TheissPa | 12.07.2010 19:52 | Also mit malwarebyte habe ich jetzt nur mal ein Quick scan gemacht ich mache morgen ein ganz voller scan und poste es noch mal mit dem vollen habe jetzt erst mal en quick villt bringt das mal was... bei Malwarebytes quick scan wurden 6 indifizierte sachen gefunden Malwarebytes Zitat:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Datenbank Version: 4305
Windows 6.0.6000
Internet Explorer 8.0.6001.18928
12.07.2010 20:37:04
mbam-log-2010-07-12 (20-37-04).txt
Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 120025
Laufzeit: 7 Minute(n), 8 Sekunde(n)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 4
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\QZAIB7KITK (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\canaveral (Trojan.Downloader) -> Quarantined and deleted successfully.
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
C:\Users\Alinschää\AppData\Local\Temp\e1bm1d6CH6.log (Extension.Mismatch) -> Quarantined and deleted successfully.
| OTL
OTL Logfile:
OTL EXTRAS Logfile: Code:
OTL logfile created on: 12.07.2010 20:43:16 - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\Alinschää\Documents\ICQ\550903612\ReceivedFiles\412282096 _~_Kleiner-Pa$$y_~_
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 63,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,88 Gb Total Space | 61,45 Gb Free Space | 54,92% Space Free | Partition Type: NTFS
Drive D: | 111,00 Gb Total Space | 94,38 Gb Free Space | 85,03% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ALINSCHÄÄ-PC
Current User Name: Alinschää
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
========== Processes (SafeList) ==========
PRC - C:\Users\Alinschää\Documents\ICQ\550903612\ReceivedFiles\412282096 _~_Kleiner-Pa$$y_~_\OTL.exe (OldTimer Tools)
PRC - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.)
PRC - C:\Programme\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Users\Alinschää\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe ()
PRC - C:\Programme\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Programme\Internet Explorer\ielowutil.exe (Microsoft Corporation)
PRC - C:\Users\Alinschää\temp\TeamViewer\Version4\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Windows\System32\sdclt.exe (Microsoft Corporation)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
========== Modules (SafeList) ==========
MOD - C:\Users\Alinschää\Documents\ICQ\550903612\ReceivedFiles\412282096 _~_Kleiner-Pa$$y_~_\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (SearchAnonymizer) -- C:\Users\Alinschää\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe ()
SRV - (MsMpSvc) -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (MpFilter) -- C:\Windows\System32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (MpNWMon) -- C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (PDNMp50) -- C:\Windows\System32\drivers\PDNMp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (PDNSp50) -- C:\Windows\System32\drivers\PDNSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (yukonwlh) -- C:\Windows\System32\drivers\yk60x86.sys (Marvell)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.wer-kennt-wen.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010.05.15 02:56:57 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010.05.15 02:57:09 | 000,000,000 | ---D | M] -- C:\Users\Alinschää\AppData\Roaming\mozilla\Extensions
[2010.05.15 02:57:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alinschää\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Ocs_SM] C:\Users\Alinschää\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Alinschää\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Alinschää\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Alinschää\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{f621b68d-fc51-11de-8dc4-00137766d515}\Shell - "" = AutoRun
O33 - MountPoints2\{f621b68d-fc51-11de-8dc4-00137766d515}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 90 Days ==========
[2010.07.12 19:38:49 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\AppData\Roaming\Malwarebytes
[2010.07.12 19:38:22 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.07.12 19:38:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.07.12 19:38:19 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.07.12 19:38:19 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2010.07.10 21:18:51 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\Desktop\Adobe Photoshop CS3
[2010.07.10 20:57:31 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2010.07.09 15:44:53 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\Desktop\GTA San Andreas
[2010.07.08 14:35:15 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\Desktop\Musik1
[2010.07.07 21:37:24 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\Desktop\neu
[2010.07.01 11:28:12 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\Desktop\fotografie=)
[2010.06.30 13:57:47 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\Documents\Updater
[2010.06.30 13:57:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe Systems
[2010.06.30 13:53:34 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Adobe PDF
[2010.06.30 13:53:03 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Adobe Systems Shared
[2010.06.30 08:40:48 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2010.06.23 16:51:02 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\Desktop\zum entwickeln
[2010.06.22 14:20:54 | 000,000,000 | ---D | C] -- C:\Windows\Downloaded Installations
[2010.06.13 19:47:12 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.06.13 19:46:22 | 000,000,000 | ---D | C] -- C:\Programme\DVDVideoSoft
[2010.06.12 12:38:57 | 000,000,000 | ---D | C] -- C:\Programme\QS
[2010.06.12 12:38:54 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\AppData\Roaming\TeamViewer
[2010.06.12 12:38:29 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\temp
[2010.06.11 22:20:46 | 000,000,000 | ---D | C] -- C:\Programme\Java
[2010.05.15 17:41:12 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\AppData\Roaming\PeerNetworking
[2010.05.15 02:57:04 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\AppData\Local\Thunderbird
[2010.05.15 02:57:03 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\AppData\Roaming\Thunderbird
[2010.05.15 02:56:53 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Thunderbird
[2010.05.09 23:02:49 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\AppData\Local\Conduit
[2010.05.09 22:55:10 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\AppData\Local\WMTools Downloaded Files
[2010.05.09 19:12:25 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft
[2010.05.09 19:12:09 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2010.05.09 19:10:12 | 000,000,000 | ---D | C] -- C:\Programme\Windows Live
[2010.05.09 19:09:43 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010.05.09 19:08:22 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft SQL Server Compact Edition
[2010.05.09 18:53:17 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Windows Live
[2010.05.02 14:50:12 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\Desktop\schatz =)
[2010.04.26 21:30:03 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Security Essentials
[2010.04.26 16:05:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Ulead Systems
[2010.04.26 16:05:43 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\InstallShield
[2010.04.19 14:46:45 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\AppData\Roaming\Opera
[2010.04.19 14:46:39 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\AppData\Roaming\OCS
[2010.04.18 17:55:18 | 000,000,000 | ---D | C] -- C:\Users\Alinschää\AppData\Local\AOL
[2010.04.18 17:55:03 | 000,000,000 | ---D | C] -- C:\Programme\ICQ7.1
========== Files - Modified Within 90 Days ==========
[2010.07.12 20:41:43 | 001,572,864 | -HS- | M] () -- C:\Users\Alinschää\NTUSER.DAT
[2010.07.12 20:38:07 | 000,054,016 | ---- | M] () -- C:\Windows\System32\drivers\cdbkona.sys
[2010.07.12 19:45:47 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.07.12 19:45:47 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.07.12 19:38:25 | 000,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.07.12 19:38:14 | 000,000,680 | ---- | M] () -- C:\Users\Alinschää\AppData\Local\d3d9caps.dat
[2010.07.12 18:45:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.07.12 14:38:55 | 000,640,596 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.07.12 14:38:55 | 000,609,730 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010.07.12 14:38:55 | 000,116,328 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.07.12 14:38:55 | 000,103,512 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.07.12 14:38:54 | 001,461,736 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.07.12 14:33:04 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.07.12 14:32:57 | 2145,566,720 | -HS- | M] () -- C:\hiberfil.sys
[2010.07.12 14:31:47 | 002,378,965 | -H-- | M] () -- C:\Users\Alinschää\AppData\Local\IconCache.db
[2010.07.11 20:52:48 | 000,000,426 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{A680AE39-105C-4EEC-B7E9-F9394DAFEFA8}.job
[2010.07.10 22:21:56 | 000,067,496 | ---- | M] () -- C:\Users\Alinschää\AppData\Local\GDIPFONTCACHEV1.DAT
[2010.07.10 22:21:18 | 000,278,544 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.07.10 21:04:07 | 000,002,560 | ---- | M] () -- C:\Windows\_MSRSTRT.EXE
[2010.07.09 17:21:15 | 000,010,752 | ---- | M] () -- C:\Users\Alinschää\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.06.30 08:40:52 | 000,000,940 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010.06.22 14:28:24 | 000,000,030 | ---- | M] () -- C:\Windows\Iedit_.INI
[2010.06.22 13:39:52 | 000,024,576 | -H-- | M] () -- C:\Users\Alinschää\Desktop\photothumb.db
[2010.06.17 18:38:50 | 003,626,157 | ---- | M] () -- C:\Users\Alinschää\Desktop\MOV04603.3GP
[2010.06.13 19:47:07 | 000,001,032 | ---- | M] () -- C:\Users\Alinschää\Desktop\DVDVideoSoft Free Studio.lnk
[2010.06.11 21:54:02 | 000,000,261 | ---- | M] () -- C:\prefs.js
[2010.05.15 23:15:59 | 000,000,944 | ---- | M] () -- C:\Users\Alinschää\Desktop\Windows Media Player.lnk
[2010.05.15 17:41:13 | 000,031,007 | ---- | M] () -- C:\Users\Alinschää\AppData\Roaming\UserTile.png
[2010.05.15 02:56:59 | 000,001,790 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2010.05.04 04:58:45 | 000,057,667 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2010.04.29 12:19:24 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.04.29 12:19:14 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.04.18 17:56:00 | 000,001,609 | ---- | M] () -- C:\Users\Public\Desktop\ICQ7.1.lnk
========== Files Created - No Company Name ==========
[2010.07.12 20:38:06 | 000,054,016 | ---- | C] () -- C:\Windows\System32\drivers\cdbkona.sys
[2010.07.12 19:38:25 | 000,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.07.12 14:02:43 | 000,000,000 | R--- | C] () -- C:\Users\Alinschää\AppData\Roaming\Bd6CH.txt
[2010.07.12 12:29:02 | 000,000,000 | ---- | C] () -- C:\Windows\cs3marked64
[2010.07.10 21:17:30 | 000,000,000 | ---- | C] () -- C:\Windows\cs3marked32
[2010.06.22 14:28:24 | 000,000,030 | ---- | C] () -- C:\Windows\Iedit_.INI
[2010.06.17 19:45:39 | 003,626,157 | ---- | C] () -- C:\Users\Alinschää\Desktop\MOV04603.3GP
[2010.06.13 19:46:56 | 000,001,032 | ---- | C] () -- C:\Users\Alinschää\Desktop\DVDVideoSoft Free Studio.lnk
[2010.06.11 21:54:02 | 000,000,261 | ---- | C] () -- C:\prefs.js
[2010.06.11 21:51:59 | 000,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2010.06.11 21:33:20 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2010.05.30 15:12:28 | 000,000,426 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{A680AE39-105C-4EEC-B7E9-F9394DAFEFA8}.job
[2010.05.15 23:15:59 | 000,000,944 | ---- | C] () -- C:\Users\Alinschää\Desktop\Windows Media Player.lnk
[2010.05.15 17:41:13 | 000,031,007 | ---- | C] () -- C:\Users\Alinschää\AppData\Roaming\UserTile.png
[2010.05.15 02:56:59 | 000,001,790 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2010.04.26 21:30:05 | 000,000,940 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010.04.18 17:56:00 | 000,001,609 | ---- | C] () -- C:\Users\Public\Desktop\ICQ7.1.lnk
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2002.03.17 02:00:00 | 000,007,420 | ---- | C] () -- C:\Windows\UA000096.DLL
========== LOP Check ==========
[2010.06.13 19:47:12 | 000,000,000 | ---D | M] -- C:\Users\Alinschää\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.07.12 20:39:58 | 000,000,000 | ---D | M] -- C:\Users\Alinschää\AppData\Roaming\ICQ
[2010.06.11 21:54:05 | 000,000,000 | ---D | M] -- C:\Users\Alinschää\AppData\Roaming\McLoad
[2010.04.19 14:46:39 | 000,000,000 | ---D | M] -- C:\Users\Alinschää\AppData\Roaming\OCS
[2010.03.11 13:39:41 | 000,000,000 | ---D | M] -- C:\Users\Alinschää\AppData\Roaming\OpenOffice.org
[2010.04.19 14:46:45 | 000,000,000 | ---D | M] -- C:\Users\Alinschää\AppData\Roaming\Opera
[2010.05.15 17:41:12 | 000,000,000 | ---D | M] -- C:\Users\Alinschää\AppData\Roaming\PeerNetworking
[2010.07.09 15:59:52 | 000,000,000 | ---D | M] -- C:\Users\Alinschää\AppData\Roaming\TeamViewer
[2010.05.15 02:57:07 | 000,000,000 | ---D | M] -- C:\Users\Alinschää\AppData\Roaming\Thunderbird
[2010.07.12 14:32:09 | 000,024,412 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010.07.11 20:52:48 | 000,000,426 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{A680AE39-105C-4EEC-B7E9-F9394DAFEFA8}.job
========== Purity Check ==========
< End of report > --- --- ---
--- --- ---
extras.txt
OTL EXTRAS Logfile: Code:
OTL Extras logfile created on: 12.07.2010 20:43:16 - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\Alinschää\Documents\ICQ\550903612\ReceivedFiles\412282096 _~_Kleiner-Pa$$y_~_
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 63,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,88 Gb Total Space | 61,45 Gb Free Space | 54,92% Space Free | Partition Type: NTFS
Drive D: | 111,00 Gb Total Space | 94,38 Gb Free Space | 85,03% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ALINSCHÄÄ-PC
Current User Name: Alinschää
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{116D375A-DABB-4604-92FD-9444301F1EFB}" = lport=445 | protocol=6 | dir=in | app=system |
"{35A84A1E-A04A-4AD6-A1E3-9CB50203E05B}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{35BB5199-3ED2-490E-A66D-434B414F66E4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4F117A95-48E1-4CA9-93C4-BF22FECCBDC8}" = rport=445 | protocol=6 | dir=out | app=system |
"{6B1480E6-3C1A-43BC-8B8B-5CB10910E2F2}" = rport=137 | protocol=17 | dir=out | app=system |
"{6B6C59C2-A95A-4803-AC24-A306D76C28CC}" = lport=139 | protocol=6 | dir=in | app=system |
"{76E1493D-DC3B-4B3B-B898-6CCDBF818FF2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{98CA74E4-C44C-4278-9A4F-0D509BDDCDEC}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{A529CFED-4457-4766-AA01-8BE9B4508DCF}" = rport=138 | protocol=17 | dir=out | app=system |
"{B09CF988-83AE-4BE9-B871-A00FBEC14E46}" = lport=137 | protocol=17 | dir=in | app=system |
"{BB894F67-75C6-432B-9819-63C6B1457C1C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{CFA6282C-0DED-44D8-AB4F-717ADFD1EA5C}" = lport=138 | protocol=17 | dir=in | app=system |
"{EE58B2C5-DD41-4A2D-B70D-24A0CB3F3414}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{FB50B985-DE18-41BA-9A3C-6C15994C099A}" = rport=139 | protocol=6 | dir=out | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0352CCAF-4F2D-4915-B72D-EF0369518D42}" = protocol=17 | dir=in | app=c:\program files\icq7.1\icq.exe |
"{0517C2B7-4FAE-41D8-8B37-68C5999ABCB5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{051C8B75-D99C-413A-9A7A-E2089E80483D}" = protocol=17 | dir=in | app=c:\program files\icq7.1\aolload.exe |
"{0830A3A5-9700-4581-825F-E02428AA04AE}" = protocol=6 | dir=in | app=c:\program files\icq7.1\aolload.exe |
"{1C510FFA-77BB-4818-A4E1-BFB65A943310}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2AA02A58-3BCE-47A4-B0DA-6A0D1B022581}" = protocol=6 | dir=in | app=c:\program files\icq7.1\aolload.exe |
"{2D0B6475-C71B-482E-A4AD-C1C4E27D1BA7}" = protocol=6 | dir=in | app=c:\program files\icq7.1\aolload.exe |
"{3A5BA9B2-49E7-4F55-91ED-BA394A7B4BFD}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{50CA61BE-D69C-4E4D-8255-6CBB8A52A5B1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{53DD3C77-1224-4C84-A209-E8576C16754A}" = protocol=6 | dir=in | app=c:\program files\icq7.1\icq.exe |
"{7E421A84-3838-482D-8ED9-55C76A659072}" = protocol=6 | dir=in | app=c:\program files\icq7.1\icq.exe |
"{A8139108-1B41-4E72-B2B0-3C6860A7ABA5}" = protocol=6 | dir=in | app=c:\program files\icq7.1\icq.exe |
"{AA2B6224-2374-4615-9FCB-EFDC1B94A7AA}" = protocol=17 | dir=in | app=c:\program files\icq7.1\icq.exe |
"{AC673BB9-E7E0-4F39-A227-B01D370E6732}" = protocol=17 | dir=in | app=c:\program files\icq7.1\aolload.exe |
"{C9E8D159-0C81-4926-B203-45AF7925F642}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{DEC23604-1164-4C16-984D-43845E187660}" = protocol=17 | dir=in | app=c:\program files\icq7.1\aolload.exe |
"{DF923D56-52D0-4E99-A52F-51200284B2CA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F7A02221-3588-4128-BFDC-32738E62AC88}" = protocol=17 | dir=in | app=c:\program files\icq7.1\icq.exe |
"TCP Query User{02029E28-4BF1-4E99-A868-98CB49C6B149}C:\users\alinschää\desktop\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\users\alinschää\desktop\icq6.5\icq.exe |
"TCP Query User{14078795-6C74-4376-B910-DC6B4BA57DA1}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{AA50E48D-EF55-40E7-BEAD-F6D6C2DE2921}C:\users\alinschää\desktop\stronghold crusader\stronghold crusader.exe" = protocol=6 | dir=in | app=c:\users\alinschää\desktop\stronghold crusader\stronghold crusader.exe |
"TCP Query User{CD1FD004-EC4B-4D55-AB4D-8EF97A0D47EE}C:\users\alinschää\temp\teamviewer\version4\teamviewer.exe" = protocol=6 | dir=in | app=c:\users\alinschää\temp\teamviewer\version4\teamviewer.exe |
"TCP Query User{E24DAF47-F226-4DCD-A2D5-2C04E067F728}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{5BB1D375-D42F-45DC-8809-67E3FEFF77CB}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{7C389F93-7889-4532-B9B7-6E2ED9D2C4B8}C:\users\alinschää\desktop\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\users\alinschää\desktop\icq6.5\icq.exe |
"UDP Query User{8E79F4F4-275C-4AA0-A99F-A09DB8BAF65E}C:\users\alinschää\temp\teamviewer\version4\teamviewer.exe" = protocol=17 | dir=in | app=c:\users\alinschää\temp\teamviewer\version4\teamviewer.exe |
"UDP Query User{ABB7D1D4-3354-42D6-9FEF-5E146DD84775}C:\users\alinschää\desktop\stronghold crusader\stronghold crusader.exe" = protocol=17 | dir=in | app=c:\users\alinschää\desktop\stronghold crusader\stronghold crusader.exe |
"UDP Query User{B4BCE334-A37F-4FE0-927B-7B6C6401CA13}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{71BFC818-0CED-42D6-9C87-5142918957EE}" = ICQ7.1
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{84ED5482-CFB0-4DD9-BF18-489FFDACD18A}" = Microsoft Antimalware Service DE-DE Language Pack
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.3 - Deutsch
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Alice" = Alice-Installationsdateien entfernen
"CCleaner" = CCleaner
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.3
"Free YouTube Download_is1" = Free YouTube Download 2.3
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.5
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Thunderbird (3.0.4)" = Mozilla Thunderbird (3.0.4)
"PhotoScape" = PhotoScape
"SearchAnonymizer" = SearchAnonymizer
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.0.1
"WinLiveSuite_Wave3" = Windows Live Essentials
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10.07.2010 15:24:41 | Computer Name = Alinschää-PC | Source = Application Hang | ID = 1002
Description = Programm Stronghold Crusader.exe, Version 0.0.0.0 arbeitet nicht mehr
mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet
"Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen
über das Problem zu suchen. Prozess-ID: 6c4 Anfangszeit: 01cb206514cc12d4 Zeitpunkt
der Beendigung: 10758
Error - 10.07.2010 15:41:44 | Computer Name = Alinschää-PC | Source = VSS | ID = 8194
Description =
Error - 11.07.2010 07:14:20 | Computer Name = Alinschää-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 11.07.2010 07:15:14 | Computer Name = Alinschää-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 11.07.2010 07:21:37 | Computer Name = Alinschää-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 11.07.2010 07:41:32 | Computer Name = Alinschää-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 11.07.2010 10:16:28 | Computer Name = Alinschää-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 11.07.2010 14:42:57 | Computer Name = Alinschää-PC | Source = Windows Backup | ID = 4104
Description =
Error - 12.07.2010 06:03:03 | Computer Name = Alinschää-PC | Source = Windows Backup | ID = 4104
Description =
Error - 12.07.2010 06:04:27 | Computer Name = Alinschää-PC | Source = Windows Backup | ID = 4104
Description =
[ System Events ]
Error - 27.04.2010 13:27:57 | Computer Name = Alinschää-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
Error - 27.04.2010 13:32:31 | Computer Name = Alinschää-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 27.04.2010 um 19:30:57 unerwartet heruntergefahren.
Error - 27.04.2010 13:33:44 | Computer Name = Alinschää-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 27.04.2010 14:01:44 | Computer Name = Alinschää-PC | Source = DCOM | ID = 10010
Description =
Error - 27.04.2010 14:13:03 | Computer Name = Alinschää-PC | Source = WPDMTPDriver | ID = 80836
Description =
Error - 28.04.2010 08:54:11 | Computer Name = Alinschää-PC | Source = Microsoft Antimalware | ID = 1008
Description = Fehler in %%861 beim Durchführen von Maßnahmen gegen Spyware oder
andere möglicherweise unerwünschte Software. Im Folgenden finden Sie weitere Innformationen:
hxxp://go.microsoft.com/fwlink/?linkid=37020&name=Exploit:JS/Pdfjsc.B&threatid=2147630774
Benutzer:
Alinschää-PC\Alinschää Name: Exploit:JS/Pdfjsc.B ID: 2147630774 Schweregrad: Schwerwiegend
Kategorie:
Ausnutzen Pfad: Aktion: %%808 Fehlercode: 0x80508023 Fehlerbeschreibung: Auf diesem
Computer wurde keine Spyware oder andere möglicherweise unerwünschte Software gefunden.
Status: Signaturversion: AV: 1.81.556.0, AS: 1.81.556.0 Modulversion: 1.1.5703.0
Error - 28.04.2010 09:02:51 | Computer Name = Alinschää-PC | Source = Microsoft Antimalware | ID = 1008
Description = Fehler in %%861 beim Durchführen von Maßnahmen gegen Spyware oder
andere möglicherweise unerwünschte Software. Im Folgenden finden Sie weitere Innformationen:
hxxp://go.microsoft.com/fwlink/?linkid=37020&name=Exploit:JS/Pdfjsc.B&threatid=2147630774
Benutzer:
Alinschää-PC\Alinschää Name: Exploit:JS/Pdfjsc.B ID: 2147630774 Schweregrad: Schwerwiegend
Kategorie:
Ausnutzen Pfad: Aktion: %%808 Fehlercode: 0x80508023 Fehlerbeschreibung: Auf diesem
Computer wurde keine Spyware oder andere möglicherweise unerwünschte Software gefunden.
Status: Signaturversion: AV: 1.81.556.0, AS: 1.81.556.0 Modulversion: 1.1.5703.0
Error - 28.04.2010 09:05:31 | Computer Name = Alinschää-PC | Source = Microsoft Antimalware | ID = 1008
Description = Fehler in %%861 beim Durchführen von Maßnahmen gegen Spyware oder
andere möglicherweise unerwünschte Software. Im Folgenden finden Sie weitere Innformationen:
hxxp://go.microsoft.com/fwlink/?linkid=37020&name=Exploit:JS/Pdfjsc.B&threatid=2147630774
Benutzer:
Alinschää-PC\Alinschää Name: Exploit:JS/Pdfjsc.B ID: 2147630774 Schweregrad: Schwerwiegend
Kategorie:
Ausnutzen Pfad: Aktion: %%808 Fehlercode: 0x80508023 Fehlerbeschreibung: Auf diesem
Computer wurde keine Spyware oder andere möglicherweise unerwünschte Software gefunden.
Status: Signaturversion: AV: 1.81.556.0, AS: 1.81.556.0 Modulversion: 1.1.5703.0
Error - 28.04.2010 11:41:14 | Computer Name = Alinschää-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 28.04.2010 um 17:40:17 unerwartet heruntergefahren.
Error - 28.04.2010 11:42:46 | Computer Name = Alinschää-PC | Source = Service Control Manager | ID = 7000
Description =
< End of report > --- --- --- |