Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: verdacht auf Trojana

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 19.02.2010, 18:36   #2
Marlissa
 
verdacht auf Trojana - Standard

verdacht auf Trojana



Code:
ATTFilter
Logfile of random's system information tool 1.06 (written by random/random)
Run by user at 2010-02-19 18:20:41
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 42 GB (38%) free of 109 GB
Total RAM: 1012 MB (50% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:21:10, on 19.02.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Programme\Gemeinsame Dateien\InterVideo\RegMgr\iviRegMgr.exe
C:\Programme\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programme\SweetIM\Messenger\SweetIM.exe
C:\Programme\Java\jre6\bin\jusched.exe
C:\Programme\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\vsnp2std.exe
C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programme\ManyCam 2.4\ManyCam.exe
C:\Programme\Skype\Phone\Skype.exe
C:\Programme\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkCalRem.exe
C:\WINDOWS\system32\igfxext.exe
C:\Programme\OpenOffice.org 3\program\soffice.exe
C:\Programme\OpenOffice.org 3\program\soffice.bin
C:\DOKUME~1\user\LOKALE~1\Temp\RtkBtMnt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programme\Skype\Plugin Manager\skypePM.exe
C:\Dokumente und Einstellungen\user\Desktop\RSIT.exe
C:\Programme\trend micro\user.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=0&o=xph&d=1108&m=aoa150
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
R3 - URLSearchHook: (no name) -  - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Programme\Realtek\Audio\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [M3000Mnt] Rundll32.exe M3000Rmv.dll ,WinMainRmv /StartStillMnt
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Programme\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [SweetIM] C:\Programme\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Programme\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ManyCam] "C:\Programme\ManyCam 2.4\ManyCam.exe"
O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: WkCalRem.LNK = C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programme\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: Google Sidewiki... - res://C:\Programme\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programme\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programme\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Programme\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Personal - Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Boonty Games - BOONTY - C:\Programme\Gemeinsame Dateien\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Programme\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Programme\Gemeinsame Dateien\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 10329 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Norton Security Scan for user.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\SDMsgUpdate (TE).job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll [2010-01-31 279664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Programme\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-01-31 812528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask.com Toolbar - C:\Programme\Ask.com\GenericAskToolbar.dll [2009-02-26 809864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Programme\Java\jre6\bin\jp2ssv.dll [2009-07-25 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-07-25 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-05-20 1258808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-05-20 1258808]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask.com Toolbar - C:\Programme\Ask.com\GenericAskToolbar.dll [2009-02-26 809864]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll [2010-01-31 279664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"=Alaunch []
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-02-28 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-02-28 166424]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-02-28 137752]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-05-16 16862720]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"AzMixerSel"=C:\Programme\Realtek\Audio\InstallShield\AzMixerSel.exe [2006-07-17 53248]
"SynTPEnh"=C:\Programme\Synaptics\SynTP\SynTPEnh.exe [2008-04-25 1044480]
"Adobe Reader Speed Launcher"=C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2008-04-13 208952]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2008-04-13 59392]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2008-04-13 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2008-04-13 455168]
"M3000Mnt"=M3000Rmv.dll ,WinMainRmv /StartStillMnt []
"LManager"=C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE [2008-05-14 821768]
"eRecoveryService"=C:\Acer\Empowering Technology\eRecovery\eRAgent.exe [2008-05-22 425984]
"avgnt"=C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
"SpywareTerminator"=C:\Programme\Spyware Terminator\SpywareTerminatorShield.exe []
"SweetIM"=C:\Programme\SweetIM\Messenger\SweetIM.exe [2009-05-20 111928]
"SunJavaUpdateSched"=C:\Programme\Java\jre6\bin\jusched.exe [2009-07-25 149280]
"VirtualCloneDrive"=C:\Programme\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2009-05-26 85160]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"tsnp2std"=C:\WINDOWS\tsnp2std.exe []
"snp2std"=C:\WINDOWS\vsnp2std.exe [2005-11-16 344064]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"swg"=C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-11-13 68856]
"ManyCam"=C:\Programme\ManyCam 2.4\ManyCam.exe [2009-12-19 1824040]
"Skype"=C:\Programme\Skype\Phone\Skype.exe [2009-10-09 25623336]

C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart
InterVideo WinCinema Manager.lnk - C:\Programme\InterVideo\Common\Bin\WinCinemaMgr.exe

C:\Dokumente und Einstellungen\user\Startmenü\Programme\Autostart
OpenOffice.org 3.1.lnk - C:\Programme\OpenOffice.org 3\program\quickstart.exe
WkCalRem.LNK - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkCalRem.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-02-15 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 239616]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Games\Paintball2\paintball2.exe"="C:\Games\Paintball2\paintball2.exe:*:Enabled:paintball2"
"F:\American McGee's Alice\alice.exe"="F:\American McGee's Alice\alice.exe:*:Enabled:American McGee's Alice"
"C:\Programme\IncrediMail\Bin\IncMail.exe"="C:\Programme\IncrediMail\Bin\IncMail.exe:*:Enabled:IncrediMail"
"C:\Programme\IncrediMail\Bin\ImApp.exe"="C:\Programme\IncrediMail\Bin\ImApp.exe:*:Enabled:IncrediMail"
"C:\Programme\IncrediMail\Bin\ImpCnt.exe"="C:\Programme\IncrediMail\Bin\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\WINDOWS\system32\fxsclnt.exe"="C:\WINDOWS\system32\fxsclnt.exe:*:Disabled:Microsoft  Fax Console"
"C:\Programme\Pinnacle\VideoSpin\Programs\RM.exe"="C:\Programme\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager"
"C:\Programme\Pinnacle\VideoSpin\Programs\umi.exe"="C:\Programme\Pinnacle\VideoSpin\Programs\umi.exe:*:Enabled:umi"
"C:\Programme\Pinnacle\VideoSpin\Programs\VideoSpin.exe"="C:\Programme\Pinnacle\VideoSpin\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin"
"C:\Programme\Skype\Plugin Manager\skypePM.exe"="C:\Programme\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Programme\Skype\Phone\Skype.exe"="C:\Programme\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4f652cc4-b232-11dd-b6d5-0022698710c3}]
shell\AutoRun\command - D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{afe32e52-e6b6-11de-b864-c10092ee41a6}]
shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{afe32e54-e6b6-11de-b864-c10092ee41a6}]
shell\AutoRun\command - G:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{afe32e57-e6b6-11de-b864-0022698710c3}]
shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{afe32e58-e6b6-11de-b864-0022698710c3}]
shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eda57c84-b225-11dd-b6d4-0022698710c3}]
shell\AutoRun\command - D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eda57c85-b225-11dd-b6d4-0022698710c3}]
shell\AutoRun\command - D:\setup.exe


======List of files/folders created in the last 3 months======

2010-02-19 18:20:42 ----D---- C:\Programme\trend micro
2010-02-19 18:20:41 ----D---- C:\rsit
2010-02-19 14:43:51 ----D---- C:\Dokumente und Einstellungen\user\Anwendungsdaten\Malwarebytes
2010-02-19 14:43:43 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
2010-02-19 14:43:42 ----D---- C:\Programme\Malwarebytes' Anti-Malware
2010-02-19 14:21:12 ----D---- C:\Programme\CCleaner
2010-02-11 22:22:18 ----D---- C:\Programme\AAALOGO2010
2010-02-10 14:54:52 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-10 14:54:44 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-10 14:51:13 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-10 14:51:06 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-10 14:50:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-10 14:50:47 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-10 14:50:33 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-10 14:50:17 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-10 14:49:56 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-02-10 14:19:59 ----D---- C:\Dokumente und Einstellungen\user\Anwendungsdaten\Skype
2010-02-10 14:18:47 ----D---- C:\Programme\Gemeinsame Dateien\Skype
2010-02-10 14:18:41 ----RD---- C:\Programme\Skype
2010-02-07 21:58:57 ----D---- C:\Dokumente und Einstellungen\user\Anwendungsdaten\PlayFirst
2010-02-07 21:58:57 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PlayFirst
2010-02-02 13:12:43 ----D---- C:\Dokumente und Einstellungen\user\Anwendungsdaten\SmartDraw
2010-02-02 13:06:06 ----D---- C:\Programme\SmartDraw 2010
2010-01-29 20:28:54 ----D---- C:\Programme\Pinnacle
2010-01-29 20:28:54 ----D---- C:\Programme\Gemeinsame Dateien\Yahoo!
2010-01-29 20:28:54 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Pinnacle VideoSpin
2010-01-29 20:27:38 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Pinnacle
2010-01-28 00:28:27 ----D---- C:\Casino
2010-01-27 15:17:00 ----D---- C:\Programme\Canon
2010-01-24 21:36:10 ----D---- C:\Dokumente und Einstellungen\user\Anwendungsdaten\Flood Light Games
2010-01-24 21:36:10 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Flood Light Games
2010-01-22 17:27:14 ----D---- C:\Programme\Gemeinsame Dateien\Symantec Shared
2010-01-22 16:32:53 ----D---- C:\Programme\Gemeinsame Dateien\DESIGNER
2010-01-22 16:32:43 ----D---- C:\WINDOWS\SHELLNEW
2010-01-22 16:02:35 ----D---- C:\Programme\Microsoft.NET
2010-01-22 15:59:41 ----RHD---- C:\MSOCache
2010-01-21 21:15:02 ----A---- C:\WINDOWS\WindowsXP-KB822603-x86.exe
2010-01-21 21:15:01 ----A---- C:\WINDOWS\vsnp2std.exe
2010-01-21 21:15:01 ----A---- C:\WINDOWS\snp2std.ini
2010-01-21 21:14:59 ----D---- C:\Programme\Trust
2010-01-21 21:14:59 ----A---- C:\WINDOWS\vsnp2std.dll
2010-01-21 21:14:59 ----A---- C:\WINDOWS\system32\csnp2std.dll
2010-01-21 21:14:59 ----A---- C:\WINDOWS\rsnp2std.dll
2010-01-21 21:14:30 ----D---- C:\download
2010-01-21 16:23:14 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\UAB
2010-01-21 16:23:13 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Drivers HeadQuarters
2010-01-21 16:21:04 ----D---- C:\Programme\PC Drivers HeadQuarters
2010-01-21 15:41:46 ----D---- C:\Programme\Norton Security Scan
2010-01-21 15:41:46 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Symantec
2010-01-21 15:41:46 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton
2010-01-21 15:41:43 ----D---- C:\Programme\NortonInstaller
2010-01-21 15:41:43 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NortonInstaller
2010-01-21 15:24:00 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-01-21 15:23:47 ----D---- C:\Dokumente und Einstellungen\user\Anwendungsdaten\ManyCam
2010-01-21 15:23:46 ----D---- C:\Programme\ManyCam 2.4
2010-01-21 15:23:38 ----D---- C:\Programme\Ask.com
2010-01-17 18:36:03 ----D---- C:\Dokumente und Einstellungen\user\Anwendungsdaten\Win LohnInfo
2010-01-17 18:35:51 ----D---- C:\Programme\Win LohnInfo
2010-01-17 18:35:41 ----D---- C:\WINDOWS\uninstall
2010-01-17 18:19:11 ----D---- C:\LOHNI
2010-01-17 18:18:55 ----D---- C:\LHWUEKT
2010-01-14 02:30:31 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-01-14 02:30:20 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-01-11 17:43:10 ----D---- C:\Dokumente und Einstellungen\user\Anwendungsdaten\Big Fish Games
2010-01-11 17:35:45 ----D---- C:\Dokumente und Einstellungen\user\Anwendungsdaten\Enlightenus
2009-12-22 13:18:08 ----A---- C:\WINDOWS\Nite Before XMas-Prefs.ini
2009-12-12 02:36:31 ----A---- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem #2.txt
2009-12-12 01:39:16 ----D---- C:\Programme\Surf & E-Mail-Stick
2009-12-12 00:49:52 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2009-12-12 00:49:43 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2009-12-12 00:49:30 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2009-12-12 00:48:09 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2009-12-12 00:47:50 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2009-12-03 16:17:55 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\IncrediMail
2009-12-03 16:17:55 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\IM
2009-12-01 22:52:39 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2009-12-01 21:49:29 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Alawar Stargaze
2009-12-01 20:37:13 ----AD---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
2009-12-01 19:36:21 ----D---- C:\Programme\bfgclient
2009-12-01 19:34:44 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BigFishGamesCache
2009-12-01 14:06:51 ----A---- C:\WINDOWS\system32\hpz3l4pi.dll
2009-12-01 14:04:56 ----A---- C:\WINDOWS\system32\HPZisn12.dll
2009-12-01 14:04:56 ----A---- C:\WINDOWS\system32\HPZipt12.dll
2009-12-01 14:04:55 ----A---- C:\WINDOWS\system32\HPZipr12.dll
2009-12-01 14:04:55 ----A---- C:\WINDOWS\system32\HPZipm12.exe
2009-12-01 14:04:55 ----A---- C:\WINDOWS\system32\HPZinw12.exe
2009-12-01 14:04:55 ----A---- C:\WINDOWS\system32\HPZidr12.dll
2009-12-01 14:04:52 ----A---- C:\WINDOWS\IsUninst.exe
2009-12-01 14:04:21 ----HD---- C:\Config.Msi
2009-12-01 14:04:15 ----D---- C:\Programme\HP
2009-12-01 14:03:17 ----A---- C:\WINDOWS\system32\hpzids01.dll
2009-12-01 13:59:10 ----A---- C:\ut9x.bat
2009-12-01 13:59:10 ----A---- C:\ut.bat
2009-11-29 22:00:32 ----D---- C:\WINDOWS\system32\XPSViewer
2009-11-29 22:00:26 ----D---- C:\Programme\MSBuild
2009-11-29 22:00:23 ----D---- C:\WINDOWS\system32\en-US
2009-11-29 22:00:13 ----D---- C:\Programme\Reference Assemblies
2009-11-29 21:59:28 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-11-29 21:59:27 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-11-29 21:59:27 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-11-29 21:59:26 ----D---- C:\c4289b3109c00050f331dcf1bf
2009-11-28 03:00:33 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2009-11-26 17:22:30 ----A---- C:\WINDOWS\system32\wshirda.dll
2009-11-26 17:22:30 ----A---- C:\WINDOWS\system32\irmon.dll
2009-11-26 17:22:30 ----A---- C:\WINDOWS\system32\irftp.exe
2009-11-26 16:24:48 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2009-11-26 16:24:39 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2009-11-26 16:24:34 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2009-11-26 16:24:25 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2009-11-26 16:24:19 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2009-11-26 16:21:42 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2009-11-26 16:21:34 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2009-11-26 16:21:26 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2009-11-26 16:20:27 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2009-11-26 16:20:17 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2009-11-26 16:19:00 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2009-11-26 16:18:48 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
2009-11-26 16:18:30 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2009-11-26 16:18:18 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2009-11-26 16:17:48 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2009-11-25 22:44:32 ----D---- C:\Programme\PokerStars.NET
2009-11-25 18:40:21 ----D---- C:\Programme\lohn
2009-11-25 17:55:41 ----D---- C:\Dokumente und Einstellungen\user\Anwendungsdaten\TZ-EasyBuch
2009-11-25 17:55:41 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TZ-EasyBuch
2009-11-25 17:55:24 ----D---- C:\Programme\MS-Buchhalter Bilanz

======List of files/folders modified in the last 3 months======

2010-02-19 18:20:42 ----RD---- C:\Programme
2010-02-19 18:19:39 ----D---- C:\WINDOWS\Temp
2010-02-19 18:19:13 ----D---- C:\WINDOWS
2010-02-19 16:29:03 ----AD---- C:\WINDOWS\system32\drivers
2010-02-19 16:28:33 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-19 16:00:43 ----D---- C:\WINDOWS\Prefetch
2010-02-19 14:33:37 ----D---- C:\WINDOWS\Minidump
2010-02-19 14:33:37 ----D---- C:\WINDOWS\Debug
2010-02-19 12:44:36 ----D---- C:\Dokumente und Einstellungen\user\Anwendungsdaten\skypePM
2010-02-18 17:34:43 ----D---- C:\Programme\Mozilla Firefox
2010-02-17 17:15:00 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-10 15:21:30 ----AD---- C:\WINDOWS\system32
2010-02-10 14:54:55 ----HD---- C:\WINDOWS\inf
2010-02-10 14:54:51 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-10 14:54:47 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-10 14:50:59 ----AD---- C:\I386
2010-02-10 14:19:32 ----SHD---- C:\WINDOWS\Installer
2010-02-10 14:18:47 ----D---- C:\Programme\Gemeinsame Dateien
2010-02-10 14:18:41 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype
2010-02-09 18:46:17 ----A---- C:\WINDOWS\win.ini
2010-02-04 00:48:42 ----D---- C:\WINDOWS\system32\FxsTmp
2010-02-02 13:12:29 ----SD---- C:\WINDOWS\Tasks
2010-02-01 20:26:20 ----A---- C:\WINDOWS\system32\MRT.exe
2010-01-31 18:21:26 ----D---- C:\Programme\Google
2010-01-29 20:29:33 ----RSD---- C:\WINDOWS\Fonts
2010-01-29 20:28:59 ----D---- C:\WINDOWS\WinSxS
2010-01-27 15:17:00 ----HD---- C:\Programme\InstallShield Installation Information
2010-01-22 17:33:50 ----D---- C:\WINDOWS\system32\de-de
2010-01-22 17:33:50 ----D---- C:\Programme\Internet Explorer
2010-01-22 16:39:08 ----SD---- C:\Dokumente und Einstellungen\user\Anwendungsdaten\Microsoft
2010-01-22 16:34:24 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft Help
2010-01-22 16:33:50 ----D---- C:\Programme\Microsoft Works
2010-01-22 16:33:42 ----D---- C:\Programme\Gemeinsame Dateien\Microsoft Shared
2010-01-22 16:05:01 ----RSD---- C:\WINDOWS\assembly
2010-01-22 16:03:41 ----D---- C:\Programme\Microsoft Office
2010-01-21 21:15:01 ----D---- C:\WINDOWS\twain_32
2010-01-18 19:23:29 ----D---- C:\WINDOWS\Network Diagnostic
2010-01-14 14:51:28 ----D---- C:\WINDOWS\AppPatch
2010-01-08 18:59:45 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-05 10:52:17 ----A---- C:\WINDOWS\system32\wininet.dll
2010-01-05 10:52:17 ----A---- C:\WINDOWS\system32\webcheck.dll
2010-01-05 10:52:17 ----A---- C:\WINDOWS\system32\urlmon.dll
2010-01-05 10:52:16 ----A---- C:\WINDOWS\system32\url.dll
2010-01-05 10:52:16 ----A---- C:\WINDOWS\system32\pngfilt.dll
2010-01-05 10:52:16 ----A---- C:\WINDOWS\system32\occache.dll
2010-01-05 10:52:16 ----A---- C:\WINDOWS\system32\mstime.dll
2010-01-05 10:52:16 ----A---- C:\WINDOWS\system32\msrating.dll
2010-01-05 10:52:15 ----A---- C:\WINDOWS\system32\mshtmled.dll
2010-01-05 10:52:15 ----A---- C:\WINDOWS\system32\mshtml.dll
2010-01-05 10:52:14 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2010-01-05 10:52:14 ----A---- C:\WINDOWS\system32\msfeeds.dll
2010-01-05 10:52:14 ----A---- C:\WINDOWS\system32\jsproxy.dll
2010-01-05 10:52:13 ----A---- C:\WINDOWS\system32\iertutil.dll
2010-01-05 10:52:13 ----A---- C:\WINDOWS\system32\iernonce.dll
2010-01-05 10:52:13 ----A---- C:\WINDOWS\system32\iepeers.dll
2010-01-05 10:52:13 ----A---- C:\WINDOWS\system32\ieframe.dll
2010-01-05 10:52:11 ----A---- C:\WINDOWS\system32\ieencode.dll
2010-01-05 10:52:11 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2010-01-05 10:52:11 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2010-01-05 10:52:11 ----A---- C:\WINDOWS\system32\ieaksie.dll
2010-01-05 10:52:11 ----A---- C:\WINDOWS\system32\ieakeng.dll
2010-01-05 10:52:11 ----A---- C:\WINDOWS\system32\icardie.dll
2010-01-05 10:52:11 ----A---- C:\WINDOWS\system32\extmgr.dll
2010-01-05 10:52:10 ----A---- C:\WINDOWS\system32\dxtrans.dll
2010-01-05 10:52:10 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2010-01-05 10:52:10 ----A---- C:\WINDOWS\system32\corpol.dll
2010-01-05 10:52:10 ----A---- C:\WINDOWS\system32\advpack.dll
2009-12-31 16:32:47 ----A---- C:\WINDOWS\system32\ieudinit.exe
2009-12-31 16:32:47 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2009-12-18 14:04:09 ----A---- C:\WINDOWS\system32\ieakui.dll
2009-12-17 08:40:01 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-12-14 08:08:20 ----A---- C:\WINDOWS\system32\csrsrv.dll
2009-12-12 01:56:05 ----A---- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem.txt
2009-12-09 11:05:52 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2009-12-09 11:05:51 ----A---- C:\WINDOWS\system32\ntkrnlpa.exe
2009-12-08 15:41:40 ----D---- C:\Programme\PartyGaming
2009-12-08 14:22:30 ----D---- C:\WINDOWS\Microsoft.NET
2009-12-08 10:23:28 ----A---- C:\WINDOWS\system32\shlwapi.dll
2009-12-01 22:53:01 ----D---- C:\WINDOWS\system32\CatRoot
2009-11-29 21:59:49 ----D---- C:\WINDOWS\system32\spool
2009-11-27 18:11:57 ----A---- C:\WINDOWS\system32\quartz.dll
2009-11-27 18:11:57 ----A---- C:\WINDOWS\system32\msyuv.dll
2009-11-27 17:08:01 ----A---- C:\WINDOWS\system32\tsbyuv.dll
2009-11-27 17:08:01 ----A---- C:\WINDOWS\system32\msvidc32.dll
2009-11-27 17:08:01 ----A---- C:\WINDOWS\system32\msrle32.dll
2009-11-27 17:08:01 ----A---- C:\WINDOWS\system32\iyuv_32.dll
2009-11-27 17:08:01 ----A---- C:\WINDOWS\system32\avifil32.dll
2009-11-26 18:37:44 ----D---- C:\WINDOWS\security
2009-11-26 16:20:49 ----D---- C:\WINDOWS\ie7updates
2009-11-25 20:28:05 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Google
2009-11-25 17:24:03 ----D---- C:\WINDOWS\Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Programme\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-05-28 75096]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 intelppm;Intel-Prozessortreiber; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 40448]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-11-08 21248]
R1 WmiAcpi;Microsoft Windows-Verwaltungsschnittstelle für ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R3 AR5416;Atheros AR5008 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athw.sys [2008-05-20 1312576]
R3 avgntflt;avgntflt; \??\C:\Programme\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 CmBatt;Treiber für Microsoft-ACPI-Kontrollmethodenkompatible Batterie; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\WINDOWS\system32\DRIVERS\DKbFltr.sys [2004-12-08 16896]
R3 HDAudBus;Microsoft UAA-Bustreiber für High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-02-15 5854752]
R3 int15.sys;int15.sys; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-05-20 4800000]
R3 M3000Srv;Acer Crystal Eye webcam Driver; C:\WINDOWS\System32\Drivers\M3000KNT.sys [2008-05-05 254976]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver; C:\WINDOWS\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-07-01 108800]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2008-04-25 225024]
R3 usbehci;Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2-aktivierter Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Miniporttreiber für universellen Microsoft USB-Hostcontroller; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2009-05-23 29696]
S1 kbdhid;Tastatur-HID-Treiber; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14720]
S3 BthEnum;Bluetooth-Anforderungsblocktreiber; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth-Gerät (PAN); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Bluetooth-Porttreiber; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 273024]
S3 BTHUSB;USB-Treiber für Bluetooth-Funkgerät; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 CCDECODE;Untertiteldecoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 HidUsb;Microsoft HID Class-Treiber; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2009-08-26 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-05-16 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2009-08-26 21568]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2008-11-08 101376]
S3 JMCR;JMCR; C:\WINDOWS\system32\DRIVERS\jmcr.sys [2008-07-08 96856]
S3 mouhid;Maus-HID-Treiber; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-18 12288]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI-Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV-/Videoverbindung; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 RFCOMM;Bluetooth-Gerät (RFCOMM-Protokoll-TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD); C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2005-11-18 10192896]
S3 streamip;BDA-IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft Standard-USB-Haupttreiber; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB-Druckerklasse; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;USB-Scannertreiber; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbstor;USB-Massenspeichertreiber; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext-Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Planer; C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 268800]
R2 IviRegMgr;IviRegMgr; C:\Programme\Gemeinsame Dateien\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 JavaQuickStarterService;Java Quick Starter; C:\Programme\Java\jre6\bin\jqs.exe [2009-07-25 153376]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2006-03-03 69632]
S2 gupdate;Google Update Service (gupdate); C:\Programme\Google\Update\GoogleUpdate.exe [2010-01-31 135664]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Boonty Games;Boonty Games; C:\Programme\Gemeinsame Dateien\BOONTY Shared\Service\Boonty.exe [2009-05-24 69120]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-02 182768]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Windows Media Player-Netzwerkfreigabedienst; C:\Programme\Windows Media Player\WMPNetwk.exe [2006-11-03 920576]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
         
__________________


 

Themen zu verdacht auf Trojana
1.exe, adware.egdaccess, adware.navipromo, einstellungen, explorer, firefox, flash player, gupdate, hotfix.exe, installation, malware.trace, messenger, microsoft, msiexec.exe, password.stealer.fb, programme, registrierungsschlüssel, rogue.residue, security, security update, software, system, trojan.agent.h, updates, windows internet, windows internet explorer, windows xp, windows-sicherheitscenterdienst, wmp11




Ähnliche Themen: verdacht auf Trojana


  1. FB Trojana wie bekomm ich den los?
    Log-Analyse und Auswertung - 30.07.2013 (4)
  2. Rechnung Zip und verdacht auf einen Trojana
    Plagegeister aller Art und deren Bekämpfung - 19.05.2013 (9)
  3. Trojana.Agent.PS
    Log-Analyse und Auswertung - 27.11.2012 (13)
  4. GVU Trojana 2.07 Windows 7
    Plagegeister aller Art und deren Bekämpfung - 28.10.2012 (10)
  5. GVU Trojana 2.07 Vista
    Log-Analyse und Auswertung - 09.10.2012 (9)
  6. Skype Trojana
    Plagegeister aller Art und deren Bekämpfung - 03.10.2012 (17)
  7. Skype Trojana
    Plagegeister aller Art und deren Bekämpfung - 30.09.2012 (5)
  8. Polizei Trojana
    Log-Analyse und Auswertung - 06.09.2012 (2)
  9. BKA Trojana
    Plagegeister aller Art und deren Bekämpfung - 22.04.2011 (35)
  10. Internet Explorer öffnet sich ständig verdacht auf Trojana oder ähnliches
    Log-Analyse und Auswertung - 17.08.2010 (28)
  11. your protection trojana
    Log-Analyse und Auswertung - 09.04.2010 (6)
  12. Trojana - hilfeeee
    Mülltonne - 21.11.2008 (1)
  13. Trojana virus
    Mülltonne - 29.09.2008 (0)
  14. Trojana TR/BHO.czo
    Log-Analyse und Auswertung - 29.07.2008 (5)
  15. hilfe trojana
    Plagegeister aller Art und deren Bekämpfung - 26.10.2007 (1)
  16. Hab ein Trojana!!!
    Plagegeister aller Art und deren Bekämpfung - 13.05.2005 (12)
  17. Ich hab nen trojana
    Plagegeister aller Art und deren Bekämpfung - 28.09.2004 (22)

Zum Thema verdacht auf Trojana - Code: Alles auswählen Aufklappen ATTFilter Logfile of random's system information tool 1.06 (written by random/random) Run by user at 2010-02-19 18:20:41 Microsoft Windows XP Home Edition Service Pack 3 System - verdacht auf Trojana...
Archiv
Du betrachtest: verdacht auf Trojana auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.