![]() |
| |||||||
Log-Analyse und Auswertung: Av AntiRootkit scan - gefährlicher Fund?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| |
| | #1 |
| | Av AntiRootkit scan - gefährlicher Fund? Hallo zusammen! Ich habe geraden einen Rootkit scan mit Av AntiRootkit Tool gemacht und habe das folgenden Report erhalten: Code:
ATTFilter Avira AntiRootkit Tool (1.1.0.1)
========================================================================================================
- Scan started Donnerstag, 7. Januar 2010 - 16:49:27
========================================================================================================
--------------------------------------------------------------------------------------------------------
Configuration:
--------------------------------------------------------------------------------------------------------
- [X] Scan files
- [X] Scan registry
- [X] Scan processes
- [ ] Fast scan
- Working disk total size : 186.30 GB
- Working disk free size : 25.38 GB (13 %)
--------------------------------------------------------------------------------------------------------
Results:
Embedded nulls : HKEY_USERS\S-1-5-21-1757981266-1060284298-839522115-1006\Software\YourCompanyName\YourProductName\Version
Hidden value : HKEY_USERS\S-1-5-21-1757981266-1060284298-839522115-1006\Software\YourCompanyName\YourProductName\Version -> versiondata
Hidden key : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\notify
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> autorestartshell
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> defaultdomainname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> defaultusername
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> legalnoticecaption
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> legalnoticetext
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> powerdownaftershutdown
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> reportbootok
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> shell
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> shutdownwithoutlogon
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> system
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> userinit
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> vmapplet
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> sfcquota
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> allocatecdroms
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> allocatedasd
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> allocatefloppies
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> cachedlogonscount
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> forceunlocklogon
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> passwordexpirywarning
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> scremoveoption
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> allowmultipletssessions
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> uihost
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> logontype
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> background
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> debugservercommand
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> sfcdisable
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> winstationsdisabled
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> hibernationpreviouslyenabled
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> showlogonoptions
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> altdefaultusername
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> altdefaultdomainname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> nomachinepolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> nouserpolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> noslowlink
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> nobackgroundpolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> nogpolistchanges
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> peruserlocalsettings
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> requiressuccessfulregistry
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> enableasynchronousprocessing
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> dllname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} -> processgrouppolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} -> dllname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} -> processgrouppolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} -> nogpolistchanges
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} -> requiressucessfulregistry
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} -> displayname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} -> requiressuccessfulregistry
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} -> displayname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} -> dllname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} -> nogpolistchanges
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} -> processgrouppolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} -> processgrouppolicyex
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} -> requiressuccessfulregistry
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> processgrouppolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> generategrouppolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> extensionrsopplanningdebuglevel
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> processgrouppolicyex
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> extensiondebuglevel
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> dllname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> nouserpolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> nogpolistchanges
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> enableasynchronousprocessing
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} -> maxnogpolistchangesinterval
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> processgrouppolicyex
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> generategrouppolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> processgrouppolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> dllname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> noslowlink
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> nobackgroundpolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> nogpolistchanges
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> nomachinepolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} -> displayname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} -> processgrouppolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} -> dllname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} -> nouserpolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} -> nogpolistchanges
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} -> requiressuccessfulregistry
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> dllname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> enableasynchronousprocessing
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> nobackgroundpolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> nogpolistchanges
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> nomachinepolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> noslowlink
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> nouserpolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> peruserlocalsettings
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> processgrouppolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} -> requiressuccessfulregistry
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> dllname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> processgrouppolicyex
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> generategrouppolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> nobackgroundpolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> requiressucessfulregistry
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> noslowlink
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> peruserlocalsettings
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} -> eventsources
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} -> displayname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} -> dllname
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} -> nogpolistchanges
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} -> processgrouppolicy
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} -> processgrouppolicyex
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} -> requiressuccessfulregistry
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> hilfeassistent
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> tsinternetuser
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> sqlagentcmdexec
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> netshowservices
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> helpassistant
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> iwam_
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> iusr_
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> vusr_
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList -> aspnet
--------------------------------------------------------------------------------------------------------
Files: 0/258891
Registry items: 113/573397
Processes: 0/54
Scan time: 00:18:10
--------------------------------------------------------------------------------------------------------
Active processes:
- ksqoalfc.exe (PID 1460) (Avira AntiRootkit Tool)
- update.exe (PID 2540)
- avnotify.exe (PID 3576)
- System (PID 4)
- smss.exe (PID 636)
- csrss.exe (PID 872)
- winlogon.exe (PID 904)
- services.exe (PID 952)
- lsass.exe (PID 964)
- ati2evxx.exe (PID 1124)
- svchost.exe (PID 1140)
- svchost.exe (PID 1212)
- svchost.exe (PID 1356)
- InCDsrv.exe (PID 1376)
- ati2evxx.exe (PID 1452)
- svchost.exe (PID 1524)
- svchost.exe (PID 1648)
- svchost.exe (PID 1728)
- spoolsv.exe (PID 1784)
- sched.exe (PID 1832)
- svchost.exe (PID 1912)
- avguard.exe (PID 1960)
- AOLacsd.exe (PID 1972)
- AppleMobileDeviceService.exe (PID 1988)
- bgsvcgen.exe (PID 2044)
- mDNSResponder.exe (PID 144)
- ICQ Service.exe (PID 192)
- svchost.exe (PID 544)
- wanmpsvc.exe (PID 664)
- alg.exe (PID 1392)
- explorer.exe (PID 2272)
- SOUNDMAN.EXE (PID 2556)
- InCD.exe (PID 2712)
- Application Launcher.exe (PID 2772)
- QTTask.exe (PID 2788)
- realplay.exe (PID 2796)
- SweetIM.exe (PID 2804)
- avgnt.exe (PID 2820)
- ctfmon.exe (PID 2828)
- MOM.exe (PID 2840)
- hpotdd01.exe (PID 2892)
- WiFiN.exe (PID 2916)
- aolsoftware.exe (PID 3112)
- CCC.exe (PID 3532)
- OIS.EXE (PID 3776)
- Generic.exe (PID 3344)
- epmworker.exe (PID 3260)
- iexplore.exe (PID 3440)
- iexplore.exe (PID 3608)
- iexplore.exe (PID 3296)
- iexplore.exe (PID 2596)
- iexplore.exe (PID 2524)
- notepad.exe (PID 276)
- avirarkd.exe (PID 1876)
========================================================================================================
- Scan finished Donnerstag, 7. Januar 2010 - 17:07:37
========================================================================================================
Hab es gestern auch noch mit GMER versucht und gescannt, dann aber nach einiger zeit abgebrochen, da es sehr langsam voran ging. Hier der Report: Code:
ATTFilter GMER 1.0.15.14966 - h******w.gmer.net
Rootkit scan 2010-01-07 053009
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
SSDT F7C8D106 ZwCreateKey
SSDT F7C8D0FC ZwCreateThread
SSDT F7C8D10B ZwDeleteKey
SSDT F7C8D115 ZwDeleteValueKey
SSDT F7C8D11A ZwLoadKey
SSDT F7C8D0E8 ZwOpenProcess
SSDT F7C8D0ED ZwOpenThread
SSDT F7C8D124 ZwReplaceKey
SSDT F7C8D11F ZwRestoreKey
SSDT F7C8D110 ZwSetValueKey
SSDT F7C8D0F7 ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2514 80501404 4 Bytes CALL 5147DCD9
---- User IATEAT - GMER 1.0.15 ----
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32msvcrt.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32WS2_32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32psapi.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32psapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32userenv.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32userenv.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32userenv.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32userenv.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOLACSAOLAcsd.exe[716] @ GWINDOWSsystem32iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32MSVCRT.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32MSVCRT.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32shell32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32shell32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32shell32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32shell32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32shell32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
IAT GProgrammeGemeinsame DateienAOL1176588086eeaolsoftware.exe[876] @ GWINDOWSsystem32Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] GProgrammeGemeinsame DateienAOLAOLDiagtbdiag.dll (AOL DiagnosticsAOL LLC)
---- Devices - GMER 1.0.15 ----
Device pci.sys (NT-Plug & Play PCI-EnumeratorMicrosoft Corporation)
---- EOF - GMER 1.0.15 ----
Die Datei 'G:\System Volume Information\_restore{BACF4CAC-049B-4C5F-863E-E8BDEFFFEB3C}\RP22\A0003150.exe' enthielt einen Virus oder unerwünschtes Programm 'TR/FraudPack.aebj' [trojan]. Durchgeführte Aktion(en): Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4b751eed.qua' verschoben! Der normale Virenscanner von AV findet keine Viren. Bitte um schnelle Hilfe! Danke im voraus! |
| | #3 |
| | Av AntiRootkit scan - gefährlicher Fund? Also hab jetzt die neuste Version von GMER 3 Stunden laufen lassen.. bei den Programmen war kein vorwärts mehr.. aber ich denke ich hab bereits fast alles im Report:
__________________Code:
ATTFilter GMER 1.0.15.15281 - h***://w**.gmer.net
Rootkit scan 2010-01-07 21:05:19
Windows 5.1.2600 Service Pack 2
Running: n211nvn0.exe; Driver: G:\DOKUME~1\******\LOKALE~1\Temp\kxnyqkoc.sys
---- System - GMER 1.0.15 ----
SSDT F7C18D9E ZwCreateKey
SSDT F7C18D94 ZwCreateThread
SSDT F7C18DA3 ZwDeleteKey
SSDT F7C18DAD ZwDeleteValueKey
SSDT F7C18DB2 ZwLoadKey
SSDT F7C18D80 ZwOpenProcess
SSDT F7C18D85 ZwOpenThread
SSDT F7C18DBC ZwReplaceKey
SSDT F7C18DB7 ZwRestoreKey
SSDT F7C18DA8 ZwSetValueKey
SSDT F7C18D8F ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text G:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF6212000, 0x187662, 0xE8000020]
.text G:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xA7D48300, 0x22020, 0xE8000020]
.text G:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xF7994300, 0x1B7E, 0xE8000020]
---- User IAT/EAT - GMER 1.0.15 ----
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\psapi.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\psapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\userenv.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe[1972] @ G:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\shell32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe[3112] @ G:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] G:\Programme\Gemeinsame Dateien\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
---- Devices - GMER 1.0.15 ----
Device pci.sys (NT-Plug & Play PCI-Enumerator/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@AutoRestartShell 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@DefaultDomainName ******-******
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@DefaultUserName ******
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@LegalNoticeCaption
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@LegalNoticeText
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@PowerdownAfterShutdown 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@ReportBootOk 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@Shell Explorer.exe
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@ShutdownWithoutLogon 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@System
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit G:\WINDOWS\system32\userinit.exe,
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@VmApplet rundll32 shell32,Control_RunDLL "sysdm.cpl"
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@SfcQuota -1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@allocatecdroms 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@allocatedasd 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@allocatefloppies 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@cachedlogonscount 10
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@forceunlocklogon 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@passwordexpirywarning 14
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@scremoveoption 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@AllowMultipleTSSessions 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@UIHost logonui.exe
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@LogonType 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@Background 0 0 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@DebugServerCommand no
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@SFCDisable 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@WinStationsDisabled 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@HibernationPreviouslyEnabled 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@ShowLogonOptions 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@AltDefaultUserName ******
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@AltDefaultDomainName ******-******
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@ Microsoft-Datentr?gerkontingent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoMachinePolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoBackgroundPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@PerUserLocalSettings 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@EnableAsynchronousProcessing 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@DllName dskquota.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@ProcessGroupPolicy ProcessGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@ Internet Explorer Zonemapping
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@DllName G:\WINDOWS\system32\iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@ProcessGroupPolicy ProcessGroupPolicyForZoneMap
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@RequiresSucessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@DisplayName @G:\WINDOWS\system32\iedkcs32.dll.mui,-3051
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@ Internet Explorer User Accelerators
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@DisplayName @G:\WINDOWS\system32\iedkcs32.dll.mui,-3051
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@DllName G:\WINDOWS\system32\iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@ProcessGroupPolicy ProcessGroupPolicyForActivities
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@ProcessGroupPolicyEx ProcessGroupPolicyForActivitiesEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ProcessGroupPolicy SceProcessSecurityPolicyGPO
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@GenerateGroupPolicy SceGenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ExtensionRsopPlanningDebugLevel 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ProcessGroupPolicyEx SceProcessSecurityPolicyGPOEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ExtensionDebugLevel 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@DllName scecli.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ Security
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@EnableAsynchronousProcessing 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@MaxNoGPOListChangesInterval 960
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@ProcessGroupPolicyEx ProcessGroupPolicyEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@GenerateGroupPolicy GenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@ProcessGroupPolicy ProcessGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@DllName G:\WINDOWS\system32\iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@ Internet Explorer Branding
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoMachinePolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@DisplayName @G:\WINDOWS\system32\iedkcs32.dll.mui,-3014
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@ProcessGroupPolicy SceProcessEFSRecoveryGPO
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@DllName scecli.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@ EFS recovery
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@ Microsoft Offline Files
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@DllName %SystemRoot%\System32\cscui.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@EnableAsynchronousProcessing 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoGPOListChanges 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoMachinePolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoSlowLink 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@PerUserLocalSettings 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@ProcessGroupPolicy ProcessGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@ Softwareinstallation
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@DllName appmgmts.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@ProcessGroupPolicyEx ProcessGroupPolicyObjectsEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@GenerateGroupPolicy GenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@RequiresSucessfulRegistry 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@PerUserLocalSettings 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@EventSources (Application Management,Application)?(MsiInstaller,Application)?
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@ Internet Explorer Machine Accelerators
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@DisplayName @G:\WINDOWS\system32\iedkcs32.dll.mui,-3051
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@DllName G:\WINDOWS\system32\iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@ProcessGroupPolicy ProcessGroupPolicyForActivities
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@ProcessGroupPolicyEx ProcessGroupPolicyForActivitiesEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@DLLName Ati2evxx.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Asynchronous 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Impersonate 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Lock AtiLockEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Logoff AtiLogoffEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Logon AtiLogonEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Disconnect AtiDisConnectEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Reconnect AtiReConnectEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Safe 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Shutdown AtiShutdownEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@StartScreenSaver AtiStartScreenSaverEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@StartShell AtiStartShellEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Startup AtiStartupEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@StopScreenSaver AtiStopScreenSaverEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@Unlock AtiUnLockEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain@Asynchronous 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain@Impersonate 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain@DllName crypt32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain@Logoff ChainWlxLogoffEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet@Asynchronous 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet@Impersonate 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet@DllName cryptnet.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet@Logoff CryptnetWlxLogoffEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@DLLName cscdll.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@Logon WinlogonLogonEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@Logoff WinlogonLogoffEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@ScreenSaver WinlogonScreenSaverEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@Startup WinlogonStartupEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@Shutdown WinlogonShutdownEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@StartShell WinlogonStartShellEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@Impersonate 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll@Asynchronous 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@DLLName wlnotify.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Logon SCardStartCertProp
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Logoff SCardStopCertProp
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Lock SCardSuspendCertProp
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Unlock SCardResumeCertProp
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Enabled 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Impersonate 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp@Asynchronous 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule@Asynchronous 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule@DllName wlnotify.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule@Impersonate 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule@StartShell SchedStartShell
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule@Logoff SchedEventLogOff
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy@Logoff WLEventLogoff
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy@Impersonate 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy@Asynchronous 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy@DllName sclgntfy.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@DLLName WlNotify.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Lock SensLockEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Logon SensLogonEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Logoff SensLogoffEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Safe 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@MaxWait 600
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@StartScreenSaver SensStartScreenSaverEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@StopScreenSaver SensStopScreenSaverEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Startup SensStartupEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Shutdown SensShutdownEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@StartShell SensStartShellEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@PostShell SensPostShellEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Disconnect SensDisconnectEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Reconnect SensReconnectEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Unlock SensUnlockEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Impersonate 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn@Asynchronous 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Asynchronous 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@DllName wlnotify.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Impersonate 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Logoff TSEventLogoff
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Logon TSEventLogon
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@PostShell TSEventPostShell
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Shutdown TSEventShutdown
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@StartShell TSEventStartShell
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Startup TSEventStartup
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@MaxWait 600
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Reconnect TSEventReconnect
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv@Disconnect TSEventDisconnect
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Logon WLEventLogon
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Logoff WLEventLogoff
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Startup WLEventStartup
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Shutdown WLEventShutdown
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@StartScreenSaver WLEventStartScreenSaver
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@StopScreenSaver WLEventStopScreenSaver
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Lock WLEventLock
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Unlock WLEventUnlock
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@StartShell WLEventStartShell
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@PostShell WLEventPostShell
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Disconnect WLEventDisconnect
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Reconnect WLEventReconnect
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Impersonate 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Asynchronous 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@SafeMode 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@MaxWait -1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@DllName WgaLogon.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@Event 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@EulaAccepted 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings@Data 0x01 0x00 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon@DLLName wlnotify.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon@Logon RegisterTicketExpiredNotificationEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon@Logoff UnregisterTicketExpiredNotificationEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon@Impersonate 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon@Asynchronous 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SCLogon
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@Hilfeassistent 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@TsInternetUser 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@SQLAgentCmdExec 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@NetShowServices 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@HelpAssistant 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@IWAM_ 65536
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@IUSR_ 65536
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@VUSR_ 65536
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@ASPNET 0
---- EOF - GMER 1.0.15 ----
Bei Av AntiRootkit Tool war alles rot. Sry kenn mich damit nicht so gut aus. Also sind die Einträge i. O.? Sind ja viele dabei die schon av gefunden hatte... |
| | #4 |
| | Av AntiRootkit scan - gefährlicher Fund? Kann mir jemand sagen ob in dem Report nun gefährliche Rootkits drin sind? Oder soll ich den Beitrag in ein anderes Forum posten? |
| | #5 | |
![]() ![]() ![]() ![]() | Av AntiRootkit scan - gefährlicher Fund?Zitat:
__________________ MfG Ralf |
| | #6 |
| | Av AntiRootkit scan - gefährlicher Fund? Okay sry. Hier der Report: Code:
ATTFilter Malwarebytes' Anti-Malware 1.44
Datenbank Version: 3519
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
08.01.2010 22:18:33
mbam-log-2010-01-08 (22-18-28).txt
Scan-Methode: Vollständiger Scan (G:\|)
Durchsuchte Objekte: 357437
Laufzeit: 2 hour(s), 33 minute(s), 10 second(s)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 3
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 3
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> No action taken.
Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
G:\Dokumente und Einstellungen\******\Lokale Einstellungen\Temp\87.tmp (Backdoor.Bot) -> No action taken.
G:\WINDOWS\system32\qgjo.ijo (Backdoor.Bot) -> No action taken.
G:\Programme\ICQToolbar\toolbaru.dll (Trojan.BHO) -> No action taken.
|
| | #8 |
| | Av AntiRootkit scan - gefährlicher Fund? Okay werde ich gleich machen. Kannst du mir sagen was die Viren, oder was auch immer es ist anrichten oder vielleicht schon angerichtet haben? Und mit welchen Folgen ich rechnen muss? |
| | #9 |
![]() ![]() ![]() ![]() | Av AntiRootkit scan - gefährlicher Fund? Mit allem! Passworte klauen, Spam versenden, DDos Attacken fahren. Bei so viel neuer Malware muss man immer vom schlimmsten ausgehen...
__________________ MfG Ralf |
| | #10 |
| | Av AntiRootkit scan - gefährlicher Fund? Hier der RSIT Report Code:
ATTFilter Logfile of random's system information tool 1.06 (written by random/random) Run by ****** at 2010-01-09 13:36:03 Microsoft Windows XP Home Edition Service Pack 2 System drive G: has 40 GB (21%) free of 191 GB Total RAM: 1023 MB (54% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:36:18, on 09.01.2010 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: G:\WINDOWS\System32\smss.exe G:\WINDOWS\system32\winlogon.exe G:\WINDOWS\system32\services.exe G:\WINDOWS\system32\lsass.exe G:\WINDOWS\system32\Ati2evxx.exe G:\WINDOWS\system32\svchost.exe G:\WINDOWS\System32\svchost.exe G:\Programme\Ahead\InCD\InCDsrv.exe G:\WINDOWS\system32\svchost.exe G:\WINDOWS\system32\spoolsv.exe G:\Programme\Avira\AntiVir Desktop\sched.exe G:\Programme\Avira\AntiVir Desktop\avguard.exe G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe G:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe G:\WINDOWS\system32\bgsvcgen.exe G:\Programme\Bonjour\mDNSResponder.exe G:\Programme\ICQ6Toolbar\ICQ Service.exe G:\WINDOWS\system32\svchost.exe G:\WINDOWS\wanmpsvc.exe G:\WINDOWS\system32\Ati2evxx.exe G:\WINDOWS\Explorer.EXE G:\WINDOWS\SOUNDMAN.EXE G:\Programme\Ahead\InCD\InCD.exe G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe G:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe G:\Programme\QuickTime\qttask.exe G:\Programme\Real\RealPlayer\RealPlay.exe G:\Programme\SweetIM\Messenger\SweetIM.exe G:\Programme\ATI Technologies\ATI.ACE\Core-Static\MOM.exe G:\Programme\Avira\AntiVir Desktop\avgnt.exe G:\WINDOWS\system32\ctfmon.exe G:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe G:\Programme\Hercules\WiFiStation\WiFiN.exe G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\aolsoftware.exe G:\Programme\ATI Technologies\ATI.ACE\Core-Static\ccc.exe G:\Dokumente und Einstellungen\******\Desktop\RSIT.exe G:\Programme\trend micro\******.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - G:\Programme\ICQ6Toolbar\ICQToolBar.dll R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - G:\Programme\SweetIM\Toolbars\Internet Explorer\mgHelper.dll R3 - URLSearchHook: (no name) - - (no file) O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - G:\PROGRA~1\ICQTOO~1\toolbaru.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Programme\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - G:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - G:\Programme\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - G:\Programme\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - G:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - G:\Programme\ICQ6Toolbar\ICQToolBar.dll O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - G:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - G:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [InCD] G:\Programme\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [AOLDialer] G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "G:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [StartCCC] "G:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" O4 - HKLM\..\Run: [QuickTime Task] "G:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [RealTray] G:\Programme\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [SweetIM] G:\Programme\SweetIM\Messenger\SweetIM.exe O4 - HKLM\..\Run: [Google Desktop Search] "G:\Programme\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [avgnt] "G:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [OM_Monitor] G:\Programme\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart O4 - HKCU\..\RunOnce: [Shockwave Updater] G:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; SIMBAR={6D66A990-DA01-11DD-8E2B-00038A000015}; GTB6; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://de.games.emule.com/spongebob-flip-or-flop/" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: hpoddt01.exe.lnk = ? O4 - Global Startup: WiFi Station.lnk = G:\Programme\Hercules\WiFiStation\WiFiN.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://G:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://G:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Programme\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Programme\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - G:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - G:\Programme\ICQ6.5\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - G:\Programme\ICQ6.5\ICQ.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Programme\Messenger\msmsgs.exe O12 - Plugin for .spop: G:\Programme\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1109841254421 O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - G:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: G:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - G:\Programme\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - G:\Programme\Avira\AntiVir Desktop\avguard.exe O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe O23 - Service: Apple Mobile Device - Apple Inc. - G:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - G:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - G:\WINDOWS\system32\ati2sgag.exe O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - G:\WINDOWS\system32\bgsvcgen.exe O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - G:\Programme\Bonjour\mDNSResponder.exe O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - G:\Programme\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Software Updater (gusvc) - Google - G:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: ICQ Service - Unknown owner - G:\Programme\ICQ6Toolbar\ICQ Service.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - G:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - G:\Programme\Ahead\InCD\InCDsrv.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - G:\Programme\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - G:\WINDOWS\system32\HPZipm12.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - G:\WINDOWS\wanmpsvc.exe O24 - Desktop Component 0: (no name) - file:///G:/DOKUME~1/******/LOKALE~1/Temp/msohtml1/01/clip_image002.jpg O24 - Desktop Component 1: (no name) - file:///G:/DOKUME~1/******/LOKALE~1/Temp/msohtml1/01/clip_image001.jpg -- End of file - 10099 bytes ======Scheduled tasks folder====== G:\WINDOWS\tasks\AppleSoftwareUpdate.job G:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1110399772.job G:\WINDOWS\tasks\User_Feed_Synchronization-{11AC6B45-AAD3-422F-8F9C-A720B6FDBF0C}.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}] XTTBPos00 Class - G:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Adobe PDF Reader Link Helper - G:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] SSVHelper Class - G:\Programme\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - G:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-09 256112] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] Google Toolbar Notifier BHO - G:\Programme\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2009-09-09 761840] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}] Google Dictionary Compression sdch - G:\Programme\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-09-09 458736] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}] SweetIM Toolbar Helper - G:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2008-10-08 1172792] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - G:\Programme\ICQ6Toolbar\ICQToolBar.dll [2009-06-01 962808] {EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - G:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2008-10-08 1172792] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - G:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-09 256112] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "SoundMan"=G:\WINDOWS\SOUNDMAN.EXE [2004-11-15 77824] "InCD"=G:\Programme\Ahead\InCD\InCD.exe [2004-09-07 1400944] "AOLDialer"=G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe [2007-06-21 70952] "Sony Ericsson PC Suite"=G:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [2006-11-24 487424] "StartCCC"=G:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440] "QuickTime Task"=G:\Programme\QuickTime\qttask.exe [2008-05-27 413696] "RealTray"=G:\Programme\Real\RealPlayer\RealPlay.exe [2005-03-09 26112] "SweetIM"=G:\Programme\SweetIM\Messenger\SweetIM.exe [2008-12-02 111928] "Google Desktop Search"=G:\Programme\Google\Google Desktop Search\GoogleDesktop.exe [2009-05-31 1838592] "avgnt"=G:\Programme\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"=G:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360] "OM_Monitor"=G:\Programme\OLYMPUS\OLYMPUS Master\Monitor.exe [2006-05-16 57344] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Shockwave Updater"=G:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE [2008-11-24 460216] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] G:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier] G:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-07-22 116040] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager] G:\Programme\Gemeinsame Dateien\AOL\1176588086\ee\AOLSoftware.exe [2006-11-17 50736] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] G:\Programme\iTunes\iTunesHelper.exe [2008-07-30 289064] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] G:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor] G:\Programme\OLYMPUS\OLYMPUS Master\FirstStart.exe [2006-05-16 40960] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Profiler] G:\Programme\Saitek\Software\Profiler.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] G:\Programme\QuickTime\QTTask.exe [2008-05-27 413696] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] G:\Programme\Real\RealPlayer\RealPlay.exe [2005-03-09 26112] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] G:\Programme\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [2003-12-08 32768] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiMfd] G:\Programme\Saitek\Software\SaiMfd.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] G:\Programme\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TerraTec Remote Control] G:\Programme\TerraTec\Cinergy 400 TV\TTTVRC.exe [2002-05-21 204800] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] G:\Programme\Winamp\winampa.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\G:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^AOL 9.0 Tray-Symbol.lnk] G:\PROGRA~1\AOL9~1.0\aoltray.exe [2004-05-10 156784] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\G:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^hp psc 1000 series.lnk] G:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpohmr08.exe [2003-04-06 147456] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\G:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^VIA RAID TOOL.lnk] G:\PROGRA~1\VIA\RAID\RAID_T~1.EXE [2004-07-14 585728] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\G:^Dokumente und Einstellungen^******^Startmenü^Programme^Autostart^hamachi.lnk] G:\PROGRA~1\Hamachi\hamachi.exe [2008-01-07 624416] G:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart hpoddt01.exe.lnk - G:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe WiFi Station.lnk - G:\Programme\Hercules\WiFiStation\WiFiN.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLS"="G:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent] G:\WINDOWS\system32\Ati2evxx.dll [2008-02-26 126976] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] G:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - G:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveAutoRun"=FFFFFFFF [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "HonorAutoRunSetting"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe"="G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL" "G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe"="G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe:*:Enabled:AOL" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "G:\Programme\EA GAMES\Need for Speed Underground 2\speed2.exe"="G:\Programme\EA GAMES\Need for Speed Underground 2\speed2.exe:*:Enabled:speed2" "G:\Programme\Firefly Studios\CivCity Rom\CivCity Rome.exe"="G:\Programme\Firefly Studios\CivCity Rom\CivCity Rome.exe:*:Enabled:CivCity Rome" "G:\Programme\Gemeinsame Dateien\aol\1176588086\ee\aolsoftware.exe"="G:\Programme\Gemeinsame Dateien\aol\1176588086\ee\aolsoftware.exe:*:Enabled:AOL Shared Components" "G:\Programme\ICQ6\ICQ.exe"="G:\Programme\ICQ6\ICQ.exe:*:Enabled:ICQ6" "G:\Programme\Counter-Strike 1.6\hl.exe"="G:\Programme\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Internet Explorer\iexplore.exe"="G:\Programme\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer" "G:\Programme\Hamachi\hamachi.exe"="G:\Programme\Hamachi\hamachi.exe:*:Enabled:Hamachi Client" "G:\Programme\Counter-Strike 1.6\hlds.exe"="G:\Programme\Counter-Strike 1.6\hlds.exe:*:Enabled:HLDS Launcher" "G:\Programme\MotoGP\motogp.exe"="G:\Programme\MotoGP\motogp.exe:*:Enabled:motogp" "G:\Programme\AOL 9.0\waol.exe"="G:\Programme\AOL 9.0\waol.exe:*:Enabled:AOL" "G:\Programme\TrackMania Nations ESWC\TmNationsESWC.exe"="G:\Programme\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC" "G:\Programme\Steam\steamapps\mycs1375\counter-strike\hl.exe"="G:\Programme\Steam\steamapps\mycs1375\counter-strike\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Steam\Steam.exe"="G:\Programme\Steam\Steam.exe:*:Enabled:Steam" "G:\Programme\Steam\steamapps\mycs1375\day of defeat\hl.exe"="G:\Programme\Steam\steamapps\mycs1375\day of defeat\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Steam\steamapps\mycs1375\dedicated server\hlds.exe"="G:\Programme\Steam\steamapps\mycs1375\dedicated server\hlds.exe:*:Enabled:HLDS Launcher" "G:\Programme\Steam\steamapps\mycs1375\deathmatch classic\hl.exe"="G:\Programme\Steam\steamapps\mycs1375\deathmatch classic\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Steam\steamapps\mycs1375\opposing force\hl.exe"="G:\Programme\Steam\steamapps\mycs1375\opposing force\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Steam\steamapps\mycs1375\ricochet\hl.exe"="G:\Programme\Steam\steamapps\mycs1375\ricochet\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Steam\steamapps\mycs1375\half-life\hl.exe"="G:\Programme\Steam\steamapps\mycs1375\half-life\hl.exe:*:Enabled:Half-Life Launcher" "G:\WINDOWS\system32\dpvsetup.exe"="G:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test" "G:\WINDOWS\system32\rundll32.exe"="G:\WINDOWS\system32\rundll32.exe:*:Enabled:Eine DLL-Datei als Anwendung ausführen" "G:\Programme\Steam\steamapps\vinamilk\counter-strike\hl.exe"="G:\Programme\Steam\steamapps\vinamilk\counter-strike\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Zattoo\zattood.exe"="G:\Programme\Zattoo\zattood.exe:*:Enabled:zattood" "G:\Programme\Zattoo\Zattoo2.exe"="G:\Programme\Zattoo\Zattoo2.exe:*:Enabled: " "G:\Programme\Age of Empires II\age2_x1\age2_x1.exe"="G:\Programme\Age of Empires II\age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion" "G:\Programme\Metin2_Germany\metin2.bin"="G:\Programme\Metin2_Germany\metin2.bin:*:Enabled:metin2" "G:\Programme\Zattoo\Zattoo.exe"="G:\Programme\Zattoo\Zattoo.exe:*:Enabled: " "G:\Programme\Bonjour\mDNSResponder.exe"="G:\Programme\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour" "G:\Programme\iTunes\iTunes.exe"="G:\Programme\iTunes\iTunes.exe:*:Enabled:iTunes" "G:\Programme\Reallusion\CrazyTalk for Skype\CT4Skype.exe"="G:\Programme\Reallusion\CrazyTalk for Skype\CT4Skype.exe:*:Enabled:CrazyTalk" "G:\Programme\Steam\steamapps\common\trackmania nations forever\TmForever.exe"="G:\Programme\Steam\steamapps\common\trackmania nations forever\TmForever.exe:*:Enabled:TrackMania Nations Forever" "G:\Programme\Steam\steamapps\common\trackmania nations forever\TmForeverLauncher.exe"="G:\Programme\Steam\steamapps\common\trackmania nations forever\TmForeverLauncher.exe:*:Enabled:TrackMania Nations Forever" "G:\Programme\Counter-Strike 1.6 Neu\hl.exe"="G:\Programme\Counter-Strike 1.6 Neu\hl.exe:*:Enabled:Half-Life Launcher" "G:\Programme\Counter-Strike 1.6 Neu\hlds.exe"="G:\Programme\Counter-Strike 1.6 Neu\hlds.exe:*:Enabled:HLDS Launcher" "G:\Programme\ICQ6.5\ICQ.exe"="G:\Programme\ICQ6.5\ICQ.exe:*:Enabled:ICQ6" "G:\Programme\Mozilla Firefox\firefox.exe"="G:\Programme\Mozilla Firefox\firefox.exe:*:Enabled:Firefox" "G:\Programme\Real\RealPlayer\realplay.exe"="G:\Programme\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer" "H:\Left_4_Dead\left 4 dead\left4dead.exe"="H:\Left_4_Dead\left 4 dead\left4dead.exe:*:Disabled:left4dead" "G:\Programme\Left_4_Dead\left 4 dead\left4dead.exe"="G:\Programme\Left_4_Dead\left 4 dead\left4dead.exe:*:Disabled:left4dead" "G:\Programme\Opera\opera.exe"="G:\Programme\Opera\opera.exe:*:Enabled:Opera Internet Browser" "G:\Programme\Skype\Phone\Skype.exe"="G:\Programme\Skype\Phone\Skype.exe:*:Enabled:Skype" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe"="G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL" "G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe"="G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe:*:Enabled:AOL" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "G:\Programme\AOL 9.0\waol.exe"="G:\Programme\AOL 9.0\waol.exe:*:Enabled:AOL" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bae47d43-f6f1-11de-90cc-0008d390423f}] shell\AutoRun\command - H:\USBAutoRun.exe ======List of files/folders created in the last 1 months====== 2010-01-09 13:36:03 ----D---- G:\rsit 2010-01-09 13:36:03 ----D---- G:\Programme\trend micro 2010-01-08 18:35:49 ----D---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\Malwarebytes 2010-01-08 18:35:26 ----D---- G:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes 2010-01-08 18:35:22 ----D---- G:\Programme\Malwarebytes' Anti-Malware 2010-01-01 18:32:32 ----A---- G:\WINDOWS\Sublock.dll 2010-01-01 18:32:32 ----A---- G:\WINDOWS\LGMobileDL.dll 2010-01-01 18:32:32 ----A---- G:\WINDOWS\Imei_dll.dll 2010-01-01 18:32:32 ----A---- G:\WINDOWS\esn.dll 2010-01-01 18:32:32 ----A---- G:\WINDOWS\AuthDll.dll 2010-01-01 18:21:11 ----A---- G:\WINDOWS\system32\msxml4a.dll 2010-01-01 18:21:11 ----A---- G:\WINDOWS\system32\lgAxconfig.ini 2010-01-01 18:21:11 ----A---- G:\WINDOWS\system32\CommonDL.dll 2010-01-01 18:21:06 ----D---- G:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LGMOBILEAX 2010-01-01 18:09:20 ----A---- G:\WINDOWS\system32\NMSDVDXU.dll 2010-01-01 18:09:10 ----HD---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\{D94BA408-F110-488B-A65E-3AE7945F79E6} 2010-01-01 17:44:14 ----D---- G:\Sounds 2010-01-01 17:22:21 ----D---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\LG Electronics 2010-01-01 17:21:36 ----D---- G:\Programme\LG Electronics 2009-12-19 14:57:04 ----D---- G:\Programme\Maxima-5.20.1 2009-12-16 22:12:37 ----D---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\Opera 2009-12-16 22:12:23 ----D---- G:\Programme\Opera 2009-12-14 10:24:56 ----A---- G:\WINDOWS\ntbtlog.txt ======List of files/folders modified in the last 1 months====== 2010-01-09 13:36:11 ----D---- G:\WINDOWS\Prefetch 2010-01-09 13:36:03 ----D---- G:\Programme 2010-01-09 13:33:27 ----A---- G:\WINDOWS\RTacDbg.txt 2010-01-09 13:33:22 ----D---- G:\WINDOWS 2010-01-09 13:23:59 ----D---- G:\WINDOWS\Temp 2010-01-09 12:58:38 ----A---- G:\WINDOWS\NeroDigital.ini 2010-01-09 11:43:31 ----D---- G:\WINDOWS\system32\CatRoot2 2010-01-09 02:08:37 ----A---- G:\WINDOWS\SchedLgU.Txt 2010-01-08 23:09:38 ----D---- G:\Programme\Mozilla Firefox 2010-01-08 21:17:13 ----D---- G:\WINDOWS\system32\drivers 2010-01-08 19:48:24 ----D---- G:\WINDOWS\system32\config 2010-01-08 13:58:48 ----HD---- G:\Programme\InstallShield Installation Information 2010-01-08 13:58:47 ----D---- G:\WINDOWS\system32 2010-01-07 17:57:10 ----D---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\Skype 2010-01-07 17:42:39 ----D---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\skypePM 2010-01-07 00:51:27 ----SHD---- G:\System Volume Information 2010-01-07 00:51:27 ----D---- G:\WINDOWS\system32\Restore 2010-01-06 18:19:26 ----D---- G:\Dokumente und Einstellungen\******\Anwendungsdaten\ICQ 2010-01-04 23:33:26 ----D---- G:\Programme\Steam 2010-01-01 22:32:26 ----D---- G:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TrackMania 2010-01-01 18:14:43 ----D---- G:\WINDOWS\system32\CatRoot 2010-01-01 18:12:51 ----HD---- G:\WINDOWS\inf 2010-01-01 18:12:45 ----SHD---- G:\WINDOWS\Installer 2010-01-01 18:11:18 ----A---- G:\WINDOWS\system32\PerfStringBackup.INI 2010-01-01 17:45:54 ----SD---- G:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft 2009-12-29 21:46:29 ----D---- G:\Programme\ICQ6.5 2009-12-15 00:11:12 ----RSHDC---- G:\WINDOWS\system32\dllcache 2009-12-15 00:11:10 ----HDC---- G:\WINDOWS\$NtUninstallKB970430$ 2009-12-15 00:11:05 ----A---- G:\WINDOWS\imsins.BAK 2009-12-15 00:11:01 ----HDC---- G:\WINDOWS\$NtUninstallKB974318$ 2009-12-15 00:10:47 ----D---- G:\Programme\Internet Explorer 2009-12-15 00:10:14 ----HDC---- G:\WINDOWS\$NtUninstallKB973904$ 2009-12-15 00:10:06 ----HDC---- G:\WINDOWS\$NtUninstallKB974392$ 2009-12-15 00:09:55 ----HDC---- G:\WINDOWS\$NtUninstallKB971737$ 2009-12-14 18:31:29 ----D---- G:\WINDOWS\system32\wbem 2009-12-14 18:31:28 ----D---- G:\WINDOWS\Registration 2009-12-14 10:26:22 ----D---- G:\Dokumente und Einstellungen ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 AFS2K;AFS2k; G:\WINDOWS\system32\drivers\AFS2K.sys [2005-03-09 82380] R1 AmdK8;AMD Athlon64 Processor Driver; G:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-05-08 35840] R1 avgio;avgio; \??\G:\Programme\Avira\AntiVir Desktop\avgio.sys [] R1 avipbb;avipbb; G:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104] R1 BUFADPT;BUFADPT; \??\G:\WINDOWS\system32\BUFADPT.SYS [] R1 cdrbsdrv;cdrbsdrv; G:\WINDOWS\system32\drivers\cdrbsdrv.sys [2005-05-10 32256] R1 InCDPass;InCDPass; G:\WINDOWS\System32\DRIVERS\InCDPass.sys [2004-09-07 28544] R1 ssmdrv;ssmdrv; G:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520] R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; G:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-11-28 21035] R2 ASCTRM;ASCTRM; G:\WINDOWS\system32\drivers\ASCTRM.sys [2005-03-09 8552] R2 atksgt;atksgt; G:\WINDOWS\system32\DRIVERS\atksgt.sys [2007-07-03 165376] R2 avgntflt;avgntflt; G:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-12-07 56816] R2 lirsgt;lirsgt; G:\WINDOWS\system32\DRIVERS\lirsgt.sys [2007-07-03 18048] R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); G:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-11-17 2297664] R3 Arp1394;1394-ARP-Clientprotokoll; G:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800] R3 ati2mtag;ati2mtag; G:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-02-26 2863616] R3 Cap7134;Cinergy 400 TV Capture; G:\WINDOWS\system32\DRIVERS\Cap7134.sys [2002-02-12 419584] R3 GEARAspiWDM;GEAR CDRom Filter; G:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2008-01-29 16168] R3 hamachi;Hamachi Network Interface; G:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-01-07 25280] R3 HidUsb;Microsoft HID Class-Treiber; G:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600] R3 HPZid412;IEEE-1284.4 Driver HPZid412; G:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-03-09 51024] R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; G:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-03-09 16080] R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; G:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-03-09 21456] R3 LgBttPort;LGE Bluetooth TransPort; G:\WINDOWS\system32\DRIVERS\lgbtport.sys [2009-09-29 12160] R3 lgbusenum;LG Bluetooth Bus Enumerator; G:\WINDOWS\system32\DRIVERS\lgbtbus.sys [2009-09-29 10496] R3 LGVMODEM;LGE Virtual Modem; G:\WINDOWS\system32\DRIVERS\lgvmodem.sys [2009-09-29 12928] R3 MODEMCSA;Unimodem-Datenstromfiltergerät; G:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128] R3 mouhid;Maus-HID-Treiber; G:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-18 12288] R3 NIC1394;1394-Netzwerktreiber; G:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824] R3 pfc;Padus ASPI Shell; G:\WINDOWS\system32\drivers\pfc.sys [2003-12-05 10368] R3 ROOTMODEM;Microsoft Legacy Modem Driver; G:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888] R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver; G:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2004-10-15 71168] R3 RTL8192su;%RTL8192su.DeviceDesc.DispName%; G:\WINDOWS\system32\DRIVERS\RTL8192su.sys [2009-04-23 572800] R3 TTTvTune;Cinergy 400 TV Tuner; G:\WINDOWS\system32\DRIVERS\PhTvTune.sys [2002-02-12 16128] R3 usbccgp;Microsoft Standard-USB-Haupttreiber; G:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616] R3 usbehci;Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller; G:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624] R3 usbhub;USB2-aktivierter Hub; G:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600] R3 usbprint;Microsoft USB-Druckerklasse; G:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856] R3 usbscan;USB-Scannertreiber; G:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104] R3 usbstor;USB-Massenspeichertreiber; G:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496] R3 usbuhci;Miniporttreiber für universellen Microsoft USB-Hostcontroller; G:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480] R3 wanatw;WAN Miniport (ATW); G:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588] R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; G:\WINDOWS\system32\drivers\WmBEnum.sys [2004-04-14 10144] R3 WmXlCore;Logitech WingMan Translation Layer Driver; G:\WINDOWS\system32\drivers\WmXlCore.sys [2004-04-14 44064] R4 InCDfs;InCD File System; G:\WINDOWS\system32\drivers\InCDfs.sys [2004-09-07 91136] S1 hidfltr;HID Filter Driver; G:\WINDOWS\system32\drivers\MWhid.sys [2004-07-22 13300] S1 kbdhid;Tastatur-HID-Treiber; G:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848] S3 CCDECODE;Untertiteldecoder; G:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024] S3 ENTECH;ENTECH; \??\G:\WINDOWS\system32\DRIVERS\ENTECH.SYS [] S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS [] S3 lac97inf;lac97inf; \??\G:\DOKUME~1\********\LOKALE~1\Temp\lac97inf.sys [] S3 MSICPL;MSICPL; \??\F:\install4\MSICPL.sys [] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; G:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504] S3 NABTSFEC;NABTS/FEC VBI-Codec; G:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376] S3 NdisIP;Microsoft TV-/Videoverbindung; G:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880] S3 NTACCESS;NTACCESS; \??\F:\NTACCESS.sys [] S3 SaiH5F0D;SaiH5F0D; G:\WINDOWS\system32\DRIVERS\SaiH5F0D.sys [2005-11-14 176640] S3 SaiMini;SaiMini; G:\WINDOWS\system32\DRIVERS\SaiMini.sys [2005-07-22 13312] S3 SaiNtBus;SaiNtBus; G:\WINDOWS\system32\drivers\SaiBus.sys [2005-07-22 33792] S3 SaiU5F0D;SaiU5F0D; G:\WINDOWS\system32\DRIVERS\SaiU5F0D.sys [2005-11-14 27264] S3 se45bus;Sony Ericsson Device 069 driver (WDM); G:\WINDOWS\system32\DRIVERS\se45bus.sys [2006-11-30 61536] S3 se45mdfl;Sony Ericsson Device 069 USB WMC Modem Filter; G:\WINDOWS\system32\DRIVERS\se45mdfl.sys [2006-11-30 9360] S3 se45mdm;Sony Ericsson Device 069 USB WMC Modem Driver; G:\WINDOWS\system32\DRIVERS\se45mdm.sys [2006-11-30 97088] S3 se45mgmt;Sony Ericsson Device 069 USB WMC Device Management Drivers (WDM); G:\WINDOWS\system32\DRIVERS\se45mgmt.sys [2006-11-30 88624] S3 se45nd5;Sony Ericsson Device 069 USB Ethernet Emulation SEMC45 (NDIS); G:\WINDOWS\system32\DRIVERS\se45nd5.sys [2006-11-30 18704] S3 se45obex;Sony Ericsson Device 069 USB WMC OBEX Interface; G:\WINDOWS\system32\DRIVERS\se45obex.sys [2006-11-30 86432] S3 se45unic;Sony Ericsson Device 069 USB Ethernet Emulation SEMC45 (WDM); G:\WINDOWS\system32\DRIVERS\se45unic.sys [2006-11-30 90800] S3 SetupNTGLM7X;SetupNTGLM7X; \??\F:\NTGLM7X.sys [] S3 SLIP;BDA Slip De-Framer; G:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136] S3 streamip;BDA-IPSink; G:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360] S3 usbbus;LGE Mobile Composite USB Device; G:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2009-08-21 13056] S3 UsbDiag;LGE Mobile USB Serial Port; G:\WINDOWS\system32\DRIVERS\lgusbdiag.sys [2009-08-21 20864] S3 USBModem;LGE Mobile USB Modem; G:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2009-08-21 24960] S3 WLIU2KG125S;BUFFALO WLI-U2-KG125S Wireless LAN Adapter Driver; G:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 12672] S3 WmFilter;Logitech WingMan HID Filter Driver; G:\WINDOWS\system32\drivers\WmFilter.sys [2004-04-14 21280] S3 WmVirHid;Logitech Virtual Hid Device Driver; G:\WINDOWS\system32\drivers\WmVirHid.sys [2004-04-14 5600] S3 WpdUsb;WpdUsb; G:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528] S3 WSTCODEC;World Standard Teletext-Codec; G:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; G:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944] S4 IntelIde;IntelIde; G:\WINDOWS\system32\drivers\IntelIde.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AntiVirSchedulerService;Avira AntiVir Planer; G:\Programme\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289] R2 AntiVirService;Avira AntiVir Guard; G:\Programme\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089] R2 AOL ACS;AOL Connectivity Service; G:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe [2006-10-23 46640] R2 Apple Mobile Device;Apple Mobile Device; G:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-07-22 116040] R2 Ati HotKey Poller;Ati HotKey Poller; G:\WINDOWS\system32\Ati2evxx.exe [2008-02-26 520192] R2 bgsvcgen;B's Recorder GOLD Library General Service; G:\WINDOWS\system32\bgsvcgen.exe [2005-04-30 86016] R2 Bonjour Service;Bonjour-Dienst; G:\Programme\Bonjour\mDNSResponder.exe [2007-07-24 229376] R2 ICQ Service;ICQ Service; G:\Programme\ICQ6Toolbar\ICQ Service.exe [2009-06-01 222968] R2 InCDsrv;InCD Helper; G:\Programme\Ahead\InCD\InCDsrv.exe [2004-09-07 1151090] R2 WANMiniportService;WAN Miniport (ATW) Service; G:\WINDOWS\wanmpsvc.exe [2003-08-27 65536] R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; G:\WINDOWS\system32\svchost.exe [2004-08-04 14336] S2 ATI Smart;ATI Smart; G:\WINDOWS\system32\ati2sgag.exe [2008-02-25 593920] S3 aspnet_state;ASP.NET State Service; G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; g:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104] S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589; G:\Programme\Google\Google Desktop Search\GoogleDesktop.exe [2009-05-31 1838592] S3 gusvc;Google Software Updater; G:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-09 182768] S3 IDriverT;InstallDriver Table Manager; G:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632] S3 idsvc;Windows CardSpace; g:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664] S3 iPod Service;iPod-Dienst; G:\Programme\iPod\bin\iPodService.exe [2008-07-30 532264] S3 ose;Office Source Engine; G:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136] S3 Pml Driver HPZ12;Pml Driver HPZ12; G:\WINDOWS\system32\HPZipm12.exe [2003-03-09 65795] S3 WMPNetworkSvc;Windows Media Player-Netzwerkfreigabedienst; G:\Programme\Windows Media Player\WMPNetwk.exe [2006-10-24 920576] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; g:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096] -----------------EOF----------------- |
| | #11 |
![]() ![]() ![]() ![]() | Av AntiRootkit scan - gefährlicher Fund? Das wichtigste ist Passworte von einem sauberen Rechner aus zu aendern und den infizierten Rechner nicht mehr ins Internet lassen...
__________________ MfG Ralf |
| | #12 |
| | Av AntiRootkit scan - gefährlicher Fund? Kurz eine Frage.. Hab jetzt die Daten auf einer Externen Platte und die mal gescannt und das ist der Report: Code:
ATTFilter Malwarebytes' Anti-Malware 1.44
Datenbank Version: 3519
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
08.01.2010 23:58:54
mbam-log-2010-01-08 (23-58-49).txt
Scan-Methode: Vollständiger Scan (H:\|)
Durchsuchte Objekte: 150920
Laufzeit: 32 minute(s), 32 second(s)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 3
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> No action taken.
Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
G:\Programme\ICQToolbar\toolbaru.dll (Trojan.BHO) -> No action taken.
Ich hab auch noch mal GMER laufen lassen, aber den selben Report bekommen. Ich setze jetzt erstmal das System neu auf. Muss ich noch was bei kopieren meiner Daten zurück auf den Rechner beachten? Scanns? oder evtl mit ubuntu live cd? |
| | #13 |
![]() ![]() ![]() ![]() | Av AntiRootkit scan - gefährlicher Fund? Ein zusaetzlicher Scan der externen, bzw andewren Partitionen ist nicht verkehrt. Wichtig ist auch, keine ausfuehrbaren Programme der externen Datentraeger und Festplatten zu nutzen, diese sollte man aus vertrauenswuerdiger Quelle neu beschaffen!
__________________ MfG Ralf |
| | #14 |
| | Av AntiRootkit scan - gefährlicher Fund? Hallo, habe mein System neu aufgesetz Daten gesichert, Scans ausgeführt etc. . Die Externe war mit großer wahrscheinlichkeit nicht befallen. Habe nur zur neugierde mit avira antirootkit tool erneut gescannt und es kamen so ziemlich die gleichen Ergebnisse. Vermutlich werden diese immer angezeigt. Malwarebytes und das normal Antivir finden bei Scanns hingegen nichts. Vielen Dank für deine Hilfe raman! |
![]() |
| Themen zu Av AntiRootkit scan - gefährlicher Fund? |
| .dll, 1.exe, antirootkittool, antivir, avgnt.exe, avira, ccc.exe, csrss.exe, dll, explorer.exe, icq, iexplore.exe, langsam, logon.exe, lsass.exe, microsoft, mom.exe, namen, neu, notepad.exe, realplay.exe, rootkit, scan, sched.exe, schnelle hilfe, secur, sehr langsam, services.exe, shell32.dll, software, svchost.exe, system volume information, trojan, virus, windows, winlogon, winlogon.exe |