}" = Norton Security Scan (Symantec Corporation)
"NVIDIA Drivers" = NVIDIA Drivers
"OpenMG HotFix4.7-07-13-22-01" = OpenMG Limited Patch 4.7-07-13-24-01
"Picasa 3" = Picasa 3
"PremElem30" = Adobe Premiere Elements 3.0.2
"RealPlayer 12.0" = RealPlayer
"Spyware Doctor" = Spyware Doctor 6.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"UN080325" = BUFFALO TurboUSB for FLASH/HDD
"XXX2Burn DVD Wizard" = XXX2Burn DVD Wizard (remove only)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 16.05.2009 16:37:24 | Computer Name = Jn-PC | Source = Perflib | ID = 1010
Description =

Error - 16.05.2009 16:37:24 | Computer Name = Jn-PC | Source = Perflib | ID = 1008
Description =

Error - 16.05.2009 16:37:24 | Computer Name = Jn-PC | Source = Perflib | ID = 1008
Description =

Error - 16.05.2009 16:37:25 | Computer Name = Jn-PC | Source = Perflib | ID = 1008
Description =

Error - 16.05.2009 16:37:25 | Computer Name = J***n-PC | Source = Perflib | ID = 1008
Description =

Error - 16.05.2009 16:37:25 | Computer Name = J***n-PC | Source = Perflib | ID = 1005
Description =

Error - 16.05.2009 16:37:25 | Computer Name = J***n-PC | Source = Perflib | ID = 1018
Description =

Error - 16.05.2009 16:37:25 | Computer Name = J***n-PC | Source = Perflib | ID = 1008
Description =

Error - 16.05.2009 16:40:50 | Computer Name = J***n-PC | Source = MsiInstaller | ID = 11713
Description =

Error - 16.05.2009 16:41:10 | Computer Name = J***n-PC | Source = MsiInstaller | ID = 11713
Description =

[ System Events ]
Error - 06.05.2010 13:01:15 | Computer Name = J***n-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 06.05.2010 13:21:19 | Computer Name = J***n-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 06.05.2010 13:22:22 | Computer Name = J***n-PC | Source = netbt | ID = 4311
Description = Es ist ein Initialisierungsfehler aufgetreten, da der Treiber nicht
erstellt werden konnte. Verwenden Sie die Zeichenfolge "001B770FF26D", um die Schnittstelle
zu identifizieren, die nicht initialisiert werden konnte. Sie stellt die MAC-Adresse
der Schnittstelle mit dem Initialisierungsfehler oder die GUID (Globally Unique
Interface Identifier) dar, wenn NetBT keine Zuordnung von der GUID zur MAC-Adresse
herstellen konnte. Wenn weder die MAC-Adresse noch die GUID verfügbar waren, dann
stellt die Zeichenfolge einen Clustergerätenamen dar.

Error - 06.05.2010 13:22:22 | Computer Name = Jürgen-PC | Source = netbt | ID = 4311
Description = Es ist ein Initialisierungsfehler aufgetreten, da der Treiber nicht
erstellt werden konnte. Verwenden Sie die Zeichenfolge "001B770FF26D", um die Schnittstelle
zu identifizieren, die nicht initialisiert werden konnte. Sie stellt die MAC-Adresse
der Schnittstelle mit dem Initialisierungsfehler oder die GUID (Globally Unique
Interface Identifier) dar, wenn NetBT keine Zuordnung von der GUID zur MAC-Adresse
herstellen konnte. Wenn weder die MAC-Adresse noch die GUID verfügbar waren, dann
stellt die Zeichenfolge einen Clustergerätenamen dar.

Error - 06.05.2010 13:22:51 | Computer Name = Jürgen-PC | Source = srv | ID = 2017
Description = Der Server konnte keinen nicht-ausgelagerten Poolspeicher reservieren,
da die konfigurierte Grenze für die Reservierung von nicht-ausgelagertem Poolspeicher
erreicht wurde.

Error - 06.05.2010 13:22:51 | Computer Name = J***n-PC | Source = srv | ID = 2019
Description = Der Server konnte keinen nicht ausgelagerten Poolspeicher reservieren,
da der Pool leer war.

Error - 07.05.2010 11:11:49 | Computer Name = J***n-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 07.05.2010 15:56:04 | Computer Name = J***n-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 08.05.2010 10:01:14 | Computer Name = J***n-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 08.05.2010 12:41:09 | Computer Name = J***n-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >

cosinus 09.05.2010 16:25

Zitat:

C:\Users\Jürgen\Shared\braunwald heart disesae 2010.cracked.FuVo\patch.exe
Sry, aber... :nixda:

Die (Be)nutzung von Cracks, Serials und Keygens ist illegal, somit gibt es im Trojaner-Board keinen weiteren Support mehr.

Für Dich geht es hier weiter => Neuaufsetzen des Systems
Bitte auch alle Passwörter abändern (für E-Mail-Konten, StudiVZ, Ebay...einfach alles!) da nicht selten in dieser dubiosen Software auch Keylogger und Backdoorfunktionen stecken.

Danach nie wieder sowas anrühren!

juergenheim 15.05.2010 16:17

Vielen Dank nochmal, die heruntergeladene Datei hat sowieso nicht funktioniert

videotuner 15.05.2010 18:50

Zitat:

Zitat von juergenheim (Beitrag 526074)
Vielen Dank nochmal, die heruntergeladene Datei hat sowieso nicht funktioniert

HAHAHA, du bist lustig. Doch die Datei hat funktioniert, nämlich dafür, für was sie gemacht wurde, nämlich deinen Rechner auszuspionieren.

juergenheim 15.05.2010 23:06

Genau, und das habe ich jetzt gelernt und werde die Finger davon lassen. Aus Erfahrung wird man klug, so ist das Leben


Alle Zeitangaben in WEZ +1. Es ist jetzt 15:27 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131