<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Trojaner-Board - Hijacker / HiJackThis Logs posten</title>
		<link>http://www.trojaner-board.de/</link>
		<description>Hier könnt Ihr HiJackThis Logs zwecks Auswertung posten. Ebenso allgemeine Fragen zu Hijackern.</description>
		<language>de</language>
		<lastBuildDate>Thu, 09 Sep 2010 00:53:48 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.trojaner-board.de/images/misc/rss.jpg</url>
			<title>Trojaner-Board - Hijacker / HiJackThis Logs posten</title>
			<link>http://www.trojaner-board.de/</link>
		</image>
		<item>
			<title>Offen BDS/Papras.PK in Windows\system21\jvienify.dll</title>
			<link>http://www.trojaner-board.de/90567-bds-papras-pk-windows-system21-jvienify-dll.html</link>
			<pubDate>Wed, 08 Sep 2010 21:14:37 GMT</pubDate>
			<description>Hallo,  
habe folgendes Problem: 
Beim Online-Banking der Postbank wurde ich am Montag dazu aufgefordert 30 unverbrauchte Tans einzugeben. Dies unterließ ich natürlich, rief die Postbank an, welche mir mitteilte, ich hätte einen Trojaner und den Zugang sperrte. 
Als Virenschutz habe ich Avira...</description>
			<content:encoded><![CDATA[<div>Hallo, <br />
habe folgendes Problem:<br />
Beim Online-Banking der Postbank wurde ich am Montag dazu aufgefordert 30 unverbrauchte Tans einzugeben. Dies unterließ ich natürlich, rief die Postbank an, welche mir mitteilte, ich hätte einen Trojaner und den Zugang sperrte.<br />
Als Virenschutz habe ich Avira Antivir ständig automatisch aktualisiert laufen. Nach erstellen einer Boot-CD am Montag konnte diese keinen Schädling finden. Heute als ich nach der Arbeit nach Hause kam, hatte sich der Rechner aufgehängt, als letztes Bild kam die Fundmeldung des BDS/Papras.PK in Windows\system21\jvienify.dll. Nach Neustart des Rechners mußte ich ca 25x den Fund durch Antivir bestätigen und &quot;Ignorieren&quot;, damit der Rechner sich nicht aufhängt. <br />
Meine Frage: Ist es damit getan die jvienify.dll zu löschen? Diese DLL ist unter google nicht bekannt. Kann das Löschen der jvienify.dll zu schwereren Schäden führen? Was wäre das sinnvollste vorgehen?<br />
Hat noch irgendjemand in Kombination mit Postbank diesen Trojaner?<br />
Danke für eine Rückmeldung<br />
Viele Grüße<br />
paniev</div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>Paniev</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90567-bds-papras-pk-windows-system21-jvienify-dll.html</guid>
		</item>
		<item>
			<title>Offen Aufrufen von google.de führt zu Phishing Seite</title>
			<link>http://www.trojaner-board.de/90559-aufrufen-von-google-de-fuehrt-zu-phishing-seite.html</link>
			<pubDate>Wed, 08 Sep 2010 19:42:09 GMT</pubDate>
			<description><![CDATA[Guten Abend, 
 
gestern als ich auf Arbeit war installierte sich auf meinem Notebook auf einmal selbständig eine Malware namens "Antivirus Security 2010". Im Netz habe ich dann gelesen wie man diese löscht, jedoch habe ich trotzdem immernoch das Problem, dass die google Seite bei mir nicht...]]></description>
			<content:encoded><![CDATA[<div>Guten Abend,<br />
<br />
gestern als ich auf Arbeit war installierte sich auf meinem Notebook auf einmal selbständig eine Malware namens &quot;Antivirus Security 2010&quot;. Im Netz habe ich dann gelesen wie man diese löscht, jedoch habe ich trotzdem immernoch das Problem, dass die google Seite bei mir nicht funktioniert. Wenn ich google.de aufrufe, dann erscheint eine Seite die aussieht wie die englische google Website, ist bei der Suche jedoch total langsam, kommt nicht mit Umlauten klar und die Links will ich gar nicht erst anklicken.<br />
<br />
Um mein Problem zu lösen habe ich bis jetzt folgendes gemacht:<br />
 -Komplettscan mit Avira Antivir<br />
 -Komplettscan mit Spybot S&amp;D<br />
 -Komplettscan Malwarebytes<br />
<br />
Es wurden einige Sachen gefunden, jedoch löst das nicht mein kleines google Problem. Wie fahre ich jetzt am besten fort?<br />
<br />
Anbei mein <a href=51130-anleitung-hijackthis.html>HijackThis</a> Log:<br />
<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">Logfile of Trend Micro <a href=51130-anleitung-hijackthis.html>HijackThis</a> v2.0.4<br />
Scan saved at 21:29:08, on 08.09.2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Programme\-=Security=-\Avira\AntiVir Desktop\sched.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Programme\-=Security=-\Avira\AntiVir Desktop\avgnt.exe<br />
C:\Programme\Apoint\Apoint.exe<br />
C:\Program Files\Sony\ISB Utility\ISBMgr.exe<br />
C:\Programme\Sony\Wireless Switch Setting Utility\Switcher.exe<br />
C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe<br />
C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Programme\FreePDF_XP\fpassist.exe<br />
C:\Programme\DivX\DivX Update\DivXUpdate.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Programme\-=Media=-\DAEMON Tools Lite\DTLite.exe<br />
C:\Programme\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Programme\-=Security=-\Avira\AntiVir Desktop\avguard.exe<br />
C:\xampp\apache\bin\httpd.exe<br />
C:\Programme\Bonjour\mDNSResponder.exe<br />
C:\Programme\Java\jre6\bin\jqs.exe<br />
C:\xampp\mysql\bin\mysqld.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Programme\Sony\VAIO Event Service\VESMgr.exe<br />
C:\Programme\Apoint\Apntex.exe<br />
C:\xampp\apache\bin\httpd.exe<br />
C:\Programme\-=Media=-\ICQ7.0\ICQ.exe<br />
C:\Programme\-=Office=-\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Programme\Trend Micro\HiJackThis\HiJackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about<b></b>:blank<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O1 - Hosts: 212.95.49.48 www.google.com<br />
O1 - Hosts: 212.95.49.48 us.search.yahoo.com<br />
O1 - Hosts: 212.95.49.48 uk.search.yahoo.com<br />
O1 - Hosts: 212.95.49.48 search.yahoo.com<br />
O1 - Hosts: 212.95.49.48 www.google.com.br<br />
O1 - Hosts: 212.95.49.48 www.google.it<br />
O1 - Hosts: 212.95.49.48 www.google.es<br />
O1 - Hosts: 212.95.49.48 www.google.co.jp<br />
O1 - Hosts: 212.95.49.48 www.google.com.mx<br />
O1 - Hosts: 212.95.49.48 www.google.ca<br />
O1 - Hosts: 212.95.49.48 www.google.com.au<br />
O1 - Hosts: 212.95.49.48 www.google.nl<br />
O1 - Hosts: 212.95.49.48 www.google.co.za<br />
O1 - Hosts: 212.95.49.48 www.google.be<br />
O1 - Hosts: 212.95.49.48 www.google.gr<br />
O1 - Hosts: 212.95.49.48 www.google.at<br />
O1 - Hosts: 212.95.49.48 www.google.se<br />
O1 - Hosts: 212.95.49.48 www.google.ch<br />
O1 - Hosts: 212.95.49.48 www.google.pt<br />
O1 - Hosts: 212.95.49.48 www.google.dk<br />
O1 - Hosts: 212.95.49.48 www.google.fi<br />
O1 - Hosts: 212.95.49.48 www.google.ie<br />
O1 - Hosts: 212.95.49.48 www.google.no<br />
O1 - Hosts: 212.95.49.48 www.google.de<br />
O1 - Hosts: 212.95.49.48 www.google.fr<br />
O1 - Hosts: 212.95.49.48 www.google.co.uk<br />
O1 - Hosts: 212.95.49.48 www.bing.com<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Programme\-=Security=-\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE<br />
O4 - HKLM\..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe<br />
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe<br />
O4 - HKLM\..\Run: [Switcher.exe] C:\Programme\Sony\Wireless Switch Setting Utility\Switcher.exe<br />
O4 - HKLM\..\Run: [VAIOCameraUtility] &quot;C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
O4 - HKLM\..\Run: [FreePDF Assistant] C:\Programme\FreePDF_XP\fpassist.exe<br />
O4 - HKLM\..\Run: [DivXUpdate] &quot;C:\Programme\DivX\DivX Update\DivXUpdate.exe&quot; /CHECKNOW<br />
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] &quot;C:\Programme\Gemeinsame Dateien\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe&quot;<br />
O4 - HKLM\..\Run: [SwitchBoard] C:\Programme\Gemeinsame Dateien\Adobe\SwitchBoard\SwitchBoard.exe<br />
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] &quot;C:\Programme\Gemeinsame Dateien\Adobe\CS5ServiceManager\CS5ServiceManager.exe&quot; -launchedbylogin<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] &quot;C:\Programme\-=Media=-\DAEMON Tools Lite\DTLite.exe&quot; -autorun<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O8 - Extra context menu item: Nach Microsoft E&amp;xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: An OneNote s&amp;enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\-=Media=-\ICQ7.0\ICQ.exe<br />
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\-=Media=-\ICQ7.0\ICQ.exe<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Programme\-=Security=-\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programme\-=Security=-\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Apache2.2 - Apache Software Foundation - C:\xampp\apache\bin\httpd.exe<br />
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programme\Bonjour\mDNSResponder.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe<br />
O23 - Service: MySQL - MySQL AB - C:\xampp\mysql\bin\mysqld.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Programme\Gemeinsame Dateien\Adobe\SwitchBoard\SwitchBoard.exe<br />
O23 - Service: VAIO Event Service - Sony Corporation - C:\Programme\Sony\VAIO Event Service\VESMgr.exe<br />
<br />
--<br />
End of file - 9196 bytes</code><hr />
</div></div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>Ducksoul</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90559-aufrufen-von-google-de-fuehrt-zu-phishing-seite.html</guid>
		</item>
		<item>
			<title>Offen TR/Dropper.Gen was ist zu tun?</title>
			<link>http://www.trojaner-board.de/90556-tr-dropper-gen-ist-zu-tun.html</link>
			<pubDate>Wed, 08 Sep 2010 18:50:31 GMT</pubDate>
			<description>Hallo, 
 
ich bin der SmaXh14 und bin neu hier. Ich habe mich deshalb angemeldet weil ich mir offenbar den Virus TR/Dropper.Gen eingefangen habe und jetzt wissen möchte wie ich den entfernen kann. Ich hoffe ihr könnt mir helfen. Hier mein Hijackthis-Log: 
 
Logfile of Trend Micro HijackThis v2.0.4...</description>
			<content:encoded><![CDATA[<div>Hallo,<br />
<br />
ich bin der SmaXh14 und bin neu hier. Ich habe mich deshalb angemeldet weil ich mir offenbar den Virus TR/Dropper.Gen eingefangen habe und jetzt wissen möchte wie ich den entfernen kann. Ich hoffe ihr könnt mir helfen. Hier mein Hijackthis-Log:<br />
<br />
Logfile of Trend Micro <a href=51130-anleitung-hijackthis.html>HijackThis</a> v2.0.4<br />
Scan saved at 20:49:20, on 08.09.2010<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18943)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe<br />
C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe<br />
C:\Program Files\Launch Manager\QtZgAcer.EXE<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Users\Max\Desktop\Virus Removal Tool\setup_9.0.0.722_01.09.2010_10-16\setup_9.0.0.722_01.09.2010_10-16.exe<br />
C:\program files\avira\antivir desktop\avcenter.exe<br />
C:\program files\avira\antivir desktop\avscan.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Mozilla Firefox\plugin-container.exe<br />
C:\Users\Max\Downloads\HiJackThis204.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&amp;l=0407&amp;s=2&amp;o=vp32&amp;d=0510&amp;m=aspire_6530g<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&amp;l=0407&amp;s=2&amp;o=vp32&amp;d=0510&amp;m=aspire_6530g<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&amp;l=0407&amp;s=2&amp;o=vp32&amp;d=0510&amp;m=aspire_6530g<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll<br />
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)<br />
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll<br />
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe<br />
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe<br />
O4 - HKLM\..\Run: [eAudio] &quot;C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe&quot;<br />
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [Eraser] &quot;C:\PROGRA~1\Eraser\Eraser.exe&quot; --atRestart<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')<br />
O4 - Startup: setup_9.0.0.722_01.09.2010_10-16.lnk = C:\Users\Max\Desktop\Virus Removal Tool\setup_9.0.0.722_01.09.2010_10-16\startup.exe<br />
O8 - Extra context menu item: Nach Microsoft E&amp;xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe<br />
O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe<br />
O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: An OneNote s&amp;enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL<br />
O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll<br />
O20 - Winlogon Notify: spba - C:\Program Files\Common Files\SPBA\homefus2.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe<br />
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe<br />
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe<br />
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe<br />
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Unknown owner - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (file missing)<br />
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe<br />
O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe<br />
<br />
--<br />
End of file - 7992 bytes<br />
<br />
<br />
Danke schonmal im Vorraus<br />
<br />
SmaXh14</div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>SmaXh14</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90556-tr-dropper-gen-ist-zu-tun.html</guid>
		</item>
		<item>
			<title>Offen Backdooprogramm BDS/Papras.PK</title>
			<link>http://www.trojaner-board.de/90554-backdooprogramm-bds-papras-pk.html</link>
			<pubDate>Wed, 08 Sep 2010 17:42:48 GMT</pubDate>
			<description>Hallo! 
 
Ich habe seit 2 Tagen folgendes Problem: 
Beim Start des PCs sowie beim Öffnen verschiedener Programme (Firefox, Läutstärkeregelung, ...) meldet mir der Avira Guard das Backdooprogramm BDS/Papras.PK. 
 
Ich habe nach Anleitung mal die Scans durchgeführt, anbei also zu erst die Logdatei...</description>
			<content:encoded><![CDATA[<div>Hallo!<br />
<br />
Ich habe seit 2 Tagen folgendes Problem:<br />
Beim Start des PCs sowie beim Öffnen verschiedener Programme (Firefox, Läutstärkeregelung, ...) meldet mir der Avira Guard das Backdooprogramm BDS/Papras.PK.<br />
<br />
Ich habe nach Anleitung mal die Scans durchgeführt, anbei also zu erst die Logdatei von Malwarebyte, danach die beiden Dateien von OTL.<br />
<br />
Vielen Dank schonmal im Vorraus für eure Hilfe!<br />
<br />
<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">Malwarebytes' Anti-Malware 1.46<br />
www.malwarebytes.org<br />
<br />
Datenbank Version: 4572<br />
<br />
Windows 6.0.6002 Service Pack 2<br />
Internet Explorer 7.0.6002.18005<br />
<br />
08.09.2010 19:12:37<br />
mbam-log-2010-09-08 (19-12-37).txt<br />
<br />
Art des Suchlaufs: Quick-Scan<br />
Durchsuchte Objekte: 133204<br />
Laufzeit: 9 Minute(n), 27 Sekunde(n)<br />
<br />
Infizierte Speicherprozesse: 0<br />
Infizierte Speichermodule: 0<br />
Infizierte Registrierungsschlüssel: 6<br />
Infizierte Registrierungswerte: 6<br />
Infizierte Dateiobjekte der Registrierung: 0<br />
Infizierte Verzeichnisse: 0<br />
Infizierte Dateien: 2<br />
<br />
Infizierte Speicherprozesse:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Speichermodule:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Registrierungsschlüssel:<br />
HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -&gt; No action taken.<br />
HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -&gt; No action taken.<br />
HKEY_CURRENT_USER\Software\M5T8QL3YW3 (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -&gt; No action taken.<br />
HKEY_CURRENT_USER\SOFTWARE\QZAIB7KITK (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -&gt; No action taken.<br />
<br />
Infizierte Registrierungswerte:<br />
HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -&gt; No action taken.<br />
HKEY_CLASSES_ROOT\secfile\shell\open\command\(default) (Rogue.MultipleAV) -&gt; No action taken.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -&gt; No action taken.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\evenconv (Trojan.Agent.U) -&gt; No action taken.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hsfg9w8gujsokgahi8gysgnsdgefshyjy (Trojan.Downloader) -&gt; No action taken.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\userinit (Trojan.Agent) -&gt; No action taken.<br />
<br />
Infizierte Dateiobjekte der Registrierung:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Verzeichnisse:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Dateien:<br />
C:\Users\***\AppData\Roaming\avdrn.dat (Malware.Trace) -&gt; No action taken.<br />
C:\Users\***\AppData\Roaming\dhxiuw.dat (Malware.Trace) -&gt; No action taken.</code><hr />
</div><br />
OTL.txt:<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">OTL logfile created on: 08.09.2010 19:27:25 - Run 1<br />
OTL by OldTimer - Version 3.2.11.0&nbsp; &nbsp;  Folder = C:\Users\***\Downloads<br />
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation<br />
Internet Explorer (Version = 7.0.6002.18005)<br />
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy<br />
&nbsp;<br />
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 63,00% Memory free<br />
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free<br />
Paging file location(s): ?:\pagefile.sys [binary data]<br />
&nbsp;<br />
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files<br />
Drive C: | 104,95 Gb Total Space | 1,71 Gb Free Space | 1,63% Space Free | Partition Type: NTFS<br />
D: Drive not present or media not loaded<br />
E: Drive not present or media not loaded<br />
F: Drive not present or media not loaded<br />
G: Drive not present or media not loaded<br />
H: Drive not present or media not loaded<br />
I: Drive not present or media not loaded<br />
&nbsp;<br />
Computer Name: ***<br />
Current User Name: ***<br />
Logged in as Administrator.<br />
&nbsp;<br />
Current Boot Mode: Normal<br />
Scan Mode: Current user<br />
Company Name Whitelist: Off<br />
Skip Microsoft Files: Off<br />
File Age = 30 Days<br />
Output = Minimal<br />
&nbsp;<br />
<font color="#E56717">========== Processes (SafeList) ==========</font><br />
&nbsp;<br />
PRC - C:\Users\***\Downloads\<a href=85104-otl-otlogfile-oldtimer.html>OTL.exe</a> (OldTimer Tools)<br />
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)<br />
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)<br />
PRC - C:\Users\Pe\AppData\Roaming\QipGuard\QipGuard.exe ()<br />
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)<br />
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)<br />
PRC - C:\Windows\explorer.exe (Microsoft Corporation)<br />
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)<br />
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()<br />
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)<br />
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)<br />
PRC - C:\Program Files\ATK Hotkey\HControl.exe (ATK0100)<br />
PRC - C:\Program Files\ATK Hotkey\ASLDRSrv.exe ()<br />
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)<br />
PRC - C:\Program Files\ASUS\Splendid\ACMON.exe (ATK)<br />
PRC - C:\Program Files\ATKOSD2\ATKOSD2.exe ()<br />
PRC - C:\Program Files\P4G\BatteryLife.exe (ATK)<br />
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)<br />
PRC - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe ()<br />
PRC - C:\Program Files\Wireless Console 2\wcourier.exe ()<br />
PRC - C:\Program Files\ATK Hotkey\ATKOSD.exe ()<br />
PRC - C:\Windows\System32\StkCSrv.exe (Syntek America Inc.)<br />
PRC - C:\Program Files\ASUS\Net4Switch\Net4Switch.exe (ASUS)<br />
PRC - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)<br />
PRC - C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUSTeK Computer INC.)<br />
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)<br />
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)<br />
PRC - C:\Program Files\Apoint2K\Apvfb.exe (ALPS)<br />
PRC - C:\Program Files\Apoint2K\hidfind.exe (Alps Electric Co., Ltd.)<br />
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)<br />
PRC - C:\Windows\System32\ACEngSvr.exe (ASUSTeK)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Modules (SafeList) ==========</font><br />
&nbsp;<br />
MOD - C:\Users\***\Downloads\<a href=85104-otl-otlogfile-oldtimer.html>OTL.exe</a> (OldTimer Tools)<br />
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)<br />
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Win32 Services (SafeList) ==========</font><br />
&nbsp;<br />
SRV - (CLTNetCnService) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe File not found<br />
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)<br />
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)<br />
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)<br />
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)<br />
SRV - (NMSAccessU) -- C:\Program Files\CDBurnerXP\NMSAccessU.exe ()<br />
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)<br />
SRV - (ASLDRService) -- C:\Program Files\ATK Hotkey\ASLDRSrv.exe ()<br />
SRV - (spmgr) -- C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe ()<br />
SRV - (StkSSrv) -- C:\Windows\System32\StkCSrv.exe (Syntek America Inc.)<br />
SRV - (TOSHIBA Bluetooth Service) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Driver Services (SafeList) ==========</font><br />
&nbsp;<br />
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found<br />
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found<br />
DRV - (ipswuio) -- C:\Windows\System32\DRIVERS\ipswuio.sys File not found<br />
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found<br />
DRV - (cpuz129) -- C:\Users\***\AppData\Local\Temp\cpuz_x32.sys File not found<br />
DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys File not found<br />
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)<br />
DRV - (BCD3000) -- C:\Windows\System32\drivers\BCD3000.SYS (Behringer Spezielle Studiotechnik GmbH)<br />
DRV - (BCD3000WDM) -- C:\Windows\System32\drivers\BCD3000WDM.SYS (Behringer Spezielle Studiotechnik GmbH)<br />
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)<br />
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)<br />
DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)<br />
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)<br />
DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)<br />
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()<br />
DRV - (MODEMCSA) -- C:\Windows\System32\drivers\MODEMCSA.sys (Microsoft Corporation)<br />
DRV - (Sntnlusb) -- C:\Windows\System32\drivers\SNTNLUSB.SYS (Rainbow Technologies Inc.)<br />
DRV - (Sentinel) -- C:\Windows\System32\Drivers\SENTINEL.SYS (Rainbow Technologies, Inc.)<br />
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)<br />
DRV - (nvstor32) -- C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)<br />
DRV - (StkCMini) -- C:\Windows\System32\drivers\StkCMini.sys (Syntek)<br />
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)<br />
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)<br />
DRV - (WCPU) -- C:\Program Files\P4G\WCPU.sys (Windows (R) Codename Longhorn DDK provider)<br />
DRV - (ghaio) -- C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys ()<br />
DRV - (MTsensor) -- C:\Windows\System32\drivers\ATKACPI.sys (ATK0100)<br />
DRV - (tosrfbd) -- C:\Windows\System32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)<br />
DRV - (smserial) -- C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)<br />
DRV - (tosrfbnp) -- C:\Windows\System32\drivers\tosrfbnp.sys (TOSHIBA Corporation)<br />
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)<br />
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)<br />
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)<br />
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)<br />
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)<br />
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)<br />
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)<br />
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)<br />
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)<br />
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)<br />
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)<br />
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)<br />
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)<br />
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)<br />
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)<br />
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)<br />
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)<br />
DRV - (TPM) -- C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)<br />
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)<br />
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)<br />
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)<br />
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)<br />
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)<br />
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)<br />
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)<br />
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)<br />
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)<br />
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)<br />
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)<br />
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)<br />
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)<br />
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)<br />
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)<br />
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)<br />
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)<br />
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)<br />
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)<br />
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)<br />
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)<br />
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)<br />
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)<br />
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)<br />
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)<br />
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)<br />
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)<br />
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation)<br />
DRV - (NETw3v32) Intel(R) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)<br />
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)<br />
DRV - (Tosrfusb) -- C:\Windows\System32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)<br />
DRV - (tosporte) -- C:\Windows\System32\drivers\tosporte.sys (TOSHIBA Corporation)<br />
DRV - (Tosrfhid) -- C:\Windows\System32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)<br />
DRV - (ApfiltrService) -- C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)<br />
DRV - (Tosrfcom) -- C:\Windows\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)<br />
DRV - (tosrfnds) -- C:\Windows\System32\drivers\tosrfnds.sys (TOSHIBA Corporation.)<br />
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\System32\drivers\sfdrv01.sys (Protection Technology)<br />
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\System32\drivers\sfhlp02.sys (Protection Technology)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Standard Registry (SafeList) ==========</font><br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Internet Explorer ==========</font><br />
&nbsp;<br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm<br />
&nbsp;<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://qip.ru<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.qip.ru<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.qip.ru<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://qip.ru<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://search.qip.ru/ie<br />
IE - HKCU\..\URLSearchHook:&nbsp; - Reg Error: Key error. File not found<br />
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)<br />
IE - HKCU\..\URLSearchHook: {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\***\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)<br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: &quot;ProxyEnable&quot; = 0<br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: &quot;ProxyOverride&quot; = *.local<br />
&nbsp;<br />
<font color="#E56717">========== FireFox ==========</font><br />
&nbsp;<br />
FF - prefs.js..browser.search.defaultenginename: &quot;QIP Search&quot;<br />
FF - prefs.js..browser.search.selectedEngine: &quot;Wikipedia (en)&quot;<br />
FF - prefs.js..browser.search.useDBForOrder: true<br />
FF - prefs.js..browser.startup.homepage: &quot;hxxp://www.spiegel.de/&quot;<br />
FF - prefs.js..extensions.enabledItems: searchdictcc@roughael:1.0<br />
FF - prefs.js..extensions.enabledItems: OpenXMLViewer@Codeplex.com:1.0.0.0<br />
FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2<br />
FF - prefs.js..extensions.enabledItems: 4<br />
FF - prefs.js..extensions.enabledItems: 9<br />
FF - prefs.js..extensions.enabledItems: 1<br />
FF - prefs.js..keyword.URL: &quot;hxxp://search.qip.ru/search?from=FF&amp;query=&quot;<br />
FF - prefs.js..network.proxy.backup.ftp: &quot;&quot;<br />
FF - prefs.js..network.proxy.backup.ftp_port: 0<br />
FF - prefs.js..network.proxy.backup.gopher: &quot;&quot;<br />
FF - prefs.js..network.proxy.backup.gopher_port: 0<br />
FF - prefs.js..network.proxy.backup.socks: &quot;&quot;<br />
FF - prefs.js..network.proxy.backup.socks_port: 0<br />
FF - prefs.js..network.proxy.backup.ssl: &quot;&quot;<br />
FF - prefs.js..network.proxy.backup.ssl_port: 0<br />
FF - prefs.js..network.proxy.ftp: &quot;143.93.243.1&quot;<br />
FF - prefs.js..network.proxy.ftp_port: 3128<br />
FF - prefs.js..network.proxy.gopher: &quot;143.93.243.1&quot;<br />
FF - prefs.js..network.proxy.gopher_port: 3128<br />
FF - prefs.js..network.proxy.http: &quot;143.93.243.1&quot;<br />
FF - prefs.js..network.proxy.http_port: 3128<br />
FF - prefs.js..network.proxy.share_proxy_settings: true<br />
FF - prefs.js..network.proxy.socks: &quot;143.93.243.1&quot;<br />
FF - prefs.js..network.proxy.socks_port: 3128<br />
FF - prefs.js..network.proxy.ssl: &quot;143.93.243.1&quot;<br />
FF - prefs.js..network.proxy.ssl_port: 3128<br />
&nbsp;<br />
&nbsp;<br />
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.04 20:19:44 | 000,000,000 | ---D | M]<br />
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.04 20:19:44 | 000,000,000 | ---D | M]<br />
&nbsp;<br />
[2008.10.27 18:08:32 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Extensions<br />
[2010.09.07 21:37:20 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\tu3325ox.default\extensions<br />
[2009.09.02 21:03:36 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Pe\AppData\Roaming\mozilla\Firefox\Profiles\tu3325ox.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}<br />
[2009.11.10 21:22:16 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\tu3325ox.default\extensions\firefox@tvunetworks.com<br />
[2010.05.03 13:29:13 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\tu3325ox.default\extensions\OpenXMLViewer@Codeplex.com<br />
[2010.03.28 21:16:49 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\tu3325ox.default\extensions\searchdictcc@roughael<br />
[2010.08.22 16:46:35 | 000,001,340 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\FireFox\Profiles\tu3325ox.default\searchplugins\wikipedia-en.xml<br />
[2010.03.15 15:12:01 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions<br />
[2009.07.16 20:13:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}<br />
[2008.09.04 02:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll<br />
[2008.08.07 15:53:06 | 001,271,760 | ---- | M] (1 mal 1 Software GmbH) -- C:\Program Files\Mozilla Firefox\plugins\NpFv501.dll<br />
[2010.02.19 16:26:07 | 000,001,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml<br />
[2010.02.19 16:26:07 | 000,002,344 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml<br />
[2010.02.19 16:26:07 | 000,006,805 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml<br />
[2010.02.19 16:26:07 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml<br />
[2010.02.19 16:26:07 | 000,000,801 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml<br />
&nbsp;<br />
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts<br />
O1 - Hosts: 127.0.0.1&nbsp; &nbsp; &nbsp;  localhost<br />
O1 - Hosts: ::1&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  localhost<br />
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)<br />
O2 - BHO: (QIPBHO Class) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Pe\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)<br />
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)<br />
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUSTeK Computer INC.)<br />
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)<br />
O4 - HKLM..\Run: [BCD3000] C:\Windows\System32\bcd3kcpan.exe File not found<br />
O4 - HKLM..\Run: [ <a href=51187-anleitung-malwarebytes-anti-malware.html>Malwarebytes Anti-Malware</a>  (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)<br />
O4 - HKLM..\Run: [MSConfig] C:\Windows\System32\msconfig.exe (Microsoft Corporation)<br />
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)<br />
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)<br />
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation)<br />
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)<br />
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)<br />
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)<br />
O4 - HKCU..\Run: [Driver Updater]&nbsp; File not found<br />
O4 - HKCU..\Run: [QIP Internet Guardian] C:\Users\***\AppData\Roaming\QipGuard\QipGuard.exe ()<br />
O8 - Extra context menu item: Nach Microsoft &amp;Excel exportieren - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)<br />
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)<br />
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)<br />
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)<br />
O13 - gopher Prefix: missing<br />
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)<br />
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)<br />
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1<br />
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)<br />
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)<br />
O24 - Desktop WallPaper: C:\Users\***\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg<br />
O24 - Desktop BackupWallPaper: C:\Users\Pe\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg<br />
O32 - HKLM CDRom: AutoRun - 1<br />
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]<br />
O33 - MountPoints2\{656d6693-d735-11dd-af09-002215297035}\Shell - &quot;&quot; = AutoRun<br />
O33 - MountPoints2\{656d6693-d735-11dd-af09-002215297035}\Shell\AutoRun\command - &quot;&quot; = F:\LaunchU3.exe -- File not found<br />
O33 - MountPoints2\{7d503b4c-8ada-11dd-9ca3-001bfc12d2b7}\Shell\AutoRun\command - &quot;&quot; = E:\programs\nu2menu\nu2menu.exe -- File not found<br />
O33 - MountPoints2\{84734a14-5364-11de-9a45-002215297035}\Shell\AutoRun\command - &quot;&quot; = E:\HEILER.EXE -- File not found<br />
O33 - MountPoints2\{84734a14-5364-11de-9a45-002215297035}\Shell\dismount\command - &quot;&quot; = E:\HEILER.EXE -- File not found<br />
O33 - MountPoints2\{84734a14-5364-11de-9a45-002215297035}\Shell\open\command - &quot;&quot; = E:\HEILER.EXE -- File not found<br />
O33 - MountPoints2\{84734a14-5364-11de-9a45-002215297035}\Shell\sz\command - &quot;&quot; = E:\HEILER.EXE -- File not found<br />
O33 - MountPoints2\F\Shell - &quot;&quot; = AutoRun<br />
O33 - MountPoints2\F\Shell\AutoRun\command - &quot;&quot; = F:\LaunchU3.exe -- File not found<br />
O34 - HKLM BootExecute: (autocheck autochk *) -&nbsp; File not found<br />
O35 - HKLM\..comfile [open] -- &quot;%1&quot; %*<br />
O35 - HKLM\..exefile [open] -- &quot;%1&quot; %*<br />
O37 - HKLM\...com [@ = comfile] -- &quot;%1&quot; %*<br />
O37 - HKLM\...exe [@ = exefile] -- &quot;%1&quot; %*<br />
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found<br />
&nbsp;<br />
<font color="#E56717">========== Files/Folders - Created Within 30 Days ==========</font><br />
&nbsp;<br />
[2010.09.02 14:44:54 | 000,000,000 | ---D | C] -- C:\Program Files\Kazaa Lite<br />
[2010.09.02 14:40:11 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite<br />
[2010.08.30 20:59:04 | 000,000,000 | ---D | C] -- C:\Users\Pe\AppData\Roaming\EB-Edit<br />
[2010.08.30 20:59:03 | 000,000,000 | ---D | C] -- C:\Program Files\EB-Edit<br />
[2010.08.18 22:09:26 | 000,000,000 | ---D | C] -- C:\Program Files\Cyanide<br />
[2010.08.18 16:18:12 | 000,000,000 | ---D | C] -- C:\Users\Pe\Desktop\ebay<br />
[2010.08.15 19:23:26 | 000,081,920 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll<br />
[2010.08.15 19:23:11 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll<br />
[2010.08.15 19:23:11 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll<br />
[2010.08.15 19:23:10 | 000,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll<br />
[2010.08.15 19:22:35 | 002,037,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys<br />
[2010.08.15 19:22:26 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll<br />
[2010.08.15 19:21:58 | 003,600,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe<br />
[2010.08.15 19:21:58 | 003,548,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe<br />
[1 C:\Users\Pe\*.tmp files -&gt; C:\Users\Pe\*.tmp -&gt; ]<br />
&nbsp;<br />
<font color="#E56717">========== Files - Modified Within 30 Days ==========</font><br />
&nbsp;<br />
[2010.09.08 19:27:34 | 003,407,872 | -HS- | M] () -- C:\Users\***\NTUSER.DAT<br />
[2010.09.08 19:15:57 | 000,012,884 | ---- | M] () -- C:\Users\***\AppData\Roaming\nvModes.dat<br />
[2010.09.08 19:15:48 | 000,012,884 | ---- | M] () -- C:\Users\***\AppData\Roaming\nvModes.001<br />
[2010.09.08 19:14:51 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0<br />
[2010.09.08 19:14:51 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0<br />
[2010.09.08 19:14:50 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT<br />
[2010.09.08 19:14:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat<br />
[2010.09.08 19:14:35 | 2146,689,024 | -HS- | M] () -- C:\hiberfil.sys<br />
[2010.09.08 19:13:28 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat<br />
[2010.09.08 19:13:18 | 000,524,288 | -HS- | M] () -- C:\Users\***\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.09.08 19:13:18 | 000,065,536 | -HS- | M] () -- C:\Users\***\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf<br />
[2010.09.08 19:13:17 | 006,291,456 | -H-- | M] () -- C:\Users\***\AppData\Local\IconCache.db<br />
[2010.09.08 18:47:51 | 000,045,056 | ---- | M] () -- C:\Windows\System32\acovcnt.exe<br />
[2010.09.08 18:44:15 | 000,000,785 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk<br />
[2010.09.08 18:05:18 | 000,000,412 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{D39855D2-C632-4CEC-BD8A-2FE67603F96A}.job<br />
[2010.09.05 16:27:49 | 000,217,088 | ---- | M] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
[2010.09.04 15:59:24 | 000,016,896 | ---- | M] () -- C:\Users\***\Desktop\Aufgaben Barentin.xls<br />
[2010.09.02 14:21:00 | 000,025,600 | ---- | M] () -- C:\Users\***\Desktop\Artikel DJK Andernach - RC Barentin.doc<br />
[2010.09.01 15:16:45 | 001,432,288 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI<br />
[2010.09.01 15:16:45 | 000,623,280 | ---- | M] () -- C:\Windows\System32\perfh007.dat<br />
[2010.09.01 15:16:45 | 000,591,320 | ---- | M] () -- C:\Windows\System32\perfh009.dat<br />
[2010.09.01 15:16:45 | 000,125,184 | ---- | M] () -- C:\Windows\System32\perfc007.dat<br />
[2010.09.01 15:16:45 | 000,103,194 | ---- | M] () -- C:\Windows\System32\perfc009.dat<br />
[2010.08.31 12:33:59 | 000,003,123 | ---- | M] () -- C:\Users\***\Documents\jeah.axp<br />
[2010.08.31 00:33:49 | 000,060,432 | ---- | M] () -- C:\Users\***\AppData\Roaming\GDIPFONTCACHEV1.DAT<br />
[2010.08.24 19:19:19 | 000,099,030 | ---- | M] () -- C:\Users\***\Desktop\40082_1588716194922_1146335417_31745850_5035355_n.jpg<br />
[2010.08.23 17:01:05 | 000,032,256 | ---- | M] () -- C:\Users\***\Desktop\Mannschaftskader DJK Andernach 2010-2011.xls<br />
[2010.08.22 13:14:08 | 000,001,702 | ---- | M] () -- C:\Users\***\Documents\eah.axp<br />
[2010.08.16 16:23:33 | 000,271,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT<br />
[1 C:\Users\Pe\*.tmp files -&gt; C:\Users\Pe\*.tmp -&gt; ]<br />
&nbsp;<br />
<font color="#E56717">========== Files Created - No Company Name ==========</font><br />
&nbsp;<br />
[2010.09.08 18:44:15 | 000,000,785 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk<br />
[2010.09.04 15:59:24 | 000,016,896 | ---- | C] () -- C:\Users\***\Desktop\***.xls<br />
[2010.09.02 02:32:24 | 000,025,600 | ---- | C] () -- C:\Users\***\Desktop\***.doc<br />
[2010.08.31 12:32:46 | 000,003,123 | ---- | C] () -- C:\Users\***\Documents\jeah.axp<br />
[2010.08.24 19:18:55 | 000,099,030 | ---- | C] () -- C:\Users\***\Desktop\40082_1588716194922_1146335417_31745850_5035355_n.jpg<br />
[2010.08.23 00:53:27 | 000,032,256 | ---- | C] () -- C:\Users\***\Desktop\***.xls<br />
[2010.08.22 13:14:08 | 000,001,702 | ---- | C] () -- C:\Users\***\Documents\eah.axp<br />
[2010.03.22 22:49:02 | 000,000,008 | ---- | C] () -- C:\Users\***\AppData\Roaming\jasltw.dat<br />
[2010.03.04 00:16:50 | 000,011,286 | -HS- | C] () -- C:\Users\***\AppData\Local\5720XLfeqCs<br />
[2010.02.03 16:42:23 | 000,004,940 | ---- | C] () -- C:\ProgramData\mtbjfghn.xbe<br />
[2010.01.26 03:44:59 | 000,000,116 | ---- | C] () -- C:\Windows\System32\applet.ini<br />
[2009.11.18 18:08:21 | 000,005,378 | ---- | C] () -- C:\Windows\PSPICEEV.INI<br />
[2009.11.18 18:08:17 | 000,176,128 | ---- | C] () -- C:\Windows\System32\lffax60n.dll<br />
[2009.11.18 18:08:17 | 000,141,824 | ---- | C] () -- C:\Windows\System32\lfcmp60n.dll<br />
[2009.11.18 18:08:17 | 000,110,080 | ---- | C] () -- C:\Windows\System32\lfpng60n.dll<br />
[2009.11.18 18:08:17 | 000,046,080 | ---- | C] () -- C:\Windows\System32\lftif60n.dll<br />
[2009.11.18 18:08:17 | 000,043,008 | ---- | C] () -- C:\Windows\System32\ltfil60n.dll<br />
[2009.11.18 18:08:17 | 000,023,552 | ---- | C] () -- C:\Windows\System32\lfpcx60n.dll<br />
[2009.11.18 18:08:17 | 000,022,528 | ---- | C] () -- C:\Windows\System32\lfpct60n.dll<br />
[2009.11.18 18:08:17 | 000,022,528 | ---- | C] () -- C:\Windows\System32\lfeps60n.dll<br />
[2009.11.18 18:08:17 | 000,022,016 | ---- | C] () -- C:\Windows\System32\lfbmp60n.dll<br />
[2009.11.18 18:08:17 | 000,020,480 | ---- | C] () -- C:\Windows\System32\lfpsd60n.dll<br />
[2009.11.18 18:08:17 | 000,019,968 | ---- | C] () -- C:\Windows\System32\lftga60n.dll<br />
[2009.11.18 18:08:17 | 000,019,456 | ---- | C] () -- C:\Windows\System32\lfwpg60n.dll<br />
[2009.11.18 18:08:17 | 000,019,456 | ---- | C] () -- C:\Windows\System32\lfwmf60n.dll<br />
[2009.11.18 18:08:17 | 000,018,432 | ---- | C] () -- C:\Windows\System32\lfmsp60n.dll<br />
[2009.11.18 18:08:17 | 000,017,920 | ---- | C] () -- C:\Windows\System32\lfmac60n.dll<br />
[2009.11.18 18:08:17 | 000,017,920 | ---- | C] () -- C:\Windows\System32\implode.dll<br />
[2009.11.12 20:27:20 | 000,000,410 | ---- | C] () -- C:\Users\***\AppData\Roaming\Solve Elec 2.5 Prefs<br />
[2009.09.01 20:41:37 | 000,022,016 | ---- | C] () -- C:\Windows\System32\prospeed_bmp2jpg.dll<br />
[2009.07.22 20:19:52 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll<br />
[2008.11.30 18:07:55 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI<br />
[2008.11.30 17:56:36 | 000,639,224 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys<br />
[2008.11.02 17:00:59 | 000,000,680 | ---- | C] () -- C:\Users\***\AppData\Local\d3d9caps.dat<br />
[2008.10.04 02:02:30 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll<br />
[2008.10.01 22:22:08 | 000,217,088 | ---- | C] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
[2008.09.18 20:37:44 | 000,012,884 | ---- | C] () -- C:\Users\***\AppData\Roaming\nvModes.001<br />
[2008.09.18 20:37:42 | 000,012,884 | ---- | C] () -- C:\Users\***\AppData\Roaming\nvModes.dat<br />
[2008.09.17 17:48:41 | 000,012,288 | ---- | C] () -- C:\Windows\impborl.dll<br />
[2007.04.18 11:06:01 | 000,000,010 | ---- | C] () -- C:\Windows\System32\ABLKSR.ini<br />
[2007.03.12 18:41:22 | 000,010,752 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll<br />
[2007.02.06 02:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI<br />
[2006.12.05 22:05:06 | 000,114,688 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll<br />
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll<br />
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini<br />
[2006.11.01 21:54:30 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll<br />
[2006.11.01 21:52:38 | 000,765,952 | ---- | C] () -- C:\Windows\System32\xvidcore.dll<br />
[2005.11.08 00:32:46 | 003,088,384 | ---- | C] () -- C:\Windows\System32\erdmpg-4.dll<br />
[2005.11.05 04:57:14 | 000,258,048 | ---- | C] () -- C:\Windows\System32\Manipulate.dll<br />
[2005.07.23 06:30:20 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll<br />
[2003.08.07 21:01:50 | 000,237,568 | ---- | C] () -- C:\Windows\System32\lame_enc.dll<br />
&lt; End of report &gt;</code><hr />
</div>Extras.txt<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">OTL Extras logfile created on: 08.09.2010 19:27:25 - Run 1<br />
OTL by OldTimer - Version 3.2.11.0&nbsp; &nbsp;  Folder = C:\Users\OTL logfile created on: 08.09.2010 19:27:25 - Run 1<br />
OTL by OldTimer - Version 3.2.11.0&nbsp; &nbsp;  Folder = C:\Users\***\Downloads<br />
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation<br />
Internet Explorer (Version = 7.0.6002.18005)<br />
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy<br />
&nbsp;<br />
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 63,00% Memory free<br />
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free<br />
Paging file location(s): ?:\pagefile.sys [binary data]<br />
&nbsp;<br />
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files<br />
Drive C: | 104,95 Gb Total Space | 1,71 Gb Free Space | 1,63% Space Free | Partition Type: NTFS<br />
D: Drive not present or media not loaded<br />
E: Drive not present or media not loaded<br />
F: Drive not present or media not loaded<br />
G: Drive not present or media not loaded<br />
H: Drive not present or media not loaded<br />
I: Drive not present or media not loaded<br />
&nbsp;<br />
Computer Name: ***<br />
Current User Name: ***<br />
Logged in as Administrator.<br />
&nbsp;<br />
Current Boot Mode: Normal<br />
Scan Mode: Current user<br />
Company Name Whitelist: Off<br />
Skip Microsoft Files: Off<br />
File Age = 30 Days<br />
Output = Minimal<br />
&nbsp;<br />
<font color="#E56717">========== Processes (SafeList) ==========</font><br />
&nbsp;<br />
PRC - C:\Users\***\Downloads\<a href=85104-otl-otlogfile-oldtimer.html>OTL.exe</a> (OldTimer Tools)<br />
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)<br />
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)<br />
PRC - C:\Users\Pe\AppData\Roaming\QipGuard\QipGuard.exe ()<br />
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)<br />
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)<br />
PRC - C:\Windows\explorer.exe (Microsoft Corporation)<br />
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)<br />
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()<br />
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)<br />
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)<br />
PRC - C:\Program Files\ATK Hotkey\HControl.exe (ATK0100)<br />
PRC - C:\Program Files\ATK Hotkey\ASLDRSrv.exe ()<br />
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)<br />
PRC - C:\Program Files\ASUS\Splendid\ACMON.exe (ATK)<br />
PRC - C:\Program Files\ATKOSD2\ATKOSD2.exe ()<br />
PRC - C:\Program Files\P4G\BatteryLife.exe (ATK)<br />
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)<br />
PRC - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe ()<br />
PRC - C:\Program Files\Wireless Console 2\wcourier.exe ()<br />
PRC - C:\Program Files\ATK Hotkey\ATKOSD.exe ()<br />
PRC - C:\Windows\System32\StkCSrv.exe (Syntek America Inc.)<br />
PRC - C:\Program Files\ASUS\Net4Switch\Net4Switch.exe (ASUS)<br />
PRC - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)<br />
PRC - C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUSTeK Computer INC.)<br />
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)<br />
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)<br />
PRC - C:\Program Files\Apoint2K\Apvfb.exe (ALPS)<br />
PRC - C:\Program Files\Apoint2K\hidfind.exe (Alps Electric Co., Ltd.)<br />
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)<br />
PRC - C:\Windows\System32\ACEngSvr.exe (ASUSTeK)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Modules (SafeList) ==========</font><br />
&nbsp;<br />
MOD - C:\Users\***\Downloads\<a href=85104-otl-otlogfile-oldtimer.html>OTL.exe</a> (OldTimer Tools)<br />
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)<br />
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Win32 Services (SafeList) ==========</font><br />
&nbsp;<br />
SRV - (CLTNetCnService) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe File not found<br />
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)<br />
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)<br />
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)<br />
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)<br />
SRV - (NMSAccessU) -- C:\Program Files\CDBurnerXP\NMSAccessU.exe ()<br />
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)<br />
SRV - (ASLDRService) -- C:\Program Files\ATK Hotkey\ASLDRSrv.exe ()<br />
SRV - (spmgr) -- C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe ()<br />
SRV - (StkSSrv) -- C:\Windows\System32\StkCSrv.exe (Syntek America Inc.)<br />
SRV - (TOSHIBA Bluetooth Service) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Driver Services (SafeList) ==========</font><br />
&nbsp;<br />
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found<br />
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found<br />
DRV - (ipswuio) -- C:\Windows\System32\DRIVERS\ipswuio.sys File not found<br />
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found<br />
DRV - (cpuz129) -- C:\Users\***\AppData\Local\Temp\cpuz_x32.sys File not found<br />
DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys File not found<br />
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)<br />
DRV - (BCD3000) -- C:\Windows\System32\drivers\BCD3000.SYS (Behringer Spezielle Studiotechnik GmbH)<br />
DRV - (BCD3000WDM) -- C:\Windows\System32\drivers\BCD3000WDM.SYS (Behringer Spezielle Studiotechnik GmbH)<br />
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)<br />
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)<br />
DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)<br />
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)<br />
DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)<br />
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()<br />
DRV - (MODEMCSA) -- C:\Windows\System32\drivers\MODEMCSA.sys (Microsoft Corporation)<br />
DRV - (Sntnlusb) -- C:\Windows\System32\drivers\SNTNLUSB.SYS (Rainbow Technologies Inc.)<br />
DRV - (Sentinel) -- C:\Windows\System32\Drivers\SENTINEL.SYS (Rainbow Technologies, Inc.)<br />
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)<br />
DRV - (nvstor32) -- C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)<br />
DRV - (StkCMini) -- C:\Windows\System32\drivers\StkCMini.sys (Syntek)<br />
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)<br />
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)<br />
DRV - (WCPU) -- C:\Program Files\P4G\WCPU.sys (Windows (R) Codename Longhorn DDK provider)<br />
DRV - (ghaio) -- C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys ()<br />
DRV - (MTsensor) -- C:\Windows\System32\drivers\ATKACPI.sys (ATK0100)<br />
DRV - (tosrfbd) -- C:\Windows\System32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)<br />
DRV - (smserial) -- C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)<br />
DRV - (tosrfbnp) -- C:\Windows\System32\drivers\tosrfbnp.sys (TOSHIBA Corporation)<br />
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)<br />
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)<br />
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)<br />
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)<br />
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)<br />
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)<br />
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)<br />
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)<br />
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)<br />
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)<br />
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)<br />
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)<br />
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)<br />
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)<br />
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)<br />
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)<br />
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)<br />
DRV - (TPM) -- C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)<br />
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)<br />
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)<br />
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)<br />
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)<br />
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)<br />
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)<br />
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)<br />
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)<br />
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)<br />
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)<br />
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)<br />
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)<br />
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)<br />
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)<br />
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)<br />
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)<br />
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)<br />
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)<br />
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)<br />
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)<br />
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)<br />
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)<br />
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)<br />
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)<br />
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)<br />
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)<br />
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)<br />
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation)<br />
DRV - (NETw3v32) Intel(R) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)<br />
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)<br />
DRV - (Tosrfusb) -- C:\Windows\System32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)<br />
DRV - (tosporte) -- C:\Windows\System32\drivers\tosporte.sys (TOSHIBA Corporation)<br />
DRV - (Tosrfhid) -- C:\Windows\System32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)<br />
DRV - (ApfiltrService) -- C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)<br />
DRV - (Tosrfcom) -- C:\Windows\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)<br />
DRV - (tosrfnds) -- C:\Windows\System32\drivers\tosrfnds.sys (TOSHIBA Corporation.)<br />
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\System32\drivers\sfdrv01.sys (Protection Technology)<br />
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\System32\drivers\sfhlp02.sys (Protection Technology)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Standard Registry (SafeList) ==========</font><br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Internet Explorer ==========</font><br />
&nbsp;<br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm<br />
&nbsp;<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://qip.ru<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.qip.ru<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.qip.ru<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://qip.ru<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://search.qip.ru/ie<br />
IE - HKCU\..\URLSearchHook:&nbsp; - Reg Error: Key error. File not found<br />
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)<br />
IE - HKCU\..\URLSearchHook: {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\***\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)<br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: &quot;ProxyEnable&quot; = 0<br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: &quot;ProxyOverride&quot; = *.local<br />
&nbsp;<br />
<font color="#E56717">========== FireFox ==========</font><br />
&nbsp;<br />
FF - prefs.js..browser.search.defaultenginename: &quot;QIP Search&quot;<br />
FF - prefs.js..browser.search.selectedEngine: &quot;Wikipedia (en)&quot;<br />
FF - prefs.js..browser.search.useDBForOrder: true<br />
FF - prefs.js..browser.startup.homepage: &quot;hxxp://www.spiegel.de/&quot;<br />
FF - prefs.js..extensions.enabledItems: searchdictcc@roughael:1.0<br />
FF - prefs.js..extensions.enabledItems: OpenXMLViewer@Codeplex.com:1.0.0.0<br />
FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2<br />
FF - prefs.js..extensions.enabledItems: 4<br />
FF - prefs.js..extensions.enabledItems: 9<br />
FF - prefs.js..extensions.enabledItems: 1<br />
FF - prefs.js..keyword.URL: &quot;hxxp://search.qip.ru/search?from=FF&amp;query=&quot;<br />
FF - prefs.js..network.proxy.backup.ftp: &quot;&quot;<br />
FF - prefs.js..network.proxy.backup.ftp_port: 0<br />
FF - prefs.js..network.proxy.backup.gopher: &quot;&quot;<br />
FF - prefs.js..network.proxy.backup.gopher_port: 0<br />
FF - prefs.js..network.proxy.backup.socks: &quot;&quot;<br />
FF - prefs.js..network.proxy.backup.socks_port: 0<br />
FF - prefs.js..network.proxy.backup.ssl: &quot;&quot;<br />
FF - prefs.js..network.proxy.backup.ssl_port: 0<br />
FF - prefs.js..network.proxy.ftp: &quot;143.93.243.1&quot;<br />
FF - prefs.js..network.proxy.ftp_port: 3128<br />
FF - prefs.js..network.proxy.gopher: &quot;143.93.243.1&quot;<br />
FF - prefs.js..network.proxy.gopher_port: 3128<br />
FF - prefs.js..network.proxy.http: &quot;143.93.243.1&quot;<br />
FF - prefs.js..network.proxy.http_port: 3128<br />
FF - prefs.js..network.proxy.share_proxy_settings: true<br />
FF - prefs.js..network.proxy.socks: &quot;143.93.243.1&quot;<br />
FF - prefs.js..network.proxy.socks_port: 3128<br />
FF - prefs.js..network.proxy.ssl: &quot;143.93.243.1&quot;<br />
FF - prefs.js..network.proxy.ssl_port: 3128<br />
&nbsp;<br />
&nbsp;<br />
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.04 20:19:44 | 000,000,000 | ---D | M]<br />
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.04 20:19:44 | 000,000,000 | ---D | M]<br />
&nbsp;<br />
[2008.10.27 18:08:32 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Extensions<br />
[2010.09.07 21:37:20 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\tu3325ox.default\extensions<br />
[2009.09.02 21:03:36 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Pe\AppData\Roaming\mozilla\Firefox\Profiles\tu3325ox.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}<br />
[2009.11.10 21:22:16 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\tu3325ox.default\extensions\firefox@tvunetworks.com<br />
[2010.05.03 13:29:13 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\tu3325ox.default\extensions\OpenXMLViewer@Codeplex.com<br />
[2010.03.28 21:16:49 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\tu3325ox.default\extensions\searchdictcc@roughael<br />
[2010.08.22 16:46:35 | 000,001,340 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\FireFox\Profiles\tu3325ox.default\searchplugins\wikipedia-en.xml<br />
[2010.03.15 15:12:01 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions<br />
[2009.07.16 20:13:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}<br />
[2008.09.04 02:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll<br />
[2008.08.07 15:53:06 | 001,271,760 | ---- | M] (1 mal 1 Software GmbH) -- C:\Program Files\Mozilla Firefox\plugins\NpFv501.dll<br />
[2010.02.19 16:26:07 | 000,001,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml<br />
[2010.02.19 16:26:07 | 000,002,344 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml<br />
[2010.02.19 16:26:07 | 000,006,805 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml<br />
[2010.02.19 16:26:07 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml<br />
[2010.02.19 16:26:07 | 000,000,801 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml<br />
&nbsp;<br />
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts<br />
O1 - Hosts: 127.0.0.1&nbsp; &nbsp; &nbsp;  localhost<br />
O1 - Hosts: ::1&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  localhost<br />
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)<br />
O2 - BHO: (QIPBHO Class) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Pe\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)<br />
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)<br />
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUSTeK Computer INC.)<br />
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)<br />
O4 - HKLM..\Run: [BCD3000] C:\Windows\System32\bcd3kcpan.exe File not found<br />
O4 - HKLM..\Run: [ <a href=51187-anleitung-malwarebytes-anti-malware.html>Malwarebytes Anti-Malware</a>  (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)<br />
O4 - HKLM..\Run: [MSConfig] C:\Windows\System32\msconfig.exe (Microsoft Corporation)<br />
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)<br />
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)<br />
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation)<br />
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)<br />
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)<br />
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)<br />
O4 - HKCU..\Run: [Driver Updater]&nbsp; File not found<br />
O4 - HKCU..\Run: [QIP Internet Guardian] C:\Users\***\AppData\Roaming\QipGuard\QipGuard.exe ()<br />
O8 - Extra context menu item: Nach Microsoft &amp;Excel exportieren - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)<br />
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)<br />
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)<br />
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)<br />
O13 - gopher Prefix: missing<br />
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)<br />
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)<br />
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1<br />
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)<br />
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)<br />
O24 - Desktop WallPaper: C:\Users\***\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg<br />
O24 - Desktop BackupWallPaper: C:\Users\Pe\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg<br />
O32 - HKLM CDRom: AutoRun - 1<br />
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]<br />
O33 - MountPoints2\{656d6693-d735-11dd-af09-002215297035}\Shell - &quot;&quot; = AutoRun<br />
O33 - MountPoints2\{656d6693-d735-11dd-af09-002215297035}\Shell\AutoRun\command - &quot;&quot; = F:\LaunchU3.exe -- File not found<br />
O33 - MountPoints2\{7d503b4c-8ada-11dd-9ca3-001bfc12d2b7}\Shell\AutoRun\command - &quot;&quot; = E:\programs\nu2menu\nu2menu.exe -- File not found<br />
O33 - MountPoints2\{84734a14-5364-11de-9a45-002215297035}\Shell\AutoRun\command - &quot;&quot; = E:\HEILER.EXE -- File not found<br />
O33 - MountPoints2\{84734a14-5364-11de-9a45-002215297035}\Shell\dismount\command - &quot;&quot; = E:\HEILER.EXE -- File not found<br />
O33 - MountPoints2\{84734a14-5364-11de-9a45-002215297035}\Shell\open\command - &quot;&quot; = E:\HEILER.EXE -- File not found<br />
O33 - MountPoints2\{84734a14-5364-11de-9a45-002215297035}\Shell\sz\command - &quot;&quot; = E:\HEILER.EXE -- File not found<br />
O33 - MountPoints2\F\Shell - &quot;&quot; = AutoRun<br />
O33 - MountPoints2\F\Shell\AutoRun\command - &quot;&quot; = F:\LaunchU3.exe -- File not found<br />
O34 - HKLM BootExecute: (autocheck autochk *) -&nbsp; File not found<br />
O35 - HKLM\..comfile [open] -- &quot;%1&quot; %*<br />
O35 - HKLM\..exefile [open] -- &quot;%1&quot; %*<br />
O37 - HKLM\...com [@ = comfile] -- &quot;%1&quot; %*<br />
O37 - HKLM\...exe [@ = exefile] -- &quot;%1&quot; %*<br />
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found<br />
&nbsp;<br />
<font color="#E56717">========== Files/Folders - Created Within 30 Days ==========</font><br />
&nbsp;<br />
[2010.09.02 14:44:54 | 000,000,000 | ---D | C] -- C:\Program Files\Kazaa Lite<br />
[2010.09.02 14:40:11 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite<br />
[2010.08.30 20:59:04 | 000,000,000 | ---D | C] -- C:\Users\Pe\AppData\Roaming\EB-Edit<br />
[2010.08.30 20:59:03 | 000,000,000 | ---D | C] -- C:\Program Files\EB-Edit<br />
[2010.08.18 22:09:26 | 000,000,000 | ---D | C] -- C:\Program Files\Cyanide<br />
[2010.08.18 16:18:12 | 000,000,000 | ---D | C] -- C:\Users\Pe\Desktop\ebay<br />
[2010.08.15 19:23:26 | 000,081,920 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll<br />
[2010.08.15 19:23:11 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll<br />
[2010.08.15 19:23:11 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll<br />
[2010.08.15 19:23:10 | 000,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll<br />
[2010.08.15 19:22:35 | 002,037,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys<br />
[2010.08.15 19:22:26 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll<br />
[2010.08.15 19:21:58 | 003,600,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe<br />
[2010.08.15 19:21:58 | 003,548,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe<br />
[1 C:\Users\Pe\*.tmp files -&gt; C:\Users\Pe\*.tmp -&gt; ]<br />
&nbsp;<br />
<font color="#E56717">========== Files - Modified Within 30 Days ==========</font><br />
&nbsp;<br />
[2010.09.08 19:27:34 | 003,407,872 | -HS- | M] () -- C:\Users\***\NTUSER.DAT<br />
[2010.09.08 19:15:57 | 000,012,884 | ---- | M] () -- C:\Users\***\AppData\Roaming\nvModes.dat<br />
[2010.09.08 19:15:48 | 000,012,884 | ---- | M] () -- C:\Users\***\AppData\Roaming\nvModes.001<br />
[2010.09.08 19:14:51 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0<br />
[2010.09.08 19:14:51 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0<br />
[2010.09.08 19:14:50 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT<br />
[2010.09.08 19:14:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat<br />
[2010.09.08 19:14:35 | 2146,689,024 | -HS- | M] () -- C:\hiberfil.sys<br />
[2010.09.08 19:13:28 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat<br />
[2010.09.08 19:13:18 | 000,524,288 | -HS- | M] () -- C:\Users\***\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.09.08 19:13:18 | 000,065,536 | -HS- | M] () -- C:\Users\***\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf<br />
[2010.09.08 19:13:17 | 006,291,456 | -H-- | M] () -- C:\Users\***\AppData\Local\IconCache.db<br />
[2010.09.08 18:47:51 | 000,045,056 | ---- | M] () -- C:\Windows\System32\acovcnt.exe<br />
[2010.09.08 18:44:15 | 000,000,785 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk<br />
[2010.09.08 18:05:18 | 000,000,412 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{D39855D2-C632-4CEC-BD8A-2FE67603F96A}.job<br />
[2010.09.05 16:27:49 | 000,217,088 | ---- | M] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
[2010.09.04 15:59:24 | 000,016,896 | ---- | M] () -- C:\Users\***\Desktop\Aufgaben Barentin.xls<br />
[2010.09.02 14:21:00 | 000,025,600 | ---- | M] () -- C:\Users\***\Desktop\Artikel DJK Andernach - RC Barentin.doc<br />
[2010.09.01 15:16:45 | 001,432,288 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI<br />
[2010.09.01 15:16:45 | 000,623,280 | ---- | M] () -- C:\Windows\System32\perfh007.dat<br />
[2010.09.01 15:16:45 | 000,591,320 | ---- | M] () -- C:\Windows\System32\perfh009.dat<br />
[2010.09.01 15:16:45 | 000,125,184 | ---- | M] () -- C:\Windows\System32\perfc007.dat<br />
[2010.09.01 15:16:45 | 000,103,194 | ---- | M] () -- C:\Windows\System32\perfc009.dat<br />
[2010.08.31 12:33:59 | 000,003,123 | ---- | M] () -- C:\Users\***\Documents\jeah.axp<br />
[2010.08.31 00:33:49 | 000,060,432 | ---- | M] () -- C:\Users\***\AppData\Roaming\GDIPFONTCACHEV1.DAT<br />
[2010.08.24 19:19:19 | 000,099,030 | ---- | M] () -- C:\Users\***\Desktop\40082_1588716194922_1146335417_31745850_5035355_n.jpg<br />
[2010.08.23 17:01:05 | 000,032,256 | ---- | M] () -- C:\Users\***\Desktop\Mannschaftskader DJK Andernach 2010-2011.xls<br />
[2010.08.22 13:14:08 | 000,001,702 | ---- | M] () -- C:\Users\***\Documents\eah.axp<br />
[2010.08.16 16:23:33 | 000,271,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT<br />
[1 C:\Users\Pe\*.tmp files -&gt; C:\Users\Pe\*.tmp -&gt; ]<br />
&nbsp;<br />
<font color="#E56717">========== Files Created - No Company Name ==========</font><br />
&nbsp;<br />
[2010.09.08 18:44:15 | 000,000,785 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk<br />
[2010.09.04 15:59:24 | 000,016,896 | ---- | C] () -- C:\Users\***\Desktop\***.xls<br />
[2010.09.02 02:32:24 | 000,025,600 | ---- | C] () -- C:\Users\***\Desktop\***.doc<br />
[2010.08.31 12:32:46 | 000,003,123 | ---- | C] () -- C:\Users\***\Documents\jeah.axp<br />
[2010.08.24 19:18:55 | 000,099,030 | ---- | C] () -- C:\Users\***\Desktop\40082_1588716194922_1146335417_31745850_5035355_n.jpg<br />
[2010.08.23 00:53:27 | 000,032,256 | ---- | C] () -- C:\Users\***\Desktop\***.xls<br />
[2010.08.22 13:14:08 | 000,001,702 | ---- | C] () -- C:\Users\***\Documents\eah.axp<br />
[2010.03.22 22:49:02 | 000,000,008 | ---- | C] () -- C:\Users\***\AppData\Roaming\jasltw.dat<br />
[2010.03.04 00:16:50 | 000,011,286 | -HS- | C] () -- C:\Users\***\AppData\Local\5720XLfeqCs<br />
[2010.02.03 16:42:23 | 000,004,940 | ---- | C] () -- C:\ProgramData\mtbjfghn.xbe<br />
[2010.01.26 03:44:59 | 000,000,116 | ---- | C] () -- C:\Windows\System32\applet.ini<br />
[2009.11.18 18:08:21 | 000,005,378 | ---- | C] () -- C:\Windows\PSPICEEV.INI<br />
[2009.11.18 18:08:17 | 000,176,128 | ---- | C] () -- C:\Windows\System32\lffax60n.dll<br />
[2009.11.18 18:08:17 | 000,141,824 | ---- | C] () -- C:\Windows\System32\lfcmp60n.dll<br />
[2009.11.18 18:08:17 | 000,110,080 | ---- | C] () -- C:\Windows\System32\lfpng60n.dll<br />
[2009.11.18 18:08:17 | 000,046,080 | ---- | C] () -- C:\Windows\System32\lftif60n.dll<br />
[2009.11.18 18:08:17 | 000,043,008 | ---- | C] () -- C:\Windows\System32\ltfil60n.dll<br />
[2009.11.18 18:08:17 | 000,023,552 | ---- | C] () -- C:\Windows\System32\lfpcx60n.dll<br />
[2009.11.18 18:08:17 | 000,022,528 | ---- | C] () -- C:\Windows\System32\lfpct60n.dll<br />
[2009.11.18 18:08:17 | 000,022,528 | ---- | C] () -- C:\Windows\System32\lfeps60n.dll<br />
[2009.11.18 18:08:17 | 000,022,016 | ---- | C] () -- C:\Windows\System32\lfbmp60n.dll<br />
[2009.11.18 18:08:17 | 000,020,480 | ---- | C] () -- C:\Windows\System32\lfpsd60n.dll<br />
[2009.11.18 18:08:17 | 000,019,968 | ---- | C] () -- C:\Windows\System32\lftga60n.dll<br />
[2009.11.18 18:08:17 | 000,019,456 | ---- | C] () -- C:\Windows\System32\lfwpg60n.dll<br />
[2009.11.18 18:08:17 | 000,019,456 | ---- | C] () -- C:\Windows\System32\lfwmf60n.dll<br />
[2009.11.18 18:08:17 | 000,018,432 | ---- | C] () -- C:\Windows\System32\lfmsp60n.dll<br />
[2009.11.18 18:08:17 | 000,017,920 | ---- | C] () -- C:\Windows\System32\lfmac60n.dll<br />
[2009.11.18 18:08:17 | 000,017,920 | ---- | C] () -- C:\Windows\System32\implode.dll<br />
[2009.11.12 20:27:20 | 000,000,410 | ---- | C] () -- C:\Users\***\AppData\Roaming\Solve Elec 2.5 Prefs<br />
[2009.09.01 20:41:37 | 000,022,016 | ---- | C] () -- C:\Windows\System32\prospeed_bmp2jpg.dll<br />
[2009.07.22 20:19:52 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll<br />
[2008.11.30 18:07:55 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI<br />
[2008.11.30 17:56:36 | 000,639,224 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys<br />
[2008.11.02 17:00:59 | 000,000,680 | ---- | C] () -- C:\Users\***\AppData\Local\d3d9caps.dat<br />
[2008.10.04 02:02:30 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll<br />
[2008.10.01 22:22:08 | 000,217,088 | ---- | C] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
[2008.09.18 20:37:44 | 000,012,884 | ---- | C] () -- C:\Users\***\AppData\Roaming\nvModes.001<br />
[2008.09.18 20:37:42 | 000,012,884 | ---- | C] () -- C:\Users\***\AppData\Roaming\nvModes.dat<br />
[2008.09.17 17:48:41 | 000,012,288 | ---- | C] () -- C:\Windows\impborl.dll<br />
[2007.04.18 11:06:01 | 000,000,010 | ---- | C] () -- C:\Windows\System32\ABLKSR.ini<br />
[2007.03.12 18:41:22 | 000,010,752 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll<br />
[2007.02.06 02:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI<br />
[2006.12.05 22:05:06 | 000,114,688 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll<br />
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll<br />
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini<br />
[2006.11.01 21:54:30 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll<br />
[2006.11.01 21:52:38 | 000,765,952 | ---- | C] () -- C:\Windows\System32\xvidcore.dll<br />
[2005.11.08 00:32:46 | 003,088,384 | ---- | C] () -- C:\Windows\System32\erdmpg-4.dll<br />
[2005.11.05 04:57:14 | 000,258,048 | ---- | C] () -- C:\Windows\System32\Manipulate.dll<br />
[2005.07.23 06:30:20 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll<br />
[2003.08.07 21:01:50 | 000,237,568 | ---- | C] () -- C:\Windows\System32\lame_enc.dll<br />
&lt; End of report &gt;<br />
\Downloads<br />
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation<br />
Internet Explorer (Version = 7.0.6002.18005)<br />
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy<br />
&nbsp;<br />
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 63,00% Memory free<br />
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free<br />
Paging file location(s): ?:\pagefile.sys [binary data]<br />
&nbsp;<br />
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files<br />
Drive C: | 104,95 Gb Total Space | 1,71 Gb Free Space | 1,63% Space Free | Partition Type: NTFS<br />
D: Drive not present or media not loaded<br />
E: Drive not present or media not loaded<br />
F: Drive not present or media not loaded<br />
G: Drive not present or media not loaded<br />
H: Drive not present or media not loaded<br />
I: Drive not present or media not loaded<br />
&nbsp;<br />
Computer Name: PE-PC<br />
Current User Name: Pe<br />
Logged in as Administrator.<br />
&nbsp;<br />
Current Boot Mode: Normal<br />
Scan Mode: Current user<br />
Company Name Whitelist: Off<br />
Skip Microsoft Files: Off<br />
File Age = 30 Days<br />
Output = Minimal<br />
&nbsp;<br />
<font color="#E56717">========== Extra Registry (SafeList) ==========</font><br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== File Associations ==========</font><br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\&lt;extension&gt;]<br />
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)<br />
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)<br />
&nbsp;<br />
[HKEY_CURRENT_USER\SOFTWARE\Classes\&lt;extension&gt;]<br />
.exe [@ = exefile] -- Reg Error: Key error. File not found<br />
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)<br />
&nbsp;<br />
<font color="#E56717">========== Shell Spawning ==========</font><br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\&lt;key&gt;\shell\[command]\command]<br />
batfile [open] -- &quot;%1&quot; %*<br />
cmdfile [open] -- &quot;%1&quot; %*<br />
comfile [open] -- &quot;%1&quot; %*<br />
cplfile [cplopen] -- %SystemRoot%\System32\control.exe &quot;%1&quot;,%* (Microsoft Corporation)<br />
exefile [open] -- &quot;%1&quot; %*<br />
helpfile [open] -- Reg Error: Key error.<br />
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)<br />
htmlfile [edit] -- &quot;C:\Program Files\Microsoft Office\Office10\msohtmed.exe&quot; %1 (Microsoft Corporation)<br />
htmlfile [print] -- &quot;C:\Program Files\Microsoft Office\Office10\msohtmed.exe&quot; /p %1 (Microsoft Corporation)<br />
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe &quot;%1&quot; (Microsoft Corporation)<br />
piffile [open] -- &quot;%1&quot; %*<br />
regfile [merge] -- Reg Error: Key error.<br />
scrfile [config] -- &quot;%1&quot;<br />
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)<br />
scrfile [open] -- &quot;%1&quot; /S<br />
txtfile [edit] -- Reg Error: Key error.<br />
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1<br />
Directory [AddToPlaylistVLC] -- &quot;C:\Program Files\VideoLAN\VLC\vlc.exe&quot; --started-from-file --playlist-enqueue &quot;%1&quot; ()<br />
Directory [cmd] -- cmd.exe /s /k pushd &quot;%V&quot; (Microsoft Corporation)<br />
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
Directory [PlayWithVLC] -- &quot;C:\Program Files\VideoLAN\VLC\vlc.exe&quot; --started-from-file --no-playlist-enqueue &quot;%1&quot; ()<br />
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)<br />
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)<br />
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
&nbsp;<br />
<font color="#E56717">========== Security Center Settings ==========</font><br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]<br />
&quot;cval&quot; = 1<br />
&quot;UacDisableNotify&quot; = 0<br />
&quot;InternetSettingsDisableNotify&quot; = 0<br />
&quot;AutoUpdateDisableNotify&quot; = 0<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]<br />
&quot;DisableMonitoring&quot; = 1<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]<br />
&quot;DisableMonitoring&quot; = 1<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]<br />
&quot;DisableMonitoring&quot; = 1<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]<br />
&quot;AntiVirusOverride&quot; = 0<br />
&quot;AntiSpywareOverride&quot; = 0<br />
&quot;FirewallOverride&quot; = 0<br />
&quot;VistaSp1&quot; = Reg Error: Unknown registry data type -- File not found<br />
&quot;VistaSp2&quot; = Reg Error: Unknown registry data type -- File not found<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]<br />
&quot;DisableNotifications&quot; = 0<br />
&quot;EnableFirewall&quot; = 1<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]<br />
&quot;DisableNotifications&quot; = 0<br />
&quot;EnableFirewall&quot; = 1<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]<br />
&quot;DisableNotifications&quot; = 0<br />
&quot;EnableFirewall&quot; = 1<br />
&nbsp;<br />
<font color="#E56717">========== Authorized Applications List ==========</font><br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]<br />
&quot;C:\Program Files\BitTorrent\bittorrent.exe&quot; = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Vista Active Open Ports Exception List ==========</font><br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]<br />
&quot;{00E6D16E-BA14-4C00-A51F-D69CC1282D00}&quot; = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | <br />
&quot;{0CA12054-255B-4675-855C-B8ADB118ED28}&quot; = rport=445 | protocol=6 | dir=out | app=system | <br />
&quot;{11E5174A-5A0D-4BD1-9BC9-E826DA6C0478}&quot; = lport=2869 | protocol=6 | dir=in | app=system | <br />
&quot;{125B846F-2101-4A50-8F26-37A3479FB677}&quot; = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | <br />
&quot;{3A6096E3-2922-4AE0-883D-6642A9A03A0C}&quot; = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | <br />
&quot;{3FCCC298-439E-43F0-AC88-5642EE33C02D}&quot; = lport=139 | protocol=6 | dir=in | app=system | <br />
&quot;{6D71E92E-DABA-4DC4-83D2-8719CDE08AA0}&quot; = rport=139 | protocol=6 | dir=out | app=system | <br />
&quot;{70750F3B-3448-48B1-9DB9-B0ED70B2C4D9}&quot; = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | <br />
&quot;{78FD3E14-2362-4D4C-AEE4-74673F6CC815}&quot; = lport=138 | protocol=17 | dir=in | app=system | <br />
&quot;{9FDC462D-7DB6-4E5C-B53C-8F193CB5D2C8}&quot; = rport=138 | protocol=17 | dir=out | app=system | <br />
&quot;{A0FD3061-C609-4F00-B7FB-A371F31E28B9}&quot; = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | <br />
&quot;{A659F963-5EFF-4AB6-B7FC-F6351D175E67}&quot; = lport=3649 | protocol=6 | dir=in | name=217.86.167.3 | <br />
&quot;{A9A80D5C-8EE4-44A1-A999-C0BAB3A341DA}&quot; = lport=10243 | protocol=6 | dir=in | app=system | <br />
&quot;{B09B0B89-8C7E-4D9C-9529-603F85994157}&quot; = lport=137 | protocol=17 | dir=in | app=system | <br />
&quot;{B8F8E66C-5684-4567-AD38-39AEC6674B31}&quot; = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | <br />
&quot;{BC71539D-F06F-486B-8E42-90C3C15059F3}&quot; = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | <br />
&quot;{C6411E97-379E-4756-B6D4-A3E6BD0D9698}&quot; = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | <br />
&quot;{DC5B2DBC-C5FE-4950-A2C3-0AB7968B4B85}&quot; = rport=10243 | protocol=6 | dir=out | app=system | <br />
&quot;{EC078192-AC23-478B-9A00-D6ADA5BD8818}&quot; = rport=137 | protocol=17 | dir=out | app=system | <br />
&quot;{F173E37D-9EE0-49F1-A997-CE32016F6341}&quot; = lport=445 | protocol=6 | dir=in | app=system | <br />
&nbsp;<br />
<font color="#E56717">========== Vista Active Application Exception List ==========</font><br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]<br />
&quot;{15FB0F2E-936B-48F4-A2F8-93F0179509C0}&quot; = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | <br />
&quot;{2E199D53-1461-443A-B546-91A82B9C1CD9}&quot; = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | <br />
&quot;{307045F9-8995-41E0-831F-4489C9128221}&quot; = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe | <br />
&quot;{368E942A-37BA-4582-BA5B-4A8FBA467FDE}&quot; = protocol=17 | dir=in | app=c:\program files\kazaa lite\klrun.exe | <br />
&quot;{3A8BC496-8162-497A-A275-02024ED27205}&quot; = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | <br />
&quot;{3B1CBA3B-FE39-48A2-BF6C-20A4A13A0B78}&quot; = protocol=6 | dir=in | app=c:\program files\kazaa lite\kazupernodes.exe | <br />
&quot;{3EC0C517-3D3D-4541-9669-E6F808FF5707}&quot; = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | <br />
&quot;{43B1097B-D18B-4276-A417-A2F8A19557DB}&quot; = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | <br />
&quot;{4A906F26-EB50-4FE3-8E31-69F28A139D61}&quot; = protocol=6 | dir=out | app=system | <br />
&quot;{4F486D76-D356-4F96-A913-142F15D57F07}&quot; = protocol=17 | dir=in | app=c:\program files\sony ericsson\sony ericsson media manager\mediamanager.exe | <br />
&quot;{52B515D4-9CEA-4411-9748-775A416C667A}&quot; = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe | <br />
&quot;{5909977D-D3E6-4757-BC9A-468D87D1E502}&quot; = protocol=6 | dir=in | app=c:\program files\sony ericsson\sony ericsson media manager\mediamanager.exe | <br />
&quot;{603044B3-1FDB-481D-9181-E4A20C626BDA}&quot; = protocol=6 | dir=in | app=c:\program files\kazaa lite\kanat.exe | <br />
&quot;{6334E7D3-B87D-44C8-8601-CF85BAFEEEAB}&quot; = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe | <br />
&quot;{6AFC7A70-529B-4C1B-AF41-2D4139804A49}&quot; = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | <br />
&quot;{8729FC4A-35FE-4AF7-9E88-52E41D5ACAE7}&quot; = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | <br />
&quot;{880B326B-CC8E-46B0-81C7-7866FD4A8B6A}&quot; = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | <br />
&quot;{8859E349-94BA-4055-9B08-8611EBD95AD2}&quot; = protocol=17 | dir=in | app=c:\program files\kazaa lite\kanat.exe | <br />
&quot;{8B55DE3D-5167-4204-BF33-2D1B9E0EEC97}&quot; = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | <br />
&quot;{8E996FC1-0807-498D-B79B-3565D1DA3B79}&quot; = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe | <br />
&quot;{8F7B47CB-7C00-4264-AC67-60352D7CB4BC}&quot; = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | <br />
&quot;{91346376-126B-4BAE-A4E3-C6F7EFA07B47}&quot; = protocol=6 | dir=in | app=c:\program files\kazaa lite\klrun.exe | <br />
&quot;{954944CA-1977-4D96-97CC-836E3738AED6}&quot; = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | <br />
&quot;{9639EE0A-9A61-4617-8BB9-0CAAF62D6E59}&quot; = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | <br />
&quot;{9AC72E4F-F21C-4341-9239-D3ACD1C35C26}&quot; = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | <br />
&quot;{A2B9C0CB-A8C8-42A0-8FEF-2A6C734DC478}&quot; = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | <br />
&quot;{A4366EBB-FE8D-4B07-9A4B-6F4F6CBDE7CB}&quot; = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | <br />
&quot;{A6FAFD37-A377-43FE-A3B6-C3F65E7AAE82}&quot; = protocol=17 | dir=in | app=c:\program files\kazaa lite\kazupernodes.exe | <br />
&quot;{C3311FD0-C555-499B-8680-DF889C89261A}&quot; = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | <br />
&quot;{EBFEFBA7-C830-4FB7-A514-F60DC01C5D80}&quot; = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | <br />
&quot;TCP Query User{41F4B18F-58A2-40E5-BAF7-F6BFE1B06BB6}C:\program files\jeak.de\qip infium\infium.exe&quot; = protocol=6 | dir=in | app=c:\program files\jeak.de\qip infium\infium.exe | <br />
&quot;TCP Query User{42853F57-1022-4984-A8FB-3FAC8F0E15C0}C:\program files\kazaa lite\clean.kmd&quot; = protocol=6 | dir=in | app=c:\program files\kazaa lite\clean.kmd | <br />
&quot;TCP Query User{575A1AAF-BBD9-42D3-87B6-8B890CA61805}C:\program files\icq6.5\icq.exe&quot; = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | <br />
&quot;TCP Query User{DC0CBDAF-07D0-4449-A9ED-EBA64F74F6D0}C:\windows\explorer.exe&quot; = protocol=6 | dir=in | app=c:\windows\explorer.exe | <br />
&quot;TCP Query User{EE82756B-D1C6-42FB-A393-449567705CAD}C:\program files\icq6\icq.exe&quot; = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe | <br />
&quot;UDP Query User{470D66E6-F54C-4082-8C2C-134929FE0F52}C:\program files\icq6.5\icq.exe&quot; = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe | <br />
&quot;UDP Query User{836E3972-E9D2-41B0-B5FA-81C346037D41}C:\windows\explorer.exe&quot; = protocol=17 | dir=in | app=c:\windows\explorer.exe | <br />
&quot;UDP Query User{BECD820D-1EB2-48CE-AFC0-43DF9FD61037}C:\program files\icq6\icq.exe&quot; = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe | <br />
&quot;UDP Query User{CF010F13-C495-4792-A9A4-0B5CE19D2339}C:\program files\kazaa lite\clean.kmd&quot; = protocol=17 | dir=in | app=c:\program files\kazaa lite\clean.kmd | <br />
&quot;UDP Query User{F8F120C4-CE7A-4504-901D-51DCCF221648}C:\program files\jeak.de\qip infium\infium.exe&quot; = protocol=17 | dir=in | app=c:\program files\jeak.de\qip infium\infium.exe | <br />
&nbsp;<br />
<font color="#E56717">========== HKEY_LOCAL_MACHINE Uninstall List ==========</font><br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]<br />
&quot;{044F9133-B8D7-4d11-BF39-803FA20F5C8B}&quot; = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32<br />
&quot;{052FDD78-A6EA-3187-8386-C82F4CA3A929}&quot; = Microsoft .NET Framework 3.5 Language Pack SP1 - deu<br />
&quot;{0A2A5039-B37F-489D-B1DC-A5258DF9E697}&quot; = FIFA 08<br />
&quot;{0CB9668D-F979-4F31-B8B8-67FE90F929F8}&quot; = Bonjour<br />
&quot;{0E592C31-09EF-3CA1-A7DE-05D13DFCF791}&quot; = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - deu<br />
&quot;{139B0FFA-187E-4BA1-BCA6-6B56B2B6AB8C}&quot; = ATK Media<br />
&quot;{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}&quot; = LifeFrame2<br />
&quot;{232FDC0C-12DE-41F2-9701-27EFCA18BEF9}&quot; = MediaJoin<br />
&quot;{26A24AE4-039D-4CA4-87B4-2F83216011FF}&quot; = Java(TM) 6 Update 11<br />
&quot;{28006915-2739-4EBE-B5E8-49B25D32EB33}&quot; = Atheros Client Installation Program<br />
&quot;{2FFE93F0-BB72-4E52-8761-354D1AAA9387}&quot; = Sony Ericsson PC Suite<br />
&quot;{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}&quot; = SQL Server System CLR Types<br />
&quot;{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}&quot; = ATK Hotkey<br />
&quot;{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}&quot; = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729<br />
&quot;{3D9892BB-A751-4E48-ADC8-E4289956CE1D}&quot; = QuickTime<br />
&quot;{57B15AD4-8C9D-4164-82BB-E33D8644E757}&quot; = ASUS InstantFun<br />
&quot;{5C1DB4ED-E9B4-402D-BB14-D75D97D6C1A6}&quot; = ATKOSD2<br />
&quot;{5EE7D259-D137-4438-9A5F-42F432EC0421}&quot; = VC80CRTRedist - 8.0.50727.4053<br />
&quot;{60DE4033-9503-48D1-A483-7846BD217CA9}&quot; = ICQ6.5<br />
&quot;{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}&quot; = NB Probe<br />
&quot;{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}&quot; = Power Tab Editor 1.7<br />
&quot;{7299052b-02a4-4627-81f2-1818da5d550d}&quot; = Microsoft Visual C++ 2005 Redistributable<br />
&quot;{7E265513-8CDA-4631-B696-F40D983F3B07}_is1&quot; = CDBurnerXP<br />
&quot;{7E910FDA-CBBE-4451-8728-235E6A4DE162}&quot; = Sony Ericsson Media Manager 1.1<br />
&quot;{83F73CB1-7705-49D1-9852-84D839CA2A45}&quot; = Wireless Console 2<br />
&quot;{842FAF7C-50EF-4463-9B8F-6222E1384D7D}&quot; = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries<br />
&quot;{85991ED2-010C-4930-96FA-52F43C2CE98A}&quot; = Apple Mobile Device Support<br />
&quot;{8CFEBE9C-F29F-4C49-80E0-7106970F8734}&quot; = Power4Gear eXtreme<br />
&quot;{90280407-6000-11D3-8CFE-0050048383C9}&quot; = Microsoft Office XP Professional mit FrontPage<br />
&quot;{95120000-00B9-0409-0000-0000000FF1CE}&quot; = Microsoft Application Error Reporting<br />
&quot;{99A4344A-C723-4661-A507-D9D939480358}&quot; = Cisco LEAP Module<br />
&quot;{9A200E68-D5F4-4E70-910F-2871753A0E2B}&quot; = Worms World Party<br />
&quot;{9A25302D-30C0-39D9-BD6F-21E6EC160475}&quot; = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
&quot;{9BFD5911-93E3-42BB-BFCD-50E4BA5B8D67}&quot; = Cisco EAP-FAST Module<br />
&quot;{9D48531D-2135-49FC-BC29-ACCDA5396A76}&quot; = Asus MultiFrame<br />
&quot;{9D6D7811-43B3-463C-BC79-5D1755269989}&quot; = Net4Switch<br />
&quot;{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}&quot; = ALPS Touch Pad Driver<br />
&quot;{AC76BA86-7AD7-1031-7B44-A91000000001}&quot; = Adobe Reader 9.1.3 - Deutsch<br />
&quot;{B2D328BE-45AD-4D92-96F9-2151490A203E}&quot; = Apple Application Support<br />
&quot;{B7050CBDB2504B34BC2A9CA0A692CC29}&quot; = DivX Plus Web Player<br />
&quot;{C0FC1C14-4824-4A73-87A6-9E888C9C3102}&quot; = ASUS Splendid Video Enhancement Technology<br />
&quot;{C41300B9-185D-475E-BFEC-39EF732F19B1}&quot; = Apple Software Update<br />
&quot;{C91C4EF4-63E1-41EE-AE6A-5152628FDC21}&quot; = Microsoft SQL Server 2008 Native Client<br />
&quot;{CD344FA5-6657-47CD-940F-8727EED35595}&quot; = Cisco PEAP Module<br />
&quot;{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}&quot; = Microsoft .NET Framework 3.5 SP1<br />
&quot;{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}&quot; = Bluetooth Stack for Windows by Toshiba<br />
&quot;{D5A7D7AB-3093-3619-9261-74DB250ECF7B}&quot; = Microsoft Visual C++ 2008 Express Edition with SP1 - DEU<br />
&quot;{D777D80E-13AE-4E6C-BCB2-9AEE10D9DEF1}&quot; = Driver Updater<br />
&quot;{DE10AB76-4756-4913-BE25-55D1C1051F9A}&quot; = WinFlash<br />
&quot;{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}&quot; = Realtek High Definition Audio Driver<br />
&quot;{F216C9C6-23F7-47B4-B57E-9878DE2E8534}&quot; = QIP Infium 9033.6 Jeak-Edition<br />
&quot;{F5E87B12-3C27-452F-8E78-21D42164FD83}&quot; = Microsoft SQL Server 2008 Management Objects<br />
&quot;{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}&quot; = Vista Codec Package<br />
&quot;{FC3D290D-79BE-44B7-ABF9-FDD110925930}&quot; = PowerForPhone<br />
&quot;Adobe Flash Player ActiveX&quot; = Adobe Flash Player ActiveX<br />
&quot;Adobe Flash Player Plugin&quot; = Adobe Flash Player 10 Plugin<br />
&quot;Adobe Shockwave Player&quot; = Adobe Shockwave Player 11.5<br />
&quot;ASIO4ALL&quot; = ASIO4ALL<br />
&quot;Asus_Camera_ScreenSaver&quot; = Asus_Camera_ScreenSaver<br />
&quot;Avira AntiVir Desktop&quot; = Avira AntiVir Personal - Free Antivirus<br />
&quot;BAE V7.2&quot; = BAE V7.2<br />
&quot;Bolzplatz 2006_is1&quot; = Bolzplatz 2006, v1.0.3<br />
&quot;CCleaner&quot; = CCleaner<br />
&quot;Collab&quot; = Collab<br />
&quot;EroBottle&quot; = EroBottle 4.6 <br />
&quot;FL Studio 8&quot; = FL Studio 8<br />
&quot;Flatcast_is1&quot; = Flatcast 5.0<br />
&quot;foobar2000&quot; = foobar2000 v0.9.5.6<br />
&quot;ICQToolbar&quot; = ICQ Toolbar<br />
&quot;IL Download Manager&quot; = IL Download Manager<br />
&quot;ImgBurn&quot; = ImgBurn<br />
&quot;LastFM_is1&quot; = Last.fm 1.5.4.24567<br />
&quot;LM98Free 2.2a_is1&quot; = LM98Free 2.2a<br />
&quot;Malwarebytes' Anti-Malware_is1&quot; = Malwarebytes' Anti-Malware<br />
&quot;MatheGrafix 8_is1&quot; = MatheGrafix Version 8 (build 03)<br />
&quot;MediaJoin&quot; = MediaJoin<br />
&quot;Microsoft .NET Framework 3.5 Language Pack SP1 - deu&quot; = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU<br />
&quot;Microsoft .NET Framework 3.5 SP1&quot; = Microsoft .NET Framework 3.5 SP1<br />
&quot;Microsoft Visual C++ 2008 Express Edition with SP1 - DEU&quot; = Microsoft Visual C++ 2008 Express Edition mit SP1 - DEU<br />
&quot;Mixxx&quot; = Mixxx<br />
&quot;Mozilla Firefox (3.5.11)&quot; = Mozilla Firefox (3.5.11)<br />
&quot;Native Instruments Service Center&quot; = Native Instruments Service Center<br />
&quot;Native Instruments Traktor 3 LE&quot; = Native Instruments Traktor 3 LE<br />
&quot;Native Instruments Traktor DJ Studio 3&quot; = Native Instruments Traktor DJ Studio 3<br />
&quot;NI Service Center&quot; = NI Service Center<br />
&quot;NVIDIA Drivers&quot; = NVIDIA Drivers<br />
&quot;oggcodecs&quot; = FLAC codecs<br />
&quot;OpenSSL Light (32-bit)_is1&quot; = OpenSSL 0.9.8l Light (32-bit)<br />
&quot;PoiZone&quot; = PoiZone<br />
&quot;PSpice Student&quot; = PSpice Student 9.1<br />
&quot;Rainbow Sentinel Driver&quot; = Sentinel System Driver<br />
&quot;SMSERIAL&quot; = Motorola SM56 Speakerphone Modem<br />
&quot;Solve Elec_is1&quot; = Solve Elec 2.5<br />
&quot;TurboPlot_is1&quot; = TurboPlot v3.7a<br />
&quot;USB2.0 1.3M WebCam&quot; = USB2.0 1.3M WebCam<br />
&quot;uTorrent&quot; = µTorrent<br />
&quot;Virtual DJ - Atomix Productions&quot; = Virtual DJ - Atomix Productions<br />
&quot;VLC media player&quot; = VLC media player 1.0.5<br />
&quot;WinRAR archiver&quot; = WinRAR<br />
&nbsp;<br />
<font color="#E56717">========== HKEY_CURRENT_USER Uninstall List ==========</font><br />
&nbsp;<br />
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]<br />
&quot;EroBottle-Extensions-Editor Vers. 1.5&quot; = EroBottle-Extensions-Editor Vers. 1.5<br />
&quot;QIP Infium&quot; = QIP Infium 2.0.9034<br />
&quot;QipGuard&quot; = QIP Internet Guardian<br />
&nbsp;<br />
<font color="#E56717">========== Last 10 Event Log Errors ==========</font><br />
&nbsp;<br />
[ Application Events ]<br />
Error - 17.01.2010 08:24:48 | Computer Name = Pe-PC | Source = Application Hang | ID = 1002<br />
Description = Programm ICQ.exe, Version 6.5.0.2024 arbeitet nicht mehr mit Windows<br />
&nbsp;zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet &quot;Lösungen<br />
&nbsp;für Probleme&quot; in der Systemsteuerung, um nach weiteren Informationen über das Problem<br />
&nbsp;zu suchen.&nbsp; Prozess-ID: 888&nbsp; Anfangszeit: 01ca976fdd0b976d&nbsp; Zeitpunkt der Beendigung:<br />
&nbsp;18<br />
&nbsp;<br />
Error - 17.01.2010 08:33:01 | Computer Name = Pe-PC | Source = RasClient | ID = 20227<br />
Description = <br />
&nbsp;<br />
Error - 17.01.2010 14:22:37 | Computer Name = Pe-PC | Source = RasClient | ID = 20227<br />
Description = <br />
&nbsp;<br />
Error - 19.01.2010 11:14:47 | Computer Name = Pe-PC | Source = Application Error | ID = 1000<br />
Description = Fehlerhafte Anwendung VCExpress.exe, Version 9.0.30729.1, Zeitstempel<br />
&nbsp;0x488f1715, fehlerhaftes Modul TosBtShell.dll_unloaded, Version 0.0.0.0, Zeitstempel<br />
&nbsp;0x4574fe0c, Ausnahmecode 0xc0000005, Fehleroffset 0x0be74680,&nbsp; Prozess-ID 0x2c0, <br />
Anwendungsstartzeit 01ca99076ed4c427.<br />
&nbsp;<br />
Error - 19.01.2010 19:04:20 | Computer Name = Pe-PC | Source = Application Error | ID = 1000<br />
Description = Fehlerhafte Anwendung wmplayer.exe, Version 11.0.6002.18111, Zeitstempel<br />
&nbsp;0x4aa91411, fehlerhaftes Modul flvDX.dll, Version 1.0.0.1, Zeitstempel 0x445872ae,<br />
&nbsp;Ausnahmecode 0xc000000d, Fehleroffset 0x00025ed0,&nbsp; Prozess-ID 0x238, Anwendungsstartzeit<br />
&nbsp;01ca99599ff4df71.<br />
&nbsp;<br />
Error - 21.01.2010 15:09:29 | Computer Name = Pe-PC | Source = RasClient | ID = 20227<br />
Description = <br />
&nbsp;<br />
Error - 24.01.2010 08:25:37 | Computer Name = Pe-PC | Source = Application Hang | ID = 1002<br />
Description = Programm firefox.exe, Version 1.9.1.3642 arbeitet nicht mehr mit Windows<br />
&nbsp;zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet &quot;Lösungen<br />
&nbsp;für Probleme&quot; in der Systemsteuerung, um nach weiteren Informationen über das Problem<br />
&nbsp;zu suchen.&nbsp; Prozess-ID: fd4&nbsp; Anfangszeit: 01ca9cefbe005834&nbsp; Zeitpunkt der Beendigung:<br />
&nbsp;24<br />
&nbsp;<br />
Error - 24.01.2010 08:25:59 | Computer Name = Pe-PC | Source = Application Hang | ID = 1002<br />
Description = Programm firefox.exe, Version 1.9.1.3642 arbeitet nicht mehr mit Windows<br />
&nbsp;zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet &quot;Lösungen<br />
&nbsp;für Probleme&quot; in der Systemsteuerung, um nach weiteren Informationen über das Problem<br />
&nbsp;zu suchen.&nbsp; Prozess-ID: cec&nbsp; Anfangszeit: 01ca9cf0566d5734&nbsp; Zeitpunkt der Beendigung:<br />
&nbsp;29<br />
&nbsp;<br />
Error - 24.01.2010 09:34:19 | Computer Name = Pe-PC | Source = Application Hang | ID = 1002<br />
Description = Programm firefox.exe, Version 1.9.1.3642 arbeitet nicht mehr mit Windows<br />
&nbsp;zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet &quot;Lösungen<br />
&nbsp;für Probleme&quot; in der Systemsteuerung, um nach weiteren Informationen über das Problem<br />
&nbsp;zu suchen.&nbsp; Prozess-ID: f00&nbsp; Anfangszeit: 01ca9cf064759094&nbsp; Zeitpunkt der Beendigung:<br />
&nbsp;21<br />
&nbsp;<br />
Error - 27.01.2010 08:33:58 | Computer Name = Pe-PC | Source = Application Error | ID = 1000<br />
Description = Fehlerhafte Anwendung Explorer.EXE, Version 6.0.6002.18005, Zeitstempel<br />
&nbsp;0x49e01da5, fehlerhaftes Modul SHELL32.dll, Version 6.0.6002.18005, Zeitstempel<br />
&nbsp;0x49e037ec, Ausnahmecode 0xc0000005, Fehleroffset 0x002d2c67,&nbsp; Prozess-ID 0x9fc, <br />
Anwendungsstartzeit 01ca9f4c519381af.<br />
&nbsp;<br />
[ System Events ]<br />
Error - 07.09.2010 15:08:43 | Computer Name = Pe-PC | Source = Service Control Manager | ID = 7026<br />
Description = <br />
&nbsp;<br />
Error - 08.09.2010 11:59:15 | Computer Name = Pe-PC | Source = Application Popup | ID = 875<br />
Description = Treiber sfdrv01.sys konnte nicht geladen werden.<br />
&nbsp;<br />
Error - 08.09.2010 12:01:10 | Computer Name = Pe-PC | Source = Service Control Manager | ID = 7000<br />
Description = <br />
&nbsp;<br />
Error - 08.09.2010 12:01:10 | Computer Name = Pe-PC | Source = Service Control Manager | ID = 7026<br />
Description = <br />
&nbsp;<br />
Error - 08.09.2010 12:47:04 | Computer Name = Pe-PC | Source = Application Popup | ID = 875<br />
Description = Treiber sfdrv01.sys konnte nicht geladen werden.<br />
&nbsp;<br />
Error - 08.09.2010 12:49:00 | Computer Name = Pe-PC | Source = Service Control Manager | ID = 7000<br />
Description = <br />
&nbsp;<br />
Error - 08.09.2010 12:49:00 | Computer Name = Pe-PC | Source = Service Control Manager | ID = 7026<br />
Description = <br />
&nbsp;<br />
Error - 08.09.2010 13:14:20 | Computer Name = Pe-PC | Source = Application Popup | ID = 875<br />
Description = Treiber sfdrv01.sys konnte nicht geladen werden.<br />
&nbsp;<br />
Error - 08.09.2010 13:15:54 | Computer Name = Pe-PC | Source = Service Control Manager | ID = 7000<br />
Description = <br />
&nbsp;<br />
Error - 08.09.2010 13:15:54 | Computer Name = Pe-PC | Source = Service Control Manager | ID = 7026<br />
Description = <br />
&nbsp;<br />
&nbsp;<br />
&lt; End of report &gt;</code><hr />
</div></div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>shawn77</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90554-backdooprogramm-bds-papras-pk.html</guid>
		</item>
		<item>
			<title>Offen Win 7 Services: file missing...</title>
			<link>http://www.trojaner-board.de/90550-win-7-services-file-missing.html</link>
			<pubDate>Wed, 08 Sep 2010 16:44:43 GMT</pubDate>
			<description>Hallo, 
 
Ich habe HJT unter meinem neuen win7 mal ausprobiert. 
Was ich dabei seltsam finde, sind folgende Einträge: 
 
 
Code: 
--------- 
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing) 
O23 - Service: Avira AntiVir Planer...</description>
			<content:encoded><![CDATA[<div>Hallo,<br />
<br />
Ich habe HJT unter meinem neuen win7 mal ausprobiert.<br />
Was ich dabei seltsam finde, sind folgende Einträge:<br />
<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)<br />
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)<br />
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)<br />
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)</code><hr />
</div>überall &quot;unknown owner&quot; und &quot;file missing&quot;. Das ist doch etwas komisch, da die Dateien eigentlich alle windowsintern sind...<br />
<br />
Kann ich die Einträge alle einfach fixen?<br />
<br />
MfG, b6d</div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>b6d</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90550-win-7-services-file-missing.html</guid>
		</item>
		<item>
			<title>Offen HiJackThis Logs zwecks Auswertung posten</title>
			<link>http://www.trojaner-board.de/90546-hijackthis-logs-zwecks-auswertung-posten.html</link>
			<pubDate>Wed, 08 Sep 2010 16:14:01 GMT</pubDate>
			<description><![CDATA[Hallo Ihr Lieben :D 
  
Ich habe festgestellt, das mit meinem Lapi (Laptop) etwas nicht stimmt, da es mega-lahm wurde und so hat ein Bekannter mit "MalwareBytes" gescannt und prommt 6 Viren gefunden ... er hat sie, wie hier im Forum empfohlen, mit "HijackThis" unschädlich gemacht und gelöscht... ...]]></description>
			<content:encoded><![CDATA[<div>Hallo Ihr Lieben :D<br />
 <br />
Ich habe festgestellt, das mit meinem Lapi (Laptop) etwas nicht stimmt, da es mega-lahm wurde und so hat ein Bekannter mit &quot;MalwareBytes&quot; gescannt und prommt 6 Viren gefunden ... er hat sie, wie hier im Forum empfohlen, mit &quot;HijackThis&quot; unschädlich gemacht und gelöscht... <br />
(oh Gott, sagt man das so ...??? Ich bin völlig unbeholfen in PC-Angelegenheiten :stirn: )<br />
 <br />
Na ja, auf jeden Fall, hat dieser Kollege mir geraten, den HijackThis.exe hier zu posten um einen netten Menschen zu finden, der mir sagen kann ob jetzt wieder alles Okay auf meinem Lapi ist ;) :huepp:<br />
 <br />
DAS IST DER REPORT: (original kopiert)<br />
 HiJackthis Logfile:<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">Logfile of Trend Micro <a href=51130-anleitung-hijackthis.html>HijackThis</a> v2.0.4<br />
Scan saved at 17:12:13, on 08.09.2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
&nbsp;<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe<br />
C:\Programme\Java\jre6\bin\jqs.exe<br />
C:\Programme\CDBurnerXP\NMSAccessU.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Programme\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe<br />
C:\Programme\Google\Update\GoogleUpdate.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\wbem\wmiapsrv.exe<br />
C:\Programme\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Programme\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe<br />
C:\WINDOWS\sm56hlpr.exe<br />
C:\WINDOWS\ATK0100\HControl.exe<br />
C:\Programme\ASUS\Power4 Gear\BatteryLife.exe<br />
C:\WINDOWS\ATK0100\ATKOSD.exe<br />
C:\Dokumente und Einstellungen\****\Desktop\This.com<br />
C:\Programme\Mobile Partner\Mobile Partner.exe<br />
C:\Programme\Mozilla Firefox\firefox.exe<br />
C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\WINDOWS\system32\notepad.exe<br />
&nbsp;<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <br />
&nbsp;<br />
hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <br />
&nbsp;<br />
hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <br />
&nbsp;<br />
hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <br />
&nbsp;<br />
hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <br />
&nbsp;<br />
hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <br />
&nbsp;<br />
hxxp://go.microsoft.com/fwlink/?LinkId=74005<br />
R3 - URLSearchHook: MessengerPlusLive Germany TB Toolbar - <br />
&nbsp;<br />
{76aeea42-e04a-4b62-83ab-df4b2be2541e} - <br />
&nbsp;<br />
C:\Programme\MessengerPlusLive_Germany_TB\tbMess.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - <br />
&nbsp;<br />
C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programme\Kaspersky <br />
&nbsp;<br />
Lab\Kaspersky Internet Security 2010\ievkbd.dll<br />
O2 - BHO: MessengerPlusLive Germany TB Toolbar - {76aeea42-e04a-4b62-83ab-df4b2be2541e} <br />
&nbsp;<br />
- C:\Programme\MessengerPlusLive_Germany_TB\tbMess.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - <br />
&nbsp;<br />
C:\Programme\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - <br />
&nbsp;<br />
C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - <br />
&nbsp;<br />
C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)<br />
O3 - Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - (no file)<br />
O3 - Toolbar: MessengerPlusLive Germany TB Toolbar - <br />
&nbsp;<br />
{76aeea42-e04a-4b62-83ab-df4b2be2541e} - <br />
&nbsp;<br />
C:\Programme\MessengerPlusLive_Germany_TB\tbMess.dll<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [AVP] &quot;C:\Programme\Kaspersky Lab\Kaspersky Internet Security <br />
&nbsp;<br />
2010\avp.exe&quot;<br />
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe<br />
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe<br />
O4 - HKCU\..\Run: [BatteryLife] C:\Programme\ASUS\Power4 Gear\BatteryLife.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER <br />
&nbsp;<br />
DIENST')<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOKALER <br />
&nbsp;<br />
DIENST')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User <br />
&nbsp;<br />
'NETZWERKDIENST')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User <br />
&nbsp;<br />
'NETZWERKDIENST')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default <br />
&nbsp;<br />
user')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default <br />
&nbsp;<br />
user')<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - <br />
&nbsp;<br />
res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Dokumente und <br />
&nbsp;<br />
Einstellungen\****\Anwendungsdaten\DVDVideoSoftIEHelpers\youtubetomp3.htm<br />
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Programme\Kaspersky <br />
&nbsp;<br />
Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm<br />
O9 - Extra button: &amp;Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - <br />
&nbsp;<br />
C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll<br />
O9 - Extra button: Li&amp;nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - <br />
&nbsp;<br />
C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - <br />
&nbsp;<br />
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - <br />
&nbsp;<br />
{e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - <br />
&nbsp;<br />
C:\Programme\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} <br />
&nbsp;<br />
- C:\Programme\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - <br />
&nbsp;<br />
hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab<br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - <br />
&nbsp;<br />
hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <br />
&nbsp;<br />
hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload <br />
&nbsp;<br />
Tool) - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab<br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{F389915F-F243-48F4-BAC3-9C3A309D8CB7}: <br />
&nbsp;<br />
NameServer = 193.189.244.225 193.189.244.206<br />
O20 - AppInit_DLLs: <br />
&nbsp;<br />
C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - <br />
&nbsp;<br />
C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - <br />
&nbsp;<br />
{8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - <br />
&nbsp;<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - <br />
&nbsp;<br />
C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - <br />
&nbsp;<br />
C:\Programme\Java\jre6\bin\jqs.exe<br />
O23 - Service: NMSAccessU - Unknown owner - C:\Programme\CDBurnerXP\NMSAccessU.exe<br />
O23 - Service: TuneUp Drive Defrag-Dienst (TuneUp.Defrag) - TuneUp Software - <br />
&nbsp;<br />
C:\Programme\TuneUp Utilities 2010\TuneUpDefragService.exe<br />
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - <br />
&nbsp;<br />
C:\Programme\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe<br />
&nbsp;<br />
--<br />
End of file - 7941 bytes</code><hr />
</div>--- --- ---<br />
<br />
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX<br />
 <br />
BITTE IST JEMAND IM FORUM DER MIR AUS DIESEM DATEN-GULASCH SAGEN KANN OB ALLES &quot;CLEAN&quot; IST ??? :confused:<br />
 <br />
Lieben Gruß an alle :D<br />
 <br />
By Coolcat</div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>Coolcat</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90546-hijackthis-logs-zwecks-auswertung-posten.html</guid>
		</item>
		<item>
			<title>Offen Antivirus 2010 Security Centre - wirklich vollständig entfernt?</title>
			<link>http://www.trojaner-board.de/90545-antivirus-2010-security-centre-wirklich-vollstaendig-entfernt.html</link>
			<pubDate>Wed, 08 Sep 2010 15:19:15 GMT</pubDate>
			<description><![CDATA[Hallo zusammen, 
 
mein Vater hat sich den oben genannten Virus eingefangen. Leider habe ich das Board erst nachgelagert entdeckt und habe die "Software" per Softwareliste deinstalliert. Was auch auf anhieb klappte. Nur auf Google wurde ich permanent auf Werbeseiten verlinkt... Also war der Virus...]]></description>
			<content:encoded><![CDATA[<div>Hallo zusammen,<br />
<br />
mein Vater hat sich den oben genannten Virus eingefangen. Leider habe ich das Board erst nachgelagert entdeckt und habe die &quot;Software&quot; per Softwareliste deinstalliert. Was auch auf anhieb klappte. Nur auf Google wurde ich permanent auf Werbeseiten verlinkt... Also war der Virus ja noch nicht ganz beseitigt. <br />
<br />
Ich bin dann auf diese Seite gestoßen und habe die Anleitung genau befolgt. Wollte jetzt aber, wie auch in der Anleitung empfohlen, die Logs posten um auch sicherzugehen das mein System wirklich sauber ist.<br />
<br />
Achja, mein Vater bestitz das Norton Internetsecurity Paket von t-online. Kostet ja bekanntlich eine monatliche Gebühr. Er fuhr auch immer zeitnah alle Updates. Kann mir mal bitte einer erklären warum <a href=51187-anleitung-malwarebytes-anti-malware.html>Malwarebytes</a> 14 Infizierungen findet und Norton nichts??????<br />
<br />
Poste jetzt mal den Malware- und OTL-Log, wie in der Anleitung beschrieben.<br />
<br />
Vielen Dank für eure Hilfe und Vielen Dank für diese Hammer Forum.. hat mir wahnsinnig viel geholfen!<br />
<br />
<b>Malwarebytes:</b><br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">Malwarebytes' Anti-Malware 1.46<br />
www.malwarebytes.org<br />
<br />
Datenbank Version: 4570<br />
<br />
Windows 5.1.2600 Service Pack 3<br />
Internet Explorer 8.0.6001.18702<br />
<br />
08.09.2010 16:35:02<br />
mbam-log-2010-09-08 (16-35-02).txt<br />
<br />
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)<br />
Durchsuchte Objekte: 230727<br />
Laufzeit: 1 Stunde(n), 15 Minute(n), 58 Sekunde(n)<br />
<br />
Infizierte Speicherprozesse: 0<br />
Infizierte Speichermodule: 0<br />
Infizierte Registrierungsschlüssel: 4<br />
Infizierte Registrierungswerte: 1<br />
Infizierte Dateiobjekte der Registrierung: 0<br />
Infizierte Verzeichnisse: 0<br />
Infizierte Dateien: 9<br />
<br />
Infizierte Speicherprozesse:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Speichermodule:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Registrierungsschlüssel:<br />
HKEY_CURRENT_USER\SOFTWARE\BMIMZMHMFM (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -&gt; No action taken.<br />
HKEY_CURRENT_USER\SOFTWARE\WS9E3IQBKY (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -&gt; No action taken.<br />
<br />
Infizierte Registrierungswerte:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\alcmtr (Trojan.Refroso.Gen) -&gt; No action taken.<br />
<br />
Infizierte Dateiobjekte der Registrierung:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Verzeichnisse:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Dateien:<br />
C:\WINDOWS\Alcmtr.exe (Trojan.Refroso.Gen) -&gt; No action taken.<br />
C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\pft143~tmp\WDM\Alcmtr.exe (Trojan.Refroso.Gen) -&gt; No action taken.<br />
C:\masm32\examples\dialogs\calender\calender.exe (Malware.Packer) -&gt; No action taken.<br />
C:\masm32\examples\dialogs\tests\tests.exe (Malware.Packer) -&gt; No action taken.<br />
C:\masm32\examples\exampl05\qeplugin\qeplugin.dll (Spyware.Passwords) -&gt; No action taken.<br />
C:\masm32\examples\exampl06\regdemo\regdemo.exe (Trojan.Downloader) -&gt; No action taken.<br />
C:\masm32\tools\makecimp\vcrtdemo\vcrtdemo.exe (Trojan.Downloader) -&gt; No action taken.<br />
C:\masm32\tutorial\dlltute\dll\dlltute.dll (Spyware.Passwords) -&gt; No action taken.<br />
C:\Programme\Realtek\Audio\InstallShield\Alcmtr.exe (Trojan.Refroso.Gen) -&gt; No action taken.</code><hr />
</div><b>OTL:</b><br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">OTL logfile created on: 08.09.2010 16:50:34 - Run 1<br />
OTL by OldTimer - Version 3.2.11.0&nbsp; &nbsp;  Folder = C:\Dokumente und Einstellungen\****\Eigene Dateien\Downloads<br />
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation<br />
Internet Explorer (Version = 8.0.6001.18702)<br />
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy<br />
&nbsp;<br />
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 77,00% Memory free<br />
5,00 Gb Paging File | 4,00 Gb Available in Paging File | 90,00% Paging File free<br />
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]<br />
&nbsp;<br />
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme<br />
Drive C: | 465,75 Gb Total Space | 439,83 Gb Free Space | 94,43% Space Free | Partition Type: NTFS<br />
Drive D: | 186,54 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS<br />
Drive E: | 3,73 Gb Total Space | 3,44 Gb Free Space | 91,99% Space Free | Partition Type: FAT32<br />
F: Drive not present or media not loaded<br />
G: Drive not present or media not loaded<br />
H: Drive not present or media not loaded<br />
I: Drive not present or media not loaded<br />
&nbsp;<br />
Computer Name: KEINE-D302CAF42<br />
Current User Name: ****<br />
Logged in as Administrator.<br />
&nbsp;<br />
Current Boot Mode: Normal<br />
Scan Mode: Current user<br />
Company Name Whitelist: Off<br />
Skip Microsoft Files: Off<br />
File Age = 30 Days<br />
Output = Standard<br />
&nbsp;<br />
<font color="#E56717">========== Processes (SafeList) ==========</font><br />
&nbsp;<br />
PRC - [2010.09.08 16:49:53 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\**\Eigene Dateien\Downloads\<a href=85104-otl-otlogfile-oldtimer.html>OTL.exe</a><br />
PRC - [2010.07.25 13:52:09 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe<br />
PRC - [2010.03.22 16:40:22 | 000,009,728 | ---- | M] (Deutsche Telekom AG) -- C:\Programme\Netzmanager\NMInfraIS2\Netzmanager_Service.exe<br />
PRC - [2009.08.27 18:09:10 | 001,253,376 | ---- | M] (MAGIX AG) -- C:\Programme\Gemeinsame Dateien\MAGIX Services\Database\bin\FABS.exe<br />
PRC - [2008.10.17 16:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) -- C:\Programme\Gemeinsame Dateien\Symantec Shared\CCSVCHST.EXE<br />
PRC - [2008.04.14 04:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe<br />
PRC - [2008.04.08 17:49:18 | 000,671,796 | ---- | M] (Deutsche Telekom AG, Marmiko IT-Solutions GmbH) -- C:\Programme\T-Online\WLAN-Access Finder\ToWLaAcF.exe<br />
PRC - [2007.08.31 11:49:50 | 000,243,064 | ---- | M] (Symantec Corporation) -- C:\Programme\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
PRC - [2007.07.26 16:55:16 | 000,483,393 | ---- | M] (Deutsche Telekom AG, Marmiko IT-Solutions GmbH) -- C:\Programme\Gemeinsame Dateien\Marmiko Shared\MWLaMaS.exe<br />
PRC - [2007.02.08 01:13:48 | 000,774,168 | ---- | M] () -- C:\Programme\Logitech\QuickCam10\QuickCam10.exe<br />
PRC - [2007.02.08 01:12:48 | 000,488,984 | ---- | M] (Logitech Inc.) -- C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe<br />
PRC - [2007.02.08 01:12:20 | 000,230,936 | ---- | M] (Logitech Inc.) -- C:\Programme\Gemeinsame Dateien\LogiShrd\LQCVFX\COCIManager.exe<br />
PRC - [2007.02.06 17:45:26 | 000,109,344 | ---- | M] (Logitech Inc.) -- c:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
PRC - [2007.02.06 17:43:26 | 000,252,704 | ---- | M] (Logitech Inc.) -- C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\LVComSX.exe<br />
PRC - [2007.01.09 17:16:12 | 000,061,440 | ---- | M] (Deutsche Telekom AG, Marmiko IT-Solutions GmbH) -- C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe<br />
PRC - [2004.03.09 15:54:44 | 000,057,393 | ---- | M] (ScanSoft, Inc.) -- C:\Programme\ScanSoft\PaperPort\pptd40nt.exe<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Modules (SafeList) ==========</font><br />
&nbsp;<br />
MOD - [2010.09.08 16:49:53 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\***\Eigene Dateien\Downloads\<a href=85104-otl-otlogfile-oldtimer.html>OTL.exe</a><br />
MOD - [2008.04.14 04:21:06 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx<br />
MOD - [2007.08.25 05:21:58 | 000,144,728 | ---- | M] (Symantec Corporation) -- C:\Programme\Gemeinsame Dateien\Symantec Shared\auCOLPwd.dll<br />
MOD - [2007.02.06 17:45:14 | 000,092,960 | ---- | M] (Logitech Inc.) -- C:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcInj.dll<br />
MOD - [2006.05.03 22:53:54 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\framedyn.dll<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Win32 Services (SafeList) ==========</font><br />
&nbsp;<br />
SRV - [2010.03.22 16:40:22 | 000,009,728 | ---- | M] (Deutsche Telekom AG) [Auto | Running] -- C:\Programme\Netzmanager\NMInfraIS2\Netzmanager_Service.exe -- (Netzmanager Service)<br />
SRV - [2009.11.03 18:39:55 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)<br />
SRV - [2009.08.27 18:09:10 | 001,253,376 | ---- | M] (MAGIX AG) [Unknown | Running] -- C:\Programme\Gemeinsame Dateien\MAGIX Services\Database\bin\FABS.exe -- (Fabs)<br />
SRV - [2008.10.17 16:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe -- (LiveUpdate Notice)<br />
SRV - [2008.10.17 16:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe -- (CLTNetCnService)<br />
SRV - [2008.10.17 16:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)<br />
SRV - [2008.10.17 16:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)<br />
SRV - [2008.08.07 12:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)<br />
SRV - [2008.04.10 23:00:49 | 001,251,720 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC)<br />
SRV - [2007.08.31 11:49:50 | 000,243,064 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Programme\Symantec\LiveUpdate\AluSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)<br />
SRV - [2007.08.23 22:35:24 | 003,192,184 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Programme\Symantec\LiveUpdate\LuComServer_3_4.EXE -- (LiveUpdate)<br />
SRV - [2007.08.22 09:21:30 | 000,055,640 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\VAScanner\comHost.exe -- (comHost)<br />
SRV - [2007.02.06 17:47:12 | 000,105,248 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Programme\Gemeinsame Dateien\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)<br />
SRV - [2007.02.06 17:45:26 | 000,109,344 | ---- | M] (Logitech Inc.) [Auto | Running] -- c:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)<br />
SRV - [2007.01.09 17:16:12 | 000,061,440 | ---- | M] (Deutsche Telekom AG, Marmiko IT-Solutions GmbH) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe -- (MZCCntrl)<br />
SRV - [2006.10.26 19:49:34 | 000,441,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)<br />
SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Driver Services (SafeList) ==========</font><br />
&nbsp;<br />
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\VBoxNetFlt.sys -- (VBoxNetFlt)<br />
DRV - [2010.07.13 10:00:00 | 001,362,608 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\VirusDefs\20100907.048\NAVEX15.SYS -- (NAVEX15)<br />
DRV - [2010.07.13 10:00:00 | 000,085,424 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\VirusDefs\20100907.048\NAVENG.SYS -- (NAVENG)<br />
DRV - [2010.06.23 21:37:11 | 000,264,568 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\SymcData\ipsdefs\20100901.003\SymIDSCo.sys -- (SYMIDSCO)<br />
DRV - [2010.05.26 10:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)<br />
DRV - [2010.05.26 10:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)<br />
DRV - [2009.05.29 20:13:40 | 000,079,888 | ---- | M] (Sun Microsystems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)<br />
DRV - [2009.02.19 12:31:42 | 000,031,280 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIMMP)<br />
DRV - [2009.02.19 12:31:42 | 000,031,280 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIM)<br />
DRV - [2009.02.19 12:31:16 | 000,184,496 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)<br />
DRV - [2009.02.19 12:31:16 | 000,096,560 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMFW.SYS -- (SYMFW)<br />
DRV - [2009.02.19 12:31:16 | 000,038,576 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMIDS.SYS -- (SYMIDS)<br />
DRV - [2009.02.19 12:31:16 | 000,037,424 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMNDIS.SYS -- (SYMNDIS)<br />
DRV - [2009.02.19 12:31:16 | 000,022,320 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)<br />
DRV - [2009.02.19 12:31:16 | 000,013,616 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMDNS.SYS -- (SYMDNS)<br />
DRV - [2009.01.09 11:58:33 | 000,124,464 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)<br />
DRV - [2008.11.09 10:24:13 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)<br />
DRV - [2008.09.05 15:31:42 | 000,447,024 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)<br />
DRV - [2008.07.30 17:42:12 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon)<br />
DRV - [2008.07.16 18:52:22 | 004,747,776 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)<br />
DRV - [2008.04.13 20:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)<br />
DRV - [2008.04.13 20:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB-Audiotreiber (WDM)<br />
DRV - [2008.04.13 18:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)<br />
DRV - [2007.12.05 01:41:00 | 007,435,392 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)<br />
DRV - [2007.11.30 23:57:12 | 000,317,616 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)<br />
DRV - [2007.11.30 23:57:12 | 000,279,088 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)<br />
DRV - [2007.11.30 23:57:12 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)<br />
DRV - [2007.08.09 01:39:56 | 000,036,056 | ---- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CO_Mon.sys -- (CO_Mon)<br />
DRV - [2007.02.06 17:45:04 | 000,025,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)<br />
DRV - [2007.02.06 17:44:36 | 001,964,064 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVMVdrv.sys -- (LVMVDrv)<br />
DRV - [2007.02.06 17:42:40 | 001,691,808 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap)<br />
DRV - [2007.02.03 20:32:34 | 000,041,504 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)<br />
DRV - [2007.02.03 20:27:27 | 000,938,272 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)<br />
DRV - [2007.02.03 20:27:15 | 000,014,240 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)<br />
DRV - [2006.10.09 15:03:56 | 000,017,152 | ---- | M] (Deutsche Telekom AG, Marmiko IT-Solutions GmbH) [Kernel | On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Marmiko Shared\MInfraIS\MIINPazx.sys -- (MIINPazX)<br />
DRV - [2006.10.09 14:46:44 | 000,017,536 | ---- | M] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) [Kernel | On_Demand | Stopped] -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys -- (MTOnlPktAlyX)<br />
DRV - [2006.10.04 09:14:26 | 000,017,280 | ---- | M] (Marmiko IT-Solutions GmbH) [Kernel | On_Demand | Running] -- C:\Programme\Gemeinsame Dateien\Marmiko Shared\MAcNdis5.sys -- (MACNDIS5)<br />
DRV - [2006.01.19 04:17:38 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BrUsbSer.sys -- (BrUsbSer)<br />
DRV - [2006.01.18 23:44:46 | 000,053,248 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BrSerIf.sys -- (BrSerIf)<br />
DRV - [2005.08.30 17:59:00 | 000,094,000 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdm.sys -- (ss_mdm)<br />
DRV - [2005.08.30 17:58:56 | 000,008,304 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdfl.sys -- (ss_mdfl)<br />
DRV - [2005.08.30 17:57:18 | 000,058,320 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bus.sys -- (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM)<br />
DRV - [2004.10.15 13:50:20 | 000,015,295 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BrScnUsb.sys -- (BrScnUsb)<br />
DRV - [2004.08.03 23:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) NT-Treiber für Realtek RTL8139(A/B/C)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Standard Registry (SafeList) ==========</font><br />
&nbsp;<br />
&nbsp;<br />
<font color="#E56717">========== Internet Explorer ==========</font><br />
&nbsp;<br />
&nbsp;<br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: &quot;ProxyEnable&quot; = 0<br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: &quot;ProxyOverride&quot; = *.local<br />
&nbsp;<br />
<font color="#E56717">========== FireFox ==========</font><br />
&nbsp;<br />
FF - prefs.js..browser.search.selectedEngine: &quot;Wikipedia (de)&quot;<br />
FF - prefs.js..browser.startup.homepage: &quot;www.t-online.de&quot;<br />
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0<br />
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102<br />
&nbsp;<br />
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Programme\Mozilla Firefox\components [2010.07.25 13:52:14 | 000,000,000 | ---D | M]<br />
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2010.07.25 13:52:14 | 000,000,000 | ---D | M]<br />
&nbsp;<br />
[2008.09.02 11:31:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Extensions<br />
[2010.09.04 10:30:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\b0qjm3u8.default\extensions<br />
[2009.09.03 08:55:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\b0qjm3u8.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}<br />
[2010.09.08 16:40:28 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions<br />
[2007.08.25 05:52:00 | 000,300,400 | ---- | M] (Symantec Corporation) -- C:\Programme\Mozilla Firefox\components\coFFPlgn.dll<br />
[2010.03.12 22:47:35 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml<br />
[2010.03.12 22:47:35 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml<br />
[2010.03.12 22:47:35 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml<br />
[2010.03.12 22:47:35 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml<br />
[2010.03.12 22:47:35 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml<br />
&nbsp;<br />
O1 HOSTS File: ([2010.09.07 05:46:00 | 000,001,843 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts<br />
O1 - Hosts: 127.0.0.1&nbsp; &nbsp; &nbsp;  localhost<br />
O1 - Hosts: 212.95.49.48 www.google.com<br />
O1 - Hosts: 212.95.49.48 us.search.yahoo.com<br />
O1 - Hosts: 212.95.49.48 uk.search.yahoo.com<br />
O1 - Hosts: 212.95.49.48 search.yahoo.com<br />
O1 - Hosts: 212.95.49.48 www.google.com.br<br />
O1 - Hosts: 212.95.49.48 www.google.it<br />
O1 - Hosts: 212.95.49.48 www.google.es<br />
O1 - Hosts: 212.95.49.48 www.google.co.jp<br />
O1 - Hosts: 212.95.49.48 www.google.com.mx<br />
O1 - Hosts: 212.95.49.48 www.google.ca<br />
O1 - Hosts: 212.95.49.48 www.google.com.au<br />
O1 - Hosts: 212.95.49.48 www.google.nl<br />
O1 - Hosts: 212.95.49.48 www.google.co.za<br />
O1 - Hosts: 212.95.49.48 www.google.be<br />
O1 - Hosts: 212.95.49.48 www.google.gr<br />
O1 - Hosts: 212.95.49.48 www.google.at<br />
O1 - Hosts: 212.95.49.48 www.google.se<br />
O1 - Hosts: 212.95.49.48 www.google.ch<br />
O1 - Hosts: 212.95.49.48 www.google.pt<br />
O1 - Hosts: 212.95.49.48 www.google.dk<br />
O1 - Hosts: 212.95.49.48 www.google.fi<br />
O1 - Hosts: 212.95.49.48 www.google.ie<br />
O1 - Hosts: 212.95.49.48 www.google.no<br />
O1 - Hosts: 212.95.49.48 www.google.de<br />
O1 - Hosts: 3 more lines...<br />
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)<br />
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programme\Gemeinsame Dateien\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)<br />
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programme\Gemeinsame Dateien\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)<br />
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)<br />
O3 - HKLM\..\Toolbar: (Norton-Symbolleiste anzeigen) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programme\Gemeinsame Dateien\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)<br />
O3 - HKCU\..\Toolbar\WebBrowser: (Norton-Symbolleiste anzeigen) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programme\Gemeinsame Dateien\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)<br />
O4 - HKLM..\Run: [ccApp] C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe (Symantec Corporation)<br />
O4 - HKLM..\Run: [ControlCenter2.0] C:\Programme\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)<br />
O4 - HKLM..\Run: [IndexSearch] C:\Programme\ScanSoft\PaperPort\IndexSearch.exe (ScanSoft, Inc.)<br />
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe (Logitech Inc.)<br />
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Programme\Logitech\QuickCam10\QuickCam10.exe ()<br />
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)<br />
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)<br />
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()<br />
O4 - HKLM..\Run: [osCheck] C:\Programme\Norton Internet Security\osCheck.exe (Symantec Corporation)<br />
O4 - HKLM..\Run: [PaperPort PTD] C:\Programme\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)<br />
O4 - HKLM..\Run: [SetDefPrt] C:\Programme\Brother\Brmfl04g\BrStDvPt.exe (Brother Industories, Ltd.)<br />
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Scansoft, Inc.)<br />
O4 - HKCU..\Run: [T-Online_Software_6\WLAN-Access Finder] C:\Programme\T-Online\WLAN-Access Finder\ToWLaAcF.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)<br />
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Lexware Info Service.lnk = C:\Programme\Gemeinsame Dateien\Lexware\Update Manager\LxUpdateManager.exe (Lexware GmbH &amp; Co. KG)<br />
O4 - Startup: C:\Dokumente und Einstellungen\***\Startmenü\Programme\Autostart\Netzmanager.lnk = C:\Programme\Netzmanager\netzmanager.exe (Deutsche Telekom AG)<br />
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1<br />
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145<br />
O8 - Extra context menu item: Nach Microsoft E&amp;xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)<br />
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)<br />
O9 - Extra 'Tools' menuitem : An OneNote s&amp;enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)<br />
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)<br />
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)<br />
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)<br />
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)<br />
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1<br />
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)<br />
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)<br />
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)<br />
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)<br />
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)<br />
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)<br />
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)<br />
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)<br />
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)<br />
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)<br />
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)<br />
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)<br />
O24 - Desktop Components:0 (Die derzeitige Homepage) - About<b></b>:Home<br />
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp<br />
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp<br />
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)<br />
O32 - HKLM CDRom: AutoRun - 1<br />
O32 - AutoRun File - [2008.04.10 17:50:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]<br />
O32 - AutoRun File - [2003.01.11 16:03:44 | 000,000,053 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]<br />
O32 - AutoRun File - [2008.12.12 10:18:00 | 028,745,404 | ---- | M] () - E:\autorun.upg -- [ FAT32 ]<br />
O34 - HKLM BootExecute: (autocheck autochk *) -&nbsp; File not found<br />
O35 - HKLM\..comfile [open] -- &quot;%1&quot; %*<br />
O35 - HKLM\..exefile [open] -- &quot;%1&quot; %*<br />
O37 - HKLM\...com [@ = comfile] -- &quot;%1&quot; %*<br />
O37 - HKLM\...exe [@ = exefile] -- &quot;%1&quot; %*<br />
&nbsp;<br />
<font color="#E56717">========== Files/Folders - Created Within 30 Days ==========</font><br />
&nbsp;<br />
[2010.09.08 16:42:21 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner<br />
[2010.09.08 16:35:10 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Desktop\virus log<br />
[2010.09.08 15:14:34 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Malwarebytes<br />
[2010.09.08 15:14:26 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys<br />
[2010.09.08 15:14:26 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes<br />
[2010.09.08 15:14:25 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys<br />
[2010.09.08 15:14:25 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware<br />
[2010.09.08 15:13:39 | 006,153,648 | ---- | C] (Malwarebytes Corporation&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ) -- C:\Dokumente und Einstellungen\***\Desktop\herbert.exe<br />
[2010.08.15 17:45:57 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\**\Desktop\Walea 2010<br />
[2010.08.12 09:32:22 | 000,000,000 | ---D | C] -- C:\Programme\Netzmanager<br />
[2010.08.12 09:32:22 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Netzmanager<br />
[2010.08.12 09:32:15 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{290883D4-FF33-4C80-B8FB-E5D5A89C103B}<br />
[2010.08.12 09:31:16 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\PackageAware<br />
[5 C:\WINDOWS\*.tmp files -&gt; C:\WINDOWS\*.tmp -&gt; ]<br />
[3 C:\WINDOWS\System32\*.tmp files -&gt; C:\WINDOWS\System32\*.tmp -&gt; ]<br />
&nbsp;<br />
<font color="#E56717">========== Files - Modified Within 30 Days ==========</font><br />
&nbsp;<br />
[2010.09.08 16:39:27 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl<br />
[2010.09.08 16:37:49 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT<br />
[2010.09.08 16:37:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat<br />
[2010.09.08 16:36:37 | 004,718,592 | -H-- | M] () -- C:\Dokumente und Einstellungen\***\NTUSER.DAT<br />
[2010.09.08 16:36:18 | 000,000,190 | -HS- | M] () -- C:\Dokumente und Einstellungen\***\ntuser.ini<br />
[2010.09.08 16:36:05 | 000,054,016 | ---- | M] () -- C:\WINDOWS\System32\drivers\ancsttvb.sys<br />
[2010.09.08 15:12:02 | 006,153,648 | ---- | M] (Malwarebytes Corporation&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ) -- C:\Dokumente und Einstellungen\***\Desktop\herbert.exe<br />
[2010.09.08 15:11:12 | 000,363,520 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Desktop\iExplorer.com<br />
[2010.09.07 16:56:04 | 000,000,718 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\.wtav<br />
[2010.09.02 08:11:20 | 000,002,313 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\KingBill 2009.lnk<br />
[2010.08.31 09:37:17 | 000,000,676 | ---- | M] () -- C:\WINDOWS\tasks\Norton Internet Security Online - Systemprüfung ausführen - ***.job<br />
[2010.08.27 12:59:24 | 000,002,285 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\KingBill 2010.lnk<br />
[2010.08.27 12:55:46 | 000,002,249 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\KingNotes.lnk<br />
[2010.08.26 17:30:31 | 000,011,149 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Eigene Dateien\Herbstzauber 2009.docx<br />
[2010.08.18 16:50:18 | 000,011,652 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Eigene Dateien\Erbeersorten2.docx<br />
[2010.08.15 19:01:31 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LauncherAccess.dt<br />
[2010.08.14 12:14:13 | 000,013,312 | ---- | M] () -- C:\Dokumente und Einstellungen\**\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
[2010.08.12 09:39:41 | 000,000,724 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Startmenü\Programme\Autostart\Netzmanager.lnk<br />
[2010.08.12 09:32:23 | 000,000,764 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Netzmanager.lnk<br />
[2010.08.12 03:24:15 | 002,334,344 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT<br />
[2010.08.12 03:05:00 | 001,033,712 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI<br />
[2010.08.12 03:05:00 | 000,462,662 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat<br />
[2010.08.12 03:05:00 | 000,444,164 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat<br />
[2010.08.12 03:05:00 | 000,085,534 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat<br />
[2010.08.12 03:05:00 | 000,072,040 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat<br />
[5 C:\WINDOWS\*.tmp files -&gt; C:\WINDOWS\*.tmp -&gt; ]<br />
[3 C:\WINDOWS\System32\*.tmp files -&gt; C:\WINDOWS\System32\*.tmp -&gt; ]<br />
&nbsp;<br />
<font color="#E56717">========== Files Created - No Company Name ==========</font><br />
&nbsp;<br />
[2010.09.08 16:36:05 | 000,054,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\ancsttvb.sys<br />
[2010.09.08 15:13:39 | 000,363,520 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Desktop\iExplorer.com<br />
[2010.09.07 05:46:14 | 000,000,718 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\.wtav<br />
[2010.08.27 13:00:36 | 000,069,850 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\COMBIT.LOG<br />
[2010.08.18 16:50:17 | 000,011,652 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Eigene Dateien\Erbeersorten2.docx<br />
[2010.08.12 09:39:41 | 000,000,724 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Startmenü\Programme\Autostart\Netzmanager.lnk<br />
[2010.08.12 09:32:23 | 000,000,764 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Netzmanager.lnk<br />
[2010.07.27 22:05:53 | 000,195,392 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat<br />
[2010.02.08 22:45:13 | 000,116,889 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\mdbu.bin<br />
[2010.02.08 21:31:00 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll<br />
[2009.10.18 18:43:09 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll<br />
[2009.03.04 10:33:53 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\BROSNMP.DLL<br />
[2009.01.07 14:12:57 | 000,013,312 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
[2008.10.15 11:45:08 | 000,000,034 | ---- | C] () -- C:\WINDOWS\Kassenbuch.INI<br />
[2008.07.26 16:14:13 | 000,050,127 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini<br />
[2008.05.01 17:57:48 | 000,000,051 | ---- | C] () -- C:\WINDOWS\brmx2001.ini<br />
[2008.05.01 17:57:48 | 000,000,040 | ---- | C] () -- C:\WINDOWS\opt_2460.ini<br />
[2008.04.18 22:27:07 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI<br />
[2008.04.18 16:06:02 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll<br />
[2008.04.18 13:41:13 | 000,000,801 | ---- | C] () -- C:\WINDOWS\Brpfx04a.ini<br />
[2008.04.18 13:41:13 | 000,000,148 | ---- | C] () -- C:\WINDOWS\brpcfx.ini<br />
[2008.04.18 13:41:13 | 000,000,052 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI<br />
[2008.04.14 20:12:32 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\LXPrnUtil10.dll<br />
[2008.04.14 20:12:32 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\LxUtl10.dll<br />
[2008.04.13 19:50:06 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LauncherAccess.dt<br />
[2008.04.13 19:48:49 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys<br />
[2008.04.13 19:14:47 | 000,000,432 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI<br />
[2008.04.13 19:07:47 | 000,027,114 | ---- | C] () -- C:\WINDOWS\maxlink.ini<br />
[2008.04.13 19:03:30 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS69.DLL<br />
[2008.04.10 18:02:10 | 000,000,057 | ---- | C] () -- C:\WINDOWS\HBUser.ini<br />
[2008.04.10 17:57:37 | 000,000,140 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat<br />
[2007.12.05 01:41:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll<br />
[2007.12.05 01:41:00 | 001,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll<br />
[2007.12.05 01:41:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll<br />
[2007.12.05 01:41:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll<br />
[2007.12.05 01:41:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll<br />
[2007.02.06 17:45:04 | 000,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys<br />
[2007.02.06 17:42:40 | 001,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys<br />
[2006.09.29 16:12:12 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\dnt27VC8.dll<br />
[2006.09.24 22:04:42 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\dntvmc27VC8.dll<br />
[2006.09.24 22:03:32 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dntvm27VC8.dll<br />
[2006.09.21 13:53:28 | 000,282,679 | ---- | C] () -- C:\WINDOWS\System32\dnt27.dll<br />
[2006.09.21 13:52:24 | 000,077,882 | ---- | C] () -- C:\WINDOWS\System32\dntvmc27.dll<br />
[2006.09.21 13:52:14 | 000,077,881 | ---- | C] () -- C:\WINDOWS\System32\dntvm27.dll<br />
[2002.03.04 10:16:34 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\Jpeg32.dll<br />
[2001.10.10 08:57:58 | 000,073,786 | ---- | C] () -- C:\WINDOWS\System32\dntvmc23.dll<br />
[2001.10.10 08:57:58 | 000,061,497 | ---- | C] () -- C:\WINDOWS\System32\dntvm23.dll<br />
[2001.03.07 08:02:30 | 000,229,431 | ---- | C] () -- C:\WINDOWS\System32\dnt23.dll<br />
&nbsp;<br />
<font color="#E56717">========== LOP Check ==========</font><br />
&nbsp;<br />
[2010.02.08 21:31:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ALDI Sued Foto Service<br />
[2010.02.08 21:33:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Aldi Sued Fotoservice<br />
[2009.01.25 18:02:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Banking<br />
[2008.06.27 20:01:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BankingT-Online<br />
[2008.04.14 20:16:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BTrieve<br />
[2008.04.14 20:16:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Lexware<br />
[2010.02.08 21:32:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MAGIX<br />
[2010.08.24 14:17:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Netzmanager<br />
[2008.04.13 19:07:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ScanSoft<br />
[2010.02.12 09:03:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\T-Online<br />
[2010.08.12 09:32:35 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{290883D4-FF33-4C80-B8FB-E5D5A89C103B}<br />
[2008.10.17 19:37:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Kingston<br />
[2008.04.14 20:17:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\**\Anwendungsdaten\Lexware<br />
[2010.02.08 21:33:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\**\Anwendungsdaten\MAGIX<br />
[2008.04.13 19:51:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Samsung<br />
[2008.04.13 19:13:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***Anwendungsdaten\ScanSoft<br />
[2008.04.10 17:58:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\T-Online<br />
&nbsp;<br />
<font color="#E56717">========== Purity Check ==========</font><br />
&nbsp;<br />
&nbsp;<br />
&lt; End of report &gt;</code><hr />
</div></div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>dasuckoor</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90545-antivirus-2010-security-centre-wirklich-vollstaendig-entfernt.html</guid>
		</item>
		<item>
			<title>Offen Trojaner (Antimaleware Doctor) und eventuell auch mehr</title>
			<link>http://www.trojaner-board.de/90537-trojaner-antimaleware-doctor-und-eventuell-auch-mehr.html</link>
			<pubDate>Wed, 08 Sep 2010 12:08:32 GMT</pubDate>
			<description>Hallo Leute, 
 
habe wohl einen bzw meherere Trojaner auf dem PC. Hatte einen Suchdurchlauf mit Malwarebytes Aniti Malware und SuperAntiSpyware laufen lassen und alles gelöscht. Doch als ich vom Abgesicherten Modus wieder in den Normalen Modus gegangen bin war alles wieder da. 
 
 Lasse jetzt...</description>
			<content:encoded><![CDATA[<div>Hallo Leute,<br />
<br />
habe wohl einen bzw meherere Trojaner auf dem PC. Hatte einen Suchdurchlauf mit <a href=51187-anleitung-malwarebytes-anti-malware.html>Malwarebytes</a> Aniti Malware und <a href=51871-anleitung-superantispyware.html>SUPERAntiSpyware</a> laufen lassen und alles gelöscht. Doch als ich vom Abgesicherten Modus wieder in den Normalen Modus gegangen bin war alles wieder da.<br />
<br />
 Lasse jetzt <a href=51187-anleitung-malwarebytes-anti-malware.html>Malwarebytes</a> ein zweites Mal durchlaufen und habe einiges mit <a href=51130-anleitung-hijackthis.html>HijackThis</a> entfernt, aber was muss ich machen um die Schädlinge permanent wegzukriegen? <br />
<br />
Vielen Dank im Vorraus<br />
<br />
<br />
HijackThis-,<br />
RSIT-,<br />
hjtscanlist logs im Anhang</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Angehängte Dateien</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.trojaner-board.de/images/attach/zip.gif" alt="Dateityp: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.trojaner-board.de/attachments/8744d1283947655-trojaner-antimaleware-doctor-und-eventuell-auch-mehr-trojaner.zip">trojaner.zip</a> (37,5 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator><![CDATA[basti']]></dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90537-trojaner-antimaleware-doctor-und-eventuell-auch-mehr.html</guid>
		</item>
		<item>
			<title>Offen Antimaleware Doctor entfernt, Malewarebytes Anti-Maleware logs zur Überprüfung</title>
			<link>http://www.trojaner-board.de/90533-antimaleware-doctor-entfernt-malewarebytes-anti-maleware-logs-zur-uberpruefung.html</link>
			<pubDate>Wed, 08 Sep 2010 09:18:03 GMT</pubDate>
			<description><![CDATA[Hallo liebes trojaner-board Team, 
 
gestern ist auf meinem Rechner der " Antimaleware Doctor" aufgetaucht. Das Programm kam mir sofort unseriös vor und ich habe es nicht ausgeführt. Heute habe ich dann ein bisschen gegoogelt und bin auch promt auf den Beitrag hier aus dem Forum gestoßen. 
 
Das...]]></description>
			<content:encoded><![CDATA[<div>Hallo liebes trojaner-board Team,<br />
<br />
gestern ist auf meinem Rechner der &quot; Antimaleware Doctor&quot; aufgetaucht. Das Programm kam mir sofort unseriös vor und ich habe es nicht ausgeführt. Heute habe ich dann ein bisschen gegoogelt und bin auch promt auf den Beitrag hier aus dem Forum gestoßen.<br />
<br />
Das Tutorial habe ich dann Schritt für Schritt befolgt. ( Und bin nun beim Posten der Logs )<br />
<br />
Als erstes habe ich rkill.com heruntergelanden und ausgeführt.<br />
<br />
Anschließen habe ich mir dann Malewarebytes Anti-Maleware runter geladen und damit die weiteren Schritte des Tutorials befolgt.<br />
<br />
Zu erst habe ich ein Quick-Scan durchgeführt und dabei wurden <b>11 infizierte Objekte</b> gefunden.<br />
<br />
Ich habs sie dann, wie erfordert, entfernt und ich bekam diesen log : <br />
<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">Malwarebytes' Anti-Malware 1.46<br />
www.malwarebytes.org<br />
<br />
Datenbank Version: 4567<br />
<br />
Windows 6.1.7600<br />
Internet Explorer 8.0.7600.16385<br />
<br />
08.09.2010 08:52:05<br />
mbam-log-2010-09-08 (08-52-05).txt<br />
<br />
Art des Suchlaufs: Quick-Scan<br />
Durchsuchte Objekte: 143331<br />
Laufzeit: 4 Minute(n), 23 Sekunde(n)<br />
<br />
Infizierte Speicherprozesse: 0<br />
Infizierte Speichermodule: 0<br />
Infizierte Registrierungsschlüssel: 2<br />
Infizierte Registrierungswerte: 2<br />
Infizierte Dateiobjekte der Registrierung: 0<br />
Infizierte Verzeichnisse: 0<br />
Infizierte Dateien: 7<br />
<br />
Infizierte Speicherprozesse:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Speichermodule:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Registrierungsschlüssel:<br />
HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -&gt; Quarantined and deleted successfully.<br />
<br />
Infizierte Registrierungswerte:<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mediafix70700en02.exe (Trojan.Agent.Gen) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*upd_debug.exe (Trojan.FakeAlert) -&gt; Quarantined and deleted successfully.<br />
<br />
Infizierte Dateiobjekte der Registrierung:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Verzeichnisse:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Dateien:<br />
C:\Users\Mastermind\AppData\Roaming\0DA290A88B8D12D3CBCCE50A39F1D66C\mediafix70700en02.exe (Trojan.Agent.Gen) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Mastermind\AppData\Local\Temp\elev.exe (Trojan.Bamital.Gen) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Mastermind\Desktop\Antimalware Doctor.lnk (Rogue.AntimalwareDoctor) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Mastermind\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Antimalware Doctor.lnk (Rogue.AntimalwareDoctor) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Mastermind\AppData\Roaming\Microsoft\Windows\Start Menu\Antimalware Doctor.lnk (Rogue.AntimalwareDoctor) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Mastermind\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Antimalware Doctor.lnk (Rogue.AntiMalwareDoctor) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Mastermind\AppData\Roaming\0DA290A88B8D12D3CBCCE50A39F1D66C\upd_debug.exe (Trojan.FakeAlert) -&gt; Quarantined and deleted successfully.</code><hr />
</div><br />
Nachdem ich den Rechner neugestartet habe, war vom &quot;Antimaleware Doctor&quot; nichts mehr zu sehen. ( Zumindest sichbtar ) <br />
<br />
Ich habe dann mit Malewarebytes Anti-Maleware noch mal einen vollständigen Scan durchgeführt und er hat <b>1 infizierte Datei</b> gefunden.<br />
<br />
Hier der Log:<br />
<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">Malwarebytes' Anti-Malware 1.46<br />
www.malwarebytes.org<br />
<br />
Datenbank Version: 4567<br />
<br />
Windows 6.1.7600<br />
Internet Explorer 8.0.7600.16385<br />
<br />
08.09.2010 10:01:40<br />
mbam-log-2010-09-08 (10-01-40).txt<br />
<br />
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)<br />
Durchsuchte Objekte: 268910<br />
Laufzeit: 49 Minute(n), 42 Sekunde(n)<br />
<br />
Infizierte Speicherprozesse: 0<br />
Infizierte Speichermodule: 0<br />
Infizierte Registrierungsschlüssel: 0<br />
Infizierte Registrierungswerte: 0<br />
Infizierte Dateiobjekte der Registrierung: 0<br />
Infizierte Verzeichnisse: 0<br />
Infizierte Dateien: 1<br />
<br />
Infizierte Speicherprozesse:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Speichermodule:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Registrierungsschlüssel:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Registrierungswerte:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Dateiobjekte der Registrierung:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Verzeichnisse:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Dateien:<br />
C:\Users\Mastermind\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\14N9RHU8\mediafix70700en02[1].exe (Trojan.Agent.Gen) -&gt; Quarantined and deleted successfully.</code><hr />
</div><br />
Ist mein System jetzt wieder komplett bereinigt ? Und ich kann auch Online-banking wieder nutzen ohne Angst haben zu müssen, dass einer meine Daten klaut oder so ? <br />
<br />
Vielen Dank im Voraus für die Antworten und Hilfen :dankeschoen:</div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>Mastermind88</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90533-antimaleware-doctor-entfernt-malewarebytes-anti-maleware-logs-zur-uberpruefung.html</guid>
		</item>
		<item>
			<title>Offen Objekt: Svchost.exe   Fund:TR/stuby.438272</title>
			<link>http://www.trojaner-board.de/90530-objekt-svchost-exe-fund-tr-stuby-438272-a.html</link>
			<pubDate>Wed, 08 Sep 2010 08:01:11 GMT</pubDate>
			<description><![CDATA[Guten Tag alle zusammen.  
 
Seit eingen Tagen bringt mein Antivir immer folgende Meldung kurz nach dem Systemstart  
 
Objekt: Svchost.exe   Fund:TR/stuby.438272 
 
Ich habe mir hijackthis runtergeladen und mein logfile checken lassen und tatsächlich: 
 
"Dieser Eintrag ist ein Trojaner. Hierbei...]]></description>
			<content:encoded><![CDATA[<div>Guten Tag alle zusammen. <br />
<br />
Seit eingen Tagen bringt mein Antivir immer folgende Meldung kurz nach dem Systemstart <br />
<br />
Objekt: Svchost.exe   Fund:TR/stuby.438272<br />
<br />
Ich habe mir <a href=51130-anleitung-hijackthis.html>HijackThis</a> runtergeladen und mein logfile checken lassen und tatsächlich:<br />
<br />
&quot;Dieser Eintrag ist ein Trojaner. Hierbei sind Programmname und Dateiname identisch:<br />
O4 - HKLM\..\RunOnce: [iepy.exe] C:\WINDOWS\system32\iepy.exe&quot;<br />
<br />
Nun meine Frage an Sie, reicht ein einfaches &quot;fixen&quot; mit <a href=51130-anleitung-hijackthis.html>HijackThis</a> oder kann ich evtl mein System neu aufsetzen?<br />
<br />
Vielen Dank für Ihre Antwort.<br />
<br />
Anbei mein Logfile.<br />
<br />
<div style="margin:20px; margin-top:5px; ">
	<div class="smallfont" style="margin-bottom:2px">Zitat:</div>
	<table cellpadding="6" cellspacing="0" border="0" width="100%">
	<tr>
		<td class="alt2">
			<hr />
			
				Logfile of Trend Micro <a href=51130-anleitung-hijackthis.html>HijackThis</a> v2.0.2<br />
Scan saved at 09:54:37, on 08.09.2010<br />
Platform: Unknown Windows (WinNT 6.01.3504)<br />
MSIE: Internet Explorer v8.00 (8.00.7600.16385)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Program Files (x86)\Analog Devices\SoundMAX\SoundMAX.exe<br />
E:\Programme Win 7\Acrobat\acrotray.exe<br />
C:\Windows\SysWOW64\explorer.exe<br />
E:\Programme Win 7\VirtualCloneDrive\VCDDaemon.exe<br />
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe<br />
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe<br />
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe<br />
E:\Programme Win 7\iTunesHelper.exe<br />
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br />
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br />
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
F2 - REG:system.ini: UserInit=userinit.exe<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - E:\ADOBE CS 5\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - E:\ADOBE CS 5\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll<br />
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe<br />
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] &quot;E:\Programme Win 7\Acrobat\Acrobat_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] &quot;E:\Programme Win 7\Acrobat\Acrotray.exe&quot;<br />
O4 - HKLM\..\Run: [VirtualCloneDrive] &quot;E:\Programme Win 7\VirtualCloneDrive\VCDDaemon.exe&quot; /s<br />
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
O4 - HKLM\..\Run: [WinampAgent] &quot;C:\Program Files (x86)\Winamp\winampa.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe<br />
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] &quot;C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe&quot; -launchedbylogin<br />
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files (x86)\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;E:\Programme Win 7\iTunesHelper.exe&quot;<br />
O4 - HKCU\..\Run: [ICQ] &quot;C:\Program Files (x86)\ICQ6.5\ICQ.exe&quot; silent<br />
O4 - HKCU\..\Run: [HKCU] C:\Users\*****\AppData\Roaming\Winbooterr\Svchost.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST')<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST')<br />
O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Program Files (x86)\Adobe\Reader 8.0\Reader\reader_sl.exe<br />
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files (x86)\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe<br />
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Nach Microsoft E&amp;xel exportieren - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: An OneNote s&amp;enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: acaptuser32.dll<br />
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Unknown owner - C:\Windows\system32\AEADISRV.EXE (file missing)<br />
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br />
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
O23 - Service: Dienst &quot;Bonjour&quot; (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe<br />
O23 - Service: Dragon Age: Origins - Inhaltsupdater (DAUpdaterSvc) - BioWare - E:\Programme Win 7\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe<br />
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30007 (IISADMIN) - Unknown owner - C:\Windows\system32\inetsrv\inetinfo.exe (file missing)<br />
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: mental ray 3.7 Satellite for Autodesk 3ds Max Design 2010 64-bit 64-bit (mi-raysat_3dsmax2010_64) - Unknown owner - E:\Autodesk\mentalray\satellite\raysat_3dsmax2010_64server.exe<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br />
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\Windows\system32\mqsvc.exe (file missing)<br />
O23 - Service: @mqutil.dll,-6203 (MSMQTriggers) - Unknown owner - C:\Windows\system32\mqtgsvc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: NIHardwareService - Native Instruments GmbH - C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe<br />
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)<br />
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe<br />
O23 - Service: TabletServicePen - Unknown owner - C:\Windows\system32\Pen_Tablet.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)<br />
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br />
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br />
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files\WTouch\WTouchService.exe<br />
<br />
--<br />
End of file - 12274 bytes
			
			<hr />
		</td>
	</tr>
	</table>
</div></div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>creativetif</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90530-objekt-svchost-exe-fund-tr-stuby-438272-a.html</guid>
		</item>
		<item>
			<title>Offen Trojan.Vundo.H und Disabled.SecurityCenter - erfolgreich gelöscht?</title>
			<link>http://www.trojaner-board.de/90527-trojan-vundo-h-und-disabled-securitycenter-erfolgreich-geloescht.html</link>
			<pubDate>Wed, 08 Sep 2010 07:44:27 GMT</pubDate>
			<description>Hallo, 
 
mein Rechner (Dell, Inspiron 1300 mit WindowsXP) ist schon seit einiger Zeit langsam und ich habe einiges versucht um ihn zu beschleunigen (Programme aus dem Autostart, einige Programme ganz gelöscht,...). Da ein Freund vor kurzem mit Malwarebytes etwas gefunden hat, habe ich gedacht das...</description>
			<content:encoded><![CDATA[<div>Hallo,<br />
<br />
mein Rechner (Dell, Inspiron 1300 mit WindowsXP) ist schon seit einiger Zeit langsam und ich habe einiges versucht um ihn zu beschleunigen (Programme aus dem Autostart, einige Programme ganz gelöscht,...). Da ein Freund vor kurzem mit <a href=51187-anleitung-malwarebytes-anti-malware.html>Malwarebytes</a> etwas gefunden hat, habe ich gedacht das lasse ich auch drüber laufen. Und prompt wurde was gefunden. Ich habe ansonsten Antivir und Zonealarm, die haben beide nichts gefunden.<br />
<br />
Nun meine Frage - ist damit alles schädliche weg, oder hat <a href=51187-anleitung-malwarebytes-anti-malware.html>Malwarebytes</a> nicht ausgereicht? Danke! <br />
Und evtl. die Zusatzfrage, ob jemand entdeckt, was ich noch machen kann um meinen Rechner wieder etwas schneller zu bekommen.<br />
<br />
Hier die Logdatei vom ersten Scan:<br />
<br />
Malwarebytes' Anti-Malware 1.46<br />
www.malwarebytes.org<br />
<br />
Datenbank Version: 4564<br />
<br />
Windows 5.1.2600 Service Pack 3<br />
Internet Explorer 8.0.6001.18702<br />
<br />
08.09.2010 00:04:59<br />
mbam-log-2010-09-08 (00-04-59).txt<br />
<br />
Art des Suchlaufs: Quick-Scan<br />
Durchsuchte Objekte: 142405<br />
Laufzeit: 40 Minute(n), 12 Sekunde(n)<br />
<br />
Infizierte Speicherprozesse: 0<br />
Infizierte Speichermodule: 0<br />
Infizierte Registrierungsschlüssel: 2<br />
Infizierte Registrierungswerte: 0<br />
Infizierte Dateiobjekte der Registrierung: 2<br />
Infizierte Verzeichnisse: 0<br />
Infizierte Dateien: 0<br />
<br />
Infizierte Speicherprozesse:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Speichermodule:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Registrierungsschlüssel:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd72ce7f-d1e0-4711-ba7b-6846a6f498ae} (Trojan.Vundo.H) -&gt; Quarantined and deleted successfully.<br />
HKEY_CLASSES_ROOT\CLSID\{dd72ce7f-d1e0-4711-ba7b-6846a6f498ae} (Trojan.Vundo.H) -&gt; Quarantined and deleted successfully.<br />
<br />
Infizierte Registrierungswerte:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Dateiobjekte der Registrierung:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
<br />
Infizierte Verzeichnisse:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Dateien:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
<br />
Hier die Logdatei vom zweiten Scan:<br />
<br />
Malwarebytes' Anti-Malware 1.46<br />
www.malwarebytes.org<br />
<br />
Datenbank Version: 4564<br />
<br />
Windows 5.1.2600 Service Pack 3<br />
Internet Explorer 8.0.6001.18702<br />
<br />
08.09.2010 01:33:58<br />
mbam-log-2010-09-08 (01-33-58).txt<br />
<br />
Art des Suchlaufs: Quick-Scan<br />
Durchsuchte Objekte: 142500<br />
Laufzeit: 48 Minute(n), 30 Sekunde(n)<br />
<br />
Infizierte Speicherprozesse: 0<br />
Infizierte Speichermodule: 0<br />
Infizierte Registrierungsschlüssel: 0<br />
Infizierte Registrierungswerte: 0<br />
Infizierte Dateiobjekte der Registrierung: 0<br />
Infizierte Verzeichnisse: 0<br />
Infizierte Dateien: 0<br />
<br />
Infizierte Speicherprozesse:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Speichermodule:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Registrierungsschlüssel:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Registrierungswerte:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Dateiobjekte der Registrierung:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Verzeichnisse:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
Infizierte Dateien:<br />
(Keine bösartigen Objekte gefunden)<br />
<br />
<br />
Lg, Swillswissen</div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>Swillswissen</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90527-trojan-vundo-h-und-disabled-securitycenter-erfolgreich-geloescht.html</guid>
		</item>
		<item>
			<title>Offen DCOM Exploit und LSASS in Windows 7</title>
			<link>http://www.trojaner-board.de/90514-dcom-exploit-und-lsass-windows-7-a.html</link>
			<pubDate>Tue, 07 Sep 2010 20:07:35 GMT</pubDate>
			<description>Hallo, 
  
das erste mal, dass sich mein PC einen Schädling zugezogen hat. Mein avast! Free Edition meldet mir seit heute Mittag ständig Angriffe. Erst waren es nur DCOM Exploit-Meldungen, grad eben kam auch auch eine LSASS-Meldungen hinzu. Ungefähr alle 5 Minuten ein Angriff. Sehr nervig! Habe mal...</description>
			<content:encoded><![CDATA[<div>Hallo,<br />
 <br />
das erste mal, dass sich mein PC einen Schädling zugezogen hat. Mein avast! Free Edition meldet mir seit heute Mittag ständig Angriffe. Erst waren es nur DCOM Exploit-Meldungen, grad eben kam auch auch eine LSASS-Meldungen hinzu. Ungefähr alle 5 Minuten ein Angriff. Sehr nervig! Habe mal meine System-Partition gescannt, mit dem Ergebniss, das nichts gefunden wurde. Was kann man da denn machen?<br />
 <br />
Habe mal <a href=51130-anleitung-hijackthis.html>HijackThis</a> drüberlaufen lassen. Hier das Ergebniss:<br />
 HiJackthis Logfile:<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">Logfile of Trend Micro <a href=51130-anleitung-hijackthis.html>HijackThis</a> v2.0.4<br />
Scan saved at 21:48:55, on 07.09.2010<br />
Platform: Windows 7 (WinNT 6.00.3504)<br />
MSIE: Internet Explorer v8.00 (8.00.7600.16385)<br />
Boot mode: Normal<br />
&nbsp;<br />
Running processes:<br />
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe<br />
C:\Program Files\Alwil Software\Avast5\AvastUI.exe<br />
C:\Program Files (x86)\iTunes\iTunesHelper.exe<br />
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe<br />
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br />
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe<br />
G:\Firefox\HiJackThis204.exe<br />
&nbsp;<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
F2 - REG:system.ini: UserInit=userinit.exe<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O4 - HKLM\..\Run: [avast5] &quot;C:\Program Files\Alwil Software\Avast5\avastUI.exe&quot; /nogui<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files (x86)\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files (x86)\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] &quot;C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe&quot; -launchedbylogin<br />
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe<br />
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] &quot;C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] &quot;C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] &quot;C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe&quot; -autorun<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST')<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST')<br />
O4 - Startup: Locate32 Autorun.lnk = ?<br />
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Nach Microsoft &amp;Excel exportieren - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL<br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab<br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{6D4E30F6-32F8-41F2-BC69-70492B2742E9}: NameServer = 213.191.74.19 62.109.123.196<br />
O17 - HKLM\System\CS1\Services\Tcpip\..\{6D4E30F6-32F8-41F2-BC69-70492B2742E9}: NameServer = 213.191.74.19 62.109.123.196<br />
O17 - HKLM\System\CS2\Services\Tcpip\..\{6D4E30F6-32F8-41F2-BC69-70492B2742E9}: NameServer = 213.191.74.19 62.109.123.196<br />
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br />
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: Dienst &quot;Bonjour&quot; (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe<br />
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: PhenomMsrTweaker service (PhenomMsrTweaker) - Unknown owner - C:\Program Files\PhenomMsrTweaker\PhenomMsrTweakerService.exe<br />
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)<br />
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe<br />
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)<br />
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br />
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br />
&nbsp;<br />
--<br />
End of file - 9256 bytes</code><hr />
</div>--- --- ---<br />
<br />
 <br />
Automatische Updates von Windows und avast! sind aktiv. Auch Java, Firefox, Thunderbird, Flash etc. halte ich stets auf dem neuesten Stand.<br />
 <br />
Bin jetzt unsicher, wie ich weiter vorgehen soll. Hatte noch nie nen Computer-Virus (wenns denn einer ist).<br />
 <br />
Vielen Dank fürs lesen ;-)<br />
 <br />
Grüsse</div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>Relax12</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90514-dcom-exploit-und-lsass-windows-7-a.html</guid>
		</item>
		<item>
			<title>Offen gefährliches Backdooprogramm BDS/Papras.PK</title>
			<link>http://www.trojaner-board.de/90513-gefaehrliches-backdooprogramm-bds-papras-pk.html</link>
			<pubDate>Tue, 07 Sep 2010 19:58:58 GMT</pubDate>
			<description><![CDATA[Hallo liebe Community, 
 
bin neu hier und hab n Problem... 
 
in der Datei C:\WINDOWS\attrnsta.dll wird das "gefährliche Backdooprogramm BDS/Papras.PK" von Avira gefunden... 
Es taucht alle 10 Sekunden erneut auf, Quaratäne oder löschen funktioniert nicht. 
 
Ich habe mich hier im Forum schonmal...]]></description>
			<content:encoded><![CDATA[<div>Hallo liebe Community,<br />
<br />
bin neu hier und hab n Problem...<br />
<br />
in der Datei C:\WINDOWS\attrnsta.dll wird das &quot;gefährliche Backdooprogramm BDS/Papras.PK&quot; von Avira gefunden...<br />
Es taucht alle 10 Sekunden erneut auf, Quaratäne oder löschen funktioniert nicht.<br />
<br />
Ich habe mich hier im Forum schonmal umgeschaut, das Problem gibt es ja öfters anscheinend...<br />
Ich hab deshalb schonmal mit OTL n Scan durchgeführt^^ Ich hoffe dadurch wird es euch erleichtert, mir zu helfen...<br />
<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">OTL Extras logfile created on: 07.09.2010 21:06:29 - Run 1<br />
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Dokumente und Einstellungen\Stephan.ISABELLE\Eigene Dateien\Downloads<br />
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation<br />
Internet Explorer (Version = 6.0.2900.5512)<br />
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy<br />
<br />
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 71,00% Memory free<br />
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 83,00% Paging File free<br />
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]<br />
<br />
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme<br />
Drive C: | 149,04 Gb Total Space | 89,15 Gb Free Space | 59,82% Space Free | Partition Type: NTFS<br />
D: Drive not present or media not loaded<br />
Drive E: | 60,88 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS<br />
F: Drive not present or media not loaded<br />
G: Drive not present or media not loaded<br />
H: Drive not present or media not loaded<br />
I: Drive not present or media not loaded<br />
<br />
Computer Name: ISABELLE<br />
Current User Name: Stephan<br />
Logged in as Administrator.<br />
<br />
Current Boot Mode: Normal<br />
Scan Mode: All users<br />
Company Name Whitelist: Off<br />
Skip Microsoft Files: Off<br />
File Age = 30 Days<br />
Output = Minimal<br />
<br />
========== Extra Registry (SafeList) ==========<br />
<br />
<br />
========== File Associations ==========<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\&lt;extension&gt;]<br />
<br />
[HKEY_USERS\S-1-5-21-527237240-329068152-839522115-1004\SOFTWARE\Classes\&lt;extension&gt;]<br />
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)<br />
<br />
========== Shell Spawning ==========<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\&lt;key&gt;\shell\[command]\command]<br />
batfile [open] -- &quot;%1&quot; %*<br />
cmdfile [open] -- &quot;%1&quot; %*<br />
comfile [open] -- &quot;%1&quot; %*<br />
exefile [open] -- &quot;%1&quot; %*<br />
htmlfile [edit] -- &quot;C:\Programme\Microsoft Office\Office12\msohtmed.exe&quot; %1 (Microsoft Corporation)<br />
htmlfile [print] -- &quot;C:\Programme\Microsoft Office\Office12\msohtmed.exe&quot; /p %1 (Microsoft Corporation)<br />
piffile [open] -- &quot;%1&quot; %*<br />
regfile [merge] -- Reg Error: Key error.<br />
scrfile [config] -- &quot;%1&quot;<br />
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)<br />
scrfile [open] -- &quot;%1&quot; /S<br />
txtfile [edit] -- Reg Error: Key error.<br />
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1<br />
Directory [AddToPlaylistVLC] -- &quot;C:\Programme\VideoLAN\VLC\vlc.exe&quot; --started-from-file --playlist-enqueue &quot;%1&quot; ()<br />
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE &quot;%L&quot; (Microsoft Corporation)<br />
Directory [PlayWithVLC] -- &quot;C:\Programme\VideoLAN\VLC\vlc.exe&quot; --started-from-file --no-playlist-enqueue &quot;%1&quot; ()<br />
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)<br />
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)<br />
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
<br />
========== Security Center Settings ==========<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]<br />
&quot;FirstRunDisabled&quot; = 1<br />
&quot;AntiVirusDisableNotify&quot; = 0<br />
&quot;FirewallDisableNotify&quot; = 0<br />
&quot;UpdatesDisableNotify&quot; = 0<br />
&quot;AntiVirusOverride&quot; = 0<br />
&quot;FirewallOverride&quot; = 0<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]<br />
&quot;139:TCP&quot; = 139:TCP:*:Enabled:@xpsp2res.dll,-22004<br />
&quot;445:TCP&quot; = 445:TCP:*:Enabled:@xpsp2res.dll,-22005<br />
&quot;137:UDP&quot; = 137:UDP:*:Enabled:@xpsp2res.dll,-22001<br />
&quot;138:UDP&quot; = 138:UDP:*:Enabled:@xpsp2res.dll,-22002<br />
&quot;26675:TCP&quot; = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service<br />
&quot;1900:UDP&quot; = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007<br />
&quot;2869:TCP&quot; = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]<br />
&quot;EnableFirewall&quot; = 1<br />
&quot;DoNotAllowExceptions&quot; = 0<br />
&quot;DisableNotifications&quot; = 0<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]<br />
&quot;1900:UDP&quot; = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007<br />
&quot;2869:TCP&quot; = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008<br />
&quot;139:TCP&quot; = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004<br />
&quot;445:TCP&quot; = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005<br />
&quot;137:UDP&quot; = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001<br />
&quot;138:UDP&quot; = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002<br />
&quot;26675:TCP&quot; = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service<br />
<br />
========== Authorized Applications List ==========<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]<br />
&quot;C:\Programme\Microsoft ActiveSync\rapimgr.exe&quot; = C:\Programme\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager -- (Microsoft Corporation)<br />
&quot;C:\Programme\Microsoft ActiveSync\wcescomm.exe&quot; = C:\Programme\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager -- (Microsoft Corporation)<br />
&quot;C:\Programme\Microsoft ActiveSync\WCESMgr.exe&quot; = C:\Programme\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application -- (Microsoft Corporation)<br />
&quot;C:\Programme\ICQ7.0\ICQ.exe&quot; = C:\Programme\ICQ7.0\ICQ.exe:*:Enabled:ICQ7 -- (ICQ, Inc.)<br />
&quot;C:\Programme\ICQ7.0\aolload.exe&quot; = C:\Programme\ICQ7.0\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]<br />
&quot;C:\Programme\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe&quot; = C:\Programme\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server -- (Apache Software Foundation)<br />
&quot;C:\Programme\TeamViewer\Version4\TeamViewer.exe&quot; = C:\Programme\TeamViewer\Version4\TeamViewer.exe:*biggrin isabled:TeamViewer Remote Control Application -- File not found<br />
&quot;C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE&quot; = C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)<br />
&quot;C:\Programme\Microsoft Office\Office12\GROOVE.EXE&quot; = C:\Programme\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- (Microsoft Corporation)<br />
&quot;C:\Programme\Microsoft Office\Office12\ONENOTE.EXE&quot; = C:\Programme\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)<br />
&quot;C:\Dokumente und Einstellungen\Isa\temp\TeamViewer\Version4\TeamViewer.exe&quot; = C:\Dokumente und Einstellungen\Isa\temp\TeamViewer\Version4\TeamViewer.exe:*biggrin isabled:TeamViewer Remote Control Application -- (TeamViewer GmbH)<br />
&quot;C:\Dokumente und Einstellungen\Isa\Desktop\Lancraft\Lancraft\lancraft.exe&quot; = C:\Dokumente und Einstellungen\Isa\Desktop\Lancraft\Lancraft\lancraft.exe:*:Enabled:lancraft -- File not found<br />
&quot;C:\Program Files\Warcraft III\yawle.exe&quot; = C:\Program Files\Warcraft III\yawle.exe:*:Enabled:yawle -- File not found<br />
&quot;C:\Programme\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe&quot; = C:\Programme\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe:*:Enabled:Kaspersky Anti-Virus -- File not found<br />
&quot;C:\Programme\xerox\nwwia\XrxFTPLt.exe&quot; = C:\Programme\xerox\nwwia\XrxFTPLt.exe:*:Enabledshutup rxFTPLt MFC Anwendung -- ()<br />
&quot;C:\Programme\Microsoft Games\Age of Empires II\empires2.exe&quot; = C:\Programme\Microsoft Games\Age of Empires II\empires2.exe:*:Enabled:Age of Empires II -- File not found<br />
&quot;C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab Setup Files\Kaspersky Internet Security 7.0.1.325\German\setup.exe&quot; = C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab Setup Files\Kaspersky Internet Security 7.0.1.325\German\setup.exe:*:Enabled:Installationsprogramm für Kaspersky Internet Security 7.0 -- (Kaspersky Lab)<br />
&quot;C:\Dokumente und Einstellungen\Isa\Desktop\YuLeech-RunesofMagic2_0_1_1821-de.exe&quot; = C:\Dokumente und Einstellungen\Isa\Desktop\YuLeech-RunesofMagic2_0_1_1821-de.exe:*:Enabled:FOG Downloader -- File not found<br />
&quot;C:\Programme\Ubisoft\Heroes of Might and Magic V Collector Edition\bin\H5_Game.exe&quot; = C:\Programme\Ubisoft\Heroes of Might and Magic V Collector Edition\bin\H5_Game.exe:*biggrin isabled:Heroes of Might and Magic V -- File not found<br />
&quot;C:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP3c\RpcAgentSrv.exe&quot; = C:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP3c\RpcAgentSrv.exe:*:Enabled:SiSoftware Deployment Agent Service -- (SiSoftware)<br />
&quot;C:\Programme\TmNationsForever\TmForever.exe&quot; = C:\Programme\TmNationsForever\TmForever.exe:*:Enabled:TmForever -- File not found<br />
&quot;C:\Programme\Java\jre6\bin\javaw.exe&quot; = C:\Programme\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)<br />
&quot;C:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP3c\WNt500x86\RpcSandraSrv.exe&quot; = C:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP3c\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service -- (SiSoftware)<br />
&quot;C:\Programme\Java\jre6\bin\java.exe&quot; = C:\Programme\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)<br />
&quot;C:\Programme\Microsoft ActiveSync\rapimgr.exe&quot; = C:\Programme\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager -- (Microsoft Corporation)<br />
&quot;C:\Programme\Microsoft ActiveSync\wcescomm.exe&quot; = C:\Programme\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager -- (Microsoft Corporation)<br />
&quot;C:\Programme\Microsoft ActiveSync\WCESMgr.exe&quot; = C:\Programme\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application -- (Microsoft Corporation)<br />
&quot;C:\Programme\Tunngle\tnglctrl.exe&quot; = C:\Programme\Tunngle\tnglctrl.exe:*:Enabled:Tunngle Service -- (Tunngle.net GmbH)<br />
&quot;C:\Programme\Tunngle\tunngle.exe&quot; = C:\Programme\Tunngle\tunngle.exe:*:Enabled:Tunngle Client -- (Tunngle.net GmbH)<br />
&quot;C:\Programme\ICQ7.0\ICQ.exe&quot; = C:\Programme\ICQ7.0\ICQ.exe:*:Enabled:ICQ7 -- (ICQ, Inc.)<br />
&quot;C:\Programme\ICQ7.0\aolload.exe&quot; = C:\Programme\ICQ7.0\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)<br />
&quot;C:\WINDOWS\explorer.exe&quot; = C:\WINDOWS\explorer.exe:*biggrin isabled:Windows Explorer -- (Microsoft Corporation)<br />
<br />
<br />
========== HKEY_LOCAL_MACHINE Uninstall List ==========<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]<br />
&quot;{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}&quot; = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148<br />
&quot;{0323C306-8B8C-BB5F-E644-5BFE9A42A7BF}&quot; = Catalyst Control Center Localization Hungarian<br />
&quot;{04AF207D-9A77-465A-8B76-991F6AB66245}&quot; = Adobe Help Viewer CS3<br />
&quot;{054CCA19-DADE-A3C9-171A-8735E23CA6FA}&quot; = Catalyst Control Center Localization Italian<br />
&quot;{055EE59D-217B-43A7-ABFF-507B966405D8}&quot; = ATI Catalyst Control Center<br />
&quot;{08B21B7E-DC6F-69F0-780F-FE7918726A34}&quot; = Catalyst Control Center Localization Korean<br />
&quot;{08B32819-6EEF-4057-AEDA-5AB681A36A23}&quot; = Adobe Bridge Start Meeting<br />
&quot;{106E35DE-FFF3-033A-0D1B-288A231BDE64}&quot; = Catalyst Control Center Localization Russian<br />
&quot;{13F3917B56CD4C25848BDC69916971BB}&quot; = DivX Converter<br />
&quot;{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}&quot; = Adobe WinSoft Linguistics Plugin<br />
&quot;{193DDD97-B56A-511D-0CD6-78D5F421D5BD}&quot; = Catalyst Control Center HydraVision Full<br />
&quot;{19CA0312-BD69-A0DE-D242-BD806E9D627A}&quot; = CCC Help Dutch<br />
&quot;{1A8F390D-E05E-A124-3FB7-89E3E49F81E2}&quot; = CCC Help Polish<br />
&quot;{1B4FC4DB-4ACD-77A1-BA99-C820E5CB68BC}&quot; = CCC Help Chinese Standard<br />
&quot;{1C4551A6-4743-4093-91E4-1477CD655043}&quot; = NVIDIA PhysX<br />
&quot;{1F6423DE-7959-4178-80E0-023C7EAA5347}&quot; = NVIDIA ForceWare Network Access Manager<br />
&quot;{26A24AE4-039D-4CA4-87B4-2F83216010FF}&quot; = Java(TM) 6 Update 20<br />
&quot;{29E5EA97-5F74-4A57-B8B2-D4F169117183}&quot; = Adobe Stock Photos CS3<br />
&quot;{29F05234-DCBB-4FE0-88DC-5160C9250312}&quot; = Adobe Photoshop CS3<br />
&quot;{2BE013D0-4CF4-AA57-05E1-19F9FACCF622}&quot; = CCC Help English<br />
&quot;{2ED57AFF-081D-3B60-0C76-E51F68A9F0D8}&quot; = Catalyst Control Center Localization Polish<br />
&quot;{332CC6BF-E6C7-48EE-BA3D-435E576AD67F}&quot; = PaperPort Image Printer<br />
&quot;{336D9EAB-B952-6023-C94C-8DE52AD75E7D}&quot; = Catalyst Control Center Localization German<br />
&quot;{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}&quot; = WebFldrs XP<br />
&quot;{36753DE9-4B0F-1C39-D2C6-D9E9A1814FC3}&quot; = CCC Help Hungarian<br />
&quot;{3FC7CBBC4C1E11DCA1A752EA55D89593}&quot; = DivX Version Checker<br />
&quot;{4891561F-8CE7-1162-5967-E741306F7616}&quot; = CCC Help Italian<br />
&quot;{4A03706F-666A-4037-7777-5F2748764D10}&quot; = Java Auto Updater<br />
&quot;{4AE31F12-E34D-83C1-BA1A-D65AF3BBB95F}&quot; = Catalyst Control Center Localization Spanish<br />
&quot;{4C8E4664-A6A1-4847-61D0-D4FA02C42BB0}&quot; = Skins<br />
&quot;{4CACC1AC-7EDF-4E73-0019-A446CE2CA02B}&quot; = Catalyst Control Center Localization Chinese Standard<br />
&quot;{4F28C8B9-E1A5-7BC1-915A-29913E129042}&quot; = Catalyst Control Center Localization Japanese<br />
&quot;{54793AA1-5001-42F4-ABB6-C364617C6078}&quot; = Adobe Linguistics CS3<br />
&quot;{57B2B2E4-A1D5-1097-C223-6A4E81554458}&quot; = Catalyst Control Center Localization Danish<br />
&quot;{5BE36E29-4207-2D14-1413-DF103390CC19}&quot; = CCC Help French<br />
&quot;{5C9530C0-957F-4CC4-ADA9-A7195BD9394C}&quot; = AGEIA GAME System Software 2.8.0<br />
&quot;{5D2B8C32-D051-0DB0-D8BD-5CA32E13723B}&quot; = CCC Help Swedish<br />
&quot;{5E85647B-DAF4-E174-9954-210D18B123E6}&quot; = Catalyst Control Center Localization Thai<br />
&quot;{5EE7D259-D137-4438-9A5F-42F432EC0421}&quot; = VC80CRTRedist - 8.0.50727.4053<br />
&quot;{63CA4C0D-7C03-69FE-AE5D-96319AD6AA08}&quot; = CCC Help Norwegian<br />
&quot;{667B8F35-6242-50D3-D69E-69D3BE5445D5}&quot; = Catalyst Control Center Localization Finnish<br />
&quot;{6A6818AD-60CE-9346-60BB-0717876E40F4}&quot; = ccc-core-preinstall<br />
&quot;{6ABE0BEE-D572-4FE8-B434-9E72A289431B}&quot; = Adobe Fonts All<br />
&quot;{6AFCA4E1-9B78-3640-8F72-A7BF33448200}&quot; = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729<br />
&quot;{6DAC0917-50F5-7F70-9776-4215DA7E2D1B}&quot; = CCC Help German<br />
&quot;{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}&quot; = Adobe Asset Services CS3<br />
&quot;{7299052b-02a4-4627-81f2-1818da5d550d}&quot; = Microsoft Visual C++ 2005 Redistributable<br />
&quot;{73B5D990-04EA-4751-B10F-5534770B91F2}&quot; = Adobe Color EU Recommended Settings<br />
&quot;{76E3C633-BC8E-E33D-8774-4A3DF581C8FE}&quot; = CCC Help Portuguese<br />
&quot;{770657D0-A123-3C07-8E44-1C83EC895118}&quot; = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
&quot;{788F45B5-816D-2294-33DD-BF080093D54D}&quot; = Catalyst Control Center Graphics Previews Common<br />
&quot;{79A636B4-3FA8-1E2F-A85D-6B6A4A0DA43D}&quot; = CCC Help Russian<br />
&quot;{7A14BF33-11BF-033B-02CC-732A30C09314}&quot; = Catalyst Control Center Localization Greek<br />
&quot;{7B63B2922B174135AFC0E1377DD81EC2}&quot; =<br />
&quot;{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}&quot; = Age of Empires III<br />
&quot;{7C7575F4-351D-8F62-5693-61D6E0171F85}&quot; = CCC Help Korean<br />
&quot;{802771A9-A856-4A41-ACF7-1450E523C923}&quot; = Adobe XMP Panels CS3<br />
&quot;{82D1C246-2D78-5311-8D3F-8214B94EEFA4}&quot; = CCC Help Turkish<br />
&quot;{85B4D6CC-ADF6-A78F-1463-F70C2E274849}&quot; = CCC Help Finnish<br />
&quot;{88EB38EF-4D2C-436D-ABD3-56B232674062}&quot; = ICQ7<br />
&quot;{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}&quot; = ATI AVIVO Codecs<br />
&quot;{8A183127-7EDB-B2DD-7D87-70FBFA3A33C1}&quot; = Catalyst Control Center Localization Portuguese<br />
&quot;{8B35E3B4-0E9B-ED12-F102-EB8160DD1F46}&quot; = Catalyst Control Center Localization Swedish<br />
&quot;{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}&quot; = Adobe Device Central CS3<br />
&quot;{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}&quot; = Adobe Type Support<br />
&quot;{8FD6CA17-DB2B-9411-CEF5-B899DCBAB685}&quot; = CCC Help Danish<br />
&quot;{90120000-0010-0407-0000-0000000FF1CE}&quot; = Microsoft Software Update for Web Folders (German) 12<br />
&quot;{90120000-0015-0407-0000-0000000FF1CE}&quot; = Microsoft Office Access MUI (German) 2007<br />
&quot;{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-0016-0407-0000-0000000FF1CE}&quot; = Microsoft Office Excel MUI (German) 2007<br />
&quot;{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-0018-0407-0000-0000000FF1CE}&quot; = Microsoft Office PowerPoint MUI (German) 2007<br />
&quot;{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-0019-0407-0000-0000000FF1CE}&quot; = Microsoft Office Publisher MUI (German) 2007<br />
&quot;{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-001A-0407-0000-0000000FF1CE}&quot; = Microsoft Office Outlook MUI (German) 2007<br />
&quot;{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-001B-0407-0000-0000000FF1CE}&quot; = Microsoft Office Word MUI (German) 2007<br />
&quot;{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-001F-0407-0000-0000000FF1CE}&quot; = Microsoft Office Proof (German) 2007<br />
&quot;{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}&quot; = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-001F-0409-0000-0000000FF1CE}&quot; = Microsoft Office Proof (English) 2007<br />
&quot;{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}&quot; = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-001F-040C-0000-0000000FF1CE}&quot; = Microsoft Office Proof (French) 2007<br />
&quot;{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}&quot; = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-001F-0410-0000-0000000FF1CE}&quot; = Microsoft Office Proof (Italian) 2007<br />
&quot;{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}&quot; = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-002C-0407-0000-0000000FF1CE}&quot; = Microsoft Office Proofing (German) 2007<br />
&quot;{90120000-0030-0000-0000-0000000FF1CE}&quot; = Microsoft Office Enterprise 2007<br />
&quot;{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}&quot; = Security Update for Microsoft Office system 2007 (972581)<br />
&quot;{90120000-0044-0407-0000-0000000FF1CE}&quot; = Microsoft Office InfoPath MUI (German) 2007<br />
&quot;{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-006E-0407-0000-0000000FF1CE}&quot; = Microsoft Office Shared MUI (German) 2007<br />
&quot;{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{26454C26-D259-4543-AA60-3189E09C5F76}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-00A1-0407-0000-0000000FF1CE}&quot; = Microsoft Office OneNote MUI (German) 2007<br />
&quot;{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-00BA-0407-0000-0000000FF1CE}&quot; = Microsoft Office Groove MUI (German) 2007<br />
&quot;{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90176341-0A8B-4CCC-A78D-F862228A6B95}&quot; = Adobe Anchor Service CS3<br />
&quot;{90D73DED-670E-BE24-C645-C4D546A1F2C3}&quot; = CCC Help Spanish<br />
&quot;{9210C991-FE28-2B30-3E27-0F921AB5B9EC}&quot; = Catalyst Control Center Localization Chinese Traditional<br />
&quot;{926D18B2-11B5-7210-621A-5231DC005705}&quot; = CCC Help Czech<br />
&quot;{99052DB7-9592-4522-A558-5417BBAD48EE}&quot; = Microsoft ActiveSync<br />
&quot;{9A25302D-30C0-39D9-BD6F-21E6EC160475}&quot; = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
&quot;{9B0CCE51-B328-D4F7-C4A4-65723AF20574}&quot; = Catalyst Control Center Core Implementation<br />
&quot;{9C9824D9-9000-4373-A6A5-D0E5D4831394}&quot; = Adobe Bridge CS3<br />
&quot;{A13C84F5-B2FC-823B-ADB2-6F5B2A6EE9DE}&quot; = ccc-utility<br />
&quot;{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}&quot; = Adobe CMaps<br />
&quot;{A2D81E70-2A98-4A08-A628-94388B063C5E}&quot; = Adobe Color - Photoshop Specific<br />
&quot;{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}&quot; = Microsoft .NET Framework 3.0 Service Pack 2<br />
&quot;{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}&quot; = Brother MFL-Pro Suite<br />
&quot;{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}&quot; = PDF Settings<br />
&quot;{B13A7C41581B411290FBC0395694E2A9}&quot; = DivX Converter<br />
&quot;{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}&quot; = Adobe Camera Raw 4.0<br />
&quot;{B6C89654-A6A2-477C-873B-724EC1C56407}&quot; = ScanSoft PaperPort 11<br />
&quot;{B70E4F29-F9C9-4D32-80F3-6E24ED1DBCDF}&quot; = Catalyst Control Center Localization Norwegian<br />
&quot;{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}&quot; = Adobe Default Language CS3<br />
&quot;{B9C149DB-E4F6-573A-DF3B-B9E392F1BA64}&quot; = CCC Help Thai<br />
&quot;{BDC209E0-8D38-F913-5246-4376FC4C3EF5}&quot; = Catalyst Control Center Localization French<br />
&quot;{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}&quot; = Microsoft .NET Framework 2.0 Service Pack 2<br />
&quot;{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}&quot; = Adobe ExtendScript Toolkit 2<br />
&quot;{C3113E55-7BCB-4de3-8EBF-60E6CE6B2196}_is1&quot; = SiSoftware Sandra Lite 2009.SP3c<br />
&quot;{C73B3D3A-2FDC-EE8F-F0E5-0269A85014D3}&quot; = Catalyst Control Center Graphics Light<br />
&quot;{C8C08FE3-05DC-7A8B-C23B-9276FFE21183}&quot; = Catalyst Control Center Localization Dutch<br />
&quot;{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}&quot; = Microsoft .NET Framework 3.5 SP1<br />
&quot;{D00A7B31-C764-94AF-7915-87676458CC66}&quot; = Catalyst Control Center Localization Turkish<br />
&quot;{D0DFF92A-492E-4C40-B862-A74A173C25C5}&quot; = Adobe Version Cue CS3 Client<br />
&quot;{D103C4BA-F905-437A-8049-DB24763BBE36}&quot; = Skype™ 4.2<br />
&quot;{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}&quot; = Adobe PDF Library Files<br />
&quot;{D3B1C799-CB73-42DE-BA0F-2344793A095C}&quot; = Catalyst Control Center - Branding<br />
&quot;{D4B95A0D-CF13-633F-09A6-15D78B24F3AE}&quot; = CCC Help Chinese Traditional<br />
&quot;{D9509DDD-74B4-A7CB-3669-7358BEE3C1AC}&quot; = ccc-core-static<br />
&quot;{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}&quot; = Adobe Color Common Settings<br />
&quot;{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}&quot; = Adobe Color JA Extra Settings<br />
&quot;{E3E71D07-CD27-46CB-8448-16D4FB29AA13}&quot; = Microsoft WSE 3.0 Runtime<br />
&quot;{E46B244B-9BF2-EA75-2D4C-7BD0BA12860A}&quot; = CCC Help Japanese<br />
&quot;{E69AE897-9E0B-485C-8552-7841F48D42D8}&quot; = Adobe Update Manager CS3<br />
&quot;{EA5C28E2-3048-5BC5-67C4-E0BB33C60FDA}&quot; = Catalyst Control Center Localization Czech<br />
&quot;{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}&quot; = Samsung PC Studio 3 USB Driver Installer<br />
&quot;{ECA89BA0-1C9B-237D-F59E-EC62534831A5}&quot; = Catalyst Control Center Graphics Full New<br />
&quot;{ECB29C3B-4D64-17C0-430D-DEB933D76834}&quot; = CCC Help Greek<br />
&quot;{ED862528-0058-F09F-F4B3-3E3276A3F3C7}&quot; = Catalyst Control Center Graphics Full Existing<br />
&quot;{F01F79AD-1F47-4685-AE4E-CCFA4EA9FF7C}&quot; = Adobe Setup<br />
&quot;{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}&quot; = Realtek High Definition Audio Driver<br />
&quot;{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}&quot; = Adobe Color NA Extra Settings<br />
&quot;Adobe Flash Player ActiveX&quot; = Adobe Flash Player 10 ActiveX<br />
&quot;Adobe Flash Player Plugin&quot; = Adobe Flash Player 10 Plugin<br />
&quot;Adobe_5f143314a5d434c8511097393d17397&quot; = Adobe Photoshop CS3<br />
&quot;All ATI Software&quot; = ATI - Dienstprogramm zur Deinstallation der Software<br />
&quot;ALUpdate_is1&quot; = ALUpdate<br />
&quot;ATI Display Driver&quot; = ATI Display Driver<br />
&quot;Avira AntiVir Desktop&quot; = Avira AntiVir Personal - Free Antivirus<br />
&quot;CCleaner&quot; = CCleaner<br />
&quot;DivX Plus DirectShow Filters&quot; = DivX Plus DirectShow Filters<br />
&quot;DivX Setup.divx.com&quot; = DivX-Setup<br />
&quot;ENTERPRISE&quot; = Microsoft Office Enterprise 2007<br />
&quot;Foxit Reader&quot; = Foxit Reader<br />
&quot;Free Audio CD Burner_is1&quot; = Free Audio CD Burner version 1.4<br />
&quot;Guild Wars&quot; = GUILD WARS<br />
&quot;Heroes of Might and Magic IV&quot; = Heroes of Might and Magic IV: Winds of War<br />
&quot;InstallShield_{1F6423DE-7959-4178-80E0-023C7EAA5347}&quot; = NVIDIA ForceWare Network Access Manager<br />
&quot;InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}&quot; = Age of Empires III<br />
&quot;InterActual Player&quot; = InterActual Player<br />
&quot;Medion GoPal Assistant&quot; = Medion GoPal Assistant 4.02.007<br />
&quot;Microsoft .NET Framework 3.5 SP1&quot; = Microsoft .NET Framework 3.5 SP1<br />
&quot;Mozilla Firefox (3.6.8)&quot; = Mozilla Firefox (3.6.8)<br />
&quot;MSCompPackV1&quot; = Microsoft Compression Client Pack 1.0 for Windows XP<br />
&quot;NVIDIA Drivers&quot; = NVIDIA Drivers<br />
&quot;Plants vs. Zombies&quot; = Plants vs. Zombies<br />
&quot;SAMSUNG Mobile Modem&quot; = SAMSUNG Mobile Modem Driver Set<br />
&quot;Samsung Mobile phone USB driver&quot; = Samsung Mobile phone USB driver Software<br />
&quot;SAMSUNG Mobile USB Modem&quot; = SAMSUNG Mobile USB Modem Software<br />
&quot;SAMSUNG Mobile USB Modem 1.0&quot; = SAMSUNG Mobile USB Modem 1.0 Software<br />
&quot;Trine_is1&quot; = Trine<br />
&quot;Tunngle beta_is1&quot; = Tunngle beta<br />
&quot;Uninstall_is1&quot; = Uninstall 1.0.0.1<br />
&quot;VirtualCloneDrive&quot; = VirtualCloneDrive<br />
&quot;VLC media player&quot; = VLC media player 1.0.5<br />
&quot;Windows Media Format Runtime&quot; = Windows Media Format 11 runtime<br />
&quot;Windows Media Player&quot; = Windows Media Player 11<br />
&quot;Windows XP Service Pack&quot; = Windows XP Service Pack 3<br />
&quot;WinRAR archiver&quot; = WinRAR<br />
&quot;WMFDist11&quot; = Windows Media Format 11 runtime<br />
&quot;wmp11&quot; = Windows Media Player 11<br />
&quot;Wudf01000&quot; = Microsoft User-Mode Driver Framework Feature Pack 1.0<br />
<br />
========== HKEY_USERS Uninstall List ==========<br />
<br />
[HKEY_USERS\S-1-5-21-527237240-329068152-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]<br />
&quot;Yahoo! BrowserPlus&quot; = Yahoo! BrowserPlus 2.7.1<br />
<br />
========== Last 10 Event Log Errors ==========<br />
<br />
[ Application Events ]<br />
Error - 10.08.2010 11:01:18 | Computer Name = ISABELLE | Source = .NET Runtime 2.0 Error Reporting | ID = 1000<br />
Description = Faulting application ccc.exe, version 2.0.0.0, stamp 48bd5e7d, faulting<br />
module mscorwks.dll, version 2.0.50727.3603, stamp 4a7cd88e, debug? 0, fault address<br />
0x00097d9a.<br />
<br />
Error - 10.08.2010 11:01:19 | Computer Name = ISABELLE | Source = .NET Runtime 2.0 Error Reporting | ID = 1000<br />
Description = Faulting application mom.exe, version 2.0.0.0, stamp 48bd603c, faulting<br />
module mscorwks.dll, version 2.0.50727.3603, stamp 4a7cd88e, debug? 0, fault address<br />
0x00097d9a.<br />
<br />
Error - 11.08.2010 11:23:13 | Computer Name = ISABELLE | Source = .NET Runtime 2.0 Error Reporting | ID = 1000<br />
Description = Faulting application ccc.exe, version 2.0.0.0, stamp 48bd5e7d, faulting<br />
module mscorwks.dll, version 2.0.50727.3615, stamp 4be902c7, debug? 0, fault address<br />
0x00097dda.<br />
<br />
Error - 20.08.2010 07:47:41 | Computer Name = ISABELLE | Source = Application Error | ID = 1000<br />
Description = Fehlgeschlagene Anwendung divxupdate.exe, Version 1.0.1.10, fehlgeschlagenes<br />
Modul msvcp80.dll, Version 8.0.50727.4053, Fehleradresse 0x000100b5.<br />
<br />
Error - 03.09.2010 11:53:27 | Computer Name = ISABELLE | Source = .NET Runtime 2.0 Error Reporting | ID = 1000<br />
Description = Faulting application ccc.exe, version 2.0.0.0, stamp 48bd5e7d, faulting<br />
module mscorwks.dll, version 2.0.50727.3615, stamp 4be902c7, debug? 0, fault address<br />
0x00097dda.<br />
<br />
Error - 03.09.2010 15:17:50 | Computer Name = ISABELLE | Source = Application Hang | ID = 1002<br />
Description = Stillstehende Anwendung firefox.exe, Version 1.9.2.3855, Stillstandmodul<br />
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.<br />
<br />
Error - 05.09.2010 12:38:03 | Computer Name = ISABELLE | Source = Application Hang | ID = 1002<br />
Description = Stillstehende Anwendung firefox.exe, Version 1.9.2.3855, Stillstandmodul<br />
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.<br />
<br />
Error - 06.09.2010 15:33:46 | Computer Name = ISABELLE | Source = .NET Runtime 2.0 Error Reporting | ID = 1000<br />
Description = Faulting application ccc.exe, version 2.0.0.0, stamp 48bd5e7d, faulting<br />
module mscorwks.dll, version 2.0.50727.3615, stamp 4be902c7, debug? 0, fault address<br />
0x00097dda.<br />
<br />
Error - 07.09.2010 14:39:23 | Computer Name = ISABELLE | Source = .NET Runtime 2.0 Error Reporting | ID = 1000<br />
Description = Faulting application ccc.exe, version 2.0.0.0, stamp 48bd5e7d, faulting<br />
module mscorwks.dll, version 2.0.50727.3615, stamp 4be902c7, debug? 0, fault address<br />
0x00097dda.<br />
<br />
Error - 07.09.2010 14:39:24 | Computer Name = ISABELLE | Source = .NET Runtime 2.0 Error Reporting | ID = 1000<br />
Description = Faulting application mom.exe, version 2.0.0.0, stamp 48bd603c, faulting<br />
module mscorwks.dll, version 2.0.50727.3615, stamp 4be902c7, debug? 0, fault address<br />
0x00097dda.<br />
<br />
[ System Events ]<br />
Error - 01.08.2010 14:19:53 | Computer Name = ISABELLE | Source = DCOM | ID = 10010<br />
Description = Der Server &quot;{ED081F25-6A77-4C89-B689-C6E15C582EC1}&quot; konnte innerhalb<br />
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.<br />
<br />
Error - 03.08.2010 15:10:50 | Computer Name = ISABELLE | Source = DCOM | ID = 10010<br />
Description = Der Server &quot;{ED081F25-6A77-4C89-B689-C6E15C582EC1}&quot; konnte innerhalb<br />
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.<br />
<br />
Error - 07.08.2010 13:46:20 | Computer Name = ISABELLE | Source = DCOM | ID = 10010<br />
Description = Der Server &quot;{ED081F25-6A77-4C89-B689-C6E15C582EC1}&quot; konnte innerhalb<br />
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.<br />
<br />
Error - 10.08.2010 04:46:24 | Computer Name = ISABELLE | Source = W32Time | ID = 39452689<br />
Description = Zeitabieter &quot;NtpClient&quot;: Beim DNS-Lookup für den manuell konfigurierten<br />
Peer &quot;time.windows.com,0x1&quot; ist ein Fehler aufgetreten. Der DNS-Lookup wird in 15<br />
Minuten wiederholt. Fehler: Der Host war bei einem Socketvorgang nicht erreichbar.<br />
(0x80072751)<br />
<br />
Error - 10.08.2010 04:46:24 | Computer Name = ISABELLE | Source = W32Time | ID = 39452701<br />
Description = Der Zeitanbieter &quot;NtpClient&quot; wurde für die Zeiterfassung von mehreren<br />
Zeitquellen konfiguriert. Es ist jedoch Keine der Quellen verfügbar. Innerhalb der<br />
nächsten 14 Minuten wird kein Versuch unternommen, eine Verbindung mit der Quelle<br />
herzustellen. Der NtpClient verfügt über keine Quelle mit genauer Zeit.<br />
<br />
Error - 10.08.2010 04:46:24 | Computer Name = ISABELLE | Source = W32Time | ID = 39452689<br />
Description = Zeitabieter &quot;NtpClient&quot;: Beim DNS-Lookup für den manuell konfigurierten<br />
Peer &quot;time.windows.com,0x1&quot; ist ein Fehler aufgetreten. Der DNS-Lookup wird in 15<br />
Minuten wiederholt. Fehler: Der Host war bei einem Socketvorgang nicht erreichbar.<br />
(0x80072751)<br />
<br />
Error - 10.08.2010 04:46:24 | Computer Name = ISABELLE | Source = W32Time | ID = 39452701<br />
Description = Der Zeitanbieter &quot;NtpClient&quot; wurde für die Zeiterfassung von mehreren<br />
Zeitquellen konfiguriert. Es ist jedoch Keine der Quellen verfügbar. Innerhalb der<br />
nächsten 14 Minuten wird kein Versuch unternommen, eine Verbindung mit der Quelle<br />
herzustellen. Der NtpClient verfügt über keine Quelle mit genauer Zeit.<br />
<br />
Error - 23.08.2010 15:05:14 | Computer Name = ISABELLE | Source = DCOM | ID = 10010<br />
Description = Der Server &quot;{ED081F25-6A77-4C89-B689-C6E15C582EC1}&quot; konnte innerhalb<br />
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.<br />
<br />
Error - 26.08.2010 14:20:13 | Computer Name = ISABELLE | Source = DCOM | ID = 10010<br />
Description = Der Server &quot;{ED081F25-6A77-4C89-B689-C6E15C582EC1}&quot; konnte innerhalb<br />
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.<br />
<br />
Error - 05.09.2010 13:25:03 | Computer Name = ISABELLE | Source = DCOM | ID = 10010<br />
Description = Der Server &quot;{ED081F25-6A77-4C89-B689-C6E15C582EC1}&quot; konnte innerhalb<br />
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.<br />
<br />
<br />
&lt; End of report &gt;</code><hr />
</div><div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools<br />
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsererweiterungen<br />
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player<br />
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - Zugang zu MSN Site<br />
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework<br />
ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders<br />
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - &quot;%ProgramFiles%\Outlook Express\setup50.exe&quot; /APP:WAB /CALLER:WINNT /user /install<br />
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll<br />
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - %SystemRoot%\system32\ie4uinit.exe<br />
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install<br />
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML-Datenbindung<br />
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework<br />
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer-Hauptschriftarten<br />
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner<br />
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1<br />
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player<br />
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML-Hilfe<br />
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface<br />
ActiveX: &gt;{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP<br />
ActiveX: &gt;{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE<br />
ActiveX: &gt;{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP<br />
ActiveX: &gt;{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE<br />
<br />
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)<br />
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)<br />
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)<br />
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)<br />
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)<br />
Drivers32: vidc.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)<br />
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()<br />
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()<br />
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)<br />
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)<br />
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)<br />
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)<br />
<br />
CREATERESTOREPOINT<br />
Restore point Set: OTL Restore Point (59404830837309440)<br />
<br />
========== Files/Folders - Created Within 30 Days ==========<br />
<br />
File not found -- C:\WINDOWS\System32\attrnsta.dll<br />
[2010.09.05 16:20:20 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\tmp<br />
[2010.09.05 16:20:17 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\hps<br />
[2010.09.05 16:17:46 | 000,000,000 | ---D | C] -- C:\Programme\CeWe Color<br />
[2010.09.03 15:47:09 | 000,106,792 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\sscdmdm.sys<br />
[2010.09.03 15:47:09 | 000,080,552 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\sscdbus.sys<br />
[2010.09.03 15:47:09 | 000,011,944 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\sscdmdfl.sys<br />
[2010.09.03 15:47:09 | 000,009,256 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\sscdwhnt.sys<br />
[2010.09.03 15:47:09 | 000,009,256 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\sscdwh.sys<br />
[2010.09.03 15:47:09 | 000,009,256 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\sscdcmnt.sys<br />
[2010.09.03 15:47:09 | 000,009,256 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\sscdcm.sys<br />
[2010.09.03 15:46:36 | 000,000,000 | ---D | C] -- C:\Programme\Samsung<br />
[2010.09.03 13:59:27 | 000,004,352 | ---- | C] (AVM Berlin) -- C:\WINDOWS\System32\drivers\avmeject.sys<br />
[2010.09.03 13:58:54 | 000,000,000 | ---D | C] -- C:\Programme\avmwlanstick<br />
[2010.09.03 13:58:52 | 000,265,088 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\drivers\fwlanusb.sys<br />
[2010.09.03 13:58:52 | 000,074,752 | ---- | C] (AVM Berlin) -- C:\WINDOWS\System32\fwlanci.dll<br />
[2010.09.03 13:58:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\AVM_Driver<br />
[2010.08.20 14:27:55 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Helper<br />
[6 C:\WINDOWS\System32\*.tmp files -&gt; C:\WINDOWS\System32\*.tmp -&gt; ]<br />
[6 C:\WINDOWS\*.tmp files -&gt; C:\WINDOWS\*.tmp -&gt; ]<br />
[6 C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp files -&gt; C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp -&gt; ]<br />
<br />
========== Files - Modified Within 30 Days ==========<br />
<br />
[2010.09.07 20:55:54 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl<br />
[2010.09.07 20:55:14 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT<br />
[2010.09.07 20:55:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat<br />
[2010.09.07 20:55:05 | 000,069,112 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap<br />
[2010.09.07 20:53:07 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\Access.dat<br />
[2010.09.05 21:13:26 | 003,377,932 | -H-- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Lokale Einstellungen\Anwendungsdaten\IconCache.db<br />
[2010.09.05 19:13:28 | 004,218,880 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\ntuser.dat<br />
[2010.09.03 21:40:37 | 000,000,190 | -HS- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\ntuser.ini<br />
[2010.09.03 21:16:58 | 000,046,592 | ---- | M] () -- C:\WINDOWS\attrnsta.dll<br />
[2010.09.03 15:48:32 | 000,435,260 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat<br />
[2010.09.03 15:48:31 | 001,050,718 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI<br />
[2010.09.03 15:48:31 | 000,451,980 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat<br />
[2010.09.03 15:48:31 | 000,080,920 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat<br />
[2010.09.03 15:48:31 | 000,068,156 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat<br />
[2010.09.03 14:46:57 | 000,000,425 | ---- | M] () -- C:\WINDOWS\BRWMARK.INI<br />
[2010.08.11 17:22:27 | 001,556,576 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT<br />
[6 C:\WINDOWS\System32\*.tmp files -&gt; C:\WINDOWS\System32\*.tmp -&gt; ]<br />
[6 C:\WINDOWS\*.tmp files -&gt; C:\WINDOWS\*.tmp -&gt; ]<br />
[6 C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp files -&gt; C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp -&gt; ]<br />
<br />
========== Files Created - No Company Name ==========<br />
<br />
[2050.01.01 01:00:00 | 000,018,432 | ---- | C] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Eigene Dateien\RGF143433758.pdf<br />
[2050.01.01 01:00:00 | 000,002,033 | ---- | C] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Eigene Dateien\RGF143433758.pdf.pkcs7<br />
[2010.09.05 19:13:28 | 004,218,880 | ---- | C] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\ntuser.dat<br />
[2010.09.03 21:16:58 | 000,046,592 | ---- | C] () -- C:\WINDOWS\attrnsta.dll<br />
[2010.09.03 13:58:52 | 000,097,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\Fwusb1b.bin<br />
[2010.07.12 17:49:17 | 000,000,004 | ---- | C] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\avdrn.dat<br />
[2010.06.03 16:08:51 | 000,000,032 | ---- | C] () -- C:\WINDOWS\PacWorld.ini<br />
[2010.05.23 11:32:31 | 000,006,144 | ---- | C] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
[2010.03.03 15:50:24 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll<br />
[2010.01.10 16:53:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI<br />
[2009.12.27 13:17:07 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\$_hpcst$.hpc<br />
[2009.12.25 23:24:16 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LauncherAccess.dt<br />
[2009.12.25 23:22:25 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys<br />
[2009.12.08 21:44:25 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\drivers\SSHDRV65.sys<br />
[2009.08.12 11:37:52 | 000,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini<br />
[2009.06.07 14:18:32 | 010,440,704 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\sandra.mda<br />
[2009.05.05 15:22:31 | 000,031,664 | ---- | C] () -- C:\WINDOWS\maxlink.ini<br />
[2009.02.15 16:21:26 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\xrxscnui.dll<br />
[2009.01.01 21:39:29 | 000,000,425 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI<br />
[2009.01.01 21:39:29 | 000,000,027 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI<br />
[2008.12.20 21:18:46 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll<br />
[2008.10.07 09:13:30 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll<br />
[2008.10.07 09:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll<br />
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll<br />
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll<br />
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll<br />
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll<br />
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll<br />
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll<br />
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll<br />
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll<br />
[2008.09.18 00:55:00 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll<br />
[2008.09.18 00:55:00 | 001,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll<br />
[2008.09.18 00:55:00 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll<br />
[2008.09.18 00:55:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll<br />
[2008.09.18 00:55:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll<br />
[2002.07.31 18:32:03 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll<br />
<br />
========== LOP Check ==========<br />
<br />
[2009.06.06 12:08:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\2DBoy<br />
[2008.12.19 17:48:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET<br />
[2008.12.20 17:29:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ICQ<br />
[2009.05.16 16:17:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PopCap Games<br />
[2009.05.05 15:22:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ScanSoft<br />
[2010.09.05 16:20:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\tmp<br />
[2009.07.15 19:27:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tunngle<br />
[2009.07.07 15:15:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Braid<br />
[2010.06.11 15:30:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\DVDVideoSoftIEHelpers<br />
[2009.03.31 21:24:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\FOG Downloader<br />
[2008.12.20 16:58:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Foxit<br />
[2009.12.25 14:10:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\FreeDoko<br />
[2010.06.19 15:36:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\ICQ<br />
[2010.08.21 18:00:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\PriceGong<br />
[2009.12.26 00:08:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Samsung<br />
[2009.06.24 18:05:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\ScanSoft<br />
[2008.12.21 22:51:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\TeamViewer<br />
[2009.11.09 22:15:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Teeworlds<br />
[2010.01.24 23:02:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Tunngle<br />
[2009.06.08 15:49:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Uniblue<br />
[2009.02.15 16:21:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Xerox <br />
[2009.03.03 21:20:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Alozwy<br />
[2010.06.09 10:55:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Apiwe<br />
[2009.09.07 10:31:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Cuecta<br />
[2009.12.27 13:18:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant<br />
[2010.07.14 18:24:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Gumo<br />
[2010.07.21 19:14:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Gylat<br />
[2010.07.30 15:08:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ihgeit<br />
[2009.05.11 22:50:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Isiwc<br />
[2009.10.09 16:46:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ivwiuf<br />
[2010.07.15 17:48:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ivxyy<br />
[2010.07.19 18:39:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Kumios<br />
[2010.07.30 21:07:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ogeci<br />
[2009.01.12 17:24:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ogonu<br />
[2010.07.10 11:15:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Omquex<br />
[2009.06.14 22:17:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ovok<br />
[2009.07.05 18:41:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\ScanSoft<br />
[2010.07.30 13:07:43 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Tyowy<br />
[2010.05.14 02:52:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Umfux<br />
[2010.03.11 11:03:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Vapaxe<br />
[2010.07.30 13:07:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ydobf<br />
[2010.01.03 01:19:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Yftok<br />
[2009.12.13 15:56:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ylygd<br />
[2010.07.29 19:38:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Zakyi<br />
<br />
========== Purity Check ==========<br />
<br />
<br />
<br />
========== Custom Scans ==========<br />
<br />
<br />
&lt; %ALLUSERSPROFILE%\Application Data\*. &gt;<br />
<br />
&lt; %ALLUSERSPROFILE%\Application Data\*.exe /s &gt;<br />
<br />
&lt; %APPDATA%\*. &gt;<br />
[2010.07.07 18:41:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Adobe<br />
[2009.03.03 21:20:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Alozwy<br />
[2010.06.09 10:55:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Apiwe<br />
[2009.06.10 16:54:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\ATI<br />
[2010.05.23 23:17:03 | 000,000,000 | R--D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Brother<br />
[2009.09.07 10:31:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Cuecta<br />
[2010.07.03 11:48:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\DivX<br />
[2009.08.11 20:49:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\ESTsoft<br />
[2009.01.31 11:47:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Google<br />
[2009.12.27 13:18:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant<br />
[2010.07.14 18:24:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Gumo<br />
[2010.07.21 19:14:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Gylat<br />
[2010.08.20 14:27:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Helper<br />
[2008.12.19 19:22:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Identities<br />
[2010.07.30 15:08:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ihgeit<br />
[2009.05.11 22:50:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Isiwc<br />
[2009.10.09 16:46:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ivwiuf<br />
[2010.07.15 17:48:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ivxyy<br />
[2010.07.19 18:39:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Kumios<br />
[2008.12.19 19:49:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Macromedia<br />
[2009.12.27 13:30:32 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Microsoft<br />
[2008.12.19 19:23:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Mozilla<br />
[2010.07.30 21:07:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ogeci<br />
[2009.01.12 17:24:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ogonu<br />
[2010.07.10 11:15:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Omquex<br />
[2009.06.14 22:17:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ovok<br />
[2009.07.05 18:41:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\ScanSoft<br />
[2010.05.16 19:04:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Skype<br />
[2008.12.19 19:29:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Sun<br />
[2010.07.30 13:07:43 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Tyowy<br />
[2010.05.14 02:52:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Umfux<br />
[2010.03.11 11:03:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Vapaxe<br />
[2010.09.06 23:17:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\vlc<br />
[2010.07.30 13:07:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ydobf<br />
[2010.01.03 01:19:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Yftok<br />
[2009.12.13 15:56:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ylygd<br />
[2010.07.29 19:38:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Zakyi<br />
<br />
&lt; %APPDATA%\*.exe /s &gt;<br />
[2009.03.03 21:20:28 | 000,165,888 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Alozwy\etvic.exe<br />
[2010.06.09 10:55:50 | 000,159,744 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Apiwe\tuaf.exe<br />
[2009.12.27 13:57:42 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\23A0B03D-F42B-4A4D-A64C-C4E946585B5E\AutoRunCE.exe<br />
[2009.12.27 13:57:45 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\23A0B03D-F42B-4A4D-A64C-C4E946585B5E\1\module.exe<br />
[2009.12.27 13:58:37 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\339E641C-73A4-44D0-AD2B-816E368225DF\AutoRunCE.exe<br />
[2009.12.27 13:58:39 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\339E641C-73A4-44D0-AD2B-816E368225DF\1\module.exe<br />
[2009.12.27 13:58:16 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\3EEA5F55-83AB-4448-98E4-C364B6DFAEF7\AutoRunCE.exe<br />
[2009.12.27 13:58:17 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\3EEA5F55-83AB-4448-98E4-C364B6DFAEF7\1\module.exe<br />
[2009.12.27 13:58:23 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\4F0ACCE4-F7AE-4923-A9F4-81C028596E55\AutoRunCE.exe<br />
[2009.12.27 13:58:25 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\4F0ACCE4-F7AE-4923-A9F4-81C028596E55\1\module.exe<br />
[2009.12.27 13:58:45 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\6274F28B-F345-4BA9-B53C-3E2E3D25E442\AutoRunCE.exe<br />
[2009.12.27 13:58:46 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\6274F28B-F345-4BA9-B53C-3E2E3D25E442\1\module.exe<br />
[2009.12.27 13:57:56 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\7AF495BA-85AD-4187-B21F-E26B6897C748\AutoRunCE.exe<br />
[2009.12.27 13:57:59 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\7AF495BA-85AD-4187-B21F-E26B6897C748\1\module.exe<br />
[2009.12.27 13:57:48 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\8BBB19C3-9C60-44CB-8A5E-BC8BCB78AC5D\AutoRunCE.exe<br />
[2009.12.27 13:57:49 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\8BBB19C3-9C60-44CB-8A5E-BC8BCB78AC5D\1\module.exe<br />
[2009.12.27 13:58:07 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\92746DE9-F77D-43A9-BAB3-87E12605CE35\AutoRunCE.exe<br />
[2009.12.27 13:58:08 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\92746DE9-F77D-43A9-BAB3-87E12605CE35\1\module.exe<br />
[2009.12.27 13:57:51 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\98B5E998-AD01-4E0C-A3D9-CC949E946A49\AutoRunCE.exe<br />
[2009.12.27 13:57:53 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\98B5E998-AD01-4E0C-A3D9-CC949E946A49\1\module.exe<br />
[2009.12.27 13:58:28 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\9F7A79D6-3A06-4F78-90D0-FA897A4FD783\AutoRunCE.exe<br />
[2009.12.27 13:58:29 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\9F7A79D6-3A06-4F78-90D0-FA897A4FD783\1\module.exe<br />
[2009.12.27 13:58:41 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\A2922E09-96FC-489E-B230-2712FFE6FE11\AutoRunCE.exe<br />
[2009.12.27 13:58:43 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\A2922E09-96FC-489E-B230-2712FFE6FE11\1\module.exe<br />
[2009.12.27 13:56:34 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\A7287F0A-05FE-408C-AB9A-5FEF470567C1\AutoRunCE.exe<br />
[2009.12.27 13:57:21 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\A7287F0A-05FE-408C-AB9A-5FEF470567C1\1\module.exe<br />
[2009.12.27 13:57:38 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\AD8325DB-A2BE-4F60-A78D-AB1748B0D4FA\AutoRunCE.exe<br />
[2009.12.27 13:57:40 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\AD8325DB-A2BE-4F60-A78D-AB1748B0D4FA\1\module.exe<br />
[2009.12.27 13:58:11 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\B77505EF-1AFD-46B9-B08A-036EF94F9AF4\AutoRunCE.exe<br />
[2009.12.27 13:58:13 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\B77505EF-1AFD-46B9-B08A-036EF94F9AF4\1\module.exe<br />
[2009.12.27 13:57:33 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\C31A8510-F49E-4961-A54B-F33A1BD80AFF\AutoRunCE.exe<br />
[2009.12.27 13:57:36 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\C31A8510-F49E-4961-A54B-F33A1BD80AFF\1\module.exe<br />
[2009.12.27 13:57:30 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\D14E9445-4543-4301-8AE3-CC56BC8D443D\AutoRunCE.exe<br />
[2009.12.27 13:57:31 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\D14E9445-4543-4301-8AE3-CC56BC8D443D\1\module.exe<br />
[2009.12.27 13:58:31 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\E57937F2-41B4-4D3C-B65A-D4A66F85A852\AutoRunCE.exe<br />
[2009.12.27 13:58:33 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\E57937F2-41B4-4D3C-B65A-D4A66F85A852\1\module.exe<br />
[2009.12.27 13:58:04 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\F504E7FB-12D2-4F6E-94B7-01FBA1B1985E\AutoRunCE.exe<br />
[2009.12.27 13:58:05 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\F504E7FB-12D2-4F6E-94B7-01FBA1B1985E\1\module.exe<br />
[2009.12.27 13:58:19 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\FDDB8B34-B577-41FB-98B9-AAC9D2A5FA75\AutoRunCE.exe<br />
[2009.12.27 13:58:21 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\FDDB8B34-B577-41FB-98B9-AAC9D2A5FA75\1\module.exe<br />
[2009.10.26 06:00:00 | 000,005,632 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\Import\gpa_nsv78\Installation\AutoRunCE.exe<br />
[2009.10.26 06:00:00 | 000,083,456 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\GoPal Assistant\Library\Import\gpa_nsv78\Installation\1\module.exe<br />
[2009.05.11 22:50:12 | 000,159,744 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Isiwc\refe.exe<br />
[2009.01.12 17:24:10 | 000,176,640 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ogonu\yler.exe<br />
[2009.06.14 22:17:31 | 000,165,888 | ---- | M] () -- C:\Dokumente und Einstellungen\Stephan.ISABELLE\Anwendungsdaten\Ovok\siacs.exe<br />
<br />
&lt; %SYSTEMDRIVE%\*.exe &gt;<br />
<br />
<br />
&lt; MD5 for: AGP440.SYS &gt;<br />
[2007.07.27 14:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys<br />
[2009.01.31 13:20:16 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys<br />
[2009.01.31 13:20:16 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys<br />
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys<br />
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys<br />
<br />
&lt; MD5 for: ATAPI.SYS &gt;<br />
[2007.07.27 14:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys<br />
[2009.01.31 13:20:16 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys<br />
[2009.01.31 13:20:16 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys<br />
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys<br />
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys<br />
[2007.07.27 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys<br />
[2007.07.27 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\atapi.sys<br />
<br />
&lt; MD5 for: EVENTLOG.DLL &gt;<br />
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll<br />
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll<br />
[2007.07.27 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll<br />
<br />
&lt; MD5 for: NETLOGON.DLL &gt;<br />
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll<br />
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll<br />
[2007.07.27 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll<br />
<br />
&lt; MD5 for: NVATA.SYS &gt;<br />
[2006.08.14 14:51:28 | 000,105,344 | ---- | M] (NVIDIA Corporation) MD5=947C4A0E7B25BCECC3B40F0F1070378B -- C:\NVIDIA\nForceWinXP\11.09\MCP61\IDE\Win2K\sata_ide\nvata.sys<br />
[2006.08.14 14:51:28 | 000,105,344 | ---- | M] (NVIDIA Corporation) MD5=947C4A0E7B25BCECC3B40F0F1070378B -- C:\NVIDIA\nForceWinXP\11.09\MCP61\IDE\WinXP\sata_ide\nvata.sys<br />
[2006.08.14 14:51:28 | 000,105,344 | ---- | M] (NVIDIA Corporation) MD5=947C4A0E7B25BCECC3B40F0F1070378B -- C:\WINDOWS\system32\drivers\nvata.sys<br />
[2006.04.24 18:52:28 | 000,100,736 | ---- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 -- C:\NVIDIA\nForceWinXP\11.09\MCP51\IDE\Win2K\sata_ide\nvata.sys<br />
[2006.04.24 18:52:28 | 000,100,736 | ---- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 -- C:\NVIDIA\nForceWinXP\11.09\MCP51\IDE\WinXP\sata_ide\nvata.sys<br />
<br />
&lt; MD5 for: NVATABUS.SYS &gt;<br />
[2006.08.14 14:51:28 | 000,105,344 | ---- | M] (NVIDIA Corporation) MD5=947C4A0E7B25BCECC3B40F0F1070378B -- C:\NVIDIA\nForceWinXP\11.09\MCP61\IDE\Win2K\sataraid\nvatabus.sys<br />
[2006.08.14 14:51:28 | 000,105,344 | ---- | M] (NVIDIA Corporation) MD5=947C4A0E7B25BCECC3B40F0F1070378B -- C:\NVIDIA\nForceWinXP\11.09\MCP61\IDE\WinXP\sataraid\nvatabus.sys<br />
[2006.04.24 18:52:28 | 000,100,736 | ---- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 -- C:\NVIDIA\nForceWinXP\11.09\MCP51\IDE\Win2K\sataraid\nvatabus.sys<br />
[2006.04.24 18:52:28 | 000,100,736 | ---- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 -- C:\NVIDIA\nForceWinXP\11.09\MCP51\IDE\WinXP\sataraid\nvatabus.sys<br />
<br />
&lt; MD5 for: SCECLI.DLL &gt;<br />
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll<br />
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll<br />
[2007.07.27 14:00:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll<br />
<br />
&lt; MD5 for: USERINIT.EXE &gt;<br />
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe<br />
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe<br />
[2007.07.27 14:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe<br />
<br />
&lt; MD5 for: WS2IFSL.SYS &gt;<br />
[2007.07.27 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys<br />
[2007.07.27 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys<br />
<br />
&lt; %systemroot%\system32\drivers\*.sys /lockedfiles &gt;<br />
<br />
&lt; %systemroot%\System32\config\*.sav &gt;<br />
[2008.12.19 17:46:38 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav<br />
[2008.12.19 17:46:38 | 000,663,552 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav<br />
[2008.12.19 17:46:37 | 000,438,272 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav<br />
<br />
&lt; %systemroot%\*. /mp /s &gt;<br />
<br />
&lt; %systemroot%\system32\*.dll /lockedfiles &gt;<br />
[2008.12.01 22:52:52 | 000,425,984 | R--- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 -- C:\WINDOWS\system32\ATIDEMGX.dll<br />
[6 C:\WINDOWS\system32\*.tmp files -&gt; C:\WINDOWS\system32\*.tmp -&gt; ]<br />
&lt; End of report &gt;</code><hr />
</div>So...das müssten die beiden Reports sein, die OTL ausgespuckt hat...<br />
Ich hoffe, jemand hilft mir dabei, das Problem zu beseitigen...<br />
Danke jetzt schonmal^^</div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>Ambro</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90513-gefaehrliches-backdooprogramm-bds-papras-pk.html</guid>
		</item>
		<item>
			<title>Offen Facebook Virus über skype bekommen</title>
			<link>http://www.trojaner-board.de/90497-facebook-virus-ueber-skype-bekommen.html</link>
			<pubDate>Tue, 07 Sep 2010 13:41:21 GMT</pubDate>
			<description><![CDATA[facebook.exe virus 
  
  
Hallo! bin neu hier!  
dies ist mein erster beitrag. 
ich hab ein problem und zwar das hier: 
  
Habe letztens nen link über skype bekommen "Foto :D P******* w*w.facebook.exe" hieß die datei. 
habe sie runtergeladen und angeklickt, es stellte sich heraus, dass es ein virus...]]></description>
			<content:encoded><![CDATA[<div>facebook.exe virus<br />
 <br />
 <br />
Hallo! bin neu hier! <br />
dies ist mein erster beitrag.<br />
ich hab ein problem und zwar das hier:<br />
 <br />
Habe letztens nen link über skype bekommen &quot;Foto :D P******* w*w.facebook.exe&quot; hieß die datei.<br />
habe sie runtergeladen und angeklickt, es stellte sich heraus, dass es ein virus war.<br />
so. hab schon mit <a href=51130-anleitung-hijackthis.html>HijackThis</a> logfiles gemacht und ausgewertet, war aber alles sicher.<br />
dann hab ich mir mal die prozesse im task manager angeguckt und einen unbekannten beendet. es stellte sich heraus, dass dieser prozess so wie die datei hieß. hab dann auch mal nen blick in den autostart geworfen und auch dort einen &quot;NVIDIA DRIVER&quot; gelöscht. kann ja nicht sein, dass ich nen nvidia treiber hab, weil ich ja ne ATI grafikkarte hab.<br />
 <br />
1-3 tage war dann ruhe.<br />
letztens, als ich mit nem anderen ne videounterhaltung geführt habe, um ihm zu helfen, den gleichen virus zu löschen, kam dann kurze zeit später bei mir ne meldung von antivir, dass malware gefunden wurde.<br />
einmal in einem öffentlichen ordner und einmal auf der partition D.<br />
hab dann beide male auf &quot;entfernen&quot; geklickt.<br />
Ich bin mir aber jetzt nicht sicher, ob der virus wirklich verschwunden ist.<br />
vorher hatte ich ihn ja auch gelöscht und war mir sicher, er wäre weg.<br />
Mein Antivir und der Windows Defender finden nichts.<br />
Spybot hat ein problem mit dem internetexplorer festgestellt, hab aber behoben.<br />
 <br />
Mein PC hat aber keine probleme, d.h. er stürzt nicht ab, die festplatte knattert nur bei nem virenscan, sonst eigentlich nichts.<br />
Windows möchte ich aber nicht neu aufspielen, wenn das möglich ist.<br />
 <br />
Hier ist ein Logfile von mir:<br />
HiJackthis Logfile:<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">Logfile of Trend Micro <a href=51130-anleitung-hijackthis.html>HijackThis</a> v2.0.4<br />
Scan saved at 15:37:41, on 07.09.2010<br />
Platform: Windows 7 (WinNT 6.00.3504)<br />
MSIE: Internet Explorer v8.00 (8.00.7600.16385)<br />
Boot mode: Normal<br />
&nbsp;<br />
Running processes:<br />
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Program Files\ASUS\TurboV EVO\TurboV_EVO.exe<br />
C:\Program Files (x86)\avmwlanstick\WLanGUI.exe<br />
D:\Programme\Avira AntiVir\Avira\AntiVir Desktop\avgnt.exe<br />
D:\Programme\Skype\Phone\Skype.exe<br />
D:\Programme\Mozilla Firefox\firefox.exe<br />
D:\Programme\Mozilla Firefox\plugin-container.exe<br />
D:\HiJackThis204.exe<br />
C:\Windows\SysWOW64\DllHost.exe<br />
&nbsp;<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
F2 - REG:system.ini: UserInit=userinit.exe<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: CBAbzockschutz.InitToolbarBHO - {2e250b90-0e7a-42a3-9d65-e39f9f227fa4} - mscoree.dll (file missing)<br />
O2 - BHO: SBCONVERT - {3017FB3E-9A77-4396-88C5-0EC9548FB42F} - D:\Programme\Speedbit Video Downloader\SpeedBit Video Downloader\Toolbar\tbcore3.dll<br />
O2 - BHO: SearchPredictObj Class - {389943B0-C3A2-4E69-82CB-8596A84CB3DC} - C:\PROGRA~2\SEARCH~1\SEARCH~1.DLL<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: GrabberObj Class - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - D:\PROGRA~1\SPEEDB~1\SPEEDB~1\Toolbar\grabber.dll<br />
O3 - Toolbar: COMPUTERBILD-Abzockschutz - {353e2a48-6254-4bd3-88f4-3b51a0ca7870} - mscoree.dll (file missing)<br />
O3 - Toolbar: SpeedBit Video Downloader - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - D:\Programme\Speedbit Video Downloader\SpeedBit Video Downloader\Toolbar\tbcore3.dll<br />
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe<br />
O4 - HKLM\..\Run: [TurboV EVO] &quot;C:\Program Files\ASUS\TurboV EVO\TurboV_EVO.exe&quot; -b<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r<br />
O4 - HKLM\..\Run: [AVMWlanClient] C:\Program Files (x86)\avmwlanstick\wlangui.exe<br />
O4 - HKLM\..\Run: [avgnt] &quot;D:\Programme\Avira AntiVir\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATICAE.EXE /FU &quot;C:\Users\Internet\AppData\Local\Temp\E_S6C89.tmp&quot; /EF &quot;HKCU&quot;<br />
O8 - Extra context menu item: Nach Microsoft E&amp;xel exportieren - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: An OneNote s&amp;enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll<br />
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - D:\Programme\ICQ 7\ICQ7.1\ICQ.exe<br />
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - D:\Programme\ICQ 7\ICQ7.1\ICQ.exe<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL<br />
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Users\Internet\AppData\Roaming\ICQ\Application\ICQ7.1\ICQ.exe (HKCU)<br />
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Users\Internet\AppData\Roaming\ICQ\Application\ICQ7.1\ICQ.exe (HKCU)<br />
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - D:\Programme\Adobe Photoshop Elements 8.0\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe<br />
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br />
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)<br />
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - D:\Programme\Avira AntiVir\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Programme\Avira AntiVir\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe<br />
O23 - Service: AVM WLAN Connection Service - AVM Berlin - C:\Program Files (x86)\avmwlanstick\WlanNetService.exe<br />
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\ASUS.SYS\config\DVMExportService.exe<br />
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)<br />
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - Unknown owner - D:\Programme\Magix Grabber\Common\Database\bin\fbserver.exe (file missing)<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br />
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe<br />
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe<br />
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe<br />
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)<br />
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br />
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br />
&nbsp;<br />
--<br />
End of file - 9516 bytes</code><hr />
</div>--- --- ---<br />
 <br />
 <br />
Kann mir jemand helfen, den Virus, falls er noch da ist, zu löschen?<br />
 <br />
hab mal otl laufen lassen und hier sind die logs: könnt ihr mir denn erstmal sagen, ob ich überhaupt nen virus noch habe??<br />
 <br />
Log 1:OTL Logfile:<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">OTL Extras logfile created on: 07.09.2010 17:20:05 - Run 2<br />
OTL by OldTimer - Version 3.2.11.0&nbsp; &nbsp;  Folder = D:\<br />
64bit- Home Premium Edition&nbsp; (Version = 6.1.7600) - Type = NTWorkstation<br />
Internet Explorer (Version = 8.0.7600.16385)<br />
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy<br />
&nbsp;<br />
8,00 Gb Total Physical Memory | 5,00 Gb Available Physical Memory | 67,00% Memory free<br />
12,00 Gb Paging File | 9,00 Gb Available in Paging File | 78,00% Paging File free<br />
Paging file location(s): c:\pagefile.sys 4096 4096 [binary data]<br />
&nbsp;<br />
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)<br />
Drive C: | 97,66 Gb Total Space | 37,30 Gb Free Space | 38,20% Space Free | Partition Type: NTFS<br />
Drive D: | 1299,51 Gb Total Space | 1177,60 Gb Free Space | 90,62% Space Free | Partition Type: NTFS<br />
E: Drive not present or media not loaded<br />
F: Drive not present or media not loaded<br />
G: Drive not present or media not loaded<br />
H: Drive not present or media not loaded<br />
I: Drive not present or media not loaded<br />
&nbsp;<br />
Computer Name: **<br />
Current User Name: **<br />
Logged in as Administrator.<br />
&nbsp;<br />
Current Boot Mode: Normal<br />
Scan Mode: Current user<br />
Include 64bit Scans<br />
Company Name Whitelist: Off<br />
Skip Microsoft Files: Off<br />
File Age = 30 Days<br />
Output = Minimal<br />
&nbsp;<br />
<font color="#e56717">========== Extra Registry (SafeList) ==========</font><br />
&nbsp;<br />
&nbsp;<br />
<font color="#e56717">========== File Associations ==========</font><br />
&nbsp;<br />
<b>64bit:</b> [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\&lt;extension&gt;]<br />
.js[@ = JSFile] -- C:\Windows\SysWow64\CScript.exe (Microsoft Corporation)<br />
.jse[@ = JSEFile] -- C:\Windows\SysWow64\CScript.exe (Microsoft Corporation)<br />
.vbe[@ = VBEFile] -- C:\Windows\SysWow64\CScript.exe (Microsoft Corporation)<br />
.vbs[@ = VBSFile] -- C:\Windows\SysWow64\CScript.exe (Microsoft Corporation)<br />
.wsf[@ = WSFFile] -- C:\Windows\SysWow64\CScript.exe (Microsoft Corporation)<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\&lt;extension&gt;]<br />
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)<br />
.js [@ = JSFile] -- C:\Windows\SysWow64\CScript.exe (Microsoft Corporation)<br />
.jse [@ = JSEFile] -- C:\Windows\SysWow64\CScript.exe (Microsoft Corporation)<br />
.vbe [@ = VBEFile] -- C:\Windows\SysWow64\CScript.exe (Microsoft Corporation)<br />
.vbs [@ = VBSFile] -- C:\Windows\SysWow64\CScript.exe (Microsoft Corporation)<br />
.wsf [@ = WSFFile] -- C:\Windows\SysWow64\CScript.exe (Microsoft Corporation)<br />
&nbsp;<br />
[HKEY_CURRENT_USER\SOFTWARE\Classes\&lt;extension&gt;]<br />
.html [@ = FirefoxHTML] -- D:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)<br />
&nbsp;<br />
<font color="#e56717">========== Shell Spawning ==========</font><br />
&nbsp;<br />
<b>64bit:</b> [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\&lt;key&gt;\shell\[command]\command]<br />
batfile [open] -- &quot;%1&quot; %* File not found<br />
cmdfile [open] -- &quot;%1&quot; %* File not found<br />
comfile [open] -- &quot;%1&quot; %* File not found<br />
exefile [open] -- &quot;%1&quot; %* File not found<br />
helpfile [open] -- Reg Error: Key error.<br />
htmlfile [edit] -- &quot;D:\Programme\Microsoft Office Home and Student 2007\Office12\msohtmed.exe&quot; %1 (Microsoft Corporation)<br />
htmlfile [print] -- &quot;D:\Programme\Microsoft Office Home and Student 2007\Office12\msohtmed.exe&quot; /p %1 (Microsoft Corporation)<br />
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe &quot;%1&quot; (Microsoft Corporation)<br />
InternetShortcut [print] -- &quot;C:\Windows\System32\rundll32.exe&quot; &quot;C:\Windows\System32\mshtml.dll&quot;,PrintHTML &quot;%1&quot; (Microsoft Corporation)<br />
jsfile [open] -- %SystemRoot%\SysWow64\CScript.exe &quot;%1&quot; %* (Microsoft Corporation)<br />
jsefile [open] -- %SystemRoot%\SysWow64\CScript.exe &quot;%1&quot; %* (Microsoft Corporation)<br />
piffile [open] -- &quot;%1&quot; %* File not found<br />
regfile [merge] -- Reg Error: Key error.<br />
scrfile [config] -- &quot;%1&quot; File not found<br />
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)<br />
scrfile [open] -- &quot;%1&quot; /S File not found<br />
txtfile [edit] -- Reg Error: Key error.<br />
vbefile [open] -- %SystemRoot%\SysWow64\CScript.exe &quot;%1&quot; %* (Microsoft Corporation)<br />
vbsfile [open] -- %SystemRoot%\SysWow64\CScript.exe &quot;%1&quot; %* (Microsoft Corporation)<br />
wsffile [open] -- %SystemRoot%\SysWow64\CScript.exe &quot;%1&quot; %* (Microsoft Corporation)<br />
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found<br />
Directory [AddToPlaylistVLC] -- &quot;D:\Programme\VLC Media Player\VLC\vlc.exe&quot; --started-from-file --playlist-enqueue &quot;%1&quot; ()<br />
Directory [cmd] -- cmd.exe /s /k pushd &quot;%V&quot; (Microsoft Corporation)<br />
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
Directory [OneNote.Open] -- D:\PROGRA~1\MICROS~1\Office12\ONENOTE.EXE &quot;%L&quot; (Microsoft Corporation)<br />
Directory [PlayWithVLC] -- &quot;D:\Programme\VLC Media Player\VLC\vlc.exe&quot; --started-from-file --no-playlist-enqueue &quot;%1&quot; ()<br />
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
Folder [explore] -- Reg Error: Value error.<br />
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\&lt;key&gt;\shell\[command]\command]<br />
batfile [open] -- &quot;%1&quot; %*<br />
cmdfile [open] -- &quot;%1&quot; %*<br />
comfile [open] -- &quot;%1&quot; %*<br />
cplfile [cplopen] -- %SystemRoot%\System32\control.exe &quot;%1&quot;,%* (Microsoft Corporation)<br />
exefile [open] -- &quot;%1&quot; %*<br />
helpfile [open] -- Reg Error: Key error.<br />
htmlfile [edit] -- &quot;D:\Programme\Microsoft Office Home and Student 2007\Office12\msohtmed.exe&quot; %1 (Microsoft Corporation)<br />
htmlfile [print] -- &quot;D:\Programme\Microsoft Office Home and Student 2007\Office12\msohtmed.exe&quot; /p %1 (Microsoft Corporation)<br />
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe &quot;%1&quot; (Microsoft Corporation)<br />
InternetShortcut [print] -- &quot;C:\Windows\System32\rundll32.exe&quot; &quot;C:\Windows\System32\mshtml.dll&quot;,PrintHTML &quot;%1&quot; (Microsoft Corporation)<br />
jsfile [open] -- %SystemRoot%\SysWow64\CScript.exe &quot;%1&quot; %* (Microsoft Corporation)<br />
jsefile [open] -- %SystemRoot%\SysWow64\CScript.exe &quot;%1&quot; %* (Microsoft Corporation)<br />
piffile [open] -- &quot;%1&quot; %*<br />
regfile [merge] -- Reg Error: Key error.<br />
scrfile [config] -- &quot;%1&quot;<br />
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)<br />
scrfile [open] -- &quot;%1&quot; /S<br />
txtfile [edit] -- Reg Error: Key error.<br />
vbefile [open] -- %SystemRoot%\SysWow64\CScript.exe &quot;%1&quot; %* (Microsoft Corporation)<br />
vbsfile [open] -- %SystemRoot%\SysWow64\CScript.exe &quot;%1&quot; %* (Microsoft Corporation)<br />
wsffile [open] -- %SystemRoot%\SysWow64\CScript.exe &quot;%1&quot; %* (Microsoft Corporation)<br />
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1<br />
Directory [AddToPlaylistVLC] -- &quot;D:\Programme\VLC Media Player\VLC\vlc.exe&quot; --started-from-file --playlist-enqueue &quot;%1&quot; ()<br />
Directory [cmd] -- cmd.exe /s /k pushd &quot;%V&quot; (Microsoft Corporation)<br />
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
Directory [OneNote.Open] -- D:\PROGRA~1\MICROS~1\Office12\ONENOTE.EXE &quot;%L&quot; (Microsoft Corporation)<br />
Directory [PlayWithVLC] -- &quot;D:\Programme\VLC Media Player\VLC\vlc.exe&quot; --started-from-file --no-playlist-enqueue &quot;%1&quot; ()<br />
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
Folder [explore] -- Reg Error: Value error.<br />
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
&nbsp;<br />
<font color="#e56717">========== Security Center Settings ==========</font><br />
&nbsp;<br />
<b>64bit:</b> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]<br />
&quot;cval&quot; = 1<br />
&nbsp;<br />
<b>64bit:</b> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]<br />
&nbsp;<br />
<b>64bit:</b> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]<br />
&quot;VistaSp1&quot; = 28 4D B2 76 41 04 CA 01&nbsp; [binary data]<br />
&quot;AntiVirusOverride&quot; = 0<br />
&quot;AntiSpywareOverride&quot; = 0<br />
&quot;FirewallOverride&quot; = 0<br />
&nbsp;<br />
<b>64bit:</b> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]<br />
&quot;DisableNotifications&quot; = 0<br />
&quot;EnableFirewall&quot; = 1<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]<br />
&quot;DisableNotifications&quot; = 0<br />
&quot;EnableFirewall&quot; = 1<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]<br />
&quot;DisableNotifications&quot; = 0<br />
&quot;EnableFirewall&quot; = 1<br />
&nbsp;<br />
<font color="#e56717">========== Authorized Applications List ==========</font><br />
&nbsp;<br />
&nbsp;<br />
<font color="#e56717">========== HKEY_LOCAL_MACHINE Uninstall List ==========</font><br />
&nbsp;<br />
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]<br />
&quot;{071c9b48-7c32-4621-a0ac-3f809523288f}&quot; = Microsoft Visual C++ 2005 Redistributable (x64)<br />
&quot;{0E3DAF3D-FF69-345A-A99E-1FED304CA083}&quot; = Microsoft .NET Framework 4 Client Profile DEU Language Pack<br />
&quot;{19BDBFE9-0B6A-37F2-80F6-48AFD1EA582D}&quot; = ATI AVIVO64 Codecs<br />
&quot;{28A0318C-B98D-B6B1-64D1-4E4755A8E668}&quot; = AMD Drag and Drop Transcoding<br />
&quot;{295CFB7C-A57E-4313-93E7-68E7CE1D0332}&quot; = Adobe WinSoft Linguistics Plugin x64<br />
&quot;{2D74E972-5A85-44DC-9193-8A302BA8C181}&quot; = Photoshop Camera Raw_x64<br />
&quot;{350AA351-21FA-3270-8B7A-835434E766AD}&quot; = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022<br />
&quot;{38145F6E-041F-69AE-59B4-37CA06F33D67}&quot; = ccc-utility64<br />
&quot;{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}&quot; = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148<br />
&quot;{4D668D4F-FAA2-4726-834C-31F4614F312E}&quot; = MSVC80_x64_v2<br />
&quot;{6245BC35-F4BE-1995-BB2E-7847D758504E}&quot; = ATI Problem Report Wizard<br />
&quot;{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}&quot; = Adobe Fonts All x64<br />
&quot;{8875A1C0-6308-4790-8CF6-D34E89880052}&quot; = Adobe Linguistics CS4 x64<br />
&quot;{887797BF-37A5-4199-B0C9-0D38D6196E9A}&quot; = Adobe Anchor Service x64 CS4<br />
&quot;{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}&quot; = Adobe Type Support x64 CS4<br />
&quot;{8DAA31EB-6830-4006-A99F-4DF8AB24714F}&quot; = Adobe CSI CS4 x64<br />
&quot;{8E3FABF5-C3B9-7F7E-4AAE-977D77D48C51}&quot; = ATI Catalyst Install Manager<br />
&quot;{90120000-002A-0000-1000-0000000FF1CE}&quot; = Microsoft Office Office 64-bit Components 2007<br />
&quot;{90120000-002A-0407-1000-0000000FF1CE}&quot; = Microsoft Office Shared 64-bit MUI (German) 2007<br />
&quot;{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}&quot; = Intel® Matrix Storage Manager<br />
&quot;{90BA8112-80B3-4617-A3C1-BD2771B60F74}&quot; = Adobe CMaps x64 CS4<br />
&quot;{95120000-00B9-0409-1000-0000000FF1CE}&quot; = Microsoft Application Error Reporting<br />
&quot;{A3454894-144A-4D80-B605-C128FE0D7329}&quot; = Adobe Drive CS4 x64<br />
&quot;{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}&quot; = MSVC90_x64<br />
&quot;{B6E3757B-5E77-3915-866A-CCFC4B8D194C}&quot; = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053<br />
&quot;{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}&quot; = Adobe Photoshop CS4 (64 Bit)<br />
&quot;{DFFABE78-8173-4E97-9C5C-22FB26192FC5}&quot; = Adobe PDF Library Files x64 CS4<br />
&quot;{E6B7BD80-A921-4C72-A68B-44A9EB438BE4}&quot; = Microsoft IntelliType Pro 7.1<br />
&quot;{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}&quot; = Microsoft .NET Framework 4 Client Profile<br />
&quot;34EA302E7F4CBD17A19E33BBCB72363234956D7E&quot; = Windows-Treiberpaket - Nokia Modem&nbsp; (06/09/2010 4.5)<br />
&quot;EEEE705096F837B7907659F100C9FE6DA001970F&quot; = Windows-Treiberpaket - Nokia Modem&nbsp; (06/09/2010 7.01.0.7)<br />
&quot;EPSON Printer and Utilities&quot; = EPSON-Drucker-Software<br />
&quot;FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D&quot; = Windows-Treiberpaket - Nokia pccsmcfd&nbsp; (08/22/2008 7.0.0.0)<br />
&quot;Microsoft .NET Framework 4 Client Profile&quot; = Microsoft .NET Framework 4 Client Profile<br />
&quot;Microsoft .NET Framework 4 Client Profile DEU Language Pack&quot; = Microsoft .NET Framework 4 Client Profile DEU Language Pack<br />
&quot;Recuva&quot; = Recuva<br />
&nbsp;<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]<br />
&quot;{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}&quot; = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148<br />
&quot;{05308C4E-7285-4066-BAE3-6B50DA6ED755}&quot; = Adobe Update Manager CS4<br />
&quot;{089DD780-DB3F-4CDB-A0C2-111360247298}&quot; = PC Connectivity Solution<br />
&quot;{098727E1-775A-4450-B573-3F441F1CA243}&quot; = kuler<br />
&quot;{098A2A49-7CF3-4F08-A38D-FB879117152A}&quot; = Adobe Color NA Extra Settings CS4<br />
&quot;{0D6013AB-A0C7-41DC-973C-E93129C9A29F}&quot; = Adobe Color JA Extra Settings CS4<br />
&quot;{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}&quot; = Adobe Setup<br />
&quot;{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}&quot; = Adobe Color EU Recommended Settings CS4<br />
&quot;{0EA7F867-D362-2E76-77B8-9396B9245B66}&quot; = CCC Help Finnish<br />
&quot;{0F723FC1-7606-4867-866C-CE80AD292DAF}&quot; = Adobe CSI CS4<br />
&quot;{1618734A-3957-4ADD-8199-F973763109A8}&quot; = Adobe Anchor Service CS4<br />
&quot;{16CF7BB1-672E-BC9F-E5CE-5854112E2C35}&quot; = CCC Help Japanese<br />
&quot;{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}&quot; = AdobeColorCommonSetRGB<br />
&quot;{1700FEE9-EB3D-35C8-28ED-0BE7860BA710}&quot; = CCC Help Portuguese<br />
&quot;{17DFE37C-064E-4834-AD8F-A4B2B4DF68F8}&quot; = Adobe Photoshop Elements 8.0<br />
&quot;{190CCE82-4867-B16E-F96A-3F21A058ED9B}&quot; = CCC Help Korean<br />
&quot;{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}&quot; = Adobe AIR<br />
&quot;{1B9B5B3B-28E7-4E59-A80D-D670AA984514}&quot; = Nokia Connectivity Cable Driver<br />
&quot;{1DA8594C-2F14-4491-B155-2BF3A999622D}&quot; = Fire Department 2<br />
&quot;{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}&quot; = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148<br />
&quot;{20400dbd-e6db-45b8-9b6b-1dd7033818ec}&quot; = Nero InfoTool<br />
&quot;{205C6BDD-7B73-42DE-8505-9A093F35A238}&quot; = Windows Live-Uploadtool<br />
&quot;{20D4A895-748C-4D88-871C-FDB1695B0169}&quot; = Platform<br />
&quot;{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}&quot; = Nokia PC Suite<br />
&quot;{22B0E143-2B0B-435B-9F56-136A3D16065F}&quot; = No23 Recorder<br />
&quot;{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}&quot; = MSVCRT<br />
&quot;{2348b586-c9ae-46ce-936c-a68e9426e214}&quot; = Nero StartSmart Help<br />
&quot;{26A24AE4-039D-4CA4-87B4-2F83216020FF}&quot; = Java(TM) 6 Update 20<br />
&quot;{280E47E4-4EFB-D268-B042-F793EB2D8E4E}&quot; = CCC Help Italian<br />
&quot;{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}&quot; = QuickTime<br />
&quot;{2A7D1710-31EB-3B24-BF52-1755099CE2C0}&quot; = CCC Help Chinese Traditional<br />
&quot;{2BA722D1-48D1-406E-9123-8AE5431D63EF}&quot; = Windows Live Fotogalerie<br />
&quot;{2EC1A4D5-4217-4ABF-A783-3706EE405716}&quot; = Mashed<br />
&quot;{33cf58f5-48d8-4575-83d6-96f574e4d83a}&quot; = Nero DriveSpeed<br />
&quot;{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}&quot; = PDF Settings CS4<br />
&quot;{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}&quot; = JMicron JMB36X Driver<br />
&quot;{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}&quot; = Adobe XMP Panels CS4<br />
&quot;{3A6B7222-A439-1BBE-58DD-76D1B632EEA8}&quot; = CCC Help Turkish<br />
&quot;{3AC02D87-274C-BAE6-ACFA-B64B714A0083}&quot; = Catalyst Control Center Core Implementation<br />
&quot;{3BD633E0-4BF8-4499-9149-88F0767D449C}&quot; = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch<br />
&quot;{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}&quot; = Adobe Color - Photoshop Specific CS4<br />
&quot;{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}&quot; = Adobe WinSoft Linguistics Plugin<br />
&quot;{3EFEF049-23D4-4B46-8903-4592FEA51018}&quot; = Windows Live Movie Maker<br />
&quot;{3F7BBDE9-79B4-4E77-B878-7E6B36F3A766}&quot; = CCC Help French<br />
&quot;{411F3ABA-2AB5-4799-AA19-6ADF0A8F7424}&quot; = Adobe Setup<br />
&quot;{41E654A9-26D0-4EAC-854B-0FA824FFFABB}&quot; = Windows Live Messenger<br />
&quot;{43509E18-076E-40FE-AF38-CA5ED400A5A9}&quot; = Pixel Bender Toolkit<br />
&quot;{44E240EC-2224-4078-A88B-2CEE0D3016EF}&quot; = Adobe After Effects CS4 Presets<br />
&quot;{45D4F727-43B5-49CD-B474-B9866A8F4FB8}&quot; = Nokia Map Loader<br />
&quot;{45EC816C-0771-4C14-AE6D-72D1B578F4C8}&quot; = Adobe After Effects CS4<br />
&quot;{491D92A9-69CA-4EB4-81D3-0106F9337957}&quot; = TurboV EVO<br />
&quot;{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}&quot; = Adobe Service Manager Extension<br />
&quot;{4A03706F-666A-4037-7777-5F2748764D10}&quot; = Java Auto Updater<br />
&quot;{4E2FAB2F-9004-40D6-8BF8-DB2F2DA16DEC}&quot; = Crashday Patch#2<br />
&quot;{52B97218-98CB-4B8B-9283-D213C85E1AA4}&quot; = Windows Live Anmelde-Assistent<br />
&quot;{553255F3-78FD-40F1-A6F8-6882140265FE}&quot; = Apple Application Support<br />
&quot;{556ea39f-26b9-4c8e-9343-0117dd17b8e4}&quot; = Nero 9 Essentials<br />
&quot;{561968FD-56A1-49FD-9ED0-F55482C7C5BC}&quot; = Adobe Media Encoder CS4 Exporter<br />
&quot;{56C049BE-79E9-4502-BEA7-9754A3E60F9B}&quot; = neroxml<br />
&quot;{59E4543A-D49D-4489-B445-473D763C79AF}&quot; = Microsoft Games for Windows - LIVE Redistributable<br />
&quot;{5FC68772-6D56-41C6-9DF1-24E868198AE6}&quot; = Windows Live Call<br />
&quot;{605DDD7B-1521-423B-A654-E9A963573D82}&quot; = Catalyst Control Center Graphics Light<br />
&quot;{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}&quot; = Adobe Dynamiclink Support<br />
&quot;{63C24A08-70F3-4C8E-B9FB-9F21A903801D}&quot; = Adobe Color Video Profiles CS CS4<br />
&quot;{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}&quot; = Adobe Photoshop CS4 Support<br />
&quot;{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}&quot; = Adobe After Effects CS4 Third Party Content<br />
&quot;{68243FF8-83CA-466B-B2B8-9F99DA5479C4}&quot; = AdobeColorCommonSetCMYK<br />
&quot;{6956856F-B6B3-4BE0-BA0B-8F495BE32033}&quot; = Apple Software Update<br />
&quot;{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}&quot; = Windows Media Player Firefox Plugin<br />
&quot;{6CF37701-7E02-873F-9543-183116AC905C}&quot; = CCC Help Danish<br />
&quot;{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}&quot; = MSVC80_x86_v2<br />
&quot;{6F1891DD-CEFE-4349-CFB3-172ED6C94A18}&quot; = ccc-core-static<br />
&quot;{71BFC818-0CED-42D6-9C87-5142918957EE}&quot; = ICQ7.1<br />
&quot;{74292F90-895A-4FC6-A692-9641532B1B63}&quot; = ArcSoft TotalMedia 3.5<br />
&quot;{75CFBC87-1B8A-2DA8-4575-F50BD61E9368}&quot; = Catalyst Control Center Graphics Previews Vista<br />
&quot;{76618402-179D-4699-A66B-D351C59436BC}&quot; = Windows Live Sync<br />
&quot;{770657D0-A123-3C07-8E44-1C83EC895118}&quot; = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
&quot;{7748ac8c-18e3-43bb-959b-088faea16fb2}&quot; = Nero StartSmart<br />
&quot;{7829db6f-a066-4e40-8912-cb07887c20bb}&quot; = Nero BurnRights<br />
&quot;{7A587AD7-EDEF-BD63-C054-5E5FBC47105C}&quot; = CCC Help Russian<br />
&quot;{8186FF34-D389-4B7E-9A2F-C197585BCFBD}&quot; = Adobe Media Encoder CS4 Importer<br />
&quot;{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}&quot; = Adobe Type Support CS4<br />
&quot;{82130914-DF2E-4AD3-BC73-5DC2A180924C}&quot; = CCC Help Thai<br />
&quot;{837b34e3-7c30-493c-8f6a-2b0f04e2912c}&quot; = Microsoft Visual C++ 2005 Redistributable<br />
&quot;{83877DB1-8B77-45BC-AB43-2BAC22E093E0}&quot; = Adobe Bridge CS4<br />
&quot;{842B4B72-9E8F-4962-B3C1-1C422A5C4434}&quot; = Suite Shared Configuration CS4<br />
&quot;{869200db-287a-4dc0-b02b-2b6787fbcd4c}&quot; = Nero DiscSpeed<br />
&quot;{8833FFB6-5B0C-4764-81AA-06DFEED9A476}&quot; = Realtek 8136 8168 8169 Ethernet Driver<br />
&quot;{88F066D3-5662-95C4-AE4E-D39174ED8F43}&quot; = CCC Help Dutch<br />
&quot;{896B238F-7CFE-4952-82EB-96E63E8E67B6}&quot; = COMPUTERBILD-Abzockschutz<br />
&quot;{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}&quot; = Microsoft Silverlight<br />
&quot;{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}&quot; = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch<br />
&quot;{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}&quot; = The Lord of the Rings FREE Trial <br />
&quot;{90120000-0016-0407-0000-0000000FF1CE}&quot; = Microsoft Office Excel MUI (German) 2007<br />
&quot;{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-0018-0407-0000-0000000FF1CE}&quot; = Microsoft Office PowerPoint MUI (German) 2007<br />
&quot;{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-001B-0407-0000-0000000FF1CE}&quot; = Microsoft Office Word MUI (German) 2007<br />
&quot;{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-001F-0407-0000-0000000FF1CE}&quot; = Microsoft Office Proof (German) 2007<br />
&quot;{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}&quot; = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-001F-0409-0000-0000000FF1CE}&quot; = Microsoft Office Proof (English) 2007<br />
&quot;{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}&quot; = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-001F-040C-0000-0000000FF1CE}&quot; = Microsoft Office Proof (French) 2007<br />
&quot;{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}&quot; = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-001F-0410-0000-0000000FF1CE}&quot; = Microsoft Office Proof (Italian) 2007<br />
&quot;{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}&quot; = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-002A-0407-1000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-002C-0407-0000-0000000FF1CE}&quot; = Microsoft Office Proofing (German) 2007<br />
&quot;{90120000-006E-0407-0000-0000000FF1CE}&quot; = Microsoft Office Shared MUI (German) 2007<br />
&quot;{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{90120000-00A1-0407-0000-0000000FF1CE}&quot; = Microsoft Office OneNote MUI (German) 2007<br />
&quot;{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{91120000-002F-0000-0000-0000000FF1CE}&quot; = Microsoft Office Home and Student 2007<br />
&quot;{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}&quot; = Microsoft Office 2007 Service Pack 2 (SP2)<br />
&quot;{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}&quot; = Security Update for Microsoft Office system 2007 (972581)<br />
&quot;{931AB7EA-3656-4BB7-864D-022B09E3DD67}&quot; = Adobe Linguistics CS4<br />
&quot;{931C37FC-594D-43A9-B10F-A2F2B1F03498}&quot; = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch<br />
&quot;{94D398EB-D2FD-4FD1-B8C4-592635E8A191}&quot; = Adobe CMaps CS4<br />
&quot;{99AD9D6D-A456-49EE-8360-F22EE7AA1272}&quot; = Express Gate<br />
&quot;{9A200E68-D5F4-4E70-910F-2871753A0E2B}&quot; = Worms World Party<br />
&quot;{9A25302D-30C0-39D9-BD6F-21E6EC160475}&quot; = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
&quot;{9C27ADE1-EAFB-4BB7-9FE3-5DD9BA9A3DD2}&quot; = Crashday<br />
&quot;{9C49AB5C-A457-DEF0-0436-AADEB2062296}&quot; = Catalyst Control Center Graphics Previews Common<br />
&quot;{9DFC3864-1C52-E552-B039-09AE59F35801}&quot; = CCC Help Swedish<br />
&quot;{A43C0289-EE84-FEC7-595D-A6F8489B2C44}&quot; = CCC Help Polish<br />
&quot;{A77B5C97-77AD-54E9-FB97-52F0A9EF72AC}&quot; = CCC Help Spanish<br />
&quot;{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}&quot; = Google Update Helper<br />
&quot;{AA2E2EA3-D999-D8A0-7C6F-DF451DF9135C}&quot; = CCC Help Greek<br />
&quot;{AC76BA86-7AD7-1031-7B44-A93000000001}&quot; = Adobe Reader 9.3.3 - Deutsch<br />
&quot;{AF111648-99A1-453E-81DD-80DBBF6DAD0D}&quot; = MSVC90_x86<br />
&quot;{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}&quot; = Adobe MotionPicture Color Files CS4<br />
&quot;{B08201F3-AE80-58C6-E832-7DF5B87795FB}&quot; = CCC Help Hungarian<br />
&quot;{B15381DD-FF97-4FCD-A881-ED4DB0975500}&quot; = Adobe Color Video Profiles AE CS4<br />
&quot;{B29AD377-CC12-490A-A480-1452337C618D}&quot; = Connect<br />
&quot;{b2ec4a38-b545-4a00-8214-13fe0e915e6d}&quot; = Advertising Center<br />
&quot;{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1&quot; = Spybot - Search &amp; Destroy<br />
&quot;{B569ACCD-8F95-53CE-AF51-70CB8EA34656}&quot; = CCC Help German<br />
&quot;{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}&quot; = Adobe Photoshop CS4<br />
&quot;{B9BDD486-EF12-B0BC-1C88-B3046092A8BD}&quot; = CCC Help Chinese Standard<br />
&quot;{BB4E33EC-8181-4685-96F7-8554293DEC6A}&quot; = Adobe Output Module<br />
&quot;{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}&quot; = Nero ControlCenter<br />
&quot;{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}&quot; = Adobe Media Encoder CS4 Additional Exporter<br />
&quot;{C3C44248-B8F7-4B20-A5C7-994870B60F55}&quot; = Hercules Webcam Station Evolution SE<br />
&quot;{C52E3EC1-048C-45E1-8D53-10B0C6509683}&quot; = Adobe Default Language CS4<br />
&quot;{C54AE051-35E6-A421-164B-FDF2C3A8EE4E}&quot; = Catalyst Control Center Graphics Full Existing<br />
&quot;{CA5290FD-1C71-D40D-E0B9-D44FF41007FA}&quot; = Catalyst Control Center HydraVision Full<br />
&quot;{cc019e3f-59d2-4486-8d4b-878105b62a71}&quot; = Nero DiscSpeed<br />
&quot;{CC75AB5C-2110-4A7F-AF52-708680D22FE8}&quot; = Photoshop Camera Raw<br />
&quot;{CED2C398-A03E-A70D-6894-78C79C501296}&quot; = CCC Help Czech<br />
&quot;{CF929EEB-CE39-4F06-B1BF-F51FC617A2B2}&quot; = Catalyst Control Center - Branding<br />
&quot;{D103C4BA-F905-437A-8049-DB24763BBE36}&quot; = Skype™ 4.2<br />
&quot;{D3CF1241-B6B9-C0F1-8D69-96A01360A07A}&quot; = Catalyst Control Center Graphics Full New<br />
&quot;{D7410A39-66CA-C554-CB1D-EB53A6B8A289}&quot; = HydraVision<br />
&quot;{dba84796-8503-4ff0-af57-1747dd9a166d}&quot; = Nero Online Upgrade<br />
&quot;{DD7851B2-C277-204C-C414-797649FBFCAA}&quot; = CCC Help English<br />
&quot;{DDBB7C89-1A09-441E-AA0F-6AA465755C17}&quot; = REALTEK DTV USB DEVICE<br />
&quot;{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}&quot; = Adobe Media Encoder CS4<br />
&quot;{E4848436-0345-47E2-B648-8B522FCDA623}&quot; = Adobe Photoshop CS4<br />
&quot;{E4F4CB1F-5319-EECB-F758-A651DAF87D02}&quot; = Catalyst Control Center Localization All<br />
&quot;{e5c7d048-f9b4-4219-b323-8bdb01a2563d}&quot; = Nero DriveSpeed<br />
&quot;{e8a80433-302b-4ff1-815d-fcc8eac482ff}&quot; = Nero Installer<br />
&quot;{ED00D08A-3C5F-488D-93A0-A04F21F23956}&quot; = Windows Live Communications Platform<br />
&quot;{EF0D610C-92BE-4D8F-BD33-9F658F8754F1}&quot; = GTI Racing<br />
&quot;{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}&quot; = Microsoft SQL Server 2005 Compact Edition [ENU]<br />
&quot;{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}&quot; = Microsoft Choice Guard<br />
&quot;{F0E64E2E-3A60-40D8-A55D-92F6831875DA}&quot; = Adobe Search for Help<br />
&quot;{F175273F-6F15-23E2-1DF9-D2A8DD477502}&quot; = CCC Help Norwegian<br />
&quot;{f4041dce-3fe1-4e18-8a9e-9de65231ee36}&quot; = Nero ControlCenter<br />
&quot;{f6bdd7c5-89ed-4569-9318-469aa9732572}&quot; = Nero BurnRights<br />
&quot;{F7338FA3-DAB5-49B2-900D-0AFB5760C166}&quot; = PC Probe II<br />
&quot;{F7B0939E-58DF-11DF-B3A6-005056806466}&quot; = Google Earth<br />
&quot;{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}&quot; = Adobe ExtendScript Toolkit CS4<br />
&quot;{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}&quot; = Windows Live Essentials<br />
&quot;{F93C84A6-0DC6-42AF-89FA-776F7C377353}&quot; = Adobe PDF Library Files CS4<br />
&quot;{fbcdfd61-7dcf-4e71-9226-873ba0053139}&quot; = Nero InfoTool<br />
&quot;{FC87BEA8-5582-476C-A754-41F3A9D976D4}&quot; = FSCTV<br />
&quot;{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}&quot; = Adobe Fonts All<br />
&quot;Adobe AIR&quot; = Adobe AIR<br />
&quot;Adobe Flash Player ActiveX&quot; = Adobe Flash Player 10 ActiveX<br />
&quot;Adobe Flash Player Plugin&quot; = Adobe Flash Player 10 Plugin<br />
&quot;Adobe Photoshop Elements 8.0&quot; = Adobe Photoshop Elements 8.0<br />
&quot;Adobe_3dcb365ab9e01871fb8c6f27b0ea079&quot; = Adobe After Effects CS4<br />
&quot;Adobe_faf656ef605427ee2f42989c3ad31b8&quot; = Adobe Photoshop CS4<br />
&quot;Adventskalender&quot; = Interaktiver Adventskalender<br />
&quot;Avira AntiVir Desktop&quot; = Avira AntiVir Personal - Free Antivirus<br />
&quot;AVMWLANCLI&quot; = AVM FRITZ!WLAN<br />
&quot;BurningWheels&quot; = Cobra 11 - Burning Wheels (remove only)<br />
&quot;CCleaner&quot; = CCleaner<br />
&quot;Cinergy T Stick Black&quot; = Cinergy T Stick Black V86.001.0824.2009<br />
&quot;EPSON Scanner&quot; = EPSON Scan<br />
&quot;Firebird SQL Server D&quot; = Firebird SQL Server - MAGIX Edition<br />
&quot;FMSLogo&quot; = FMSLogo<br />
&quot;FormatFactory&quot; = FormatFactory 2.30<br />
&quot;Hamachi&quot; = Hamachi 1.0.1.5<br />
&quot;HighwayNights&quot; = Cobra 11 - Highway Nights (remove only)<br />
&quot;HOMESTUDENTR&quot; = Microsoft Office Home and Student 2007<br />
&quot;HyperCam 2&quot; = HyperCam 2<br />
&quot;InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}&quot; = VIA Plattform-Geräte-Manager<br />
&quot;InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}&quot; = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch<br />
&quot;InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}&quot; = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch<br />
&quot;InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}&quot; = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch<br />
&quot;InstallShield_{EF0D610C-92BE-4D8F-BD33-9F658F8754F1}&quot; = GTI Racing<br />
&quot;InstallShield_{FC87BEA8-5582-476C-A754-41F3A9D976D4}&quot; = FSCTV<br />
&quot;MAGIX Filme auf DVD TerraTec Edition D&quot; = MAGIX Filme auf DVD TerraTec Edition 7.0.3.6 (D)<br />
&quot;Malwarebytes' Anti-Malware_is1&quot; = Malwarebytes' Anti-Malware<br />
&quot;Mozilla Firefox (3.6.3)&quot; = Mozilla Firefox (3.6.3)<br />
&quot;Nokia Maps Updater_is1&quot; = Nokia Maps Updater 1.0.12<br />
&quot;Nokia PC Suite&quot; = Nokia PC Suite<br />
&quot;ProtectDisc Driver 11&quot; = ProtectDisc Driver, Version 11<br />
&quot;Revo Uninstaller&quot; = Revo Uninstaller 1.89<br />
&quot;Slim Mobile USB DVB-T&quot; = Slim Mobile USB DVB-T 1.0.64.29<br />
&quot;SpeedBit Video Downloader&quot; = SpeedBit Video Downloader<br />
&quot;Stellarium_is1&quot; = Stellarium 0.10.3<br />
&quot;TerraTec Grabby&quot; = TerraTec Grabby V5.09.0813.00<br />
&quot;TmNationsForever_is1&quot; = TmNationsForever<br />
&quot;Tunatic&quot; = Tunatic<br />
&quot;VideoReDo TVSuite V4 w/H.264_is1&quot; = VideoReDo TVSuite Version 4.20.5.600<br />
&quot;VLC media player&quot; = VLC media player 1.1.0<br />
&quot;Window Hide Tool_is1&quot; = Window Hide Tool 2.0<br />
&quot;WinLiveSuite_Wave3&quot; = Windows Live Essentials<br />
&quot;WinRAR archiver&quot; = WinRAR<br />
&nbsp;<br />
<font color="#e56717">========== Last 10 Event Log Errors ==========</font><br />
&nbsp;<br />
[ Application Events ]<br />
Error - 03.08.2010 14:10:47 | Computer Name = ANTEC-PC1 | Source = Application Error | ID = 1000<br />
Description = Name der fehlerhaften Anwendung: HighwayNightsHi.exe, Version: 1.0.0.0,<br />
&nbsp;Zeitstempel: 0x4add4ed8&nbsp; Name des fehlerhaften Moduls: HighwayNightsHi.exe, Version:<br />
&nbsp;1.0.0.0, Zeitstempel: 0x4add4ed8&nbsp; Ausnahmecode: 0xc0000005&nbsp; Fehleroffset: 0x00071da0<br />
ID<br />
&nbsp;des fehlerhaften Prozesses: 0x17d4&nbsp; Startzeit der fehlerhaften Anwendung: 0x01cb33372ca739c2<br />
Pfad<br />
&nbsp;der fehlerhaften Anwendung: D:\Spiele\Alarm für Cobra 11 - Highway Nights\HighwayNightsHi.exe<br />
Pfad<br />
&nbsp;des fehlerhaften Moduls: D:\Spiele\Alarm für Cobra 11 - Highway Nights\HighwayNightsHi.exe<br />
Berichtskennung:<br />
&nbsp;70013c35-9f2a-11df-9db0-001f3f0c33d1<br />
&nbsp;<br />
Error - 03.08.2010 14:25:40 | Computer Name = ** | Source = EventSystem | ID = 4622<br />
Description = <br />
&nbsp;<br />
Error - 04.08.2010 06:19:51 | Computer Name = ** | Source = Application Error | ID = 1000<br />
Description = Name der fehlerhaften Anwendung: setupstb.exe, Version: 0.0.0.0, Zeitstempel:<br />
&nbsp;0x4af0e7cd&nbsp; Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7600.16559, Zeitstempel:<br />
&nbsp;0x4ba9b29c&nbsp; Ausnahmecode: 0xc0000006&nbsp; Fehleroffset: 0x00058563&nbsp; ID des fehlerhaften Prozesses:<br />
&nbsp;0x10c8&nbsp; Startzeit der fehlerhaften Anwendung: 0x01cb33be49d12d4c&nbsp; Pfad der fehlerhaften<br />
&nbsp;Anwendung: E:\setupstb.exe&nbsp; Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll<br />
Berichtskennung:<br />
&nbsp;d08f9fbd-9fb1-11df-ad9b-d2a0197c7f83<br />
&nbsp;<br />
Error - 04.08.2010 06:19:51 | Computer Name = ** | Source = Application Error | ID = 1005<br />
Description = Aus einem der folgenden Gründe kann nicht auf die Datei &quot;&quot; zugegriffen<br />
&nbsp;werden:&nbsp; Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger mit der<br />
&nbsp;gespeicherten Datei bzw. den auf dem Computer installierten&nbsp; Speichertreibern, oder<br />
&nbsp;der Datenträger fehlt.&nbsp; Das Programm setupstb.exe wurde wegen dieses Fehlers geschlossen.<br />
&nbsp;<br />
Programm:<br />
&nbsp;setupstb.exe&nbsp; Datei:&nbsp; &nbsp;  Der Fehlerwert ist im Abschnitt &quot;Zusätzliche Dateien&quot; aufgelistet.<br />
Benutzeraktion<br />
1.<br />
&nbsp;Öffnen Sie die Datei erneut.&nbsp; Diese Situation ist eventuell ein temporäres Problem,<br />
&nbsp;das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird.&nbsp; 2.&nbsp; Wenn<br />
&nbsp;Sie weiterhin nicht auf die Datei zugreifen können und&nbsp;  - diese sich im Netzwerk <br />
befindet,&nbsp;  dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem<br />
&nbsp;besteht und dass eine Verbindung mit dem Server hergestellt werden kann.&nbsp;  - diese<br />
&nbsp;sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet,<br />
&nbsp;überprüfen Sie, ob der Datenträger richtig in den Computer eingelegt ist.&nbsp; 3. Überprüfen<br />
&nbsp;und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu<br />
&nbsp;im Menü &quot;Start&quot; auf &quot;Ausführen&quot;, geben Sie CMD ein, und klicken Sie auf &quot;OK&quot;. Geben<br />
&nbsp;Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE.<br />
4.<br />
&nbsp;Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin<br />
&nbsp;besteht.&nbsp; 5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet<br />
&nbsp;werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt.<br />
&nbsp;  Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware, <br />
um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt.&nbsp; &nbsp; Zusätzliche<br />
&nbsp;Daten&nbsp; Fehlerwert: C0000013&nbsp; Datenträgertyp: 0<br />
&nbsp;<br />
Error - 04.08.2010 08:08:34 | Computer Name = ** | Source = Application Error | ID = 1000<br />
Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 8.0.7600.16385,<br />
&nbsp;Zeitstempel: 0x4a5bc69e&nbsp; Name des fehlerhaften Moduls: SEARCH~1.DLL_unloaded, Version:<br />
&nbsp;0.0.0.0, Zeitstempel: 0x4bc59369&nbsp; Ausnahmecode: 0xc0000005&nbsp; Fehleroffset: 0x3599aa50<br />
ID<br />
&nbsp;des fehlerhaften Prozesses: 0x1108&nbsp; Startzeit der fehlerhaften Anwendung: 0x01cb33cdb476f603<br />
Pfad<br />
&nbsp;der fehlerhaften Anwendung: C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
Pfad<br />
&nbsp;des fehlerhaften Moduls: SEARCH~1.DLL&nbsp; Berichtskennung: 00932649-9fc1-11df-ae2d-001f3f0c33d1<br />
&nbsp;<br />
Error - 04.08.2010 09:03:58 | Computer Name = * | Source = Application Error | ID = 1000<br />
Description = Name der fehlerhaften Anwendung: Fire.exe, Version: 0.0.0.0, Zeitstempel:<br />
&nbsp;0x41b82995&nbsp; Name des fehlerhaften Moduls: Fire.exe, Version: 0.0.0.0, Zeitstempel:<br />
&nbsp;0x41b82995&nbsp; Ausnahmecode: 0xc0000005&nbsp; Fehleroffset: 0x00106440&nbsp; ID des fehlerhaften Prozesses:<br />
&nbsp;0x11e0&nbsp; Startzeit der fehlerhaften Anwendung: 0x01cb33d57c27dfc2&nbsp; Pfad der fehlerhaften<br />
&nbsp;Anwendung: D:\Spiele\Fire Department 2\Fire.exe&nbsp; Pfad des fehlerhaften Moduls: D:\Spiele\Fire<br />
&nbsp;Department 2\Fire.exe&nbsp; Berichtskennung: be3cee01-9fc8-11df-ae2d-001f3f0c33d1<br />
&nbsp;<br />
Error - 05.08.2010 17:00:05 | Computer Name =** | Source = Google Update | ID = 20<br />
Description = <br />
&nbsp;<br />
Error - 05.08.2010 18:00:05 | Computer Name = ** | Source = Google Update | ID = 20<br />
Description = <br />
&nbsp;<br />
Error - 06.08.2010 15:54:52 | Computer Name = ** | Source = EventSystem | ID = 4621<br />
Description = <br />
&nbsp;<br />
Error - 06.08.2010 17:00:05 | Computer Name = ** | Source = Google Update | ID = 20<br />
Description = <br />
&nbsp;<br />
[ OSession Events ]<br />
Error - 14.06.2010 14:05:10 | Computer Name = ** | Source = Microsoft Office 12 Sessions | ID = 7001<br />
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application <br />
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session <br />
lasted 92870 seconds with 300 seconds of active time.&nbsp; This session ended with a<br />
&nbsp;crash.<br />
&nbsp;<br />
[ System Events ]<br />
Error - 06.09.2010 08:47:41 | Computer Name = ** | Source = Disk | ID = 262155<br />
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden.<br />
&nbsp;<br />
Error - 06.09.2010 08:47:41 | Computer Name = ** | Source = Disk | ID = 262155<br />
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden.<br />
&nbsp;<br />
Error - 06.09.2010 08:47:42 | Computer Name = ** | Source = Disk | ID = 262155<br />
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden.<br />
&nbsp;<br />
Error - 06.09.2010 08:47:42 | Computer Name = ANTEC-PC1 | Source = Disk | ID = 262155<br />
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden.<br />
&nbsp;<br />
Error - 06.09.2010 08:47:43 | Computer Name = ** | Source = Disk | ID = 262155<br />
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden.<br />
&nbsp;<br />
Error - 06.09.2010 13:30:04 | Computer Name = ** | Source = Disk | ID = 262155<br />
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden.<br />
&nbsp;<br />
Error - 06.09.2010 13:35:45 | Computer Name = ** | Source = volsnap | ID = 393241<br />
Description = Die Schattenkopien von Volume &quot;M:&quot; wurden gelöscht, weil der Schattenkopiespeicher<br />
&nbsp;nicht rechtzeitig vergrößert wurde. Sie sollten die E/A-Last auf dem System verringern<br />
&nbsp;oder ein Schattenkopie-Speichervolume, von dem keine Schattenkopie erstellt wird,<br />
&nbsp;auswählen.<br />
&nbsp;<br />
Error - 06.09.2010 15:25:11 | Computer Name = ** | Source = Disk | ID = 262155<br />
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR5 gefunden.<br />
&nbsp;<br />
Error - 07.09.2010 07:45:54 | Computer Name = ** | Source = Service Control Manager | ID = 7031<br />
Description = Der Dienst &quot;Microsoft Antimalware Service&quot; wurde unerwartet beendet.<br />
&nbsp;Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 15000<br />
&nbsp;Millisekunden durchgeführt: Neustart des Diensts.<br />
&nbsp;<br />
Error - 07.09.2010 07:46:09 | Computer Name = ** | Source = Service Control Manager | ID = 7032<br />
Description = Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden<br />
&nbsp;des Dienstes &quot;Microsoft Antimalware Service&quot; Korrekturmaßnahmen (Neustart des Diensts)<br />
&nbsp;durchzuführen, ist fehlgeschlagen. Fehler:&nbsp;  %%1056<br />
&nbsp;<br />
&nbsp;<br />
&lt; End of report &gt;</code><hr />
</div>--- --- ---<br />
OTL Logfile:<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">OTL logfile created on: 07.09.2010 17:20:05 - Run 2<br />
OTL by OldTimer - Version 3.2.11.0&nbsp; &nbsp;  Folder = D:\<br />
64bit- Home Premium Edition&nbsp; (Version = 6.1.7600) - Type = NTWorkstation<br />
Internet Explorer (Version = 8.0.7600.16385)<br />
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy<br />
&nbsp;<br />
8,00 Gb Total Physical Memory | 5,00 Gb Available Physical Memory | 67,00% Memory free<br />
12,00 Gb Paging File | 9,00 Gb Available in Paging File | 78,00% Paging File free<br />
Paging file location(s): c:\pagefile.sys 4096 4096 [binary data]<br />
&nbsp;<br />
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)<br />
Drive C: | 97,66 Gb Total Space | 37,30 Gb Free Space | 38,20% Space Free | Partition Type: NTFS<br />
Drive D: | 1299,51 Gb Total Space | 1177,60 Gb Free Space | 90,62% Space Free | Partition Type: NTFS<br />
E: Drive not present or media not loaded<br />
F: Drive not present or media not loaded<br />
G: Drive not present or media not loaded<br />
H: Drive not present or media not loaded<br />
I: Drive not present or media not loaded<br />
&nbsp;<br />
Computer Name: **<br />
Current User Name: **<br />
Logged in as Administrator.<br />
&nbsp;<br />
Current Boot Mode: Normal<br />
Scan Mode: Current user<br />
Include 64bit Scans<br />
Company Name Whitelist: Off<br />
Skip Microsoft Files: Off<br />
File Age = 30 Days<br />
Output = Minimal<br />
&nbsp;<br />
<font color="#e56717">========== Processes (SafeList) ==========</font><br />
&nbsp;<br />
PRC - D:\<a href=85104-otl-otlogfile-oldtimer.html>OTL.exe</a> (OldTimer Tools)<br />
PRC - D:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)<br />
PRC - C:\Windows\SysWOW64\PnkBstrB.exe ()<br />
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()<br />
PRC - D:\0000000\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)<br />
PRC - D:\Programme\Avira AntiVir\Avira\AntiVir Desktop\avscan.exe (Avira GmbH)<br />
PRC - D:\Programme\Avira AntiVir\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)<br />
PRC - D:\Programme\Avira AntiVir\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)<br />
PRC - D:\Programme\Avira AntiVir\Avira\AntiVir Desktop\sched.exe (Avira GmbH)<br />
PRC - C:\Program Files (x86)\ASUS\AASP\1.01.02\aaCenter.exe (ASUSTeK Computer Inc.)<br />
PRC - D:\Programme\Adobe Photoshop Elements 8.0\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)<br />
PRC - C:\Programme\ASUS\TurboV EVO\TurboV_EVO.exe (ASUSTeK Computer Inc.)<br />
PRC - C:\Programme\ASUS\TurboV EVO\TurboVHelp.exe (ASUSTeK Computer Inc.)<br />
PRC - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe (ASUSTeK Computer Inc.)<br />
PRC - C:\ASUS.SYS\config\DVMExportService.exe (DeviceVM, Inc.)<br />
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)<br />
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)<br />
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)<br />
PRC - C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (AVM Berlin)<br />
PRC - C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (AVM Berlin)<br />
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#e56717">========== Modules (SafeList) ==========</font><br />
&nbsp;<br />
MOD - D:\<a href=85104-otl-otlogfile-oldtimer.html>OTL.exe</a> (OldTimer Tools)<br />
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)<br />
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#e56717">========== Win32 Services (SafeList) ==========</font><br />
&nbsp;<br />
SRV:<b>64bit:</b> - (PnkBstrB) -- C:\Windows\SysNative\PnkBstrB.exe File not found<br />
SRV:<b>64bit:</b> - (PnkBstrA) -- C:\Windows\SysNative\PnkBstrA.exe File not found<br />
SRV:<b>64bit:</b> - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)<br />
SRV:<b>64bit:</b> - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)<br />
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)<br />
SRV - (PnkBstrB) -- C:\Windows\SysWOW64\PnkBstrB.exe ()<br />
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()<br />
SRV - (AntiVirService) -- D:\Programme\Avira AntiVir\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)<br />
SRV - (clr_optimization_v4.0.30319_64) -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)<br />
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)<br />
SRV - (AntiVirSchedulerService) -- D:\Programme\Avira AntiVir\Avira\AntiVir Desktop\sched.exe (Avira GmbH)<br />
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)<br />
SRV - (AdobeActiveFileMonitor8.0) -- D:\Programme\Adobe Photoshop Elements 8.0\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)<br />
SRV - (AsSysCtrlService) -- C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe (ASUSTeK Computer Inc.)<br />
SRV - (DvmMDES) -- C:\ASUS.SYS\config\DVMExportService.exe (DeviceVM, Inc.)<br />
SRV - (IAANTMON) Intel(R) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)<br />
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)<br />
SRV - (AVM WLAN Connection Service) -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (AVM Berlin)<br />
SRV - (ACDaemon) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#e56717">========== Driver Services (SafeList) ==========</font><br />
&nbsp;<br />
DRV:<b>64bit:</b> - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)<br />
DRV:<b>64bit:</b> - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)<br />
DRV:<b>64bit:</b> - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)<br />
DRV:<b>64bit:</b> - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()<br />
DRV:<b>64bit:</b> - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)<br />
DRV:<b>64bit:</b> - (RTL2832UBDA) -- C:\Windows\SysNative\drivers\RTL2832UBDA.sys (REALTEK SEMICONDUCTOR Corp.)<br />
DRV:<b>64bit:</b> - (RTL2832UUSB) -- C:\Windows\SysNative\drivers\RTL2832UUSB.sys (REALTEK SEMICONDUCTOR Corp.)<br />
DRV:<b>64bit:</b> - (RTL2832U_IRHID) -- C:\Windows\SysNative\drivers\RTL2832U_IRHID.sys (Realtek)<br />
DRV:<b>64bit:</b> - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)<br />
DRV:<b>64bit:</b> - (UsbserFilt) -- C:\Windows\SysNative\drivers\usbser_lowerfltx64j.sys (Nokia)<br />
DRV:<b>64bit:</b> - (upperdev) -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia)<br />
DRV:<b>64bit:</b> - (nmwcdcx64) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)<br />
DRV:<b>64bit:</b> - (nmwcdx64) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)<br />
DRV:<b>64bit:</b> - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)<br />
DRV:<b>64bit:</b> - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; )<br />
DRV:<b>64bit:</b> - (USB28xxBGA) -- C:\Windows\SysNative\drivers\emBDA64.sys (eMPIA Technology, Inc.)<br />
DRV:<b>64bit:</b> - (USB28xxOEM) -- C:\Windows\SysNative\drivers\emOEM64.sys (eMPIA Technology, Inc.)<br />
DRV:<b>64bit:</b> - (dc3d) MS Hardware Device Detection Driver (USB) -- C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)<br />
DRV:<b>64bit:</b> - (Point64) -- C:\Windows\SysNative\drivers\point64k.sys (Microsoft Corporation)<br />
DRV:<b>64bit:</b> - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)<br />
DRV:<b>64bit:</b> - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)<br />
DRV:<b>64bit:</b> - (BthAvrcp) -- C:\Windows\SysNative\drivers\BthAvrcp.sys (CSR, plc)<br />
DRV:<b>64bit:</b> - (JRAID) -- C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)<br />
DRV:<b>64bit:</b> - (MTsensor) -- C:\Windows\SysNative\drivers\ASACPI.sys ()<br />
DRV:<b>64bit:</b> - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)<br />
DRV:<b>64bit:</b> - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)<br />
DRV:<b>64bit:</b> - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)<br />
DRV:<b>64bit:</b> - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)<br />
DRV:<b>64bit:</b> - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)<br />
DRV:<b>64bit:</b> - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)<br />
DRV:<b>64bit:</b> - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)<br />
DRV:<b>64bit:</b> - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)<br />
DRV:<b>64bit:</b> - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof ()<br />
DRV:<b>64bit:</b> - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)<br />
DRV:<b>64bit:</b> - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)<br />
DRV:<b>64bit:</b> - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)<br />
DRV:<b>64bit:</b> - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)<br />
DRV:<b>64bit:</b> - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)<br />
DRV:<b>64bit:</b> - (SNP2UVC) -- C:\Windows\SysNative\drivers\snp2uvc.sys ()<br />
DRV:<b>64bit:</b> - (fwlanusbn) -- C:\Windows\SysNative\drivers\fwlanusbn.sys (AVM GmbH)<br />
DRV:<b>64bit:</b> - (avmeject) -- C:\Windows\SysNative\drivers\avmeject.sys (AVM Berlin)<br />
DRV:<b>64bit:</b> - (hxctlflt) -- C:\Windows\SysNative\drivers\hxctlflt.sys (Guillemot Corporation)<br />
DRV:<b>64bit:</b> - (acedrv11) -- C:\Windows\SysNative\drivers\acedrv11.sys (Protect Software GmbH)<br />
DRV:<b>64bit:</b> - (pccsmcfd) -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)<br />
DRV:<b>64bit:</b> - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)<br />
DRV - (RTL2832U_IRHID) -- C:\Windows\SysWOW64\drivers\RTL2832U_IRHID.sys (Realtek)<br />
DRV - (RTL2832UUSB) -- C:\Windows\SysWOW64\drivers\RTL2832UUSB.sys (REALTEK SEMICONDUCTOR Corp.)<br />
DRV - (RTL2832UBDA) -- C:\Windows\SysWOW64\drivers\RTL2832UBDA.sys (REALTEK SEMICONDUCTOR Corp.)<br />
&nbsp;<br />
&nbsp;<br />
<font color="#e56717">========== Standard Registry (SafeList) ==========</font><br />
&nbsp;<br />
&nbsp;<br />
<font color="#e56717">========== Internet Explorer ==========</font><br />
&nbsp;<br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br />
&nbsp;<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = <br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Nachrichten - Service - Shopping bei t-online.de<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN, Messenger und Hotmail sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 5D A3 A5 EF B8 87 CA 01&nbsp; [binary data]<br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: &quot;ProxyEnable&quot; = 0<br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: &quot;ProxyOverride&quot; = fritz.box<br />
&nbsp;<br />
<font color="#e56717">========== FireFox ==========</font><br />
&nbsp;<br />
FF - prefs.js..browser.startup.homepage: &quot;hxxp://www.t-online.de&quot;<br />
FF - prefs.js..extensions.enabledItems: {d49175b3-3fd8-43b8-b28e-da5d47f3c398}:1.0.29<br />
FF - prefs.js..extensions.enabledItems: <a href="mailto:fb_add_on@avm.de">fb_add_on@avm.de</a>:1.5.5<br />
FF - prefs.js..extensions.enabledItems: <a href="mailto:bkmrksync@nokia.com">bkmrksync@nokia.com</a>:1.0.0.732<br />
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100823<br />
FF - prefs.js..extensions.enabledItems: {0329E7D6-6F54-462D-93F6-F5C3118BADF2}:2.2.4<br />
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20<br />
&nbsp;<br />
FF - HKLM\software\mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}: D:\Programme\Speedbit Video Downloader\SpeedBit Video Downloader\SPFireFox [2010.05.08 21:12:32 | 000,000,000 | ---D | M]<br />
FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: D:\Programme\Nokia\Nokia PC Suite\Nokia PC Suite 7\bkmrksync\ [2010.07.08 15:26:32 | 000,000,000 | ---D | M]<br />
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: D:\Programme\Mozilla Firefox\components [2010.08.06 00:36:31 | 000,000,000 | ---D | M]<br />
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: D:\Programme\Mozilla Firefox\plugins [2010.08.05 18:16:35 | 000,000,000 | ---D | M]<br />
&nbsp;<br />
[2009.12.31 13:24:54 | 000,000,000 | ---D | M] -- C:\Users\Antec\AppData\Roaming\mozilla\Extensions<br />
[2010.09.04 21:02:08 | 000,000,000 | ---D | M] -- C:\Users\Antec\AppData\Roaming\mozilla\Firefox\Profiles\cgu9kj7n.default\extensions<br />
[2010.04.15 20:13:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Antec\AppData\Roaming\mozilla\Firefox\Profiles\cgu9kj7n.default\extensions\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}<br />
[2010.08.31 20:23:35 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Antec\AppData\Roaming\mozilla\Firefox\Profiles\cgu9kj7n.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}<br />
[2010.06.27 12:31:38 | 000,000,000 | ---D | M] (COMPUTERBILD-Abzockschutz) -- C:\Users\Antec\AppData\Roaming\mozilla\Firefox\Profiles\cgu9kj7n.default\extensions\{d49175b3-3fd8-43b8-b28e-da5d47f3c398}<br />
[2010.01.11 20:33:08 | 000,000,000 | ---D | M] -- C:\Users\Antec\AppData\Roaming\mozilla\Firefox\Profiles\cgu9kj7n.default\extensions\fb_add_on@avm.de<br />
&nbsp;<br />
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts<br />
O2 - BHO: (SBCONVERT Class) - {3017FB3E-9A77-4396-88C5-0EC9548FB42F} - D:\Programme\Speedbit Video Downloader\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()<br />
O2 - BHO: (SearchPredictObj Class) - {389943B0-C3A2-4E69-82CB-8596A84CB3DC} - C:\PROGRA~2\SEARCH~1\SEARCH~1.DLL (Speedbit Ltd.)<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.<br />
O2 - BHO: (GrabberObj Class) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - D:\Programme\Speedbit Video Downloader\SpeedBit Video Downloader\Toolbar\Grabber.dll (Speedbit Ltd.)<br />
O3 - HKLM\..\Toolbar: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - D:\Programme\Speedbit Video Downloader\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()<br />
O3 - HKCU\..\Toolbar\WebBrowser: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - D:\Programme\Speedbit Video Downloader\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()<br />
O4:<b>64bit:</b> - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)<br />
O4:<b>64bit:</b> - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)<br />
O4 - HKLM..\Run: [avgnt] D:\Programme\Avira AntiVir\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)<br />
O4 - HKLM..\Run: [AVMWlanClient] C:\Program Files (x86)\avmwlanstick\wlangui.exe (AVM Berlin)<br />
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)<br />
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()<br />
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)<br />
O4 - HKLM..\Run: [TurboV EVO] C:\Program Files\ASUS\TurboV EVO\TurboV_EVO.exe (ASUSTeK Computer Inc.)<br />
O4 - HKCU..\Run: [EPSON Stylus DX4400 Series] C:\Windows\SysWow64\spool\DRIVERS\x64\3\E_IATICAE.EXE File not found<br />
O4 - HKCU..\Run: [EPSON Stylus DX8400 Series] C:\Windows\SysWow64\spool\DRIVERS\x64\3\E_IATICEE.EXE File not found<br />
O4 - HKCU..\Run: [SpybotSD TeaTimer] D:\Programme\Spybot\Spybot - Search &amp; Destroy\TeaTimer.exe (Safer-Networking Ltd.)<br />
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] D:\0000000\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)<br />
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1<br />
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1<br />
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5<br />
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3<br />
O8:<b>64bit:</b> - Extra context menu item: Nach Microsoft E&amp;xel exportieren - D:\Programme\Microsoft Office Home and Student 2007\Office12\EXCEL.EXE (Microsoft Corporation)<br />
O8 - Extra context menu item: Nach Microsoft E&amp;xel exportieren - D:\Programme\Microsoft Office Home and Student 2007\Office12\EXCEL.EXE (Microsoft Corporation)<br />
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Programme\Microsoft Office Home and Student 2007\Office12\ONBttnIE.dll (Microsoft Corporation)<br />
O9 - Extra 'Tools' menuitem : An OneNote s&amp;enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Programme\Microsoft Office Home and Student 2007\Office12\ONBttnIE.dll (Microsoft Corporation)<br />
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - D:\Programme\ICQ 7\ICQ7.1\ICQ.exe (ICQ, LLC.)<br />
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - D:\Programme\ICQ 7\ICQ7.1\ICQ.exe (ICQ, LLC.)<br />
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Programme\Microsoft Office Home and Student 2007\Office12\REFIEBAR.DLL (Microsoft Corporation)<br />
O13 - gopher Prefix: missing<br />
O13 - gopher Prefix: missing<br />
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet)<br />
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet)<br />
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)<br />
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)<br />
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1<br />
O18:<b>64bit:</b> - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found<br />
O18:<b>64bit:</b> - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found<br />
O18:<b>64bit:</b> - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found<br />
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)<br />
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)<br />
O18:<b>64bit:</b> - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)<br />
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)<br />
O20:<b>64bit:</b> - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)<br />
O20:<b>64bit:</b> - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)<br />
O20:<b>64bit:</b> - HKLM Winlogon: VMApplet - (/pagefile) -&nbsp; File not found<br />
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)<br />
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)<br />
O20 - HKLM Winlogon: VMApplet - (/pagefile) -&nbsp; File not found<br />
O21:<b>64bit:</b> - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.<br />
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.<br />
O32 - HKLM CDRom: AutoRun - 1<br />
O33 - MountPoints2\{30c049a3-f398-11de-be0a-806e6f6e6963}\Shell - &quot;&quot; = AutoRun<br />
O33 - MountPoints2\{30c049a3-f398-11de-be0a-806e6f6e6963}\Shell\AutoRun\command - &quot;&quot; = E:\.\Bin\ASSETUP.exe -- File not found<br />
O33 - MountPoints2\{cc05b800-fc8d-11de-9627-90e6ba155d30}\Shell - &quot;&quot; = AutoRun<br />
O33 - MountPoints2\{cc05b800-fc8d-11de-9627-90e6ba155d30}\Shell\AutoRun\command - &quot;&quot; = L:\pushinst.exe -- File not found<br />
O33 - MountPoints2\{fb09731c-f958-11de-ba03-90e6ba155d30}\Shell - &quot;&quot; = AutoRun<br />
O33 - MountPoints2\{fb09731c-f958-11de-ba03-90e6ba155d30}\Shell\AutoRun\command - &quot;&quot; = J:\pushinst.exe -- File not found<br />
O33 - MountPoints2\K\Shell - &quot;&quot; = AutoRun<br />
O33 - MountPoints2\K\Shell\AutoRun\command - &quot;&quot; = K:\pushinst.exe -- File not found<br />
O34 - HKLM BootExecute: (autocheck autochk *) -&nbsp; File not found<br />
O35:<b>64bit:</b> - HKLM\..comfile [open] -- &quot;%1&quot; %*<br />
O35:<b>64bit:</b> - HKLM\..exefile [open] -- &quot;%1&quot; %*<br />
O35 - HKLM\..comfile [open] -- &quot;%1&quot; %*<br />
O35 - HKLM\..exefile [open] -- &quot;%1&quot; %*<br />
O37:<b>64bit:</b> - HKLM\...com [@ = comfile] -- &quot;%1&quot; %*<br />
O37:<b>64bit:</b> - HKLM\...exe [@ = exefile] -- &quot;%1&quot; %*<br />
O37 - HKLM\...com [@ = comfile] -- &quot;%1&quot; %*<br />
O37 - HKLM\...exe [@ = exefile] -- &quot;%1&quot; %*<br />
&nbsp;<br />
<font color="#e56717">========== Files/Folders - Created Within 30 Days ==========</font><br />
&nbsp;<br />
[2010.09.07 17:08:01 | 000,000,000 | ---D | C] -- C:\Users\Antec\AppData\Roaming\Malwarebytes<br />
[2010.09.07 14:14:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search &amp; Destroy<br />
[2010.09.06 21:50:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Antimalware<br />
[2010.09.06 20:23:05 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys<br />
[2010.09.06 20:23:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes<br />
[2010.09.06 20:23:02 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys<br />
[2010.09.06 18:38:48 | 000,000,000 | ---D | C] -- C:\Users\Antec\AppData\Roaming\VideoReDo-TVSuite4<br />
[2010.09.05 19:12:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab Setup Files<br />
[2010.08.25 15:32:04 | 000,861,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll<br />
[2010.08.17 23:41:11 | 000,000,000 | ---D | C] -- C:\Users\Antec\Documents\MAGIX Downloads<br />
[2010.08.15 03:17:56 | 000,000,000 | ---D | C] -- C:\Users\Antec\AppData\Local\Microsoft Games<br />
[2010.08.14 23:15:59 | 000,000,000 | ---D | C] -- C:\Users\Antec\AppData\Roaming\Auslogics<br />
[2010.08.14 13:07:54 | 001,712,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gdiplus.dll<br />
[2010.08.14 13:07:54 | 001,060,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC71.dll<br />
[2010.08.14 13:07:54 | 001,047,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC71u.dll<br />
[2010.08.14 13:07:54 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC71DEU.DLL<br />
[2010.08.14 13:07:54 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC71ITA.DLL<br />
[2010.08.14 13:07:54 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC71FRA.DLL<br />
[2010.08.14 13:07:54 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC71ESP.DLL<br />
[2010.08.14 13:07:54 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC71ENU.DLL<br />
[2010.08.14 13:07:54 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC71KOR.DLL<br />
[2010.08.14 13:07:54 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC71JPN.DLL<br />
[2010.08.14 13:07:54 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC71CHT.DLL<br />
[2010.08.14 13:07:54 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC71CHS.DLL<br />
[2010.08.10 22:20:01 | 005,507,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe<br />
[2010.08.10 22:20:01 | 003,955,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe<br />
[2010.08.10 22:20:00 | 003,899,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe<br />
[2010.08.10 22:19:54 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll<br />
[2010.08.10 22:19:54 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll<br />
[2010.08.10 22:19:54 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll<br />
[2010.08.10 22:19:54 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll<br />
[2010.08.10 22:19:54 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe<br />
[2010.08.10 22:19:54 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe<br />
[2010.08.10 22:19:48 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\SysWow64\iccvid.dll<br />
[2010.08.10 22:19:48 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rtutils.dll<br />
[2010.08.10 22:19:48 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rtutils.dll<br />
[2010.08.09 12:58:23 | 000,719,872 | ---- | C] (Abysmal Software) -- C:\Windows\SysWow64\devil.dll<br />
[2010.08.09 12:58:23 | 000,369,152 | ---- | C] (The Public) -- C:\Windows\SysWow64\avisynth.dll<br />
[2010.08.09 12:58:22 | 000,070,656 | ---- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\yv12vfw.dll<br />
[2010.08.09 12:58:22 | 000,070,656 | ---- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\i420vfw.dll<br />
[2010.08.09 12:58:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AviSynth 2.5<br />
[2010.08.09 02:09:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DVDVideoSoft<br />
[2010.08.09 02:07:12 | 000,000,000 | ---D | C] -- C:\Users\Antec\AppData\Roaming\Cuttermaran<br />
&nbsp;<br />
<font color="#e56717">========== Files - Modified Within 30 Days ==========</font><br />
&nbsp;<br />
[2010.09.07 17:19:32 | 002,621,440 | -HS- | M] () -- C:\Users\Antec\ntuser.dat<br />
[2010.09.07 17:07:53 | 000,000,653 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk<br />
[2010.09.07 17:00:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job<br />
[2010.09.07 14:15:08 | 000,000,985 | ---- | M] () -- C:\Users\Antec\Desktop\Spybot - Search &amp; Destroy.lnk<br />
[2010.09.07 13:57:35 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI<br />
[2010.09.07 13:57:35 | 000,653,928 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat<br />
[2010.09.07 13:57:35 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat<br />
[2010.09.07 13:57:35 | 000,129,800 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat<br />
[2010.09.07 13:57:35 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat<br />
[2010.09.07 13:53:28 | 000,000,177 | -H-- | M] () -- C:\dvmexp.idx<br />
[2010.09.07 13:51:06 | 000,023,552 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0<br />
[2010.09.07 13:51:06 | 000,023,552 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0<br />
[2010.09.07 13:44:49 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{0d327a79-ba75-11df-8cd0-001f3f0c33d1}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.09.07 13:44:49 | 000,065,536 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{0d327a79-ba75-11df-8cd0-001f3f0c33d1}.TM.blf<br />
[2010.09.07 13:44:48 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{0d327a79-ba75-11df-8cd0-001f3f0c33d1}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.09.07 13:43:42 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job<br />
[2010.09.07 13:43:22 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT<br />
[2010.09.07 13:43:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat<br />
[2010.09.07 13:43:00 | 2140,446,719 | -HS- | M] () -- C:\hiberfil.sys<br />
[2010.09.06 15:24:03 | 002,780,633 | -H-- | M] () -- C:\Users\Antec\AppData\Local\IconCache.db<br />
[2010.09.05 00:08:04 | 000,000,046 | ---- | M] () -- C:\Users\Antec\jagex_runescape_preferences.dat<br />
[2010.09.05 00:04:07 | 000,000,099 | ---- | M] () -- C:\Users\Antec\jagex_runescape_preferences2.dat<br />
[2010.08.29 16:57:15 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\00000D34.LCS<br />
[2010.08.27 10:53:05 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\00001199.LCS<br />
[2010.08.24 22:27:42 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{88e65186-afbc-11df-93b8-dfb9091abe82}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.24 22:27:42 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{88e65186-afbc-11df-93b8-dfb9091abe82}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.24 22:27:42 | 000,065,536 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{88e65186-afbc-11df-93b8-dfb9091abe82}.TM.blf<br />
[2010.08.24 18:03:54 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{3a26c060-af98-11df-8f7e-fdcde1824b83}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.24 18:03:54 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{3a26c060-af98-11df-8f7e-fdcde1824b83}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.24 18:03:54 | 000,065,536 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{3a26c060-af98-11df-8f7e-fdcde1824b83}.TM.blf<br />
[2010.08.24 17:04:45 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{79981c64-af8f-11df-96bb-9f8548c4fb85}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.24 17:04:45 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{79981c64-af8f-11df-96bb-9f8548c4fb85}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.24 17:04:45 | 000,065,536 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{79981c64-af8f-11df-96bb-9f8548c4fb85}.TM.blf<br />
[2010.08.23 16:10:37 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{1069a3ae-aec0-11df-8cb8-f3407ef10b8a}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.23 16:10:37 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{1069a3ae-aec0-11df-8cb8-f3407ef10b8a}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.23 16:10:37 | 000,065,536 | -HS- | M] () -- C:\Users\Antec\ntuser.dat{1069a3ae-aec0-11df-8cb8-f3407ef10b8a}.TM.blf<br />
[2010.08.16 21:43:21 | 000,000,774 | ---- | M] () -- C:\Users\Antec\Desktop\PC Probe II V1.04.88.lnk<br />
[2010.08.16 18:38:44 | 000,000,045 | ---- | M] () -- C:\Windows\SysWow64\initdebug.nfo<br />
[2010.08.13 18:41:27 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\NTUSER.DAT{8590155b-a6f9-11df-b097-d118d666e583}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.13 18:41:27 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\NTUSER.DAT{8590155b-a6f9-11df-b097-d118d666e583}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.13 18:41:27 | 000,065,536 | -HS- | M] () -- C:\Users\Antec\NTUSER.DAT{8590155b-a6f9-11df-b097-d118d666e583}.TM.blf<br />
[2010.08.10 23:46:12 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\NTUSER.DAT{5c3c72e7-a4c8-11df-b305-001f3f0c33d1}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.10 23:46:12 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\NTUSER.DAT{5c3c72e7-a4c8-11df-b305-001f3f0c33d1}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.10 23:46:12 | 000,065,536 | -HS- | M] () -- C:\Users\Antec\NTUSER.DAT{5c3c72e7-a4c8-11df-b305-001f3f0c33d1}.TM.blf<br />
[2010.08.10 23:44:22 | 002,970,840 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT<br />
[2010.08.09 17:57:12 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\NTUSER.DAT{46e31ddc-a3ce-11df-aaa7-001f3f0c33d1}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.09 17:57:12 | 000,524,288 | -HS- | M] () -- C:\Users\Antec\NTUSER.DAT{46e31ddc-a3ce-11df-aaa7-001f3f0c33d1}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.09 17:57:12 | 000,065,536 | -HS- | M] () -- C:\Users\Antec\NTUSER.DAT{46e31ddc-a3ce-11df-aaa7-001f3f0c33d1}.TM.blf<br />
&nbsp;<br />
<font color="#e56717">========== Files Created - No Company Name ==========</font><br />
&nbsp;<br />
[2010.09.07 17:07:53 | 000,000,653 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk<br />
[2010.09.07 14:15:08 | 000,000,985 | ---- | C] () -- C:\Users\Antec\Desktop\Spybot - Search &amp; Destroy.lnk<br />
[2010.09.07 13:44:47 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{0d327a79-ba75-11df-8cd0-001f3f0c33d1}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.09.07 13:44:47 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{0d327a79-ba75-11df-8cd0-001f3f0c33d1}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.09.07 13:44:47 | 000,065,536 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{0d327a79-ba75-11df-8cd0-001f3f0c33d1}.TM.blf<br />
[2010.08.24 22:24:08 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{88e65186-afbc-11df-93b8-dfb9091abe82}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.24 22:24:08 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{88e65186-afbc-11df-93b8-dfb9091abe82}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.24 22:24:08 | 000,065,536 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{88e65186-afbc-11df-93b8-dfb9091abe82}.TM.blf<br />
[2010.08.24 18:02:04 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{3a26c060-af98-11df-8f7e-fdcde1824b83}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.24 18:02:04 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{3a26c060-af98-11df-8f7e-fdcde1824b83}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.24 18:02:04 | 000,065,536 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{3a26c060-af98-11df-8f7e-fdcde1824b83}.TM.blf<br />
[2010.08.24 17:03:25 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{79981c64-af8f-11df-96bb-9f8548c4fb85}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.24 17:03:25 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{79981c64-af8f-11df-96bb-9f8548c4fb85}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.24 17:03:25 | 000,065,536 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{79981c64-af8f-11df-96bb-9f8548c4fb85}.TM.blf<br />
[2010.08.23 16:10:11 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{1069a3ae-aec0-11df-8cb8-f3407ef10b8a}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.23 16:10:11 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{1069a3ae-aec0-11df-8cb8-f3407ef10b8a}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.23 16:10:11 | 000,065,536 | -HS- | C] () -- C:\Users\Antec\ntuser.dat{1069a3ae-aec0-11df-8cb8-f3407ef10b8a}.TM.blf<br />
[2010.08.16 21:43:21 | 000,000,774 | ---- | C] () -- C:\Users\Antec\Desktop\PC Probe II V1.04.88.lnk<br />
[2010.08.16 21:42:57 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys<br />
[2010.08.16 21:42:56 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys<br />
[2010.08.13 18:41:27 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\NTUSER.DAT{8590155b-a6f9-11df-b097-d118d666e583}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.13 18:41:27 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\NTUSER.DAT{8590155b-a6f9-11df-b097-d118d666e583}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.13 18:41:27 | 000,065,536 | -HS- | C] () -- C:\Users\Antec\NTUSER.DAT{8590155b-a6f9-11df-b097-d118d666e583}.TM.blf<br />
[2010.08.10 23:46:12 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\NTUSER.DAT{5c3c72e7-a4c8-11df-b305-001f3f0c33d1}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.10 23:46:12 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\NTUSER.DAT{5c3c72e7-a4c8-11df-b305-001f3f0c33d1}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.10 23:46:12 | 000,065,536 | -HS- | C] () -- C:\Users\Antec\NTUSER.DAT{5c3c72e7-a4c8-11df-b305-001f3f0c33d1}.TM.blf<br />
[2010.08.09 17:57:11 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\NTUSER.DAT{46e31ddc-a3ce-11df-aaa7-001f3f0c33d1}.TMContainer00000000000000000002.regtrans-ms<br />
[2010.08.09 17:57:11 | 000,524,288 | -HS- | C] () -- C:\Users\Antec\NTUSER.DAT{46e31ddc-a3ce-11df-aaa7-001f3f0c33d1}.TMContainer00000000000000000001.regtrans-ms<br />
[2010.08.09 17:57:10 | 000,065,536 | -HS- | C] () -- C:\Users\Antec\NTUSER.DAT{46e31ddc-a3ce-11df-aaa7-001f3f0c33d1}.TM.blf<br />
[2010.08.09 12:58:22 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll<br />
[2010.05.26 14:36:49 | 000,034,308 | ---- | C] () -- C:\Windows\SysWow64\BASSMOD.dll<br />
[2010.05.25 20:33:23 | 000,000,007 | ---- | C] () -- C:\Windows\treeskp.sys<br />
[2010.05.25 14:37:54 | 000,110,080 | ---- | C] () -- C:\Windows\SysWow64\advd.dll<br />
[2010.05.25 14:37:54 | 000,023,040 | ---- | C] () -- C:\Windows\SysWow64\auth.dll<br />
[2010.05.25 14:37:53 | 000,237,568 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll<br />
[2010.05.25 14:36:48 | 000,017,408 | ---- | C] () -- C:\Users\Antec\AppData\Local\WebpageIcons.db<br />
[2010.05.18 16:27:40 | 000,000,295 | ---- | C] () -- C:\Windows\game.ini<br />
[2010.03.30 15:12:41 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini<br />
[2010.03.21 18:13:15 | 000,554,496 | ---- | C] () -- C:\Windows\SysWow64\dvmsg.dll<br />
[2010.02.21 13:53:50 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll<br />
[2010.02.21 13:50:49 | 000,007,119 | ---- | C] () -- C:\Windows\mgxoschk.ini<br />
[2010.02.11 18:41:30 | 000,049,152 | R--- | C] () -- C:\Windows\SysWow64\AVerIO.dll<br />
[2010.02.11 18:41:30 | 000,003,456 | R--- | C] () -- C:\Windows\SysWow64\AVerIO.sys<br />
[2010.02.11 18:41:25 | 000,258,048 | R--- | C] () -- C:\Windows\SysWow64\sptlib01.dll<br />
[2010.02.11 18:41:25 | 000,253,952 | R--- | C] () -- C:\Windows\SysWow64\sptlib02.dll<br />
[2010.02.01 12:30:55 | 000,000,096 | ---- | C] () -- C:\Users\Antec\AppData\Roaming\d3a10f4e.dat<br />
[2010.01.10 12:16:04 | 000,013,824 | ---- | C] () -- C:\Users\Antec\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
[2010.01.03 23:06:02 | 000,127,085 | ---- | C] () -- C:\Windows\SysWow64\RTKFMSOURCE.dll<br />
[2009.12.28 13:08:27 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll<br />
[2009.12.28 13:08:27 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys<br />
[2009.12.28 13:06:36 | 000,035,862 | ---- | C] () -- C:\Windows\Ascd_log.ini<br />
[2009.12.28 13:00:35 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini<br />
[2009.12.28 13:00:30 | 000,024,648 | ---- | C] () -- C:\Windows\Ascd_tmp.ini<br />
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll<br />
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll<br />
[2009.04.02 14:30:14 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS<br />
[2008.12.01 19:32:32 | 000,362,029 | ---- | C] () -- C:\Windows\SysWow64\sqlite3.dll<br />
[2008.10.22 05:29:06 | 000,173,550 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat<br />
&nbsp;<br />
<font color="#e56717">========== Alternate Data Streams ==========</font><br />
&nbsp;<br />
@Alternate Data Stream - 218 bytes -&gt; C:\ProgramData\TEMP:3440EB47<br />
@Alternate Data Stream - 178 bytes -&gt; C:\ProgramData\TEMP:0888F409<br />
@Alternate Data Stream - 136 bytes -&gt; C:\ProgramData\TEMP:66633281<br />
&lt; End of report &gt;</code><hr />
</div>--- --- ---</div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>technisat</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90497-facebook-virus-ueber-skype-bekommen.html</guid>
		</item>
		<item>
			<title>Offen Virus der Sich über Skype verschickt</title>
			<link>http://www.trojaner-board.de/90496-virus-der-sich-ueber-skype-verschickt.html</link>
			<pubDate>Tue, 07 Sep 2010 13:39:26 GMT</pubDate>
			<description><![CDATA[Hallo 
Ich habe von meinem Freund vor 2 Tagen einen Link über Skype geschickt bekommen. Die Nachricht sah ca. so aus: "Foto :P w*w.facebook..." .Leider war das ein Downloadlink für einen Virus der sich selbstständig über skype verschickt :headbang: 
Ich hab mit Malwarebytes einen Scan gemacht, weiß...]]></description>
			<content:encoded><![CDATA[<div>Hallo<br />
Ich habe von meinem Freund vor 2 Tagen einen Link über Skype geschickt bekommen. Die Nachricht sah ca. so aus: &quot;Foto :P w*w.facebook...&quot; .Leider war das ein Downloadlink für einen Virus der sich selbstständig über skype verschickt :headbang:<br />
Ich hab mit <a href=51187-anleitung-malwarebytes-anti-malware.html>Malwarebytes</a> einen Scan gemacht, weiß aber noch nicht ob der Virus jetzt weg ist. <br />
Bitte um schnelle Hilfe<br />
 <br />
Hier ein Logfile von Hijackthis:<br />
 <br />
HiJackthis Logfile:<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">Logfile of Trend Micro <a href=51130-anleitung-hijackthis.html>HijackThis</a> v2.0.4<br />
Scan saved at 15:33:05, on 07.09.2010<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18943)<br />
Boot mode: Normal<br />
&nbsp;<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Program Files\Window Hide Tool\Window Hide Tool.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\ProgramData\Skype\Plugins\Plugins\9F9CE45F74274F5689DEAD48836386CA\MusicMaestro.exe<br />
C:\Program Files\Opera\Opera.exe<br />
C:\Users\*****\Desktop\HiJackThis204.exe<br />
&nbsp;<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://fullarticles.net<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)<br />
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll<br />
O1 - Hosts: ÿþ127.0.0.1 localhost<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: Videoraptor_WebRipPlugin Class - {3C0372C2-04C3-4100-BAB1-1D42C552BC48} - C:\Program Files\RapidSolution\Videoraptor\plugins\IE\VR_WebRipIePlugin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll<br />
O3 - Toolbar: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)<br />
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [RemoteControl] &quot;C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe&quot;<br />
O4 - HKLM\..\Run: [LanguageShortcut] &quot;C:\Program Files\CyberLink\PowerDVD\Language\Language.exe&quot;<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Common Files\Java\Java Update\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] &quot;C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe&quot; -launchedbylogin<br />
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] &quot;C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe&quot; --auto-start<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [Window Hide Tool] C:\Program Files\Window Hide Tool\Window Hide Tool.exe<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe -autorun<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - Global Startup: BTTray.lnk = ?<br />
O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: An OneNote s&amp;enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe<br />
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe<br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab<br />
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab<br />
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - hxxp://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Update Service (gupdate1cb059687ea4443) (gupdate1cb059687ea4443) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe<br />
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br />
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe<br />
O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe<br />
&nbsp;<br />
--<br />
End of file - 9043 bytes</code><hr />
</div>--- --- ---<br />
</div>

]]></content:encoded>
			<category domain="http://www.trojaner-board.de/hijacker-hijackthis-logs-posten/">Hijacker / HiJackThis Logs posten</category>
			<dc:creator>Lomoko</dc:creator>
			<guid isPermaLink="true">http://www.trojaner-board.de/90496-virus-der-sich-ueber-skype-verschickt.html</guid>
		</item>
	</channel>
</rss>
