Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Java-Virus JAVA/Stutter.AG und Java-Virus JAVA/Stutter.AH (https://www.trojaner-board.de/99473-java-virus-java-stutter-ag-java-virus-java-stutter-ah.html)

MasterDragon 23.05.2011 15:33

Java-Virus JAVA/Stutter.AG und Java-Virus JAVA/Stutter.AH
 
So, ich habe ein Problem mit den oben genannten Viren,
Java-Virus JAVA/Stutter.AH wurde 1xmal gefunden und Java-Virus JAVA/Stutter.AG 2xMal
Wie gehe ich jetzt dagegen vor?
Bin ein absoluter Neuling in sachen PC's bitte um Hilfe.
Danke im Voraus

kira 23.05.2011 19:22

Hallo und Herzlich Willkommen! :)

Bevor wir unsere Zusammenarbeit beginnen, [Bitte Vollständig lesen]:
Zitat:

  • "Fernbehandlungen/Fernhilfe" und die damit verbundenen Haftungsrisken:
    - da die Fehlerprüfung und Handlung werden über große Entfernungen durchgeführt, besteht keine Haftung unsererseits für die daraus entstehenden Folgen.
    - also, jede Haftung für die daraus entstandene Schäden wird ausgeschlossen, ANWEISUNGEN UND DEREN BEFOLGUNG, ERFOLGT AUF DEINE EIGENE VERANTWORTUNG!
  • Charakteristische Merkmale/Profilinformationen:
    - aus der verwendeten Loglisten oder Logdateien - wie z.B. deinen Realnamen, Seriennummer in Programm etc)- kannst Du herauslöschen oder durch [X] ersetzen
  • Die Systemprüfung und Bereinigung:
    - kann einige Zeit in Anspruch nehmen (je nach Art der Infektion), kann aber sogar so stark kompromittiert sein, so dass eine wirkungsvolle technische Säuberung ist nicht mehr möglich bzw Du es neu installieren musst
  • Ich empfehle Dir die Anweisungen erst einmal komplett durchzulesen, bevor du es anwendest, weil wenn du etwas falsch machst, kann es wirklich gefährlich werden. Wenn du meinen Anweisungen Schritt für Schritt folgst, kann eigentlich nichts schief gehen.
  • Innerhalb der Betreuungszeit:
    - ohne Abspräche bitte nicht auf eigene Faust handeln!- bei Problemen nachfragen.
  • Die Reihenfolge:
    - genau so wie beschrieben bitte einhalten, nicht selbst die Reihenfolge wählen!
  • GECRACKTE SOFTWARE werden hier nicht geduldet!!!!
  • Ansonsten unsere Forumsregeln:
    - Bitte erst lesen, dann posten!-> Für alle Hilfesuchenden! Was muss ich vor der Eröffnung eines Themas beachten?
  • Alle Logfile mit einem vBCode Tag eingefügen, das bietet hier eine gute Übersicht, erleichtert mir die Arbeit! Falls das Logfile zu groß, teile es in mehrere Teile auf.

Sobald Du diesen Einführungstext gelesen hast, kannst Du beginnen:)

Zitat:

Wenn ein System kompromittiert wurde, ist das System nicht mehr vertrauenswürdig
Eine Neuinstallation garantiert die rückstandsfreie Entfernung der Infektion - Lesestoff: "Hilfe: Ich wurde das Opfer eines Hackerangriffs. Was soll ich tun?" - Säubern eines gefährdeten Systems
Falls du doch für die Systemreinigung entscheidest - Ein System zu bereinigen kann ein paar Tage dauern (je nach Art der Infektion), kann aber sogar so stark kompromittiert sein, so dass eine wirkungsvolle technische Säuberung ist nicht mehr möglich bzw Du es neu installieren musst::

Für Vista und Win7:
Wichtig: Alle Befehle bitte als Administrator ausführen! rechte Maustaste auf die Eingabeaufforderung und "als Administrator ausführen" auswählen
Auf der angewählten Anwendung einen Rechtsklick (rechte Maustaste) und "Als Administrator ausführen" wählen!

1.
Lade Dir Malwarebytes Anti-Malware von→ malwarebytes.org
  • Installieren und per Doppelklick starten.
  • Deutsch einstellen und gleich mal die Datenbanken zu aktualisieren - online updaten
  • "Komplett Scan durchführen" wählen (überall Haken setzen)
  • wenn der Scanvorgang beendet ist, klicke auf "Zeige Resultate"
  • Alle Funde - falls MBAM meldet in C:\System Volume Information - den Haken bitte entfernen - markieren und auf "Löschen" - "Ausgewähltes entfernen") klicken.
  • Poste das Ergebnis hier in den Thread - den Bericht findest Du unter "Scan-Berichte"
eine bebilderte Anleitung findest Du hier: Anleitung

2.
Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles in Code-Tags hier in den Thread.

3.
→ Lade Dir HJTscanlist.zip herunter
→ entpacke die Datei auf deinem Desktop
→ Bei WindowsXP Home musst vor dem Scan zusätzlich tasklist.zip installieren
→ per Doppelklick starten
→ Wähle dein Betriebsystem aus - bei Win7 wähle Vista
→ Wenn Du gefragt wirst, die Option "Einstellung" (1) - scanlist" wählen
→ Nach kurzer Zeit sollte sich Dein Editor öffnen und die Datei hjtscanlist.txt präsentieren
→ Bitte kopiere den Inhalt hier in Deinen Thread.
** Falls es klappt auf einmal nicht, kannst den Text in mehrere Teile teilen und so posten

4.
Ich würde gerne noch all deine installierten Programme sehen:
Lade dir das Tool Ccleaner herunter
Download
installieren (Software-Lizenzvereinbarung lesen, falls angeboten wird "Füge CCleaner Yahoo! Toolbar hinzu" abwählen)→ starten→ falls nötig - unter Options settings-> "german" einstellen
dann klick auf "Extra (um die installierten Programme auch anzuzeigen)→ weiter auf "Als Textdatei speichern..."
wird eine Textdatei (*.txt) erstellt, kopiere dazu den Inhalt und füge ihn da ein

5.
Rechtsklick auf den AntiVir-Schirm in der Taskleiste => AntiVir starten => Übersicht => Ereignisse
jeden Fund markieren => Rechtsklick auf Funde => Ereignis(se) exportieren
und als Ereignisse.txt auf dem Desktop speichern und den Inhalt hier posten.

Zitat:

Damit dein Thread übersichtlicher und schön lesbar bleibt, am besten nutze den Code-Tags für deinen Post:
→ vor dein Log schreibst Du (also am Anfang des Logfiles):[code]
hier kommt dein Logfile rein - z.B hjtsanlist o. sonstiges
→ dahinter - also am Ende der Logdatei: [/code]

** Möglichst nicht ins internet gehen, kein Online-Banking, File-sharing, Chatprogramme usw
gruß
Coverflow

MasterDragon 26.05.2011 20:52

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6674

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048

25.05.2011 17:43:47
mbam-log-2011-05-25 (17-43-47).txt

Art des Suchlaufs: Vollständiger Suchlauf (A:\|C:\|D:\|E:\|F:\|)
Durchsuchte Objekte: 355900
Laufzeit: 1 Stunde(n), 5 Minute(n), 22 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 1
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 1
Infizierte Dateien: 3

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\CLSID\{003541A1-3BC0-1B1C-AAF3-040114001C01} (Trojan.Agent) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SwUpdate (Trojan.Agent) -> Value: SwUpdate -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Bad: (C:\PROGRA~2\\MACROM~1\SWFUPD~1\swfupdate.dll) Good: () -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
c:\Washer2.rar (Trojan.SpyEyes) -> Quarantined and deleted successfully.

Infizierte Dateien:
c:\programdata\macromedia\swfupdate\swfupdate.dll (Trojan.Agent) -> Delete on reboot.
c:\Windows\System32\config\systemprofile\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\K72RMM3K\users_root_file_file[1].exe (Malware.Packer.GenX) -> Quarantined and deleted successfully.
c:\Washer2.rar\config.bin (Trojan.SpyEyes) -> Quarantined and deleted successfully.

Code:

OTL logfile created on: 25.05.2011 18:26:26 - Run 3
OTL by OldTimer - Version 3.2.23.0    Folder = C:\Users\Alex\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 0,54 Gb Available Physical Memory | 26,86% Memory free
4,24 Gb Paging File | 1,94 Gb Available in Paging File | 45,67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116,50 Gb Total Space | 59,17 Gb Free Space | 50,79% Space Free | Partition Type: NTFS
Drive E: | 68,36 Gb Total Space | 49,30 Gb Free Space | 72,12% Space Free | Partition Type: NTFS
Drive F: | 48,03 Gb Total Space | 29,19 Gb Free Space | 60,78% Space Free | Partition Type: NTFS
 
Computer Name: MARCSPC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Alex\Downloads\OTL(2).exe (OldTimer Tools)
PRC - C:\Programme\Java\jre6\bin\java.exe (Sun Microsystems, Inc.)
PRC - C:\Programme\Java\jre6\bin\jp2launcher.exe (Sun Microsystems, Inc.)
PRC - C:\Progfiles\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Progfiles\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Progfiles\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Progfiles\Adobe\Reader8.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Programme\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Progfiles\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Programme\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe (Sony Ericsson Mobile Communications AB)
PRC - C:\Programme\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Programme\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe ()
PRC - C:\Programme\Common Files\Teleca Shared\Generic.exe (Teleca AB)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Alex\Downloads\OTL(2).exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (gusvc) --  File not found
SRV - (Akamai) -- C:/Program Files/Common Files/Akamai/netsession_win_8832f4b.dll ()
SRV - (AntiVirSchedulerService) -- C:\Progfiles\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) -- C:\Progfiles\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (RMCAST) RMCAST (Pgm) -- C:\Windows\System32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (avgio) -- C:\Progfiles\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (s816mdm) -- C:\Windows\System32\drivers\s816mdm.sys (MCCI Corporation)
DRV - (s816mgmt) Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM) -- C:\Windows\System32\drivers\s816mgmt.sys (MCCI Corporation)
DRV - (s816unic) Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM) -- C:\Windows\System32\drivers\s816unic.sys (MCCI)
DRV - (s816obex) -- C:\Windows\System32\drivers\s816obex.sys (MCCI Corporation)
DRV - (s816nd5) Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS) -- C:\Windows\System32\drivers\s816nd5.sys (MCCI Corporation)
DRV - (s816mdfl) -- C:\Windows\System32\drivers\s816mdfl.sys (MCCI Corporation)
DRV - (s816bus) Sony Ericsson Device 816 driver (WDM) -- C:\Windows\System32\drivers\s816bus.sys (MCCI Corporation)
DRV - (StMp3Rec) -- C:\Windows\System32\drivers\StMp3Rec.sys (Generic)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation)
DRV - (PLCNDIS5) -- C:\Windows\System32\PLCNDIS5.SYS (Intellon, Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.goggle.de/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = localhost:3128
 
========== FireFox ==========
 
FF - prefs.js..CommunityToolbar.SearchFromAddressBarSavedUrl: "data:text/plain,keyword.URL=hxxp://go.web.de/br/moz4_keyurl_search/?su="
FF - prefs.js..browser.startup.homepage: "hxxp://www.goggle.de"
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..keyword.URL: "data:text/plain,keyword.URL=hxxp://go.web.de/br/moz4_keyurl_search/?su="
FF - prefs.js..network.proxy.share_proxy_settings: true
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{184AA5E6-741D-464a-820E-94B3ABC2F3B4}: C:\Windows\system32\config\systemprofile\AppData\Roaming\5015 [2011.05.01 14:14:53 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.05.15 19:01:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
 
[2011.02.20 14:37:04 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\mozilla\Extensions
[2011.05.15 19:03:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions
[2011.05.07 14:01:04 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.05.12 06:42:55 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2011.05.07 14:01:04 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.05.12 06:42:53 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\engine@conduit.com
[2011.05.15 19:03:11 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\support@lastpass.com
[2011.05.16 06:51:32 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.05.16 06:50:54 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
File not found (No name found) --
[2011.05.16 06:50:54 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011.05.21 14:29:02 | 000,000,000 | ---D | M] (Java String Helper) -- C:\USERS\ALEX\APPDATA\ROAMING\5015
() (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5DI26CSR.DEFAULT\EXTENSIONS\TOOLBAR@WEB.DE.XPI
[2011.04.14 18:40:03 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Programme\Mozilla Firefox\components\browsercomps.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
Hosts file not found
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\progfiles\Adobe\Reader8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\ProgFiles\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Programme\OpenOffice3.0.1\OpenOffice.org 3\program\quickstart.exe ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMultiIE = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWB = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWC = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWD = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWE = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWF = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWG = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWH = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWI = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWJ = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWK = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWL = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWM = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWN = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWO = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWP = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWQ = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWR = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWS = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWT = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWU = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWV = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWW = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWX = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWY = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWZ = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 67108800
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Alex\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.05.25 14:22:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Macromedia
[2011.05.24 16:03:41 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Malwarebytes
[2011.05.24 16:03:29 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.05.24 16:03:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\Malwarebytes' Anti-Malware
[2011.05.24 16:03:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.05.24 16:03:21 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.05.24 16:03:19 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.05.24 15:58:33 | 000,236,496 | ---- | C] (Adobe Systems, Incorporated) -- C:\Users\Alex\AppData\Roaming\AcroIEHelpe029.dll
[2011.05.23 15:57:38 | 000,000,000 | ---D | C] -- C:\Programme\Downloaded Installers
[2011.05.21 14:29:02 | 000,236,496 | ---- | C] (Adobe Systems, Incorporated) -- C:\Users\Alex\AppData\Roaming\AcroIEHelpe.dll
[2011.05.20 19:42:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\CCleaner
[2011.05.20 19:42:39 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2011.05.16 21:16:26 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.05.16 06:50:51 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011.05.16 06:50:51 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011.05.16 06:50:51 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011.05.15 19:01:21 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2011.05.14 09:53:51 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Dabou
[2011.05.14 09:53:51 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Bive
[2011.05.08 21:46:22 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike Source
[2011.05.08 21:46:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\Counter-Strike Source
[2011.05.07 13:46:38 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TECHNO4EVER Player
[2011.05.07 13:23:27 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011.05.07 09:37:02 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Koenr
[2011.05.05 17:48:40 | 000,000,000 | ---D | C] -- C:\Programme\Counter-Strike Source
[2011.05.04 16:43:08 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\kock
[2011.05.04 15:16:28 | 000,000,000 | ---D | C] -- C:\2011838ae5cda6dd97
[2011.05.04 14:55:21 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Ruyqit
[2011.05.04 14:55:21 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Exyl
[2011.05.04 14:30:05 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Oghipu
[2011.05.04 14:30:04 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Ewonum
[2011.05.03 19:12:01 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Xyopu
[2011.05.03 15:59:49 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Ythuu
[2011.05.03 08:08:55 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Fyel
[2011.05.02 21:59:59 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Erakwi
[2011.05.02 18:29:14 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Iwreob
[2011.05.01 13:34:50 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Vasago
[2011.05.01 03:15:17 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Heuty
[2011.05.01 03:15:17 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Duiclu
[2011.04.28 12:26:12 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\5015
[2011.04.26 21:12:04 | 000,000,000 | ---D | C] -- C:\Users\Alex\Documents\Black & White 2
[2011.04.26 21:05:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\Black & White 2
[2011.04.26 21:04:18 | 000,000,000 | ---D | C] -- C:\Programme\Lionhead Studios
[2011.04.26 19:15:20 | 000,000,000 | ---D | C] -- C:\Users\Alex\Documents\Drakensang
[2011.04.26 18:49:16 | 000,000,000 | ---D | C] -- C:\Programme\Drakensang
[2011.04.26 15:28:03 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Uniblue
[2011.04.26 15:27:52 | 000,000,000 | -H-D | C] -- C:\ProgramData\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A}
[2011.04.26 15:27:51 | 000,000,000 | ---D | C] -- C:\Programme\Uniblue
[2011.04.26 13:29:51 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\xmldm
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\Users\Alex\AppData\Roaming\*.tmp files -> C:\Users\Alex\AppData\Roaming\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.05.25 17:55:05 | 000,638,510 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.05.25 17:55:05 | 000,604,126 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.05.25 17:55:05 | 000,107,562 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.05.25 17:55:04 | 000,130,462 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.05.25 17:50:31 | 000,004,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.05.25 17:50:31 | 000,004,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.05.25 17:49:47 | 000,030,259 | ---- | M] () -- C:\Users\Alex\Desktop\hjtscanlist.bat
[2011.05.25 17:44:05 | 000,054,016 | ---- | M] () -- C:\Windows\System32\drivers\rabcfw.sys
[2011.05.25 16:33:08 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.05.25 14:26:59 | 000,000,398 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{32723199-A1BE-4670-9193-A50997F9A519}.job
[2011.05.25 14:25:00 | 000,000,394 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{ACD25646-07DA-497D-821D-5A16BB7A684A}.job
[2011.05.25 13:51:39 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{38515D3F-8908-46D7-8055-3092D76ADA21}.job
[2011.05.25 13:50:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.05.24 15:58:33 | 000,236,496 | ---- | M] (Adobe Systems, Incorporated) -- C:\Users\Alex\AppData\Roaming\AcroIEHelpe029.dll
[2011.05.24 06:44:08 | 000,000,428 | ---- | M] () -- C:\Windows\tasks\Error Fix Scan.job
[2011.05.23 17:57:23 | 007,975,821 | ---- | M] () -- C:\Users\Alex\Documents\MafiaBug.rtf
[2011.05.23 16:43:47 | 000,014,408 | ---- | M] () -- C:\Users\Alex\Documents\Antivir².rtf
[2011.05.23 16:08:35 | 000,014,402 | ---- | M] () -- C:\Users\Alex\Documents\Virusbericht 3Funde.rtf
[2011.05.23 14:05:53 | 000,001,280 | ---- | M] () -- C:\Users\Alex\Documents\CMV.rtf
[2011.05.22 19:21:48 | 007,975,821 | ---- | M] () -- C:\Users\Alex\Documents\Barcelona Fan.rtf
[2011.05.21 22:54:49 | 000,001,390 | ---- | M] () -- C:\Users\Alex\Documents\lehrer..rtf
[2011.05.21 17:59:05 | 000,001,326 | RHS- | M] () -- C:\Users\Alex\ntuser.pol
[2011.05.21 14:29:02 | 000,236,496 | ---- | M] (Adobe Systems, Incorporated) -- C:\Users\Alex\AppData\Roaming\AcroIEHelpe.dll
[2011.05.20 16:04:36 | 000,000,962 | ---- | M] () -- C:\Users\Alex\Documents\OGame.de Alte Allianz -ISF-.rtf
[2011.05.16 21:16:26 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.05.16 06:50:36 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011.05.16 06:50:36 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011.05.16 06:50:36 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011.05.16 06:50:36 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011.05.15 19:01:22 | 000,000,846 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.05.15 13:33:57 | 206,240,140 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011.05.14 08:47:32 | 2926,603,649 | ---- | M] () -- C:\Users\Alex\Desktop\rohan_de_installer_20101001.exe
[2011.05.11 16:23:37 | 000,000,210 | ---- | M] () -- C:\Users\Alex\Documents\RunKittyRunmusik.rtf
[2011.05.09 15:11:01 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2011.05.09 07:13:02 | 000,000,680 | ---- | M] () -- C:\Users\Alex\AppData\Local\d3d9caps.dat
[2011.05.08 21:46:23 | 000,001,808 | ---- | M] () -- C:\Users\Alex\Desktop\Counter-Strike Source.lnk
[2011.05.07 13:46:38 | 000,000,823 | ---- | M] () -- C:\Users\Alex\Desktop\T4E Player.lnk
[2011.04.26 19:15:07 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\00001119.LCS
[2011.04.26 13:55:11 | 000,000,112 | ---- | M] () -- C:\ProgramData\56iE4qch.dat
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\Users\Alex\AppData\Roaming\*.tmp files -> C:\Users\Alex\AppData\Roaming\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.05.25 17:44:05 | 000,054,016 | ---- | C] () -- C:\Windows\System32\drivers\rabcfw.sys
[2011.05.24 16:03:29 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.05.23 17:57:22 | 007,975,821 | ---- | C] () -- C:\Users\Alex\Documents\MafiaBug.rtf
[2011.05.23 16:43:47 | 000,014,408 | ---- | C] () -- C:\Users\Alex\Documents\Antivir².rtf
[2011.05.23 16:08:35 | 000,014,402 | ---- | C] () -- C:\Users\Alex\Documents\Virusbericht 3Funde.rtf
[2011.05.23 16:01:48 | 000,000,428 | ---- | C] () -- C:\Windows\tasks\Error Fix Scan.job
[2011.05.23 14:05:53 | 000,001,280 | ---- | C] () -- C:\Users\Alex\Documents\CMV.rtf
[2011.05.22 19:21:48 | 007,975,821 | ---- | C] () -- C:\Users\Alex\Documents\Barcelona Fan.rtf
[2011.05.21 22:54:49 | 000,001,390 | ---- | C] () -- C:\Users\Alex\Documents\lehrer..rtf
[2011.05.15 19:45:18 | 000,000,962 | ---- | C] () -- C:\Users\Alex\Documents\OGame.de Alte Allianz -ISF-.rtf
[2011.05.15 19:01:22 | 000,000,846 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.05.14 08:15:34 | 2926,603,649 | ---- | C] () -- C:\Users\Alex\Desktop\rohan_de_installer_20101001.exe
[2011.05.11 16:23:36 | 000,000,210 | ---- | C] () -- C:\Users\Alex\Documents\RunKittyRunmusik.rtf
[2011.05.09 07:13:02 | 000,000,680 | ---- | C] () -- C:\Users\Alex\AppData\Local\d3d9caps.dat
[2011.05.08 21:46:23 | 000,001,808 | ---- | C] () -- C:\Users\Alex\Desktop\Counter-Strike Source.lnk
[2011.05.07 13:46:38 | 000,000,823 | ---- | C] () -- C:\Users\Alex\Desktop\T4E Player.lnk
[2011.04.26 19:14:42 | 000,004,096 | ---- | C] () -- C:\Users\Public\Documents\00001119.LCS
[2011.04.26 13:31:37 | 000,000,112 | ---- | C] () -- C:\ProgramData\56iE4qch.dat
[2011.04.25 11:12:06 | 000,000,136 | ---- | C] () -- C:\ProgramData\~41672456r
[2011.04.25 11:12:06 | 000,000,120 | ---- | C] () -- C:\ProgramData\~41672456
[2011.04.25 11:11:53 | 000,000,400 | ---- | C] () -- C:\ProgramData\41672456
[2011.04.25 11:05:41 | 000,000,136 | ---- | C] () -- C:\ProgramData\~41017096r
[2011.04.25 11:05:41 | 000,000,120 | ---- | C] () -- C:\ProgramData\~41017096
[2011.04.25 11:05:22 | 000,000,400 | ---- | C] () -- C:\ProgramData\41017096
[2011.03.27 15:22:11 | 000,000,151 | ---- | C] () -- C:\Windows\PhotoSnapViewer.INI
[2011.03.24 20:04:02 | 000,065,040 | ---- | C] () -- C:\Windows\War3Unin.dat
[2011.02.28 19:04:27 | 000,045,568 | ---- | C] () -- C:\Windows\UniFish3.exe
[2011.02.19 23:03:25 | 000,000,000 | ---- | C] () -- C:\Windows\msicpl.ini
[2009.08.02 16:29:26 | 000,000,276 | ---- | C] () -- C:\Windows\thug2.ini
[2009.05.27 17:05:42 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.05.27 17:05:42 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2008.12.28 04:59:54 | 000,138,608 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2008.12.28 04:59:37 | 000,189,800 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2008.12.28 04:59:35 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2008.12.28 04:59:34 | 000,000,274 | ---- | C] () -- C:\Windows\game.ini
[2008.12.21 13:51:15 | 000,069,632 | ---- | C] () -- C:\Windows\RAUNINST.EXE
[2008.11.21 20:30:29 | 000,000,040 | ---- | C] () -- C:\Windows\nfsc_patch.ini
[2008.11.02 22:46:37 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2008.11.02 22:46:37 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2008.11.02 22:17:35 | 000,000,050 | ---- | C] () -- C:\Windows\System32\bridf07a.dat
[2008.11.02 22:14:55 | 000,106,496 | ---- | C] () -- C:\Windows\System32\BrMuSNMP.dll
[2008.09.10 17:25:40 | 000,116,224 | ---- | C] () -- C:\Windows\System32\redmonnt.dll
[2008.09.02 17:04:44 | 000,765,952 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2008.09.02 17:04:44 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2008.08.07 11:52:24 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008.04.11 17:24:03 | 000,399,736 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2008.04.10 17:28:40 | 000,000,049 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2008.04.02 15:52:26 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2008.03.18 18:53:53 | 000,053,248 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2008.03.17 17:05:08 | 000,000,034 | ---- | C] () -- C:\Windows\cdplayer.ini
[2008.02.27 10:30:18 | 000,000,022 | ---- | C] () -- C:\ProgramData\60a7806a-0eea-424c-a464-20f4730cd631
[2008.01.04 13:38:57 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2007.12.23 12:00:36 | 000,000,026 | ---- | C] () -- C:\Windows\NeoSetup.INI
[2007.12.23 11:50:55 | 000,000,010 | ---- | C] () -- C:\Windows\popcinfo.dat
[2007.12.16 15:11:36 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2007.12.09 22:15:31 | 000,479,232 | ---- | C] () -- C:\Windows\System32\HookShield.dll
[2007.12.09 22:15:31 | 000,040,960 | ---- | C] () -- C:\Windows\System32\executeosd.exe
[2007.12.09 22:15:30 | 000,134,504 | ---- | C] () -- C:\Windows\System32\smdll.dll
[2007.12.09 22:15:30 | 000,036,200 | ---- | C] () -- C:\Windows\System32\Auxiliary.dll
[2007.12.09 22:15:28 | 000,036,864 | ---- | C] () -- C:\Windows\System32\startup.exe
[2007.12.09 22:15:27 | 000,462,848 | ---- | C] () -- C:\Windows\System32\HookMap.dll
[2007.12.09 20:23:49 | 000,502,784 | ---- | C] () -- C:\Windows\x2.64.exe
[2007.12.09 20:23:49 | 000,408,576 | ---- | C] () -- C:\Windows\System32\Smab.dll
[2007.12.09 20:23:49 | 000,240,128 | ---- | C] () -- C:\Windows\System32\x.264.exe
[2007.12.09 20:23:49 | 000,217,073 | ---- | C] () -- C:\Windows\meta4.exe
[2007.12.09 20:23:49 | 000,066,560 | ---- | C] () -- C:\Windows\MOTA113.exe
[2007.12.09 20:23:49 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2007.11.20 16:24:52 | 000,159,744 | ---- | C] () -- C:\Windows\gdf.dll
[2007.08.23 18:30:00 | 000,007,680 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2007.04.27 10:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2006.11.02 17:33:31 | 000,638,510 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 17:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 17:33:31 | 000,130,462 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 17:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,272,288 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 000,604,126 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,107,562 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[1997.06.14 13:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll
 
========== LOP Check ==========
 
[2011.05.21 14:29:02 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\5015
[2011.05.23 06:49:09 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Bive
[2011.02.20 20:41:26 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\Bombermaaan
[2011.05.21 15:06:28 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Dabou
[2011.05.04 15:23:44 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Duiclu
[2011.03.03 20:47:42 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.05.02 21:59:59 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Erakwi
[2011.05.04 15:24:28 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Ewonum
[2011.05.04 15:25:47 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Exyl
[2011.05.03 08:08:55 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Fyel
[2011.05.03 19:35:08 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Heuty
[2011.02.20 14:59:26 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\ICQ
[2011.05.02 18:29:15 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Iwreob
[2011.05.04 16:43:08 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\kock
[2011.05.07 09:38:34 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Koenr
[2011.05.04 14:30:05 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Oghipu
[2011.03.24 20:03:01 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\OpenOffice.org
[2011.02.19 23:00:40 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\ParentalControl
[2011.05.04 14:55:21 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Ruyqit
[2011.03.23 18:30:11 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\Sony
[2011.05.07 14:01:04 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Sony Setup
[2011.05.24 21:28:52 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\SpeedSim
[2011.03.02 14:58:51 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\TeamViewer
[2011.03.23 18:41:54 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\Teleca
[2011.04.26 15:28:03 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Uniblue
[2011.05.01 13:34:56 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Vasago
[2011.04.26 13:29:51 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\xmldm
[2011.05.03 19:12:01 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Xyopu
[2011.05.03 15:59:49 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Ythuu
[2011.05.24 06:44:08 | 000,000,428 | ---- | M] () -- C:\Windows\Tasks\Error Fix Scan.job
[2011.05.25 14:28:49 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.05.25 14:26:59 | 000,000,398 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{32723199-A1BE-4670-9193-A50997F9A519}.job
[2011.05.25 13:51:39 | 000,000,420 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{38515D3F-8908-46D7-8055-3092D76ADA21}.job
[2011.05.25 14:25:00 | 000,000,394 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{ACD25646-07DA-497D-821D-5A16BB7A684A}.job
 
========== Purity Check ==========
 
 

< End of report >

[CODE]OTL Extras logfile created on: 25.05.2011 18:26:26 - Run 3
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Alex\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

2,00 Gb Total Physical Memory | 0,54 Gb Available Physical Memory | 26,86% Memory free
4,24 Gb Paging File | 1,94 Gb Available in Paging File | 45,67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116,50 Gb Total Space | 59,17 Gb Free Space | 50,79% Space Free | Partition Type: NTFS
Drive E: | 68,36 Gb Total Space | 49,30 Gb Free Space | 72,12% Space Free | Partition Type: NTFS
Drive F: | 48,03 Gb Total Space | 29,19 Gb Free Space | 60,78% Space Free | Partition Type: NTFS

Computer Name: MARCSPC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\ProgFiles\VLC MediaPlayer\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\ProgFiles\VLC MediaPlayer\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{065E1C38-973B-420F-B300-BDE7042A66CD}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{153011C4-F9EB-4BF1-AEBB-27FB9BA2E179}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{166FABF1-D78E-44B7-A59A-B1DFB57652EE}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{3DD9E3BA-BBE6-4022-AB7A-BF11F5A333FE}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{59671036-B829-4941-A9E3-F7379DB24EB0}" = lport=6112 | protocol=17 | dir=in | name=warcraft hosten (udp) |
"{603119FC-035D-4A3A-9327-6807EC4345EF}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{6F655981-E0B6-49CB-9EED-1541861992A3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{74474826-2651-4A2C-97A1-92B0A325D5B6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8ECFC677-3E3C-4DE5-9DBE-FFC1C658C195}" = rport=67 | protocol=17 | dir=in | svc=dhcp | app=c:\windows\system32\svchost.exe |
"{A5A54654-BB71-4AEB-831F-7E0C6A3EE5C0}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{AA24654D-64AE-4106-8141-753E04303CC4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{AD3F7378-5448-477B-8039-67EA7A916894}" = rport=53 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{ADB8B2A9-030F-4370-9AD3-9C1952FE31E0}" = rport=10243 | protocol=6 | dir=out | app=system |
"{BF180437-BA42-47EA-86C4-E1034F2652C9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C1674B6F-19D8-46E7-B498-56D0B5AC4B01}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{C1B99E14-D1A6-441E-847E-22D821F81ABA}" = lport=49161 | protocol=6 | dir=in | name=akamai netsession interface |
"{DCDF20B5-C6DC-4B06-9DCB-71E40B6C704A}" = lport=6112 | protocol=6 | dir=in | name=warcraft hosten (tcp) |
"{DEE52D1E-7AD8-4587-8797-A336A942CFD1}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{DFB2FDC5-AC69-46D9-B918-C8D3C3D1C974}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E4ED2BDD-F5F1-4448-86EF-22328182D7C2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F0AD1039-C922-48D5-A915-75A6627719C8}" = lport=teredo | protocol=17 | dir=in | svc=iphlpsvc | app=c:\windows\system32\svchost.exe |
"{F4B94E0C-13A7-4238-ADE2-CFEA87226B1E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FD234473-D514-4495-9D7E-DA93CD8571DF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FD9D77BE-C2C6-46A8-B921-44B7FF0CC0AC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FEBE93D1-C791-43D6-A149-03E12BAA9F98}" = rport=67 | protocol=17 | dir=out | svc=dhcp | app=c:\windows\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03EA7C1D-C51B-4363-B127-4D11EF1F7CF2}" = protocol=41 | dir=out | app=system |
"{07857146-54F5-404C-B2AF-23E5F8B270FD}" = protocol=58 | dir=in | app=system |
"{0AE01A6B-3E5B-4186-B521-5E57A0908AF6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1516A6E8-5B15-4ADC-B6A7-AC141C8EB166}" = protocol=58 | dir=out | name=kernnetzwerk - routerankündigung (icmpv6 ausgehend) |
"{18398135-4B64-4406-B89A-6893889751F4}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{19C5B54D-4E44-4D0F-A81B-8721687466C0}" = protocol=58 | dir=in | app=system |
"{2D881E67-AC89-4417-B94D-B1F12B22AEEA}" = protocol=58 | dir=in | app=system |
"{3056500B-E1AD-4B9F-9192-61A8C5A36D06}" = protocol=17 | dir=in | app=c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\k72rmm3k\users_root_file_file[1].exe |
"{3127CCFC-444D-4677-8BB6-3FCADB49CC9D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{31F7B4CC-315B-4771-90C5-2346508D32D1}" = protocol=58 | dir=out | name=kernnetzwerk - multicastabhörabfrage (icmpv6 ausgehend) |
"{34975BFD-5193-4648-88B8-E11456940F7E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{35318073-168C-4CBA-9ACC-B5B5C2438A5B}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{380053FD-4EC8-48C1-B580-87E0EA7C9CCD}" = protocol=6 | dir=in | app=c:\progfiles\itunes\itunes.exe |
"{4B50C50A-C5D8-4BB1-BF95-4FA8348197CA}" = protocol=1 | dir=in | app=system |
"{52C5FB71-3087-40A9-9258-02A001F6C752}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{539EE3FA-207C-4BA5-B539-F9F7695B6704}" = protocol=58 | dir=in | app=system |
"{5C96D9AE-02AC-4F75-8531-9BE55F67520D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{60231891-8EDF-4967-908D-0B19B961CF5F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6B0D204E-BE84-4507-BC7F-E9C0D60E0ACE}" = protocol=58 | dir=out | name=kernnetzwerk - zeitüberschreitung (icmpv6 ausgehend) |
"{6EB29043-E7B3-4627-95F5-862CEE5B892B}" = protocol=58 | dir=in | app=system |
"{72EE8667-87C0-4714-B93C-FA98BA3AF6F4}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{790FFA2C-EBCD-4103-A7C1-3447363CEEAB}" = protocol=58 | dir=out | name=kernnetzwerk - multicastabhörbericht (icmpv6 ausgehend) |
"{7B6C17ED-459C-41E4-890B-7854F2B640B3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7E07FE11-8F48-4EC8-8ABF-5F96B4E9BC6D}" = protocol=17 | dir=in | app=c:\program files\sony ericsson\sony ericsson media manager\mediamanager.exe |
"{847993E7-A11C-4B11-9DCA-C208A2650937}" = protocol=17 | dir=in | app=c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\k72rmm3k\users_root_file_file[1].exe |
"{857BDD0D-295F-4026-BEEF-2DD2A010222D}" = protocol=58 | dir=in | app=system |
"{8BA0DDA9-D3C0-4D15-A650-6213891173AB}" = protocol=17 | dir=in | app=c:\progfiles\itunes\itunes.exe |
"{8E493B07-5F47-48F6-AE90-5C7E3DB88CD5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{921E215D-E43B-4C4C-8FD3-4A0B3B8481D1}" = protocol=58 | dir=out | name=kernnetzwerk - nachbarermittlungsanfrage (icmpv6 ausgehend) |
"{92D14525-95D6-4698-AD31-7ECFA02F7350}" = protocol=58 | dir=out | name=kernnetzwerk - multicastabhörbericht v2 (icmpv6 ausgehend) |
"{965E55CF-7ADF-495F-95A5-262731EDFCA2}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{9B91B485-E126-4A8C-A06A-6EA661D9E790}" = protocol=41 | dir=in | app=system |
"{9C1649E5-F2C9-4A26-8FDD-1C1686D24D6B}" = protocol=58 | dir=out | name=kernnetzwerk - nachbarermittlungsankündigung (icmpv6 ausgehend) |
"{A6B366F9-F865-4036-AD89-BB5308496B7D}" = protocol=58 | dir=out | name=kernnetzwerk - routeranfrage (icmpv6 ausgehend) |
"{A9E45AAD-C3EB-46C3-B13F-618218A2B693}" = protocol=17 | dir=out | svc=iphlpsvc | app=c:\windows\system32\svchost.exe |
"{AB2F0A65-7D60-4257-8191-CA9AEC3BF39F}" = protocol=6 | dir=out | app=system |
"{AE50CCDF-CE9B-49E5-A7EE-8234071B33B8}" = protocol=2 | dir=in | app=system |
"{AF3964B1-517D-43AD-B6E8-9869A17C1799}" = protocol=6 | dir=in | app=c:\program files\sony ericsson\sony ericsson media manager\mediamanager.exe |
"{AF6942F8-3D04-470D-B417-A814BE9CF585}" = protocol=58 | dir=out | name=kernnetzwerk - multicastabhörvorgang abgeschlossen (icmpv6 ausgehend) |
"{B17E2752-A463-4FF4-88D3-5BB5228E1C09}" = protocol=58 | dir=in | app=system |
"{BEDDA3A2-E64C-4CFD-9438-0763C8ECCCF5}" = protocol=58 | dir=in | app=system |
"{C151598C-C645-4AB0-A7BF-3943C343F230}" = protocol=58 | dir=in | app=system |
"{C46D1837-4E3D-4637-BFCD-B9FF14FC106A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D083D3B2-816D-43ED-A0AF-8577CE985BDD}" = protocol=2 | dir=out | app=system |
"{D67D5A69-C19C-4255-BFB3-398D2BEF48FA}" = protocol=6 | dir=in | app=c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\k72rmm3k\users_root_file_file[1].exe |
"{D9C8C3D5-E97B-4275-A216-267C11A87FB4}" = protocol=58 | dir=in | app=system |
"{E2982187-6155-4B4C-AD9D-556DB2CC8AE4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E444E485-F907-4E74-876E-7F05871BAB07}" = protocol=58 | dir=in | app=system |
"{E68D854F-15AC-4168-89FC-B4D5B8CFDCD1}" = protocol=58 | dir=out | name=kernnetzwerk - parameterproblem (icmpv6 ausgehend) |
"{E8089052-4DA6-4B5F-9A62-293A4498981B}" = protocol=58 | dir=out | name=kernnetzwerk - paket zu gross (icmpv6 ausgehend) |
"{E97F0E39-5924-4C45-9DCB-E7A96F9C7533}" = protocol=58 | dir=in | app=system |
"{F38372D4-EF54-4052-B299-FF49CFA53380}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{F3FCC74E-5FC4-48AD-BEF1-87402F2B2D79}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FACAEB83-3312-4D9C-979D-241358EA7513}" = protocol=6 | dir=in | app=c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\k72rmm3k\users_root_file_file[1].exe |
"TCP Query User{040A77D4-C269-4FEC-9843-AE0918C9F810}C:\progfiles\java\jdk1.6.0_07\jre\bin\java.exe" = protocol=6 | dir=in | app=c:\progfiles\java\jdk1.6.0_07\jre\bin\java.exe |
"TCP Query User{0D1A2328-BB85-406B-B69A-21DCD2E563F5}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=6 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe |
"TCP Query User{22372A26-D688-4650-953E-FB0CBE63AD6F}F:\warcraft iii\war3.exe" = protocol=6 | dir=in | app=f:\warcraft iii\war3.exe |
"TCP Query User{288018B9-20ED-4065-8190-340DAB7156C1}F:\css\hl2.exe" = protocol=6 | dir=in | app=f:\css\hl2.exe |
"TCP Query User{2D9EE5FD-7FAF-4D3D-A6FB-6BF3AF079657}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"TCP Query User{2E648958-69DD-4501-8A4E-0D9DCE0AF2F8}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{2FE0DB96-0D88-4DE3-99C4-97245DF2D068}F:\callofduty4\iw3mp.exe" = protocol=6 | dir=in | app=f:\callofduty4\iw3mp.exe |
"TCP Query User{4518FABE-E6A7-4276-98A6-212B8B70330F}F:\ageofempiresii\empires2.exe" = protocol=6 | dir=in | app=f:\ageofempiresii\empires2.exe |
"TCP Query User{475C53F3-55E2-402E-AB30-70E9C7CD1C3F}F:\warcraft iii\war3.exe" = protocol=6 | dir=in | app=f:\warcraft iii\war3.exe |
"TCP Query User{58D32D27-08C6-44E3-800F-358C6990D4B2}F:\ageofempiresii\empires2.exe" = protocol=6 | dir=in | app=f:\ageofempiresii\empires2.exe |
"TCP Query User{5A0DF772-B951-4485-906B-9AE926786D3F}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{62F9BB5A-047F-45AB-9888-7227980F8F96}C:\progfiles\screamerradio\screamer.exe" = protocol=6 | dir=in | app=c:\progfiles\screamerradio\screamer.exe |
"TCP Query User{68A290FC-BF34-4278-BC2D-1F0543CAB416}C:\progfiles\zattoo\zattood.exe" = protocol=6 | dir=in | app=c:\progfiles\zattoo\zattood.exe |
"TCP Query User{6BEB8DDB-06FE-49DF-9D3B-A60123DC6F19}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=6 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"TCP Query User{70972043-A089-4B7D-9CEB-02940A6501B9}C:\users\marc\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=6 | dir=in | app=c:\users\marc\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"TCP Query User{740BAB1F-6D64-4B75-A0F0-2C0959463A21}F:\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=f:\tmnationsforever\tmforever.exe |
"TCP Query User{7CF46998-ED4B-44FE-BA2A-9DB7CE7E7919}F:\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=f:\tmnationsforever\tmforever.exe |
"TCP Query User{84E52A8F-7A12-4E26-A5A3-E94F139147A1}C:\progfiles\garena\garena.exe" = protocol=6 | dir=in | app=c:\progfiles\garena\garena.exe |
"TCP Query User{87862B45-EA94-4065-A0D2-D0814254A4B4}C:\users\marc\desktop\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=c:\users\marc\desktop\call of duty 2\cod2mp_s.exe |
"TCP Query User{8B10CF85-D4DC-44A4-A5D8-EF6E6A8D09B1}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{8EB4347A-06C9-4FF2-9592-57C118DBD47E}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{986C8BEC-9FAE-4AFE-9768-C9391CD2B4AB}C:\progfiles\firefox\firefox.exe" = protocol=6 | dir=in | app=c:\progfiles\firefox\firefox.exe |
"TCP Query User{98A2A7F9-770B-4676-A924-FFF15EA432BE}F:\cs\valve\hl.exe" = protocol=6 | dir=in | app=f:\cs\valve\hl.exe |
"TCP Query User{99311A98-6A0C-419A-81E4-C68269C737EB}C:\program files\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\counter-strike source\hl2.exe |
"TCP Query User{B53B81CA-32F9-4D7C-9431-B17872382D31}F:\cs\valve\hl.exe" = protocol=6 | dir=in | app=f:\cs\valve\hl.exe |
"TCP Query User{BDF81878-22DF-4784-8B0D-063E84A4BB2B}F:\heroesofnewerth\hon.exe" = protocol=6 | dir=in | app=f:\heroesofnewerth\hon.exe |
"TCP Query User{D7127690-B8D7-4BCB-BE91-B9777A037CBA}C:\aeriagames\rohan\rohanclient.exe" = protocol=6 | dir=in | app=c:\aeriagames\rohan\rohanclient.exe |
"TCP Query User{DDD2B434-CB82-48A1-AECC-E57EC3D967E8}C:\progfiles\icq6\icq.exe" = protocol=6 | dir=in | app=c:\progfiles\icq6\icq.exe |
"TCP Query User{E61D138D-11DC-4EF7-9B44-F68CF26866D4}F:\css\hl2.exe" = protocol=6 | dir=in | app=f:\css\hl2.exe |
"TCP Query User{E8B709B1-9ACC-49DE-9EAA-702937865120}F:\serios sam ii\bin\sam2.exe" = protocol=6 | dir=in | app=f:\serios sam ii\bin\sam2.exe |
"TCP Query User{E8EC0FD6-9538-4903-8B6A-0B62353E23F1}F:\ageofempiresii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=f:\ageofempiresii\age2_x1\age2_x1.exe |
"TCP Query User{E91CD75E-963F-43A5-B4E3-825044A163B8}F:\ageofempiresii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=f:\ageofempiresii\age2_x1\age2_x1.exe |
"TCP Query User{ED0BDEDC-B31B-4F37-BCC9-446AE8A1921B}F:\heroesofnewerth\hon.exe" = protocol=6 | dir=in | app=f:\heroesofnewerth\hon.exe |
"TCP Query User{EDA64722-9CC6-41AA-A50D-A3D5DB7D2E84}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{F2484FDC-7C5E-4351-A3F9-3012DDBA3C8E}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{03E7B46B-31B0-436D-A1EE-DFD92363438E}F:\css\hl2.exe" = protocol=17 | dir=in | app=f:\css\hl2.exe |
"UDP Query User{0969CEB8-4C31-4381-95F0-7049E7E22BE3}F:\css\hl2.exe" = protocol=17 | dir=in | app=f:\css\hl2.exe |
"UDP Query User{10EC67F6-663D-47A2-A4D6-F5AFF2C10406}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{13544F0F-3A35-4B25-9F54-CA3ED7FFF3DC}C:\progfiles\firefox\firefox.exe" = protocol=17 | dir=in | app=c:\progfiles\firefox\firefox.exe |
"UDP Query User{1935E1FF-9806-4C40-BBAD-29AE173F99B5}F:\warcraft iii\war3.exe" = protocol=17 | dir=in | app=f:\warcraft iii\war3.exe |
"UDP Query User{217316AA-80B0-4B6D-A694-4D03F611CE9C}C:\progfiles\screamerradio\screamer.exe" = protocol=17 | dir=in | app=c:\progfiles\screamerradio\screamer.exe |
"UDP Query User{2B3C385E-FBB8-4C6B-A3C9-C9808776DE65}F:\heroesofnewerth\hon.exe" = protocol=17 | dir=in | app=f:\heroesofnewerth\hon.exe |
"UDP Query User{315F4795-2594-4011-A831-281BADCCCD69}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{42C667E3-7F8D-4844-A3C8-100B870922E3}F:\serios sam ii\bin\sam2.exe" = protocol=17 | dir=in | app=f:\serios sam ii\bin\sam2.exe |
"UDP Query User{435FFE92-F275-40B0-BC64-6FE106BF4A2A}C:\program files\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\counter-strike source\hl2.exe |
"UDP Query User{46D5DB42-95CF-4125-AE0A-A61419396A55}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{5540E194-BF17-4517-BB89-88962D3EADC1}C:\aeriagames\rohan\rohanclient.exe" = protocol=17 | dir=in | app=c:\aeriagames\rohan\rohanclient.exe |
"UDP Query User{5586E9DA-02D1-41CC-898D-ED60E72152B3}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=17 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"UDP Query User{56F3ABFF-8D06-4332-B5AD-F85EA33E7E91}F:\callofduty4\iw3mp.exe" = protocol=17 | dir=in | app=f:\callofduty4\iw3mp.exe |
"UDP Query User{57F199C6-D85F-4715-A523-2A2069E2E38C}F:\cs\valve\hl.exe" = protocol=17 | dir=in | app=f:\cs\valve\hl.exe |
"UDP Query User{59C856D3-5AB1-4F10-90EF-D4EB41491BB4}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=17 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe |
"UDP Query User{66575AE9-C0D4-454C-8157-FCB1129EB4BD}F:\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=f:\tmnationsforever\tmforever.exe |
"UDP Query User{6AC60CC6-AFC7-4E39-944C-BA11887C964D}F:\ageofempiresii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=f:\ageofempiresii\age2_x1\age2_x1.exe |
"UDP Query User{6D0260B9-6763-485A-A942-EC606691F259}F:\cs\valve\hl.exe" = protocol=17 | dir=in | app=f:\cs\valve\hl.exe |
"UDP Query User{6F78FF01-CA2C-4BE8-9B19-6B274198FEC5}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{70904A82-EF0D-46D5-9628-BF11580D11E2}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{710C74B2-1A3C-46E0-A97D-240CAB43E0C1}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{85E1CFB1-B4AA-4ED5-9D14-F5CFF96B2B76}C:\progfiles\garena\garena.exe" = protocol=17 | dir=in | app=c:\progfiles\garena\garena.exe |
"UDP Query User{95428427-AFB4-4EE3-A146-6049A5A7E105}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{9C18AEC0-4DA4-4F32-9019-B51D3B240235}F:\warcraft iii\war3.exe" = protocol=17 | dir=in | app=f:\warcraft iii\war3.exe |
"UDP Query User{9E22FA4F-0B9A-438C-8912-66BF20ACEEC2}F:\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=f:\tmnationsforever\tmforever.exe |
"UDP Query User{A1FA7043-06C2-4E10-AD02-9C99BD56FD8D}F:\ageofempiresii\empires2.exe" = protocol=17 | dir=in | app=f:\ageofempiresii\empires2.exe |
"UDP Query User{B6D23BB0-FC4C-4F83-A59E-EAA0B3331E00}F:\ageofempiresii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=f:\ageofempiresii\age2_x1\age2_x1.exe |
"UDP Query User{BADEBABF-AF1B-4478-B5AB-34D0EC5E04E0}C:\progfiles\zattoo\zattood.exe" = protocol=17 | dir=in | app=c:\progfiles\zattoo\zattood.exe |
"UDP Query User{C4405CDE-EF56-4DF8-A473-00952B53ACD5}F:\ageofempiresii\empires2.exe" = protocol=17 | dir=in | app=f:\ageofempiresii\empires2.exe |
"UDP Query User{D58B51BF-353D-4741-A9CD-B1EE0C087809}C:\progfiles\java\jdk1.6.0_07\jre\bin\java.exe" = protocol=17 | dir=in | app=c:\progfiles\java\jdk1.6.0_07\jre\bin\java.exe |
"UDP Query User{DA60D498-5BFB-4FAE-8A46-810771B87052}C:\users\marc\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=17 | dir=in | app=c:\users\marc\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"UDP Query User{DE111D63-5C5B-4405-96CE-7DD7528E9CCC}F:\heroesofnewerth\hon.exe" = protocol=17 | dir=in | app=f:\heroesofnewerth\hon.exe |
"UDP Query User{F2F2DBF3-F3F1-4F89-B8CD-1A5332A2A027}C:\users\marc\desktop\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=c:\users\marc\desktop\call of duty 2\cod2mp_s.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0192ED7A-0AF2-426B-AFDF-AD8506295C94}" = Error Fix
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{128A6D30-D64D-4923-8EA3-4A4C536E0A4C}" = Mega ePower 85 Software
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{259C0ABB-A3B2-4D70-008F-BF7EE491B70B}" = Need for Speed™ Carbon
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java(TM) 6 Update 25
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{32A3A4F4-B792-11D6-A78A-00B0D0160070}" = Java(TM) SE Development Kit 6 Update 7
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{451C4ACA-0B6A-4564-BD9D-A6C365DB9C76}_is1" = Bombermaaan 1.4
"{45235788-142C-44BE-8A4D-DDE9A84492E5}" = AGEIA PhysX v7.09.13
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{61E3FE32-07B9-4563-A3E0-2DE2D620FE10}" = PixiePack Codec Pack
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7EC19307-7C22-47A8-922B-3FA965291260}" = OpenOffice.org 3.0
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{909F8EBC-EC7F-48FF-0085-475D818F0F31}" = Need for Speed Underground 2
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98EA51C9-B0B0-45BC-8641-3E119EA47D7B}" = Sony Ericsson Media Manager 1.2
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{AC76BA86-7AD7-1031-7B44-A82000000003}" = Adobe Reader 8.2.0 - Deutsch
"{ADC20BE6-8CA6-4989-B3E8-68EBD2AF1031}" = Nero 7 Essentials
"{C60BA916-9E44-4DA4-B11A-9E27B7624EF5}" = Sony Ericsson Drivers
"{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}" = Sony Ericsson Device Data
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD49361E-3FE6-457E-90A1-9C59E29B5D02}" = Java DB 10.3.1.4
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D59AC9E9-FFAE-471B-B1FF-4B311D23417A}" = Sony Ericsson PC Suite
"{D6BF6477-8369-489F-8DE6-3731F4B88560}" = Sony Ericsson PC Suite
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{EF1394D4-9FB6-4F1F-9A09-20FF3033AE14}" = Tony Hawk's Underground 2
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"7-Zip" = 7-Zip 4.57
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AFPL Ghostscript 8.54" = AFPL Ghostscript 8.54
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"Akamai" = Akamai NetSession Interface
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"CCleaner" = CCleaner
"Cossacks : Back To War" = Cossacks - Back To War
"Counter-Strike: Source" = Counter-Strike: Source
"DX-Ball 1.09" = DX-Ball 1.09
"ffdshow_is1" = ffdshow [rev 2033] [2008-07-05]
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.33
"FreePDF_XP" = FreePDF XP (Remove only)
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{EF1394D4-9FB6-4F1F-9A09-20FF3033AE14}" = Tony Hawk's Underground 2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox 4.0.1 (x86 de)" = Mozilla Firefox 4.0.1 (x86 de)
"NVIDIA Drivers" = NVIDIA Drivers
"Red Alert" = Red Alert Windows 95
"Rohan_DE" = R.O.H.A.N. Vendetta
"SpeedSim" = SpeedSim
"SuperTux_is1" = SuperTux 0.1.3
"T4EPlayer" = T4E Player
"TmNationsForever_is1" = TmNationsForever
"UltraStar Deluxe" = UltraStar Deluxe
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.0.3
"Warcraft III" = Warcraft III
"Xvid_is1" = Xvid 1.1.3 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =

Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =

Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =

Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =

Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =

Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =

Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =

Error - 16.08.2009 18:00:19 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =

Error - 20.08.2009 07:02:33 | Computer Name = MarcsPC | Source = ESENT | ID = 215
Description = WinMail (3060) WindowsMail0: Die Sicherung wurde abgebrochen, weil
sie vom Client angehalten wurde, oder weil die Verbindung mit dem Client unterbrochen
wurde.

Error - 20.08.2009 07:04:30 | Computer Name = MarcsPC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

[ Media Center Events ]
Error - 16.04.2008 09:35:30 | Computer Name = MarcsPC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight
gescheitert.

Error - 18.04.2008 12:54:59 | Computer Name = MarcsPC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight
gescheitert.

Error - 18.04.2008 16:09:11 | Computer Name = MarcsPC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight
gescheitert.

[ System Events ]
Error - 25.05.2011 02:20:27 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7026
Description =

Error - 25.05.2011 07:51:55 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7026
Description =

Error - 25.05.2011 08:12:39 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =

Error - 25.05.2011 08:12:39 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =

Error - 25.05.2011 11:50:49 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7034
Description =

Error - 25.05.201

MasterDragon 26.05.2011 21:11

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6674

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048

25.05.2011 17:43:47
mbam-log-2011-05-25 (17-43-47).txt

Art des Suchlaufs: Vollständiger Suchlauf (A:\|C:\|D:\|E:\|F:\|)
Durchsuchte Objekte: 355900
Laufzeit: 1 Stunde(n), 5 Minute(n), 22 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 1
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 1
Infizierte Dateien: 3

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\CLSID\{003541A1-3BC0-1B1C-AAF3-040114001C01} (Trojan.Agent) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SwUpdate (Trojan.Agent) -> Value: SwUpdate -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Bad: (C:\PROGRA~2\\MACROM~1\SWFUPD~1\swfupdate.dll) Good: () -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
c:\Washer2.rar (Trojan.SpyEyes) -> Quarantined and deleted successfully.

Infizierte Dateien:
c:\programdata\macromedia\swfupdate\swfupdate.dll (Trojan.Agent) -> Delete on reboot.
c:\Windows\System32\config\systemprofile\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\K72RMM3K\users_root_file_file[1].exe (Malware.Packer.GenX) -> Quarantined and deleted successfully.
c:\Washer2.rar\config.bin (Trojan.SpyEyes) -> Quarantined and deleted successfully.

Muss leider alles einzeln Posten sonst kommt so ein Lade fehler tut mir leid.

kira 28.05.2011 08:43

Punkt 5. fehlt noch:-> http://www.trojaner-board.de/99473-j...tml#post662613

MasterDragon 30.05.2011 20:45

yp, das weiß ich nich wie ich alle markieren soll oder geht das auch einzeln?

kira 31.05.2011 16:51

Teile es zur Not auf mehrere Beiträge auf. oder am besten nur die Funde posten

MasterDragon 31.05.2011 18:47

In der Datei 'C:\Recycle.Bin\Recycle.Bin.exe'
wurde ein Virus oder unerwünschtes Programm 'HIDDENEXT/Crypted' [heuristic] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Recycle.Bin\Recycle.Bin.exe'
wurde ein Virus oder unerwünschtes Programm 'HIDDENEXT/Crypted' [heuristic] gefunden.
Ausgeführte Aktion: Zugriff erlauben

In der Datei 'C:\Recycle.Bin\Recycle.Bin.exe'
wurde ein Virus oder unerwünschtes Programm 'HIDDENEXT/Crypted' [heuristic] gefunden.
Ausgeführte Aktion: Zugriff erlauben

In der Datei 'C:\Recycle.Bin\Recycle.Bin.exe'
wurde ein Virus oder unerwünschtes Programm 'HIDDENEXT/Crypted' [heuristic] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Recycle.Bin\Recycle.Bin.exe'
wurde ein Virus oder unerwünschtes Programm 'HIDDENEXT/Crypted' [heuristic] gefunden.
Ausgeführte Aktion: Zugriff erlauben

In der Datei 'C:\Recycle.Bin\Recycle.Bin.exe'
wurde ein Virus oder unerwünschtes Programm 'HIDDENEXT/Crypted' [heuristic] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Recycle.Bin\Recycle.Bin.exe'
wurde ein Virus oder unerwünschtes Programm 'HIDDENEXT/Crypted' [heuristic] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Recycle.Bin\Recycle.Bin.exe'
wurde ein Virus oder unerwünschtes Programm 'HIDDENEXT/Crypted' [heuristic] gefunden.
Ausgeführte Aktion: Zugriff erlauben

In der Datei 'C:\Recycle.Bin\Recycle.Bin.exe'
wurde ein Virus oder unerwünschtes Programm 'HIDDENEXT/Crypted' [heuristic] gefunden.
Ausgeführte Aktion: Zugriff erlauben

Die Datei 'C:\Windows\Temp\639.tmp.VIR'
enthielt einen Virus oder unerwünschtes Programm 'TR/Kazy.24362.2' [trojan].
Durchgeführte Aktion(en):
Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4ab3f56e.qua' verschoben!

In der Datei 'C:\Windows\Temp\639.tmp.VIR'
wurde ein Virus oder unerwünschtes Programm 'TR/Kazy.24362.2' [trojan] gefunden.
Ausgeführte Aktion: Zugriff erlauben

Die Datei 'C:\Windows\Temp\639.tmp'
enthielt einen Virus oder unerwünschtes Programm 'TR/Kazy.24362.2' [trojan].
Durchgeführte Aktion(en):
Die Datei wurde nach '639.tmp.VIR' umbenannt!

Die Datei 'C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HTFIOXXN\hudshpioitgw[1].html.VIR'
enthielt einen Virus oder unerwünschtes Programm 'EXP/CVE-2010-3552' [exploit].
Durchgeführte Aktion(en):
Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4a2af4f3.qua' verschoben!

Die Datei 'C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HTFIOXXN\hudshpioitgw[1].html'
enthielt einen Virus oder unerwünschtes Programm 'EXP/CVE-2010-3552' [exploit].
Durchgeführte Aktion(en):
Die Datei wurde nach 'hudshpioitgw[1].html.VIR' umbenannt!

In der Datei 'C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HTFIOXXN\hudshpioitgw[1].html.VIR'
wurde ein Virus oder unerwünschtes Programm 'EXP/CVE-2010-3552' [exploit] gefunden.
Ausgeführte Aktion: Zugriff erlauben

Die Datei 'C:\ProgramData\Macromedia\swfupdate\swfupdate.dll.VIR'
enthielt einen Virus oder unerwünschtes Programm 'TR/Trash.Gen' [trojan].
Durchgeführte Aktion(en):
Die Datei wurde gelöscht.

In der Datei 'C:\ProgramData\Macromedia\swfupdate\swfupdate.dll.VIR'
wurde ein Virus oder unerwünschtes Programm 'TR/Trash.Gen' [trojan] gefunden.
Ausgeführte Aktion: Zugriff erlauben

Die Datei 'c:\ProgramData\Macromedia\swfupdate\swfupdate.dll'
enthielt einen Virus oder unerwünschtes Programm 'TR/Trash.Gen' [trojan].
Durchgeführte Aktion(en):
Der Registrierungseintrag <HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations> wurde erfolgreich entfernt.
Die Datei wurde nach 'swfupdate.dll.VIR' umbenannt!

n der Datei 'C:\Users\Alex\AppData\Roaming\appconf32.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Trash.Gen' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

Die Datei 'C:\Recycle.Bin\Recycle.Bin.exe.VIR'
enthielt einen Virus oder unerwünschtes Programm 'TR/Jorik.SpyEyes.mu' [trojan].
Durchgeführte Aktion(en):
Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4b336482.qua' verschoben!

In der Datei 'C:\Recycle.Bin\Recycle.Bin.exe.VIR'
wurde ein Virus oder unerwünschtes Programm 'TR/Jorik.SpyEyes.mu' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

Die Datei 'C:\Windows\Temp\E114.tmp'
enthielt einen Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen' [trojan].
Durchgeführte Aktion(en):
Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4adcef9f.qua' verschoben!

In der Datei 'C:\Windows\Temp\E114.tmp'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Windows\Temp\E114.tmp'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Windows\Temp\E114.tmp'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen' [trojan] gefunden.
Ausgeführte Aktion: Zugriff erlauben

Die Datei 'C:\Windows\Temp\BA9F.tmp'
enthielt einen Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen' [trojan].
Durchgeführte Aktion(en):
Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4aa49a88.qua' verschoben!

In der Datei 'C:\Windows\Temp\BA9F.tmp'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Windows\Temp\BA9F.tmp'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Windows\Temp\BA9F.tmp'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen' [trojan] gefunden.
Ausgeführte Aktion: Zugriff erlauben

In der Datei 'C:\Windows\Temp\hnfx\setup.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen2' [trojan] gefunden.
Ausgeführte Aktion: Zugriff erlauben

In der Datei 'C:\Windows\Temp\hnfx\setup.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen2' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Windows\Temp\mrfx\setup.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen2' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Windows\Temp\mrfx\setup.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen2' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Windows\Temp\wpvm\setup.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen2' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Windows\Temp\pskx\setup.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen2' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Windows\Temp\yenr\setup.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen2' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

Die Datei 'C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\c669a2-5ae3f6c8.VIR'
enthielt einen Virus oder unerwünschtes Programm 'JAVA/Stutter.AG' [virus].
Durchgeführte Aktion(en):
Die Datei wurde gelöscht.

Die Datei 'C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\c669a2-5ae3f6c8'
enthielt einen Virus oder unerwünschtes Programm 'JAVA/Stutter.AG' [virus].
Durchgeführte Aktion(en):
Die Datei wurde nach 'c669a2-5ae3f6c8.VIR' umbenannt!

In der Datei 'C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\c669a2-5ae3f6c8.VIR'
wurde ein Virus oder unerwünschtes Programm 'JAVA/Stutter.AH' [virus] gefunden.
Ausgeführte Aktion: Zugriff erlauben

Die Datei 'C:\Recycle.Bin\Recycle.Bin.exe.VIR'
enthielt einen Virus oder unerwünschtes Programm 'TR/Jorik.SpyEyes.mu' [trojan].
Durchgeführte Aktion(en):

Die Datei 'C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FD98QIDH\users_root_file_file[1].exe'
enthielt einen Virus oder unerwünschtes Programm 'TR/VBKrypt.dayt' [trojan].
Durchgeführte Aktion(en):
Die Datei wurde gelöscht.

In der Datei 'C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FD98QIDH\users_root_file_file[1].exe'
wurde ein Virus oder unerwünschtes Programm 'TR/VBKrypt.dayt' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

In der Datei 'C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FD98QIDH\users_root_file_file[1].exe'
wurde ein Virus oder unerwünschtes Programm 'TR/VBKrypt.dayt' [trojan] gefunden.
Ausgeführte Aktion: Zugriff erlauben

Danke für die Hilfe :)
Wollte ich am Anfang schon sagen aber leider vergessen
Hab ja keine Ahnung ob das jetzt viel ist oder nicht? Aber hoffe diese Berichte sind nicht schlimm.

kira 31.05.2011 20:53

1.
Kommen dir bekannt vor? Wo kommen die folgenden "Dateinamen" her? von dem Spiel vlt ?
Code:

[2011.05.04 16:43:08 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\kock
[2011.05.04 14:55:21 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Ruyqit
[2011.05.04 14:55:21 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Exyl
[2011.05.04 14:30:05 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Oghipu
[2011.05.04 14:30:04 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Ewonum
[2011.05.03 19:12:01 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Xyopu
[2011.05.03 15:59:49 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Ythuu
[2011.05.03 08:08:55 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Fyel
[2011.05.02 21:59:59 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Erakwi
[2011.05.02 18:29:14 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Iwreob
[2011.05.01 13:34:50 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Vasago
[2011.05.01 03:15:17 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Heuty
[2011.05.01 03:15:17 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Duiclu
[2011.05.23 06:49:09 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Bive
[2011.02.20 20:41:26 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\Bombermaaan
[2011.05.21 15:06:28 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Dabou
[2011.05.04 15:23:44 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Duiclu
[2011.05.07 09:38:34 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Koenr
[2011.05.04 14:30:05 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Oghipu
[2011.03.23 18:41:54 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\Teleca
[2011.04.26 15:28:03 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Uniblue

2.
Fixen mit OTL
  • Starte die OTL.exe.
  • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
  • Kopiere folgendes Skript:
Code:

:OTL
[2011.05.12 06:42:53 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\engine@conduit.com
[2011.04.25 11:12:06 | 000,000,136 | ---- | C] () -- C:\ProgramData\~41672456r
[2011.04.25 11:12:06 | 000,000,120 | ---- | C] () -- C:\ProgramData\~41672456
[2011.04.25 11:11:53 | 000,000,400 | ---- | C] () -- C:\ProgramData\41672456
[2011.04.25 11:05:41 | 000,000,136 | ---- | C] () -- C:\ProgramData\~41017096r
[2011.04.25 11:05:41 | 000,000,120 | ---- | C] () -- C:\ProgramData\~41017096
[2011.04.25 11:05:22 | 000,000,400 | ---- | C] () -- C:\ProgramData\41017096

:Commands
[purity]
[emptytemp]


3.
erneut einen Scan mit OTL:
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt - OTL.txt und extra.txt
  • Poste die Logfiles in Code-Tags hier in den Thread.

4.
läuft unter XP, Vista mit (32Bit) und Windows 7 (32Bit)
Achtung!:
WENN GMER NICHT AUSGEFÜHRT WERDEN KANN ODER PROBMLEME VERURSACHT, fahre mit dem nächsten Punkt fort!- Es ist NICHT sinnvoll einen zweiten Versuch zu starten!
Um einen tieferen Einblick in dein System, um eine mögliche Infektion mit einem Rootkit/Info v.wikipedia.org) aufzuspüren, werden wir ein Tool - Gmer - einsetzen :
  • - also lade Dir Gmer herunter und entpacke es auf deinen Desktop
    - starte gmer.exe
    - [b]schließe alle Programme, ausserdem Antiviren und andere Schutzprogramme usw müssen deaktiviert sein, keine Verbindung zum Internet, WLAN auch trennen)
    - bitte nichts am Pc machen während der Scan läuft!
    - klicke auf "Scan", um das Tool zu starten
    - wenn der Scan fertig ist klicke auf "Copy" (das Log wird automatisch in die Zwischenablage kopiert) und mit STRG + V musst Du gleich da einfügen
    - mit "Ok" wird Gmer beendet.
    - das Log aus der Zwischenablage hier in Deinem Thread vollständig hineinkopieren

** keine Verbindung zu einem Netzwerk und Internet - WLAN nicht vergessen
Wenn der Scan beendet ist, bitte alle Programme und Tools wieder aktivieren!
Anleitung:-> GMER - Rootkit Scanner

5.
Kontrolle mit MBR -t, ob Master Boot Record in Ordnung ist (MBR-Rootkit)

Mit dem folgenden Tool prüfen wir, ob sich etwas Schädliches im Master Boot Record eingenistet hat.
  • Downloade die MBR.exe von Gmer und
    kopiere die Datei mbr.exe in den Ordner C:\Windows\system32.
    Falls Du den Ordner nicht sehen kannst, diese Einstellungen in den Ordneroptionen vornehmen.
  • Start => ausführen => cmd (da reinschreiben) => OK
    es öffnet sich eine Eingabeaufforderung.

    Vista- und Windows 7-User: Start => Alle Programme => Zubehör => Rechtsklick auf Eingabeaufforderung und wähle Als Administrator ausführen.
  • Nach dem Prompt (>_) folgenden

    aus der Codebox manuell eingeben oder alternativ den mit STRG + C ins Clipboard kopieren und einfügen.
    Einfügen in der Eingabeaufforderung: in der Titelleiste einen Rechtsklick machen => Bearbeiten => einfügen.

    Code:

    mbr.exe -t > C:\mbr.log & C:\mbr.log
    (Enter drücken)
  • Nach kurzer Zeit wird sich Dein Editor öffnen und die Datei C:\mbr.log beinhalten.
    Bitte kopiere den Inhalt hier in Deinen Thread.

MasterDragon 01.06.2011 16:53

Ja sind Spiele.
Spiel sehr viel zurzeit.
2.
Code:

All processes killed
========== OTL ==========
C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\engine@conduit.com\searchplugin folder moved successfully.
C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\engine@conduit.com\META-INF folder moved successfully.
C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\engine@conduit.com\lib folder moved successfully.
C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\engine@conduit.com\DualPackage folder moved successfully.
C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\engine@conduit.com\defaults folder moved successfully.
C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\engine@conduit.com\components folder moved successfully.
C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\engine@conduit.com\chrome folder moved successfully.
C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\engine@conduit.com folder moved successfully.
C:\ProgramData\~41672456r moved successfully.
C:\ProgramData\~41672456 moved successfully.
C:\ProgramData\41672456 moved successfully.
C:\ProgramData\~41017096r moved successfully.
C:\ProgramData\~41017096 moved successfully.
C:\ProgramData\41017096 moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Alex
->Temp folder emptied: 13489205 bytes
->Temporary Internet Files folder emptied: 31564690 bytes
->Java cache emptied: 4646599 bytes
->FireFox cache emptied: 134039115 bytes
->Flash cache emptied: 1840247 bytes
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 83 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Gast
->Temp folder emptied: 49660 bytes
->Temporary Internet Files folder emptied: 30678207 bytes
->Flash cache emptied: 698 bytes
 
User: Marc
 
User: Public
 
User: Walter
->Temp folder emptied: 4043038 bytes
->Temporary Internet Files folder emptied: 36839076 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 33377807 bytes
->Flash cache emptied: 4434 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 279440 bytes
Windows Temp folder emptied: 2032679617 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 71595368 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 24590 bytes
RecycleBin emptied: 39543 bytes
 
Total Files Cleaned = 2.284,00 mb
 
 
OTL by OldTimer - Version 3.2.23.0 log created on 06012011_151811

Files\Folders moved on Reboot...
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OJ7M36V9\search[5].txt moved successfully.
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OJ7M36V9\search[6].txt moved successfully.
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OJ7M36V9\search[9].txt moved successfully.
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MCOKCB4P\search[4].txt moved successfully.
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MCOKCB4P\search[6].txt moved successfully.
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MCOKCB4P\search[7].txt moved successfully.
File\Folder C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MCOKCB4P\seller[1].txt not found!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I8DUF76L\search[4].txt moved successfully.
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I8DUF76L\search[8].txt moved successfully.
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I8DUF76L\search[9].txt moved successfully.
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\06VK2VYG\search[2].txt moved successfully.
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\06VK2VYG\search[3].txt moved successfully.

Registry entries deleted on Reboot...

Code:

OTL logfile created on: 01.06.2011 16:29:05 - Run 5
OTL by OldTimer - Version 3.2.23.0    Folder = C:\Users\Alex\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 0,96 Gb Available Physical Memory | 47,79% Memory free
4,24 Gb Paging File | 2,85 Gb Available in Paging File | 67,20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116,50 Gb Total Space | 57,66 Gb Free Space | 49,49% Space Free | Partition Type: NTFS
Drive E: | 68,36 Gb Total Space | 49,30 Gb Free Space | 72,12% Space Free | Partition Type: NTFS
Drive F: | 48,03 Gb Total Space | 29,19 Gb Free Space | 60,78% Space Free | Partition Type: NTFS
 
Computer Name: MARCSPC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Alex\Downloads\OTL(4).exe (OldTimer Tools)
PRC - C:\Progfiles\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Progfiles\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Progfiles\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Programme\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Progfiles\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Programme\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe (Sony Ericsson Mobile Communications AB)
PRC - C:\Programme\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Programme\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe ()
PRC - C:\Programme\Common Files\Teleca Shared\Generic.exe (Teleca AB)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Alex\Downloads\OTL(4).exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\GdiPlus.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (gusvc) --  File not found
SRV - (Akamai) -- C:/Program Files/Common Files/Akamai/netsession_win_8832f4b.dll ()
SRV - (AntiVirSchedulerService) -- C:\Progfiles\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) -- C:\Progfiles\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (XDva385) --  File not found
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (RMCAST) RMCAST (Pgm) -- C:\Windows\System32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (avgio) -- C:\Progfiles\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (s816mdm) -- C:\Windows\System32\drivers\s816mdm.sys (MCCI Corporation)
DRV - (s816mgmt) Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM) -- C:\Windows\System32\drivers\s816mgmt.sys (MCCI Corporation)
DRV - (s816unic) Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM) -- C:\Windows\System32\drivers\s816unic.sys (MCCI)
DRV - (s816obex) -- C:\Windows\System32\drivers\s816obex.sys (MCCI Corporation)
DRV - (s816nd5) Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS) -- C:\Windows\System32\drivers\s816nd5.sys (MCCI Corporation)
DRV - (s816mdfl) -- C:\Windows\System32\drivers\s816mdfl.sys (MCCI Corporation)
DRV - (s816bus) Sony Ericsson Device 816 driver (WDM) -- C:\Windows\System32\drivers\s816bus.sys (MCCI Corporation)
DRV - (StMp3Rec) -- C:\Windows\System32\drivers\StMp3Rec.sys (Generic)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation)
DRV - (PLCNDIS5) -- C:\Windows\System32\PLCNDIS5.SYS (Intellon, Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.goggle.de/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = localhost:3128
 
========== FireFox ==========
 
FF - prefs.js..CommunityToolbar.SearchFromAddressBarSavedUrl: "data:text/plain,keyword.URL=hxxp://go.web.de/br/moz4_keyurl_search/?su="
FF - prefs.js..browser.startup.homepage: "hxxp://www.goggle.de"
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..keyword.URL: "data:text/plain,keyword.URL=hxxp://go.web.de/br/moz4_keyurl_search/?su="
FF - prefs.js..network.proxy.share_proxy_settings: true
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{184AA5E6-741D-464a-820E-94B3ABC2F3B4}: C:\Windows\system32\config\systemprofile\AppData\Roaming\5015 [2011.05.01 14:14:53 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.05.15 19:01:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
 
[2011.02.20 14:37:04 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\mozilla\Extensions
[2011.06.01 15:21:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions
[2011.05.07 14:01:04 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.05.12 06:42:55 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2011.05.28 09:48:30 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.05.15 19:03:11 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\support@lastpass.com
[2011.05.16 06:51:32 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.05.16 06:50:54 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
File not found (No name found) --
[2011.05.16 06:50:54 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011.05.21 14:29:02 | 000,000,000 | ---D | M] (Java String Helper) -- C:\USERS\ALEX\APPDATA\ROAMING\5015
() (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5DI26CSR.DEFAULT\EXTENSIONS\TOOLBAR@WEB.DE.XPI
[2011.04.14 18:40:03 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Programme\Mozilla Firefox\components\browsercomps.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
Hosts file not found
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\progfiles\Adobe\Reader8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvCplDaemonTool] C:\Windows\System32\hloads57.dll (Comp)
O4 - HKLM..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\ProgFiles\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [NvCplDaemonTool] C:\Users\Alex\hloads57.dll (Comp)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Programme\OpenOffice3.0.1\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scancdiskk39.dll (Comp)
O4 - Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scanudiskzc80.dll (Comp)
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMultiIE = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWB = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWC = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWD = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWE = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWF = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWG = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWH = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWI = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWJ = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWK = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWL = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWM = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWN = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWO = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWP = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWQ = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWR = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWS = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWT = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWU = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWV = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWW = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWX = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWY = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWZ = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 67108800
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Free YouTube Download - C:\Users\Alex\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.06.01 15:18:11 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.05.31 13:54:08 | 000,000,000 | ---D | C] -- C:\xmldm
[2011.05.31 06:42:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\alaplaya
[2011.05.31 06:38:02 | 000,000,000 | ---D | C] -- C:\Programme\alaplaya
[2011.05.31 06:29:56 | 711,189,938 | ---- | C] (InstallShield Software Corporation) -- C:\Users\Alex\Desktop\S4League.exe
[2011.05.28 09:48:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\DVDVideoSoft
[2011.05.28 09:47:59 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Plasmoo
[2011.05.28 09:47:13 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\DVDVideoSoft
[2011.05.28 09:46:28 | 000,000,000 | ---D | C] -- C:\Programme\DVDVideoSoft
[2011.05.25 14:22:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Macromedia
[2011.05.24 16:03:41 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Malwarebytes
[2011.05.24 16:03:29 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.05.24 16:03:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\Malwarebytes' Anti-Malware
[2011.05.24 16:03:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.05.24 16:03:21 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.05.24 16:03:19 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.05.24 15:58:33 | 000,236,496 | ---- | C] (Adobe Systems, Incorporated) -- C:\Users\Alex\AppData\Roaming\AcroIEHelpe029.dll
[2011.05.23 15:57:38 | 000,000,000 | ---D | C] -- C:\Programme\Downloaded Installers
[2011.05.21 14:29:02 | 000,236,496 | ---- | C] (Adobe Systems, Incorporated) -- C:\Users\Alex\AppData\Roaming\AcroIEHelpe.dll
[2011.05.20 19:42:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\CCleaner
[2011.05.20 19:42:39 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2011.05.16 21:16:26 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.05.16 06:50:51 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011.05.16 06:50:51 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011.05.16 06:50:51 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011.05.15 19:01:21 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2011.05.14 09:53:51 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Dabou
[2011.05.14 09:53:51 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Bive
[2011.05.08 21:46:22 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike Source
[2011.05.08 21:46:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\Counter-Strike Source
[2011.05.07 13:46:38 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TECHNO4EVER Player
[2011.05.07 13:23:27 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011.05.07 09:37:02 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Koenr
[2011.05.05 17:48:40 | 000,000,000 | ---D | C] -- C:\Programme\Counter-Strike Source
[2011.05.04 16:43:08 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\kock
[2011.05.04 15:16:28 | 000,000,000 | ---D | C] -- C:\2011838ae5cda6dd97
[2011.05.04 14:55:21 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Ruyqit
[2011.05.04 14:55:21 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Exyl
[2011.05.04 14:30:05 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Oghipu
[2011.05.04 14:30:04 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Ewonum
[2011.05.03 19:12:01 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Xyopu
[2011.05.03 15:59:49 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Ythuu
[2011.05.03 08:08:55 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Fyel
[2011.05.02 21:59:59 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Erakwi
[2011.05.02 18:29:14 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Iwreob
[1 C:\Users\Alex\AppData\Roaming\*.tmp files -> C:\Users\Alex\AppData\Roaming\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.06.01 16:30:58 | 000,000,889 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.lnk
[2011.06.01 16:30:00 | 000,000,394 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{ACD25646-07DA-497D-821D-5A16BB7A684A}.job
[2011.06.01 16:27:00 | 000,000,398 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{32723199-A1BE-4670-9193-A50997F9A519}.job
[2011.06.01 16:12:14 | 000,638,510 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.06.01 16:12:14 | 000,604,126 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.06.01 16:12:14 | 000,130,462 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.06.01 16:12:14 | 000,107,562 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.06.01 15:23:46 | 000,004,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.06.01 15:23:46 | 000,004,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.06.01 15:23:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.06.01 13:53:20 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{38515D3F-8908-46D7-8055-3092D76ADA21}.job
[2011.05.31 19:33:28 | 174,373,452 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011.05.31 13:47:12 | 000,001,326 | RHS- | M] () -- C:\Users\Alex\ntuser.pol
[2011.05.31 06:42:40 | 000,001,599 | ---- | M] () -- C:\Users\Public\Desktop\S4League.lnk
[2011.05.31 06:37:20 | 711,189,938 | ---- | M] (InstallShield Software Corporation) -- C:\Users\Alex\Desktop\S4League.exe
[2011.05.28 09:48:14 | 000,001,032 | ---- | M] () -- C:\Users\Alex\Desktop\DVDVideoSoft Free Studio.lnk
[2011.05.25 20:19:52 | 000,137,542 | ---- | M] () -- C:\Users\Alex\Documents\gesamter virusbericht.rtf
[2011.05.25 17:49:47 | 000,030,259 | ---- | M] () -- C:\Users\Alex\Desktop\hjtscanlist.bat
[2011.05.25 16:33:08 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.05.24 15:58:33 | 000,236,496 | ---- | M] (Adobe Systems, Incorporated) -- C:\Users\Alex\AppData\Roaming\AcroIEHelpe029.dll
[2011.05.24 06:44:08 | 000,000,428 | ---- | M] () -- C:\Windows\tasks\Error Fix Scan.job
[2011.05.23 17:57:23 | 007,975,821 | ---- | M] () -- C:\Users\Alex\Documents\MafiaBug.rtf
[2011.05.23 16:43:47 | 000,014,408 | ---- | M] () -- C:\Users\Alex\Documents\Antivir².rtf
[2011.05.23 16:08:35 | 000,014,402 | ---- | M] () -- C:\Users\Alex\Documents\Virusbericht 3Funde.rtf
[2011.05.23 14:05:53 | 000,001,280 | ---- | M] () -- C:\Users\Alex\Documents\CMV.rtf
[2011.05.22 19:21:48 | 007,975,821 | ---- | M] () -- C:\Users\Alex\Documents\Barcelona Fan.rtf
[2011.05.21 22:54:49 | 000,001,390 | ---- | M] () -- C:\Users\Alex\Documents\lehrer..rtf
[2011.05.21 14:29:02 | 000,236,496 | ---- | M] (Adobe Systems, Incorporated) -- C:\Users\Alex\AppData\Roaming\AcroIEHelpe.dll
[2011.05.20 16:04:36 | 000,000,962 | ---- | M] () -- C:\Users\Alex\Documents\OGame.de Alte Allianz -ISF-.rtf
[2011.05.16 21:16:26 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.05.16 06:50:36 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011.05.16 06:50:36 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011.05.16 06:50:36 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011.05.16 06:50:36 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011.05.15 19:01:22 | 000,000,846 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.05.14 08:47:32 | 2926,603,649 | ---- | M] () -- C:\Users\Alex\Desktop\rohan_de_installer_20101001.exe
[2011.05.11 16:23:37 | 000,000,210 | ---- | M] () -- C:\Users\Alex\Documents\RunKittyRunmusik.rtf
[2011.05.09 15:11:01 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2011.05.09 07:13:02 | 000,000,680 | ---- | M] () -- C:\Users\Alex\AppData\Local\d3d9caps.dat
[2011.05.08 21:46:23 | 000,001,808 | ---- | M] () -- C:\Users\Alex\Desktop\Counter-Strike Source.lnk
[2011.05.07 13:46:38 | 000,000,823 | ---- | M] () -- C:\Users\Alex\Desktop\T4E Player.lnk
[1 C:\Users\Alex\AppData\Roaming\*.tmp files -> C:\Users\Alex\AppData\Roaming\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.05.31 06:42:40 | 000,001,599 | ---- | C] () -- C:\Users\Public\Desktop\S4League.lnk
[2011.05.28 09:48:14 | 000,001,032 | ---- | C] () -- C:\Users\Alex\Desktop\DVDVideoSoft Free Studio.lnk
[2011.05.25 20:19:52 | 000,137,542 | ---- | C] () -- C:\Users\Alex\Documents\gesamter virusbericht.rtf
[2011.05.25 20:16:58 | 000,000,889 | ---- | C] () -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.lnk
[2011.05.24 16:03:29 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.05.23 17:57:22 | 007,975,821 | ---- | C] () -- C:\Users\Alex\Documents\MafiaBug.rtf
[2011.05.23 16:43:47 | 000,014,408 | ---- | C] () -- C:\Users\Alex\Documents\Antivir².rtf
[2011.05.23 16:08:35 | 000,014,402 | ---- | C] () -- C:\Users\Alex\Documents\Virusbericht 3Funde.rtf
[2011.05.23 16:01:48 | 000,000,428 | ---- | C] () -- C:\Windows\tasks\Error Fix Scan.job
[2011.05.23 14:05:53 | 000,001,280 | ---- | C] () -- C:\Users\Alex\Documents\CMV.rtf
[2011.05.22 19:21:48 | 007,975,821 | ---- | C] () -- C:\Users\Alex\Documents\Barcelona Fan.rtf
[2011.05.21 22:54:49 | 000,001,390 | ---- | C] () -- C:\Users\Alex\Documents\lehrer..rtf
[2011.05.15 19:45:18 | 000,000,962 | ---- | C] () -- C:\Users\Alex\Documents\OGame.de Alte Allianz -ISF-.rtf
[2011.05.15 19:01:22 | 000,000,846 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.05.14 08:15:34 | 2926,603,649 | ---- | C] () -- C:\Users\Alex\Desktop\rohan_de_installer_20101001.exe
[2011.05.11 16:23:36 | 000,000,210 | ---- | C] () -- C:\Users\Alex\Documents\RunKittyRunmusik.rtf
[2011.05.09 07:13:02 | 000,000,680 | ---- | C] () -- C:\Users\Alex\AppData\Local\d3d9caps.dat
[2011.05.08 21:46:23 | 000,001,808 | ---- | C] () -- C:\Users\Alex\Desktop\Counter-Strike Source.lnk
[2011.05.07 13:46:38 | 000,000,823 | ---- | C] () -- C:\Users\Alex\Desktop\T4E Player.lnk
[2011.04.26 13:31:37 | 000,000,112 | ---- | C] () -- C:\ProgramData\56iE4qch.dat
[2011.03.27 15:22:11 | 000,000,151 | ---- | C] () -- C:\Windows\PhotoSnapViewer.INI
[2011.03.24 20:04:02 | 000,065,040 | ---- | C] () -- C:\Windows\War3Unin.dat
[2011.02.28 19:04:27 | 000,045,568 | ---- | C] () -- C:\Windows\UniFish3.exe
[2011.02.19 23:03:25 | 000,000,000 | ---- | C] () -- C:\Windows\msicpl.ini
[2009.08.02 16:29:26 | 000,000,276 | ---- | C] () -- C:\Windows\thug2.ini
[2009.05.27 17:05:42 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.05.27 17:05:42 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2008.12.28 04:59:54 | 000,138,608 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2008.12.28 04:59:37 | 000,189,800 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2008.12.28 04:59:35 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2008.12.28 04:59:34 | 000,000,274 | ---- | C] () -- C:\Windows\game.ini
[2008.12.21 13:51:15 | 000,069,632 | ---- | C] () -- C:\Windows\RAUNINST.EXE
[2008.11.21 20:30:29 | 000,000,040 | ---- | C] () -- C:\Windows\nfsc_patch.ini
[2008.11.02 22:46:37 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2008.11.02 22:46:37 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2008.11.02 22:17:35 | 000,000,050 | ---- | C] () -- C:\Windows\System32\bridf07a.dat
[2008.11.02 22:14:55 | 000,106,496 | ---- | C] () -- C:\Windows\System32\BrMuSNMP.dll
[2008.09.10 17:25:40 | 000,116,224 | ---- | C] () -- C:\Windows\System32\redmonnt.dll
[2008.09.02 17:04:44 | 000,765,952 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2008.09.02 17:04:44 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2008.08.07 11:52:24 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008.04.11 17:24:03 | 000,399,736 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2008.04.10 17:28:40 | 000,000,049 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2008.04.02 15:52:26 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2008.03.18 18:53:53 | 000,053,248 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2008.03.17 17:05:08 | 000,000,034 | ---- | C] () -- C:\Windows\cdplayer.ini
[2008.02.27 10:30:18 | 000,000,022 | ---- | C] () -- C:\ProgramData\60a7806a-0eea-424c-a464-20f4730cd631
[2008.01.04 13:38:57 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2007.12.23 12:00:36 | 000,000,026 | ---- | C] () -- C:\Windows\NeoSetup.INI
[2007.12.23 11:50:55 | 000,000,010 | ---- | C] () -- C:\Windows\popcinfo.dat
[2007.12.16 15:11:36 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2007.12.09 22:15:31 | 000,479,232 | ---- | C] () -- C:\Windows\System32\HookShield.dll
[2007.12.09 22:15:31 | 000,040,960 | ---- | C] () -- C:\Windows\System32\executeosd.exe
[2007.12.09 22:15:30 | 000,134,504 | ---- | C] () -- C:\Windows\System32\smdll.dll
[2007.12.09 22:15:30 | 000,036,200 | ---- | C] () -- C:\Windows\System32\Auxiliary.dll
[2007.12.09 22:15:28 | 000,036,864 | ---- | C] () -- C:\Windows\System32\startup.exe
[2007.12.09 22:15:27 | 000,462,848 | ---- | C] () -- C:\Windows\System32\HookMap.dll
[2007.12.09 20:23:49 | 000,502,784 | ---- | C] () -- C:\Windows\x2.64.exe
[2007.12.09 20:23:49 | 000,408,576 | ---- | C] () -- C:\Windows\System32\Smab.dll
[2007.12.09 20:23:49 | 000,240,128 | ---- | C] () -- C:\Windows\System32\x.264.exe
[2007.12.09 20:23:49 | 000,217,073 | ---- | C] () -- C:\Windows\meta4.exe
[2007.12.09 20:23:49 | 000,066,560 | ---- | C] () -- C:\Windows\MOTA113.exe
[2007.12.09 20:23:49 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2007.11.20 16:24:52 | 000,159,744 | ---- | C] () -- C:\Windows\gdf.dll
[2007.08.23 18:30:00 | 000,007,680 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2007.04.27 10:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2006.11.02 17:33:31 | 000,638,510 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 17:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 17:33:31 | 000,130,462 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 17:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,272,288 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 000,604,126 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,107,562 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[1997.06.14 13:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll
 
========== LOP Check ==========
 
[2011.05.21 14:29:02 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\5015
[2011.05.23 06:49:09 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Bive
[2011.02.20 20:41:26 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\Bombermaaan
[2011.05.21 15:06:28 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Dabou
[2011.05.04 15:23:44 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Duiclu
[2011.05.28 09:47:58 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\DVDVideoSoft
[2011.05.28 09:48:21 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.05.02 21:59:59 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Erakwi
[2011.05.04 15:24:28 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Ewonum
[2011.05.04 15:25:47 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Exyl
[2011.05.03 08:08:55 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Fyel
[2011.05.03 19:35:08 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Heuty
[2011.02.20 14:59:26 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\ICQ
[2011.05.02 18:29:15 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Iwreob
[2011.05.04 16:43:08 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\kock
[2011.05.07 09:38:34 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Koenr
[2011.05.04 14:30:05 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Oghipu
[2011.03.24 20:03:01 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\OpenOffice.org
[2011.02.19 23:00:40 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\ParentalControl
[2011.05.04 14:55:21 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Ruyqit
[2011.03.23 18:30:11 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\Sony
[2011.05.07 14:01:04 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Sony Setup
[2011.05.24 21:28:52 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\SpeedSim
[2011.03.02 14:58:51 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\TeamViewer
[2011.03.23 18:41:54 | 000,000,000 | -H-D | M] -- C:\Users\Alex\AppData\Roaming\Teleca
[2011.04.26 15:28:03 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Uniblue
[2011.05.01 13:34:56 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Vasago
[2011.04.26 13:29:51 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\xmldm
[2011.05.03 19:12:01 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Xyopu
[2011.05.03 15:59:49 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Ythuu
[2011.05.24 06:44:08 | 000,000,428 | ---- | M] () -- C:\Windows\Tasks\Error Fix Scan.job
[2011.06.01 16:05:34 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.06.01 16:27:00 | 000,000,398 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{32723199-A1BE-4670-9193-A50997F9A519}.job
[2011.06.01 13:53:20 | 000,000,420 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{38515D3F-8908-46D7-8055-3092D76ADA21}.job
[2011.06.01 16:30:00 | 000,000,394 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{ACD25646-07DA-497D-821D-5A16BB7A684A}.job
 
========== Purity Check ==========
 
 

< End of report >

2a.
Code:

OTL Extras logfile created on: 01.06.2011 16:29:05 - Run 5
OTL by OldTimer - Version 3.2.23.0    Folder = C:\Users\Alex\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 0,96 Gb Available Physical Memory | 47,79% Memory free
4,24 Gb Paging File | 2,85 Gb Available in Paging File | 67,20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116,50 Gb Total Space | 57,66 Gb Free Space | 49,49% Space Free | Partition Type: NTFS
Drive E: | 68,36 Gb Total Space | 49,30 Gb Free Space | 72,12% Space Free | Partition Type: NTFS
Drive F: | 48,03 Gb Total Space | 29,19 Gb Free Space | 60,78% Space Free | Partition Type: NTFS
 
Computer Name: MARCSPC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- Reg Error: Key error. File not found
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\ProgFiles\VLC MediaPlayer\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\ProgFiles\VLC MediaPlayer\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{065E1C38-973B-420F-B300-BDE7042A66CD}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{153011C4-F9EB-4BF1-AEBB-27FB9BA2E179}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1C297379-69C0-4544-8D28-F70BFF12CE9E}" = lport=49161 | protocol=6 | dir=in | name=akamai netsession interface |
"{3DD9E3BA-BBE6-4022-AB7A-BF11F5A333FE}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{59671036-B829-4941-A9E3-F7379DB24EB0}" = lport=6112 | protocol=17 | dir=in | name=warcraft hosten (udp) |
"{603119FC-035D-4A3A-9327-6807EC4345EF}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{6F655981-E0B6-49CB-9EED-1541861992A3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{74474826-2651-4A2C-97A1-92B0A325D5B6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8ECFC677-3E3C-4DE5-9DBE-FFC1C658C195}" = rport=67 | protocol=17 | dir=in | svc=dhcp | app=c:\windows\system32\svchost.exe |
"{A5A54654-BB71-4AEB-831F-7E0C6A3EE5C0}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{AA24654D-64AE-4106-8141-753E04303CC4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{AD3F7378-5448-477B-8039-67EA7A916894}" = rport=53 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{ADB8B2A9-030F-4370-9AD3-9C1952FE31E0}" = rport=10243 | protocol=6 | dir=out | app=system |
"{BF180437-BA42-47EA-86C4-E1034F2652C9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C1674B6F-19D8-46E7-B498-56D0B5AC4B01}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{C4B28741-7742-42AC-AA0C-DD1B555B8859}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{DCDF20B5-C6DC-4B06-9DCB-71E40B6C704A}" = lport=6112 | protocol=6 | dir=in | name=warcraft hosten (tcp) |
"{DEE52D1E-7AD8-4587-8797-A336A942CFD1}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{DFB2FDC5-AC69-46D9-B918-C8D3C3D1C974}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E4ED2BDD-F5F1-4448-86EF-22328182D7C2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F0AD1039-C922-48D5-A915-75A6627719C8}" = lport=teredo | protocol=17 | dir=in | svc=iphlpsvc | app=c:\windows\system32\svchost.exe |
"{F4B94E0C-13A7-4238-ADE2-CFEA87226B1E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FD234473-D514-4495-9D7E-DA93CD8571DF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FD9D77BE-C2C6-46A8-B921-44B7FF0CC0AC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FEBE93D1-C791-43D6-A149-03E12BAA9F98}" = rport=67 | protocol=17 | dir=out | svc=dhcp | app=c:\windows\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03EA7C1D-C51B-4363-B127-4D11EF1F7CF2}" = protocol=41 | dir=out | app=system |
"{07857146-54F5-404C-B2AF-23E5F8B270FD}" = protocol=58 | dir=in | app=system |
"{0AE01A6B-3E5B-4186-B521-5E57A0908AF6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1516A6E8-5B15-4ADC-B6A7-AC141C8EB166}" = protocol=58 | dir=out | name=kernnetzwerk - routerankündigung (icmpv6 ausgehend) |
"{18398135-4B64-4406-B89A-6893889751F4}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{19C5B54D-4E44-4D0F-A81B-8721687466C0}" = protocol=58 | dir=in | app=system |
"{2D881E67-AC89-4417-B94D-B1F12B22AEEA}" = protocol=58 | dir=in | app=system |
"{3056500B-E1AD-4B9F-9192-61A8C5A36D06}" = protocol=17 | dir=in | app=c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\k72rmm3k\users_root_file_file[1].exe |
"{3127CCFC-444D-4677-8BB6-3FCADB49CC9D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{31F7B4CC-315B-4771-90C5-2346508D32D1}" = protocol=58 | dir=out | name=kernnetzwerk - multicastabhörabfrage (icmpv6 ausgehend) |
"{34975BFD-5193-4648-88B8-E11456940F7E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{35318073-168C-4CBA-9ACC-B5B5C2438A5B}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{380053FD-4EC8-48C1-B580-87E0EA7C9CCD}" = protocol=6 | dir=in | app=c:\progfiles\itunes\itunes.exe |
"{4B50C50A-C5D8-4BB1-BF95-4FA8348197CA}" = protocol=1 | dir=in | app=system |
"{52C5FB71-3087-40A9-9258-02A001F6C752}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{539EE3FA-207C-4BA5-B539-F9F7695B6704}" = protocol=58 | dir=in | app=system |
"{5C96D9AE-02AC-4F75-8531-9BE55F67520D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{60231891-8EDF-4967-908D-0B19B961CF5F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6B0D204E-BE84-4507-BC7F-E9C0D60E0ACE}" = protocol=58 | dir=out | name=kernnetzwerk - zeitüberschreitung (icmpv6 ausgehend) |
"{6EB29043-E7B3-4627-95F5-862CEE5B892B}" = protocol=58 | dir=in | app=system |
"{72EE8667-87C0-4714-B93C-FA98BA3AF6F4}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{790FFA2C-EBCD-4103-A7C1-3447363CEEAB}" = protocol=58 | dir=out | name=kernnetzwerk - multicastabhörbericht (icmpv6 ausgehend) |
"{7B6C17ED-459C-41E4-890B-7854F2B640B3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7E07FE11-8F48-4EC8-8ABF-5F96B4E9BC6D}" = protocol=17 | dir=in | app=c:\program files\sony ericsson\sony ericsson media manager\mediamanager.exe |
"{847993E7-A11C-4B11-9DCA-C208A2650937}" = protocol=17 | dir=in | app=c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\k72rmm3k\users_root_file_file[1].exe |
"{857BDD0D-295F-4026-BEEF-2DD2A010222D}" = protocol=58 | dir=in | app=system |
"{8BA0DDA9-D3C0-4D15-A650-6213891173AB}" = protocol=17 | dir=in | app=c:\progfiles\itunes\itunes.exe |
"{8E493B07-5F47-48F6-AE90-5C7E3DB88CD5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{921E215D-E43B-4C4C-8FD3-4A0B3B8481D1}" = protocol=58 | dir=out | name=kernnetzwerk - nachbarermittlungsanfrage (icmpv6 ausgehend) |
"{92D14525-95D6-4698-AD31-7ECFA02F7350}" = protocol=58 | dir=out | name=kernnetzwerk - multicastabhörbericht v2 (icmpv6 ausgehend) |
"{965E55CF-7ADF-495F-95A5-262731EDFCA2}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{9B91B485-E126-4A8C-A06A-6EA661D9E790}" = protocol=41 | dir=in | app=system |
"{9C1649E5-F2C9-4A26-8FDD-1C1686D24D6B}" = protocol=58 | dir=out | name=kernnetzwerk - nachbarermittlungsankündigung (icmpv6 ausgehend) |
"{A6B366F9-F865-4036-AD89-BB5308496B7D}" = protocol=58 | dir=out | name=kernnetzwerk - routeranfrage (icmpv6 ausgehend) |
"{A9E45AAD-C3EB-46C3-B13F-618218A2B693}" = protocol=17 | dir=out | svc=iphlpsvc | app=c:\windows\system32\svchost.exe |
"{AB2F0A65-7D60-4257-8191-CA9AEC3BF39F}" = protocol=6 | dir=out | app=system |
"{AE50CCDF-CE9B-49E5-A7EE-8234071B33B8}" = protocol=2 | dir=in | app=system |
"{AF3964B1-517D-43AD-B6E8-9869A17C1799}" = protocol=6 | dir=in | app=c:\program files\sony ericsson\sony ericsson media manager\mediamanager.exe |
"{AF6942F8-3D04-470D-B417-A814BE9CF585}" = protocol=58 | dir=out | name=kernnetzwerk - multicastabhörvorgang abgeschlossen (icmpv6 ausgehend) |
"{B17E2752-A463-4FF4-88D3-5BB5228E1C09}" = protocol=58 | dir=in | app=system |
"{BEDDA3A2-E64C-4CFD-9438-0763C8ECCCF5}" = protocol=58 | dir=in | app=system |
"{C151598C-C645-4AB0-A7BF-3943C343F230}" = protocol=58 | dir=in | app=system |
"{C46D1837-4E3D-4637-BFCD-B9FF14FC106A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D083D3B2-816D-43ED-A0AF-8577CE985BDD}" = protocol=2 | dir=out | app=system |
"{D67D5A69-C19C-4255-BFB3-398D2BEF48FA}" = protocol=6 | dir=in | app=c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\k72rmm3k\users_root_file_file[1].exe |
"{D9C8C3D5-E97B-4275-A216-267C11A87FB4}" = protocol=58 | dir=in | app=system |
"{E2982187-6155-4B4C-AD9D-556DB2CC8AE4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E444E485-F907-4E74-876E-7F05871BAB07}" = protocol=58 | dir=in | app=system |
"{E68D854F-15AC-4168-89FC-B4D5B8CFDCD1}" = protocol=58 | dir=out | name=kernnetzwerk - parameterproblem (icmpv6 ausgehend) |
"{E8089052-4DA6-4B5F-9A62-293A4498981B}" = protocol=58 | dir=out | name=kernnetzwerk - paket zu gross (icmpv6 ausgehend) |
"{E97F0E39-5924-4C45-9DCB-E7A96F9C7533}" = protocol=58 | dir=in | app=system |
"{F38372D4-EF54-4052-B299-FF49CFA53380}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{F3FCC74E-5FC4-48AD-BEF1-87402F2B2D79}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FACAEB83-3312-4D9C-979D-241358EA7513}" = protocol=6 | dir=in | app=c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\k72rmm3k\users_root_file_file[1].exe |
"TCP Query User{040A77D4-C269-4FEC-9843-AE0918C9F810}C:\progfiles\java\jdk1.6.0_07\jre\bin\java.exe" = protocol=6 | dir=in | app=c:\progfiles\java\jdk1.6.0_07\jre\bin\java.exe |
"TCP Query User{0D1A2328-BB85-406B-B69A-21DCD2E563F5}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=6 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe |
"TCP Query User{22372A26-D688-4650-953E-FB0CBE63AD6F}F:\warcraft iii\war3.exe" = protocol=6 | dir=in | app=f:\warcraft iii\war3.exe |
"TCP Query User{288018B9-20ED-4065-8190-340DAB7156C1}F:\css\hl2.exe" = protocol=6 | dir=in | app=f:\css\hl2.exe |
"TCP Query User{2D9EE5FD-7FAF-4D3D-A6FB-6BF3AF079657}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"TCP Query User{2E648958-69DD-4501-8A4E-0D9DCE0AF2F8}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{2FE0DB96-0D88-4DE3-99C4-97245DF2D068}F:\callofduty4\iw3mp.exe" = protocol=6 | dir=in | app=f:\callofduty4\iw3mp.exe |
"TCP Query User{4518FABE-E6A7-4276-98A6-212B8B70330F}F:\ageofempiresii\empires2.exe" = protocol=6 | dir=in | app=f:\ageofempiresii\empires2.exe |
"TCP Query User{475C53F3-55E2-402E-AB30-70E9C7CD1C3F}F:\warcraft iii\war3.exe" = protocol=6 | dir=in | app=f:\warcraft iii\war3.exe |
"TCP Query User{58D32D27-08C6-44E3-800F-358C6990D4B2}F:\ageofempiresii\empires2.exe" = protocol=6 | dir=in | app=f:\ageofempiresii\empires2.exe |
"TCP Query User{5A0DF772-B951-4485-906B-9AE926786D3F}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{62F9BB5A-047F-45AB-9888-7227980F8F96}C:\progfiles\screamerradio\screamer.exe" = protocol=6 | dir=in | app=c:\progfiles\screamerradio\screamer.exe |
"TCP Query User{68A290FC-BF34-4278-BC2D-1F0543CAB416}C:\progfiles\zattoo\zattood.exe" = protocol=6 | dir=in | app=c:\progfiles\zattoo\zattood.exe |
"TCP Query User{6BEB8DDB-06FE-49DF-9D3B-A60123DC6F19}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=6 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"TCP Query User{70972043-A089-4B7D-9CEB-02940A6501B9}C:\users\marc\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=6 | dir=in | app=c:\users\marc\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"TCP Query User{740BAB1F-6D64-4B75-A0F0-2C0959463A21}F:\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=f:\tmnationsforever\tmforever.exe |
"TCP Query User{7CF46998-ED4B-44FE-BA2A-9DB7CE7E7919}F:\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=f:\tmnationsforever\tmforever.exe |
"TCP Query User{84E52A8F-7A12-4E26-A5A3-E94F139147A1}C:\progfiles\garena\garena.exe" = protocol=6 | dir=in | app=c:\progfiles\garena\garena.exe |
"TCP Query User{87862B45-EA94-4065-A0D2-D0814254A4B4}C:\users\marc\desktop\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=c:\users\marc\desktop\call of duty 2\cod2mp_s.exe |
"TCP Query User{8B10CF85-D4DC-44A4-A5D8-EF6E6A8D09B1}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{8EB4347A-06C9-4FF2-9592-57C118DBD47E}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{986C8BEC-9FAE-4AFE-9768-C9391CD2B4AB}C:\progfiles\firefox\firefox.exe" = protocol=6 | dir=in | app=c:\progfiles\firefox\firefox.exe |
"TCP Query User{98A2A7F9-770B-4676-A924-FFF15EA432BE}F:\cs\valve\hl.exe" = protocol=6 | dir=in | app=f:\cs\valve\hl.exe |
"TCP Query User{99311A98-6A0C-419A-81E4-C68269C737EB}C:\program files\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\counter-strike source\hl2.exe |
"TCP Query User{B53B81CA-32F9-4D7C-9431-B17872382D31}F:\cs\valve\hl.exe" = protocol=6 | dir=in | app=f:\cs\valve\hl.exe |
"TCP Query User{BDF81878-22DF-4784-8B0D-063E84A4BB2B}F:\heroesofnewerth\hon.exe" = protocol=6 | dir=in | app=f:\heroesofnewerth\hon.exe |
"TCP Query User{D7127690-B8D7-4BCB-BE91-B9777A037CBA}C:\aeriagames\rohan\rohanclient.exe" = protocol=6 | dir=in | app=c:\aeriagames\rohan\rohanclient.exe |
"TCP Query User{DDD2B434-CB82-48A1-AECC-E57EC3D967E8}C:\progfiles\icq6\icq.exe" = protocol=6 | dir=in | app=c:\progfiles\icq6\icq.exe |
"TCP Query User{E61D138D-11DC-4EF7-9B44-F68CF26866D4}F:\css\hl2.exe" = protocol=6 | dir=in | app=f:\css\hl2.exe |
"TCP Query User{E8B709B1-9ACC-49DE-9EAA-702937865120}F:\serios sam ii\bin\sam2.exe" = protocol=6 | dir=in | app=f:\serios sam ii\bin\sam2.exe |
"TCP Query User{E8EC0FD6-9538-4903-8B6A-0B62353E23F1}F:\ageofempiresii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=f:\ageofempiresii\age2_x1\age2_x1.exe |
"TCP Query User{E91CD75E-963F-43A5-B4E3-825044A163B8}F:\ageofempiresii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=f:\ageofempiresii\age2_x1\age2_x1.exe |
"TCP Query User{ED0BDEDC-B31B-4F37-BCC9-446AE8A1921B}F:\heroesofnewerth\hon.exe" = protocol=6 | dir=in | app=f:\heroesofnewerth\hon.exe |
"TCP Query User{EDA64722-9CC6-41AA-A50D-A3D5DB7D2E84}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{F2484FDC-7C5E-4351-A3F9-3012DDBA3C8E}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{03E7B46B-31B0-436D-A1EE-DFD92363438E}F:\css\hl2.exe" = protocol=17 | dir=in | app=f:\css\hl2.exe |
"UDP Query User{0969CEB8-4C31-4381-95F0-7049E7E22BE3}F:\css\hl2.exe" = protocol=17 | dir=in | app=f:\css\hl2.exe |
"UDP Query User{10EC67F6-663D-47A2-A4D6-F5AFF2C10406}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{13544F0F-3A35-4B25-9F54-CA3ED7FFF3DC}C:\progfiles\firefox\firefox.exe" = protocol=17 | dir=in | app=c:\progfiles\firefox\firefox.exe |
"UDP Query User{1935E1FF-9806-4C40-BBAD-29AE173F99B5}F:\warcraft iii\war3.exe" = protocol=17 | dir=in | app=f:\warcraft iii\war3.exe |
"UDP Query User{217316AA-80B0-4B6D-A694-4D03F611CE9C}C:\progfiles\screamerradio\screamer.exe" = protocol=17 | dir=in | app=c:\progfiles\screamerradio\screamer.exe |
"UDP Query User{2B3C385E-FBB8-4C6B-A3C9-C9808776DE65}F:\heroesofnewerth\hon.exe" = protocol=17 | dir=in | app=f:\heroesofnewerth\hon.exe |
"UDP Query User{315F4795-2594-4011-A831-281BADCCCD69}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{42C667E3-7F8D-4844-A3C8-100B870922E3}F:\serios sam ii\bin\sam2.exe" = protocol=17 | dir=in | app=f:\serios sam ii\bin\sam2.exe |
"UDP Query User{435FFE92-F275-40B0-BC64-6FE106BF4A2A}C:\program files\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\counter-strike source\hl2.exe |
"UDP Query User{46D5DB42-95CF-4125-AE0A-A61419396A55}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{5540E194-BF17-4517-BB89-88962D3EADC1}C:\aeriagames\rohan\rohanclient.exe" = protocol=17 | dir=in | app=c:\aeriagames\rohan\rohanclient.exe |
"UDP Query User{5586E9DA-02D1-41CC-898D-ED60E72152B3}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=17 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"UDP Query User{56F3ABFF-8D06-4332-B5AD-F85EA33E7E91}F:\callofduty4\iw3mp.exe" = protocol=17 | dir=in | app=f:\callofduty4\iw3mp.exe |
"UDP Query User{57F199C6-D85F-4715-A523-2A2069E2E38C}F:\cs\valve\hl.exe" = protocol=17 | dir=in | app=f:\cs\valve\hl.exe |
"UDP Query User{59C856D3-5AB1-4F10-90EF-D4EB41491BB4}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=17 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe |
"UDP Query User{66575AE9-C0D4-454C-8157-FCB1129EB4BD}F:\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=f:\tmnationsforever\tmforever.exe |
"UDP Query User{6AC60CC6-AFC7-4E39-944C-BA11887C964D}F:\ageofempiresii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=f:\ageofempiresii\age2_x1\age2_x1.exe |
"UDP Query User{6D0260B9-6763-485A-A942-EC606691F259}F:\cs\valve\hl.exe" = protocol=17 | dir=in | app=f:\cs\valve\hl.exe |
"UDP Query User{6F78FF01-CA2C-4BE8-9B19-6B274198FEC5}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{70904A82-EF0D-46D5-9628-BF11580D11E2}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{710C74B2-1A3C-46E0-A97D-240CAB43E0C1}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{85E1CFB1-B4AA-4ED5-9D14-F5CFF96B2B76}C:\progfiles\garena\garena.exe" = protocol=17 | dir=in | app=c:\progfiles\garena\garena.exe |
"UDP Query User{95428427-AFB4-4EE3-A146-6049A5A7E105}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{9C18AEC0-4DA4-4F32-9019-B51D3B240235}F:\warcraft iii\war3.exe" = protocol=17 | dir=in | app=f:\warcraft iii\war3.exe |
"UDP Query User{9E22FA4F-0B9A-438C-8912-66BF20ACEEC2}F:\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=f:\tmnationsforever\tmforever.exe |
"UDP Query User{A1FA7043-06C2-4E10-AD02-9C99BD56FD8D}F:\ageofempiresii\empires2.exe" = protocol=17 | dir=in | app=f:\ageofempiresii\empires2.exe |
"UDP Query User{B6D23BB0-FC4C-4F83-A59E-EAA0B3331E00}F:\ageofempiresii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=f:\ageofempiresii\age2_x1\age2_x1.exe |
"UDP Query User{BADEBABF-AF1B-4478-B5AB-34D0EC5E04E0}C:\progfiles\zattoo\zattood.exe" = protocol=17 | dir=in | app=c:\progfiles\zattoo\zattood.exe |
"UDP Query User{C4405CDE-EF56-4DF8-A473-00952B53ACD5}F:\ageofempiresii\empires2.exe" = protocol=17 | dir=in | app=f:\ageofempiresii\empires2.exe |
"UDP Query User{D58B51BF-353D-4741-A9CD-B1EE0C087809}C:\progfiles\java\jdk1.6.0_07\jre\bin\java.exe" = protocol=17 | dir=in | app=c:\progfiles\java\jdk1.6.0_07\jre\bin\java.exe |
"UDP Query User{DA60D498-5BFB-4FAE-8A46-810771B87052}C:\users\marc\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=17 | dir=in | app=c:\users\marc\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"UDP Query User{DE111D63-5C5B-4405-96CE-7DD7528E9CCC}F:\heroesofnewerth\hon.exe" = protocol=17 | dir=in | app=f:\heroesofnewerth\hon.exe |
"UDP Query User{F2F2DBF3-F3F1-4F89-B8CD-1A5332A2A027}C:\users\marc\desktop\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=c:\users\marc\desktop\call of duty 2\cod2mp_s.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0192ED7A-0AF2-426B-AFDF-AD8506295C94}" = Error Fix
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{128A6D30-D64D-4923-8EA3-4A4C536E0A4C}" = Mega ePower 85 Software
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{259C0ABB-A3B2-4D70-008F-BF7EE491B70B}" = Need for Speed™ Carbon
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java(TM) 6 Update 25
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{32A3A4F4-B792-11D6-A78A-00B0D0160070}" = Java(TM) SE Development Kit 6 Update 7
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{451C4ACA-0B6A-4564-BD9D-A6C365DB9C76}_is1" = Bombermaaan 1.4
"{45235788-142C-44BE-8A4D-DDE9A84492E5}" = AGEIA PhysX v7.09.13
"{4BA56822-4E76-42EC-883F-52EF0859957E}" = S4 League_EU
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{61E3FE32-07B9-4563-A3E0-2DE2D620FE10}" = PixiePack Codec Pack
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7EC19307-7C22-47A8-922B-3FA965291260}" = OpenOffice.org 3.0
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{909F8EBC-EC7F-48FF-0085-475D818F0F31}" = Need for Speed Underground 2
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98EA51C9-B0B0-45BC-8641-3E119EA47D7B}" = Sony Ericsson Media Manager 1.2
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{AC76BA86-7AD7-1031-7B44-A82000000003}" = Adobe Reader 8.2.0 - Deutsch
"{ADC20BE6-8CA6-4989-B3E8-68EBD2AF1031}" = Nero 7 Essentials
"{C60BA916-9E44-4DA4-B11A-9E27B7624EF5}" = Sony Ericsson Drivers
"{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}" = Sony Ericsson Device Data
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD49361E-3FE6-457E-90A1-9C59E29B5D02}" = Java DB 10.3.1.4
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D59AC9E9-FFAE-471B-B1FF-4B311D23417A}" = Sony Ericsson PC Suite
"{D6BF6477-8369-489F-8DE6-3731F4B88560}" = Sony Ericsson PC Suite
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{EF1394D4-9FB6-4F1F-9A09-20FF3033AE14}" = Tony Hawk's Underground 2
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"7-Zip" = 7-Zip 4.57
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AFPL Ghostscript 8.54" = AFPL Ghostscript 8.54
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"Akamai" = Akamai NetSession Interface
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"CCleaner" = CCleaner
"Cossacks : Back To War" = Cossacks - Back To War
"Counter-Strike: Source" = Counter-Strike: Source
"DX-Ball 1.09" = DX-Ball 1.09
"ffdshow_is1" = ffdshow [rev 2033] [2008-07-05]
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"Free Studio_is1" = Free Studio version 5.0.9
"FreePDF_XP" = FreePDF XP (Remove only)
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{EF1394D4-9FB6-4F1F-9A09-20FF3033AE14}" = Tony Hawk's Underground 2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox 4.0.1 (x86 de)" = Mozilla Firefox 4.0.1 (x86 de)
"NVIDIA Drivers" = NVIDIA Drivers
"Red Alert" = Red Alert Windows 95
"Rohan_DE" = R.O.H.A.N. Vendetta
"SpeedSim" = SpeedSim
"SuperTux_is1" = SuperTux 0.1.3
"T4EPlayer" = T4E Player
"TmNationsForever_is1" = TmNationsForever
"UltraStar Deluxe" = UltraStar Deluxe
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.0.3
"Warcraft III" = Warcraft III
"Xvid_is1" = Xvid 1.1.3 final uninstall
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Warcraft III" = Warcraft III: All Products
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 16.08.2009 18:00:19 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 20.08.2009 07:02:33 | Computer Name = MarcsPC | Source = ESENT | ID = 215
Description = WinMail (3060) WindowsMail0: Die Sicherung wurde abgebrochen, weil
 sie vom Client angehalten wurde, oder weil die Verbindung mit dem Client unterbrochen
 wurde.
 
Error - 20.08.2009 07:04:30 | Computer Name = MarcsPC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
 
[ Media Center Events ]
Error - 16.04.2008 09:35:30 | Computer Name = MarcsPC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight
 gescheitert.
 
Error - 18.04.2008 12:54:59 | Computer Name = MarcsPC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight
 gescheitert.
 
Error - 18.04.2008 16:09:11 | Computer Name = MarcsPC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight
 gescheitert.
 
[ System Events ]
Error - 01.06.2011 02:22:07 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7026
Description =
 
Error - 01.06.2011 02:35:03 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
Error - 01.06.2011 02:35:03 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
Error - 01.06.2011 07:52:19 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7026
Description =
 
Error - 01.06.2011 08:09:02 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
Error - 01.06.2011 08:09:02 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
Error - 01.06.2011 09:25:07 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7026
Description =
 
Error - 01.06.2011 09:46:20 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
Error - 01.06.2011 09:46:20 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
Error - 01.06.2011 10:10:35 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
 
< End of report >


MasterDragon 01.06.2011 16:55

3.OTL.exe
OTL Logfile:
Code:

OTL logfile created on: 01.06.2011 17:38:03 - Run 6
OTL by OldTimer - Version 3.2.23.0    Folder = C:\Users\Alex\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 0,80 Gb Available Physical Memory | 40,13% Memory free
4,25 Gb Paging File | 2,71 Gb Available in Paging File | 63,78% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116,50 Gb Total Space | 57,52 Gb Free Space | 49,37% Space Free | Partition Type: NTFS
Drive E: | 68,36 Gb Total Space | 49,30 Gb Free Space | 72,12% Space Free | Partition Type: NTFS
Drive F: | 48,03 Gb Total Space | 29,19 Gb Free Space | 60,78% Space Free | Partition Type: NTFS
 
Computer Name: MARCSPC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Alex\Downloads\OTL(5).exe (OldTimer Tools)
PRC - C:\Progfiles\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Progfiles\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Programme\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
PRC - C:\Progfiles\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Programme\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Progfiles\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Programme\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe (Sony Ericsson Mobile Communications AB)
PRC - C:\Programme\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Programme\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe ()
PRC - C:\Programme\Common Files\Teleca Shared\Generic.exe (Teleca AB)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Alex\Downloads\OTL(5).exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (gusvc) --  File not found
SRV - (Akamai) -- C:/Program Files/Common Files/Akamai/netsession_win_8832f4b.dll ()
SRV - (AntiVirSchedulerService) -- C:\Progfiles\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) -- C:\Progfiles\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (RMCAST) RMCAST (Pgm) -- C:\Windows\System32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (avgio) -- C:\Progfiles\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (s816mdm) -- C:\Windows\System32\drivers\s816mdm.sys (MCCI Corporation)
DRV - (s816mgmt) Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM) -- C:\Windows\System32\drivers\s816mgmt.sys (MCCI Corporation)
DRV - (s816unic) Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM) -- C:\Windows\System32\drivers\s816unic.sys (MCCI)
DRV - (s816obex) -- C:\Windows\System32\drivers\s816obex.sys (MCCI Corporation)
DRV - (s816nd5) Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS) -- C:\Windows\System32\drivers\s816nd5.sys (MCCI Corporation)
DRV - (s816mdfl) -- C:\Windows\System32\drivers\s816mdfl.sys (MCCI Corporation)
DRV - (s816bus) Sony Ericsson Device 816 driver (WDM) -- C:\Windows\System32\drivers\s816bus.sys (MCCI Corporation)
DRV - (StMp3Rec) -- C:\Windows\System32\drivers\StMp3Rec.sys (Generic)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation)
DRV - (PLCNDIS5) -- C:\Windows\System32\PLCNDIS5.SYS (Intellon, Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.goggle.de/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = localhost:3128
 
========== FireFox ==========
 
FF - prefs.js..CommunityToolbar.SearchFromAddressBarSavedUrl: "data:text/plain,keyword.URL=hxxp://go.web.de/br/moz4_keyurl_search/?su="
FF - prefs.js..browser.startup.homepage: "hxxp://www.goggle.de"
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..keyword.URL: "data:text/plain,keyword.URL=hxxp://go.web.de/br/moz4_keyurl_search/?su="
FF - prefs.js..network.proxy.share_proxy_settings: true
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{184AA5E6-741D-464a-820E-94B3ABC2F3B4}: C:\Windows\system32\config\systemprofile\AppData\Roaming\5015 [2011.05.01 14:14:53 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.05.15 19:01:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
 
[2011.02.20 14:37:04 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\mozilla\Extensions
[2011.06.01 15:21:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions
[2011.05.07 14:01:04 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.05.12 06:42:55 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2011.05.28 09:48:30 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.05.15 19:03:11 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\5di26csr.default\extensions\support@lastpass.com
[2011.05.16 06:51:32 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.05.16 06:50:54 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
File not found (No name found) --
[2011.05.16 06:50:54 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011.05.21 14:29:02 | 000,000,000 | ---D | M] (Java String Helper) -- C:\USERS\ALEX\APPDATA\ROAMING\5015
() (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5DI26CSR.DEFAULT\EXTENSIONS\TOOLBAR@WEB.DE.XPI
[2011.04.14 18:40:03 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Programme\Mozilla Firefox\components\browsercomps.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
Hosts file not found
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\progfiles\Adobe\Reader8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvCplDaemonTool] C:\Windows\System32\hloads57.dll (Comp)
O4 - HKLM..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\ProgFiles\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [NvCplDaemonTool] C:\Users\Alex\hloads57.dll (Comp)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Programme\OpenOffice3.0.1\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scancdiskk39.dll (Comp)
O4 - Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scanudiskzc80.dll (Comp)
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMultiIE = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWB = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWC = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWD = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWE = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWF = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWG = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWH = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWI = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWJ = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWK = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWL = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWM = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWN = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWO = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWP = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWQ = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWR = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWS = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWT = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWU = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWV = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWW = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWX = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWY = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LWZ = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 67108800
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Free YouTube Download - C:\Users\Alex\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.06.01 15:18:11 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.05.31 13:54:08 | 000,000,000 | ---D | C] -- C:\xmldm
[2011.05.31 06:42:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\alaplaya
[2011.05.31 06:38:02 | 000,000,000 | ---D | C] -- C:\Programme\alaplaya
[2011.05.31 06:29:56 | 711,189,938 | ---- | C] (InstallShield Software Corporation) -- C:\Users\Alex\Desktop\S4League.exe
[2011.05.28 09:48:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\DVDVideoSoft
[2011.05.28 09:47:59 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Plasmoo
[2011.05.28 09:47:13 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\DVDVideoSoft
[2011.05.28 09:46:28 | 000,000,000 | ---D | C] -- C:\Programme\DVDVideoSoft
[2011.05.25 14:22:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Macromedia
[2011.05.24 16:03:41 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Malwarebytes
[2011.05.24 16:03:29 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.05.24 16:03:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\Malwarebytes' Anti-Malware
[2011.05.24 16:03:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.05.24 16:03:21 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.05.24 16:03:19 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.05.24 15:58:33 | 000,236,496 | ---- | C] (Adobe Systems, Incorporated) -- C:\Users\Alex\AppData\Roaming\AcroIEHelpe029.dll
[2011.05.23 15:57:38 | 000,000,000 | ---D | C] -- C:\Programme\Downloaded Installers
[2011.05.21 14:29:02 | 000,236,496 | ---- | C] (Adobe Systems, Incorporated) -- C:\Users\Alex\AppData\Roaming\AcroIEHelpe.dll
[2011.05.20 19:42:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\CCleaner
[2011.05.20 19:42:39 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2011.05.16 21:16:26 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.05.16 06:50:51 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011.05.16 06:50:51 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011.05.16 06:50:51 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011.05.15 19:01:21 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2011.05.14 09:53:51 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Dabou
[2011.05.14 09:53:51 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Bive
[2011.05.08 21:46:22 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike Source
[2011.05.08 21:46:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programme\Counter-Strike Source
[2011.05.07 13:46:38 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TECHNO4EVER Player
[2011.05.07 13:23:27 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011.05.07 09:37:02 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Koenr
[2011.05.05 17:48:40 | 000,000,000 | ---D | C] -- C:\Programme\Counter-Strike Source
[2011.05.04 16:43:08 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\kock
[2011.05.04 15:16:28 | 000,000,000 | ---D | C] -- C:\2011838ae5cda6dd97
[2011.05.04 14:55:21 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Ruyqit
[2011.05.04 14:55:21 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Exyl
[2011.05.04 14:30:05 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Oghipu
[2011.05.04 14:30:04 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Ewonum
[2011.05.03 19:12:01 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Xyopu
[2011.05.03 15:59:49 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Ythuu
[2011.05.03 08:08:55 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Fyel
[2011.05.02 21:59:59 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Erakwi
[2011.05.02 18:29:14 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Iwreob
[1 C:\Users\Alex\AppData\Roaming\*.tmp files -> C:\Users\Alex\AppData\Roaming\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.06.01 17:41:12 | 000,000,889 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.lnk
[2011.06.01 17:40:00 | 000,000,394 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{ACD25646-07DA-497D-821D-5A16BB7A684A}.job
[2011.06.01 17:38:16 | 000,036,579 | ---- | M] () -- C:\Users\Alex\Documents\Gmer.rtf
[2011.06.01 17:36:59 | 000,000,398 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{32723199-A1BE-4670-9193-A50997F9A519}.job
[2011.06.01 16:45:10 | 000,638,510 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.06.01 16:45:10 | 000,604,126 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.06.01 16:45:10 | 000,130,462 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.06.01 16:45:10 | 000,107,562 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.06.01 16:39:09 | 000,004,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.06.01 16:39:09 | 000,004,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.06.01 16:38:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.06.01 16:38:41 | 240,519,884 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011.06.01 13:53:20 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{38515D3F-8908-46D7-8055-3092D76ADA21}.job
[2011.05.31 13:47:12 | 000,001,326 | RHS- | M] () -- C:\Users\Alex\ntuser.pol
[2011.05.31 06:42:40 | 000,001,599 | ---- | M] () -- C:\Users\Public\Desktop\S4League.lnk
[2011.05.31 06:37:20 | 711,189,938 | ---- | M] (InstallShield Software Corporation) -- C:\Users\Alex\Desktop\S4League.exe
[2011.05.28 09:48:14 | 000,001,032 | ---- | M] () -- C:\Users\Alex\Desktop\DVDVideoSoft Free Studio.lnk
[2011.05.25 20:19:52 | 000,137,542 | ---- | M] () -- C:\Users\Alex\Documents\gesamter virusbericht.rtf
[2011.05.25 17:49:47 | 000,030,259 | ---- | M] () -- C:\Users\Alex\Desktop\hjtscanlist.bat
[2011.05.25 16:33:08 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.05.24 15:58:33 | 000,236,496 | ---- | M] (Adobe Systems, Incorporated) -- C:\Users\Alex\AppData\Roaming\AcroIEHelpe029.dll
[2011.05.24 06:44:08 | 000,000,428 | ---- | M] () -- C:\Windows\tasks\Error Fix Scan.job
[2011.05.23 17:57:23 | 007,975,821 | ---- | M] () -- C:\Users\Alex\Documents\MafiaBug.rtf
[2011.05.23 16:43:47 | 000,014,408 | ---- | M] () -- C:\Users\Alex\Documents\Antivir².rtf
[2011.05.23 16:08:35 | 000,014,402 | ---- | M] () -- C:\Users\Alex\Documents\Virusbericht 3Funde.rtf
[2011.05.23 14:05:53 | 000,001,280 | ---- | M] () -- C:\Users\Alex\Documents\CMV.rtf
[2011.05.22 19:21:48 | 007,975,821 | ---- | M] () -- C:\Users\Alex\Documents\Barcelona Fan.rtf
[2011.05.21 22:54:49 | 000,001,390 | ---- | M] () -- C:\Users\Alex\Documents\lehrer..rtf
[2011.05.21 14:29:02 | 000,236,496 | ---- | M] (Adobe Systems, Incorporated) -- C:\Users\Alex\AppData\Roaming\AcroIEHelpe.dll
[2011.05.20 16:04:36 | 000,000,962 | ---- | M] () -- C:\Users\Alex\Documents\OGame.de Alte Allianz -ISF-.rtf
[2011.05.16 21:16:26 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.05.16 06:50:36 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011.05.16 06:50:36 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011.05.16 06:50:36 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011.05.16 06:50:36 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011.05.15 19:01:22 | 000,000,846 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.05.14 08:47:32 | 2926,603,649 | ---- | M] () -- C:\Users\Alex\Desktop\rohan_de_installer_20101001.exe
[2011.05.11 16:23:37 | 000,000,210 | ---- | M] () -- C:\Users\Alex\Documents\RunKittyRunmusik.rtf
[2011.05.09 15:11:01 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2011.05.09 07:13:02 | 000,000,680 | ---- | M] () -- C:\Users\Alex\AppData\Local\d3d9caps.dat
[2011.05.08 21:46:23 | 000,001,808 | ---- | M] () -- C:\Users\Alex\Desktop\Counter-Strike Source.lnk
[2011.05.07 13:46:38 | 000,000,823 | ---- | M] () -- C:\Users\Alex\Desktop\T4E Player.lnk
[1 C:\Users\Alex\AppData\Roaming\*.tmp files -> C:\Users\Alex\AppData\Roaming\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.06.01 17:34:11 | 000,036,579 | ---- | C] () -- C:\Users\Alex\Documents\Gmer.rtf
[2011.05.31 06:42:40 | 000,001,599 | ---- | C] () -- C:\Users\Public\Desktop\S4League.lnk
[2011.05.28 09:48:14 | 000,001,032 | ---- | C] () -- C:\Users\Alex\Desktop\DVDVideoSoft Free Studio.lnk
[2011.05.25 20:19:52 | 000,137,542 | ---- | C] () -- C:\Users\Alex\Documents\gesamter virusbericht.rtf
[2011.05.25 20:16:58 | 000,000,889 | ---- | C] () -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.lnk
[2011.05.24 16:03:29 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.05.23 17:57:22 | 007,975,821 | ---- | C] () -- C:\Users\Alex\Documents\MafiaBug.rtf
[2011.05.23 16:43:47 | 000,014,408 | ---- | C] () -- C:\Users\Alex\Documents\Antivir².rtf
[2011.05.23 16:08:35 | 000,014,402 | ---- | C] () -- C:\Users\Alex\Documents\Virusbericht 3Funde.rtf
[2011.05.23 16:01:48 | 000,000,428 | ---- | C] () -- C:\Windows\tasks\Error Fix Scan.job
[2011.05.23 14:05:53 | 000,001,280 | ---- | C] () -- C:\Users\Alex\Documents\CMV.rtf
[2011.05.22 19:21:48 | 007,975,821 | ---- | C] () -- C:\Users\Alex\Documents\Barcelona Fan.rtf
[2011.05.21 22:54:49 | 000,001,390 | ---- | C] () -- C:\Users\Alex\Documents\lehrer..rtf
[2011.05.15 19:45:18 | 000,000,962 | ---- | C] () -- C:\Users\Alex\Documents\OGame.de Alte Allianz -ISF-.rtf
[2011.05.15 19:01:22 | 000,000,846 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.05.14 08:15:34 | 2926,603,649 | ---- | C] () -- C:\Users\Alex\Desktop\rohan_de_installer_20101001.exe
[2011.05.11 16:23:36 | 000,000,210 | ---- | C] () -- C:\Users\Alex\Documents\RunKittyRunmusik.rtf
[2011.05.09 07:13:02 | 000,000,680 | ---- | C] () -- C:\Users\Alex\AppData\Local\d3d9caps.dat
[2011.05.08 21:46:23 | 000,001,808 | ---- | C] () -- C:\Users\Alex\Desktop\Counter-Strike Source.lnk
[2011.05.07 13:46:38 | 000,000,823 | ---- | C] () -- C:\Users\Alex\Desktop\T4E Player.lnk
[2011.04.26 13:31:37 | 000,000,112 | ---- | C] () -- C:\ProgramData\56iE4qch.dat
[2011.03.27 15:22:11 | 000,000,151 | ---- | C] () -- C:\Windows\PhotoSnapViewer.INI
[2011.03.24 20:04:02 | 000,065,040 | ---- | C] () -- C:\Windows\War3Unin.dat
[2011.02.28 19:04:27 | 000,045,568 | ---- | C] () -- C:\Windows\UniFish3.exe
[2011.02.19 23:03:25 | 000,000,000 | ---- | C] () -- C:\Windows\msicpl.ini
[2009.08.02 16:29:26 | 000,000,276 | ---- | C] () -- C:\Windows\thug2.ini
[2009.05.27 17:05:42 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.05.27 17:05:42 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2008.12.28 04:59:54 | 000,138,608 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2008.12.28 04:59:37 | 000,189,800 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2008.12.28 04:59:35 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2008.12.28 04:59:34 | 000,000,274 | ---- | C] () -- C:\Windows\game.ini
[2008.12.21 13:51:15 | 000,069,632 | ---- | C] () -- C:\Windows\RAUNINST.EXE
[2008.11.21 20:30:29 | 000,000,040 | ---- | C] () -- C:\Windows\nfsc_patch.ini
[2008.11.02 22:46:37 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2008.11.02 22:46:37 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2008.11.02 22:17:35 | 000,000,050 | ---- | C] () -- C:\Windows\System32\bridf07a.dat
[2008.11.02 22:14:55 | 000,106,496 | ---- | C] () -- C:\Windows\System32\BrMuSNMP.dll
[2008.09.10 17:25:40 | 000,116,224 | ---- | C] () -- C:\Windows\System32\redmonnt.dll
[2008.09.02 17:04:44 | 000,765,952 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2008.09.02 17:04:44 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2008.08.07 11:52:24 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008.04.11 17:24:03 | 000,399,736 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2008.04.10 17:28:40 | 000,000,049 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2008.04.02 15:52:26 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2008.03.18 18:53:53 | 000,053,248 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2008.03.17 17:05:08 | 000,000,034 | ---- | C] () -- C:\Windows\cdplayer.ini
[2008.02.27 10:30:18 | 000,000,022 | ---- | C] () -- C:\ProgramData\60a7806a-0eea-424c-a464-20f4730cd631
[2008.01.04 13:38:57 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2007.12.23 12:00:36 | 000,000,026 | ---- | C] () -- C:\Windows\NeoSetup.INI
[2007.12.23 11:50:55 | 000,000,010 | ---- | C] () -- C:\Windows\popcinfo.dat
[2007.12.16 15:11:36 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2007.12.09 22:15:31 | 000,479,232 | ---- | C] () -- C:\Windows\System32\HookShield.dll
[2007.12.09 22:15:31 | 000,040,960 | ---- | C] () -- C:\Windows\System32\executeosd.exe
[2007.12.09 22:15:30 | 000,134,504 | ---- | C] () -- C:\Windows\System32\smdll.dll
[2007.12.09 22:15:30 | 000,036,200 | ---- | C] () -- C:\Windows\System32\Auxiliary.dll
[2007.12.09 22:15:28 | 000,036,864 | ---- | C] () -- C:\Windows\System32\startup.exe
[2007.12.09 22:15:27 | 000,462,848 | ---- | C] () -- C:\Windows\System32\HookMap.dll
[2007.12.09 20:23:49 | 000,502,784 | ---- | C] () -- C:\Windows\x2.64.exe
[2007.12.09 20:23:49 | 000,408,576 | ---- | C] () -- C:\Windows\System32\Smab.dll
[2007.12.09 20:23:49 | 000,240,128 | ---- | C] () -- C:\Windows\System32\x.264.exe
[2007.12.09 20:23:49 | 000,217,073 | ---- | C] () -- C:\Windows\meta4.exe
[2007.12.09 20:23:49 | 000,066,560 | ---- | C] () -- C:\Windows\MOTA113.exe
[2007.12.09 20:23:49 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2007.11.20 16:24:52 | 000,159,744 | ---- | C] () -- C:\Windows\gdf.dll
[2007.08.23 18:30:00 | 000,007,680 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2007.04.27 10:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2006.11.02 17:33:31 | 000,638,510 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 17:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 17:33:31 | 000,130,462 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 17:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,272,288 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 000,604,126 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,107,562 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[1997.06.14 13:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll

< End of report >

--- --- ---



Otl.exe/Extras
OTL Logfile:
Code:

OTL Extras logfile created on: 01.06.2011 17:38:04 - Run 6
OTL by OldTimer - Version 3.2.23.0    Folder = C:\Users\Alex\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 0,80 Gb Available Physical Memory | 40,13% Memory free
4,25 Gb Paging File | 2,71 Gb Available in Paging File | 63,78% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116,50 Gb Total Space | 57,52 Gb Free Space | 49,37% Space Free | Partition Type: NTFS
Drive E: | 68,36 Gb Total Space | 49,30 Gb Free Space | 72,12% Space Free | Partition Type: NTFS
Drive F: | 48,03 Gb Total Space | 29,19 Gb Free Space | 60,78% Space Free | Partition Type: NTFS
 
Computer Name: MARCSPC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- Reg Error: Key error. File not found
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\ProgFiles\VLC MediaPlayer\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\ProgFiles\VLC MediaPlayer\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{065E1C38-973B-420F-B300-BDE7042A66CD}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{153011C4-F9EB-4BF1-AEBB-27FB9BA2E179}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3DD9E3BA-BBE6-4022-AB7A-BF11F5A333FE}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{59671036-B829-4941-A9E3-F7379DB24EB0}" = lport=6112 | protocol=17 | dir=in | name=warcraft hosten (udp) |
"{603119FC-035D-4A3A-9327-6807EC4345EF}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{6F655981-E0B6-49CB-9EED-1541861992A3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{74474826-2651-4A2C-97A1-92B0A325D5B6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8ECFC677-3E3C-4DE5-9DBE-FFC1C658C195}" = rport=67 | protocol=17 | dir=in | svc=dhcp | app=c:\windows\system32\svchost.exe |
"{A5A54654-BB71-4AEB-831F-7E0C6A3EE5C0}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{AA24654D-64AE-4106-8141-753E04303CC4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{AD3F7378-5448-477B-8039-67EA7A916894}" = rport=53 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{ADB8B2A9-030F-4370-9AD3-9C1952FE31E0}" = rport=10243 | protocol=6 | dir=out | app=system |
"{B4099ED2-9F02-4B59-BD07-15BA42878DEB}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{BF180437-BA42-47EA-86C4-E1034F2652C9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C1674B6F-19D8-46E7-B498-56D0B5AC4B01}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{D0B4E190-D7AC-4816-B1F6-9BA877D28CED}" = lport=49161 | protocol=6 | dir=in | name=akamai netsession interface |
"{DCDF20B5-C6DC-4B06-9DCB-71E40B6C704A}" = lport=6112 | protocol=6 | dir=in | name=warcraft hosten (tcp) |
"{DEE52D1E-7AD8-4587-8797-A336A942CFD1}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{DFB2FDC5-AC69-46D9-B918-C8D3C3D1C974}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E4ED2BDD-F5F1-4448-86EF-22328182D7C2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F0AD1039-C922-48D5-A915-75A6627719C8}" = lport=teredo | protocol=17 | dir=in | svc=iphlpsvc | app=c:\windows\system32\svchost.exe |
"{F4B94E0C-13A7-4238-ADE2-CFEA87226B1E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FD234473-D514-4495-9D7E-DA93CD8571DF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FD9D77BE-C2C6-46A8-B921-44B7FF0CC0AC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FEBE93D1-C791-43D6-A149-03E12BAA9F98}" = rport=67 | protocol=17 | dir=out | svc=dhcp | app=c:\windows\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03EA7C1D-C51B-4363-B127-4D11EF1F7CF2}" = protocol=41 | dir=out | app=system |
"{07857146-54F5-404C-B2AF-23E5F8B270FD}" = protocol=58 | dir=in | app=system |
"{0AE01A6B-3E5B-4186-B521-5E57A0908AF6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1516A6E8-5B15-4ADC-B6A7-AC141C8EB166}" = protocol=58 | dir=out | name=kernnetzwerk - routerankündigung (icmpv6 ausgehend) |
"{18398135-4B64-4406-B89A-6893889751F4}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{19C5B54D-4E44-4D0F-A81B-8721687466C0}" = protocol=58 | dir=in | app=system |
"{2D881E67-AC89-4417-B94D-B1F12B22AEEA}" = protocol=58 | dir=in | app=system |
"{3056500B-E1AD-4B9F-9192-61A8C5A36D06}" = protocol=17 | dir=in | app=c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\k72rmm3k\users_root_file_file[1].exe |
"{3127CCFC-444D-4677-8BB6-3FCADB49CC9D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{31F7B4CC-315B-4771-90C5-2346508D32D1}" = protocol=58 | dir=out | name=kernnetzwerk - multicastabhörabfrage (icmpv6 ausgehend) |
"{34975BFD-5193-4648-88B8-E11456940F7E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{35318073-168C-4CBA-9ACC-B5B5C2438A5B}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{380053FD-4EC8-48C1-B580-87E0EA7C9CCD}" = protocol=6 | dir=in | app=c:\progfiles\itunes\itunes.exe |
"{4B50C50A-C5D8-4BB1-BF95-4FA8348197CA}" = protocol=1 | dir=in | app=system |
"{52C5FB71-3087-40A9-9258-02A001F6C752}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{539EE3FA-207C-4BA5-B539-F9F7695B6704}" = protocol=58 | dir=in | app=system |
"{5C96D9AE-02AC-4F75-8531-9BE55F67520D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{60231891-8EDF-4967-908D-0B19B961CF5F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6B0D204E-BE84-4507-BC7F-E9C0D60E0ACE}" = protocol=58 | dir=out | name=kernnetzwerk - zeitüberschreitung (icmpv6 ausgehend) |
"{6EB29043-E7B3-4627-95F5-862CEE5B892B}" = protocol=58 | dir=in | app=system |
"{72EE8667-87C0-4714-B93C-FA98BA3AF6F4}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{790FFA2C-EBCD-4103-A7C1-3447363CEEAB}" = protocol=58 | dir=out | name=kernnetzwerk - multicastabhörbericht (icmpv6 ausgehend) |
"{7B6C17ED-459C-41E4-890B-7854F2B640B3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7E07FE11-8F48-4EC8-8ABF-5F96B4E9BC6D}" = protocol=17 | dir=in | app=c:\program files\sony ericsson\sony ericsson media manager\mediamanager.exe |
"{847993E7-A11C-4B11-9DCA-C208A2650937}" = protocol=17 | dir=in | app=c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\k72rmm3k\users_root_file_file[1].exe |
"{857BDD0D-295F-4026-BEEF-2DD2A010222D}" = protocol=58 | dir=in | app=system |
"{8BA0DDA9-D3C0-4D15-A650-6213891173AB}" = protocol=17 | dir=in | app=c:\progfiles\itunes\itunes.exe |
"{8E493B07-5F47-48F6-AE90-5C7E3DB88CD5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{921E215D-E43B-4C4C-8FD3-4A0B3B8481D1}" = protocol=58 | dir=out | name=kernnetzwerk - nachbarermittlungsanfrage (icmpv6 ausgehend) |
"{92D14525-95D6-4698-AD31-7ECFA02F7350}" = protocol=58 | dir=out | name=kernnetzwerk - multicastabhörbericht v2 (icmpv6 ausgehend) |
"{965E55CF-7ADF-495F-95A5-262731EDFCA2}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{9B91B485-E126-4A8C-A06A-6EA661D9E790}" = protocol=41 | dir=in | app=system |
"{9C1649E5-F2C9-4A26-8FDD-1C1686D24D6B}" = protocol=58 | dir=out | name=kernnetzwerk - nachbarermittlungsankündigung (icmpv6 ausgehend) |
"{A6B366F9-F865-4036-AD89-BB5308496B7D}" = protocol=58 | dir=out | name=kernnetzwerk - routeranfrage (icmpv6 ausgehend) |
"{A9E45AAD-C3EB-46C3-B13F-618218A2B693}" = protocol=17 | dir=out | svc=iphlpsvc | app=c:\windows\system32\svchost.exe |
"{AB2F0A65-7D60-4257-8191-CA9AEC3BF39F}" = protocol=6 | dir=out | app=system |
"{AE50CCDF-CE9B-49E5-A7EE-8234071B33B8}" = protocol=2 | dir=in | app=system |
"{AF3964B1-517D-43AD-B6E8-9869A17C1799}" = protocol=6 | dir=in | app=c:\program files\sony ericsson\sony ericsson media manager\mediamanager.exe |
"{AF6942F8-3D04-470D-B417-A814BE9CF585}" = protocol=58 | dir=out | name=kernnetzwerk - multicastabhörvorgang abgeschlossen (icmpv6 ausgehend) |
"{B17E2752-A463-4FF4-88D3-5BB5228E1C09}" = protocol=58 | dir=in | app=system |
"{BEDDA3A2-E64C-4CFD-9438-0763C8ECCCF5}" = protocol=58 | dir=in | app=system |
"{C151598C-C645-4AB0-A7BF-3943C343F230}" = protocol=58 | dir=in | app=system |
"{C46D1837-4E3D-4637-BFCD-B9FF14FC106A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D083D3B2-816D-43ED-A0AF-8577CE985BDD}" = protocol=2 | dir=out | app=system |
"{D67D5A69-C19C-4255-BFB3-398D2BEF48FA}" = protocol=6 | dir=in | app=c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\k72rmm3k\users_root_file_file[1].exe |
"{D9C8C3D5-E97B-4275-A216-267C11A87FB4}" = protocol=58 | dir=in | app=system |
"{E2982187-6155-4B4C-AD9D-556DB2CC8AE4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E444E485-F907-4E74-876E-7F05871BAB07}" = protocol=58 | dir=in | app=system |
"{E68D854F-15AC-4168-89FC-B4D5B8CFDCD1}" = protocol=58 | dir=out | name=kernnetzwerk - parameterproblem (icmpv6 ausgehend) |
"{E8089052-4DA6-4B5F-9A62-293A4498981B}" = protocol=58 | dir=out | name=kernnetzwerk - paket zu gross (icmpv6 ausgehend) |
"{E97F0E39-5924-4C45-9DCB-E7A96F9C7533}" = protocol=58 | dir=in | app=system |
"{F38372D4-EF54-4052-B299-FF49CFA53380}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{F3FCC74E-5FC4-48AD-BEF1-87402F2B2D79}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FACAEB83-3312-4D9C-979D-241358EA7513}" = protocol=6 | dir=in | app=c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\k72rmm3k\users_root_file_file[1].exe |
"TCP Query User{040A77D4-C269-4FEC-9843-AE0918C9F810}C:\progfiles\java\jdk1.6.0_07\jre\bin\java.exe" = protocol=6 | dir=in | app=c:\progfiles\java\jdk1.6.0_07\jre\bin\java.exe |
"TCP Query User{0D1A2328-BB85-406B-B69A-21DCD2E563F5}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=6 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe |
"TCP Query User{22372A26-D688-4650-953E-FB0CBE63AD6F}F:\warcraft iii\war3.exe" = protocol=6 | dir=in | app=f:\warcraft iii\war3.exe |
"TCP Query User{288018B9-20ED-4065-8190-340DAB7156C1}F:\css\hl2.exe" = protocol=6 | dir=in | app=f:\css\hl2.exe |
"TCP Query User{2D9EE5FD-7FAF-4D3D-A6FB-6BF3AF079657}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"TCP Query User{2E648958-69DD-4501-8A4E-0D9DCE0AF2F8}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{2FE0DB96-0D88-4DE3-99C4-97245DF2D068}F:\callofduty4\iw3mp.exe" = protocol=6 | dir=in | app=f:\callofduty4\iw3mp.exe |
"TCP Query User{4518FABE-E6A7-4276-98A6-212B8B70330F}F:\ageofempiresii\empires2.exe" = protocol=6 | dir=in | app=f:\ageofempiresii\empires2.exe |
"TCP Query User{475C53F3-55E2-402E-AB30-70E9C7CD1C3F}F:\warcraft iii\war3.exe" = protocol=6 | dir=in | app=f:\warcraft iii\war3.exe |
"TCP Query User{58D32D27-08C6-44E3-800F-358C6990D4B2}F:\ageofempiresii\empires2.exe" = protocol=6 | dir=in | app=f:\ageofempiresii\empires2.exe |
"TCP Query User{5A0DF772-B951-4485-906B-9AE926786D3F}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{62F9BB5A-047F-45AB-9888-7227980F8F96}C:\progfiles\screamerradio\screamer.exe" = protocol=6 | dir=in | app=c:\progfiles\screamerradio\screamer.exe |
"TCP Query User{68A290FC-BF34-4278-BC2D-1F0543CAB416}C:\progfiles\zattoo\zattood.exe" = protocol=6 | dir=in | app=c:\progfiles\zattoo\zattood.exe |
"TCP Query User{6BEB8DDB-06FE-49DF-9D3B-A60123DC6F19}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=6 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"TCP Query User{70972043-A089-4B7D-9CEB-02940A6501B9}C:\users\marc\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=6 | dir=in | app=c:\users\marc\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"TCP Query User{740BAB1F-6D64-4B75-A0F0-2C0959463A21}F:\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=f:\tmnationsforever\tmforever.exe |
"TCP Query User{7CF46998-ED4B-44FE-BA2A-9DB7CE7E7919}F:\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=f:\tmnationsforever\tmforever.exe |
"TCP Query User{84E52A8F-7A12-4E26-A5A3-E94F139147A1}C:\progfiles\garena\garena.exe" = protocol=6 | dir=in | app=c:\progfiles\garena\garena.exe |
"TCP Query User{87862B45-EA94-4065-A0D2-D0814254A4B4}C:\users\marc\desktop\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=c:\users\marc\desktop\call of duty 2\cod2mp_s.exe |
"TCP Query User{8B10CF85-D4DC-44A4-A5D8-EF6E6A8D09B1}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{8EB4347A-06C9-4FF2-9592-57C118DBD47E}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{986C8BEC-9FAE-4AFE-9768-C9391CD2B4AB}C:\progfiles\firefox\firefox.exe" = protocol=6 | dir=in | app=c:\progfiles\firefox\firefox.exe |
"TCP Query User{98A2A7F9-770B-4676-A924-FFF15EA432BE}F:\cs\valve\hl.exe" = protocol=6 | dir=in | app=f:\cs\valve\hl.exe |
"TCP Query User{99311A98-6A0C-419A-81E4-C68269C737EB}C:\program files\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\counter-strike source\hl2.exe |
"TCP Query User{B53B81CA-32F9-4D7C-9431-B17872382D31}F:\cs\valve\hl.exe" = protocol=6 | dir=in | app=f:\cs\valve\hl.exe |
"TCP Query User{BDF81878-22DF-4784-8B0D-063E84A4BB2B}F:\heroesofnewerth\hon.exe" = protocol=6 | dir=in | app=f:\heroesofnewerth\hon.exe |
"TCP Query User{D7127690-B8D7-4BCB-BE91-B9777A037CBA}C:\aeriagames\rohan\rohanclient.exe" = protocol=6 | dir=in | app=c:\aeriagames\rohan\rohanclient.exe |
"TCP Query User{DDD2B434-CB82-48A1-AECC-E57EC3D967E8}C:\progfiles\icq6\icq.exe" = protocol=6 | dir=in | app=c:\progfiles\icq6\icq.exe |
"TCP Query User{E61D138D-11DC-4EF7-9B44-F68CF26866D4}F:\css\hl2.exe" = protocol=6 | dir=in | app=f:\css\hl2.exe |
"TCP Query User{E8B709B1-9ACC-49DE-9EAA-702937865120}F:\serios sam ii\bin\sam2.exe" = protocol=6 | dir=in | app=f:\serios sam ii\bin\sam2.exe |
"TCP Query User{E8EC0FD6-9538-4903-8B6A-0B62353E23F1}F:\ageofempiresii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=f:\ageofempiresii\age2_x1\age2_x1.exe |
"TCP Query User{E91CD75E-963F-43A5-B4E3-825044A163B8}F:\ageofempiresii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=f:\ageofempiresii\age2_x1\age2_x1.exe |
"TCP Query User{ED0BDEDC-B31B-4F37-BCC9-446AE8A1921B}F:\heroesofnewerth\hon.exe" = protocol=6 | dir=in | app=f:\heroesofnewerth\hon.exe |
"TCP Query User{EDA64722-9CC6-41AA-A50D-A3D5DB7D2E84}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{F2484FDC-7C5E-4351-A3F9-3012DDBA3C8E}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{03E7B46B-31B0-436D-A1EE-DFD92363438E}F:\css\hl2.exe" = protocol=17 | dir=in | app=f:\css\hl2.exe |
"UDP Query User{0969CEB8-4C31-4381-95F0-7049E7E22BE3}F:\css\hl2.exe" = protocol=17 | dir=in | app=f:\css\hl2.exe |
"UDP Query User{10EC67F6-663D-47A2-A4D6-F5AFF2C10406}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{13544F0F-3A35-4B25-9F54-CA3ED7FFF3DC}C:\progfiles\firefox\firefox.exe" = protocol=17 | dir=in | app=c:\progfiles\firefox\firefox.exe |
"UDP Query User{1935E1FF-9806-4C40-BBAD-29AE173F99B5}F:\warcraft iii\war3.exe" = protocol=17 | dir=in | app=f:\warcraft iii\war3.exe |
"UDP Query User{217316AA-80B0-4B6D-A694-4D03F611CE9C}C:\progfiles\screamerradio\screamer.exe" = protocol=17 | dir=in | app=c:\progfiles\screamerradio\screamer.exe |
"UDP Query User{2B3C385E-FBB8-4C6B-A3C9-C9808776DE65}F:\heroesofnewerth\hon.exe" = protocol=17 | dir=in | app=f:\heroesofnewerth\hon.exe |
"UDP Query User{315F4795-2594-4011-A831-281BADCCCD69}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{42C667E3-7F8D-4844-A3C8-100B870922E3}F:\serios sam ii\bin\sam2.exe" = protocol=17 | dir=in | app=f:\serios sam ii\bin\sam2.exe |
"UDP Query User{435FFE92-F275-40B0-BC64-6FE106BF4A2A}C:\program files\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\counter-strike source\hl2.exe |
"UDP Query User{46D5DB42-95CF-4125-AE0A-A61419396A55}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{5540E194-BF17-4517-BB89-88962D3EADC1}C:\aeriagames\rohan\rohanclient.exe" = protocol=17 | dir=in | app=c:\aeriagames\rohan\rohanclient.exe |
"UDP Query User{5586E9DA-02D1-41CC-898D-ED60E72152B3}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=17 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"UDP Query User{56F3ABFF-8D06-4332-B5AD-F85EA33E7E91}F:\callofduty4\iw3mp.exe" = protocol=17 | dir=in | app=f:\callofduty4\iw3mp.exe |
"UDP Query User{57F199C6-D85F-4715-A523-2A2069E2E38C}F:\cs\valve\hl.exe" = protocol=17 | dir=in | app=f:\cs\valve\hl.exe |
"UDP Query User{59C856D3-5AB1-4F10-90EF-D4EB41491BB4}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=17 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe |
"UDP Query User{66575AE9-C0D4-454C-8157-FCB1129EB4BD}F:\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=f:\tmnationsforever\tmforever.exe |
"UDP Query User{6AC60CC6-AFC7-4E39-944C-BA11887C964D}F:\ageofempiresii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=f:\ageofempiresii\age2_x1\age2_x1.exe |
"UDP Query User{6D0260B9-6763-485A-A942-EC606691F259}F:\cs\valve\hl.exe" = protocol=17 | dir=in | app=f:\cs\valve\hl.exe |
"UDP Query User{6F78FF01-CA2C-4BE8-9B19-6B274198FEC5}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{70904A82-EF0D-46D5-9628-BF11580D11E2}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{710C74B2-1A3C-46E0-A97D-240CAB43E0C1}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{85E1CFB1-B4AA-4ED5-9D14-F5CFF96B2B76}C:\progfiles\garena\garena.exe" = protocol=17 | dir=in | app=c:\progfiles\garena\garena.exe |
"UDP Query User{95428427-AFB4-4EE3-A146-6049A5A7E105}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{9C18AEC0-4DA4-4F32-9019-B51D3B240235}F:\warcraft iii\war3.exe" = protocol=17 | dir=in | app=f:\warcraft iii\war3.exe |
"UDP Query User{9E22FA4F-0B9A-438C-8912-66BF20ACEEC2}F:\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=f:\tmnationsforever\tmforever.exe |
"UDP Query User{A1FA7043-06C2-4E10-AD02-9C99BD56FD8D}F:\ageofempiresii\empires2.exe" = protocol=17 | dir=in | app=f:\ageofempiresii\empires2.exe |
"UDP Query User{B6D23BB0-FC4C-4F83-A59E-EAA0B3331E00}F:\ageofempiresii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=f:\ageofempiresii\age2_x1\age2_x1.exe |
"UDP Query User{BADEBABF-AF1B-4478-B5AB-34D0EC5E04E0}C:\progfiles\zattoo\zattood.exe" = protocol=17 | dir=in | app=c:\progfiles\zattoo\zattood.exe |
"UDP Query User{C4405CDE-EF56-4DF8-A473-00952B53ACD5}F:\ageofempiresii\empires2.exe" = protocol=17 | dir=in | app=f:\ageofempiresii\empires2.exe |
"UDP Query User{D58B51BF-353D-4741-A9CD-B1EE0C087809}C:\progfiles\java\jdk1.6.0_07\jre\bin\java.exe" = protocol=17 | dir=in | app=c:\progfiles\java\jdk1.6.0_07\jre\bin\java.exe |
"UDP Query User{DA60D498-5BFB-4FAE-8A46-810771B87052}C:\users\marc\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=17 | dir=in | app=c:\users\marc\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"UDP Query User{DE111D63-5C5B-4405-96CE-7DD7528E9CCC}F:\heroesofnewerth\hon.exe" = protocol=17 | dir=in | app=f:\heroesofnewerth\hon.exe |
"UDP Query User{F2F2DBF3-F3F1-4F89-B8CD-1A5332A2A027}C:\users\marc\desktop\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=c:\users\marc\desktop\call of duty 2\cod2mp_s.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0192ED7A-0AF2-426B-AFDF-AD8506295C94}" = Error Fix
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{128A6D30-D64D-4923-8EA3-4A4C536E0A4C}" = Mega ePower 85 Software
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{259C0ABB-A3B2-4D70-008F-BF7EE491B70B}" = Need for Speed™ Carbon
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java(TM) 6 Update 25
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{32A3A4F4-B792-11D6-A78A-00B0D0160070}" = Java(TM) SE Development Kit 6 Update 7
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{451C4ACA-0B6A-4564-BD9D-A6C365DB9C76}_is1" = Bombermaaan 1.4
"{45235788-142C-44BE-8A4D-DDE9A84492E5}" = AGEIA PhysX v7.09.13
"{4BA56822-4E76-42EC-883F-52EF0859957E}" = S4 League_EU
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{61E3FE32-07B9-4563-A3E0-2DE2D620FE10}" = PixiePack Codec Pack
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7EC19307-7C22-47A8-922B-3FA965291260}" = OpenOffice.org 3.0
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{909F8EBC-EC7F-48FF-0085-475D818F0F31}" = Need for Speed Underground 2
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98EA51C9-B0B0-45BC-8641-3E119EA47D7B}" = Sony Ericsson Media Manager 1.2
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{AC76BA86-7AD7-1031-7B44-A82000000003}" = Adobe Reader 8.2.0 - Deutsch
"{ADC20BE6-8CA6-4989-B3E8-68EBD2AF1031}" = Nero 7 Essentials
"{C60BA916-9E44-4DA4-B11A-9E27B7624EF5}" = Sony Ericsson Drivers
"{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}" = Sony Ericsson Device Data
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD49361E-3FE6-457E-90A1-9C59E29B5D02}" = Java DB 10.3.1.4
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D59AC9E9-FFAE-471B-B1FF-4B311D23417A}" = Sony Ericsson PC Suite
"{D6BF6477-8369-489F-8DE6-3731F4B88560}" = Sony Ericsson PC Suite
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{EF1394D4-9FB6-4F1F-9A09-20FF3033AE14}" = Tony Hawk's Underground 2
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"7-Zip" = 7-Zip 4.57
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AFPL Ghostscript 8.54" = AFPL Ghostscript 8.54
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"Akamai" = Akamai NetSession Interface
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"CCleaner" = CCleaner
"Cossacks : Back To War" = Cossacks - Back To War
"Counter-Strike: Source" = Counter-Strike: Source
"DX-Ball 1.09" = DX-Ball 1.09
"ffdshow_is1" = ffdshow [rev 2033] [2008-07-05]
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"Free Studio_is1" = Free Studio version 5.0.9
"FreePDF_XP" = FreePDF XP (Remove only)
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{EF1394D4-9FB6-4F1F-9A09-20FF3033AE14}" = Tony Hawk's Underground 2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox 4.0.1 (x86 de)" = Mozilla Firefox 4.0.1 (x86 de)
"NVIDIA Drivers" = NVIDIA Drivers
"Red Alert" = Red Alert Windows 95
"Rohan_DE" = R.O.H.A.N. Vendetta
"SpeedSim" = SpeedSim
"SuperTux_is1" = SuperTux 0.1.3
"T4EPlayer" = T4E Player
"TmNationsForever_is1" = TmNationsForever
"UltraStar Deluxe" = UltraStar Deluxe
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.0.3
"Warcraft III" = Warcraft III
"Xvid_is1" = Xvid 1.1.3 final uninstall
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Warcraft III" = Warcraft III: All Products
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 06.08.2009 15:12:18 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 16.08.2009 18:00:19 | Computer Name = MarcsPC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 20.08.2009 07:02:33 | Computer Name = MarcsPC | Source = ESENT | ID = 215
Description = WinMail (3060) WindowsMail0: Die Sicherung wurde abgebrochen, weil
 sie vom Client angehalten wurde, oder weil die Verbindung mit dem Client unterbrochen
 wurde.
 
Error - 20.08.2009 07:04:30 | Computer Name = MarcsPC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
 
[ Media Center Events ]
Error - 16.04.2008 09:35:30 | Computer Name = MarcsPC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight
 gescheitert.
 
Error - 18.04.2008 12:54:59 | Computer Name = MarcsPC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight
 gescheitert.
 
Error - 18.04.2008 16:09:11 | Computer Name = MarcsPC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight
 gescheitert.
 
[ System Events ]
Error - 01.06.2011 02:35:03 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
Error - 01.06.2011 07:52:19 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7026
Description =
 
Error - 01.06.2011 08:09:02 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
Error - 01.06.2011 08:09:02 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
Error - 01.06.2011 09:25:07 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7026
Description =
 
Error - 01.06.2011 09:46:20 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
Error - 01.06.2011 09:46:20 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
Error - 01.06.2011 10:10:35 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7032
Description =
 
Error - 01.06.2011 10:38:47 | Computer Name = MarcsPC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 01.06.2011 um 16:37:26 unerwartet heruntergefahren.
 
Error - 01.06.2011 10:40:20 | Computer Name = MarcsPC | Source = Service Control Manager | ID = 7026
Description =
 
 
< End of report >

--- --- ---

MasterDragon 01.06.2011 17:00

und jetzt das dritte und letzte Stück.

4.Gmer
Code:

GMER 1.0.15.15640 - hxxp://www.gmer.net
Rootkit scan 2011-06-01 17:29:33
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdePort4 SAMSUNG_HD250HJ rev.FH100-05
Running: xrzv5vp7.exe; Driver: C:\Users\Alex\AppData\Local\Temp\kxldypog.sys


---- System - GMER 1.0.15 ----

INT 0x52  ?                                                                                                                        84458BF8
INT 0x52  ?                                                                                                                        84458BF8
INT 0x52  ?                                                                                                                        84458BF8
INT 0x52  ?                                                                                                                        84458BF8
INT 0x52  ?                                                                                                                        863A5BF8
INT 0x52  ?                                                                                                                        84458BF8
INT 0x62  ?                                                                                                                        84458BF8
INT 0x72  ?                                                                                                                        84458BF8
INT 0xB4  ?                                                                                                                        863A5BF8

---- Kernel code sections - GMER 1.0.15 ----

?        System32\Drivers\sper.sys                                                                                                Das System kann den angegebenen Pfad nicht finden. !
.text    USBPORT.SYS!DllUnload                                                                                                    8839441B 5 Bytes  JMP 863A51D8
.text    C:\Windows\system32\DRIVERS\nvlddmkm.sys                                                                                  section is writeable [0x8D400340, 0x39DB57, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text    C:\Windows\Explorer.EXE[296] ntdll.dll!NtProtectVirtualMemory                                                            770E4B84 5 Bytes  JMP 0179000A
.text    C:\Windows\Explorer.EXE[296] ntdll.dll!NtWriteVirtualMemory                                                              770E54C4 5 Bytes  JMP 017A000A
.text    C:\Windows\Explorer.EXE[296] ntdll.dll!KiUserExceptionDispatcher                                                          770E5BF8 5 Bytes  JMP 004C000A
.text    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe[1004] kernel32.dll!TerminateProcess            75D118EF 6 Bytes  PUSH 02502680; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe[1004] kernel32.dll!FindNextFileA                75D32FF9 6 Bytes  PUSH 025024D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe[1004] kernel32.dll!FindNextFileW                75D3B79E 6 Bytes  PUSH 02502590; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe[1004] kernel32.dll!ExitProcess                  75D541D8 6 Bytes  PUSH 02502630; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe[1004] ADVAPI32.dll!RegDeleteValueA              75E12F59 6 Bytes  PUSH 02502340; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe[1004] ADVAPI32.dll!RegDeleteValueW              75E13FB6 6 Bytes  PUSH 025023D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe[1004] WS2_32.dll!closesocket                    75C8330C 5 Bytes  JMP 026B9E64
.text    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe[1004] WS2_32.dll!recv                          75C8343A 5 Bytes  JMP 026B9AE2
.text    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe[1004] WS2_32.dll!WSASend                        75C84496 5 Bytes  JMP 026B9BB5
.text    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe[1004] WS2_32.dll!send                          75C8659B 5 Bytes  JMP 026B9A01
.text    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe[1004] WS2_32.dll!WSARecv                        75C88400 5 Bytes  JMP 026B9D16
.text    C:\Windows\system32\svchost.exe[1116] ntdll.dll!NtProtectVirtualMemory                                                    770E4B84 5 Bytes  JMP 004C000A
.text    C:\Windows\system32\svchost.exe[1116] ntdll.dll!NtWriteVirtualMemory                                                      770E54C4 5 Bytes  JMP 004F000A
.text    C:\Windows\system32\svchost.exe[1116] ntdll.dll!KiUserExceptionDispatcher                                                770E5BF8 5 Bytes  JMP 004B000A
.text    C:\Windows\system32\svchost.exe[1116] ole32.dll!CoCreateInstance                                                          75B29F3E 5 Bytes  JMP 0062000A
.text    C:\Windows\system32\svchost.exe[1116] USER32.dll!WindowFromPoint                                                          7594884F 5 Bytes  JMP 018F000A
.text    C:\Windows\system32\svchost.exe[1116] USER32.dll!GetForegroundWindow                                                      759532C4 5 Bytes  JMP 0190000A
.text    C:\Windows\system32\svchost.exe[1116] USER32.dll!GetCursorPos                                                            75960B88 5 Bytes  JMP 013E000A
.text    C:\Windows\system32\taskeng.exe[1996] kernel32.dll!TerminateProcess                                                      75D118EF 6 Bytes  PUSH 031A2680; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\system32\taskeng.exe[1996] kernel32.dll!FindNextFileA                                                          75D32FF9 6 Bytes  PUSH 031A24D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\system32\taskeng.exe[1996] kernel32.dll!FindNextFileW                                                          75D3B79E 6 Bytes  PUSH 031A2590; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\system32\taskeng.exe[1996] kernel32.dll!ExitProcess                                                            75D541D8 6 Bytes  PUSH 031A2630; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\system32\taskeng.exe[1996] ADVAPI32.dll!RegDeleteValueA                                                        75E12F59 6 Bytes  PUSH 031A2340; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\system32\taskeng.exe[1996] ADVAPI32.dll!RegDeleteValueW                                                        75E13FB6 6 Bytes  PUSH 031A23D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\system32\taskeng.exe[1996] WS2_32.dll!closesocket                                                              75C8330C 5 Bytes  JMP 02289E64
.text    C:\Windows\system32\taskeng.exe[1996] WS2_32.dll!recv                                                                    75C8343A 5 Bytes  JMP 02289AE2
.text    C:\Windows\system32\taskeng.exe[1996] WS2_32.dll!WSASend                                                                  75C84496 5 Bytes  JMP 02289BB5
.text    C:\Windows\system32\taskeng.exe[1996] WS2_32.dll!send                                                                    75C8659B 5 Bytes  JMP 02289A01
.text    C:\Windows\system32\taskeng.exe[1996] WS2_32.dll!WSARecv                                                                  75C88400 5 Bytes  JMP 02289D16
.text    C:\Windows\system32\Dwm.exe[2012] kernel32.dll!TerminateProcess                                                          75D118EF 6 Bytes  PUSH 05FE2680; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\system32\Dwm.exe[2012] kernel32.dll!FindNextFileA                                                              75D32FF9 6 Bytes  PUSH 05FE24D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\system32\Dwm.exe[2012] kernel32.dll!FindNextFileW                                                              75D3B79E 6 Bytes  PUSH 05FE2590; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\system32\Dwm.exe[2012] kernel32.dll!ExitProcess                                                                75D541D8 6 Bytes  PUSH 05FE2630; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\system32\Dwm.exe[2012] ADVAPI32.dll!RegDeleteValueA                                                            75E12F59 6 Bytes  PUSH 05FE2340; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\system32\Dwm.exe[2012] ADVAPI32.dll!RegDeleteValueW                                                            75E13FB6 6 Bytes  PUSH 05FE23D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\system32\Dwm.exe[2012] WS2_32.dll!closesocket                                                                  75C8330C 5 Bytes  JMP 06389E64
.text    C:\Windows\system32\Dwm.exe[2012] WS2_32.dll!recv                                                                        75C8343A 5 Bytes  JMP 06389AE2
.text    C:\Windows\system32\Dwm.exe[2012] WS2_32.dll!WSASend                                                                      75C84496 5 Bytes  JMP 06389BB5
.text    C:\Windows\system32\Dwm.exe[2012] WS2_32.dll!send                                                                        75C8659B 5 Bytes  JMP 06389A01
.text    C:\Windows\system32\Dwm.exe[2012] WS2_32.dll!WSARecv                                                                      75C88400 5 Bytes  JMP 06389D16
.text    C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe[2748] kernel32.dll!TerminateProcess                                          75D118EF 6 Bytes  PUSH 02082680; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe[2748] kernel32.dll!FindNextFileA                                            75D32FF9 6 Bytes  PUSH 020824D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe[2748] kernel32.dll!FindNextFileW                                            75D3B79E 6 Bytes  PUSH 02082590; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe[2748] kernel32.dll!ExitProcess                                              75D541D8 6 Bytes  PUSH 02082630; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe[2748] ADVAPI32.dll!RegDeleteValueA                                          75E12F59 6 Bytes  PUSH 02082340; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe[2748] ADVAPI32.dll!RegDeleteValueW                                          75E13FB6 6 Bytes  PUSH 020823D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe[2748] WS2_32.dll!closesocket                                                75C8330C 5 Bytes  JMP 02E69E64
.text    C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe[2748] WS2_32.dll!recv                                                        75C8343A 5 Bytes  JMP 02E69AE2
.text    C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe[2748] WS2_32.dll!WSASend                                                    75C84496 5 Bytes  JMP 02E69BB5
.text    C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe[2748] WS2_32.dll!send                                                        75C8659B 5 Bytes  JMP 02E69A01
.text    C:\Progfiles\Avira\AntiVir Desktop\avgnt.exe[2748] WS2_32.dll!WSARecv                                                    75C88400 5 Bytes  JMP 02E69D16
.text    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe[2828] kernel32.dll!TerminateProcess  75D118EF 6 Bytes  PUSH 00AB2680; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe[2828] kernel32.dll!FindNextFileA    75D32FF9 6 Bytes  PUSH 00AB24D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe[2828] kernel32.dll!FindNextFileW    75D3B79E 6 Bytes  PUSH 00AB2590; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe[2828] kernel32.dll!ExitProcess      75D541D8 6 Bytes  PUSH 00AB2630; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe[2828] ADVAPI32.dll!RegDeleteValueA  75E12F59 6 Bytes  PUSH 00AB2340; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe[2828] ADVAPI32.dll!RegDeleteValueW  75E13FB6 6 Bytes  PUSH 00AB23D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe[2828] WS2_32.dll!closesocket        75C8330C 5 Bytes  JMP 01EF9E64
.text    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe[2828] WS2_32.dll!recv                75C8343A 5 Bytes  JMP 01EF9AE2
.text    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe[2828] WS2_32.dll!WSASend            75C84496 5 Bytes  JMP 01EF9BB5
.text    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe[2828] WS2_32.dll!send                75C8659B 5 Bytes  JMP 01EF9A01
.text    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe[2828] WS2_32.dll!WSARecv            75C88400 5 Bytes  JMP 01EF9D16
.text    C:\Windows\System32\rundll32.exe[2856] kernel32.dll!TerminateProcess                                                      75D118EF 6 Bytes  PUSH 00C72680; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\System32\rundll32.exe[2856] kernel32.dll!FindNextFileA                                                        75D32FF9 6 Bytes  PUSH 00C724D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\System32\rundll32.exe[2856] kernel32.dll!FindNextFileW                                                        75D3B79E 6 Bytes  PUSH 00C72590; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\System32\rundll32.exe[2856] kernel32.dll!ExitProcess                                                          75D541D8 6 Bytes  PUSH 00C72630; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\System32\rundll32.exe[2856] ADVAPI32.dll!RegDeleteValueA                                                      75E12F59 6 Bytes  PUSH 00C72340; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\System32\rundll32.exe[2856] ADVAPI32.dll!RegDeleteValueW                                                      75E13FB6 6 Bytes  PUSH 00C723D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Windows\System32\rundll32.exe[2856] WS2_32.dll!closesocket                                                            75C8330C 5 Bytes  JMP 02249E64
.text    C:\Windows\System32\rundll32.exe[2856] WS2_32.dll!recv                                                                    75C8343A 5 Bytes  JMP 02249AE2
.text    C:\Windows\System32\rundll32.exe[2856] WS2_32.dll!WSASend                                                                75C84496 5 Bytes  JMP 02249BB5
.text    C:\Windows\System32\rundll32.exe[2856] WS2_32.dll!send                                                                    75C8659B 5 Bytes  JMP 02249A01
.text    C:\Windows\System32\rundll32.exe[2856] WS2_32.dll!WSARecv                                                                75C88400 5 Bytes  JMP 02249D16
.text    C:\Program Files\Windows Sidebar\sidebar.exe[2864] kernel32.dll!TerminateProcess                                          75D118EF 6 Bytes  PUSH 05FC2680; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Windows Sidebar\sidebar.exe[2864] kernel32.dll!FindNextFileA                                            75D32FF9 6 Bytes  PUSH 05FC24D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Windows Sidebar\sidebar.exe[2864] kernel32.dll!FindNextFileW                                            75D3B79E 6 Bytes  PUSH 05FC2590; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Windows Sidebar\sidebar.exe[2864] kernel32.dll!ExitProcess                                              75D541D8 6 Bytes  PUSH 05FC2630; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Windows Sidebar\sidebar.exe[2864] ADVAPI32.dll!RegDeleteValueA                                          75E12F59 6 Bytes  PUSH 05FC2340; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Windows Sidebar\sidebar.exe[2864] ADVAPI32.dll!RegDeleteValueW                                          75E13FB6 6 Bytes  PUSH 05FC23D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Windows Sidebar\sidebar.exe[2864] WS2_32.dll!closesocket                                                75C8330C 5 Bytes  JMP 05309E64
.text    C:\Program Files\Windows Sidebar\sidebar.exe[2864] WS2_32.dll!recv                                                        75C8343A 5 Bytes  JMP 05309AE2
.text    C:\Program Files\Windows Sidebar\sidebar.exe[2864] WS2_32.dll!WSASend                                                    75C84496 5 Bytes  JMP 05309BB5
.text    C:\Program Files\Windows Sidebar\sidebar.exe[2864] WS2_32.dll!send                                                        75C8659B 5 Bytes  JMP 05309A01
.text    C:\Program Files\Windows Sidebar\sidebar.exe[2864] WS2_32.dll!WSARecv                                                    75C88400 5 Bytes  JMP 05309D16
.text    C:\Program Files\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin[3032] kernel32.dll!TerminateProcess                75D118EF 6 Bytes  PUSH 05CA2680; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin[3032] kernel32.dll!FindNextFileA                    75D32FF9 6 Bytes  PUSH 05CA24D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin[3032] kernel32.dll!FindNextFileW                    75D3B79E 6 Bytes  PUSH 05CA2590; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin[3032] kernel32.dll!ExitProcess                      75D541D8 6 Bytes  PUSH 05CA2630; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin[3032] ADVAPI32.dll!RegDeleteValueA                  75E12F59 6 Bytes  PUSH 05CA2340; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin[3032] ADVAPI32.dll!RegDeleteValueW                  75E13FB6 6 Bytes  PUSH 05CA23D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin[3032] WS2_32.dll!closesocket                        75C8330C 5 Bytes  JMP 05DB9E64
.text    C:\Program Files\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin[3032] WS2_32.dll!recv                              75C8343A 5 Bytes  JMP 05DB9AE2
.text    C:\Program Files\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin[3032] WS2_32.dll!WSASend                            75C84496 5 Bytes  JMP 05DB9BB5
.text    C:\Program Files\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin[3032] WS2_32.dll!send                              75C8659B 5 Bytes  JMP 05DB9A01
.text    C:\Program Files\OpenOffice3.0.1\OpenOffice.org 3\program\soffice.bin[3032] WS2_32.dll!WSARecv                            75C88400 5 Bytes  JMP 05DB9D16
.text    C:\Program Files\Common Files\Teleca Shared\Generic.exe[4044] kernel32.dll!TerminateProcess                              75D118EF 6 Bytes  PUSH 03C62680; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Common Files\Teleca Shared\Generic.exe[4044] kernel32.dll!FindNextFileA                                  75D32FF9 6 Bytes  PUSH 03C624D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Common Files\Teleca Shared\Generic.exe[4044] kernel32.dll!FindNextFileW                                  75D3B79E 6 Bytes  PUSH 03C62590; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Common Files\Teleca Shared\Generic.exe[4044] kernel32.dll!ExitProcess                                    75D541D8 6 Bytes  PUSH 03C62630; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Common Files\Teleca Shared\Generic.exe[4044] ADVAPI32.dll!RegDeleteValueA                                75E12F59 6 Bytes  PUSH 03C62340; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Common Files\Teleca Shared\Generic.exe[4044] ADVAPI32.dll!RegDeleteValueW                                75E13FB6 6 Bytes  PUSH 03C623D0; RET C:\Windows\system32\hloads57.dll (zhvlevupcutixuctcqcstqn/Comp)
.text    C:\Program Files\Common Files\Teleca Shared\Generic.exe[4044] ws2_32.dll!closesocket                                      75C8330C 5 Bytes  JMP 01D79E64
.text    C:\Program Files\Common Files\Teleca Shared\Generic.exe[4044] ws2_32.dll!recv                                            75C8343A 5 Bytes  JMP 01D79AE2
.text    C:\Program Files\Common Files\Teleca Shared\Generic.exe[4044] ws2_32.dll!WSASend                                          75C84496 5 Bytes  JMP 01D79BB5
.text    C:\Program Files\Common Files\Teleca Shared\Generic.exe[4044] ws2_32.dll!send                                            75C8659B 5 Bytes  JMP 01D79A01
.text    C:\Program Files\Common Files\Teleca Shared\Generic.exe[4044] ws2_32.dll!WSARecv                                          75C88400 5 Bytes  JMP 01D79D16

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT      \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar]                                                [806056D2] \SystemRoot\System32\Drivers\sper.sys
IAT      \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar]                                                  [80605040] \SystemRoot\System32\Drivers\sper.sys
IAT      \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort]                                          [806057FC] \SystemRoot\System32\Drivers\sper.sys
IAT      \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort]                                                [806050BE] \SystemRoot\System32\Drivers\sper.sys
IAT      \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort]                                          [8060513C] \SystemRoot\System32\Drivers\sper.sys

---- Devices - GMER 1.0.15 ----

Device    \FileSystem\Ntfs \Ntfs                                                                                                    8521D1F8
Device    \Driver\volmgr \Device\VolMgrControl                                                                                      8445A1F8
Device    \Driver\usbohci \Device\USBPDO-0                                                                                          863831F8
Device    \Driver\usbehci \Device\USBPDO-1                                                                                          849701F8
Device    \Driver\volmgr \Device\HarddiskVolume1                                                                                    8445A1F8
Device    \Driver\volmgr \Device\HarddiskVolume2                                                                                    8445A1F8
Device    \Driver\cdrom \Device\CdRom0                                                                                              849731F8
Device    \Driver\atapi \Device\Ide\IdePort0                                                                                        8521B1F8
Device    \Driver\atapi \Device\Ide\IdePort1                                                                                        8521B1F8
Device    \Driver\atapi \Device\Ide\IdePort2                                                                                        8521B1F8
Device    \Driver\atapi \Device\Ide\IdePort3                                                                                        8521B1F8
Device    \Driver\atapi \Device\Ide\IdePort4                                                                                        8521B1F8
Device    \Driver\atapi \Device\Ide\IdePort5                                                                                        8521B1F8
Device    \Driver\msahci \Device\Ide\PciIde1Channel0                                                                                8521C1F8
Device    \Driver\msahci \Device\Ide\PciIde1Channel1                                                                                8521C1F8
Device    \Driver\msahci \Device\Ide\PciIde1Channel2                                                                                8521C1F8
Device    \Driver\msahci \Device\Ide\PciIde1Channel3                                                                                8521C1F8
Device    \Driver\atapi \Device\Ide\IdeDeviceP5T0L0-7                                                                              8521B1F8
Device    \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-6                                                                              8521B1F8
Device    \Driver\volmgr \Device\HarddiskVolume3                                                                                    8445A1F8
Device    \Driver\netbt \Device\NetBt_Wins_Export                                                                                  86631500
Device    \Driver\Smb \Device\NetbiosSmb                                                                                            8653D1F8
Device    \Driver\netbt \Device\NetBT_Tcpip_{B00D18A5-30D7-4BB1-A95A-9A338C37A8F2}                                                  86631500
Device    \Driver\iScsiPrt \Device\RaidPort0                                                                                        863871F8
Device    \Driver\usbohci \Device\USBFDO-0                                                                                          863831F8
Device    \Driver\usbehci \Device\USBFDO-1                                                                                          849701F8
Device    \FileSystem\cdfs \Cdfs                                                                                                    8704A1F8

---- Registry - GMER 1.0.15 ----

Reg      HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)                     
Reg      HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                          C:\ProgFiles\DAEMON_Tools\
Reg      HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                          0
Reg      HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                        0x7B 0x51 0x82 0x42 ...
Reg      HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)           
Reg      HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                                  0x20 0x01 0x00 0x00 ...
Reg      HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                              0x96 0xC1 0x1B 0x2D ...
Reg      HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)     
Reg      HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                        0xD4 0xFE 0x4C 0x64 ...
Reg      HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)     
Reg      HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh                        0x32 0xF6 0x33 0xC3 ...
Reg      HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)                     
Reg      HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                          C:\ProgFiles\DAEMON_Tools\
Reg      HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                          0
Reg      HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                        0x7B 0x51 0x82 0x42 ...
Reg      HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)           
Reg      HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                                  0x20 0x01 0x00 0x00 ...
Reg      HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                              0x96 0xC1 0x1B 0x2D ...
Reg      HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)     
Reg      HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                        0xD4 0xFE 0x4C 0x64 ...
Reg      HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)     
Reg      HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh                        0x32 0xF6 0x33 0xC3 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1                                                                        771343423
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2                                                                        285507792
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0                                                                        1
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                         
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                      C:\ProgFiles\DAEMON_Tools\
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                      0
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                    0x7B 0x51 0x82 0x42 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001                               
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                              0x20 0x01 0x00 0x00 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                          0x96 0xC1 0x1B 0x2D ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40                         
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                    0xD4 0xFE 0x4C 0x64 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41                         
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh                    0x32 0xF6 0x33 0xC3 ...

---- Disk sectors - GMER 1.0.15 ----

Disk      \Device\Harddisk0\DR0                                                                                                    TDL4@MBR code has been found                                                                          <-- ROOTKIT !!!
Disk      \Device\Harddisk0\DR0                                                                                                    sector 00: rootkit-like behavior

---- EOF - GMER 1.0.15 ----

5. War nichts drinnen.

Danke dir nochmal für die Hilfe. :)
Und wollte nebenbei mal fragen woher du dein Computertechnisches wissen hast. :)

kira 01.06.2011 20:04

In einem anderen Forum Einschulung gehabt. Natürlich die Entwicklung geht weiter, weil ja es werden (leider) ständig neue Viren erzeugt. Aber wir zeigen uns kämpferisch und versuchen das Beste draus zu machen:)
Ansonsten einfach Hobby von mir, weil Bereich der Virenbekämpfung sehr interessant ist, auch eine Herausforderung und man hilft doch auch gern ...
ausserdem es wird von Jahr zu Jahr interessanter, eine sehr gute Erfahrung und man sehr viel dabei lernen kann;)


- Nun ist es traurige Gewissheit, vermutlich das bösartige MBR-Rootkit hat sich im MBR festgesetzt...
Der Master Boot Record (MBR) der ersten Festplatte wird beim Start des Rechners geladen, noch vor dem Betriebssystem. Code, der Dort residiert, kann im Prinzip das Betriebssystem kontrollieren.

- wenn Du statt Format C:\ für Systemreinigung entscheidest, dann so geht`s weiter:

TDSSKiller von Kaspersky
  • Lade den TDSSKiller und entpacke das Archiv auf Deinen Desktop.
  • Vergewissere Dich, dass die TDSSKiller.exe direkt auf dem Desktop liegt (nicht in einem Ordner auf dem Desktop).
  • deaktiviere vorübergehend dein AntiVirus-Programm
  • Starte die TDSSKiller.exe durch Doppelklick.
  • Nach Beendigung der Arbeit schlägt das Tool vor, das System neu zu starten.
    Bestätige das ggfs. mit Y(es).
    Beim Hochfahren des Systems führt der Treiber alle geplanten Operationen aus löscht sich danach.
  • Poste mir den Inhalt von C:\TDSSKiller<random>.txt hier in den Thread.
Hier findest Du eine ausführlichere Anleitung.

MasterDragon 01.06.2011 22:24

Achso okey.
Weil ich mir jetzt auchn bisschen das schreiben beigebracht hab.

Also wie darf ich das denn verstehn?
- Nun ist es traurige Gewissheit, vermutlich das bösartige MBR-Rootkit hat sich im MBR festgesetzt...
Der Master Boot Record (MBR) der ersten Festplatte wird beim Start des Rechners geladen, noch vor dem Betriebssystem. Code, der Dort residiert, kann im Prinzip das Betriebssystem kontrollieren.

- wenn Du statt Format C:\ für Systemreinigung entscheidest, dann so geht`s weiter:

und wie zieh ich das auf den Desktop und nicht in einem Ordner auf den Desktop?

kira 01.06.2011 22:32

keine Ordner anlegen für...

MasterDragon 01.06.2011 22:47

So, ich hab das jetz durchlaufen lassen und ich glaube hab alles richtig gemacht und dann nochmal durchlaufen lassen, und da stand nichts gefunden beim 2.Durchlauf.

Aber soetwas kam nicht wie du sagtes kein logfile und keine geplanten Operationen.

Aber es müsste jetzt endlich drausen sein oder?
Wenn ja dann ein großes dickes :dankeschoen: an dich! :)
Hast mir echt super geholfen.

kira 02.06.2011 08:08

das Protokoll vom ersten Durchlauf bitte hier posten!!-> C:\TDSSKiller<random>.txt

MasterDragon 02.06.2011 08:39

Code:

2011/06/01 23:38:53.0311 4084        TDSS rootkit removing tool 2.5.3.0 May 25 2011 07:09:24
2011/06/01 23:38:53.0410 4084        ================================================================================
2011/06/01 23:38:53.0410 4084        SystemInfo:
2011/06/01 23:38:53.0410 4084       
2011/06/01 23:38:53.0410 4084        OS Version: 6.0.6002 ServicePack: 2.0
2011/06/01 23:38:53.0410 4084        Product type: Workstation
2011/06/01 23:38:53.0410 4084        ComputerName: MARCSPC
2011/06/01 23:38:53.0410 4084        UserName: Alex
2011/06/01 23:38:53.0410 4084        Windows directory: C:\Windows
2011/06/01 23:38:53.0410 4084        System windows directory: C:\Windows
2011/06/01 23:38:53.0411 4084        Processor architecture: Intel x86
2011/06/01 23:38:53.0411 4084        Number of processors: 2
2011/06/01 23:38:53.0411 4084        Page size: 0x1000
2011/06/01 23:38:53.0411 4084        Boot type: Normal boot
2011/06/01 23:38:53.0411 4084        ================================================================================
2011/06/01 23:38:54.0394 4084        Initialize success
2011/06/01 23:38:59.0232 5000        ================================================================================
2011/06/01 23:38:59.0233 5000        Scan started
2011/06/01 23:38:59.0233 5000        Mode: Manual;
2011/06/01 23:38:59.0233 5000        ================================================================================
2011/06/01 23:39:01.0034 5000        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/06/01 23:39:01.0092 5000        adp94xx        (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
2011/06/01 23:39:01.0135 5000        adpahci        (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
2011/06/01 23:39:01.0163 5000        adpu160m        (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
2011/06/01 23:39:01.0187 5000        adpu320        (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
2011/06/01 23:39:01.0257 5000        AFD            (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2011/06/01 23:39:01.0288 5000        agp440          (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys
2011/06/01 23:39:01.0315 5000        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/06/01 23:39:01.0354 5000        aliide          (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
2011/06/01 23:39:01.0383 5000        amdagp          (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
2011/06/01 23:39:01.0406 5000        amdide          (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
2011/06/01 23:39:01.0431 5000        AmdK7          (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
2011/06/01 23:39:01.0474 5000        AmdK8          (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
2011/06/01 23:39:01.0757 5000        arc            (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
2011/06/01 23:39:01.0860 5000        arcsas          (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
2011/06/01 23:39:01.0901 5000        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/06/01 23:39:01.0943 5000        atapi          (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/06/01 23:39:02.0107 5000        avgio          (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Progfiles\Avira\AntiVir Desktop\avgio.sys
2011/06/01 23:39:02.0161 5000        avgntflt        (47b879406246ffdced59e18d331a0e7d) C:\Windows\system32\DRIVERS\avgntflt.sys
2011/06/01 23:39:02.0222 5000        avipbb          (5fedef54757b34fb611b9ec8fb399364) C:\Windows\system32\DRIVERS\avipbb.sys
2011/06/01 23:39:02.0258 5000        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/06/01 23:39:02.0336 5000        bowser          (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
2011/06/01 23:39:02.0390 5000        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/06/01 23:39:02.0438 5000        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/06/01 23:39:02.0482 5000        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/06/01 23:39:02.0510 5000        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/06/01 23:39:02.0541 5000        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/06/01 23:39:02.0560 5000        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/06/01 23:39:02.0589 5000        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/06/01 23:39:02.0662 5000        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/06/01 23:39:02.0699 5000        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/06/01 23:39:02.0729 5000        circlass        (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
2011/06/01 23:39:02.0786 5000        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/06/01 23:39:02.0829 5000        cmdide          (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
2011/06/01 23:39:02.0855 5000        Compbatt        (82b8c91d327cfecf76cb58716f7d4997) C:\Windows\system32\drivers\compbatt.sys
2011/06/01 23:39:02.0898 5000        crcdisk        (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
2011/06/01 23:39:02.0928 5000        Crusoe          (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
2011/06/01 23:39:03.0020 5000        DfsC            (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2011/06/01 23:39:03.0058 5000        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/06/01 23:39:03.0114 5000        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/06/01 23:39:03.0333 5000        DXGKrnl        (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/06/01 23:39:03.0393 5000        E1G60          (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/06/01 23:39:03.0455 5000        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/06/01 23:39:03.0516 5000        elxstor        (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
2011/06/01 23:39:03.0626 5000        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/06/01 23:39:03.0674 5000        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/06/01 23:39:03.0720 5000        fdc            (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/06/01 23:39:03.0775 5000        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/06/01 23:39:03.0823 5000        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/06/01 23:39:03.0841 5000        flpydisk        (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/06/01 23:39:03.0905 5000        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/06/01 23:39:03.0943 5000        Fs_Rec          (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/06/01 23:39:03.0994 5000        gagp30kx        (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
2011/06/01 23:39:04.0068 5000        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2011/06/01 23:39:04.0198 5000        hamachi        (7929a161f9951d173ca9900fe7067391) C:\Windows\system32\DRIVERS\hamachi.sys
2011/06/01 23:39:04.0246 5000        HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
2011/06/01 23:39:04.0308 5000        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/06/01 23:39:04.0349 5000        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/06/01 23:39:04.0388 5000        HidIr          (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/06/01 23:39:04.0441 5000        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2011/06/01 23:39:04.0516 5000        HpCISSs        (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
2011/06/01 23:39:04.0591 5000        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2011/06/01 23:39:04.0641 5000        i2omp          (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
2011/06/01 23:39:04.0704 5000        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/06/01 23:39:04.0757 5000        iaStorV        (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
2011/06/01 23:39:04.0812 5000        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/06/01 23:39:04.0863 5000        intelide        (97469037714070e45194ed318d636401) C:\Windows\system32\drivers\intelide.sys
2011/06/01 23:39:04.0901 5000        intelppm        (ce44cc04262f28216dd4341e9e36a16f) C:\Windows\system32\DRIVERS\intelppm.sys
2011/06/01 23:39:04.0945 5000        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/06/01 23:39:05.0001 5000        IPMIDRV        (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
2011/06/01 23:39:05.0047 5000        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/06/01 23:39:05.0104 5000        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/06/01 23:39:05.0150 5000        isapnp          (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
2011/06/01 23:39:05.0202 5000        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/06/01 23:39:05.0237 5000        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/06/01 23:39:05.0260 5000        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/06/01 23:39:05.0303 5000        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/06/01 23:39:05.0346 5000        kbdhid          (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/06/01 23:39:05.0452 5000        KSecDD          (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/06/01 23:39:05.0568 5000        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/06/01 23:39:05.0672 5000        LSI_FC          (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
2011/06/01 23:39:05.0768 5000        LSI_SAS        (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
2011/06/01 23:39:05.0923 5000        LSI_SCSI        (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
2011/06/01 23:39:06.0007 5000        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/06/01 23:39:06.0041 5000        megasas        (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
2011/06/01 23:39:06.0093 5000        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/06/01 23:39:06.0143 5000        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/06/01 23:39:06.0190 5000        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/06/01 23:39:06.0241 5000        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/06/01 23:39:06.0282 5000        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/06/01 23:39:06.0332 5000        mpio            (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
2011/06/01 23:39:06.0374 5000        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/06/01 23:39:06.0413 5000        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/06/01 23:39:06.0457 5000        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/06/01 23:39:06.0505 5000        mrxsmb          (5fe5cf325f5b02ebc60832d3440cb414) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/06/01 23:39:06.0540 5000        mrxsmb10        (30b9c769446af379a2afb72b0392604d) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/06/01 23:39:06.0584 5000        mrxsmb20        (fea239b3ec4877e2b7e23204af589ddf) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/06/01 23:39:06.0620 5000        msahci          (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys
2011/06/01 23:39:06.0658 5000        msdsm          (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
2011/06/01 23:39:06.0751 5000        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/06/01 23:39:06.0807 5000        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/06/01 23:39:06.0852 5000        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/06/01 23:39:06.0886 5000        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/06/01 23:39:06.0914 5000        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/06/01 23:39:06.0970 5000        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/06/01 23:39:07.0029 5000        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/06/01 23:39:07.0113 5000        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/06/01 23:39:07.0140 5000        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/06/01 23:39:07.0191 5000        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/06/01 23:39:07.0273 5000        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/06/01 23:39:07.0300 5000        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/06/01 23:39:07.0371 5000        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/06/01 23:39:07.0399 5000        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/06/01 23:39:07.0448 5000        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/06/01 23:39:07.0486 5000        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/06/01 23:39:07.0533 5000        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/06/01 23:39:07.0678 5000        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/06/01 23:39:07.0749 5000        nmwcd          (9a908a9bb857c2cceb2907eb9dcaeb8b) C:\Windows\system32\drivers\ccdcmb.sys
2011/06/01 23:39:07.0803 5000        nmwcdc          (68ec3ee2348e475ea62c66e6aafcfc9b) C:\Windows\system32\drivers\ccdcmbo.sys
2011/06/01 23:39:07.0849 5000        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/06/01 23:39:07.0913 5000        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/06/01 23:39:08.0114 5000        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/06/01 23:39:08.0162 5000        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/06/01 23:39:08.0193 5000        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/06/01 23:39:08.0579 5000        nvlddmkm        (f623c2b16fde938b908031aeba445344) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/06/01 23:39:08.0984 5000        nvraid          (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
2011/06/01 23:39:09.0010 5000        nvstor          (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
2011/06/01 23:39:09.0040 5000        nv_agp          (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
2011/06/01 23:39:09.0109 5000        ohci1394        (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
2011/06/01 23:39:09.0166 5000        Parport        (8a79fdf04a73428597e2caf9d0d67850) C:\Windows\system32\DRIVERS\parport.sys
2011/06/01 23:39:09.0226 5000        partmgr        (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/06/01 23:39:09.0261 5000        Parvdm          (6c580025c81caf3ae9e3617c22cad00e) C:\Windows\system32\DRIVERS\parvdm.sys
2011/06/01 23:39:09.0333 5000        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/06/01 23:39:09.0445 5000        pciide          (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
2011/06/01 23:39:09.0528 5000        pcmcia          (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2011/06/01 23:39:09.0694 5000        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/06/01 23:39:09.0785 5000        PLCNDIS5        (2aba2f545b35f9c6cc2cfc4e1d539a80) C:\Windows\system32\PLCNDIS5.SYS
2011/06/01 23:39:09.0976 5000        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/06/01 23:39:10.0017 5000        Processor      (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
2011/06/01 23:39:10.0062 5000        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/06/01 23:39:10.0106 5000        PxHelp20        (03e0fe281823ba64b3782f5b38950e73) C:\Windows\system32\Drivers\PxHelp20.sys
2011/06/01 23:39:10.0151 5000        ql2300          (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
2011/06/01 23:39:10.0203 5000        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/06/01 23:39:10.0246 5000        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/06/01 23:39:10.0269 5000        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/06/01 23:39:10.0330 5000        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/06/01 23:39:10.0375 5000        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/06/01 23:39:10.0419 5000        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/06/01 23:39:10.0457 5000        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/06/01 23:39:10.0485 5000        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/06/01 23:39:10.0540 5000        rdpdr          (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
2011/06/01 23:39:10.0567 5000        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/06/01 23:39:10.0630 5000        RDPWD          (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/06/01 23:39:10.0688 5000        RMCAST          (eec7ee5675294b03e88aa868540007c1) C:\Windows\system32\DRIVERS\RMCAST.sys
2011/06/01 23:39:10.0714 5000        ROOTMODEM      (75e8a6bfa7374aba833ae92bf41ae4e6) C:\Windows\system32\Drivers\RootMdm.sys
2011/06/01 23:39:10.0772 5000        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/06/01 23:39:10.0805 5000        RTL8169        (283392af1860ecdb5e0f8ebd7f3d72df) C:\Windows\system32\DRIVERS\Rtlh86.sys
2011/06/01 23:39:10.0880 5000        s816bus        (8c156e6b568aa927eb5deadeb870bdd2) C:\Windows\system32\DRIVERS\s816bus.sys
2011/06/01 23:39:10.0910 5000        s816mdfl        (d4ed429953a2b8b09c702805813a26c8) C:\Windows\system32\DRIVERS\s816mdfl.sys
2011/06/01 23:39:10.0940 5000        s816mdm        (94306f371a6ff8b690bea81157111b3b) C:\Windows\system32\DRIVERS\s816mdm.sys
2011/06/01 23:39:10.0968 5000        s816mgmt        (fafdd00abad1b6029bf7f4067764ab41) C:\Windows\system32\DRIVERS\s816mgmt.sys
2011/06/01 23:39:11.0085 5000        s816nd5        (fd0d1e39cb22558d79bff59b66a5874a) C:\Windows\system32\DRIVERS\s816nd5.sys
2011/06/01 23:39:11.0116 5000        s816obex        (8eacd5e46764463e75f171d9bf305348) C:\Windows\system32\DRIVERS\s816obex.sys
2011/06/01 23:39:11.0146 5000        s816unic        (e2090b041b935430abc8e184b7d6cd75) C:\Windows\system32\DRIVERS\s816unic.sys
2011/06/01 23:39:11.0184 5000        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/06/01 23:39:11.0255 5000        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/06/01 23:39:11.0312 5000        Serenum        (ce9ec966638ef0b10b864ddedf62a099) C:\Windows\system32\DRIVERS\serenum.sys
2011/06/01 23:39:11.0343 5000        Serial          (6d663022db3e7058907784ae14b69898) C:\Windows\system32\DRIVERS\serial.sys
2011/06/01 23:39:11.0382 5000        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/06/01 23:39:11.0461 5000        sffdisk        (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys
2011/06/01 23:39:11.0487 5000        sffp_mmc        (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
2011/06/01 23:39:11.0514 5000        sffp_sd        (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys
2011/06/01 23:39:11.0538 5000        sfloppy        (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/06/01 23:39:11.0591 5000        sisagp          (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys
2011/06/01 23:39:11.0640 5000        SiSRaid2        (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
2011/06/01 23:39:11.0670 5000        SiSRaid4        (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
2011/06/01 23:39:11.0732 5000        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/06/01 23:39:11.0788 5000        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/06/01 23:39:11.0853 5000        sptd            (7f1b7c4d446cd3f926af45b8c48bd593) C:\Windows\system32\Drivers\sptd.sys
2011/06/01 23:39:11.0853 5000        Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 7f1b7c4d446cd3f926af45b8c48bd593
2011/06/01 23:39:11.0860 5000        sptd - detected LockedFile.Multi.Generic (1)
2011/06/01 23:39:11.0915 5000        srv            (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
2011/06/01 23:39:11.0962 5000        srv2            (a5940ca32ed206f90be9fabdf6e92de4) C:\Windows\system32\DRIVERS\srv2.sys
2011/06/01 23:39:12.0003 5000        srvnet          (37aa1d560d5fa486c4b11c2f276ada61) C:\Windows\system32\DRIVERS\srvnet.sys
2011/06/01 23:39:12.0047 5000        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
2011/06/01 23:39:12.0104 5000        StMp3Rec        (833ac40f6e7be17951d6d9a956829547) C:\Windows\system32\Drivers\StMp3Rec.sys
2011/06/01 23:39:12.0136 5000        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/06/01 23:39:12.0184 5000        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/06/01 23:39:12.0224 5000        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/06/01 23:39:12.0247 5000        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/06/01 23:39:12.0316 5000        Tcpip          (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2011/06/01 23:39:12.0362 5000        Tcpip6          (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2011/06/01 23:39:12.0415 5000        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2011/06/01 23:39:12.0457 5000        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/06/01 23:39:12.0487 5000        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/06/01 23:39:12.0525 5000        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/06/01 23:39:12.0563 5000        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/06/01 23:39:12.0627 5000        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/06/01 23:39:12.0655 5000        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/06/01 23:39:12.0700 5000        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2011/06/01 23:39:12.0741 5000        uagp35          (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
2011/06/01 23:39:12.0797 5000        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/06/01 23:39:12.0849 5000        uliagpkx        (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
2011/06/01 23:39:12.0880 5000        uliahci        (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
2011/06/01 23:39:12.0914 5000        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/06/01 23:39:12.0948 5000        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/06/01 23:39:12.0985 5000        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/06/01 23:39:13.0028 5000        upperdev        (a34560a5d516a2f5240180370866b99d) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
2011/06/01 23:39:13.0113 5000        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/06/01 23:39:13.0144 5000        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/06/01 23:39:13.0177 5000        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/06/01 23:39:13.0207 5000        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/06/01 23:39:13.0240 5000        usbohci        (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
2011/06/01 23:39:13.0272 5000        usbprint        (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys
2011/06/01 23:39:13.0315 5000        usbser          (d575246188f63de0accf6eac5fb59e6a) C:\Windows\system32\DRIVERS\usbser.sys
2011/06/01 23:39:13.0363 5000        UsbserFilt      (6410eebd6e0427466812858ee84c8467) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
2011/06/01 23:39:13.0413 5000        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/06/01 23:39:13.0437 5000        usbuhci        (325dbbacb8a36af9988ccf40eac228cc) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/06/01 23:39:13.0479 5000        vga            (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/06/01 23:39:13.0512 5000        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/06/01 23:39:13.0541 5000        viaagp          (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
2011/06/01 23:39:13.0563 5000        ViaC7          (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
2011/06/01 23:39:13.0592 5000        viaide          (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
2011/06/01 23:39:13.0633 5000        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/06/01 23:39:13.0694 5000        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2011/06/01 23:39:13.0738 5000        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2011/06/01 23:39:13.0769 5000        vsmraid        (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
2011/06/01 23:39:13.0811 5000        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/06/01 23:39:13.0846 5000        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/06/01 23:39:13.0870 5000        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/06/01 23:39:13.0910 5000        Wd              (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
2011/06/01 23:39:13.0959 5000        Wdf01000        (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/06/01 23:39:14.0092 5000        WmiAcpi        (701a9f884a294327e9141d73746ee279) C:\Windows\system32\drivers\wmiacpi.sys
2011/06/01 23:39:14.0164 5000        WpdUsb          (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/06/01 23:39:14.0214 5000        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/06/01 23:39:14.0283 5000        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/06/01 23:39:14.0376 5000        MBR (0x1B8)    (04d4350ae5fb6fc2ad3e7c26b1323c68) \Device\Harddisk0\DR0
2011/06/01 23:39:14.0382 5000        \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/06/01 23:39:14.0388 5000        ================================================================================
2011/06/01 23:39:14.0388 5000        Scan finished
2011/06/01 23:39:14.0388 5000        ================================================================================
2011/06/01 23:39:14.0404 2728        Detected object count: 2
2011/06/01 23:39:14.0404 2728        Actual detected object count: 2
2011/06/01 23:40:31.0337 2728        HKLM\SYSTEM\ControlSet001\services\sptd - will be deleted after reboot
2011/06/01 23:40:31.0362 2728        HKLM\SYSTEM\ControlSet002\services\sptd - will be deleted after reboot
2011/06/01 23:40:31.0373 2728        HKLM\SYSTEM\ControlSet003\services\sptd - will be deleted after reboot
2011/06/01 23:40:31.0384 2728        C:\Windows\system32\Drivers\sptd.sys - will be deleted after reboot
2011/06/01 23:40:31.0384 2728        LockedFile.Multi.Generic(sptd) - User select action: Delete
2011/06/01 23:40:31.0395 2728        \Device\Harddisk0\DR0 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot
2011/06/01 23:40:31.0395 2728        \Device\Harddisk0\DR0 - ok
2011/06/01 23:40:31.0396 2728        Rootkit.Win32.TDSS.tdl4(\Device\Harddisk0\DR0) - User select action: Cure
2011/06/01 23:40:40.0478 1516        Deinitialize success

So habs gefunden hier der erste Durchlauf.

kira 02.06.2011 08:57

Punkt 4. fehlt auch noch:-> http://www.trojaner-board.de/99473-j...tml#post662613

MasterDragon 02.06.2011 09:55

Wie gesagt das war leer.
Und ist es jetzt immernoch?

kira 02.06.2011 09:59

was war leer?

MasterDragon 02.06.2011 10:11

Dieser CmD befehl log,
und Punkt 4 ist vorhanden

Bei mir verbrauchst du deine Geduld :>

kira 02.06.2011 10:59

Zitat:

Zitat von MasterDragon (Beitrag 667025)
Dieser CmD befehl log,

welche denn genau?

Zitat:

Zitat von MasterDragon (Beitrag 667025)
und Punkt 4 ist vorhanden

wo denn?
Zitat:

Ich würde gerne noch all deine installierten Programme sehen:
Lade dir das Tool Ccleaner herunter
Download
installieren (Software-Lizenzvereinbarung lesen, falls angeboten wird "Füge CCleaner Yahoo! Toolbar hinzu" abwählen)→ starten→ falls nötig - unter Options settings-> "german" einstellen
dann klick auf "Extra (um die installierten Programme auch anzuzeigen)→ weiter auf "Als Textdatei speichern..."
wird eine Textdatei (*.txt) erstellt, kopiere dazu den Inhalt und füge ihn da ein



MasterDragon 02.06.2011 16:36

Der mit Mbr
Aber hatte Nummern vertauscht. :)

Code:

7-Zip 4.57                14.11.2008        2,86MB       
Adobe Flash Player 10 Plugin        Adobe Systems Incorporated        15.05.2011                10.3.181.14
Adobe Flash Player ActiveX        Adobe Systems Incorporated        10.08.2008                9.0.124.0
Adobe Reader 8.2.0 - Deutsch        Adobe Systems Incorporated        26.02.2010        102,0MB        8.2.0
AFPL Ghostscript 8.54                05.03.2008        28,2MB       
AFPL Ghostscript Fonts                05.03.2008        4,82MB       
AGEIA PhysX v7.09.13        AGEIA Technologies, Inc.        02.05.2008        99,6MB        7.09.13
Akamai NetSession Interface                04.04.2011        13,6MB       
Apple Application Support        Apple Inc.        22.03.2011        42,8MB        1.3.2
Apple Software Update        Apple Inc.        22.03.2011        2,16MB        2.1.1.116
Avira AntiVir Personal - Free Antivirus        Avira GmbH        06.05.2011        159,1MB        10.0.0.648
Bombermaaan 1.4        The Bombermaaan team        21.12.2008        9,09MB       
CCleaner        Piriform        19.05.2011        3,63MB        3.06
Cossacks - Back To War                17.03.2008        527MB       
Counter-Strike: Source        Valve        07.05.2011        1.713MB       
DX-Ball 1.09                22.12.2007        2,37MB       
Error Fix        PC Utility, Inc.        22.05.2011        38,2MB        2.8.4170
ffdshow [rev 2033] [2008-07-05]                21.10.2008        11,0MB        1.0
FoxyTunes for Firefox                21.07.2008               
Free Audio CD Burner version 1.4.7        DVDVideoSoft Limited.        02.03.2011        3,02MB       
Free YouTube to MP3 Converter version 3.9.33        DVDVideoSoft Limited.        02.03.2011        3,48MB       
FreeMind                06.01.2008        13,4MB        0.8.0
FreePDF XP (Remove only)                09.09.2008        3,01MB       
Java(TM) 6 Update 25        Oracle        15.05.2011        94,7MB        6.0.250
Java(TM) 6 Update 7        Sun Microsystems, Inc.        26.09.2008        171,1MB        1.6.0.70
Java(TM) SE Development Kit 6 Update 7        Sun Microsystems, Inc.        26.09.2008        371MB        1.6.0.70
Malwarebytes' Anti-Malware        Malwarebytes Corporation        24.05.2011        4,84MB       
Microsoft .NET Framework 1.1                10.12.2007               
Microsoft .NET Framework 1.1 German Language Pack        Microsoft        08.12.2007        3,02MB        1.1.4322
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU        Microsoft Corporation        27.06.2009        37,0MB       
Microsoft .NET Framework 3.5 SP1        Microsoft Corporation        14.05.2009        37,0MB       
Microsoft .NET Framework 4 Client Profile        Microsoft Corporation        16.02.2011        120,3MB        4.0.30319
Microsoft .NET Framework 4 Client Profile DEU Language Pack        Microsoft Corporation        16.02.2011        24,5MB        4.0.30319
Microsoft Age of Empires II                12.01.2009        580MB       
Microsoft Age of Empires II: The Conquerors Expansion                12.01.2009        580MB       
Microsoft Silverlight        Microsoft Corporation        20.04.2011        169,6MB        4.0.60310.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053        Microsoft Corporation        29.07.2009        0,25MB        8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable        Microsoft Corporation        06.04.2008        0,41MB        8.0.56336
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148        Microsoft Corporation        29.07.2009        0,19MB        9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17        Microsoft Corporation        26.05.2009        0,58MB        9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148        Microsoft Corporation        18.02.2011        0,58MB        9.0.30729.4148
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319        Microsoft Corporation        06.05.2011        11,0MB        10.0.30319
Mozilla Firefox 4.0.1 (x86 de)        Mozilla        14.05.2011        30,0MB        4.0.1
MSXML 4.0 SP2 (KB936181)        Microsoft Corporation        15.12.2007        1,27MB        4.20.9848.0
MSXML 4.0 SP2 (KB941833)        Microsoft Corporation        16.12.2007        1,27MB        4.20.9849.0
MSXML 4.0 SP2 (KB954430)        Microsoft Corporation        11.11.2008        1,28MB        4.20.9870.0
MSXML 4.0 SP2 (KB973688)        Microsoft Corporation        23.11.2009        1,34MB        4.20.9876.0
MSXML 4.0 SP2 Parser and SDK        Microsoft Corporation        03.03.2011        36,00KB        4.20.9818.0
Need for Speed Underground 2                09.12.2007        1.732MB       
Need for Speed™ Carbon                18.11.2008        4.994MB       
Nero 7 Essentials        Nero AG        27.02.2011        2.346MB        7.03.0300
NVIDIA Drivers                11.04.2008               
OpenOffice.org 3.0        OpenOffice.org        09.05.2009        347MB        3.0.9379
PixiePack Codec Pack        None        07.04.2008        11,4MB        0.10.6.0
QuickTime        Apple Inc.        22.03.2011        73,7MB        7.68.75.0
R.O.H.A.N. Vendetta        YNK-GAMES Entertainment        04.04.2011        9.788MB        1.00.0000
Red Alert Windows 95                20.12.2008               
Sony Ericsson Media Manager 1.2        Sony Ericsson        22.03.2011        66,2MB        1.2.610
Sony Ericsson PC Suite                02.03.2011        41,9MB        2.10.44
SpeedSim                09.04.2011        0,95MB        0.9.8.1b
SuperTux 0.1.3        SuperTux Development Team        20.09.2008        17,4MB       
T4E Player        Techno4ever        06.05.2011        4,53MB       
TmNationsForever        Nadeo        01.08.2008        717MB       
Tony Hawk's Underground 2        Activision        01.08.2009        2.251MB        1.00.0000
UltraStar Deluxe        USDX Team        14.09.2008        1.634MB        1.01
Uninstall 1.0.0.1                02.03.2011        31,5MB       
VLC media player 1.0.3        VideoLAN Team        05.12.2009        73,1MB        1.0.3
Warcraft III                23.03.2011        1.146MB       
Warcraft III: All Products                23.03.2011        1.146MB       
Xvid 1.1.3 final uninstall        Xvid team (Koepi)        01.09.2008        0,77MB        1.1

Hier sind die Progs nochmal

kira 02.06.2011 21:39

1.
Adobe Reader aktualisieren :
- Bei Installation aufpassen/mitlesen!: Wenn irgendeine Software, Toolbar etc angeboten wird, bitte abwählen! - (z.B "McAfee Security Scan Plus")
Adobe Reader
Oder: Adobe starten-> gehe auf "Hilfe"-> "Nach Update suchen..."

2.
Die alte Java-Versionen verbleiben auf dem PC...aus Sicherheitsgründen müssen entfernt werden,auch in Zukunft darauf achten!
Code:

Java(TM) 6 Update 7
3.
  • lade Dir SUPERAntiSpyware FREE Edition herunter.
  • installiere das Programm und update online.
  • starte SUPERAntiSpyware und klicke auf "Ihren Computer durchsuchen"
  • setze ein Häkchen bei "Kompletter Scan" und klicke auf "Weiter"
  • anschließend alle gefundenen Schadprogramme werden aufgelistet, bei alle Funde Häkchen setzen und mit "OK" bestätigen
  • auf "Weiter" klicken dann "OK" und auf "Fertig stellen"
  • um die Ergebnisse anzuzeigen: auf "Präferenzen" dann auf den "Statistiken und Protokolle" klicken
  • drücke auf "Protokoll anzeigen" - anschließend diesen Bericht bitte speichern und hier posten

4.
- "Link:-> ESET Online Scanner
>>Du sollst nicht die Antivirus-Sicherheitssoftware installieren, sondern dein System nur online scannen<<
Auch auf USB-Sticks, selbstgebrannten Datenträgern, externen Festplatten und anderen Datenträgern können Viren transportiert werden. Man muss daher durch regelmäßige Prüfungen auf Schäden, die durch Malware ("Worm.Win32.Autorun") verursacht worden sein können, überwacht werden. Hierfür sind ser gut geegnet und empfohlen, die auf dem Speichermedium gesicherten Daten, mit Hilfe des kostenlosen Online Scanners zu prüfen.
Schließe jetzt alle externe Datenträgeran (USB Sticks etc) Deinen Rechner an, dabei die Hochstell-Taste [Shift-Taste] gedrückt halten, damit die Autorun-Funktion nicht ausgeführt wird. (So verhindest Du die Ausführung der AUTORUN-Funktion) - Man kann die AUTORUN-Funktion aber auch generell abschalten.► [Sicherheit] Autorun Funktion für mehr Sicherheit auf allen Laufwerken deaktivieren /Avira Support Forum

-> Führe dann einen Komplett-Systemcheck mit Eset/Nod32 durch

- folgendes bitte anhaken > "Remove found threads" und "Scan archives"
- die Scanergebnis als *.txt Dateien speichern)
- meistens "C:\Programme\Eset\EsetOnlineScanner\log.txt"

Vor dem Scan Einstellungen im Internet Explorer:
- "Extras→ Internetoptionen→ Sicherheit":
- alles auf Standardstufe stellen
- Active X erlauben
- um den Scan zu starten: wenn du danach gefragt wirst (den Text in der Informationsleiste ) - ActiveX-Steuerelement installieren lassen

5.
erneut einen Scan mit OTL:
  • Doppelklick auf die OTL.exe
  • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
  • Oben findest Du ein Kästchen mit Ausgabe.
    Wähle bitte Standard-Ausgabe
  • Unter Extra-Registrierung wähle bitte Benutze SafeList.
  • Mache Häckchen bei LOP- und Purity-Prüfung.
  • Klicke nun auf Scan links oben.
  • Wenn der Scan beendet wurde werden zwei Logfiles erstellt.
    Du findest die Logfiles auf Deinem Desktop => OTL.txt und Extras.txt
  • Poste die Logfiles in Code-Tags hier in den Thread.

► Wie ist den aktuellen Zustand des Rechners? Auffälligkeiten, Probleme?

MasterDragon 21.06.2011 21:50

So, ich danke dir mal aber da ich es jeden tag mindestens 3mla versucht habe mit antispy und es sich immer kein rückmeldung ergeben hat hab ich es gelassen und bin in den urlaub zack war ich wieder da gings weiter, dann kammen updates 14stück war voll überrascht jedoch wenn ich diese Installiert hatte zack hatte ich nen fehler und da der pc dann garnet erst bis zu den benutzerkonten gekommen ist hab ich ihn ganz neu installiert
danke für deine Hilfe :)
:dankeschoen:

MasterDragon 27.06.2011 21:05

Wollte mal fragen wo ich mir solches wissen auch anschaffen könnte? x)


Alle Zeitangaben in WEZ +1. Es ist jetzt 13:41 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55