Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Trojaner TR/Crypt.XPACK.Gen und viele Fehlermeldungen (https://www.trojaner-board.de/96850-trojaner-tr-crypt-xpack-gen-viele-fehlermeldungen.html)

SebastianEF 25.03.2011 19:55

Trojaner TR/Crypt.XPACK.Gen und viele Fehlermeldungen
 
Hallo zusammen,

habe gestern an meinem Rechner gearbeitet und nebenbei VZ und Facebook offen gehabt. Auf einmal kam von AntiVir die Meldung, dass es den Trojaner TR/Crypt.XPACK.Gen identifiziert habe. Ich habe es über AntiVir "entfernt". Anschließend traten sehr viele Fehlermeldungen auf:

Die in der Regestrierung angegebene Anwendung "C:\USER\****\AppData\Local\temp\csrss.exe" konnte nicht geladen oder gestartet werden. Stellen Sie sicher, dass die Datei vorhanden ist, oder entfernen Sie den Eintrag mit Bezug auf diese Datei aus der Regestrierung.

Anschließend kamen Fehlermeldungen wie:

Critical Error Damaged Harddriive
Critical Error RAM memory usage


usw. usw. usw.

Der PC startete von alleine neu und anschließend war mein Desktophintergrund weg und schwarz. Nach und nach verschwanden alle Symbole auf dem Desktop bis auf Arbeitszplatz, UserOrdner und Papierkorb. Außerdem kann ich keine Programme mehr in der Start-Leiste anzeigen lassen oder öffnen.

Wenn ich im Internet unterwegs bin lande ich immer auf merkwürdige Seiten :stirn: Google ist auch nicht das Originalgoogle, sondern hat ein merkwürdiges Bild oben im Kopf. Also definitiv eine Fälschung.

Ich weiß nun leider nicht ob meine externe HDD ebenfalls befallen ist. Zudem habe ich extrem viele Fotos auf meinem PC die sehr wichtig sind. (Fotografie) Das ist eine halbe Lebensarbeit darin und natürlich habe ich Trottel bisher keine Sicherung gemacht :headbang:

Wichtig ist es mir die externe HDD und die Bilder zu retten. Ich hoffe ihr könnt mir helfen. :confused:

Ich habe nun wie im Board hier vorgegeben die TFC, ERUNT und OTL laufen lassen. (interessant ist das in den Logfiles was von Bit Torrent steht... das habe ich noch nie gehabt *grübel*)

Hier die Logfiles:OTL Logfile:
Code:

OTL logfile created on: 25.03.2011 19:38:22 - Run 2
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\****\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 62,00% Memory free
8,00 Gb Paging File | 7,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,76 Gb Total Space | 83,78 Gb Free Space | 17,99% Space Free | Partition Type: NTFS
 
Computer Name: ****-PC | User Name: **** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\****\AppData\Local\Temp\csrss.exe ()
PRC - C:\Users\****\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Users\****\AppData\Roaming\dwm.exe ()
PRC - C:\Users\****\AppData\Roaming\Microsoft\conhost.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Google\Update\1.2.183.39\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe ()
PRC - C:\Program Files (x86)\REALTEK PCI&Cardbus Wireless LAN Driver and Utility\RtWLan.exe (Realtek Semiconductor Corp.)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\****\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msshsq.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\duser.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\IconCodecService.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (TVersityMediaServer) -- C:\Users\****\AppData\Local\TVersity\Media Server\MediaServer.exe ()
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (OMSI download service) -- C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe ()
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (LBTServ) -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira GmbH)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys ()
DRV:64bit: - (s1029unic) Sony Ericsson Device 1029 USB Ethernet Emulation (WDM) -- C:\Windows\SysNative\DRIVERS\s1029unic.sys (MCCI Corporation)
DRV:64bit: - (s1029mgmt) Sony Ericsson Device 1029 USB WMC Device Management Drivers (WDM) -- C:\Windows\SysNative\DRIVERS\s1029mgmt.sys (MCCI Corporation)
DRV:64bit: - (s1029obex) -- C:\Windows\SysNative\DRIVERS\s1029obex.sys (MCCI Corporation)
DRV:64bit: - (s1029mdm) -- C:\Windows\SysNative\DRIVERS\s1029mdm.sys (MCCI Corporation)
DRV:64bit: - (s1029nd5) Sony Ericsson Device 1029 USB Ethernet Emulation (NDIS) -- C:\Windows\SysNative\DRIVERS\s1029nd5.sys (MCCI Corporation)
DRV:64bit: - (s1029mdfl) -- C:\Windows\SysNative\DRIVERS\s1029mdfl.sys (MCCI Corporation)
DRV:64bit: - (s1029bus) Sony Ericsson Device 1029 driver (WDM) -- C:\Windows\SysNative\DRIVERS\s1029bus.sys (MCCI Corporation)
DRV:64bit: - (s0016mdm) -- C:\Windows\SysNative\DRIVERS\s0016mdm.sys (MCCI Corporation)
DRV:64bit: - (s0016mdfl) -- C:\Windows\SysNative\DRIVERS\s0016mdfl.sys (MCCI Corporation)
DRV:64bit: - (s0016bus) Sony Ericsson Device 0016 driver (WDM) -- C:\Windows\SysNative\DRIVERS\s0016bus.sys (MCCI Corporation)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation                                            )
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (V0330VID) -- C:\Windows\SysNative\DRIVERS\V0330Vid.sys (Creative Technology Ltd.)
DRV:64bit: - (RTL85n64) -- C:\Windows\SysNative\DRIVERS\RTL85n64.sys (Realtek)
DRV:64bit: - (s816mdm) -- C:\Windows\SysNative\DRIVERS\s816mdm.sys (MCCI Corporation)
DRV:64bit: - (s816unic) Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM) -- C:\Windows\SysNative\DRIVERS\s816unic.sys (MCCI)
DRV:64bit: - (s816mgmt) Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM) -- C:\Windows\SysNative\DRIVERS\s816mgmt.sys (MCCI Corporation)
DRV:64bit: - (s816obex) -- C:\Windows\SysNative\DRIVERS\s816obex.sys (MCCI Corporation)
DRV:64bit: - (s816nd5) Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS) -- C:\Windows\SysNative\DRIVERS\s816nd5.sys (MCCI Corporation)
DRV:64bit: - (s816mdfl) -- C:\Windows\SysNative\DRIVERS\s816mdfl.sys (MCCI Corporation)
DRV:64bit: - (s816bus) Sony Ericsson Device 816 driver (WDM) -- C:\Windows\SysNative\DRIVERS\s816bus.sys (MCCI Corporation)
DRV:64bit: - (s115mgmt) Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM) -- C:\Windows\SysNative\DRIVERS\s115mgmt.sys (MCCI Corporation)
DRV:64bit: - (s115obex) -- C:\Windows\SysNative\DRIVERS\s115obex.sys (MCCI Corporation)
DRV:64bit: - (s115mdm) -- C:\Windows\SysNative\DRIVERS\s115mdm.sys (MCCI Corporation)
DRV:64bit: - (s115mdfl) -- C:\Windows\SysNative\DRIVERS\s115mdfl.sys (MCCI Corporation)
DRV:64bit: - (s115bus) Sony Ericsson Device 115 driver (WDM) -- C:\Windows\SysNative\DRIVERS\s115bus.sys (MCCI Corporation)
DRV:64bit: - (RtlProt) -- C:\Windows\SysNative\DRIVERS\rtlprot.sys (Windows (R) Codename Longhorn DDK provider)
DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\Wbem\ntfs.mof ()
DRV:64bit: - (Ser2pl64) -- C:\Windows\SysNative\DRIVERS\ser2pl64.sys (Prolific Technology Inc.)
DRV - (Pwa16bcy) -- C:\Windows\SysWOW64\drivers\ssmdrv.sys (Avira GmbH)
DRV - (ASPI32) -- C:\Windows\SysWow64\drivers\ASPI32.SYS (Adaptec)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.google.de/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:55515
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "www.google.de"
FF - prefs.js..extensions.enabledItems: {62760FD6-B943-48C9-AB09-F99C6FE96088}:2.1.8
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.36.0
FF - prefs.js..extensions.enabledItems: NPDyyno@dyyno.com:1.0.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.1.1
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: extension@virtusdesigns.com:3.6.7
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.0.19
FF - prefs.js..extensions.enabledItems: {b80f591e-fe9a-46cf-a13e-180377240586}:3.3.0.19
FF - prefs.js..extensions.enabledItems: {795828a9-f271-43a8-8536-4484bb991d3d}:3.3.0.19
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.6.7
FF - prefs.js..keyword.URL: "hxxp://search.sweetim.com/search.asp?src=2&q="
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 55515
FF - prefs.js..network.proxy.type: 1
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files (x86)\Google\Google Gears\Firefox\ [2010.03.06 09:26:30 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.03.24 07:42:43 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.03.24 07:42:43 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 0.8\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2010.12.26 09:01:46 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 0.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins [2010.12.26 09:01:46 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.03.05 19:18:02 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2010.12.26 09:01:46 | 000,000,000 | -H-D | M]
 
[2010.08.27 15:14:02 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Extensions
[2010.08.27 15:14:02 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.03.24 21:36:15 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions
[2010.05.11 12:37:36 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008.04.10 22:30:59 | 000,000,000 | -H-D | M] ("Firefox Default for Vista") -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\{2843a0c8-caba-4428-b96a-83b5547c0fdd}
[2011.03.06 21:59:06 | 000,000,000 | -H-D | M] (Stylish) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010.11.12 20:43:02 | 000,000,000 | -H-D | M] (Aero Fox XL) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
[2011.03.23 06:09:41 | 000,000,000 | -H-D | M] (eBay Sidebar for Firefox) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}
[2011.01.14 18:44:36 | 000,000,000 | -H-D | M] (Productivity 2 Community Toolbar) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\{795828a9-f271-43a8-8536-4484bb991d3d}
[2010.09.18 16:21:16 | 000,000,000 | -H-D | M] (DVDVideoSoftTB Toolbar) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010.07.04 20:28:20 | 000,000,000 | -H-D | M] ("DVDVideoSoft Menu") -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.01.08 11:22:50 | 000,000,000 | -H-D | M] (Elf 1.13 Community Toolbar) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\{b80f591e-fe9a-46cf-a13e-180377240586}
[2011.01.08 11:27:31 | 000,000,000 | -H-D | M] ("DAEMON Tools Toolbar") -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\DTToolbar@toolbarnet.com
[2011.01.14 18:44:36 | 000,000,000 | -H-D | M] (Conduit Engine) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\engine@conduit.com
[2010.11.12 20:43:05 | 000,000,000 | -H-D | M] (Virtus Search Opt-in) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\extension@virtusdesigns.com
[2009.05.17 15:27:13 | 000,000,000 | -H-D | M] (Simple Dyyno Launcher) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\NPDyyno@dyyno.com
[2010.11.12 20:43:05 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\extension@virtusdesigns.com\chrome
[2010.11.12 20:43:02 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\v4itc736.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\win\mozapps\extensions
[2008.04.13 11:57:15 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Sunbird\Profiles\7zep4cwc.default\extensions
[2009.06.26 19:16:18 | 000,002,399 | -H-- | M] () -- C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\v4itc736.default\searchplugins\daemon-search.xml
[2011.03.21 06:44:50 | 000,000,944 | -H-- | M] () -- C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\v4itc736.default\searchplugins\icqplugin.xml
[2009.10.11 10:57:47 | 000,003,915 | -H-- | M] () -- C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\v4itc736.default\searchplugins\sweetim.xml
[2011.03.24 21:36:15 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2008.05.25 11:03:39 | 000,000,000 | -H-D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
[2010.04.16 18:39:33 | 000,000,000 | -H-D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.09.26 09:43:02 | 000,000,000 | -H-D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.10.16 10:28:14 | 000,000,000 | -H-D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010.12.18 12:51:24 | 000,000,000 | -H-D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.02.19 19:02:43 | 000,000,000 | -H-D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010.03.06 09:26:30 | 000,000,000 | -H-D | M] (Google Gears) -- C:\PROGRAM FILES (X86)\GOOGLE\GOOGLE GEARS\FIREFOX
[2008.09.04 01:11:24 | 000,054,600 | -H-- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npbittorrent.dll
[2011.02.02 21:40:24 | 000,472,808 | -H-- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010.03.14 13:03:36 | 000,001,392 | -H-- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.03.14 13:03:36 | 000,002,344 | -H-- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.03.14 13:03:36 | 000,006,805 | -H-- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.03.14 13:03:36 | 000,001,178 | -H-- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.03.14 13:03:36 | 000,001,105 | -H-- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 22:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LgDevAgt] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [conhost] C:\Users\****\AppData\Roaming\Microsoft\conhost.exe ()
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NWEReboot]  File not found
O4 - HKLM..\Run: [V0330Mon.exe] C:\Windows\V0330Mon.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [sCRrtWXnjAgI] C:\ProgramData\sCRrtWXnjAgI.exe (FPAV)
O4 - HKCU..\Run: [Sony Ericsson PC Suite] C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
O4 - HKCU..\Run: [Steam] c:\program files (x86)\steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files (x86)\Xfire\xfire.exe (Xfire Inc.)
F3:64bit: - HKCU WinNT: Load - (C:\Users\****\AppData\Local\Temp\csrss.exe) - C:\Users\****\AppData\Local\Temp\csrss.exe ()
F3 - HKCU WinNT: Load - (C:\Users\****\AppData\Local\Temp\csrss.exe) - C:\Users\****\AppData\Local\Temp\csrss.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\****\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\****\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Gears-Einstellungen - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files (x86)\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files (x86)\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Users\****\AppData\Roaming\dwm.exe) - C:\Users\****\AppData\Roaming\dwm.exe ()
O24 - Desktop WallPaper: C:\Users\****\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\****\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{36d21537-97bb-11df-9a93-001d7dd02838}\Shell - "" = AutoRun
O33 - MountPoints2\{36d21537-97bb-11df-9a93-001d7dd02838}\Shell\AutoRun\command - "" = F:\Startme.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
 
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.03.25 19:23:18 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.03.25 19:22:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011.03.25 19:22:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT
[2011.03.25 19:15:37 | 000,791,393 | ---- | C] (Lars Hederer                                                ) -- C:\Users\****\Desktop\Erunt-setup.exe
[2011.03.25 19:15:34 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Users\****\Desktop\TFC.exe
[2011.03.25 19:13:48 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\****\Desktop\OTL.exe
[2011.03.24 22:04:48 | 000,546,304 | -H-- | C] (FPAV) -- C:\ProgramData\sCRrtWXnjAgI.exe
[2011.03.20 10:43:17 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photomatix Pro 4.0
[2011.03.20 10:43:15 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\PhotomatixPro4
[2011.03.20 10:43:15 | 000,000,000 | -H-D | C] -- C:\Users\****\AppData\Roaming\HDRsoft
[2011.03.09 23:24:57 | 002,425,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2011.03.09 23:24:56 | 002,067,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2011.03.09 23:24:56 | 000,731,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
[2011.03.09 23:24:56 | 000,677,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2011.03.09 23:24:54 | 000,559,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2011.03.09 23:24:54 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2011.03.09 23:24:54 | 000,416,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sbe.dll
[2011.03.09 23:24:53 | 000,322,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sbe.dll
[2011.03.09 23:24:53 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax
[2011.03.09 23:24:53 | 000,210,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sbeio.dll
[2011.03.09 23:24:53 | 000,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax
[2011.03.09 23:24:53 | 000,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sbeio.dll
[2011.03.07 20:36:10 | 000,000,000 | -H-D | C] -- C:\Users\****\AppData\Roaming\Avira
[2011.02.27 11:43:41 | 000,000,000 | -H-D | C] -- C:\Users\****\AppData\Roaming\ZoomBrowser EX
[2011.02.27 11:37:58 | 000,000,000 | -H-D | C] -- C:\Users\****\AppData\Local\CANON_INC
[2011.02.27 11:35:18 | 000,000,000 | -H-D | C] -- C:\Users\****\AppData\Roaming\Canon
[2011.02.27 11:33:33 | 000,000,000 | -H-D | C] -- C:\ProgramData\ZoomBrowser
[2011.02.27 11:32:37 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
[2011.02.27 11:32:31 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Canon
[2011.02.27 11:31:58 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Common Files\Canon
[2010.07.25 10:58:01 | 000,148,736 | -H-- | C] (Avanquest Software) -- C:\ProgramData\hpeAF06.dll
 
========== Files - Modified Within 30 Days ==========
 
[2011.03.25 19:24:08 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{E6D8AD8D-8C04-436D-8FED-9272D6C69435}.job
[2011.03.25 19:22:37 | 000,000,763 | ---- | M] () -- C:\Users\****\Desktop\NTREGOPT.lnk
[2011.03.25 19:22:37 | 000,000,744 | ---- | M] () -- C:\Users\****\Desktop\ERUNT.lnk
[2011.03.25 19:19:04 | 000,001,104 | -H-- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.03.25 19:19:01 | 000,000,330 | -H-- | M] () -- C:\Windows\tasks\RtlVistaStart.job
[2011.03.25 19:18:33 | 000,003,712 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.03.25 19:18:33 | 000,003,712 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.03.25 19:18:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.03.25 19:15:54 | 000,791,393 | ---- | M] (Lars Hederer                                                ) -- C:\Users\****\Desktop\Erunt-setup.exe
[2011.03.25 19:15:38 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\****\Desktop\OTL.exe
[2011.03.25 19:15:38 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Users\****\Desktop\TFC.exe
[2011.03.25 19:14:52 | 000,377,280 | ---- | M] () -- C:\Users\****\Desktop\Load.exe
[2011.03.25 19:12:44 | 000,005,686 | -H-- | M] () -- C:\Users\****\AppData\Roaming\A748.111
[2011.03.25 19:04:05 | 000,001,108 | -H-- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.03.24 23:04:50 | 000,000,239 | -H-- | M] () -- C:\Windows\WINCMD.INI
[2011.03.24 22:34:56 | 000,002,338 | -H-- | M] () -- C:\Windows\SysWow64\tversity.cookies
[2011.03.24 22:04:48 | 000,546,304 | -H-- | M] (FPAV) -- C:\ProgramData\sCRrtWXnjAgI.exe
[2011.03.23 21:27:12 | 000,171,008 | -H-- | M] () -- C:\Users\****\AppData\Roaming\dwm.exe
[2011.03.20 18:41:33 | 000,242,176 | -H-- | M] () -- C:\Users\****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.03.20 10:43:17 | 000,001,837 | -H-- | M] () -- C:\Users\****\Desktop\Photomatix Pro 4.0.2 (32-bit).lnk
[2011.03.19 16:04:17 | 000,000,069 | -H-- | M] () -- C:\Windows\NeroDigital.ini
[2011.03.19 10:56:51 | 001,566,490 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.03.19 10:56:51 | 000,675,174 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.03.19 10:56:51 | 000,633,688 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.03.19 10:56:51 | 000,146,282 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.03.19 10:56:51 | 000,118,694 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.03.18 16:46:50 | 000,008,772 | -H-- | M] () -- C:\Users\****\AppData\Local\d3d9caps64.dat
[2011.03.14 21:30:49 | 235,867,844 | -H-- | M] () -- C:\Users\****\Desktop\Festival of darkness.rar
[2011.03.14 19:32:09 | 001,940,749 | -H-- | M] () -- C:\Users\****\Desktop\IMG_0392.JPG
[2011.03.14 19:32:02 | 002,583,155 | -H-- | M] () -- C:\Users\****\Desktop\IMG_0390.JPG
[2011.03.14 19:13:12 | 002,751,162 | -H-- | M] () -- C:\Users\****\Desktop\IMG_0465.JPG
[2011.03.14 19:12:45 | 002,662,506 | -H-- | M] () -- C:\Users\****\Desktop\IMG_0460.JPG
[2011.03.14 19:11:53 | 002,706,082 | -H-- | M] () -- C:\Users\****\Desktop\IMG_0464.JPG
[2011.03.14 19:10:37 | 002,387,951 | -H-- | M] () -- C:\Users\****\Desktop\IMG_0475.JPG
[2011.03.14 19:09:59 | 002,431,977 | -H-- | M] () -- C:\Users\****\Desktop\IMG_0470.JPG
[2011.03.14 19:09:50 | 002,467,600 | -H-- | M] () -- C:\Users\****\Desktop\IMG_0469.JPG
[2011.03.14 19:09:28 | 002,487,936 | -H-- | M] () -- C:\Users\****\Desktop\IMG_0471.JPG
[2011.03.14 19:05:32 | 002,409,599 | -H-- | M] () -- C:\Users\****\Desktop\IMG_0468.JPG
[2011.03.13 12:40:23 | 000,005,701 | ---- | M] () -- C:\Users\****\Desktop\Anleitung.html
[2011.03.11 10:11:36 | 017,865,424 | -H-- | M] () -- C:\Users\****\Desktop\TVersitySetup_1_9_3.exe
[2011.02.26 18:55:29 | 000,000,032 | -H-- | M] () -- C:\Windows\Menu.INI
[2011.02.26 02:19:32 | 000,041,872 | -H-- | M] () -- C:\Windows\SysWow64\xfcodec.dll
[2011.02.26 02:19:32 | 000,027,536 | ---- | M] () -- C:\Windows\SysNative\xfcodec64.dll
 
========== Files Created - No Company Name ==========
 
[2011.03.25 19:22:37 | 000,000,763 | ---- | C] () -- C:\Users\****\Desktop\NTREGOPT.lnk
[2011.03.25 19:22:37 | 000,000,744 | ---- | C] () -- C:\Users\****\Desktop\ERUNT.lnk
[2011.03.25 19:15:00 | 000,377,280 | ---- | C] () -- C:\Users\****\Desktop\Load.exe
[2011.03.24 23:04:40 | 000,000,239 | -H-- | C] () -- C:\Windows\WINCMD.INI
[2011.03.23 21:27:12 | 000,171,008 | -H-- | C] () -- C:\Users\****\AppData\Roaming\dwm.exe
[2011.03.23 21:26:54 | 000,005,686 | -H-- | C] () -- C:\Users\****\AppData\Roaming\A748.111
[2011.03.20 10:43:17 | 000,001,837 | -H-- | C] () -- C:\Users\****\Desktop\Photomatix Pro 4.0.2 (32-bit).lnk
[2011.03.14 19:36:19 | 235,867,844 | -H-- | C] () -- C:\Users\****\Desktop\Festival of darkness.rar
[2011.03.14 19:31:12 | 001,940,749 | -H-- | C] () -- C:\Users\****\Desktop\IMG_0392.JPG
[2011.03.14 19:31:03 | 002,583,155 | -H-- | C] () -- C:\Users\****\Desktop\IMG_0390.JPG
[2011.03.14 19:07:19 | 002,662,506 | -H-- | C] () -- C:\Users\****\Desktop\IMG_0460.JPG
[2011.03.14 19:07:09 | 002,751,162 | -H-- | C] () -- C:\Users\****\Desktop\IMG_0465.JPG
[2011.03.14 19:07:07 | 002,706,082 | -H-- | C] () -- C:\Users\****\Desktop\IMG_0464.JPG
[2011.03.14 19:06:25 | 002,387,951 | -H-- | C] () -- C:\Users\****\Desktop\IMG_0475.JPG
[2011.03.14 19:05:55 | 002,487,936 | -H-- | C] () -- C:\Users\****\Desktop\IMG_0471.JPG
[2011.03.14 19:05:52 | 002,431,977 | -H-- | C] () -- C:\Users\****\Desktop\IMG_0470.JPG
[2011.03.14 19:05:49 | 002,467,600 | -H-- | C] () -- C:\Users\****\Desktop\IMG_0469.JPG
[2011.03.14 19:00:58 | 002,409,599 | -H-- | C] () -- C:\Users\****\Desktop\IMG_0468.JPG
[2011.03.13 12:41:14 | 000,005,701 | ---- | C] () -- C:\Users\****\Desktop\Anleitung.html
[2011.03.11 10:10:36 | 017,865,424 | -H-- | C] () -- C:\Users\****\Desktop\TVersitySetup_1_9_3.exe
[2011.02.26 18:55:29 | 000,000,032 | -H-- | C] () -- C:\Windows\Menu.INI
[2011.02.26 02:19:32 | 000,041,872 | -H-- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2011.02.26 02:19:32 | 000,027,536 | ---- | C] () -- C:\Windows\SysNative\xfcodec64.dll
[2010.07.11 17:03:34 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010.01.29 19:18:52 | 002,434,856 | -H-- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2009.09.24 06:35:12 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009.09.24 06:34:44 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009.09.24 06:34:15 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.09.24 06:33:59 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2009.06.09 23:17:11 | 001,448,396 | -H-- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009.04.15 17:35:11 | 000,000,171 | -H-- | C] () -- C:\Users\****\AppData\Local\rahistory.xml
[2009.04.06 20:01:15 | 000,000,069 | -H-- | C] () -- C:\Windows\NeroDigital.ini
[2009.04.04 08:54:06 | 000,007,680 | -H-- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2009.03.28 15:53:51 | 000,682,280 | -H-- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2009.03.07 11:37:13 | 000,000,613 | -H-- | C] () -- C:\Windows\wiso.ini
[2008.12.29 17:01:39 | 000,000,359 | -H-- | C] () -- C:\Windows\CoDUO.INI
[2008.12.29 16:52:31 | 000,000,745 | -H-- | C] () -- C:\Windows\CoD.INI
[2008.12.28 19:17:29 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2008.12.18 21:21:03 | 000,000,680 | -H-- | C] () -- C:\Users\****\AppData\Local\d3d9caps.dat
[2008.12.10 22:12:37 | 000,000,552 | -H-- | C] () -- C:\Users\****\AppData\Local\d3d8caps.dat
[2008.11.06 17:37:32 | 003,596,288 | -H-- | C] () -- C:\Windows\SysWow64\qt-dx331.dll
[2008.11.06 17:33:02 | 000,012,288 | -H-- | C] () -- C:\Windows\SysWow64\DivXWMPExtType.dll
[2008.07.05 18:18:45 | 000,007,867 | -H-- | C] () -- C:\Windows\Irremote.ini
[2008.04.17 22:12:23 | 000,242,176 | -H-- | C] () -- C:\Users\****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.04.13 12:02:15 | 000,000,032 | -H-- | C] () -- C:\ProgramData\ezsid.dat
[2008.04.10 23:00:15 | 000,270,776 | -H-- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2008.04.10 23:00:14 | 000,075,136 | -H-- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2008.04.10 23:00:13 | 000,000,286 | -H-- | C] () -- C:\Windows\game.ini
[2008.04.10 22:22:41 | 000,000,305 | -H-- | C] () -- C:\ProgramData\addr_file.html
[2008.04.10 21:46:19 | 000,000,400 | -H-- | C] () -- C:\Windows\ODBC.INI
[2008.04.10 11:35:46 | 000,000,000 | -H-- | C] () -- C:\Windows\nsreg.dat
[2008.04.10 11:19:09 | 000,003,972 | -H-- | C] () -- C:\Windows\SysWow64\drivers\PciBus.sys
[2008.04.10 11:11:20 | 000,111,932 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat
[2008.04.10 11:11:20 | 000,031,053 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat
[2008.04.10 11:11:20 | 000,027,417 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat
[2008.04.10 11:11:20 | 000,026,154 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat
[2008.04.10 11:11:20 | 000,024,903 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat
[2008.04.10 11:11:20 | 000,021,390 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat
[2008.04.10 11:11:20 | 000,020,148 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat
[2008.04.10 11:11:20 | 000,011,811 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat
[2008.04.10 11:11:20 | 000,004,943 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat
[2008.04.10 11:11:20 | 000,001,146 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPresetData_DU.dat
[2008.04.10 11:11:20 | 000,001,139 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2008.04.10 11:11:20 | 000,001,139 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2008.04.10 11:11:20 | 000,001,136 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2008.04.10 11:11:20 | 000,001,129 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2008.04.10 11:11:20 | 000,001,129 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2008.04.10 11:11:20 | 000,001,120 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPresetData_IT.dat
[2008.04.10 11:11:20 | 000,001,107 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPresetData_GE.dat
[2008.04.10 11:11:20 | 000,001,104 | -H-- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2008.04.10 11:11:20 | 000,000,097 | -H-- | C] () -- C:\Windows\SysWow64\PICSDK.ini
[2008.04.10 10:45:57 | 000,008,772 | -H-- | C] () -- C:\Users\****\AppData\Local\d3d9caps64.dat
[2008.01.21 03:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2006.11.02 16:37:05 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:37:14 | 000,215,943 | -H-- | C] () -- C:\Windows\SysWow64\dssec.dat
[2006.11.02 13:24:17 | 000,000,741 | -H-- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2006.11.02 13:18:17 | 000,673,088 | -H-- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006.11.02 10:47:54 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2003.02.20 16:53:42 | 000,005,702 | -H-- | C] () -- C:\Windows\SysWow64\OUTLPERF.INI
 
========== LOP Check ==========
 
[2008.04.18 10:11:22 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\Ashampoo
[2009.03.07 11:37:19 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\Buhl Data Service
[2011.02.27 11:35:18 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\Canon
[2008.05.30 22:04:20 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\CDBurnerXP_Soft
[2009.06.26 19:20:09 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\DAEMON Tools Lite
[2009.12.19 13:43:41 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\DNA
[2011.03.04 18:50:06 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\DVDVideoSoftIEHelpers
[2009.07.07 20:19:24 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\EPSON
[2010.06.27 09:05:15 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\Facebook
[2011.03.20 10:43:15 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\HDRsoft
[2011.03.20 14:02:56 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\ICQ
[2010.03.23 16:24:39 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien
[2011.02.21 20:54:17 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\Picturenaut
[2010.07.25 11:00:41 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\Sony
[2010.07.25 10:48:58 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\Sony Setup
[2008.07.06 09:21:31 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\Teleca
[2010.08.27 15:14:02 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\Thunderbird
[2010.08.18 21:21:25 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\Umakm
[2009.12.19 09:44:46 | 000,000,000 | -H-D | M] -- C:\Users\****\AppData\Roaming\VSRevoGroup
[2011.03.25 19:19:01 | 000,000,330 | -H-- | M] () -- C:\Windows\Tasks\RtlVistaStart.job
[2011.03.25 19:17:20 | 000,032,534 | -H-- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.03.25 19:24:08 | 000,000,416 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{E6D8AD8D-8C04-436D-8FED-9272D6C69435}.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*. >
[2010.06.11 17:46:50 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2009.09.24 17:13:03 | 000,000,000 | -HSD | M] -- C:\Boot
[2006.11.02 16:42:17 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2008.04.10 10:43:55 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2008.04.10 10:52:22 | 000,000,000 | -H-D | M] -- C:\Intel
[2010.06.13 13:54:35 | 000,000,000 | -H-D | M] -- C:\Ligeia
[2008.04.10 21:42:37 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2009.10.01 21:42:24 | 000,000,000 | -H-D | M] -- C:\NVIDIA
[2008.01.21 04:04:13 | 000,000,000 | -H-D | M] -- C:\PerfLogs
[2010.03.19 10:29:29 | 000,000,000 | RH-D | M] -- C:\Programme
[2011.03.25 19:22:37 | 000,000,000 | RH-D | M] -- C:\Program Files (x86)
[2011.03.25 19:06:18 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2008.04.10 10:43:55 | 000,000,000 | -HSD | M] -- C:\Programme
[2011.03.25 19:38:59 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2010.08.22 10:57:35 | 000,000,000 | RH-D | M] -- C:\Users
[2011.03.25 19:23:18 | 000,000,000 | -H-D | M] -- C:\Windows
 
< %PROGRAMFILES%\*.exe >
 
< %LOCALAPPDATA%\*.exe >
 
< %systemroot%\*. /mp /s >
 
 
< MD5 for: EXPLORER.EXE  >
[2008.10.29 07:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_b5f700fe698beb14\explorer.exe
[2008.10.29 07:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_b7eb106e66a7ac19\explorer.exe
[2008.10.29 07:15:50 | 003,087,360 | ---- | M] (Microsoft Corporation) MD5=50514057C28A74BAC2BD04B7B990D615 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_aba256ac352b2919\explorer.exe
[2008.10.30 04:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_b8583e9d7fda0512\explorer.exe
[2009.04.11 08:10:17 | 003,079,168 | ---- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 -- C:\Windows\explorer.exe
[2009.04.11 08:10:17 | 003,079,168 | ---- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_afbebba22f3bab41\explorer.exe
[2008.10.28 03:30:12 | 003,086,848 | ---- | M] (Microsoft Corporation) MD5=72B9990E45C25AA3C75C4FB50A9D6CE0 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_ac5266dd4e2b0a41\explorer.exe
[2008.10.29 07:49:22 | 003,080,704 | ---- | M] (Microsoft Corporation) MD5=BBD8E74F23D7605CB0CDB57A1B25D826 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_ad96661c3246ea1e\explorer.exe
[2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\SysWOW64\explorer.exe
[2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_ba1365f4639c6d3c\explorer.exe
[2008.10.30 06:30:07 | 003,081,216 | ---- | M] (Microsoft Corporation) MD5=E404A65EF890140410E9F3D405841C95 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_ae03944b4b794317\explorer.exe
[2008.10.28 03:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_b6a7112f828bcc3c\explorer.exe
[2008.01.21 03:48:44 | 003,080,704 | ---- | M] (Microsoft Corporation) MD5=F6D765FB6B457542D954682F50C26E4F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_add342963219dff5\explorer.exe
[2008.01.21 03:49:23 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_b827ece8667aa1f0\explorer.exe
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 03:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008.01.21 03:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2008.01.21 03:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\SysNative\userinit.exe
[2008.01.21 03:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 03:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SysWOW64\wininit.exe
[2008.01.21 03:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008.01.21 03:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\SysNative\wininit.exe
[2008.01.21 03:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 08:11:08 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SysNative\winlogon.exe
[2009.04.11 08:11:08 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008.01.21 03:49:47 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 03:50:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 24 bytes -> C:\Windows:6A7BF95613718B6A
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:6971CCC5

< End of report >

--- --- ---


Und hier ExtrasOTL Logfile:
Code:

OTL Extras logfile created on: 25.03.2011 19:38:22 - Run 2
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\****\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 62,00% Memory free
8,00 Gb Paging File | 7,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,76 Gb Total Space | 83,78 Gb Free Space | 17,99% Space Free | Partition Type: NTFS
 
Computer Name: ****-PC | User Name: **** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Programme\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Programme\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l File not found
InternetShortcut [print] -- rundll32.exe C:\Windows\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [CEWE FOTOSCHAU] -- "C:\Program Files (x86)\dm\dm-Fotowelt\CEWE FOTOSCHAU.exe" -d "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Digital Photo Professional] -- C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [dm Fotowelt] -- "C:\Program Files (x86)\dm\dm Fotowelt\dm Fotowelt.exe" "%1" ()
Directory [dm-Fotowelt] -- "C:\Program Files (x86)\dm\dm-Fotowelt\dm-Fotowelt.exe" "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Fotoschau] -- "C:\Program Files (x86)\Pixum\Pixum Fotobuch\Fotoschau.exe" -d "%1" ()
Directory [Pixum Fotobuch] -- "C:\Program Files (x86)\Pixum\Pixum Fotobuch\Pixum Fotobuch.exe" "%1" ()
Directory [TVersity] -- "C:\Users\****\AppData\Local\TVersity\Media Server\GUILaunch.exe" -type "folder" -url "%1" -title "" -tags "" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Programme\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Programme\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [CEWE FOTOSCHAU] -- "C:\Program Files (x86)\dm\dm-Fotowelt\CEWE FOTOSCHAU.exe" -d "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Digital Photo Professional] -- C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [dm Fotowelt] -- "C:\Program Files (x86)\dm\dm Fotowelt\dm Fotowelt.exe" "%1" ()
Directory [dm-Fotowelt] -- "C:\Program Files (x86)\dm\dm-Fotowelt\dm-Fotowelt.exe" "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Fotoschau] -- "C:\Program Files (x86)\Pixum\Pixum Fotobuch\Fotoschau.exe" -d "%1" ()
Directory [Pixum Fotobuch] -- "C:\Program Files (x86)\Pixum\Pixum Fotobuch\Pixum Fotobuch.exe" "%1" ()
Directory [TVersity] -- "C:\Users\****\AppData\Local\TVersity\Media Server\GUILaunch.exe" -type "folder" -url "%1" -title "" -tags "" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01  [binary data]
"VistaSp2" = F1 37 9B DA 31 3D CA 01  [binary data]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\BitTorrent\bittorrent.exe" = C:\Program Files (x86)\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\BitTorrent\bittorrent.exe" = C:\Program Files (x86)\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0CC6E5A6-16DF-459A-8E20-88F7524023DB}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{0D49261A-3F17-40B7-B530-3E8A0DF28728}" = lport=3390 | protocol=6 | dir=in | app=system |
"{137C80DE-56A9-4E40-9D3A-114BF2CA657C}" = lport=7777 | protocol=17 | dir=in | app=c:\windows\ehome\ehshell.exe |
"{1AA82A50-8AD6-450B-A413-3FC98A2C64B0}" = lport=3101 | protocol=17 | dir=in | name=mw2 |
"{1AE642C2-3178-4EDA-B524-A2796DD92846}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{1B146C3C-AC8D-4D28-90EF-9E3CB99DCD75}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{28DF119A-B6DA-45BF-8FBF-C625355E289F}" = lport=41952 | protocol=6 | dir=in | name=tversity |
"{2DABA2B8-C778-4BE8-9666-B585B04FFDC6}" = lport=10243 | protocol=6 | dir=in | app=system |
"{2E867F43-D014-4423-A753-B359C70BA108}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{35C14320-16CF-4716-8C6D-E27DC7D2AA79}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{3AEF9E2A-5678-46AE-B484-DBB82146BBCD}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{4F3656C2-901F-497E-81C8-9CF3B16A6F30}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{52EAA6FD-E126-41AF-AD54-693875636666}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{5FEA79D9-A6BD-41ED-8B73-9E9E1A1BC7C6}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{61313132-E365-4FFE-9C25-48F5F1ECAA6A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{63811C4F-6F12-4112-9DFD-3BD008600294}" = lport=41952 | protocol=17 | dir=in | name=41952 |
"{64B4F51C-35A2-4FAC-A14A-95FDAD4CB7D6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{67C31A32-92A2-4534-9C29-C5BEA3F7DEC3}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{68A6F940-69B2-4ECC-AE1E-A3B37CE29AF7}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{8999AA6A-074B-4432-9141-F096AB43CCAB}" = lport=554 | protocol=6 | dir=in | app=c:\windows\ehome\ehshell.exe |
"{8AFE5408-F0E9-41AD-A8A5-ED430519E8A7}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{8C5B0AAC-C07D-40B5-9EE3-DFDB05C92225}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{985FDBF6-40A9-40F1-B409-CF83C66D2736}" = lport=3005 | protocol=17 | dir=in | name=mw2 |
"{9AE922EC-7E03-4B13-8AE1-D5B7C7E42466}" = rport=10243 | protocol=6 | dir=out | app=system |
"{A48197FF-D85A-4177-8241-71444BC2B1F2}" = lport=445 | protocol=6 | dir=in | app=system |
"{B9BDCE08-6B16-4FD2-AAB0-635D99C085DE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BAD5EB18-C39B-4B15-BF14-99E4CF2647DB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BC064E09-C25B-4453-9538-CD1A94240684}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C3E508F8-B13F-40B0-B543-904CC6CA1BBD}" = lport=10244 | protocol=6 | dir=in | app=system |
"{D7B5253C-85F4-431B-827A-827122BF9876}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\services.exe |
"{DE327CF5-54CE-4D61-AF44-9B396CDBE73F}" = lport=28960 | protocol=17 | dir=in | name=mw2 |
"{DF892F5E-9345-4497-954E-671E1DC1B8F5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E38B50FA-75B2-48FB-9AFF-8A806C1FA6D9}" = lport=1500 | protocol=17 | dir=in | name=mw2 |
"{E4FFBFF8-1B22-4378-9D48-0FAA2CD34686}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ED2A9864-915C-49C2-A196-75D686884468}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{F1A83492-F23F-4BF7-960A-B35159B906BB}" = lport=41952 | protocol=6 | dir=in | name=tversity |
"{F97E8188-8FCD-451E-8B39-06988B2158C4}" = rport=10244 | protocol=6 | dir=out | app=system |
"{FFA0E8BB-1289-4C59-9DE6-323A8465270A}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{004079D1-58EA-4BC5-8A83-1CAB904B9FFE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{005AECD3-5D74-45F8-8EC0-40DE4573C7B7}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2 - beta\bfbc2betaupdater.exe |
"{014FA9D6-08AE-46A3-8C6E-44ADCA3E6EB2}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\die schlacht um mittelerde ii\game.dat |
"{05D7C640-08C1-4E6C-8AA7-4D5C5B222E83}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
"{0C5ADAAD-0506-4CED-998C-36D12D562307}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
"{1900A799-F22E-4A5E-BE05-8F9BE1CDFDD8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{19C8089E-7C11-487B-A957-BDFAC94BBCAA}" = protocol=6 | dir=in | app=c:\users\****\appdata\local\tversity\media server\mediaserver.exe |
"{243A5CFF-A330-4450-9046-E96AA4C4017D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{2537310F-FC86-4742-8D5D-BD268A2D3995}" = protocol=17 | dir=out | app=c:\windows\ehome\ehshell.exe |
"{253FE906-E54F-4E66-9608-996F2EE6C172}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{25ADE3CF-AD1B-4DEE-8BAD-6F38694ABD38}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{26370A67-33E2-4BA5-AF90-4EDFAEDC9E94}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.0\aolload.exe |
"{26A18F58-24CF-40C1-BA93-9DB48919DC1F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{2819204C-E993-4AB1-AF1B-4B6BC6200A03}" = protocol=17 | dir=in | app=c:\program files (x86)\dna\btdna.exe |
"{2875449B-37BB-467D-8E0D-9F6AF5FA6472}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{28AEFF47-C596-4D11-BE1B-AA7038E7F1B2}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.0\icq.exe |
"{2B81A700-EA97-4DC5-831D-99E29F9F4E71}" = protocol=6 | dir=in | app=c:\users\****\appdata\locallow\dyyno receiver\dppm.exe |
"{2F894A09-E472-4493-9EE5-41B835B9325E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{306A5871-FBD7-4F3A-811F-EBE003FBDFAB}" = protocol=17 | dir=in | app=c:\users\****\appdata\local\tversity\media server\mediaserver.exe |
"{3719BC6D-8093-44D7-B691-FCF20BF5290D}" = protocol=17 | dir=in | app=c:\users\****\appdata\local\tversity\media server\web\admin\tversity.exe |
"{3842B488-B243-4143-90D8-67D08D558853}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{39817115-5F56-4EB2-9969-27703BAE1B0F}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.0\aolload.exe |
"{39E4D214-9CB4-4E6E-B7EC-51E78DD47C54}" = protocol=6 | dir=out | svc=mcx2svc | app=c:\windows\system32\svchost.exe |
"{3A2258C9-CC5C-45CF-8542-9526AEDBADB5}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2 - beta\bfbc2betaupdater.exe |
"{3C111DF8-E2C1-4C57-B6D2-81AF69A398E9}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
"{3CB64647-D33A-44C7-8856-243CBB4756F2}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{419A1AEF-93A2-4BA8-B96A-36B65261ABB3}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\die schlacht um mittelerde ii\game.dat |
"{46AB9820-F63C-4768-8ABE-1608DB4E5349}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{493CD95E-8865-405E-B320-9EA993AE135F}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{4D53EC7F-FC37-4F4C-9654-F79737370FB2}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{500681BD-0AC7-48E5-A467-81EA9C115794}" = protocol=17 | dir=in | app=c:\program files (x86)\tversity\media server\mediaserver.exe |
"{50633951-9F46-4B33-8C12-780E7A0E8881}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.0\icq.exe |
"{5A47B9C4-E55D-418E-BF86-A9AFC5F94C1C}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\xr_3da.exe |
"{5FB19E01-73B0-4E53-B160-0E6ECB3A510E}" = protocol=17 | dir=in | app=c:\users\****\appdata\locallow\dyyno receiver\dppm.exe |
"{6042AAA7-3E4E-4B13-85D2-6193AF4F302C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{60CD4FB2-082F-41F8-8FBD-889DC80CF9F0}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{61FBBFCB-0537-4E4A-8118-E700A08E5663}" = dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{659145F0-8DDF-4A39-90A8-C28614B4F493}" = protocol=6 | dir=in | app=c:\users\****\appdata\local\tversity\media server\web\admin\tversity.exe |
"{683A6F5F-0FE3-497F-BC36-C5E516A46E7C}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{687D96F4-C52F-4DFD-92FB-267C0C3FA5B9}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{6BAE34DD-2634-4A40-B265-FF5A3171CAC6}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.0\icq.exe |
"{6D3F166D-6C6D-4B26-9627-96DDA24D3DF2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6F41D2B8-1562-443D-B55B-88143C78FCFF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{749F4B64-F24E-4E13-9CC4-3BA81BAF6C60}" = protocol=6 | dir=out | app=c:\windows\ehome\mcx2prov.exe |
"{74EDD5A2-727A-4EE9-8827-073F343653CA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{799EA453-255F-4778-AB71-EAE4348D9C05}" = protocol=6 | dir=in | app=c:\program files (x86)\dna\btdna.exe |
"{7BFAA1FC-9474-4F4B-925D-7DF4872E65D1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7D0CFE88-CA55-442A-B36F-DD5A5F074D6F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7EFE49BC-95A5-4BB7-90FD-363881E6D0D3}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{85C10DD3-33DD-420D-95BB-F4DC591ABBD9}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{8A081D99-B275-480C-A7F4-79015980D428}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.0\aolload.exe |
"{8C57ED70-E660-4FA0-BA7A-E3E1139FE44A}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{8D071E16-38D4-4BA6-82A8-58215EF11E8D}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.0\icq.exe |
"{8E559077-E727-42E4-A42B-AAA131FD6816}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{90BB9E92-4F99-4CF4-AAE2-FC85791CF603}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9274AB23-7E54-46F5-B403-0BAB9E58F93F}" = protocol=6 | dir=in | app=c:\users\****\appdata\local\tversity\media server\mediaserver.exe |
"{959185C9-1C45-43C2-AA91-DF69E157053C}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{96B12550-04CA-48F7-9D20-B4CD6F8FA5CB}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\dedicated\xr_3da.exe |
"{9B17F210-2C1B-41CA-BEBE-5A535CAD883F}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{9F416E9C-0C12-40AA-8D57-059E838F3854}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A513745F-E18B-4C5C-ADD5-0626FDFC9865}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.0\aolload.exe |
"{A5A66EEE-E8BE-4025-8F0D-74A01F5681F8}" = protocol=17 | dir=in | app=c:\users\****\appdata\local\tversity\media server\mediaserver.exe |
"{A78B201A-348F-48A0-A0EE-B98372370FA7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AE849C87-4CE2-4077-B57C-AD137A1893BF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AFF6CEC8-F1BE-4202-909A-FF98733437A2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{B4649046-7348-46D7-8BA7-22E450644DC7}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{B480590F-C5EF-486D-B769-4ADF2E6F54B9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{B5E468F6-AE8F-4971-B2E8-C39881D3325D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{B97AB61D-2431-4BFC-9857-3B8D71BFEC36}" = protocol=6 | dir=out | app=c:\windows\ehome\ehshell.exe |
"{BB57F18E-A921-4AE2-8C6B-3B49A960C636}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.0\aolload.exe |
"{BDACCDCF-ED59-43F7-8F07-EF29E091ACE6}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C29CE330-333E-468B-B24E-339747CEF06A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{C59F0FD8-3662-4937-B7ED-4EF136A43C72}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.0\aolload.exe |
"{C766832C-3FA3-4B2D-BDE4-BA3D1F26DDA3}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CD2FE1D6-A135-49B5-9473-576B12EA455B}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\xr_3da.exe |
"{CDEEAF7B-6DE2-45A5-ADA5-F6ECE2C47F80}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CE7BF0CA-1963-4DEE-8E70-842C82118190}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D3D538F8-F2EF-46EB-9B44-697F58DBA98C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{D45D8FB9-6371-4A06-9695-3D3930C7E2DA}" = protocol=6 | dir=out | app=system |
"{D82DFA94-ABD4-4188-9569-70BDBAFE393E}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{D8D7A847-395E-4521-926C-3375951F360E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{DA6724A9-223E-4EF5-B84D-E9B998007933}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{DB7B2697-7D27-4E42-8C20-161355604DC7}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{E5BE0130-F73B-474E-9063-ABC2C52AADF9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E74E9D9A-98DA-4CD6-838B-752DF3BC62D1}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.0\icq.exe |
"{EA356834-9D43-42AE-B18C-0AF2EEA5F99F}" = protocol=6 | dir=in | app=c:\program files (x86)\tversity\media server\mediaserver.exe |
"{ECFC28E0-CE51-46EA-8EEB-CF72844E53A2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{EF1A6DC6-D6A3-4766-9452-AAE765862F90}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\dedicated\xr_3da.exe |
"{F32B3207-1327-4172-958F-6BE980D5A4DF}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
"{F858B314-C4BD-4AE1-AEFF-D6A43313F845}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.0\icq.exe |
"{F92584AC-FDA7-4282-A936-39F9990A1B2B}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe |
"TCP Query User{025F6404-05E5-4CA5-BA7F-4F7372B51B74}C:\program files (x86)\kazaa lite\clean.kmd" = protocol=6 | dir=in | app=c:\program files (x86)\kazaa lite\clean.kmd |
"TCP Query User{1D3E6626-D3C5-4DC8-ACE1-C0E39CA5878F}E:\apps\mirandaportable\app\miranda\miranda32.exe" = protocol=6 | dir=in | app=e:\apps\mirandaportable\app\miranda\miranda32.exe |
"TCP Query User{2E819D66-C252-4B22-BF98-25D29F90D285}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe |
"TCP Query User{31A7F6CB-98F0-40D7-A5C7-E0C28CEA8650}C:\users\****\program files (x86)\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\****\program files (x86)\dna\btdna.exe |
"TCP Query User{3984A979-2564-4073-8429-25444582124A}C:\program files (x86)\call of duty\coduomp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\call of duty\coduomp.exe |
"TCP Query User{3BB46A9E-E3B1-4F4D-97B5-03F369DC1FA4}C:\program files (x86)\dna\btdna.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dna\btdna.exe |
"TCP Query User{47D361B5-1AFB-4CE1-819D-7B37F057F77F}C:\program files (x86)\dcc\dcc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dcc\dcc.exe |
"TCP Query User{4AD1F99F-0345-49A2-AA32-BE6D46024902}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe |
"TCP Query User{60E164CD-DAA8-47FD-B7D3-781E04EE221B}C:\program files (x86)\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xfire\xfire.exe |
"TCP Query User{6360917A-32E8-4414-92F9-6100B79ABE4C}C:\users\****\program files (x86)\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\****\program files (x86)\dna\btdna.exe |
"TCP Query User{78214362-4DEF-45CE-9AF0-E693C453527C}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"TCP Query User{7CDF39FA-2CFA-49E0-8E44-691F6AC1CB88}C:\program files (x86)\electronic arts\battlefield bad company 2 - beta\bfbc2game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2 - beta\bfbc2game.exe |
"TCP Query User{8E764AC0-2697-422F-8695-C1CCAFB39BFC}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{9494033C-A5DD-44A6-9BCA-AD430006883F}C:\program files (x86)\nero\nero8\nero home\nerohome.exe" = protocol=6 | dir=in | app=c:\program files (x86)\nero\nero8\nero home\nerohome.exe |
"TCP Query User{C7F61CE8-6BC5-43CB-AD67-E4A1E72DF8BF}C:\users\****\appdata\roaming\vyuwe\uklu.exe" = protocol=6 | dir=in | app=c:\users\****\appdata\roaming\vyuwe\uklu.exe |
"TCP Query User{CEE9AB14-F8F9-444F-A58F-7C1D0CDDBAC8}C:\program files (x86)\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xfire\xfire.exe |
"TCP Query User{E548B9A5-4849-4505-913C-87FAEB16F1A9}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{E651F9AE-A0AA-41C3-B314-06F2120A22F1}C:\program files (x86)\sony\media go\mediago.exe" = protocol=6 | dir=in | app=c:\program files (x86)\sony\media go\mediago.exe |
"TCP Query User{EF8E141A-81DF-46E0-8238-3C2A01A5E0D0}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{F5D99F3F-EF61-4752-A487-B255FAEF09AD}C:\program files (x86)\call of duty\codmp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\call of duty\codmp.exe |
"TCP Query User{F6D74C11-5E73-45E4-B177-338B8525B128}C:\program files (x86)\activision\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty 2\cod2mp_s.exe |
"UDP Query User{2A3CE5F0-EBA9-4B8C-B2B7-A90ADC8C2620}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe |
"UDP Query User{2C5104BE-6C0D-44B4-9DDB-0842415597A3}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe |
"UDP Query User{3788D361-6A6A-4C07-917E-730FB0412E77}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{4C2CF337-568B-42BF-BBB3-943884B773B8}C:\program files (x86)\kazaa lite\clean.kmd" = protocol=17 | dir=in | app=c:\program files (x86)\kazaa lite\clean.kmd |
"UDP Query User{6475783B-D117-45AA-A5DE-CDE33A2EA65B}C:\program files (x86)\activision\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty 2\cod2mp_s.exe |
"UDP Query User{67A8A20F-091B-4F58-B4AA-0407313C7613}C:\users\****\program files (x86)\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\****\program files (x86)\dna\btdna.exe |
"UDP Query User{6C12F53F-0C83-4DC3-8CFF-9AF2D4EB8AE9}C:\users\****\program files (x86)\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\****\program files (x86)\dna\btdna.exe |
"UDP Query User{79F3EADD-1C40-4A36-BF49-CCBFE0A14E36}C:\program files (x86)\call of duty\coduomp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\call of duty\coduomp.exe |
"UDP Query User{7AE8C248-8F8A-4877-B303-078F3B6D364C}C:\program files (x86)\nero\nero8\nero home\nerohome.exe" = protocol=17 | dir=in | app=c:\program files (x86)\nero\nero8\nero home\nerohome.exe |
"UDP Query User{7EC2DECC-7CF4-406B-A335-2D681B16F521}C:\program files (x86)\call of duty\codmp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\call of duty\codmp.exe |
"UDP Query User{A7F684E0-C50F-4FDC-AB01-297DA8833C82}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{B92038F5-78D3-4E1F-8742-1FA81DA2755A}C:\program files (x86)\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xfire\xfire.exe |
"UDP Query User{C05FC7A2-1CAA-4B8E-BAF1-72607D6816CE}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{C5EC5EA9-4420-4849-BA0B-71471BBD877B}E:\apps\mirandaportable\app\miranda\miranda32.exe" = protocol=17 | dir=in | app=e:\apps\mirandaportable\app\miranda\miranda32.exe |
"UDP Query User{D69CB170-A831-4EF0-994B-6371DE35ADF9}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{E471C611-3B9D-455B-8E55-77B5CE25FDC7}C:\program files (x86)\sony\media go\mediago.exe" = protocol=17 | dir=in | app=c:\program files (x86)\sony\media go\mediago.exe |
"UDP Query User{E71C18BD-0FD0-488A-9C39-22C4427FFC85}C:\users\****\appdata\roaming\vyuwe\uklu.exe" = protocol=17 | dir=in | app=c:\users\****\appdata\roaming\vyuwe\uklu.exe |
"UDP Query User{EA61BECC-150F-42F0-A3B5-C81EF9540CBE}C:\program files (x86)\dna\btdna.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dna\btdna.exe |
"UDP Query User{EB74D391-16A7-4ECF-8745-FB1B78188EA4}C:\program files (x86)\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xfire\xfire.exe |
"UDP Query User{F19039CE-09F7-41A8-B47D-F910E609EFAD}C:\program files (x86)\electronic arts\battlefield bad company 2 - beta\bfbc2game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2 - beta\bfbc2game.exe |
"UDP Query User{FBEEDE14-7C98-4DC8-8D35-052AD54BB6F2}C:\program files (x86)\dcc\dcc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dcc\dcc.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{217727BD-9B2C-47E5-B5FB-773D9DAC7210}" = Microsoft SQL Server Native Client
"{4432F6A4-33D7-41B9-88E4-6735CF334671}" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - DEU
"{68FCD2C3-67B6-42E7-B677-2B4053225801}" = Microsoft SQL Server VSS Writer
"{906BDDA8-9E8F-45B7-8520-36F7961FD65D}" = Logitech GamePanel Software 2.02
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 266.58
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F0309609-E415-42C8-8C61-2483EBA338E9}" = Sony Ericsson PC Suite x64
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"Creative VF0330" = Creative WebCam Vista/Live! Cam Chat Driver (1.11.01.00)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual Studio 2005 Remote Debugger Light (x64) - DEU" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - DEU
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{00C58EBE-223E-4AB6-8AE9-38F27F4420BD}" = WISO Sparbuch 2009
"{028ED9C4-25EE-4DEE-9CF4-91034BC89B18}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty(R) - World at War(TM) 1.6 Patch
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation(R)Store
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty(R) - World at War(TM) 1.3 Patch
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{19D2B63E-C1F1-4803-BA8B-4AB8FE216952}" = EPSON PRINT Image Framer Tool
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{25724802-CC14-4B90-9F3B-3D6955EE27B1}" = Company of Heroes
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java(TM) 6 Update 24
"{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}" = Die Schlacht um Mittelerde™ II
"{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty(R) - World at War(TM) 1.2 Patch
"{2FA41EBB-3F5A-35C3-85D6-51EC72A11FBD}" = Google Gears
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 6.011.00
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java(TM) SE Runtime Environment 6
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{46B70DEB-97B3-4E38-B746-EC16905E6A8F}" = WISO Sparbuch 2010
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C8DE415-3AB4-4E46-8349-1DD0B5AB297D}" = Microsoft Visual Basic 2005 Express Edition - DEU
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5B52E1FF-BD66-4582-97BA-55C575C19504}" = Microsoft MSDN 2005 Express Edition - DEU
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F3AD00A-1819-4B15-BB7D-08B3586336D7}" = 3DMark06
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Patch
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista
"{88EB38EF-4D2C-436D-ABD3-56B232674062}" = ICQ7
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8C13BEE4-E7CE-4E46-BD13-8F41DAD00FEF}" = SweetIM Toolbar for Internet Explorer 3.4
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90510407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Visio Professional 2003
"{919635D1-5C0D-4B64-B724-BDDB31D11031}" = Nero 8
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty(R) - World at War(TM) 1.4 Patch
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A662E280-64A8-4CF5-8407-13D0808602B3}" = Call of Duty - United Offensive
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1031-7B44-A81300000003}" = Adobe Reader 8.1.4 - Deutsch
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty(R) - World at War(TM) 1.1 Patch
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation(R)Network Downloader
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BBAAAD82-6242-420F-86D4-BD72BB5E6C86}" = Tools für Microsoft SQL Server 2005 Express Edition
"{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty(R) - World at War(TM) 1.5 Patch
"{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}" = Sony Ericsson Device Data
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}" = WinZip 11.1
"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D59AC9E9-FFAE-471B-B1FF-4B311D23417A}" = Sony Ericsson PC Suite
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D6BF6477-8369-489F-8DE6-3731F4B88560}" = Sony Ericsson PC Suite
"{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM)
"{E06C8E13-7A8C-434C-8548-34BC4762212D}" = Logitech Harmony Remote Software 7
"{E237FA24-CFB3-431F-B356-DF8FB116DE4B}" = Call of Duty(R) - World at War(TM) 1.7 Patch
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{E728E952-DD4F-4BCD-A5C8-40FBFEFF91FE}" = OpenOffice.org Installer 1.0
"{EC87E256-B0A4-4A41-8682-AB57FF21196D}" = SweetIM for Messenger 2.7
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EF72E0A5-57E8-471F-837E-82BB19771363}" = REALTEK PCI&Cardbus Wireless LAN Driver and Utility
"{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony Ericsson PC Companion 1.60.13
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{FBE5AA96-22F0-4C4A-8E92-4BE3498D4CCB}" = Media Go
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Benutzerhandbuch für Creative WebCam Vista German" = Benutzerhandbuch für Creative WebCam Vista (Deutsch)
"Call of Duty" = Call of Duty
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"CCleaner" = CCleaner
"Creative Live! Cam Center" = Creative Live! Cam Center
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"dm Fotowelt" = dm Fotowelt
"dm-Fotowelt" = dm-Fotowelt
"DPP" = Canon Utilities Digital Photo Professional 3.8
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"EOS Utility" = Canon Utilities EOS Utility
"EPSON Scanner" = EPSON Scan
"ERUNT_is1" = ERUNT 1.1j
"Exact Audio Copy" = Exact Audio Copy 0.99pb3
"ffdshow_is1" = ffdshow [rev 1723] [2007-12-24]
"FLV Player" = FLV Player 2.0 (build 25)
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free Studio_is1" = Free Studio version 4.3
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.33
"HijackThis" = HijackThis 2.0.2
"ICQToolbar" = ICQ Toolbar
"InstallShield_{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty(R) - World at War(TM) 1.6 Patch
"InstallShield_{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty(R) - World at War(TM) 1.3 Patch
"InstallShield_{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty(R) - World at War(TM) 1.2 Patch
"InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
"InstallShield_{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty(R) - World at War(TM) 1.4 Patch
"InstallShield_{A662E280-64A8-4CF5-8407-13D0808602B3}" = Call of Duty - United Offensive
"InstallShield_{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty(R) - World at War(TM) 1.1 Patch
"InstallShield_{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty(R) - World at War(TM) 1.5 Patch
"InstallShield_{CC862A04-B2B0-4A79-ADD2-4B76D6CF4DCD}" = Call of Duty(R) - World at War(TM) 1.4 Patch
"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM)
"InstallShield_{E237FA24-CFB3-431F-B356-DF8FB116DE4B}" = Call of Duty(R) - World at War(TM) 1.7 Patch
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"Microsoft MSDN 2005 Express Edition - DEU" = Microsoft MSDN 2005 Express Edition - DEU
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual Basic 2005 Express Edition - DEU" = Microsoft Visual Basic 2005 Express Edition - DEU
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"Mozilla Sunbird (0.8)" = Mozilla Sunbird (0.8)
"Mozilla Thunderbird (3.1.9)" = Mozilla Thunderbird (3.1.9)
"MP3 Splitter_is1" = MP3 Splitter version 3.11
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"PhotomatixPro4.0x32_is1" = Photomatix Pro version 4.0.2
"PhotoStitch" = Canon Utilities PhotoStitch
"Picture Style Editor" = Canon Utilities Picture Style Editor
"Pixum Fotobuch" = Pixum Fotobuch
"PunkBusterSvc" = PunkBuster Services
"Revo Uninstaller" = Revo Uninstaller 1.83
"S.T.A.L.K.E.R. - Shadow of Chernobyl_is1" = S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0006]
"Steam App 10180" = Call of Duty: Modern Warfare 2
"Steam App 10190" = Call of Duty: Modern Warfare 2 - Multiplayer
"SysInfo" = Creative Systeminformationen
"SystemRequirementsLab" = System Requirements Lab
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"TVersity Codec Pack" = TVersity Codec Pack 1.4
"TVersity Media Server" = TVersity Media Server 1.9.2
"TVersity Media Server " = TVersity Media Server  1.6 Beta
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VideoLAN VLC media player 0.8.6f
"WFTK" = Canon Utilities WFT Utility
"WinRAR archiver" = WinRAR
"Xfire" = Xfire (remove only)
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent DNA" = DNA
"Facebook Plug-In" = Facebook Plug-In
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 03.04.2010 06:11:00 | Computer Name = ****-PC | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Nero\Nero8\Nero PhotoSnap\PhotoSnapViewer.exe". Fehler in Manifest- oder
Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen bereits aktiven Komponentenversion.  Die widersprüchlichen
 Komponenten sind:  Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
 
Error - 03.04.2010 06:11:00 | Computer Name = ****-PC | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Nero\Nero8\Nero PhotoSnap\PhotoSnap.exe". Fehler in Manifest- oder Richtliniendatei
 "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt
 mit einer anderen bereits aktiven Komponentenversion.  Die widersprüchlichen Komponenten
 sind:  Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
 
Error - 03.04.2010 06:11:00 | Computer Name = ****-PC | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Nero\Nero8\Nero Toolkit\DiscSpeed.exe". Fehler in Manifest- oder Richtliniendatei
 "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt
 mit einer anderen bereits aktiven Komponentenversion.  Die widersprüchlichen Komponenten
 sind:  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
 
Error - 09.04.2010 14:01:50 | Computer Name = ****-PC | Source = Application Hang | ID = 1002
Description = Programm BFBC2Game.exe, Version 1.0.1.0 arbeitet nicht mehr mit Windows
 zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen
 für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem
 zu suchen.  Prozess-ID: c38  Anfangszeit: 01cad80df93e6e8c  Zeitpunkt der Beendigung:
 110
 
Error - 10.04.2010 02:40:41 | Computer Name = ****-PC | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Nero\Nero8\Nero PhotoSnap\PhotoSnapViewer.exe". Fehler in Manifest- oder
Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen bereits aktiven Komponentenversion.  Die widersprüchlichen
 Komponenten sind:  Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
 
Error - 10.04.2010 02:40:41 | Computer Name = ****-PC | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Nero\Nero8\Nero PhotoSnap\PhotoSnap.exe". Fehler in Manifest- oder Richtliniendatei
 "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt
 mit einer anderen bereits aktiven Komponentenversion.  Die widersprüchlichen Komponenten
 sind:  Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
 
Error - 10.04.2010 02:40:42 | Computer Name = ****-PC | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Nero\Nero8\Nero Toolkit\DiscSpeed.exe". Fehler in Manifest- oder Richtliniendatei
 "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt
 mit einer anderen bereits aktiven Komponentenversion.  Die widersprüchlichen Komponenten
 sind:  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
 
Error - 10.04.2010 07:44:21 | Computer Name = ****-PC | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Nero\Nero8\Nero PhotoSnap\PhotoSnapViewer.exe". Fehler in Manifest- oder
Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen bereits aktiven Komponentenversion.  Die widersprüchlichen
 Komponenten sind:  Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
 
Error - 10.04.2010 07:44:22 | Computer Name = ****-PC | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Nero\Nero8\Nero PhotoSnap\PhotoSnap.exe". Fehler in Manifest- oder Richtliniendatei
 "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt
 mit einer anderen bereits aktiven Komponentenversion.  Die widersprüchlichen Komponenten
 sind:  Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
 
Error - 10.04.2010 07:44:23 | Computer Name = ****-PC | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Nero\Nero8\Nero Toolkit\DiscSpeed.exe". Fehler in Manifest- oder Richtliniendatei
 "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt
 mit einer anderen bereits aktiven Komponentenversion.  Die widersprüchlichen Komponenten
 sind:  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
 
[ Media Center Events ]
Error - 03.10.2009 10:20:37 | Computer Name = ****-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerAccumulate failed;
 Win32 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center
 Guide
 
Error - 03.10.2009 12:49:03 | Computer Name = ****-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 05.04.2010 04:32:58 | Computer Name = ****-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 05.04.2010 04:36:04 | Computer Name = ****-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 17.04.2010 12:18:50 | Computer Name = ****-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 17.04.2010 15:11:51 | Computer Name = ****-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 13.06.2010 06:16:37 | Computer Name = ****-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 06.09.2010 15:19:51 | Computer Name = ****-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 06.09.2010 16:21:42 | Computer Name = ****-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 13.02.2011 05:11:24 | Computer Name = ****-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
[ System Events ]
Error - 25.03.2011 13:57:58 | Computer Name = ****-PC | Source = Application Popup | ID = 1060
Description = Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\ASPI32.SYS
 nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version
 des Treibers zu erhalten.
 
Error - 25.03.2011 13:59:34 | Computer Name = ****-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 25.03.2011 13:59:34 | Computer Name = ****-PC | Source = Service Control Manager | ID = 7026
Description =
 
Error - 25.03.2011 14:00:25 | Computer Name = ****-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 25.03.2011 14:00:25 | Computer Name = ****-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 25.03.2011 14:18:20 | Computer Name = ****-PC | Source = Application Popup | ID = 1060
Description = Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\ASPI32.SYS
 nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version
 des Treibers zu erhalten.
 
Error - 25.03.2011 14:19:56 | Computer Name = ****-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 25.03.2011 14:19:56 | Computer Name = ****-PC | Source = Service Control Manager | ID = 7026
Description =
 
Error - 25.03.2011 14:20:49 | Computer Name = ****-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 25.03.2011 14:20:49 | Computer Name = ****-PC | Source = Service Control Manager | ID = 7001
Description =
 
 
< End of report >

--- --- ---


Danke euch schon mal für eure Hilfe :)




NACHTRAG: Es war übrigens nicht XPACK sondern TR/Crypt.ZPACK.Gen

Außerdem hat Antivir jetzt auch noch folgende Mareware gefunden: TR/Kazy.16727.1 und BDS/Cycbot.B.1491

SebastianEF 26.03.2011 14:02

Hallo zusammen,

sorry wenn ich jetzt schon wieder schreibe, ich weiß in den Forenregeln steht was von 3 Tagen Wartezeit. Bei anderen Threads gabs allerdings schon fleißig antworten. Da wollte ich noch mal auf Nummer sicher gehen. :o :dummguck:

Ich habe leider in der Woche keine Zeit Maßnahmen an meinem PC durchzuführen. Ich habe nur am WE Zeit dafür. Deshalb wäre es super wenn sich jemand meldet und mir helfen kann. :dankeschoen:

Schönen Gruß
Sebastian

SebastianEF 26.03.2011 20:22

Geduld war noch nie meine Stärke :taenzer:

Ich habe mal Malwarebytes laufen lassen. Und siehe da, 10 Infizierte Dateien. Anschließend Rechner neu gestartet. Da meldete sich der Windows Defender und meldete zwei Backdoorprogramme. Die gelöscht und noch mal neugestartet. Dann festgestellt das im Firefox ein Proxy eingegeben war. Diesen entfernt.

Nun die Logfile von Malwarebytes

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6176

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

26.03.2011 19:57:07
mbam-log-2011-03-26 (19-57-07).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Durchsuchte Objekte: 382537
Laufzeit: 1 Stunde(n), 15 Minute(n), 44 Sekunde(n)

Infizierte Speicherprozesse: 2
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 3
Infizierte Dateiobjekte der Registrierung: 3
Infizierte Verzeichnisse: 0
Infizierte Dateien: 2

Infizierte Speicherprozesse:
c:\Users\****\AppData\Roaming\microsoft\conhost.exe (Trojan.Agent) -> 772 -> Unloaded process successfully.
c:\Users\****\AppData\Local\Temp\csrss.exe (Trojan.Agent) -> 3184 -> Unloaded process successfully.

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\conhost (Trojan.Agent) -> Value: conhost -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Value: Load -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell.Gen) -> Value: Shell -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Bad: (C:\Users\****\AppData\Local\Temp\csrss.exe) Good: () -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallPaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\Users\****\AppData\Roaming\microsoft\conhost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\****\AppData\Local\Temp\csrss.exe (Trojan.Agent) -> Quarantined and deleted successfully.



Was soll ich nun machen?

SebastianEF 26.03.2011 21:59

Ich möchte echt nicht nerven. Aber kann es sein, dass mein Thread nicht beantwortet wird? Alle anderen haben schon ne Antwort :(

SebastianEF 26.03.2011 22:01

****doppelposting****

cosinus 27.03.2011 20:59

Gibt es noch weitere Logs von Malwarebytes? Wenn ja bitte alle posten, die in Malwarebytes im Reiter Logdateien sichtbar sind.

SebastianEF 28.03.2011 11:06

Hi Cosinus :)

Nee habe Malwarebyte das erste mal genutzt. Habe jetzt noch Super Antispyware laufen lassen, dabei wurde noch mal ein Fund entfernt (Trojaner) und anschließend noch ein Lauf, da war dann nix mehr.

Habe auch CC Cleaner drüber gejagt und nun scheint so als wenn alles weg sei. Aber: Ich trau dem Frieden nicht. Zudem ist mein Desktop noch immer rot und mein Design ist weg. Die Dateien und Programme werden nicht angezeigt. Die Daten sind allerdings noch alle da, wenn ich Dateien suche finde ich sie. So werden sie aber nicht angezeigt und alle Ordner seien leer.

Gruß
Sebastian

cosinus 28.03.2011 11:53

Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.

Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )

SebastianEF 28.03.2011 11:57

Ok. Meinste das kann ich jetzt schon machen, oder sollte ich erstmal noch mal prüfen ob irgendwo was ist?

Kannst du bitte prüfen ob ich alles weghabe? Was brauchst dazu? Logiles von welchen Programmen?

Und die letzte Frage. Habe ne externe HDD. Die habe ich gleich ausgemacht als ich gemerkt habe das ich nen Trojaner habe. Weiß aber nicht ob sie infiziert ist. Wie soll ich vorgehen beim Einschalten? Ich brauch die Daten welche drauf sind.

cosinus 28.03.2011 13:14

Mach erstmal den unhide. Dann gehts weiter mit einem OTL-Fix.

SebastianEF 28.03.2011 13:34

Fertig. Hat super geklappt ist alles wieder sichtbar.

Weiter nun mit OTL? Wie? :heilig:

cosinus 28.03.2011 18:23

Deinstallier erstmal über die Systemsteuerung sämtliche Toolbars die du finden kannst. Wenn nicht alle gehen erstmal überspringen.

Mach danach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Hinweis: Falls Du Deinen Benutzernamen unkenntlich gemacht hast, musst Du das Ausgesternte in Deinen richtigen Benutzernamen wieder verwandeln, sonst funktioniert das Script nicht!!

Code:

:OTL
@Alternate Data Stream - 24 bytes -> C:\Windows:6A7BF95613718B6A
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:6971CCC5
[2011.03.23 21:27:12 | 000,171,008 | -H-- | C] () -- C:\Users\****\AppData\Roaming\dwm.exe
[2011.03.23 21:26:54 | 000,005,686 | -H-- | C] () -- C:\Users\****\AppData\Roaming\A748.111
[2011.03.24 22:04:48 | 000,546,304 | -H-- | M] (FPAV) -- C:\ProgramData\sCRrtWXnjAgI.exe
[2011.03.23 21:27:12 | 000,171,008 | -H-- | M] () -- C:\Users\****\AppData\Roaming\dwm.exe
[2011.03.20 18:41:33 | 000,242,176 | -H-- | M] () -- C:\Users\****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{36d21537-97bb-11df-9a93-001d7dd02838}\Shell - "" = AutoRun
O33 - MountPoints2\{36d21537-97bb-11df-9a93-001d7dd02838}\Shell\AutoRun\command - "" = F:\Startme.exe
O4 - HKLM..\Run: [conhost] C:\Users\****\AppData\Roaming\Microsoft\conhost.exe ()
O4 - HKCU..\Run: [sCRrtWXnjAgI] C:\ProgramData\sCRrtWXnjAgI.exe (FPAV)
O4 - Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files (x86)\Xfire\xfire.exe (Xfire Inc.)
F3:64bit: - HKCU WinNT: Load - (C:\Users\****\AppData\Local\Temp\csrss.exe) - C:\Users\****\AppData\Local\Temp\csrss.exe ()
F3 - HKCU WinNT: Load - (C:\Users\****\AppData\Local\Temp\csrss.exe) - C:\Users\****\AppData\Local\Temp\csrss.exe ()
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 55515
FF - prefs.js..network.proxy.type: 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:55515
PRC - C:\Users\****\AppData\Local\Temp\csrss.exe ()
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

SebastianEF 28.03.2011 18:50

Das mit den Toolbars hat geklappt. Wusste garnicht wie viel Sch... ich da drin hatte :(

So, habe deine Logfile genommen, sie im Editor angepasst zwecks Namen (Ersetze alle **** in den richtigen USER Namen) und hab sie in das Textfeld von OTL eingefügt. Nach dem Fix nun folgendes Logfile:

All processes killed
========== OTL ==========
ADS C:\Windows:6A7BF95613718B6A deleted successfully.
ADS C:\ProgramData\TEMP:6971CCC5 deleted successfully.
File C:\Users\****\AppData\Roaming\dwm.exe not found.
C:\Users\****\AppData\Roaming\A748.111 moved successfully.
File C:\ProgramData\sCRrtWXnjAgI.exe not found.
File C:\Users\****\AppData\Roaming\dwm.exe not found.
C:\Users\****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{36d21537-97bb-11df-9a93-001d7dd02838}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{36d21537-97bb-11df-9a93-001d7dd02838}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{36d21537-97bb-11df-9a93-001d7dd02838}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{36d21537-97bb-11df-9a93-001d7dd02838}\ not found.
File F:\Startme.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\conhost not found.
File C:\Users\****\AppData\Roaming\Microsoft\conhost.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\sCRrtWXnjAgI not found.
File C:\ProgramData\sCRrtWXnjAgI.exe not found.
C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk moved successfully.
C:\Program Files (x86)\Xfire\xfire.exe moved successfully.
File C:\Users\****\AppData\Local\Temp\csrss.exe not found.
64bit-Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\Users\****\AppData\Local\Temp\csrss.exe deleted successfully.
File C:\Users\****\AppData\Local\Temp\csrss.exe not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\Users\****\AppData\Local\Temp\csrss.exe deleted successfully.
Prefs.js: "127.0.0.1" removed from network.proxy.http
Prefs.js: 55515 removed from network.proxy.http_port
Prefs.js: 1 removed from network.proxy.type
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
No active process named csrss.exe was found!
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: AppData

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Sandy
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: ****
->Temp folder emptied: 895482 bytes
->Temporary Internet Files folder emptied: 8194028 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 49760298 bytes
->Flash cache emptied: 456 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3954 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 56,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 03282011_194440

Files\Folders moved on Reboot...
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.

Registry entries deleted on Reboot...

cosinus 28.03.2011 19:46

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

SebastianEF 28.03.2011 20:12

CoFi läuft ja schneller als ich dachte. Hier die Logs:

Combofix Logfile:
Code:

ComboFix 11-03-28.01 - **** 28.03.2011  21:01:59.1.2 - x64
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.4094.2778 [GMT 2:00]
ausgeführt von:: c:\users\****\Desktop\cofi.exe.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\hpeAF06.dll
c:\users\****\eac-0.99pb3.exe
c:\users\****\EULA.txt
c:\users\****\EZCD_Setup.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-02-28 bis 2011-03-28  ))))))))))))))))))))))))))))))
.
.
2011-03-28 17:44 . 2011-03-28 17:44        --------        d-----w-        C:\_OTL
2011-03-28 15:08 . 2011-03-15 05:17        8424784        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{C2BB97D4-342C-4664-BC3A-7DC769C7E215}\mpengine.dll
2011-03-26 19:51 . 2011-03-26 19:51        --------        d-----w-        c:\programdata\SUPERAntiSpyware.com
2011-03-26 19:51 . 2011-03-26 19:51        --------        d-----w-        c:\users\****\AppData\Roaming\SUPERAntiSpyware.com
2011-03-26 19:51 . 2011-03-26 19:51        --------        d-----w-        c:\programdata\!SASCORE
2011-03-26 19:51 . 2011-03-28 13:44        --------        d-----w-        c:\program files\SUPERAntiSpyware
2011-03-26 17:31 . 2011-03-26 17:31        --------        d-----w-        c:\users\****\AppData\Roaming\Malwarebytes
2011-03-26 17:31 . 2011-03-26 17:31        --------        d-----w-        c:\programdata\Malwarebytes
2011-03-26 17:31 . 2010-12-20 17:09        38224        ----a-w-        c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-03-26 17:31 . 2011-03-26 17:31        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2011-03-26 17:31 . 2010-12-20 17:08        24152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-03-25 18:22 . 2011-03-25 18:22        --------        d-----w-        c:\program files (x86)\ERUNT
2011-03-20 09:43 . 2011-03-20 09:43        --------        d-----w-        c:\program files (x86)\PhotomatixPro4
2011-03-20 09:43 . 2011-03-20 09:43        --------        d-----w-        c:\users\****\AppData\Roaming\HDRsoft
2011-03-09 22:24 . 2010-12-17 17:34        2425344        ----a-w-        c:\windows\system32\mstscax.dll
2011-03-09 22:24 . 2010-12-17 15:45        2067968        ----a-w-        c:\windows\SysWow64\mstscax.dll
2011-03-09 22:24 . 2010-12-17 15:41        731136        ----a-w-        c:\windows\system32\mstsc.exe
2011-03-09 22:24 . 2010-12-17 13:54        677888        ----a-w-        c:\windows\SysWow64\mstsc.exe
2011-03-09 22:24 . 2010-12-29 19:01        416768        ----a-w-        c:\windows\system32\sbe.dll
2011-03-09 22:24 . 2010-12-29 19:01        559616        ----a-w-        c:\windows\system32\EncDec.dll
2011-03-09 22:24 . 2010-12-29 18:28        429056        ----a-w-        c:\windows\SysWow64\EncDec.dll
2011-03-09 22:24 . 2010-12-29 19:01        210944        ----a-w-        c:\windows\system32\sbeio.dll
2011-03-09 22:24 . 2010-12-29 18:59        226816        ----a-w-        c:\windows\system32\mpg2splt.ax
2011-03-09 22:24 . 2010-12-29 18:28        322560        ----a-w-        c:\windows\SysWow64\sbe.dll
2011-03-09 22:24 . 2010-12-29 18:28        153088        ----a-w-        c:\windows\SysWow64\sbeio.dll
2011-03-09 22:24 . 2010-12-29 18:26        177664        ----a-w-        c:\windows\SysWow64\mpg2splt.ax
2011-03-07 19:36 . 2011-03-07 19:36        --------        d-----w-        c:\users\****\AppData\Roaming\Avira
2011-02-27 10:43 . 2011-02-27 10:43        --------        d-----w-        c:\users\****\AppData\Roaming\ZoomBrowser EX
2011-02-27 10:37 . 2011-02-27 10:41        --------        d-----w-        c:\users\****\AppData\Local\CANON_INC
2011-02-27 10:35 . 2011-02-27 10:35        --------        d-----w-        c:\users\****\AppData\Roaming\Canon
2011-02-27 10:33 . 2011-02-27 10:33        --------        d-----w-        c:\programdata\ZoomBrowser
2011-02-27 10:32 . 2011-02-27 10:34        --------        d-----w-        c:\program files (x86)\Canon
2011-02-27 10:31 . 2011-02-27 10:31        --------        d-----w-        c:\program files (x86)\Common Files\Canon
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-26 01:19 . 2011-02-26 01:19        41872        ----a-w-        c:\windows\SysWow64\xfcodec.dll
2011-02-26 01:19 . 2011-02-26 01:19        27536        ----a-w-        c:\windows\system32\xfcodec64.dll
2011-02-02 20:40 . 2010-04-16 17:39        472808        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2011-02-02 16:11 . 2009-10-03 13:10        270720        ------w-        c:\windows\system32\MpSigStub.exe
2011-01-18 18:57 . 2009-03-24 20:26        270776        ----a-w-        c:\windows\SysWow64\PnkBstrB.xtr
2011-01-18 18:57 . 2008-04-10 22:00        270776        ----a-w-        c:\windows\SysWow64\PnkBstrB.exe
2011-01-18 18:56 . 2008-04-10 22:00        215152        ----a-w-        c:\windows\SysWow64\PnkBstrB.ex0
2011-01-15 13:49 . 2008-04-10 22:00        75136        ----a-w-        c:\windows\SysWow64\PnkBstrA.exe
2011-01-08 09:03 . 2011-02-09 20:30        48128        ----a-w-        c:\windows\system32\atmlib.dll
2011-01-08 08:47 . 2011-02-09 20:30        34304        ----a-w-        c:\windows\SysWow64\atmlib.dll
2011-01-08 06:45 . 2011-02-09 20:30        367104        ----a-w-        c:\windows\system32\atmfd.dll
2011-01-08 06:28 . 2011-02-09 20:30        292352        ----a-w-        c:\windows\SysWow64\atmfd.dll
2011-01-08 03:27 . 2011-02-12 09:09        7729256        ----a-w-        c:\windows\system32\nvwgf2umx.dll
2011-01-08 03:27 . 2011-02-12 09:09        67176        ----a-w-        c:\windows\system32\OpenCL.dll
2011-01-08 03:27 . 2011-02-12 09:09        6604904        ----a-w-        c:\windows\system32\nvcuda.dll
2011-01-08 03:27 . 2011-02-12 09:09        57960        ----a-w-        c:\windows\SysWow64\OpenCL.dll
2011-01-08 03:27 . 2011-02-12 09:09        5653096        ----a-w-        c:\windows\SysWow64\nvwgf2um.dll
2011-01-08 03:27 . 2011-02-12 09:09        4941928        ----a-w-        c:\windows\SysWow64\nvcuda.dll
2011-01-08 03:27 . 2011-02-12 09:09        3112040        ----a-w-        c:\windows\system32\nvcuvid.dll
2011-01-08 03:27 . 2011-02-12 09:09        2895976        ----a-w-        c:\windows\SysWow64\nvcuvid.dll
2011-01-08 03:27 . 2011-02-12 09:09        2479720        ----a-w-        c:\windows\system32\nvcuvenc.dll
2011-01-08 03:27 . 2011-02-12 09:09        2251368        ----a-w-        c:\windows\SysWow64\nvcuvenc.dll
2011-01-08 03:27 . 2011-02-12 09:09        20471912        ----a-w-        c:\windows\system32\nvoglv64.dll
2011-01-08 03:27 . 2011-02-12 09:09        1965672        ----a-w-        c:\windows\SysWow64\nvapi.dll
2011-01-08 03:27 . 2011-02-12 09:09        18580072        ----a-w-        c:\windows\system32\nvcompiler.dll
2011-01-08 03:27 . 2011-02-12 09:09        1614440        ----a-w-        c:\windows\system32\nvdispco642090.dll
2011-01-08 03:27 . 2011-02-12 09:09        15047272        ----a-w-        c:\windows\SysWow64\nvoglv32.dll
2011-01-08 03:27 . 2011-02-12 09:09        1359976        ----a-w-        c:\windows\system32\nvgenco642040.dll
2011-01-08 03:27 . 2011-02-12 09:09        13011560        ----a-w-        c:\windows\SysWow64\nvcompiler.dll
2011-01-08 03:27 . 2011-02-12 09:09        12961640        ----a-w-        c:\windows\system32\drivers\nvlddmkm.sys
2011-01-08 03:27 . 2011-02-12 09:09        10078312        ----a-w-        c:\windows\SysWow64\nvd3dum.dll
2011-01-08 03:27 . 2007-12-11 15:06        2200680        ----a-w-        c:\windows\system32\nvapi64.dll
2011-01-08 03:27 . 2007-12-11 15:06        12859496        ----a-w-        c:\windows\system32\nvd3dumx.dll
2011-01-07 19:50 . 2011-01-07 19:50        795752        ----a-w-        c:\windows\system32\easyUpdatusAPIU64.dll
2011-01-07 19:50 . 2011-01-07 19:50        6143080        ----a-w-        c:\windows\system32\nvcpl.dll
2011-01-07 19:49 . 2011-01-07 19:49        3156072        ----a-w-        c:\windows\system32\nvsvc64.dll
2011-01-07 19:49 . 2011-01-07 19:49        117864        ----a-w-        c:\windows\system32\nvmctray.dll
2011-01-07 19:49 . 2011-01-07 19:49        2558568        ----a-w-        c:\windows\system32\nvsvcr.dll
2011-01-07 19:49 . 2011-01-07 19:49        1005160        ----a-w-        c:\windows\system32\nvvsvc.exe
2010-12-31 14:16 . 2011-02-09 20:30        2757632        ----a-w-        c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"Steam"="c:\program files (x86)\steam\steam.exe" [2010-11-17 1242448]
"Sony Ericsson PC Suite"="c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2009-11-20 434176]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-03-16 2988488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NBKeyScan"="c:\program files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"V0330Mon.exe"="c:\windows\V0330Mon.exe" [2007-04-30 32768]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-11-11 281768]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-2-8 113664]
Logitech SetPoint.lnk - c:\programme\Logitech\SetPoint\SetPoint.exe [2008-7-13 1196048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 gupdate1c9f673eccd7262;Google Update Service (gupdate1c9f673eccd7262);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-06-26 133104]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [x]
R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [x]
R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [x]
R3 s1029bus;Sony Ericsson Device 1029 driver (WDM);c:\windows\system32\DRIVERS\s1029bus.sys [x]
R3 s1029mdfl;Sony Ericsson Device 1029 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1029mdfl.sys [x]
R3 s1029mdm;Sony Ericsson Device 1029 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1029mdm.sys [x]
R3 s1029mgmt;Sony Ericsson Device 1029 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1029mgmt.sys [x]
R3 s1029nd5;Sony Ericsson Device 1029 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1029nd5.sys [x]
R3 s1029obex;Sony Ericsson Device 1029 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1029obex.sys [x]
R3 s1029unic;Sony Ericsson Device 1029 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1029unic.sys [x]
R3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\DRIVERS\s115bus.sys [x]
R3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s115mdfl.sys [x]
R3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s115mdm.sys [x]
R3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s115mgmt.sys [x]
R3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s115obex.sys [x]
R3 s816bus;Sony Ericsson Device 816 driver (WDM);c:\windows\system32\DRIVERS\s816bus.sys [x]
R3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s816mdfl.sys [x]
R3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s816mdm.sys [x]
R3 s816mgmt;Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s816mgmt.sys [x]
R3 s816nd5;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS);c:\windows\system32\DRIVERS\s816nd5.sys [x]
R3 s816obex;Sony Ericsson Device 816 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s816obex.sys [x]
R3 s816unic;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM);c:\windows\system32\DRIVERS\s816unic.sys [x]
R3 Ser2pl64;Prolific Serial port driver;c:\windows\system32\DRIVERS\ser2pl64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\system32\DRIVERS\rtlprot.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2010-11-11 135336]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
S3 RTL85n64;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;c:\windows\system32\DRIVERS\RTL85n64.sys [x]
S3 V0330VID;WebCam Vista/Live! Cam Chat;c:\windows\system32\DRIVERS\V0330Vid.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2011-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-06-26 15:36]
.
2011-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-06-26 15:36]
.
2011-03-28 c:\windows\Tasks\RtlVistaStart.job
- c:\program files (x86)\REALTEK PCI&Cardbus Wireless LAN Driver and Utility\RtWLan.exe [2008-04-10 11:11]
.
2011-03-28 c:\windows\Tasks\User_Feed_Synchronization-{E6D8AD8D-8C04-436D-8FED-9272D6C69435}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:50]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [X]
"RtHDVCpl"="RAVCpl64.exe" [2008-02-13 5684736]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"Launch LgDevAgt"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2007-12-13 374808]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2007-12-13 3040280]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 242192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
mLocal Page = %SystemRoot%\system32\blank.htm
IE: Free YouTube to Mp3 Converter - c:\users\****\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft &Excel exportieren - c:\programme\Microsoft Office\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\****\AppData\Roaming\Mozilla\Firefox\Profiles\v4itc736.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.de
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: network.proxy.type - 0
FF - Ext: eBay Sidebar for Firefox: {62760FD6-B943-48C9-AB09-F99C6FE96088} - %profile%\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}
FF - Ext: Aero Fox XL: {5c8bfb7c-9a54-11dc-8314-0800200c9a66} - %profile%\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
FF - Ext: Simple Dyyno Launcher: NPDyyno@dyyno.com - %profile%\extensions\NPDyyno@dyyno.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Stylish: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8} - %profile%\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Ext: Virtus Search Opt-in: extension@virtusdesigns.com - %profile%\extensions\extension@virtusdesigns.com
FF - Ext: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - %profile%\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: Elf 1.13 Community Toolbar: {b80f591e-fe9a-46cf-a13e-180377240586} - %profile%\extensions\{b80f591e-fe9a-46cf-a13e-180377240586}
FF - Ext: Productivity 2 Community Toolbar: {795828a9-f271-43a8-8536-4484bb991d3d} - %profile%\extensions\{795828a9-f271-43a8-8536-4484bb991d3d}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Google Gears: {000a9d1c-beef-4f90-9363-039d445309b8} - c:\program files (x86)\Google\Google Gears\Firefox
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
Wow6432Node-HKLM-Run-NWEReboot - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_bc2.exe
AddRemove-{D6BF6477-8369-489F-8DE6-3731F4B88560} - c:\windows\Installer\{D6BF6477-8369-489F-8DE6-3731F4B88560}\setup.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2011-03-28  21:08:37
ComboFix-quarantined-files.txt  2011-03-28 19:08
.
Vor Suchlauf: 12 Verzeichnis(se), 84.154.937.344 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 84.059.504.640 Bytes frei
.
- - End Of File - - 658092516DFD5ECAE2031098A7799C3C

--- --- ---

SebastianEF 29.03.2011 08:05

Passt jetzt alles oder was soll ich noch machen? Wie gehe ich mit der externen HDD vor?

Danke und Gruß
Sebastian

cosinus 29.03.2011 15:36

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

SebastianEF 29.03.2011 15:53

Habe ich gemacht. Ging aber sehr schnell und so wie es in der Anleitung dargestellt wurde, sieht es garnicht aus... habe ich was falsch gemacht. Ging auch alles innerhalb weniger Sekunden und Neustart war auch nicht.

Aber hier mal der Report/Logfile:

2011/03/29 16:48:37.0783 3336 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/03/29 16:48:38.0158 3336 ================================================================================
2011/03/29 16:48:38.0158 3336 SystemInfo:
2011/03/29 16:48:38.0158 3336
2011/03/29 16:48:38.0158 3336 OS Version: 6.0.6002 ServicePack: 2.0
2011/03/29 16:48:38.0158 3336 Product type: Workstation
2011/03/29 16:48:38.0158 3336 ComputerName: ****-PC
2011/03/29 16:48:38.0173 3336 UserName: ****
2011/03/29 16:48:38.0173 3336 Windows directory: C:\Windows
2011/03/29 16:48:38.0173 3336 System windows directory: C:\Windows
2011/03/29 16:48:38.0173 3336 Running under WOW64
2011/03/29 16:48:38.0173 3336 Processor architecture: Intel x64
2011/03/29 16:48:38.0173 3336 Number of processors: 2
2011/03/29 16:48:38.0173 3336 Page size: 0x1000
2011/03/29 16:48:38.0173 3336 Boot type: Normal boot
2011/03/29 16:48:38.0173 3336 ================================================================================
2011/03/29 16:48:46.0317 3336 Initialize success
2011/03/29 16:49:15.0785 3484 ================================================================================
2011/03/29 16:49:15.0816 3484 Scan started
2011/03/29 16:49:15.0816 3484 Mode: Manual;
2011/03/29 16:49:15.0816 3484 ================================================================================
2011/03/29 16:49:18.0827 3484 ACPI (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
2011/03/29 16:49:19.0966 3484 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
2011/03/29 16:49:20.0044 3484 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
2011/03/29 16:49:20.0122 3484 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
2011/03/29 16:49:20.0184 3484 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
2011/03/29 16:49:20.0278 3484 AFD (12415ccfd3e7cec55b5184e67b039fe4) C:\Windows\system32\drivers\afd.sys
2011/03/29 16:49:20.0325 3484 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
2011/03/29 16:49:20.0371 3484 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
2011/03/29 16:49:20.0590 3484 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
2011/03/29 16:49:20.0808 3484 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
2011/03/29 16:49:20.0855 3484 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
2011/03/29 16:49:20.0980 3484 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
2011/03/29 16:49:21.0011 3484 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
2011/03/29 16:49:21.0073 3484 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/03/29 16:49:21.0105 3484 atapi (e68d9b3a3905619732f7fe039466a623) C:\Windows\system32\drivers\atapi.sys
2011/03/29 16:49:21.0167 3484 avgntflt (39c2e2870fc0c2ae0595b883cbe716b4) C:\Windows\system32\DRIVERS\avgntflt.sys
2011/03/29 16:49:21.0245 3484 avipbb (c98fa6e5ad0e857d22716bd2b8b1f399) C:\Windows\system32\DRIVERS\avipbb.sys
2011/03/29 16:49:21.0339 3484 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
2011/03/29 16:49:21.0385 3484 bowser (8b2b19031d0aeade6e1b933df1acba7e) C:\Windows\system32\DRIVERS\bowser.sys
2011/03/29 16:49:21.0417 3484 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
2011/03/29 16:49:21.0448 3484 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
2011/03/29 16:49:21.0479 3484 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
2011/03/29 16:49:21.0495 3484 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
2011/03/29 16:49:21.0541 3484 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
2011/03/29 16:49:21.0557 3484 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
2011/03/29 16:49:21.0588 3484 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
2011/03/29 16:49:21.0666 3484 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
2011/03/29 16:49:21.0729 3484 cdrom (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
2011/03/29 16:49:22.0056 3484 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
2011/03/29 16:49:22.0259 3484 CLFS (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
2011/03/29 16:49:22.0540 3484 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
2011/03/29 16:49:22.0618 3484 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\drivers\compbatt.sys
2011/03/29 16:49:22.0649 3484 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
2011/03/29 16:49:22.0883 3484 DfsC (36cd31121f228e7e79bae60aa45764c6) C:\Windows\system32\Drivers\dfsc.sys
2011/03/29 16:49:23.0133 3484 disk (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
2011/03/29 16:49:23.0445 3484 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
2011/03/29 16:49:24.0084 3484 DXGKrnl (e828cdca431d1f98d33501dfc390079a) C:\Windows\System32\drivers\dxgkrnl.sys
2011/03/29 16:49:24.0771 3484 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
2011/03/29 16:49:25.0051 3484 Ecache (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
2011/03/29 16:49:25.0223 3484 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
2011/03/29 16:49:25.0379 3484 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
2011/03/29 16:49:25.0660 3484 exfat (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
2011/03/29 16:49:26.0065 3484 fastfat (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
2011/03/29 16:49:26.0440 3484 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
2011/03/29 16:49:26.0674 3484 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
2011/03/29 16:49:26.0814 3484 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
2011/03/29 16:49:27.0079 3484 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/03/29 16:49:27.0235 3484 FltMgr (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
2011/03/29 16:49:27.0657 3484 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
2011/03/29 16:49:28.0078 3484 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
2011/03/29 16:49:28.0203 3484 HdAudAddService (df45f8142dc6df9d18c39b3effbd0409) C:\Windows\system32\drivers\HdAudio.sys
2011/03/29 16:49:28.0405 3484 HDAudBus (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/03/29 16:49:28.0452 3484 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
2011/03/29 16:49:28.0499 3484 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
2011/03/29 16:49:28.0561 3484 HidUsb (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
2011/03/29 16:49:28.0593 3484 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
2011/03/29 16:49:28.0639 3484 HTTP (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
2011/03/29 16:49:28.0686 3484 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
2011/03/29 16:49:28.0717 3484 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/03/29 16:49:28.0764 3484 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
2011/03/29 16:49:28.0795 3484 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
2011/03/29 16:49:28.0936 3484 IntcAzAudAddService (197ebb23caac8a29a5f166d186c5a117) C:\Windows\system32\drivers\RTKVHD64.sys
2011/03/29 16:49:28.0967 3484 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
2011/03/29 16:49:29.0014 3484 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
2011/03/29 16:49:29.0092 3484 IpFilterDriver (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/03/29 16:49:29.0139 3484 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
2011/03/29 16:49:29.0170 3484 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
2011/03/29 16:49:29.0201 3484 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
2011/03/29 16:49:29.0217 3484 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
2011/03/29 16:49:29.0279 3484 iScsiPrt (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/03/29 16:49:29.0310 3484 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
2011/03/29 16:49:29.0357 3484 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
2011/03/29 16:49:29.0373 3484 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/03/29 16:49:29.0404 3484 kbdhid (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/03/29 16:49:29.0451 3484 KSecDD (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys
2011/03/29 16:49:29.0482 3484 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
2011/03/29 16:49:29.0529 3484 LHidFilt (aa3d903c5a7538803f2400a8391f1881) C:\Windows\system32\DRIVERS\LHidFilt.Sys
2011/03/29 16:49:29.0575 3484 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
2011/03/29 16:49:29.0607 3484 LMouFilt (90b4b2b0b5f05abb9fb365405a7b825b) C:\Windows\system32\DRIVERS\LMouFilt.Sys
2011/03/29 16:49:29.0638 3484 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
2011/03/29 16:49:29.0669 3484 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
2011/03/29 16:49:29.0700 3484 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
2011/03/29 16:49:29.0731 3484 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
2011/03/29 16:49:29.0778 3484 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
2011/03/29 16:49:29.0825 3484 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
2011/03/29 16:49:30.0012 3484 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
2011/03/29 16:49:30.0137 3484 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
2011/03/29 16:49:30.0215 3484 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
2011/03/29 16:49:30.0293 3484 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
2011/03/29 16:49:30.0324 3484 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
2011/03/29 16:49:30.0355 3484 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
2011/03/29 16:49:30.0402 3484 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
2011/03/29 16:49:30.0433 3484 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
2011/03/29 16:49:30.0480 3484 MRxDAV (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
2011/03/29 16:49:30.0527 3484 mrxsmb (d58d129e26705e83a4deba7177eb7972) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/03/29 16:49:30.0558 3484 mrxsmb10 (d5be5c14e0f1dc489f5bb2a67983f630) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/03/29 16:49:30.0574 3484 mrxsmb20 (09a2990c3b293c212816c9bc0d7c200e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/03/29 16:49:30.0605 3484 msahci (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys
2011/03/29 16:49:30.0636 3484 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
2011/03/29 16:49:30.0683 3484 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
2011/03/29 16:49:30.0699 3484 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
2011/03/29 16:49:30.0730 3484 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
2011/03/29 16:49:30.0761 3484 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/03/29 16:49:30.0777 3484 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
2011/03/29 16:49:30.0917 3484 MsRPC (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
2011/03/29 16:49:30.0979 3484 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/03/29 16:49:31.0026 3484 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
2011/03/29 16:49:31.0057 3484 Mup (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
2011/03/29 16:49:31.0104 3484 NativeWifiP (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
2011/03/29 16:49:31.0167 3484 NDIS (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
2011/03/29 16:49:31.0213 3484 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/03/29 16:49:31.0276 3484 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/03/29 16:49:31.0323 3484 NdisWan (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/03/29 16:49:31.0401 3484 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
2011/03/29 16:49:31.0479 3484 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
2011/03/29 16:49:31.0588 3484 netbt (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
2011/03/29 16:49:31.0635 3484 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
2011/03/29 16:49:31.0806 3484 Npfs (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
2011/03/29 16:49:32.0243 3484 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
2011/03/29 16:49:32.0758 3484 Ntfs (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
2011/03/29 16:49:33.0304 3484 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
2011/03/29 16:49:36.0143 3484 nvlddmkm (f12c5f17d48d9f5c70e4408b3ccb5443) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/03/29 16:49:36.0549 3484 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
2011/03/29 16:49:37.0032 3484 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
2011/03/29 16:49:37.0656 3484 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
2011/03/29 16:49:38.0577 3484 ohci1394 (7b58953e2f263421fdbb09a192712a85) C:\Windows\system32\drivers\ohci1394.sys
2011/03/29 16:49:38.0951 3484 Parport (4c6a7fd04ddf4db88791048382e3edb1) C:\Windows\system32\DRIVERS\parport.sys
2011/03/29 16:49:39.0731 3484 partmgr (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys
2011/03/29 16:49:39.0965 3484 pci (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
2011/03/29 16:49:40.0246 3484 pciide (2657f6c0b78c36d95034be109336e382) C:\Windows\system32\drivers\pciide.sys
2011/03/29 16:49:40.0839 3484 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
2011/03/29 16:49:41.0400 3484 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
2011/03/29 16:49:41.0915 3484 PptpMiniport (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
2011/03/29 16:49:42.0133 3484 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
2011/03/29 16:49:42.0523 3484 PSched (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
2011/03/29 16:49:43.0444 3484 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
2011/03/29 16:49:44.0037 3484 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
2011/03/29 16:49:44.0567 3484 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
2011/03/29 16:49:44.0707 3484 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
2011/03/29 16:49:44.0832 3484 Rasl2tp (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/03/29 16:49:45.0004 3484 RasPppoe (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/03/29 16:49:45.0207 3484 RasSstp (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
2011/03/29 16:49:45.0597 3484 rdbss (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
2011/03/29 16:49:45.0768 3484 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/03/29 16:49:45.0971 3484 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys
2011/03/29 16:49:46.0174 3484 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
2011/03/29 16:49:46.0267 3484 RDPWD (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys
2011/03/29 16:49:46.0408 3484 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
2011/03/29 16:49:46.0611 3484 RTL8169 (479f29909b9a48726a07971662f77316) C:\Windows\system32\DRIVERS\Rtlh64.sys
2011/03/29 16:49:46.0767 3484 RTL85n64 (8f41da39d89886d7282751ec58579811) C:\Windows\system32\DRIVERS\RTL85n64.sys
2011/03/29 16:49:46.0907 3484 RtlProt (d1664991a07acf2703d4a4e5be4b6c80) C:\Windows\system32\DRIVERS\rtlprot.sys
2011/03/29 16:49:47.0063 3484 s0016bus (ea268bce30691c2dd24f02e617fd2eb5) C:\Windows\system32\DRIVERS\s0016bus.sys
2011/03/29 16:49:47.0313 3484 s0016mdfl (f5f9deb89996d333ef976624d37e24e3) C:\Windows\system32\DRIVERS\s0016mdfl.sys
2011/03/29 16:49:47.0484 3484 s0016mdm (c17ce2aee67480febcc36eccb54c0be8) C:\Windows\system32\DRIVERS\s0016mdm.sys
2011/03/29 16:49:47.0609 3484 s1029bus (68f717bc57b0fe12011eb9517c97f78d) C:\Windows\system32\DRIVERS\s1029bus.sys
2011/03/29 16:49:47.0781 3484 s1029mdfl (fcfafa529f4fa27b02fce1e52a84922e) C:\Windows\system32\DRIVERS\s1029mdfl.sys
2011/03/29 16:49:47.0952 3484 s1029mdm (35bd0866eb422ab2d7c8f0ddcc67bf7c) C:\Windows\system32\DRIVERS\s1029mdm.sys
2011/03/29 16:49:48.0139 3484 s1029mgmt (e0fd4f4f42b76e910cc4295c97aa30ba) C:\Windows\system32\DRIVERS\s1029mgmt.sys
2011/03/29 16:49:48.0327 3484 s1029nd5 (90276f1d842eb96f82510e73fdb792ad) C:\Windows\system32\DRIVERS\s1029nd5.sys
2011/03/29 16:49:48.0607 3484 s1029obex (128ed45223fab846e8436a2f2baebb55) C:\Windows\system32\DRIVERS\s1029obex.sys
2011/03/29 16:49:49.0153 3484 s1029unic (400fc5591586a1dfecf7a0cfaa6b0d68) C:\Windows\system32\DRIVERS\s1029unic.sys
2011/03/29 16:49:49.0247 3484 s115bus (e0f0977caafdf719929c8ca02a1c5147) C:\Windows\system32\DRIVERS\s115bus.sys
2011/03/29 16:49:49.0309 3484 s115mdfl (136328e6c3086a19eb3154058bc7b3a3) C:\Windows\system32\DRIVERS\s115mdfl.sys
2011/03/29 16:49:49.0372 3484 s115mdm (54552277de7eae1a2e108a4cff7abb07) C:\Windows\system32\DRIVERS\s115mdm.sys
2011/03/29 16:49:49.0403 3484 s115mgmt (e9b3966836cb9c2107264e44249267df) C:\Windows\system32\DRIVERS\s115mgmt.sys
2011/03/29 16:49:49.0434 3484 s115obex (f6ab3b6e35981c4f3fed4198d3f29674) C:\Windows\system32\DRIVERS\s115obex.sys
2011/03/29 16:49:49.0481 3484 s816bus (81f778d9f3f71f48f498ca1f773d1539) C:\Windows\system32\DRIVERS\s816bus.sys
2011/03/29 16:49:49.0512 3484 s816mdfl (3f4e14192b72a148dd508329e04affd4) C:\Windows\system32\DRIVERS\s816mdfl.sys
2011/03/29 16:49:49.0559 3484 s816mdm (17a29b53dfd7e9cd8043b7adadb83f22) C:\Windows\system32\DRIVERS\s816mdm.sys
2011/03/29 16:49:49.0590 3484 s816mgmt (f9ba1c5df3854d36ea1f7086feb97643) C:\Windows\system32\DRIVERS\s816mgmt.sys
2011/03/29 16:49:49.0653 3484 s816nd5 (0323c1accd67844304d69e6bfd93e52d) C:\Windows\system32\DRIVERS\s816nd5.sys
2011/03/29 16:49:49.0684 3484 s816obex (f8e19bfb8a67407cd54c5fd63f7b3c17) C:\Windows\system32\DRIVERS\s816obex.sys
2011/03/29 16:49:49.0731 3484 s816unic (b8a998b3a7d6da10221d479e4dde5ef7) C:\Windows\system32\DRIVERS\s816unic.sys
2011/03/29 16:49:49.0809 3484 SASDIFSV (99df79c258b3342b6c8a5f802998de56) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
2011/03/29 16:49:49.0824 3484 SASKUTIL (2859c35c0651e8eb0d86d48e740388f2) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
2011/03/29 16:49:49.0871 3484 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
2011/03/29 16:49:49.0949 3484 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2011/03/29 16:49:49.0980 3484 Ser2pl64 (93189722b4e685b8a655bf340c2a292b) C:\Windows\system32\DRIVERS\ser2pl64.sys
2011/03/29 16:49:50.0027 3484 Serenum (2449316316411d65bd2c761a6ffb2ce2) C:\Windows\system32\DRIVERS\serenum.sys
2011/03/29 16:49:50.0105 3484 Serial (4b438170be2fc8e0bd35ee87a960f84f) C:\Windows\system32\DRIVERS\serial.sys
2011/03/29 16:49:50.0214 3484 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
2011/03/29 16:49:50.0292 3484 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
2011/03/29 16:49:50.0339 3484 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
2011/03/29 16:49:50.0401 3484 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
2011/03/29 16:49:50.0464 3484 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys
2011/03/29 16:49:50.0635 3484 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
2011/03/29 16:49:50.0760 3484 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
2011/03/29 16:49:50.0963 3484 Smb (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
2011/03/29 16:49:51.0415 3484 spldr (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
2011/03/29 16:49:51.0915 3484 sptd (88e5162e58c8919cc873f5d8946197cf) C:\Windows\system32\Drivers\sptd.sys
2011/03/29 16:49:51.0915 3484 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 88e5162e58c8919cc873f5d8946197cf
2011/03/29 16:49:51.0977 3484 sptd - detected Locked file (1)
2011/03/29 16:49:52.0195 3484 srv (8cd33a47ca02c79038b669f31f95bdac) C:\Windows\system32\DRIVERS\srv.sys
2011/03/29 16:49:52.0336 3484 srv2 (1bedf533096c56e70f87e3e3ee02caf5) C:\Windows\system32\DRIVERS\srv2.sys
2011/03/29 16:49:52.0398 3484 srvnet (2b8c340f830c465f514d966f7e6a822f) C:\Windows\system32\DRIVERS\srvnet.sys
2011/03/29 16:49:52.0476 3484 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
2011/03/29 16:49:52.0523 3484 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
2011/03/29 16:49:52.0554 3484 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
2011/03/29 16:49:52.0585 3484 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
2011/03/29 16:49:52.0663 3484 Tcpip (973658a2ea9c06b2976884b9046dfc6c) C:\Windows\system32\drivers\tcpip.sys
2011/03/29 16:49:52.0741 3484 Tcpip6 (973658a2ea9c06b2976884b9046dfc6c) C:\Windows\system32\DRIVERS\tcpip.sys
2011/03/29 16:49:52.0788 3484 tcpipreg (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys
2011/03/29 16:49:52.0819 3484 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
2011/03/29 16:49:52.0851 3484 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
2011/03/29 16:49:52.0929 3484 tdx (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
2011/03/29 16:49:52.0960 3484 TermDD (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
2011/03/29 16:49:53.0022 3484 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/03/29 16:49:53.0053 3484 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
2011/03/29 16:49:53.0116 3484 tunnel (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
2011/03/29 16:49:53.0147 3484 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
2011/03/29 16:49:53.0194 3484 udfs (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
2011/03/29 16:49:53.0256 3484 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
2011/03/29 16:49:53.0334 3484 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
2011/03/29 16:49:53.0381 3484 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
2011/03/29 16:49:53.0428 3484 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
2011/03/29 16:49:53.0490 3484 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
2011/03/29 16:49:53.0537 3484 usbaudio (c6ba890de6e41857fbe84175519cae7d) C:\Windows\system32\drivers\usbaudio.sys
2011/03/29 16:49:53.0584 3484 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/03/29 16:49:53.0615 3484 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
2011/03/29 16:49:53.0646 3484 usbehci (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
2011/03/29 16:49:53.0693 3484 usbhub (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
2011/03/29 16:49:53.0724 3484 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
2011/03/29 16:49:53.0771 3484 usbprint (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys
2011/03/29 16:49:53.0802 3484 usbscan (ea0bf666868964fbe8cb10e50c97b9f1) C:\Windows\system32\DRIVERS\usbscan.sys
2011/03/29 16:49:53.0833 3484 USBSTOR (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/03/29 16:49:53.0865 3484 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/03/29 16:49:53.0974 3484 V0330VID (3fbb9df34e7a41c53904521e084b5294) C:\Windows\system32\DRIVERS\V0330Vid.sys
2011/03/29 16:49:54.0067 3484 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/03/29 16:49:54.0145 3484 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
2011/03/29 16:49:54.0364 3484 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
2011/03/29 16:49:54.0411 3484 volmgr (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
2011/03/29 16:49:54.0489 3484 volmgrx (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
2011/03/29 16:49:54.0707 3484 volsnap (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
2011/03/29 16:49:54.0847 3484 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
2011/03/29 16:49:54.0925 3484 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
2011/03/29 16:49:55.0003 3484 Wanarp (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
2011/03/29 16:49:55.0035 3484 Wanarpv6 (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
2011/03/29 16:49:55.0113 3484 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
2011/03/29 16:49:55.0269 3484 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
2011/03/29 16:49:55.0393 3484 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\drivers\wmiacpi.sys
2011/03/29 16:49:55.0487 3484 WpdUsb (6329d1990db931073b86ab5946d8e317) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/03/29 16:49:55.0549 3484 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
2011/03/29 16:49:55.0627 3484 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/03/29 16:49:55.0690 3484 ================================================================================
2011/03/29 16:49:55.0690 3484 Scan finished
2011/03/29 16:49:55.0690 3484 ================================================================================
2011/03/29 16:49:55.0705 2612 Detected object count: 1
2011/03/29 16:50:03.0724 2612 Locked file(sptd) - User select action: Skip

cosinus 29.03.2011 17:00

Bitte nun Logs mit GMER und mbrcheck erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg

Anleitung zu mbrcheck:
Downloade Dir MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

SebastianEF 29.03.2011 17:40

GMER lief ohne Probleme. Hier die Logdatei:

GMER Logfile:
Code:

GMER 1.0.15.15570 - hxxp://www.gmer.net
Rootkit scan 2011-03-29 18:32:20
Windows 6.0.6002 Service Pack 2
Running: cgpfjewd.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1                                                                  771343423
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2                                                                  285507792
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0                                                                  1
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                   
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                C:\Program Files (x86)\DAEMON Tools Lite\
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                0
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                              0xAD 0x5B 0x68 0xA4 ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001                         
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                        0x20 0x01 0x00 0x00 ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                    0xE3 0x6A 0x1F 0x09 ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0                     
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                0xA8 0x52 0x85 0x1E ...
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)               
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                    C:\Program Files (x86)\DAEMON Tools Lite\
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                    0
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                  0xAD 0x5B 0x68 0xA4 ...
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)     
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                            0x20 0x01 0x00 0x00 ...
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                        0xE3 0x6A 0x1F 0x09 ...
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) 
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                    0xA8 0x52 0x85 0x1E ...

---- EOF - GMER 1.0.15 ----

--- --- ---


MBR Check Log:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 64-bit
Base Board Manufacturer: Gigabyte Technology Co., Ltd.
BIOS Manufacturer: Award Software International, Inc.
System Manufacturer: Gigabyte Technology Co., Ltd.
System Product Name: EP35-DS3
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 143):
0x01C56000 \SystemRoot\system32\ntoskrnl.exe
0x01C10000 \SystemRoot\system32\hal.dll
0x00607000 \SystemRoot\system32\kdcom.dll
0x00611000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x0064C000 \SystemRoot\system32\PSHED.dll
0x00660000 \SystemRoot\system32\CLFS.SYS
0x006BD000 \SystemRoot\system32\CI.dll
0x0080B000 \SystemRoot\system32\drivers\Wdf01000.sys
0x008E5000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00A08000 \SystemRoot\System32\Drivers\spus.sys
0x00B3C000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x00B45000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x00B73000 \SystemRoot\system32\drivers\acpi.sys
0x00BC9000 \SystemRoot\system32\drivers\msisadrv.sys
0x008F3000 \SystemRoot\system32\drivers\pci.sys
0x00BD3000 \SystemRoot\System32\drivers\partmgr.sys
0x00BE8000 \SystemRoot\system32\drivers\volmgr.sys
0x00923000 \SystemRoot\System32\drivers\volmgrx.sys
0x00A00000 \SystemRoot\system32\drivers\pciide.sys
0x00989000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x00999000 \SystemRoot\System32\drivers\mountmgr.sys
0x009AC000 \SystemRoot\system32\drivers\atapi.sys
0x009B4000 \SystemRoot\system32\drivers\ataport.SYS
0x0076F000 \SystemRoot\system32\drivers\fltmgr.sys
0x009D8000 \SystemRoot\system32\drivers\fileinfo.sys
0x00C0F000 \SystemRoot\System32\Drivers\ksecdd.sys
0x00E04000 \SystemRoot\system32\drivers\ndis.sys
0x00C96000 \SystemRoot\system32\drivers\msrpc.sys
0x00CE6000 \SystemRoot\system32\drivers\NETIO.SYS
0x01009000 \SystemRoot\System32\drivers\tcpip.sys
0x0117F000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01207000 \SystemRoot\System32\Drivers\Ntfs.sys
0x01387000 \SystemRoot\system32\drivers\volsnap.sys
0x013CB000 \SystemRoot\System32\Drivers\spldr.sys
0x013D3000 \SystemRoot\System32\Drivers\mup.sys
0x011AB000 \SystemRoot\System32\drivers\ecache.sys
0x013E5000 \SystemRoot\system32\drivers\disk.sys
0x00FC7000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x011D7000 \SystemRoot\system32\drivers\crcdisk.sys
0x00FF3000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x00D3F000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x00D48000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x02202000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x02E5D000 \SystemRoot\System32\Drivers\nvBridge.kmd
0x02E5F000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x02F40000 \SystemRoot\System32\drivers\watchdog.sys
0x02F50000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x02F5C000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x02FA2000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x0300D000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x030FA000 \SystemRoot\system32\DRIVERS\Rtlh64.sys
0x03123000 \SystemRoot\system32\DRIVERS\RTL85n64.sys
0x03190000 \SystemRoot\system32\DRIVERS\serial.sys
0x031AD000 \SystemRoot\system32\DRIVERS\serenum.sys
0x031B9000 \SystemRoot\system32\DRIVERS\parport.sys
0x031D5000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x02FB3000 \SystemRoot\System32\Drivers\ajscsile.SYS
0x00D5B000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x00D94000 \SystemRoot\system32\DRIVERS\storport.sys
0x031F1000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x007B6000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x03000000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x0320A000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x0323B000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x0324B000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x03269000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x03281000 \SystemRoot\system32\DRIVERS\termdd.sys
0x03294000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x032A2000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x032AE000 \SystemRoot\system32\DRIVERS\swenum.sys
0x032B0000 \SystemRoot\system32\DRIVERS\ks.sys
0x032E4000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x032EF000 \SystemRoot\system32\DRIVERS\umbus.sys
0x032FF000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x03347000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x0420F000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x0435A000 \SystemRoot\system32\drivers\portcls.sys
0x04395000 \SystemRoot\system32\drivers\drmk.sys
0x043B8000 \SystemRoot\system32\drivers\ksthunk.sys
0x043BE000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x043C8000 \SystemRoot\System32\Drivers\Null.SYS
0x043DC000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x043E4000 \SystemRoot\System32\drivers\vga.sys
0x0335B000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x043F2000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x04200000 \SystemRoot\system32\drivers\rdpencdd.sys
0x043D1000 \SystemRoot\System32\Drivers\Msfs.SYS
0x03380000 \SystemRoot\System32\Drivers\Npfs.SYS
0x03391000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x0339A000 \SystemRoot\system32\DRIVERS\tdx.sys
0x033B7000 \SystemRoot\system32\DRIVERS\smb.sys
0x0400F000 \SystemRoot\system32\drivers\afd.sys
0x0407A000 \SystemRoot\System32\DRIVERS\netbt.sys
0x040BE000 \SystemRoot\system32\DRIVERS\pacer.sys
0x040DC000 \SystemRoot\system32\DRIVERS\rtlprot.sys
0x040E7000 \SystemRoot\system32\DRIVERS\netbios.sys
0x040F6000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x04111000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
0x0411B000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
0x04125000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x04172000 \SystemRoot\system32\drivers\nsiproxy.sys
0x0417E000 \SystemRoot\System32\Drivers\dfsc.sys
0x0419B000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x041BD000 \SystemRoot\system32\DRIVERS\V0330Vid.sys
0x041ED000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x033D2000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x041EF000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x033EE000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x009EC000 \SystemRoot\system32\DRIVERS\LHidFilt.Sys
0x04000000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x007D9000 \SystemRoot\system32\DRIVERS\LMouFilt.Sys
0x011E1000 \SystemRoot\System32\Drivers\crashdmp.sys
0x011EF000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x041F8000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x00DF1000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x00040000 \SystemRoot\System32\win32k.sys
0x00C00000 \SystemRoot\System32\drivers\Dxapi.sys
0x007ED000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00480000 \SystemRoot\System32\TSDDD.dll
0x006F0000 \SystemRoot\System32\cdd.dll
0x0820E000 \SystemRoot\system32\drivers\luafv.sys
0x08230000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x0824D000 \SystemRoot\system32\drivers\spsys.sys
0x082E7000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x082FB000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x0832F000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x0833A000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x08352000 \SystemRoot\system32\drivers\HTTP.sys
0x08A01000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x08A2A000 \SystemRoot\system32\DRIVERS\bowser.sys
0x08A48000 \SystemRoot\System32\drivers\mpsdrv.sys
0x08A62000 \SystemRoot\system32\drivers\mrxdav.sys
0x08A89000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x08AB2000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x08AFB000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x08B1A000 \SystemRoot\System32\DRIVERS\srv2.sys
0x08B4C000 \SystemRoot\System32\DRIVERS\srv.sys
0x08BE0000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0x0900C000 \SystemRoot\system32\drivers\peauth.sys
0x090C2000 \SystemRoot\System32\Drivers\secdrv.SYS
0x090CD000 \SystemRoot\System32\drivers\tcpipreg.sys
0x090DD000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x77980000 \Windows\System32\ntdll.dll

Processes (total 67):
0 System Idle Process
4 System
448 C:\Windows\System32\smss.exe
516 csrss.exe
560 C:\Windows\System32\wininit.exe
580 csrss.exe
616 C:\Windows\System32\services.exe
628 C:\Windows\System32\lsass.exe
636 C:\Windows\System32\lsm.exe
748 C:\Windows\System32\winlogon.exe
816 C:\Windows\System32\svchost.exe
880 C:\Windows\System32\nvvsvc.exe
912 C:\Windows\System32\svchost.exe
972 C:\Windows\System32\svchost.exe
1008 C:\Windows\System32\svchost.exe
208 C:\Windows\System32\svchost.exe
284 C:\Windows\System32\svchost.exe
476 C:\Windows\System32\audiodg.exe
520 C:\Windows\System32\SLsvc.exe
608 C:\Windows\System32\svchost.exe
1080 C:\Windows\System32\svchost.exe
1304 C:\Windows\System32\spoolsv.exe
1332 C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
1344 C:\Windows\System32\svchost.exe
1588 C:\Program Files\SUPERAntiSpyware\SASCore64.exe
1624 C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
1668 C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
1824 C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
1836 C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
1900 C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
1936 C:\Windows\SysWOW64\PnkBstrA.exe
1968 C:\Windows\System32\svchost.exe
1988 C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
2032 C:\Windows\System32\svchost.exe
1092 C:\Users\****\AppData\Local\TVersity\Media Server\MediaServer.exe
800 C:\Windows\System32\svchost.exe
2008 C:\Windows\System32\SearchIndexer.exe
2392 C:\Windows\System32\taskeng.exe
2684 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
2696 C:\Windows\System32\nvvsvc.exe
1600 C:\Program Files (x86)\Google\Update\1.2.183.39\GoogleCrashHandler.exe
2560 C:\Windows\System32\dwm.exe
1556 C:\Windows\System32\taskeng.exe
2988 C:\Windows\explorer.exe
1320 C:\Windows\RAVCpl64.exe
3108 C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
3116 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
3144 C:\Program Files\Windows Sidebar\sidebar.exe
3152 C:\Windows\ehome\ehtray.exe
3176 C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
3184 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
3212 C:\Program Files\Logitech\SetPoint\SetPoint.exe
3248 C:\Windows\V0330Mon.exe
3264 C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
3336 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
3436 C:\Windows\ehome\ehmsas.exe
3660 C:\Program Files (x86)\REALTEK PCI&Cardbus Wireless LAN Driver and Utility\RtWLan.exe
4048 C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
2756 C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
4024 <unknown>
3560 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
2904 C:\Windows\System32\wbem\WMIADAP.exe
3104 WmiPrvSE.exe
1944 C:\Windows\System32\SearchProtocolHost.exe
764 C:\Windows\System32\SearchFilterHost.exe
1180 C:\Users\****\Desktop\MBRCheck.exe
3760 C:\Windows\SysWOW64\conime.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)

PhysicalDrive0 Model Number: SAMSUNGHD501LJ, Rev: CR100-12

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


Done!


Und nu? :kaffee:

cosinus 29.03.2011 19:15

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

SebastianEF 29.03.2011 22:30

hier ist schon mal Malwarebytes:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6204

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

29.03.2011 21:23:04
mbam-log-2011-03-29 (21-23-04).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Durchsuchte Objekte: 382548
Laufzeit: 1 Stunde(n), 4 Minute(n), 36 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


SuperAntiSpyware läuft schon seit zwei Stunden....

SebastianEF 29.03.2011 23:04

So. nach 2,5 h endlich fertig. :D

SUPERAntiSpyware Scann-Protokoll
hxxp://www.superantispyware.com

Generiert 03/29/2011 bei 11:53 PM

Version der Applikation : 4.50.1002

Version der Kern-Datenbank : 6701
Version der Spur-Datenbank : 4513

Scan Art : kompletter Scann
Totale Scann-Zeit : 02:25:54

Gescannte Speicherelemente : 546
Erfasste Speicher-Bedrohungen : 0
Gescannte Register-Elemente : 15392
Erfasste Register-Bedrohungen : 0
Gescannte Datei-Elemente : 214143
Erfasste Datei-Elemente : 0

cosinus 30.03.2011 11:45

Keine Funde :)
Rechner soweit wieder ok?

SebastianEF 30.03.2011 14:48

Hi,

jepp, der PC ist soweit ok. Keine Auffälligkeiten mehr. Leistung wieder wie bisher. Proxy aus Firefox raus usw.

Meinste wir haben es geschafft? :party:

Was mach ich nun mit der externen HDD. Ich weiß nicht ob da was drauf ist. Hab sie bisher ausgelasse. Würde sie aber gerne wieder einschalten. Wie kann ich verhindern das ich von da einen Trojaner wieder drauf bekomme?

cosinus 30.03.2011 15:46

Zitat:

Ich weiß nicht ob da was drauf ist. Hab sie bisher ausgelasse. Würde sie aber gerne wieder einschalten. Wie kann ich verhindern das ich von da einen Trojaner wieder drauf bekomme?
Lade Dir den Flash Disinfector von sUBs und speichere Flash_Disinfector.exe auf Deinem Desktop ab.
Gehe nun wie folgt vor (Anleitung):
  1. Trenne den Rechner physikalisch vom Netz.
  2. Deaktiviere den Hintergrundwächter deines AVP.
  3. Schließe jetzt alle externe Datenträgeran Deinen Rechner an.
  4. Starte den Flash Disinfector mit einem Doppelklick und folge ggf. den Anweisungen.
  5. Wenn der Scan zuende ist, kannst du das Programm schließen.
  6. Starte Deinen Rechner neu.
Hinweis:
Flash Disinfector desinfiziert all Deine Laufwerke von Autoruninfektionen und erstellt einen versteckten Ordner mit demselben Namen, so dass dein Datenträger in Zukunft vor dieser Infektion geschützt ist.
Während dem Scan wird Dein Desktop kurzfristig verschwinden und dann wiederkommen. Das ist normal.

SebastianEF 30.03.2011 19:38

Das herunterladen funktioniert. Allerdings startet das Programm nicht, wenn ich es doppeklicke oder mit rechter Maustaste als Admin öffnen möchte. :(

cosinus 30.03.2011 19:55

Ach du hast ein 64-Bit-Win drauf, ich denke daran liegt es.
Dann lieber so: Über die Systemsteuerung die automatische Wiedergabe komplett deaktivieren => Einstellungen für automatische Wiedergabe ändern

Danach kannst du gefahrlos externe Datenträger anstecken oder einlegen.

Mach dann das => http://www.trojaner-board.de/59624-a...-sichtbar.html

Steck die USB-Datenträger an und achte auf eine autorun.inf direkt auf dem Stick (ist nicht in einem Unterordner) - falls du eine siehst bitte mit dem Editor (zB Notepad++) aufmachen und den Inhalt hier posten.

SebastianEF 30.03.2011 20:14

Hm.... ich glaube sie ist sauber. Es ist nur eine Autorun.unf vorhanden. Diese ist aber für die Software der HDD die mitgeliefert wurde. Der Inhalt:

[AutoRun]
open=Menu.exe
icon=Menu.exe,0
label=CnMemory Drive


Ansonsten habe ich nirgendswo eine autorun.inf gefunden.

cosinus 30.03.2011 20:18

Ja scheint sauber. Den autorun.inf trau ich aber grundsätzlich nicht ;)
Ichmag es nicht, wenn irgendwas meint, automatisch starten zu müssen, nur weil ich einen Datenträger angesteckt habe :balla: :schrei:

SebastianEF 30.03.2011 20:32

Puh.... glück gehabt.

Sind wir jetzt komplett fertig und mein PC ist wieder sauber?

cosinus 30.03.2011 20:49

Hast du keine anderen Stick oder externe festplatte?

Wenn nicht wären wir durch! :abklatsch:


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update



PDF-Reader aktualisieren
Dein Adobe Reader ist nicht aktuell, was ein großes Sicherheitsrisiko darstellt. Du solltest daher besser die alte Version über Systemsteuerung => Software deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst.

Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

SebastianEF 30.03.2011 21:19

GEIL :D

:dankeschoen::dankeschoen::dankeschoen::daumenhoc:daumenhoc:daumenhoc:applaus::applaus::applaus:

Arne. Ich danke dir für deine Nerven und deine Hilfe :daumenhoch: echt topp :dankeschoen:


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:11 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131