![]() |
Internetsicherheitseinstellungen Hallo ich habe seid 3 tagen das problem das ich viele dienste unter windows nicht mehr ausführen kann wie z.B. das auswählen vom aufnahmemous ind der Lautsrärkeregelung (unten rechts das icon) es erscheint jedesmal eine meldung http://yfrog.com/1r41639008j die internetsicherheitseinstellungen herunterzuschreuben bringt leider auch nichts außerdem problem nummer 2 ist das die minamal anwendungen nicht richtig angezeigt werden ich benutze windows 7 ich habe 2 mal mit malwarebytes geprüft Zitat:
Zitat:
|
Zitat:
|
nur ein key changer für warcraft 3 hatte den vor jahren mal benutzt hatte die cd kaputt und hab dann von einer anderen version den key auf mienen original key geändert also wenn dann hätte der schon vor 3 jahren was gemacht |
Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
|
so der otl scan OTL Logfile: Code: OTL logfile created on: 25.10.2010 21:12:35 - Run 1 OTL Logfile: Code: OTL Extras logfile created on: 25.10.2010 21:12:35 - Run 1 |
Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code: :OTL Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. |
habe alles gemacht musste den pc auch neustarten aber es hat sich keine logdatei erstellt und es wurde auch keine geöffnet |
jetzt hab ich das gefunden unter c: otl Zitat:
|
CustomScan mit OTL Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code: netsvcs
|
so der scan OTL Logfile: Code: OTL logfile created on: 27.10.2010 19:41:42 - Run 2 ========== Processes (SafeList) ========== PRC - C:\Users\Michael\Desktop\OTL(2).exe (OldTimer Tools) PRC - C:\Programme\Alwil Software\Avast5\AvastSvc.exe (AVAST Software) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.) PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG) PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.) PRC - D:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.) PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.) ========== Modules (SafeList) ========== MOD - C:\Users\Michael\Desktop\OTL(2).exe (OldTimer Tools) MOD - C:\Windows\SysWOW64\normaliz.dll (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (VMware NAT Service) -- C:\Windows\SysNative\vmnat.exe File not found SRV:64bit: - (VMnetDHCP) -- C:\Windows\SysNative\vmnetdhcp.exe File not found SRV:64bit: - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software) SRV:64bit: - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software) SRV:64bit: - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software) SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia) SRV - (Application Updater) -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.) SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (VMnetDHCP) -- C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.) SRV - (VMAuthdService) -- D:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.) SRV - (VMware NAT Service) -- C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.) ========== Driver Services (SafeList) ========== DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software) DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions) DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys () DRV:64bit: - (nmwcdx64) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia) DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\drivers\usbser_lowerfltx64j.sys (Nokia) DRV:64bit: - (nmwcdcx64) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia) DRV:64bit: - (upperdev) -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia) DRV:64bit: - (ggsemc) -- C:\Windows\SysNative\drivers\ggsemc.sys (Sony Ericsson Mobile Communications) DRV:64bit: - (ggflt) -- C:\Windows\SysNative\drivers\ggflt.sys (Sony Ericsson Mobile Communications) DRV:64bit: - (tbhsd) -- C:\Windows\SysNative\drivers\tbhsd.sys (RapidSolution Software AG) DRV:64bit: - (RRNetCapMP) -- C:\Windows\SysNative\drivers\rrnetcap.sys (RapidSolution Software AG) DRV:64bit: - (RRNetCap) -- C:\Windows\SysNative\drivers\rrnetcap.sys (RapidSolution Software AG) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation) DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof () DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (vmx86) -- C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.) DRV:64bit: - (vmci) -- C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.) DRV:64bit: - (VMnetuserif) -- C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.) DRV:64bit: - (hcmon) -- C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.) DRV:64bit: - (vmkbd) -- C:\Windows\SysNative\drivers\VMkbd.sys (VMware, Inc.) DRV:64bit: - (VMnetBridge) -- C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.) DRV:64bit: - (VMnetAdapter) -- C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.) DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = ICQ.com Suche IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN, Messenger und Hotmail sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D0 B5 79 D3 AA E7 CA 01 [binary data] IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files (x86)\Search Settings\SearchSettings.dll (Spigot, Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = file://C:/Users/Michael/Music/Temp/Tunebite/.downloading/profile/rrproxy_ie_4afae4f0.pac ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://de.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:de:official" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2 FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1 FF - prefs.js..extensions.enabledItems: 6 FF - prefs.js..extensions.enabledItems: 2 FF - prefs.js..extensions.enabledItems: 49 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8 FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:4.0.0 FF - prefs.js..extensions.enabledItems: smarterwiki@wikiatic.com:4.1.7 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.2.0 FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.9.1.14019 FF - prefs.js..extensions.enabledItems: foxyMeter@tim-wood.net:0.5.0 FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.3&q=" FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "chrome://browser-region/locale/region.properties" FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010.04.08 23:42:42 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.10.20 22:59:55 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.10.20 22:59:55 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.5\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2010.10.22 15:53:54 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2010.07.06 17:32:36 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010.04.08 23:42:42 | 000,000,000 | ---D | M] [2010.01.07 23:21:10 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Extensions [2010.01.07 23:21:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michael\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2010.10.26 22:27:39 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions [2010.05.23 19:11:50 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2010.08.25 22:27:17 | 000,000,000 | ---D | M] (DVDVideoSoftTB Toolbar) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2010.08.05 00:14:34 | 000,000,000 | ---D | M] (ReloadEvery) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644} [2010.08.25 22:22:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2010.08.05 00:14:35 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010.08.18 22:32:32 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010.09.26 19:55:49 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8} [2009.11.25 16:07:43 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2010.09.24 18:33:33 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\foxyMeter@tim-wood.net [2010.09.25 16:45:41 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\smarterwiki@wikiatic.com [2010.10.15 17:22:17 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\toolbar@ask.com [2010.10.24 18:02:17 | 000,000,950 | ---- | M] () -- C:\Users\Michael\AppData\Roaming\Mozilla\FireFox\Profiles\uqihgmfi.default\searchplugins\icqplugin-1.xml [2010.07.28 11:36:49 | 000,000,950 | ---- | M] () -- C:\Users\Michael\AppData\Roaming\Mozilla\FireFox\Profiles\uqihgmfi.default\searchplugins\icqplugin-2.xml [2010.06.28 23:10:17 | 000,000,947 | ---- | M] () -- C:\Users\Michael\AppData\Roaming\Mozilla\FireFox\Profiles\uqihgmfi.default\searchplugins\icqplugin.xml [2010.10.26 21:00:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2010.10.01 14:12:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010.10.01 14:12:28 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2009.12.21 07:47:02 | 000,063,488 | ---- | M] (Nullsoft) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2010.07.28 00:06:18 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.07.28 00:06:18 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.07.28 00:06:18 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.07.28 00:06:18 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.07.28 00:06:18 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.10.27 14:23:44 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O2 - BHO: (SearchSettings Class) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files (x86)\Search Settings\SearchSettings.dll (Spigot, Inc.) O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NapsterShell] C:\Program Files (x86)\Napster\napster.exe (Napster) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm () O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm () O8 - Extra context menu item: Free YouTube Download - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm () O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - D:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - D:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - D:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - D:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll File not found O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.10.27 19:27:05 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Michael\Desktop\OTL(2).exe [2010.10.27 14:16:27 | 000,000,000 | ---D | C] -- C:\_OTL [2010.10.26 22:01:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2010.10.26 22:01:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy [2010.10.26 18:38:29 | 000,000,000 | ---D | C] -- C:\Windows\Sun [2010.10.23 16:14:59 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\Neuer Ordner (8) [2010.10.22 14:33:53 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\Neuer Ordner (6) [2010.10.21 20:31:33 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\rock neu [2010.10.20 18:46:53 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\Malwarebytes [2010.10.20 18:46:29 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010.10.20 18:46:27 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2010.10.20 18:46:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.10.20 18:46:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010.10.08 12:58:00 | 000,155,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\LMRT.dll [2010.10.08 12:58:00 | 000,140,800 | ---- | C] (The Duck Corporation) -- C:\Windows\SysWow64\tm20dec.ax [2010.10.08 12:58:00 | 000,038,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\LMRTREND.dll [2010.10.08 12:57:59 | 000,217,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\strmdll.dll [2010.10.08 12:57:59 | 000,182,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtmsft3.dll [2010.10.08 12:57:59 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unam4ie.exe [2010.10.08 12:57:58 | 001,088,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\danim.dll [2010.10.08 12:57:58 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mciqtz.drv [2010.10.08 12:57:57 | 000,194,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qcut.dll [2010.10.08 12:57:57 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\w95inf32.dll [2010.10.08 12:57:57 | 000,002,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\w95inf16.dll [2010.10.08 12:33:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LEGO Media [2010.10.08 12:33:35 | 000,328,704 | ---- | C] (InstallShield Software Corporation ) -- C:\Windows\IsUn0407.exe [2010.10.08 09:48:48 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Local\AOL [2010.10.07 23:06:54 | 000,000,000 | ---D | C] -- C:\Programme\Defraggler [2010.10.07 23:06:35 | 004,236,112 | ---- | C] (Piriform Ltd) -- C:\Users\Michael\Desktop\dfsetup121.exe [2010.10.06 20:16:45 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\Neuer Ordner (10) [2010.10.06 20:04:52 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Local\DVDVideoSoft_Ltd [2010.10.06 19:18:27 | 000,000,000 | ---D | C] -- C:\Users\Michael\Documents\Freemake [2010.10.06 19:18:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Freemake [2010.10.06 19:18:11 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\DVDVideoSoft [2010.10.06 19:12:25 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\AVS4YOU [2010.10.06 19:11:40 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3a.dll [2010.10.06 19:11:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVSMedia [2010.10.06 19:11:40 | 000,000,000 | ---D | C] -- C:\ProgramData\AVS4YOU [2010.10.05 19:35:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Trymedia [2010.10.05 18:54:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JDownloader [2010.10.05 15:42:12 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\house [2010.10.05 15:42:05 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\oldies [2010.10.05 15:37:44 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\rock [2010.10.04 19:50:13 | 000,000,000 | R--D | C] -- C:\Users\Michael\Documents\Notes [2010.10.01 16:38:38 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\java [2010.10.01 15:38:55 | 000,000,000 | ---D | C] -- C:\Users\Michael\.nbprofiler [2010.10.01 15:38:54 | 000,000,000 | ---D | C] -- C:\Users\Michael\.netbeans [2010.10.01 15:38:53 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\.visualvm [2010.10.01 15:26:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JavaFX [2010.10.01 15:15:58 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\hamster [2010.10.01 14:55:41 | 000,000,000 | ---D | C] -- C:\Programme\hamstersimulator-v28-01 [2010.09.30 15:36:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared [2010.09.30 15:36:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Roxio Shared [2010.09.30 15:36:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Napster Shared [2010.09.30 15:36:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Napster [2010.09.30 15:35:54 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\InstallShield [2010.09.29 22:23:00 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\Neuer Ordner (9) [2010.09.28 15:13:25 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Local\DOSBox [2010.09.28 15:13:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DOSBox-0.74 [2010.09.28 15:02:38 | 000,000,000 | ---D | C] -- C:\MPS ========== Files - Modified Within 30 Days ========== [2010.10.27 19:26:51 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Michael\Desktop\OTL(2).exe [2010.10.27 14:30:03 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2010.10.27 14:30:03 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2010.10.27 14:24:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.10.27 14:24:50 | 3220,713,472 | -HS- | M] () -- C:\hiberfil.sys [2010.10.27 14:23:44 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts [2010.10.26 22:06:28 | 000,423,309 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20101026-220659.backup [2010.10.26 22:01:11 | 000,001,262 | ---- | M] () -- C:\Users\Michael\Desktop\Spybot - Search & Destroy.lnk [2010.10.26 14:19:15 | 000,000,217 | ---- | M] () -- C:\Users\Michael\Desktop\ICQ Spiele.url [2010.10.25 16:59:22 | 000,023,552 | ---- | M] () -- C:\Users\Michael\Desktop\house.doc [2010.10.25 15:41:12 | 000,029,518 | ---- | M] () -- C:\Users\Michael\Desktop\jk.JPG [2010.10.23 16:11:18 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010.10.23 16:11:18 | 000,643,628 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2010.10.23 16:11:18 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010.10.23 16:11:18 | 000,126,188 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2010.10.23 16:11:18 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010.10.20 18:46:32 | 000,001,013 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.10.19 23:45:45 | 000,025,088 | ---- | M] () -- C:\Users\Michael\Desktop\Microsoft Word-Dokument (neu) (3).doc [2010.10.19 19:11:22 | 000,024,064 | ---- | M] () -- C:\Users\Michael\Desktop\Microsoft Word-Dokument (neu) (5).doc [2010.10.19 16:59:26 | 000,024,064 | ---- | M] () -- C:\Users\Michael\Desktop\napster.doc [2010.10.17 20:52:52 | 000,000,171 | ---- | M] () -- C:\Users\Michael\Desktop\file-231042330.flv [2010.10.14 17:46:45 | 000,121,856 | ---- | M] () -- C:\Users\Michael\Documents\Dok2.doc [2010.10.08 12:57:56 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\w95inf32.dll [2010.10.08 12:57:56 | 000,002,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\w95inf16.dll [2010.10.08 12:57:52 | 000,001,293 | ---- | M] () -- C:\Users\Public\Desktop\LEGO Racers.lnk [2010.10.07 23:06:36 | 004,236,112 | ---- | M] (Piriform Ltd) -- C:\Users\Michael\Desktop\dfsetup121.exe [2010.10.06 19:18:26 | 000,001,210 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk [2010.10.06 19:18:24 | 000,001,243 | ---- | M] () -- C:\Users\Michael\Desktop\DVDVideoSoft Free Studio.lnk [2010.10.05 19:27:42 | 000,002,221 | ---- | M] () -- C:\Users\Public\Desktop\Need For Speed World.lnk [2010.10.05 18:54:50 | 000,001,025 | ---- | M] () -- C:\Users\Public\Desktop\JDownloader.lnk [2010.10.01 14:12:28 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll [2010.10.01 14:12:28 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2010.10.01 14:12:28 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2010.10.01 14:12:28 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2010.09.30 15:37:03 | 000,001,885 | ---- | M] () -- C:\Users\Public\Desktop\Napster.lnk [2010.09.28 15:13:06 | 000,001,922 | ---- | M] () -- C:\Users\Public\Desktop\DOSBox 0.74.lnk ========== Files Created - No Company Name ========== [2010.10.26 22:01:11 | 000,001,262 | ---- | C] () -- C:\Users\Michael\Desktop\Spybot - Search & Destroy.lnk [2010.10.26 14:19:15 | 000,000,217 | ---- | C] () -- C:\Users\Michael\Desktop\ICQ Spiele.url [2010.10.25 15:41:10 | 000,029,518 | ---- | C] () -- C:\Users\Michael\Desktop\jk.JPG [2010.10.22 14:12:12 | 000,229,376 | ---- | C] () -- C:\Users\Michael\Desktop\SMS Ton - Schrei.mp3 [2010.10.20 18:46:32 | 000,001,013 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.10.19 19:11:11 | 000,024,064 | ---- | C] () -- C:\Users\Michael\Desktop\Microsoft Word-Dokument (neu) (5).doc [2010.10.17 23:17:26 | 004,814,976 | ---- | C] () -- C:\Users\Michael\Desktop\PETERLICHT - SONNENDECK [RADIO-FASSUNG (EKIMAS PROPPE REMIX].MP3 [2010.10.17 20:52:50 | 000,000,171 | ---- | C] () -- C:\Users\Michael\Desktop\file-231042330.flv [2010.10.14 17:46:45 | 000,121,856 | ---- | C] () -- C:\Users\Michael\Documents\Dok2.doc [2010.10.14 16:53:48 | 000,024,064 | ---- | C] () -- C:\Users\Michael\Desktop\napster.doc [2010.10.08 12:57:58 | 000,010,240 | ---- | C] () -- C:\Windows\SysWow64\vidx16.dll [2010.10.08 12:57:58 | 000,005,672 | ---- | C] () -- C:\Windows\SysWow64\quartz.vxd [2010.10.08 12:33:46 | 000,001,293 | ---- | C] () -- C:\Users\Public\Desktop\LEGO Racers.lnk [2010.10.06 19:18:26 | 000,001,210 | ---- | C] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk [2010.10.05 19:27:42 | 000,002,221 | ---- | C] () -- C:\Users\Public\Desktop\Need For Speed World.lnk [2010.10.05 18:54:50 | 000,001,025 | ---- | C] () -- C:\Users\Public\Desktop\JDownloader.lnk [2010.09.30 15:37:03 | 000,001,885 | ---- | C] () -- C:\Users\Public\Desktop\Napster.lnk [2010.09.28 15:13:06 | 000,001,922 | ---- | C] () -- C:\Users\Public\Desktop\DOSBox 0.74.lnk [2010.09.02 19:45:41 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll [2010.04.11 20:29:21 | 000,006,656 | ---- | C] () -- C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.03.17 16:42:12 | 001,499,556 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2010.02.16 17:15:54 | 000,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010.02.09 22:37:18 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\mgxasio2.dll [2010.02.09 22:36:24 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll [2010.01.10 18:30:47 | 000,290,904 | R--- | C] () -- C:\Windows\SysWow64\vc6-re200l.dll [2009.12.07 17:05:05 | 000,007,598 | ---- | C] () -- C:\Users\Michael\AppData\Local\Resmon.ResmonCfg [2009.11.25 13:40:50 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2009.11.17 14:58:09 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2009.08.07 20:51:34 | 000,178,430 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2010.10.01 15:38:53 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\.visualvm [2010.08.06 10:34:54 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Adobe [2010.10.06 19:12:25 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\AVS4YOU [2009.12.01 21:56:06 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Bioshock [2010.10.14 19:56:46 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\BitTorrent [2009.11.18 15:07:56 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Canneverbe_Limited [2010.04.22 15:08:51 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\com.adobe.ExMan [2010.04.20 12:56:59 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\DAEMON Tools Lite [2010.03.12 21:47:34 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Dexpot [2010.07.12 23:02:50 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\DivX [2010.10.27 18:03:32 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\dvdcss [2010.10.06 20:04:07 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\DVDVideoSoft [2010.10.06 19:18:28 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers [2010.09.13 14:24:09 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\FileZilla [2010.02.16 15:42:55 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Foxit [2009.11.20 20:52:44 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\FreeFLVConverter [2010.04.22 17:05:34 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\gtk-2.0 [2010.10.27 19:28:26 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\ICQ [2009.11.10 18:10:05 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Identities [2010.01.07 18:31:59 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\ImgBurn [2010.09.30 15:35:54 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\InstallShield [2009.12.01 17:18:12 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\L4dOgerLauncher [2009.11.10 18:26:25 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Macromedia [2010.02.09 22:37:41 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\MAGIX [2010.10.20 18:46:53 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Malwarebytes [2009.07.14 20:18:19 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Media Center Programs [2010.08.14 15:04:10 | 000,000,000 | --SD | M] -- C:\Users\Michael\AppData\Roaming\Microsoft [2010.01.18 17:14:04 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Miranda [2009.11.10 18:19:51 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Mozilla [2010.01.18 17:37:01 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Nero [2010.04.09 17:22:15 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Nokia [2010.04.14 23:33:21 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\org.bcdef.antenna.43FD862ECBF25EB623FC234EF1704635B78E3AB6.1 [2010.06.09 14:02:17 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\PC Suite [2010.10.11 19:50:38 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Roxio [2009.12.01 21:47:14 | 000,000,000 | RH-D | M] -- C:\Users\Michael\AppData\Roaming\SecuROM [2010.10.07 23:18:51 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Skype [2010.10.07 19:43:38 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\skypePM [2010.01.07 23:21:09 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Thunderbird [2010.05.02 19:25:58 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Ubisoft [2010.10.27 19:28:20 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\vlc [2010.10.24 23:15:18 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\VMware [2009.11.24 16:11:36 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\WinRAR < %APPDATA%\*.exe /s > [2010.09.19 21:51:35 | 000,010,134 | R--- | M] () -- C:\Users\Michael\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe [2009.11.06 10:20:16 | 000,022,352 | ---- | M] (NOS Microsystems Ltd.) -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe [2009.11.06 10:20:16 | 000,034,112 | ---- | M] (NOS Microsystems Ltd.) -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe [2010.10.14 16:36:46 | 003,056,008 | ---- | M] (Ask) -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\uqihgmfi.default\extensions\toolbar@ask.com\chrome\temp\askToolbar.exe < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys < MD5 for: ATAPI.SYS > [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll [2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll < MD5 for: IASTORV.SYS > [2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys [2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys < MD5 for: NETLOGON.DLL > [2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll < MD5 for: NVSTOR.SYS > [2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys [2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys < MD5 for: SCECLI.DLL > [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll [2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll < MD5 for: USER32.DLL > [2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll [2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll [2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll [2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll < MD5 for: USERINIT.EXE > [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe [2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe [2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe [2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe < MD5 for: WS2IFSL.SYS > [2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < End of report > FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010.04.08 23:42:42 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.10.20 22:59:55 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.10.20 22:59:55 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.5\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2010.10.22 15:53:54 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2010.07.06 17:32:36 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010.04.08 23:42:42 | 000,000,000 | ---D | M] [2010.01.07 23:21:10 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Extensions [2010.01.07 23:21:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michael\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2010.10.26 22:27:39 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions [2010.05.23 19:11:50 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2010.08.25 22:27:17 | 000,000,000 | ---D | M] (DVDVideoSoftTB Toolbar) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2010.08.05 00:14:34 | 000,000,000 | ---D | M] (ReloadEvery) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644} [2010.08.25 22:22:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2010.08.05 00:14:35 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010.08.18 22:32:32 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010.09.26 19:55:49 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8} [2009.11.25 16:07:43 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2010.09.24 18:33:33 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\foxyMeter@tim-wood.net [2010.09.25 16:45:41 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\smarterwiki@wikiatic.com [2010.10.15 17:22:17 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\uqihgmfi.default\extensions\toolbar@ask.com [2010.10.24 18:02:17 | 000,000,950 | ---- | M] () -- C:\Users\Michael\AppData\Roaming\Mozilla\FireFox\Profiles\uqihgmfi.default\searchplugins\icqplugin-1.xml [2010.07.28 11:36:49 | 000,000,950 | ---- | M] () -- C:\Users\Michael\AppData\Roaming\Mozilla\FireFox\Profiles\uqihgmfi.default\searchplugins\icqplugin-2.xml [2010.06.28 23:10:17 | 000,000,947 | ---- | M] () -- C:\Users\Michael\AppData\Roaming\Mozilla\FireFox\Profiles\uqihgmfi.default\searchplugins\icqplugin.xml [2010.10.26 21:00:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2010.10.01 14:12:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010.10.01 14:12:28 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2009.12.21 07:47:02 | 000,063,488 | ---- | M] (Nullsoft) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2010.07.28 00:06:18 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.07.28 00:06:18 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.07.28 00:06:18 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.07.28 00:06:18 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.07.28 00:06:18 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.10.27 14:23:44 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O2 - BHO: (SearchSettings Class) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files (x86)\Search Settings\SearchSettings.dll (Spigot, Inc.) O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NapsterShell] C:\Program Files (x86)\Napster\napster.exe (Napster) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm () O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm () O8 - Extra context menu item: Free YouTube Download - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm () O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - D:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - D:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - D:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - D:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll File not found O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.10.27 19:27:05 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Michael\Desktop\OTL(2).exe [2010.10.27 14:16:27 | 000,000,000 | ---D | C] -- C:\_OTL [2010.10.26 22:01:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2010.10.26 22:01:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy [2010.10.26 18:38:29 | 000,000,000 | ---D | C] -- C:\Windows\Sun [2010.10.23 16:14:59 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\Neuer Ordner (8) [2010.10.22 14:33:53 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\Neuer Ordner (6) [2010.10.21 20:31:33 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\rock neu [2010.10.20 18:46:53 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\Malwarebytes [2010.10.20 18:46:29 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010.10.20 18:46:27 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2010.10.20 18:46:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.10.20 18:46:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010.10.08 12:58:00 | 000,155,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\LMRT.dll [2010.10.08 12:58:00 | 000,140,800 | ---- | C] (The Duck Corporation) -- C:\Windows\SysWow64\tm20dec.ax [2010.10.08 12:58:00 | 000,038,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\LMRTREND.dll [2010.10.08 12:57:59 | 000,217,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\strmdll.dll [2010.10.08 12:57:59 | 000,182,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtmsft3.dll [2010.10.08 12:57:59 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unam4ie.exe [2010.10.08 12:57:58 | 001,088,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\danim.dll [2010.10.08 12:57:58 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mciqtz.drv [2010.10.08 12:57:57 | 000,194,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qcut.dll [2010.10.08 12:57:57 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\w95inf32.dll [2010.10.08 12:57:57 | 000,002,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\w95inf16.dll [2010.10.08 12:33:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LEGO Media [2010.10.08 12:33:35 | 000,328,704 | ---- | C] (InstallShield Software Corporation ) -- C:\Windows\IsUn0407.exe [2010.10.08 09:48:48 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Local\AOL [2010.10.07 23:06:54 | 000,000,000 | ---D | C] -- C:\Programme\Defraggler [2010.10.07 23:06:35 | 004,236,112 | ---- | C] (Piriform Ltd) -- C:\Users\Michael\Desktop\dfsetup121.exe [2010.10.06 20:16:45 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\Neuer Ordner (10) [2010.10.06 20:04:52 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Local\DVDVideoSoft_Ltd [2010.10.06 19:18:27 | 000,000,000 | ---D | C] -- C:\Users\Michael\Documents\Freemake [2010.10.06 19:18:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Freemake [2010.10.06 19:18:11 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\DVDVideoSoft [2010.10.06 19:12:25 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\AVS4YOU [2010.10.06 19:11:40 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3a.dll [2010.10.06 19:11:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVSMedia [2010.10.06 19:11:40 | 000,000,000 | ---D | C] -- C:\ProgramData\AVS4YOU [2010.10.05 19:35:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Trymedia [2010.10.05 18:54:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JDownloader [2010.10.05 15:42:12 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\house [2010.10.05 15:42:05 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\oldies [2010.10.05 15:37:44 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\rock [2010.10.04 19:50:13 | 000,000,000 | R--D | C] -- C:\Users\Michael\Documents\Notes [2010.10.01 16:38:38 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\java [2010.10.01 15:38:55 | 000,000,000 | ---D | C] -- C:\Users\Michael\.nbprofiler [2010.10.01 15:38:54 | 000,000,000 | ---D | C] -- C:\Users\Michael\.netbeans [2010.10.01 15:38:53 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\.visualvm [2010.10.01 15:26:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JavaFX [2010.10.01 15:15:58 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\hamster [2010.10.01 14:55:41 | 000,000,000 | ---D | C] -- C:\Programme\hamstersimulator-v28-01 [2010.09.30 15:36:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared [2010.09.30 15:36:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Roxio Shared [2010.09.30 15:36:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Napster Shared [2010.09.30 15:36:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Napster [2010.09.30 15:35:54 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\InstallShield [2010.09.29 22:23:00 | 000,000,000 | ---D | C] -- C:\Users\Michael\Desktop\Neuer Ordner (9) [2010.09.28 15:13:25 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Local\DOSBox [2010.09.28 15:13:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DOSBox-0.74 [2010.09.28 15:02:38 | 000,000,000 | ---D | C] -- C:\MPS ========== Files - Modified Within 30 Days ========== [2010.10.27 19:26:51 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Michael\Desktop\OTL(2).exe [2010.10.27 14:30:03 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2010.10.27 14:30:03 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2010.10.27 14:24:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.10.27 14:24:50 | 3220,713,472 | -HS- | M] () -- C:\hiberfil.sys [2010.10.27 14:23:44 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts [2010.10.26 22:06:28 | 000,423,309 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20101026-220659.backup [2010.10.26 22:01:11 | 000,001,262 | ---- | M] () -- C:\Users\Michael\Desktop\Spybot - Search & Destroy.lnk [2010.10.26 14:19:15 | 000,000,217 | ---- | M] () -- C:\Users\Michael\Desktop\ICQ Spiele.url [2010.10.25 16:59:22 | 000,023,552 | ---- | M] () -- C:\Users\Michael\Desktop\house.doc [2010.10.25 15:41:12 | 000,029,518 | ---- | M] () -- C:\Users\Michael\Desktop\jk.JPG [2010.10.23 16:11:18 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010.10.23 16:11:18 | 000,643,628 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2010.10.23 16:11:18 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010.10.23 16:11:18 | 000,126,188 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2010.10.23 16:11:18 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010.10.20 18:46:32 | 000,001,013 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.10.19 23:45:45 | 000,025,088 | ---- | M] () -- C:\Users\Michael\Desktop\Microsoft Word-Dokument (neu) (3).doc [2010.10.19 19:11:22 | 000,024,064 | ---- | M] () -- C:\Users\Michael\Desktop\Microsoft Word-Dokument (neu) (5).doc [2010.10.19 16:59:26 | 000,024,064 | ---- | M] () -- C:\Users\Michael\Desktop\napster.doc [2010.10.17 20:52:52 | 000,000,171 | ---- | M] () -- C:\Users\Michael\Desktop\file-231042330.flv [2010.10.14 17:46:45 | 000,121,856 | ---- | M] () -- C:\Users\Michael\Documents\Dok2.doc [2010.10.08 12:57:56 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\w95inf32.dll [2010.10.08 12:57:56 | 000,002,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\w95inf16.dll [2010.10.08 12:57:52 | 000,001,293 | ---- | M] () -- C:\Users\Public\Desktop\LEGO Racers.lnk [2010.10.07 23:06:36 | 004,236,112 | ---- | M] (Piriform Ltd) -- C:\Users\Michael\Desktop\dfsetup121.exe [2010.10.06 19:18:26 | 000,001,210 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk [2010.10.06 19:18:24 | 000,001,243 | ---- | M] () -- C:\Users\Michael\Desktop\DVDVideoSoft Free Studio.lnk [2010.10.05 19:27:42 | 000,002,221 | ---- | M] () -- C:\Users\Public\Desktop\Need For Speed World.lnk [2010.10.05 18:54:50 | 000,001,025 | ---- | M] () -- C:\Users\Public\Desktop\JDownloader.lnk [2010.10.01 14:12:28 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll [2010.10.01 14:12:28 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2010.10.01 14:12:28 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2010.10.01 14:12:28 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2010.09.30 15:37:03 | 000,001,885 | ---- | M] () -- C:\Users\Public\Desktop\Napster.lnk [2010.09.28 15:13:06 | 000,001,922 | ---- | M] () -- C:\Users\Public\Desktop\DOSBox 0.74.lnk ========== Files Created - No Company Name ========== [2010.10.26 22:01:11 | 000,001,262 | ---- | C] () -- C:\Users\Michael\Desktop\Spybot - Search & Destroy.lnk [2010.10.26 14:19:15 | 000,000,217 | ---- | C] () -- C:\Users\Michael\Desktop\ICQ Spiele.url [2010.10.25 15:41:10 | 000,029,518 | ---- | C] () -- C:\Users\Michael\Desktop\jk.JPG [2010.10.22 14:12:12 | 000,229,376 | ---- | C] () -- C:\Users\Michael\Desktop\SMS Ton - Schrei.mp3 [2010.10.20 18:46:32 | 000,001,013 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.10.19 19:11:11 | 000,024,064 | ---- | C] () -- C:\Users\Michael\Desktop\Microsoft Word-Dokument (neu) (5).doc [2010.10.17 23:17:26 | 004,814,976 | ---- | C] () -- C:\Users\Michael\Desktop\PETERLICHT - SONNENDECK [RADIO-FASSUNG (EKIMAS PROPPE REMIX].MP3 [2010.10.17 20:52:50 | 000,000,171 | ---- | C] () -- C:\Users\Michael\Desktop\file-231042330.flv [2010.10.14 17:46:45 | 000,121,856 | ---- | C] () -- C:\Users\Michael\Documents\Dok2.doc [2010.10.14 16:53:48 | 000,024,064 | ---- | C] () -- C:\Users\Michael\Desktop\napster.doc [2010.10.08 12:57:58 | 000,010,240 | ---- | C] () -- C:\Windows\SysWow64\vidx16.dll [2010.10.08 12:57:58 | 000,005,672 | ---- | C] () -- C:\Windows\SysWow64\quartz.vxd [2010.10.08 12:33:46 | 000,001,293 | ---- | C] () -- C:\Users\Public\Desktop\LEGO Racers.lnk [2010.10.06 19:18:26 | 000,001,210 | ---- | C] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk [2010.10.05 19:27:42 | 000,002,221 | ---- | C] () -- C:\Users\Public\Desktop\Need For Speed World.lnk [2010.10.05 18:54:50 | 000,001,025 | ---- | C] () -- C:\Users\Public\Desktop\JDownloader.lnk [2010.09.30 15:37:03 | 000,001,885 | ---- | C] () -- C:\Users\Public\Desktop\Napster.lnk [2010.09.28 15:13:06 | 000,001,922 | ---- | C] () -- C:\Users\Public\Desktop\DOSBox 0.74.lnk [2010.09.02 19:45:41 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll [2010.04.11 20:29:21 | 000,006,656 | ---- | C] () -- C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.03.17 16:42:12 | 001,499,556 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2010.02.16 17:15:54 | 000,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010.02.09 22:37:18 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\mgxasio2.dll [2010.02.09 22:36:24 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll [2010.01.10 18:30:47 | 000,290,904 | R--- | C] () -- C:\Windows\SysWow64\vc6-re200l.dll [2009.12.07 17:05:05 | 000,007,598 | ---- | C] () -- C:\Users\Michael\AppData\Local\Resmon.ResmonCfg [2009.11.25 13:40:50 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2009.11.17 14:58:09 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2009.08.07 20:51:34 | 000,178,430 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2010.10.01 15:38:53 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\.visualvm [2010.08.06 10:34:54 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Adobe [2010.10.06 19:12:25 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\AVS4YOU [2009.12.01 21:56:06 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Bioshock [2010.10.14 19:56:46 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\BitTorrent [2009.11.18 15:07:56 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Canneverbe_Limited [2010.04.22 15:08:51 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\com.adobe.ExMan [2010.04.20 12:56:59 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\DAEMON Tools Lite [2010.03.12 21:47:34 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Dexpot [2010.07.12 23:02:50 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\DivX [2010.10.27 18:03:32 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\dvdcss [2010.10.06 20:04:07 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\DVDVideoSoft [2010.10.06 19:18:28 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers [2010.09.13 14:24:09 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\FileZilla [2010.02.16 15:42:55 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Foxit [2009.11.20 20:52:44 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\FreeFLVConverter [2010.04.22 17:05:34 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\gtk-2.0 [2010.10.27 19:28:26 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\ICQ [2009.11.10 18:10:05 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Identities [2010.01.07 18:31:59 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\ImgBurn [2010.09.30 15:35:54 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\InstallShield [2009.12.01 17:18:12 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\L4dOgerLauncher [2009.11.10 18:26:25 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Macromedia [2010.02.09 22:37:41 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\MAGIX [2010.10.20 18:46:53 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Malwarebytes [2009.07.14 20:18:19 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Media Center Programs [2010.08.14 15:04:10 | 000,000,000 | --SD | M] -- C:\Users\Michael\AppData\Roaming\Microsoft [2010.01.18 17:14:04 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Miranda [2009.11.10 18:19:51 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Mozilla [2010.01.18 17:37:01 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Nero [2010.04.09 17:22:15 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Nokia [2010.04.14 23:33:21 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\org.bcdef.antenna.43FD862ECBF25EB623FC234EF1704635B78E3AB6.1 [2010.06.09 14:02:17 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\PC Suite [2010.10.11 19:50:38 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Roxio [2009.12.01 21:47:14 | 000,000,000 | RH-D | M] -- C:\Users\Michael\AppData\Roaming\SecuROM [2010.10.07 23:18:51 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Skype [2010.10.07 19:43:38 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\skypePM [2010.01.07 23:21:09 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Thunderbird [2010.05.02 19:25:58 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Ubisoft [2010.10.27 19:28:20 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\vlc [2010.10.24 23:15:18 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\VMware [2009.11.24 16:11:36 | 000,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\WinRAR < %APPDATA%\*.exe /s > [2010.09.19 21:51:35 | 000,010,134 | R--- | M] () -- C:\Users\Michael\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe [2009.11.06 10:20:16 | 000,022,352 | ---- | M] (NOS Microsystems Ltd.) -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe [2009.11.06 10:20:16 | 000,034,112 | ---- | M] (NOS Microsystems Ltd.) -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\uqihgmfi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe [2010.10.14 16:36:46 | 003,056,008 | ---- | M] (Ask) -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\uqihgmfi.default\extensions\toolbar@ask.com\chrome\temp\askToolbar.exe < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys < MD5 for: ATAPI.SYS > [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll [2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll < MD5 for: IASTORV.SYS > [2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys [2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys < MD5 for: NETLOGON.DLL > [2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll < MD5 for: NVSTOR.SYS > [2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys [2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys < MD5 for: SCECLI.DLL > [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll [2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll < MD5 for: USER32.DLL > [2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll [2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll [2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll [2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll < MD5 for: USERINIT.EXE > [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe [2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe [2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe [2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe < MD5 for: WS2IFSL.SYS > [2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < End of report > [/QUOTE] |
Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!! |
ok mach ich morgen und danke schonmal |
schon mal die logfile von malware Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4936 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 28.10.2010 15:43:04 mbam-log-2010-10-28 (15-43-04).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 454789 Laufzeit: 1 Stunde(n), 10 Minute(n), 50 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 11/01/2010 at 10:53 PM Application Version : 4.45.1000 Core Rules Database Version : 5792 Trace Rules Database Version: 3604 Scan type : Complete Scan Total Scan Time : 02:42:47 Memory items scanned : 543 Memory threats detected : 0 Registry items scanned : 13287 Registry threats detected : 0 File items scanned : 317960 File threats detected : 9 Adware.Tracking Cookie C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Cookies\michael@atwola[1].txt C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Cookies\michael@ad.yieldmanager[2].txt C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Cookies\michael@doubleclick[1].txt C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Cookies\michael@tracking.quisma[1].txt C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Cookies\michael@2o7[1].txt C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Cookies\michael@content.yieldmanager[2].txt C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Cookies\michael@tradedoubler[1].txt C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Cookies\michael@content.yieldmanager[3].txt Adware.Vundo/Variant-MSFake D:\AGE OF EMPIRES II\AGE2_X1.EXE |
Zitat:
|
Alle Zeitangaben in WEZ +1. Es ist jetzt 22:09 Uhr. |
Copyright ©2000-2025, Trojaner-Board