Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   svchost.bat? Was ist das? (https://www.trojaner-board.de/94797-svchost-bat.html)

daniel508 17.01.2011 14:59

svchost.bat? Was ist das?
 
Hallo,
habe heute mal mit Norton 360 den Auto Start Manager ausgeführt und da ist mir eine Datei aufgefallen die dort aufgelistet war.
Ihr Name heißt "svchost.bat"!
Habe gegooglet und bin auf nichts nützliches gestoßen.
Als ich vor einer Woche den Start Manager ausgeführt habe, war diese Datei noch nicht da.
Virus Total hat die Datei mehrfach als Trojaner erkannt.
Ist es wirklich einer?

(LINK: hxxp://tiny.cc/0b3mw)

Meine Frage: Was ist "svchost.bat"?

Gruß

cosinus 17.01.2011 16:00

Lad die svchost.bat bitte bei uns hoch => Trojaner-Board Upload Channel

daniel508 17.01.2011 16:06

Hab ich nicht mehr, CHIP hat mir geraten ich soll die Datei löschen.
hxxp://forum.chip.de/viren-trojaner-wuermer/svchost-bat-1476037.html#post8963870

ist es eigentlich nötig meine Passwörter zu ändern?

cosinus 17.01.2011 16:09

Und warum dann ein Crossposting? :mad:

daniel508 17.01.2011 16:11

Wegen der Frage.
Und weil ich dachte, dass sich TROJANERBoard in Sachen Trojanern ein wenig besser auskennt.

Hätte ja auch was schlimmes sein können oder so..

cosinus 17.01.2011 16:20

Du hättest aber am Anfang schon drauf hinweisen können! :pfui:



Bitte routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!

Danach OTL:

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.

daniel508 17.01.2011 16:53

Malwarebytes:
Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 5537

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

17.01.2011 15:07:03
mbam-log-2011-01-17 (15-07-03).txt

Art des Suchlaufs: Vollständiger Suchlauf (A:\|C:\|D:\|E:\|F:\|H:\|X:\|)
Durchsuchte Objekte: 255319
Laufzeit: 40 Minute(n), 31 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\Users\Daniel\Desktop\Backup!\cryptload\ocr\netload.in\asmcaptcha\test.exe (Malware.Packer) -> Quarantined and deleted successfully.

OTL:
Extras:
Code:

OTL Extras logfile created on: 17.01.2011 16:43:44 - Run 1
OTL by OldTimer - Version 3.2.20.2    Folder = C:\Users\Daniel\Downloads
 Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 48,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 74,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 49,90 Gb Total Space | 22,50 Gb Free Space | 45,09% Space Free | Partition Type: NTFS
Drive D: | 99,05 Gb Total Space | 61,56 Gb Free Space | 62,15% Space Free | Partition Type: NTFS
Drive E: | 931,40 Gb Total Space | 909,02 Gb Free Space | 97,60% Space Free | Partition Type: FAT32
Drive H: | 100,00 Mb Total Space | 70,20 Mb Free Space | 70,20% Space Free | Partition Type: NTFS
 
Computer Name: DANIEL-PC | User Name: Daniel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- "E:\Backup\User@USER-PC\#D\Programme\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1"
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "D:\Programme\VLC Media Player\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [pd4Encrypt] -- "D:\Programme\Password Depot 4\PasswordDepot.exe" -encrypt "%1" (AceBIT GmbH)
Directory [pd4Erase] -- "D:\Programme\Password Depot 4\PasswordDepot.exe" -erase "%1" (AceBIT GmbH)
Directory [PlayWithVLC] -- "D:\Programme\VLC Media Player\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 1
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0B7C79A5-5CB2-4ABD-A9C1-92A6213CE8DD}_is1" = MSI Kombustor 1.1.2 (DX11)
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5546F4E9-B0F4-4F54-B949-2AB006C9284F}" = DJ_AIO_06_F2400_SW_Min
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{60FFB3E0-6D5B-4D73-AE5B-07E58B83AF0C}" = 32 Bit HP CIO Components Installer
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{79E9C7C5-4FCC-4DFF-B79E-17319E9522F3}" = MagicTunePremium
"{819CA3BC-2FF8-4811-B42F-421F7BFD3559}" = HP Deskjet F2400 All-in-One Driver 14.0 Rel. 6
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86A4C6D9-29EE-4719-AFA1-BA3341862B83}" = Microsoft Games for Windows - LIVE
"{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D1E61D1-1395-4E97-997F-D002DB3A5074}" = OpenOffice.org 3.2
"{8DB77BE4-629D-458D-BD68-9F36667C2177}" = TubeBox!
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A748A983-311C-4D65-B570-E7764492803E}" = Password Depot 4
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1031-7B44-AA0000000001}" = Adobe Reader X - Deutsch
"{AD483998-2E9A-4405-83FF-6E503AF49CBB}" = Microsoft Virtual PC 2007 SP1
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D7D50E0C-27DD-4999-BC05-E026B580F93A}" = Electronic Arts Product Registration
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DE042823-C359-4B87-B66B-308057E8B6AF}" = Camtasia Studio 7
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Afterburner" = MSI Afterburner 2.0.0 Beta 4
"Akamai" = Akamai NetSession Interface
"Alarm für Cobra 11 - Das Syndikat_is1" = Alarm für Cobra 11 - Das Syndikat
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.56
"Fraps" = Fraps (remove only)
"InstallShield_{D7D50E0C-27DD-4999-BC05-E026B580F93A}" = Electronic Arts Product Registration
"JDownloader" = JDownloader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"N360" = Norton 360
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"RocketDock_is1" = RocketDock 1.3.5
"sp6" = Logitech SetPoint 6.20
"VLC media player" = VLC media player 1.1.5
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"Zattoo4" = Zattoo4 4.0.5
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CopyTrans Suite" = Nur Deinstallierung der CopyTrans Suite möglich.
"Google Chrome" = Google Chrome
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 16.01.2011 12:38:21 | Computer Name = Daniel-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5694
 
Error - 16.01.2011 12:38:22 | Computer Name = Daniel-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 16.01.2011 12:38:22 | Computer Name = Daniel-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6693
 
Error - 16.01.2011 12:38:22 | Computer Name = Daniel-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6693
 
Error - 16.01.2011 12:38:23 | Computer Name = Daniel-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 16.01.2011 12:38:23 | Computer Name = Daniel-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7691
 
Error - 16.01.2011 12:38:23 | Computer Name = Daniel-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7691
 
Error - 16.01.2011 12:38:24 | Computer Name = Daniel-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 16.01.2011 12:38:24 | Computer Name = Daniel-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 8690
 
Error - 16.01.2011 12:38:24 | Computer Name = Daniel-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 8690
 
[ System Events ]
Error - 13.01.2011 12:44:11 | Computer Name = Daniel-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?13.?01.?2011 um 17:43:31 unerwartet heruntergefahren.
 
Error - 13.01.2011 12:44:21 | Computer Name = Daniel-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  MagicTune
 
Error - 14.01.2011 10:20:22 | Computer Name = Daniel-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  MagicTune
 
Error - 14.01.2011 19:34:46 | Computer Name = Daniel-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 15.01.2011 09:11:22 | Computer Name = Daniel-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  MagicTune
 
Error - 15.01.2011 15:14:06 | Computer Name = Daniel-PC | Source = DCOM | ID = 10010
Description =
 
Error - 16.01.2011 00:15:57 | Computer Name = Daniel-PC | Source = DCOM | ID = 10010
Description =
 
Error - 16.01.2011 08:27:34 | Computer Name = Daniel-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  MagicTune
 
Error - 16.01.2011 08:28:20 | Computer Name = Daniel-PC | Source = Microsoft-Windows-Application-Experience | ID = 205
Description = Der Dienst "Programmkompatibilitäts-Assistent" konnte Phase 2 nicht
 initialisieren.
 
Error - 17.01.2011 08:50:55 | Computer Name = Daniel-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  MagicTune
 
 
< End of report >

OTL.txt
Code:

OTL logfile created on: 17.01.2011 16:43:44 - Run 1
OTL by OldTimer - Version 3.2.20.2    Folder = C:\Users\Daniel\Downloads
 Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 48,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 74,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 49,90 Gb Total Space | 22,50 Gb Free Space | 45,09% Space Free | Partition Type: NTFS
Drive D: | 99,05 Gb Total Space | 61,56 Gb Free Space | 62,15% Space Free | Partition Type: NTFS
Drive E: | 931,40 Gb Total Space | 909,02 Gb Free Space | 97,60% Space Free | Partition Type: FAT32
Drive H: | 100,00 Mb Total Space | 70,20 Mb Free Space | 70,20% Space Free | Partition Type: NTFS
 
Computer Name: DANIEL-PC | User Name: Daniel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Daniel\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - D:\Programme\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - D:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.)
PRC - C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - D:\Programme\Password Depot 4\PasswordDepot.exe (AceBIT GmbH)
PRC - C:\Programme\Norton 360\Engine\4.3.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - D:\Programme\RocketDock\RocketDock.exe ()
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Daniel\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Akamai) -- c:\Programme\Common Files\Akamai\netsession_win_dbc0250.dll ()
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (LBTServ) -- C:\Programme\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Stereo Service) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (N360) -- C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (WwanSvc) -- C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) -- C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) -- C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) -- C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) -- C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) -- C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) -- C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) -- C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) -- C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (Dhcp) -- C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) -- C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) -- C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX-Installer (AxInstSV) -- C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) -- C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) -- C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (SBSDWSCService) -- C:\Programme\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (vmm) -- C:\Windows\System32\drivers\VMM.sys (Microsoft Corporation)
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110116.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110116.003\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Programme\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Programme\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSVix86) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110114.002\IDSvix86.sys (Symantec Corporation)
DRV - (BHDrvx86) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20101123.003\BHDrvx86.sys (Symantec Corporation)
DRV - (LMouFilt) -- C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (cpuz134) -- C:\Windows\System32\drivers\cpuz134_x32.sys (Windows (R) Win 7 DDK provider)
DRV - (SYMTDIv) -- C:\Windows\System32\Drivers\N360\0403000.005\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymIRON) -- C:\Windows\system32\drivers\N360\0403000.005\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) -- C:\Windows\system32\drivers\N360\0403000.005\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) -- C:\Windows\System32\Drivers\N360\0403000.005\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\Windows\system32\drivers\N360\0403000.005\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) -- C:\Windows\system32\drivers\N360\0403000.005\ccHPx86.sys (Symantec Corporation)
DRV - (acedrv11) -- C:\Windows\System32\drivers\acedrv11.sys (Protect Software GmbH)
DRV - (KSecPkg) -- C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (SymDS) -- C:\Windows\system32\drivers\N360\0403000.005\SYMDS.SYS (Symantec Corporation)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (cmdide) -- C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) -- C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) -- C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) -- C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) -- C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) -- C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) -- C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) -- C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) -- C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) -- C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) -- C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) -- C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) -- C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) -- C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) -- C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) -- C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) -- C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) -- C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) -- C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) -- C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) -- C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) -- C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) -- C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) -- C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) -- C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) -- C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) -- C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) -- C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) -- C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) -- C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) -- C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) -- C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) -- C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) -- C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) -- C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) -- C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) -- C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) -- C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) -- C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) -- C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) -- C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifibus) -- C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) -- C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) -- C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) -- C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) -- C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) -- C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) -- C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) -- C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) -- C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (AcpiPmi) -- C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) -- C:\Windows\System32\drivers\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) -- C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) -- C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) -- C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) -- C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) -- C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (MagicTune) -- C:\Windows\system32\drivers\MTiCtwl.sys (Samsung Electronics, Inc. )
DRV - (VPCNetS2) -- C:\Windows\System32\drivers\VMNetSrv.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D0 B8 83 3D BE 98 CB 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: foxyproxy@eric.h.jung:2.22.4
FF - prefs.js..extensions.enabledItems: StrataBuddy@ReduxTeam:0.6.2
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.0.12
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: Strata40Lite@SpewBoy.au:0.6.2
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010.12.12 13:54:13 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010.12.11 12:54:01 | 000,000,000 | ---D | M]
 
[2010.12.11 00:03:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Daniel\AppData\Roaming\mozilla\Extensions
[2011.01.16 18:34:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\5ovo6p8c.default\extensions
[2010.12.27 11:26:41 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\5ovo6p8c.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2010.12.11 00:07:13 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\5ovo6p8c.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010.12.27 11:26:40 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\5ovo6p8c.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.12.27 11:26:42 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\5ovo6p8c.default\extensions\foxyproxy@eric.h.jung
[2010.12.26 16:07:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\5ovo6p8c.default\extensions\Strata40@SpewBoy.au
[2010.12.26 16:07:18 | 000,000,000 | ---D | M] ("Strata40 Lite") -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\5ovo6p8c.default\extensions\Strata40Lite@SpewBoy.au
[2010.12.26 16:05:16 | 000,000,000 | ---D | M] (StrataBuddy) -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\5ovo6p8c.default\extensions\StrataBuddy@ReduxTeam
[2010.12.26 16:07:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\5ovo6p8c.default\extensions\Strata40Lite@SpewBoy.au\chrome\mozapps\extensions
[2010.12.11 12:54:01 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\COFFPLGN
[2010.12.12 13:54:13 | 000,000,000 | ---D | M] (Norton IPS) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPLGN
[2010.12.11 16:04:04 | 000,000,000 | ---D | M] (Java Console) -- D:\PROGRAMME\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
 
O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programme\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programme\Norton 360\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programme\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programme\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [MagicTuneEngine]  File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Update]  File not found
O4 - HKCU..\Run: [RocketDock] D:\Programme\RocketDock\RocketDock.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Users\Daniel\AppData\Local\Temp/Win_Update_newdsfsd/Windows_Updatedsfsd.exe) -  File not found
O20 - HKLM Winlogon: UserInit - (C:\Users\Daniel\AppData\Local\Temp\Windupdt_microsoft\winupdate_microsoft.exe) -  File not found
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Programme\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\System32\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009.12.30 22:35:26 | 000,000,088 | ---- | M] () - E:\Autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2010.11.25 21:38:10 | 000,000,000 | ---D | M] - E:\AutoBackup2 -- [ FAT32 ]
O33 - MountPoints2\{0909c1c1-1401-11e0-9605-4487fc575c0c}\Shell - "" = AutoRun
O33 - MountPoints2\{0909c1c1-1401-11e0-9605-4487fc575c0c}\Shell\AutoRun\command - "" = F:\AUTORUN.EXE
O33 - MountPoints2\{fb77fc0b-04ae-11e0-8f7d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{fb77fc0b-04ae-11e0-8f7d-806e6f6e6963}\Shell\AutoRun\command - "" = F:\setup.exe
O33 - MountPoints2\X\Shell - "" = AutoRun
O33 - MountPoints2\X\Shell\AutoRun\command - "" = X:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.01.17 14:30:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011.01.17 14:30:11 | 000,000,000 | ---D | C] -- C:\Programme\Spybot - Search & Destroy
[2011.01.17 14:30:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011.01.17 14:23:37 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\Malwarebytes
[2011.01.17 14:23:30 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.01.17 14:23:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.01.17 14:23:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.01.17 14:23:27 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.01.17 14:23:27 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.01.16 15:37:59 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{55E8946D-80B1-455D-A733-61F8E691B044}
[2011.01.15 21:14:29 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{805CFEEA-09F3-4F5F-8851-021600B3ABAC}
[2011.01.15 21:14:14 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\Windows Live Writer
[2011.01.15 21:14:14 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\Windows Live Writer
[2011.01.15 20:43:36 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\Leadertech
[2011.01.15 20:43:09 | 000,016,400 | ---- | C] (Logitech, Inc.) -- C:\Windows\System32\drivers\LNonPnP.sys
[2011.01.15 20:42:17 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\LogiShrd
[2011.01.15 20:42:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
[2011.01.15 20:42:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Logishrd
[2011.01.15 20:42:06 | 000,000,000 | ---D | C] -- C:\Programme\Logitech
[2011.01.15 20:41:00 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\LogiShrd
[2011.01.15 20:40:36 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\Logitech
[2011.01.15 20:40:36 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\Logishrd
[2011.01.15 16:35:59 | 000,000,000 | ---D | C] -- C:\Users\Daniel\Desktop\minecraft
[2011.01.14 22:13:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games
[2011.01.14 22:11:29 | 000,000,000 | ---D | C] -- C:\Programme\Electronic Arts
[2011.01.14 22:11:18 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Electronic Arts
[2011.01.14 22:11:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
[2011.01.13 20:48:13 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
[2011.01.13 20:00:14 | 000,000,000 | ---D | C] -- C:\Fraps
[2011.01.12 15:25:18 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbc32.dll
[2011.01.12 15:25:16 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll
[2011.01.12 15:25:16 | 001,170,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2011.01.12 15:25:16 | 001,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2011.01.12 15:25:16 | 000,801,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FntCache.dll
[2011.01.12 15:25:16 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2011.01.12 15:25:16 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2011.01.12 15:25:16 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2011.01.12 15:25:16 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2011.01.12 15:25:16 | 000,211,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2011.01.12 15:25:16 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2011.01.12 15:25:15 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2011.01.12 15:25:15 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
[2011.01.09 20:37:09 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\Diagnostics
[2011.01.06 20:01:57 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\Zattoo
[2011.01.06 20:01:52 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zattoo4
[2011.01.06 20:01:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zattoo4
[2011.01.06 20:01:51 | 000,000,000 | ---D | C] -- C:\Programme\Zattoo4
[2011.01.02 18:33:11 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2011.01.02 14:32:41 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{199DA840-424E-4890-A832-AF03690DFE17}
[2011.01.01 12:47:56 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{B034AFCB-95F0-4EAA-93BB-3EF57B24EDCE}
[2011.01.01 12:18:43 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{AA4E31FD-C175-40B8-B73B-35FB40EC470D}
[2010.12.31 23:18:35 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{D2AD38A3-C36A-41A6-A70E-03F136377506}
[2010.12.31 11:18:08 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{2FE9414D-7136-4A6E-9066-E1FC354C73CE}
[2010.12.31 00:23:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2010.12.30 13:12:40 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{20AE1908-0B43-449A-8231-399911053B25}
[2010.12.30 12:23:30 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2010.12.30 12:23:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Synetic
[2010.12.30 12:18:47 | 000,000,000 | ---D | C] -- C:\Programme\ProtectDisc Driver Installer
[2010.12.30 12:18:43 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\ProtectDISC
[2010.12.30 12:17:15 | 000,000,000 | ---D | C] -- C:\Windows\System32\xlive
[2010.12.30 12:17:15 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Games for Windows - LIVE
[2010.12.30 01:22:54 | 000,000,000 | ---D | C] -- C:\Programme\DAEMON Tools Lite
[2010.12.30 01:22:39 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\DAEMON Tools Lite
[2010.12.30 01:22:37 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2010.12.30 01:12:15 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{A9CFF0C5-2185-4AD0-85A3-E542B156EC01}
[2010.12.30 01:12:14 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{023D09EA-4EEB-4F89-9B5F-145A0235D115}
[2010.12.29 15:18:37 | 000,023,096 | ---- | C] (Samsung Electronics, Inc. ) -- C:\Windows\System32\drivers\MTiCtwl.sys
[2010.12.29 14:42:46 | 000,020,328 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\System32\drivers\cpuz134_x32.sys
[2010.12.29 14:42:46 | 000,000,000 | ---D | C] -- C:\Programme\CPUID
[2010.12.29 14:42:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2010.12.29 13:48:26 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2010.12.29 13:08:08 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{83E78A7F-678C-419C-86F6-F271115401A4}
[2010.12.29 00:24:53 | 000,000,000 | ---D | C] -- C:\Programme\MSXML 4.0
[2010.12.28 22:06:21 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{4EF3B195-5BEA-4421-8C86-819D57AFDA2B}
[2010.12.28 18:26:50 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\NVIDIA
[2010.12.28 18:26:48 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\2K Games
[2010.12.28 18:25:53 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll
[2010.12.28 18:25:53 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll
[2010.12.28 18:25:53 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll
[2010.12.28 18:25:53 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll
[2010.12.28 18:25:53 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll
[2010.12.28 18:25:53 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll
[2010.12.28 18:25:52 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll
[2010.12.28 18:25:52 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll
[2010.12.28 18:25:52 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll
[2010.12.28 18:25:52 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll
[2010.12.28 18:25:52 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll
[2010.12.28 18:25:51 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2010.12.28 18:25:51 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2010.12.28 18:25:51 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll
[2010.12.28 18:25:50 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2010.12.28 18:25:50 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2010.12.28 18:25:50 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2010.12.28 18:25:50 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2010.12.28 18:25:50 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2010.12.28 18:25:49 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_41.dll
[2010.12.28 18:25:49 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_4.dll
[2010.12.28 18:25:49 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_4.dll
[2010.12.28 18:25:49 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2010.12.28 18:25:49 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_6.dll
[2010.12.28 18:25:48 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll
[2010.12.28 18:25:48 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll
[2010.12.28 18:25:48 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2010.12.28 18:25:47 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2010.12.28 18:25:47 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2010.12.28 18:25:47 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2010.12.28 18:25:47 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2010.12.28 18:25:46 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2010.12.28 18:25:46 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2010.12.28 18:25:46 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2010.12.28 18:25:45 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2010.12.28 18:25:45 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2010.12.28 18:25:45 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2010.12.28 18:25:44 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll
[2010.12.28 18:25:44 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll
[2010.12.28 18:25:44 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_1.dll
[2010.12.28 18:25:44 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll
[2010.12.28 18:25:44 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_1.dll
[2010.12.28 18:25:44 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_0.dll
[2010.12.28 18:25:44 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_4.dll
[2010.12.28 18:25:43 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_37.dll
[2010.12.28 18:25:43 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_0.dll
[2010.12.28 18:25:43 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_37.dll
[2010.12.28 18:25:43 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_0.dll
[2010.12.28 18:25:43 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_3.dll
[2010.12.28 18:25:42 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_37.dll
[2010.12.28 18:25:42 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_36.dll
[2010.12.28 18:25:42 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_36.dll
[2010.12.28 18:25:42 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_36.dll
[2010.12.28 18:25:42 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_10.dll
[2010.12.28 18:25:41 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_35.dll
[2010.12.28 18:25:41 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_35.dll
[2010.12.28 18:25:41 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_9.dll
[2010.12.28 18:25:40 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_35.dll
[2010.12.28 18:25:40 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_34.dll
[2010.12.28 18:25:40 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_34.dll
[2010.12.28 18:25:40 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_8.dll
[2010.12.28 18:25:40 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_2.dll
[2010.12.28 18:25:39 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_34.dll
[2010.12.28 18:25:39 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_7.dll
[2010.12.28 18:25:39 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_3.dll
[2010.12.28 18:25:38 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_33.dll
[2010.12.28 18:25:38 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_33.dll
[2010.12.28 18:25:38 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_33.dll
[2010.12.28 18:25:38 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_6.dll
[2010.12.28 18:25:37 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll
[2010.12.28 18:25:37 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll
[2010.12.28 18:25:37 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll
[2010.12.28 18:25:36 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll
[2010.12.28 18:25:36 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll
[2010.12.28 18:25:36 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_1.dll
[2010.12.28 18:25:35 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll
[2010.12.28 18:25:35 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_2.dll
[2010.12.28 18:25:35 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll
[2010.12.28 18:25:34 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_1.dll
[2010.12.28 18:25:34 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_1.dll
[2010.12.28 18:25:27 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_30.dll
[2010.12.28 18:25:27 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_29.dll
[2010.12.28 18:25:27 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_0.dll
[2010.12.28 18:25:27 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_0.dll
[2010.12.28 18:25:26 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_25.dll
[2010.12.28 18:25:26 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll
[2010.12.28 18:25:26 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_27.dll
[2010.12.28 18:25:26 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_26.dll
[2010.12.28 18:25:25 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_24.dll
[2010.12.28 17:35:32 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Steam
[2010.12.28 17:35:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2010.12.28 14:47:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor (DX11)
[2010.12.28 14:47:25 | 000,000,000 | ---D | C] -- C:\Programme\MSI Kombustor (DX11)
[2010.12.28 14:41:11 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
[2010.12.28 14:03:03 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2010.12.28 14:02:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2010.12.28 14:02:38 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2010.12.28 13:43:43 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2010.12.28 13:43:41 | 000,000,000 | ---D | C] -- C:\Programme\NVIDIA Corporation
[2010.12.28 10:05:56 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{3C200DEE-2DB4-447B-B4F7-E814DB398D81}
[2010.12.28 00:55:37 | 000,229,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\VMM.sys
[2010.12.28 00:10:34 | 000,000,000 | ---D | C] -- C:\Users\Daniel\Documents\Meine empfangenen Dateien
[2010.12.27 22:56:33 | 000,000,000 | ---D | C] -- C:\Users\Daniel\Desktop\glp
[2010.12.27 18:15:36 | 000,000,000 | ---D | C] -- C:\Users\Daniel\Documents\MCEdit-schematics
[2010.12.27 18:15:30 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MCEdit
[2010.12.27 18:15:29 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\MCEdit
[2010.12.27 17:43:14 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\HP
[2010.12.27 17:43:06 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Hewlett-Packard
[2010.12.27 17:42:54 | 000,123,904 | ---- | C] (Hewlett-Packard Company) -- C:\Windows\System32\hpf3l70v.dll
[2010.12.27 17:42:16 | 000,000,000 | ---D | C] -- C:\Programme\HP
[2010.12.27 17:42:15 | 000,000,000 | -H-D | C] -- C:\Config.Msi
[2010.12.27 17:41:45 | 000,000,000 | ---D | C] -- C:\ProgramData\HP
[2010.12.27 17:41:42 | 000,712,704 | ---- | C] (Hewlett-Packard) -- C:\Windows\System32\hposwia_d02c.dll
[2010.12.27 17:41:42 | 000,589,824 | ---- | C] (Hewlett-Packard Co.) -- C:\Windows\System32\hpost_d02c.dll
[2010.12.27 17:41:42 | 000,452,408 | ---- | C] (Hewlett-Packard) -- C:\Windows\System32\hpzids01.dll
[2010.12.27 17:41:42 | 000,372,736 | ---- | C] (Hewlett-Packard) -- C:\Windows\System32\hppldcoi.dll
[2010.12.27 17:41:42 | 000,315,392 | ---- | C] (Hewlett-Packard Co.) -- C:\Windows\System32\hposc_d02a.dll
[2010.12.27 17:29:56 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\ElevatedDiagnostics
[2010.12.27 17:05:28 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{B75D4B22-08C3-4F00-97B6-F37AD93F0742}
[2010.12.27 17:05:15 | 000,000,000 | ---D | C] -- C:\Users\Daniel\Tracing
[2010.12.27 16:32:55 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010.12.27 16:25:29 | 000,000,000 | ---D | C] -- C:\Programme\Windows Live
[2010.12.27 16:22:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2010.12.27 16:22:13 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Silverlight
[2010.12.27 16:19:15 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2010.12.27 16:19:15 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2010.12.27 16:19:15 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
[2010.12.27 16:17:45 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\Windows Live
[2010.12.27 16:17:44 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Windows Live
[2010.12.27 11:29:24 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft.NET
[2010.12.27 00:20:29 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2010.12.27 00:20:29 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2010.12.27 00:20:29 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2010.12.27 00:16:29 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browserchoice.exe
[2010.12.27 00:16:05 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ks.sys
[2010.12.26 22:56:02 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Roaming\.minecraft
[2010.12.26 17:34:42 | 000,197,632 | ---- | C] (Intel(R) Corporation) -- C:\Windows\System32\ir32_32.dll
[2010.12.26 17:34:42 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
[2010.12.26 17:34:41 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2010.12.26 17:34:41 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll
[2010.12.26 17:34:40 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2010.12.26 17:34:40 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdri.dll
[2010.12.26 17:34:40 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2010.12.26 17:34:40 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2010.12.26 17:34:39 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010.12.26 17:34:32 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2010.12.26 17:34:32 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2010.12.26 17:34:32 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2010.12.26 17:34:32 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010.12.26 17:34:32 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2010.12.26 17:34:32 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2010.12.26 17:34:32 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2010.12.26 17:34:32 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2010.12.26 17:34:32 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2010.12.26 17:34:32 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2010.12.26 17:34:31 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2010.12.26 17:34:30 | 000,496,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskschd.dll
[2010.12.26 17:34:30 | 000,351,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmicmiplugin.dll
[2010.12.26 17:34:30 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskcomp.dll
[2010.12.26 17:34:30 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schtasks.exe
[2010.12.26 17:34:29 | 001,037,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lsasrv.dll
[2010.12.26 17:34:29 | 000,133,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ksecpkg.sys
[2010.12.26 17:34:28 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll
[2010.12.26 17:34:23 | 001,320,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnroll.dll
[2010.12.26 17:34:23 | 000,507,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.exe
[2010.12.26 17:34:23 | 000,442,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.exe
[2010.12.26 17:34:19 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\asycfilt.dll
[2010.12.26 17:34:17 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40.dll
[2010.12.26 17:34:17 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40u.dll
[2010.12.26 17:34:09 | 000,026,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys
[2010.12.26 17:34:08 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2010.12.26 17:34:07 | 000,294,400 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2010.12.26 17:34:06 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll
[2010.12.26 17:34:06 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2010.12.26 17:34:06 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2010.12.26 17:34:05 | 003,955,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010.12.26 17:34:05 | 003,899,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2010.12.26 17:34:01 | 000,738,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpmde.dll
[2010.12.26 17:34:00 | 000,427,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2010.12.26 17:34:00 | 000,101,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
[2010.12.26 17:31:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Hewlett-Packard
[2010.12.26 17:30:38 | 002,327,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2010.12.26 16:16:51 | 000,000,000 | ---D | C] -- C:\Programme\Safari
[2010.12.26 16:15:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2010.12.26 16:15:19 | 000,000,000 | ---D | C] -- C:\Programme\iPod
[2010.12.26 16:11:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
 
========== Files - Modified Within 30 Days ==========
 
[2011.01.17 15:07:53 | 000,054,016 | ---- | M] () -- C:\Windows\System32\drivers\tetpv.sys
[2011.01.17 14:30:18 | 000,001,242 | ---- | M] () -- C:\Users\Daniel\Desktop\Spybot - Search & Destroy.lnk
[2011.01.17 14:23:31 | 000,001,093 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.01.17 13:58:12 | 000,014,608 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.01.17 13:58:12 | 000,014,608 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.01.17 13:50:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.01.17 13:50:35 | 2616,745,984 | -HS- | M] () -- C:\hiberfil.sys
[2011.01.15 20:43:09 | 000,016,400 | ---- | M] (Logitech, Inc.) -- C:\Windows\System32\drivers\LNonPnP.sys
[2011.01.14 22:33:57 | 000,001,289 | ---- | M] () -- C:\Users\Daniel\Desktop\Temp.lnk
[2011.01.14 22:33:18 | 000,002,163 | ---- | M] () -- C:\Users\Daniel\Desktop\Temporary Internet Files.lnk
[2011.01.13 20:48:14 | 000,000,584 | ---- | M] () -- C:\Users\Daniel\Desktop\Fraps.lnk
[2011.01.11 22:22:41 | 000,017,408 | ---- | M] () -- C:\Users\Daniel\AppData\Local\WebpageIcons.db
[2011.01.11 20:22:37 | 000,000,526 | ---- | M] () -- C:\Windows\eReg.dat
[2011.01.06 21:00:25 | 000,004,608 | ---- | M] () -- C:\Users\Daniel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.01.06 20:01:52 | 000,001,840 | ---- | M] () -- C:\Users\Daniel\Desktop\Zattoo.lnk
[2011.01.04 17:56:19 | 000,001,320 | ---- | M] () -- C:\Users\Daniel\Documents\mcedit.ini
[2011.01.01 12:51:17 | 000,655,604 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.01.01 12:51:17 | 000,616,484 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.01.01 12:51:17 | 000,130,516 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.01.01 12:51:17 | 000,106,864 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.12.30 12:20:29 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\000017B4.LCS
[2010.12.30 01:23:20 | 000,001,922 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2010.12.30 01:23:19 | 000,691,696 | ---- | M] () -- C:\Windows\System32\drivers\sptd.sys
[2010.12.29 14:42:46 | 000,001,048 | ---- | M] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2010.12.29 13:48:21 | 356,719,174 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010.12.28 17:40:38 | 000,000,649 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2010.12.28 16:32:26 | 000,001,658 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2010.12.28 14:41:12 | 000,000,708 | ---- | M] () -- C:\Users\Daniel\Desktop\MSI Afterburner.lnk
[2010.12.28 00:55:37 | 000,229,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\VMM.sys
[2010.12.27 18:15:31 | 000,002,073 | ---- | M] () -- C:\Users\Daniel\Desktop\MCEdit.lnk
[2010.12.27 17:48:14 | 000,146,688 | ---- | M] () -- C:\Windows\hpoins44.dat
[2010.12.27 11:24:45 | 003,640,832 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.12.26 22:55:53 | 000,232,501 | ---- | M] () -- C:\Users\Daniel\Desktop\Minecraft.exe
[2010.12.26 16:16:54 | 000,002,479 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2010.12.26 16:15:35 | 000,001,543 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010.12.26 16:11:40 | 000,001,837 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010.12.20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.12.20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
 
========== Files Created - No Company Name ==========
 
[2011.01.17 15:07:53 | 000,054,016 | ---- | C] () -- C:\Windows\System32\drivers\tetpv.sys
[2011.01.17 14:30:18 | 000,001,242 | ---- | C] () -- C:\Users\Daniel\Desktop\Spybot - Search & Destroy.lnk
[2011.01.17 14:23:31 | 000,001,093 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.01.14 22:31:21 | 000,002,163 | ---- | C] () -- C:\Users\Daniel\Desktop\Temporary Internet Files.lnk
[2011.01.13 20:48:13 | 000,000,584 | ---- | C] () -- C:\Users\Daniel\Desktop\Fraps.lnk
[2011.01.11 20:22:37 | 000,000,526 | ---- | C] () -- C:\Windows\eReg.dat
[2011.01.06 21:00:24 | 000,004,608 | ---- | C] () -- C:\Users\Daniel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.01.06 20:01:57 | 000,017,408 | ---- | C] () -- C:\Users\Daniel\AppData\Local\WebpageIcons.db
[2011.01.06 20:01:52 | 000,001,840 | ---- | C] () -- C:\Users\Daniel\Desktop\Zattoo.lnk
[2010.12.30 12:18:46 | 000,004,096 | ---- | C] () -- C:\Users\Public\Documents\000017B4.LCS
[2010.12.30 01:23:19 | 000,691,696 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2010.12.30 01:23:19 | 000,001,922 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2010.12.29 14:42:46 | 000,001,048 | ---- | C] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2010.12.29 13:48:21 | 356,719,174 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010.12.28 17:35:31 | 000,000,649 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2010.12.28 16:32:25 | 000,001,658 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2010.12.28 14:41:11 | 000,000,708 | ---- | C] () -- C:\Users\Daniel\Desktop\MSI Afterburner.lnk
[2010.12.27 18:15:37 | 000,001,320 | ---- | C] () -- C:\Users\Daniel\Documents\mcedit.ini
[2010.12.27 18:15:31 | 000,002,073 | ---- | C] () -- C:\Users\Daniel\Desktop\MCEdit.lnk
[2010.12.27 17:41:46 | 000,000,357 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2010.12.27 17:41:45 | 000,146,688 | ---- | C] () -- C:\Windows\hpoins44.dat
[2010.12.27 17:41:45 | 000,000,512 | ---- | C] () -- C:\Windows\hpomdl44.dat
[2010.12.26 22:55:52 | 000,232,501 | ---- | C] () -- C:\Users\Daniel\Desktop\Minecraft.exe
[2010.12.26 16:16:53 | 000,002,479 | ---- | C] () -- C:\Users\Public\Desktop\Safari.lnk
[2010.12.26 16:15:35 | 000,001,543 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010.12.26 16:11:40 | 000,001,837 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010.10.14 01:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll

< End of report >


cosinus 17.01.2011 19:10

Gibt es noch weitere Logs von Malwarebytes? Wenn ja bitte alle davon posten. Du findest diese im Reiter Logdateien in Malwarebytes.

daniel508 17.01.2011 19:15

Nein, gibt es nicht.

cosinus 17.01.2011 19:26

Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
O4 - HKLM..\Run: [MagicTuneEngine]  File not found
O4 - HKLM..\Run: [Update]  File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009.12.30 22:35:26 | 000,000,088 | ---- | M] () - E:\Autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2010.11.25 21:38:10 | 000,000,000 | ---D | M] - E:\AutoBackup2 -- [ FAT32 ]
O33 - MountPoints2\{0909c1c1-1401-11e0-9605-4487fc575c0c}\Shell - "" = AutoRun
O33 - MountPoints2\{0909c1c1-1401-11e0-9605-4487fc575c0c}\Shell\AutoRun\command - "" = F:\AUTORUN.EXE
O33 - MountPoints2\{fb77fc0b-04ae-11e0-8f7d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{fb77fc0b-04ae-11e0-8f7d-806e6f6e6963}\Shell\AutoRun\command - "" = F:\setup.exe
O33 - MountPoints2\X\Shell - "" = AutoRun
O33 - MountPoints2\X\Shell\AutoRun\command - "" = X:\setup.exe
[2011.01.16 15:37:59 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{55E8946D-80B1-455D-A733-61F8E691B044}
[2011.01.15 21:14:29 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{805CFEEA-09F3-4F5F-8851-021600B3ABAC}
[2011.01.02 14:32:41 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{199DA840-424E-4890-A832-AF03690DFE17}
[2011.01.01 12:47:56 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{B034AFCB-95F0-4EAA-93BB-3EF57B24EDCE}
[2011.01.01 12:18:43 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{AA4E31FD-C175-40B8-B73B-35FB40EC470D}
[2010.12.31 23:18:35 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{D2AD38A3-C36A-41A6-A70E-03F136377506}
[2010.12.31 11:18:08 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{2FE9414D-7136-4A6E-9066-E1FC354C73CE}
[2010.12.30 01:12:15 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{A9CFF0C5-2185-4AD0-85A3-E542B156EC01}
[2010.12.30 01:12:14 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\{023D09EA-4EEB-4F89-9B5F-145A0235D115}
[2011.01.17 15:07:53 | 000,054,016 | ---- | M] () -- C:\Windows\System32\drivers\tetpv.sys
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

daniel508 17.01.2011 23:38

Okay - gebe dir morgen das Logfile.

Danke und lieben Gruß

daniel508 18.01.2011 14:52

Hier:

Code:

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MagicTuneEngine deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Update deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
E:\Autorun.inf moved successfully.
File  not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0909c1c1-1401-11e0-9605-4487fc575c0c}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0909c1c1-1401-11e0-9605-4487fc575c0c}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0909c1c1-1401-11e0-9605-4487fc575c0c}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0909c1c1-1401-11e0-9605-4487fc575c0c}\ not found.
File F:\AUTORUN.EXE not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fb77fc0b-04ae-11e0-8f7d-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fb77fc0b-04ae-11e0-8f7d-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fb77fc0b-04ae-11e0-8f7d-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fb77fc0b-04ae-11e0-8f7d-806e6f6e6963}\ not found.
File F:\setup.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X\ not found.
File X:\setup.exe not found.
C:\Users\Daniel\AppData\Local\{55E8946D-80B1-455D-A733-61F8E691B044} folder moved successfully.
C:\Users\Daniel\AppData\Local\{805CFEEA-09F3-4F5F-8851-021600B3ABAC} folder moved successfully.
C:\Users\Daniel\AppData\Local\{199DA840-424E-4890-A832-AF03690DFE17} folder moved successfully.
C:\Users\Daniel\AppData\Local\{B034AFCB-95F0-4EAA-93BB-3EF57B24EDCE} folder moved successfully.
C:\Users\Daniel\AppData\Local\{AA4E31FD-C175-40B8-B73B-35FB40EC470D} folder moved successfully.
C:\Users\Daniel\AppData\Local\{D2AD38A3-C36A-41A6-A70E-03F136377506} folder moved successfully.
C:\Users\Daniel\AppData\Local\{2FE9414D-7136-4A6E-9066-E1FC354C73CE} folder moved successfully.
C:\Users\Daniel\AppData\Local\{A9CFF0C5-2185-4AD0-85A3-E542B156EC01} folder moved successfully.
C:\Users\Daniel\AppData\Local\{023D09EA-4EEB-4F89-9B5F-145A0235D115} folder moved successfully.
File C:\Windows\System32\drivers\tetpv.sys not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
[EMPTYTEMP]
 
User: All Users
 
User: Daniel
->Temp folder emptied: 6205 bytes
->Temporary Internet Files folder emptied: 295783 bytes
->Java cache emptied: 131108 bytes
->FireFox cache emptied: 47471001 bytes
->Google Chrome cache emptied: 256824179 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 7660 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41620 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1572032 bytes
RecycleBin emptied: 5308247392 bytes
 
Total Files Cleaned = 5.355,00 mb
 
 
OTL by OldTimer - Version 3.2.20.2 log created on 01182011_144757

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...


cosinus 18.01.2011 14:56

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

daniel508 18.01.2011 15:16

Bin beim CCleaner auf ein Problem gestossen:
Und zwar kommen bei der Registry Reinigung 2 Fehler immer wieder:
myimg.de/?img=trojanerboard2f7aa.png
(Rot markiert im Bild)

Also ich klick auf Fehler beheben: Sie sind weg.
Dann nach der Anleitung auf "Fehler suchen" und sie erscheinen wieder..

cosinus 18.01.2011 15:19

Ignorier das und mach mit CF weiter.

daniel508 18.01.2011 15:26

Wie kann ich Norton 360 vollständig deaktivieren?

cosinus 18.01.2011 16:05

Musst im Handbuch nachsehen. Ich kann unmöglich wissen, wie alle 2965 Virenscanner, die es so auf der Welt gibt, im Detail funktionieren / zu bedienen sind. Etwas Eigeninitiative schadet nie!

daniel508 18.01.2011 16:10

Habe das Handbuch verlegt ~_~

Dann muss ich wohl Norton deinstallieren - der Key geht eh nur noch wenige Tage und ich habe sowieso bald vor mir GData zu kaufen, da Norton für mich Müll ist.

cosinus 18.01.2011 16:15

Zitat:

habe sowieso bald vor mir GData zu kaufen, da Norton für mich Müll ist.
Geld ausgeben muss man für sowas nicht. Kostenlose Virenscanner sind genauso gut. Besseren Schutz bieten Bezahlversionen auch nicht wirklich. Auf das richtige Verhalten kommt es an.

daniel508 18.01.2011 16:32

Code:

ComboFix 11-01-17.05 - Daniel 18.01.2011  16:26:53.1.2 - x86
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.49.1031.18.3327.2578 [GMT 1:00]
ausgeführt von:: c:\users\Daniel\Desktop\cofi.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.

(((((((((((((((((((((((  Dateien erstellt von 2010-12-18 bis 2011-01-18  ))))))))))))))))))))))))))))))
.

2011-01-18 15:30 . 2011-01-18 15:30        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-01-18 14:07 . 2011-01-18 14:07        --------        d-----w-        c:\program files\CCleaner
2011-01-18 13:47 . 2011-01-18 13:47        --------        d-----w-        C:\_OTL
2011-01-17 13:30 . 2011-01-18 14:09        --------        d-----w-        c:\programdata\Spybot - Search & Destroy
2011-01-17 13:30 . 2011-01-17 13:30        --------        d-----w-        c:\program files\Spybot - Search & Destroy
2011-01-17 13:23 . 2011-01-17 13:23        --------        d-----w-        c:\users\Daniel\AppData\Roaming\Malwarebytes
2011-01-17 13:23 . 2011-01-17 13:23        --------        d-----w-        c:\programdata\Malwarebytes
2011-01-17 13:23 . 2010-12-20 17:09        38224        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-17 13:23 . 2011-01-17 13:23        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2011-01-17 13:23 . 2010-12-20 17:08        20952        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-01-15 20:14 . 2011-01-15 21:56        --------        d-----w-        c:\users\Daniel\AppData\Roaming\Windows Live Writer
2011-01-15 20:14 . 2011-01-15 20:14        --------        d-----w-        c:\users\Daniel\AppData\Local\Windows Live Writer
2011-01-15 19:43 . 2011-01-15 19:43        --------        d-----w-        c:\users\Daniel\AppData\Roaming\Leadertech
2011-01-15 19:43 . 2011-01-15 19:43        53248        ----a-r-        c:\users\Daniel\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-01-15 19:43 . 2011-01-15 19:43        16400        ----a-w-        c:\windows\system32\drivers\LNonPnP.sys
2011-01-15 19:42 . 2011-01-15 19:43        --------        d-----w-        c:\programdata\Logishrd
2011-01-15 19:42 . 2011-01-15 19:42        --------        d-----w-        c:\program files\Logitech
2011-01-15 19:41 . 2011-01-15 19:43        --------        d-----w-        c:\program files\Common Files\LogiShrd
2011-01-15 19:40 . 2011-01-15 19:46        --------        d-----w-        c:\users\Daniel\AppData\Roaming\Logitech
2011-01-15 19:40 . 2011-01-15 19:41        --------        d-----w-        c:\users\Daniel\AppData\Roaming\Logishrd
2011-01-14 21:11 . 2011-01-14 21:11        --------        d-----w-        c:\program files\Electronic Arts
2011-01-14 21:10 . 2001-09-05 04:18        225280        ------w-        c:\program files\Common Files\InstallShield\IScript\IScript.dll
2011-01-14 21:10 . 2001-09-05 04:14        176128        ------w-        c:\program files\Common Files\InstallShield\engine\6\Intel 32\iuser.dll
2011-01-14 21:10 . 2001-09-05 04:13        32768        ------w-        c:\program files\Common Files\InstallShield\engine\6\Intel 32\objectps.dll
2011-01-14 21:10 . 2001-09-05 04:18        77824        ----a-w-        c:\program files\Common Files\InstallShield\engine\6\Intel 32\ctor.dll
2011-01-13 19:00 . 2011-01-16 13:58        --------        d-----w-        C:\Fraps
2011-01-11 19:20 . 2000-01-04 05:39        212992        ----a-w-        c:\program files\Common Files\InstallShield\engine\6\Intel 32\ILog.dll
2011-01-09 19:37 . 2011-01-09 19:37        --------        d-----w-        c:\users\Daniel\AppData\Local\Diagnostics
2011-01-06 19:01 . 2011-01-06 19:01        --------        d-----w-        c:\users\Daniel\AppData\Local\Zattoo
2011-01-06 19:01 . 2011-01-06 19:01        --------        d-----w-        c:\program files\Zattoo4
2010-12-30 12:12 . 2010-12-30 12:12        --------        d-----w-        c:\users\Daniel\AppData\Local\{20AE1908-0B43-449A-8231-399911053B25}
2010-12-30 11:23 . 2010-12-30 11:23        --------        d-----w-        c:\programdata\Synetic
2010-12-30 11:18 . 2010-12-30 11:18        --------        d-----w-        c:\program files\ProtectDisc Driver Installer
2010-12-30 11:18 . 2010-12-30 11:18        --------        d-----w-        c:\users\Daniel\AppData\Roaming\ProtectDISC
2010-12-30 11:17 . 2010-12-30 23:23        --------        d-----w-        c:\program files\Microsoft Games for Windows - LIVE
2010-12-30 11:17 . 2010-12-30 11:17        --------        d-----w-        c:\windows\system32\xlive
2010-12-30 00:23 . 2010-12-30 00:23        691696        ----a-w-        c:\windows\system32\drivers\sptd.sys
2010-12-30 00:22 . 2010-12-30 00:23        --------        d-----w-        c:\program files\DAEMON Tools Lite
2010-12-30 00:22 . 2010-12-30 11:09        --------        d-----w-        c:\users\Daniel\AppData\Roaming\DAEMON Tools Lite
2010-12-30 00:22 . 2010-12-30 00:22        --------        d-----w-        c:\programdata\DAEMON Tools Lite
2010-12-29 14:18 . 2008-11-04 12:12        23096        ----a-w-        c:\windows\system32\drivers\MTiCtwl.sys
2010-12-29 13:42 . 2010-12-29 13:42        --------        d-----w-        c:\program files\CPUID
2010-12-29 13:42 . 2010-07-09 12:18        20328        ----a-w-        c:\windows\system32\drivers\cpuz134_x32.sys
2010-12-29 12:08 . 2010-12-29 12:11        --------        d-----w-        c:\users\Daniel\AppData\Local\{83E78A7F-678C-419C-86F6-F271115401A4}
2010-12-28 23:24 . 2010-12-28 23:24        --------        d-----w-        c:\program files\MSXML 4.0
2010-12-28 21:06 . 2010-12-28 21:06        --------        d-----w-        c:\users\Daniel\AppData\Local\{4EF3B195-5BEA-4421-8C86-819D57AFDA2B}
2010-12-28 17:26 . 2010-12-28 17:26        --------        d-----w-        c:\users\Daniel\AppData\Roaming\NVIDIA
2010-12-28 17:26 . 2010-12-28 17:26        --------        d-----w-        c:\users\Daniel\AppData\Local\2K Games
2010-12-28 16:35 . 2010-12-29 12:08        --------        d-----w-        c:\program files\Common Files\Steam
2010-12-28 13:47 . 2010-12-28 13:47        --------        d-----w-        c:\program files\MSI Kombustor (DX11)
2010-12-28 13:03 . 2010-12-28 13:03        --------        d-----w-        C:\NVIDIA
2010-12-28 13:02 . 2011-01-18 15:22        --------        d-----w-        c:\programdata\NVIDIA
2010-12-28 12:43 . 2010-12-28 12:43        --------        d-----w-        c:\programdata\NVIDIA Corporation
2010-12-28 12:43 . 2010-12-28 17:26        --------        d-----w-        c:\program files\NVIDIA Corporation
2010-12-28 09:05 . 2010-12-28 09:06        --------        d-----w-        c:\users\Daniel\AppData\Local\{3C200DEE-2DB4-447B-B4F7-E814DB398D81}
2010-12-27 23:55 . 2010-12-27 23:55        229224        ----a-w-        c:\windows\system32\drivers\VMM.sys
2010-12-27 17:15 . 2010-12-27 17:15        --------        d-----w-        c:\users\Daniel\AppData\Local\MCEdit
2010-12-27 16:44 . 2009-04-16 13:08        312832        ----a-w-        c:\windows\system32\Spool\prtprocs\w32x86\hpfpp70v.dll
2010-12-27 16:43 . 2010-12-27 16:43        --------        d-----w-        c:\program files\Common Files\HP
2010-12-27 16:43 . 2010-12-27 16:43        --------        d-----w-        c:\program files\Common Files\Hewlett-Packard
2010-12-27 16:42 . 2009-04-16 13:08        123904        ----a-w-        c:\windows\system32\hpf3l70v.dll
2010-12-27 16:42 . 2010-12-27 16:43        --------        d-----w-        c:\program files\HP
2010-12-27 16:41 . 2010-12-27 16:41        --------        d-----w-        c:\programdata\HP
2010-12-27 16:41 . 2009-04-16 11:53        452408        ----a-w-        c:\windows\system32\hpzids01.dll
2010-12-27 16:41 . 2009-02-11 11:03        712704        ----a-w-        c:\windows\system32\hposwia_d02c.dll
2010-12-27 16:41 . 2009-02-11 11:03        589824        ----a-w-        c:\windows\system32\hpost_d02c.dll
2010-12-27 16:41 . 2009-02-11 11:03        315392        ----a-w-        c:\windows\system32\hposc_d02a.dll
2010-12-27 16:41 . 2008-10-29 00:27        372736        ----a-w-        c:\windows\system32\hppldcoi.dll
2010-12-27 16:29 . 2010-12-27 16:29        --------        d-----w-        c:\users\Daniel\AppData\Local\ElevatedDiagnostics
2010-12-27 16:05 . 2010-12-27 16:05        --------        d-----w-        c:\users\Daniel\AppData\Local\{B75D4B22-08C3-4F00-97B6-F37AD93F0742}
2010-12-27 16:05 . 2011-01-18 14:09        --------        d-----w-        c:\users\Daniel\Tracing
2010-12-27 15:32 . 2010-12-27 15:32        --------        d-----w-        c:\windows\PCHEALTH
2010-12-27 15:25 . 2011-01-15 20:10        --------        d-----w-        c:\program files\Windows Live
2010-12-27 15:22 . 2010-12-29 17:41        --------        d-----w-        c:\program files\Microsoft Silverlight
2010-12-27 15:19 . 2010-05-23 10:15        1619456        ----a-w-        c:\windows\system32\WMVDECOD.DLL
2010-12-27 15:19 . 2010-05-23 10:11        196608        ----a-w-        c:\windows\system32\mfreadwrite.dll
2010-12-27 15:19 . 2010-05-23 10:11        3181568        ----a-w-        c:\windows\system32\mf.dll
2010-12-27 15:17 . 2011-01-15 20:13        --------        d-----w-        c:\users\Daniel\AppData\Local\Windows Live
2010-12-27 15:17 . 2010-12-27 15:17        --------        d-----w-        c:\program files\Common Files\Windows Live
2010-12-27 10:29 . 2010-12-27 10:29        --------        d-----w-        c:\program files\Microsoft.NET
2010-12-26 23:21 . 2009-09-10 05:52        257024        ----a-w-        c:\windows\system32\msv1_0.dll
2010-12-26 23:20 . 2009-11-25 11:47        99176        ----a-w-        c:\windows\system32\PresentationHostProxy.dll
2010-12-26 23:20 . 2009-11-25 11:47        49472        ----a-w-        c:\windows\system32\netfxperf.dll
2010-12-26 23:20 . 2009-11-25 11:47        297808        ----a-w-        c:\windows\system32\mscoree.dll
2010-12-26 23:20 . 2009-11-25 11:47        295264        ----a-w-        c:\windows\system32\PresentationHost.exe
2010-12-26 23:20 . 2009-11-25 11:47        1130824        ----a-w-        c:\windows\system32\dfshim.dll
2010-12-26 23:16 . 2010-02-11 07:10        293376        ----a-w-        c:\windows\system32\browserchoice.exe
2010-12-26 23:16 . 2010-03-04 03:57        190976        ----a-w-        c:\windows\system32\drivers\ks.sys
2010-12-26 21:56 . 2010-12-26 21:57        --------        d-----w-        c:\users\Daniel\AppData\Roaming\.minecraft
2010-12-26 16:33 . 2010-04-07 07:10        571904        ----a-w-        c:\windows\system32\oleaut32.dll
2010-12-26 16:31 . 2010-12-26 16:31        --------        d-----w-        c:\programdata\Hewlett-Packard
2010-12-26 16:31 . 2009-07-14 01:15        280064        ----a-w-        c:\windows\system32\Spool\prtprocs\w32x86\hpzppw71.dll
2010-12-26 16:30 . 2010-10-20 03:00        2327552        ----a-w-        c:\windows\system32\win32k.sys
2010-12-26 15:16 . 2010-12-26 15:16        --------        d-----w-        c:\program files\Safari
2010-12-26 15:15 . 2010-12-26 15:15        --------        d-----w-        c:\program files\iPod
2010-12-26 15:11 . 2010-12-26 15:11        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2010-12-26 15:11 . 2010-12-26 15:11        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2010-12-26 15:11 . 2010-12-26 15:11        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2010-12-26 15:11 . 2010-12-26 15:11        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2010-12-26 15:11 . 2010-12-26 15:11        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2010-12-26 15:11 . 2010-12-26 15:11        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2010-12-26 15:11 . 2010-12-26 15:11        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin.dll

.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-14 17:49 . 2010-12-14 17:49        411368        ----a-w-        c:\windows\system32\deployJava1.dll
2010-12-12 17:57 . 2010-12-12 17:57        164880        ---ha-w-        c:\users\Daniel\AppData\Roaming\Microsoft\Virtual PC\VPCKeyboard.dll
2010-11-29 16:38 . 2010-11-29 16:38        94208        ----a-w-        c:\windows\system32\QuickTimeVR.qtx
2010-11-29 16:38 . 2010-11-29 16:38        69632        ----a-w-        c:\windows\system32\QuickTime.qts
2010-11-16 11:01 . 2010-12-10 23:11        6273872        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{A3830CA3-D68E-45F3-B785-3C0453B19E79}\mpengine.dll
2010-11-10 01:54 . 2010-11-10 01:54        49016        ----a-w-        c:\windows\system32\sirenacm.dll
.

((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="d:\programme\RocketDock\RocketDock.exe" [2007-09-02 495616]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-10-28 10:13        64592        ----a-w-        c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-30 691696]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 185472]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-07-09 20328]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai        REG_MULTI_SZ          Akamai
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Settings,ProxyOverride = *.local
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------

[HKEY_USERS\S-1-5-21-1825434329-3494875349-1569995196-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"

[HKEY_USERS\S-1-5-21-1825434329-3494875349-1569995196-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2011-01-18  16:31:14
ComboFix-quarantined-files.txt  2011-01-18 15:31

Vor Suchlauf: 10 Verzeichnis(se), 27.060.678.656 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 26.837.024.768 Bytes frei

- - End Of File - - 8DBE9AABA67EA2303F4CCD9133D07042


cosinus 18.01.2011 19:15

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.


Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur einige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

daniel508 18.01.2011 19:40

GMER:
Code:

GMER 1.0.15.15530 - hxxp://www.gmer.net
Rootkit scan 2011-01-18 19:38:47
Windows 6.1.7600  Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD1600AAJB-00J3A0 rev.01.03E01
Running: tooisb8h.exe; Driver: C:\Users\Daniel\AppData\Local\Temp\uxrirpod.sys


---- Kernel code sections - GMER 1.0.15 ----

.text          ntkrnlpa.exe!ZwSaveKeyEx + 13AD                                                                                    82C57599 1 Byte  [06]
.text          ntkrnlpa.exe!KiDispatchInterrupt + 5A2                                                                              82C7BF52 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
?              System32\Drivers\spnu.sys                                                                                          Das System kann den angegebenen Pfad nicht finden. !
.text          USBPORT.SYS!DllUnload                                                                                              9105ACA0 5 Bytes  JMP 86A4C1D8
.text          arf1h6gp.SYS                                                                                                        92DAF000 12 Bytes  [44, 98, 02, 83, EE, 96, 02, ...]
.text          arf1h6gp.SYS                                                                                                        92DAF00D 9 Bytes  [77, 02, 83, 48, 9B, 02, 83, ...] {JA 0x4; OR DWORD [EAX-0x65], 0x2; ADD DWORD [EAX], 0x0}
.text          arf1h6gp.SYS                                                                                                        92DAF017 20 Bytes  [00, DE, C7, B1, 8B, E6, C5, ...]
.text          arf1h6gp.SYS                                                                                                        92DAF02C 149 Bytes  [00, 00, 00, 00, D0, 21, C5, ...]
.text          arf1h6gp.SYS                                                                                                        92DAF0C3 8 Bytes  [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
.text          ...                                                                                                               
.vmp2          C:\Windows\system32\drivers\acedrv11.sys                                                                            entry point in ".vmp2" section [0x9A15769D]
?              C:\Users\Daniel\AppData\Local\Temp\catchme.sys                                                                      Das System kann die angegebene Datei nicht finden. !
?              C:\Windows\system32\Drivers\PROCEXP113.SYS                                                                          Das System kann die angegebene Datei nicht finden. !

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT            \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortUchar]                                            [8BA20042] \SystemRoot\System32\Drivers\spnu.sys
IAT            \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortUchar]                                          [8BA206D6] \SystemRoot\System32\Drivers\spnu.sys
IAT            \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort]                                    [8BA20800] \SystemRoot\System32\Drivers\spnu.sys
IAT            \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort]                                    [8BA2013E] \SystemRoot\System32\Drivers\spnu.sys
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortNotification]                                          00147880
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortQuerySystemTime]                                      78800C75
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortReadPortUchar]                                        06750015
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortStallExecution]                                        C25DC033
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortWritePortUchar]                                        458B0008
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortWritePortUlong]                                        6A006A08
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortGetPhysicalAddress]                                    50056A24
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong]                        005AB7E8
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortGetScatterGatherList]                                  0001B800
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortGetParentBusType]                                      C25D0000
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortRequestCallback]                                      CCCC0008
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortWritePortBufferUshort]                                CCCCCCCC
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortGetUnCachedExtension]                                  CCCCCCCC
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortCompleteRequest]                                      CCCCCCCC
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortCopyMemory]                                            53EC8B55
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortEtwTraceLog]                                          800C5D8B
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests]                            7500117B
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb]                                127B806A
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb]                                  80647500
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortReadPortBufferUshort]                                  7500137B
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortInitialize]                                            157B805E
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortGetDeviceBase]                                        56587500
IAT            \SystemRoot\System32\Drivers\arf1h6gp.SYS[ataport.SYS!AtaPortDeviceStateChange]                                    8008758B

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipAlloc]                                      [747B2494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdiplusStartup]                                [74795624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdiplusShutdown]                                [747956E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipFree]                                      [747B250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipDeleteGraphics]                            [747A8573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipDisposeImage]                              [747A4D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipGetImageWidth]                              [747A50CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipGetImageHeight]                            [747A51A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipCreateBitmapFromHBITMAP]                    [747A66D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipCreateFromHDC]                              [747A82CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipSetCompositingMode]                        [747A8819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipSetInterpolationMode]                      [747A907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipDrawImageRectI]                            [747AE21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.exe[868] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipCloneImage]                                [747A4C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                              857431F8
Device          \FileSystem\fastfat \FatCdrom                                                                                      874EB1F8
Device          \Driver\volmgr \Device\VolMgrControl                                                                                8573E1F8
Device          \Driver\usbohci \Device\USBPDO-0                                                                                    86A4D1F8
Device          \Driver\usbehci \Device\USBPDO-1                                                                                    86A4E1F8
Device          \Driver\ACPI_HAL \Device\00000046                                                                                  halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device          \Driver\NetBT \Device\NetBT_Tcpip_{EE50375E-14DC-4B33-B7C7-D9AF6379614E}                                            869E91F8
Device          \Driver\volmgr \Device\HarddiskVolume1                                                                              8573E1F8

AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                              fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device          \Driver\volmgr \Device\HarddiskVolume2                                                                              8573E1F8

AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                              fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device          \Driver\cdrom \Device\CdRom0                                                                                        869233C8
Device          \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0                                                                        857401F8
Device          \Driver\atapi \Device\Ide\IdePort0                                                                                  857401F8
Device          \Driver\atapi \Device\Ide\IdePort1                                                                                  857401F8
Device          \Driver\volmgr \Device\HarddiskVolume3                                                                              8573E1F8

AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                              fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device          \Driver\cdrom \Device\CdRom1                                                                                        869233C8
Device          \Driver\volmgr \Device\HarddiskVolume4                                                                              8573E1F8

AttachedDevice  \Driver\volmgr \Device\HarddiskVolume4                                                                              fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device          \Driver\NetBT \Device\NetBt_Wins_Export                                                                            869E91F8
Device          \Driver\USBSTOR \Device\00000078                                                                                    869511F8
Device          \Driver\USBSTOR \Device\00000079                                                                                    869511F8
Device          \Driver\nvstor \Device\RaidPort0                                                                                    857411F8
Device          \Driver\PCI_PNP6528 \Device\0000004f                                                                                spnu.sys
Device          \Driver\nvstor \Device\RaidPort1                                                                                    857411F8
Device          \Driver\nvstor \Device\0000005e                                                                                    857411F8
Device          \Driver\usbohci \Device\USBFDO-0                                                                                    86A4D1F8
Device          \Driver\usbehci \Device\USBFDO-1                                                                                    86A4E1F8
Device          \Driver\arf1h6gp \Device\Scsi\arf1h6gp1Port4Path0Target0Lun0                                                        86BD81F8
Device          \Driver\arf1h6gp \Device\Scsi\arf1h6gp1                                                                            86BD81F8
Device          \Driver\sptd \Device\2146174528                                                                                    spnu.sys
Device          \FileSystem\fastfat \Fat                                                                                            874EB1F8

AttachedDevice  \FileSystem\fastfat \Fat                                                                                            fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1                                                                  771343423
Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2                                                                  285507792
Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0                                                                  1
Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                   
Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                C:\Program Files\DAEMON Tools Lite\
Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                0x00 0x00 0x00 0x00 ...
Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                0
Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                              0x95 0x99 0xB8 0x74 ...
Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001                         
Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                        0x20 0x01 0x00 0x00 ...
Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                    0x05 0xBC 0x3B 0x5F ...
Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0                     
Reg            HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                0x12 0xAE 0xDC 0x0D ...
Reg            HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)               
Reg            HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                    C:\Program Files\DAEMON Tools Lite\
Reg            HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                    0x00 0x00 0x00 0x00 ...
Reg            HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                    0
Reg            HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                  0x95 0x99 0xB8 0x74 ...
Reg            HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                            0x20 0x01 0x00 0x00 ...
Reg            HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                        0x05 0xBC 0x3B 0x5F ...
Reg            HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) 
Reg            HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                    0x12 0xAE 0xDC 0x0D ...

---- EOF - GMER 1.0.15 ----


daniel508 18.01.2011 19:48

OSAM:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 19:46:39 on 18.01.2011

OS: Windows 7 Home Premium Edition (Build 7600), 32-bit
Default Browser: Unable to get information

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"acedrv11" (acedrv11) - "Protect Software GmbH" - C:\Windows\system32\drivers\acedrv11.sys
"amodgld4" (amodgld4) - "Microsoft Corporation" - C:\Windows\system32\drivers\amodgld4.sys  (Hidden registry entry, rootkit activity | File signed by Microsoft)
"atikmdag" (atikmdag) - "ATI Technologies Inc." - C:\Windows\System32\DRIVERS\atikmdag.sys
"catchme" (catchme) - ? - C:\Users\Daniel\AppData\Local\Temp\catchme.sys  (File not found)
"cpuz134" (cpuz134) - "Windows (R) Win 7 DDK provider" - C:\Windows\system32\drivers\cpuz134_x32.sys
"GMSIPCI" (GMSIPCI) - ? - X:\INSTALL\GMSIPCI.SYS  (File not found)
"MagicTune" (MagicTune) - "Samsung Electronics, Inc. " - C:\Windows\system32\drivers\MTiCtwl.sys
"sptd" (sptd) - "Duplex Secure Ltd." - C:\Windows\System32\Drivers\sptd.sys  (File is exclusively opened, access blocked)
"Virtual Machine Monitor" (vmm) - "Microsoft Corporation" - C:\Windows\system32\Drivers\vmm.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - D:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\Program Files\Windows Live\Messenger\msgrapp.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Messenger\msgrapp.dll
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - D:\Programme\iTunes\iTunesMiniPlayer.dll
{DC70C4A5-2044-4c59-B806-DEFB9AE0DF7C} "KbLogiExt Class" - "Logitech, Inc." - C:\Program Files\Logitech\SetPointP\kbcplext.dll
{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll
{FFB699E0-306A-11d3-8BD1-00104B6F7516} "NVIDIA CPL Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - D:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - D:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - D:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - D:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{8932AEFE-9DB6-4f43-AFB2-5682F55E773A} "VPCHostCopyHook" - "Microsoft Corporation" - C:\Program Files\Microsoft Virtual PC\VPCShExH.DLL
{0563DB41-F538-4B37-A92D-4659049B7766} "WLMD Message Handler" - ? -  (File not found | COM-object registry key not found)
Logitech Setpoint Extension "{B9B9F083-2B04-452A-8691-83694AC1037B}" - ? -  (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_20.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID Sign-in Helper" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[LSA Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )-----
"Security Packages" - "Microsoft Corp." - C:\Windows\system32\livessp.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"RocketDock" - ? - "D:\Programme\RocketDock\RocketDock.exe"  (File found, but it contains no detailed information)
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Akamai NetSession Interface" (Akamai) - ? - c:\program files\common files\akamai\netsession_win_dbc0250.dll  (File found, but it contains no detailed information)
"AMD External Events Utility" (AMD External Events Utility) - "AMD" - C:\Windows\system32\atiesrxx.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"Logitech Bluetooth Service" (LBTServ) - "Logitech, Inc." - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"NVIDIA Display Driver Service" (nvsvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
"NVIDIA Stereoscopic 3D Driver Service" (Stereo Service) - "NVIDIA Corporation" - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files\Common Files\Steam\SteamService.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

[Winlogon]
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )-----
"LBTWlgn" - "Logitech, Inc." - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
"WindowsLive Local NSP" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
"WindowsLive NSP" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


daniel508 18.01.2011 19:50

MBR Check:
Code:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:                       
Windows Version:                Windows 7 Home Premium Edition
Windows Information:                (build 7600), 32-bit
Base Board Manufacturer:        ECS
BIOS Manufacturer:                American Megatrends Inc.
System Manufacturer:                ECS
System Product Name:                GeForce6100PM-M2
Logical Drives Mask:                0x008000bd

Kernel Drivers (total 170):
  0x82C0A000 \SystemRoot\system32\ntkrnlpa.exe
  0x8301A000 \SystemRoot\system32\halmacpi.dll
  0x80BB7000 \SystemRoot\system32\kdcom.dll
  0x83226000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll
  0x83231000 \SystemRoot\system32\PSHED.dll
  0x83242000 \SystemRoot\system32\BOOTVID.dll
  0x8324A000 \SystemRoot\system32\CLFS.SYS
  0x8328C000 \SystemRoot\system32\CI.dll
  0x83337000 \SystemRoot\system32\drivers\Wdf01000.sys
  0x833A8000 \SystemRoot\system32\drivers\WDFLDR.SYS
  0x8BA0E000 \SystemRoot\System32\Drivers\spxf.sys
  0x8BB01000 \SystemRoot\System32\Drivers\WMILIB.SYS
  0x8BB0A000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
  0x8BB30000 \SystemRoot\system32\DRIVERS\ACPI.sys
  0x8BB78000 \SystemRoot\system32\DRIVERS\msisadrv.sys
  0x8BB80000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
  0x8BB8B000 \SystemRoot\system32\DRIVERS\pci.sys
  0x8BBB5000 \SystemRoot\System32\drivers\partmgr.sys
  0x8BBC6000 \SystemRoot\system32\DRIVERS\volmgr.sys
  0x8BC25000 \SystemRoot\System32\drivers\volmgrx.sys
  0x8BC70000 \SystemRoot\system32\DRIVERS\pciide.sys
  0x8BC77000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
  0x8BC85000 \SystemRoot\System32\drivers\mountmgr.sys
  0x8BC9B000 \SystemRoot\system32\DRIVERS\atapi.sys
  0x8BCA4000 \SystemRoot\system32\DRIVERS\ataport.SYS
  0x8BCC7000 \SystemRoot\system32\DRIVERS\nvstor.sys
  0x8BCEC000 \SystemRoot\system32\DRIVERS\storport.sys
  0x8BD33000 \SystemRoot\system32\DRIVERS\amdxata.sys
  0x8BD3C000 \SystemRoot\system32\drivers\fltmgr.sys
  0x8BD70000 \SystemRoot\system32\drivers\fileinfo.sys
  0x8BE3A000 \SystemRoot\System32\Drivers\Ntfs.sys
  0x8BF69000 \SystemRoot\System32\Drivers\msrpc.sys
  0x8BF94000 \SystemRoot\System32\Drivers\ksecdd.sys
  0x8BD81000 \SystemRoot\System32\Drivers\cng.sys
  0x8BFA7000 \SystemRoot\System32\drivers\pcw.sys
  0x8BFB5000 \SystemRoot\System32\Drivers\Fs_Rec.sys
  0x8C003000 \SystemRoot\system32\drivers\ndis.sys
  0x8C0BA000 \SystemRoot\system32\drivers\NETIO.SYS
  0x8C0F8000 \SystemRoot\System32\Drivers\ksecpkg.sys
  0x8C23E000 \SystemRoot\System32\drivers\tcpip.sys
  0x8C387000 \SystemRoot\System32\drivers\fwpkclnt.sys
  0x8C3B8000 \SystemRoot\system32\DRIVERS\volsnap.sys
  0x8C3F7000 \SystemRoot\System32\Drivers\spldr.sys
  0x8C200000 \SystemRoot\System32\drivers\rdyboost.sys
  0x8C22D000 \SystemRoot\System32\Drivers\mup.sys
  0x8C11D000 \SystemRoot\System32\drivers\hwpolicy.sys
  0x8C125000 \SystemRoot\System32\DRIVERS\fvevol.sys
  0x8C157000 \SystemRoot\system32\DRIVERS\disk.sys
  0x8C168000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
  0x8C1BF000 \SystemRoot\system32\DRIVERS\cdrom.sys
  0x8C1DE000 \SystemRoot\System32\Drivers\Null.SYS
  0x8C1E5000 \SystemRoot\System32\Drivers\Beep.SYS
  0x8C1EC000 \SystemRoot\System32\drivers\vga.sys
  0x8BFBE000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
  0x8BFDF000 \SystemRoot\System32\drivers\watchdog.sys
  0x8C1F8000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
  0x8BFEC000 \SystemRoot\system32\drivers\rdpencdd.sys
  0x8BFF4000 \SystemRoot\system32\drivers\rdprefmp.sys
  0x8BE00000 \SystemRoot\System32\Drivers\Msfs.SYS
  0x8BE0B000 \SystemRoot\System32\Drivers\Npfs.SYS
  0x8BE19000 \SystemRoot\system32\DRIVERS\tdx.sys
  0x8BDDE000 \SystemRoot\system32\DRIVERS\TDI.SYS
  0x90228000 \SystemRoot\system32\drivers\afd.sys
  0x90282000 \SystemRoot\System32\DRIVERS\netbt.sys
  0x902B4000 \SystemRoot\system32\DRIVERS\wfplwf.sys
  0x902BB000 \SystemRoot\system32\DRIVERS\pacer.sys
  0x902DA000 \SystemRoot\system32\DRIVERS\netbios.sys
  0x902E8000 \SystemRoot\system32\DRIVERS\serial.sys
  0x90302000 \SystemRoot\system32\DRIVERS\wanarp.sys
  0x90315000 \??\C:\Windows\system32\Drivers\vmm.sys
  0x90350000 \SystemRoot\system32\DRIVERS\termdd.sys
  0x90360000 \SystemRoot\system32\DRIVERS\rdbss.sys
  0x903A1000 \SystemRoot\system32\drivers\nsiproxy.sys
  0x903AB000 \SystemRoot\system32\DRIVERS\mssmbios.sys
  0x903B5000 \SystemRoot\System32\drivers\discache.sys
  0x903C1000 \SystemRoot\System32\Drivers\dfsc.sys
  0x903D9000 \SystemRoot\system32\DRIVERS\blbdrive.sys
  0x90200000 \SystemRoot\system32\DRIVERS\tunnel.sys
  0x903E7000 \SystemRoot\system32\DRIVERS\amdppm.sys
  0x8BE30000 \SystemRoot\system32\DRIVERS\serenum.sys
  0x8BDE9000 \SystemRoot\system32\DRIVERS\fdc.sys
  0x8BC00000 \SystemRoot\system32\DRIVERS\parport.sys
  0x8BC18000 \SystemRoot\system32\DRIVERS\usbohci.sys
  0x90E3C000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
  0x90E87000 \SystemRoot\system32\DRIVERS\usbehci.sys
  0x90E96000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
  0x90EB5000 \SystemRoot\system32\DRIVERS\nvm62x32.sys
  0x90F0A000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
  0x92235000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
  0x92CB3000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
  0x92CB5000 \SystemRoot\System32\drivers\dxgkrnl.sys
  0x92D6C000 \SystemRoot\System32\drivers\dxgmms1.sys
  0x92DA5000 \SystemRoot\System32\Drivers\amodgld4.SYS
  0x92DDE000 \SystemRoot\system32\DRIVERS\VMNetSrv.sys
  0x92DEF000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
  0x92200000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
  0x92212000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
  0x9222A000 \SystemRoot\system32\DRIVERS\ndistapi.sys
  0x90F10000 \SystemRoot\system32\DRIVERS\ndiswan.sys
  0x90F32000 \SystemRoot\system32\DRIVERS\raspppoe.sys
  0x90F4A000 \SystemRoot\system32\DRIVERS\raspptp.sys
  0x90F61000 \SystemRoot\system32\DRIVERS\rassstp.sys
  0x90F78000 \SystemRoot\system32\DRIVERS\kbdclass.sys
  0x90F85000 \SystemRoot\system32\DRIVERS\mouclass.sys
  0x92DFC000 \SystemRoot\system32\DRIVERS\swenum.sys
  0x90F92000 \SystemRoot\system32\DRIVERS\ks.sys
  0x90FC6000 \SystemRoot\system32\DRIVERS\umbus.sys
  0x90FD4000 \SystemRoot\system32\DRIVERS\flpydisk.sys
  0x833B6000 \SystemRoot\system32\DRIVERS\usbhub.sys
  0x90FDE000 \SystemRoot\System32\Drivers\NDProxy.SYS
  0x96809000 \SystemRoot\system32\drivers\HdAudio.sys
  0x96859000 \SystemRoot\system32\drivers\portcls.sys
  0x96888000 \SystemRoot\system32\drivers\drmk.sys
  0x968A1000 \SystemRoot\System32\Drivers\crashdmp.sys
  0x968AE000 \SystemRoot\System32\Drivers\dump_dumpata.sys
  0x968B9000 \SystemRoot\System32\Drivers\dump_atapi.sys
  0x968C2000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
  0x968D3000 \SystemRoot\system32\DRIVERS\usbccgp.sys
  0x968EA000 \SystemRoot\system32\DRIVERS\USBD.SYS
  0x968EC000 \SystemRoot\system32\DRIVERS\hidusb.sys
  0x968F7000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
  0x9690A000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
  0x97A00000 \SystemRoot\System32\win32k.sys
  0x96911000 \SystemRoot\System32\drivers\Dxapi.sys
  0x9691B000 \SystemRoot\system32\DRIVERS\LHidFilt.Sys
  0x96923000 \SystemRoot\system32\DRIVERS\kbdhid.sys
  0x9692F000 \SystemRoot\system32\DRIVERS\mouhid.sys
  0x9693A000 \SystemRoot\system32\DRIVERS\LMouFilt.Sys
  0x96942000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
  0x96959000 \SystemRoot\System32\Drivers\fastfat.SYS
  0x96983000 \SystemRoot\system32\DRIVERS\monitor.sys
  0x97C60000 \SystemRoot\System32\TSDDD.dll
  0x9698E000 \SystemRoot\system32\drivers\usbaudio.sys
  0x97C90000 \SystemRoot\System32\cdd.dll
  0x97CB0000 \SystemRoot\System32\ATMFD.DLL
  0x969A2000 \SystemRoot\system32\drivers\luafv.sys
  0x969BD000 \SystemRoot\system32\drivers\WudfPf.sys
  0x969D7000 \SystemRoot\system32\DRIVERS\lltdio.sys
  0x969E7000 \SystemRoot\system32\DRIVERS\rspndr.sys
  0x98E12000 \SystemRoot\system32\drivers\HTTP.sys
  0x98E97000 \SystemRoot\system32\DRIVERS\bowser.sys
  0x98EB0000 \SystemRoot\System32\drivers\mpsdrv.sys
  0x98EC2000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
  0x98EE5000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
  0x98F20000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
  0x98F3B000 \SystemRoot\system32\DRIVERS\parvdm.sys
  0x98F42000 \??\C:\Windows\system32\drivers\acedrv11.sys
  0x98F6E000 \??\C:\Windows\system32\drivers\cpuz134_x32.sys
  0x9EE37000 \SystemRoot\system32\drivers\peauth.sys
  0x9EECE000 \SystemRoot\System32\Drivers\secdrv.SYS
  0x9EED8000 \SystemRoot\System32\DRIVERS\srvnet.sys
  0x9EEF9000 \SystemRoot\System32\drivers\tcpipreg.sys
  0x9EF06000 \SystemRoot\System32\DRIVERS\srv2.sys
  0x9EF55000 \SystemRoot\System32\DRIVERS\srv.sys
  0x98F72000
  0x9EFA6000 \SystemRoot\system32\DRIVERS\asyncmac.sys
  0x76FC0000 \Windows\System32\ntdll.dll
  0x48190000 \Windows\System32\smss.exe
  0x77200000 \Windows\System32\apisetschema.dll
  0x00DA0000 \Windows\System32\autochk.exe
  0x10000000 \Program Files\DAEMON Tools Lite\Engine.dll
  0x771E0000 \Windows\System32\nsi.dll
  0x77180000 \Windows\System32\difxapi.dll
  0x76370000 \Windows\System32\shell32.dll
  0x77150000 \Windows\System32\imagehlp.dll
  0x762D0000 \Windows\System32\usp10.dll
  0x77140000 \Windows\System32\lpk.dll
  0x77120000 \Windows\System32\sechost.dll
  0x76290000 \Windows\System32\ws2_32.dll
  0x76200000 \Windows\System32\clbcatq.dll

Processes (total 54):
      0 System Idle Process
      4 System
    272 C:\Windows\System32\smss.exe
    368 csrss.exe
    420 C:\Windows\System32\wininit.exe
    436 csrss.exe
    508 C:\Windows\System32\services.exe
    516 C:\Windows\System32\winlogon.exe
    544 C:\Windows\System32\lsass.exe
    556 C:\Windows\System32\lsm.exe
    656 C:\Windows\System32\svchost.exe
    720 C:\Windows\System32\nvvsvc.exe
    760 C:\Windows\System32\svchost.exe
    812 C:\Windows\System32\atiesrxx.exe
    892 C:\Windows\System32\svchost.exe
    924 C:\Windows\System32\svchost.exe
    952 C:\Windows\System32\svchost.exe
    1040 C:\Windows\System32\audiodg.exe
    1116 C:\Windows\System32\svchost.exe
    1208 C:\Windows\System32\atieclxx.exe
    1224 C:\Windows\System32\nvvsvc.exe
    1312 C:\Windows\System32\svchost.exe
    1464 C:\Windows\System32\spoolsv.exe
    1504 C:\Windows\System32\svchost.exe
    1576 C:\Windows\System32\svchost.exe
    1600 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1664 C:\Program Files\Bonjour\mDNSResponder.exe
    1704 C:\Windows\System32\svchost.exe
    1736 C:\Windows\System32\svchost.exe
    1812 C:\Windows\System32\svchost.exe
    1844 C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    1976 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
    604 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
    2176 C:\Windows\System32\svchost.exe
    2772 C:\Windows\System32\svchost.exe
    2812 C:\Program Files\Windows Media Player\wmpnetwk.exe
    2976 C:\Windows\System32\SearchIndexer.exe
    2984 WmiPrvSE.exe
    3424 C:\Windows\System32\dwm.exe
    3500 C:\Windows\explorer.exe
    3516 C:\Windows\System32\taskhost.exe
    3628 D:\Programme\RocketDock\RocketDock.exe
    2392 C:\Windows\System32\svchost.exe
    768 D:\Programme\Mozilla Firefox\firefox.exe
    2376 dllhost.exe
    1908 C:\Windows\servicing\TrustedInstaller.exe
    2480 C:\Windows\System32\wuauclt.exe
    1048 C:\Users\Daniel\Desktop\osam\osam.exe
    2256 C:\Windows\System32\SearchProtocolHost.exe
    3620 C:\Windows\System32\SearchFilterHost.exe
    3204 C:\Windows\explorer.exe
    1644 C:\Users\Daniel\Desktop\MBRCheck.exe
    2036 C:\Windows\System32\conhost.exe
    1304 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000  (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x0000000c`80100000  (NTFS)
\\.\E: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00  (FAT32)
\\.\H: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000  (NTFS)

PhysicalDrive0 Model Number: WDCWD1600AAJB-00J3A0, Rev: 01.03E01
PhysicalDrive1 Model Number: SamsungSTORY Station P, Rev:

      Size  Device Name          MBR Status
  --------------------------------------------
    149 GB  \\.\PhysicalDrive0  Windows 7 MBR code detected
            SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
    931 GB  \\.\PhysicalDrive1  RE: Unknown MBR code
            SHA1: 639AC5CDF8A5CF3245975932C6A4215450A7B98F


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:


cosinus 18.01.2011 20:18

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

daniel508 18.01.2011 20:29

Beide Scans laufen gerade.

Übrigens möchte ich mich an dieser Stelle schon mal für die Mühe bedanken, trotz meines Crosspostings.^^

daniel508 18.01.2011 21:05

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 5549

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

18.01.2011 21:04:35
mbam-log-2011-01-18 (21-04-35).txt

Art des Suchlaufs: Vollständiger Suchlauf (A:\|C:\|D:\|E:\|F:\|H:\|X:\|)
Durchsuchte Objekte: 253065
Laufzeit: 40 Minute(n), 52 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


daniel508 18.01.2011 23:26

Also alles in Ordnung jetzt?

cosinus 18.01.2011 23:32

Du hast ein Log vergessen :pfeiff:

daniel508 18.01.2011 23:33

Welchen? :S

cosinus 18.01.2011 23:33

Das von SASW

daniel508 18.01.2011 23:37

Wann bekomme ich den bzw. Wo finde ich ihn?

cosinus 18.01.2011 23:37

Ja hast Du SASW denn noch nicht ausgeführt? :confused: Du solltest doch zwei Kontrollscans machen!

daniel508 18.01.2011 23:38

Doch habe ich.
Habe nur keinen Log bekommen, habe ihn eben aber gefunden ;)

Code:

SUPERAntiSpyware Scann-Protokoll
hxxp://www.superantispyware.com

Generiert 01/18/2011 bei 09:00 PM

Version der Applikation : 4.48.1000

Version der Kern-Datenbank : 6226
Version der Spur-Datenbank : 4038

Scan Art      : kompletter Scann
Totale Scann-Zeit : 00:32:20

Gescannte Speicherelemente  : 628
Erfasste Speicher-Bedrohungen  : 0
Gescannte Register-Elemente  : 8187
Erfasste Register-Bedrohungen  : 0
Gescannte Datei-Elemente    : 28898
Erfasste Datei-Elemente  : 0


daniel508 18.01.2011 23:51

Also ich entdeckte bei dem Logs nichts aussergewöhnliches.
Sind wir fertig? :?

cosinus 19.01.2011 10:53

Ja, keine Funde. Rechner wieder ok? ;)

daniel508 19.01.2011 18:39

Na, ich hoffe es. ;)

Ich installier dann noch mal Norton, denn wenn ich schon einen Key gekauft habe, dann will ich das Programm auch ausnutzen! ;)

daniel508 19.01.2011 19:57

Mache gerade einen Scan mit Malwarebytes..
Der zeigt mir schon wieder 2 infizierte Dateien an -.-

daniel508 19.01.2011 20:14

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 5554

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

19.01.2011 20:13:45
mbam-log-2011-01-19 (20-13-42).txt

Art des Suchlaufs: Vollständiger Suchlauf (A:\|C:\|D:\|E:\|F:\|H:\|X:\|)
Durchsuchte Objekte: 257178
Laufzeit: 35 Minute(n), 13 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 2

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\program files\windows live\installer\langselectorres.dll (Trojan.Downloader) -> No action taken.
c:\Windows\installer\$patchcache$\Managed\f132f0b0a6ecd384aa32773b467f9571\15.4.3502\langselectorres.dll (Trojan.Downloader) -> No action taken.


daniel508 19.01.2011 20:18

Anscheinend soll eine DLL Datei des Language Selectors von Windows Live ein Trojan.Dowloader sein.. ?!

daniel508 19.01.2011 20:32

Habe aus dem Malwarebytes Forum diese Anleitung gelesen: forums.malwarebytes.org/index.php?showtopic=3228
Also ist es kein Virus?

cosinus 19.01.2011 21:15

Ja, sieht nach Fehlalarmen aus.
Rechner jetzt wirklich wieder ok?

daniel508 19.01.2011 21:41

Ja, ich denke schon.
Übrigens : Meine Maus und Tastatur hatten mal Lagg Attacken.
Seitdem ich die Viren (dank dir) entfernt habe sind sie weg! :D

Vielen, vielen Dank! ;)

cosinus 19.01.2011 22:39

Dann wären wir durch! :abklatsch:

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update



PDF-Reader aktualisieren
Dein Adobe Reader ist nicht aktuell, was ein großes Sicherheitsrisiko darstellt. Du solltest daher besser die alte Version über Systemsteuerung => Software deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst.

Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink => http://filepony.de/?q=Flash+Player


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 15:59 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131