Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Windows 7 blockiert, 50€ (https://www.trojaner-board.de/107301-windows-7-blockiert-50-a.html)

cbone11 30.12.2011 20:54

Windows 7 blockiert, 50€
 
Nabend selbes Problem wie viele hier.
Im Anhang die Dateien.

gruss

OTL zu gross, daher gleich hier

OTL logfile created on: 30.12.2011 20:31:01 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\standard\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19120)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,75 Gb Total Physical Memory | 1,94 Gb Available Physical Memory | 70,50% Memory free
5,74 Gb Paging File | 4,93 Gb Available in Paging File | 85,91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144,04 Gb Total Space | 86,60 Gb Free Space | 60,12% Space Free | Partition Type: NTFS
Drive D: | 144,04 Gb Total Space | 140,23 Gb Free Space | 97,35% Space Free | Partition Type: NTFS
Drive F: | 7,46 Gb Total Space | 5,36 Gb Free Space | 71,90% Space Free | Partition Type: FAT32
Computer Name: STANDARD-PC | User Name: standard | Logged in as Administrator.
Cannot determine boot mode. | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========

PRC - C:\Users\standard\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe (EgisTec Inc.)
PRC - C:\ACER\Mobility Center\MobilityService.exe ()

========== Modules (No Company Name) ==========

MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll ()

========== Win32 Services (SafeList) ==========

SRV - (CPUCooLServer) -- File not found
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (VMCService) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (ePowerSvc) -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV - (MWLService) -- C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe ()
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MobilityService) -- C:\Acer\Mobility Center\MobilityService.exe ()


========== Driver Services (SafeList) ==========

DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (ntiopnp) -- C:\Windows\System32\drivers\ntiopnp.sys ()
DRV - (ntiomin) -- C:\Windows\System32\drivers\ntiomin.sys ()
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (SQTECH905C) -- C:\Windows\System32\drivers\Capt905c.sys (Service & Quality Technology.)
DRV - (mwlPSDVDisk) -- C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Incorporated.)
DRV - (mwlPSDFilter) -- C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Incorporated.)
DRV - (mwlPSDNServ) -- C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Incorporated.)
DRV - (tcpipBM) -- C:\Windows\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (JMCR) -- C:\Windows\System32\drivers\jmcr.sys (JMicron Technology Corporation)
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvsmu) -- C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (nvstor32) -- C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://global.acer.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=0309&m=aspire_5737z

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2010.06.20 19:39:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.12 15:16:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.15 23:12:45 | 000,000,000 | ---D | M]

[2011.08.12 14:12:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\standard\AppData\Roaming\mozilla\Extensions
[2011.09.25 09:03:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\standard\AppData\Roaming\mozilla\Firefox\Profiles\l3x08d7v.default\extensions
[2011.11.11 10:10:04 | 000,000,000 | ---D | M] (@@toolbarname@@) -- C:\Users\standard\AppData\Roaming\mozilla\Firefox\Profiles\l3x08d7v.default\extensions\toolbar@ask.com
[2011.11.12 15:16:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.12.17 20:34:39 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.02.23 19:38:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\webbooster@iminent.com
[2011.11.12 15:16:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010.07.31 15:42:28 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.11.12 15:16:30 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.11.12 15:16:30 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.11.12 15:16:30 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.11.12 15:16:30 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.11.12 15:16:30 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.11.12 15:16:30 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google: originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms }
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U21 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google-Suche = C:\Users\standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Skype Click to Call = C:\Users\standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.8.0.8855_0\
CHR - Extension: Google Mail = C:\Users\standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\

O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No CLSID value found.
O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe ({StringFileInfo_CompanyName})
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKCU..\Run: [iexploer.exe] C:\Users\standard\AppData\Roaming\Microsoft\Internet Explorer\iexploer.exe ()
O4 - HKCU..\Run: [Microsoft® Windows Manager] C:\Users\standard\M-1-25-5432-6437-5685\winmgr.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe File not found
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} hxxp://turnier.freenet.de/ctl/kingcomie.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3C136A47-E9CD-412C-BC6E-9263DFF9E91B}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\x-sdch - No CLSID value found
O20 - AppInit_DLLs: (C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\standard\Pictures\handybilder\CIMG2977.JPG
O24 - Desktop BackupWallPaper: C:\Users\standard\Pictures\handybilder\CIMG2977.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{080fc061-ab9b-11de-95c5-00235a49e57f}\Shell\AutoRun\command - "" = F:\Menu.exe
O33 - MountPoints2\{1d8d9ee4-0ff8-11de-a641-00242b4db9a8}\Shell - "" = AutoRun
O33 - MountPoints2\{1d8d9ee4-0ff8-11de-a641-00242b4db9a8}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{5871a5a9-2b26-11de-82b5-00235a49e57f}\Shell - "" = AutoRun
O33 - MountPoints2\{5871a5a9-2b26-11de-82b5-00235a49e57f}\Shell\AutoRun\command - "" = G:\VoiceMemoPlayer.exe
O33 - MountPoints2\{65bf3f75-e04d-11df-9438-00235a49e57f}\Shell - "" = AutoRun
O33 - MountPoints2\{65bf3f75-e04d-11df-9438-00235a49e57f}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.hta
O33 - MountPoints2\{794dd61d-7c9a-11df-8f76-00235a49e57f}\Shell - "" = AutoRun
O33 - MountPoints2\{794dd61d-7c9a-11df-8f76-00235a49e57f}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{794dd624-7c9a-11df-8f76-001e101f7fb6}\Shell - "" = AutoRun
O33 - MountPoints2\{794dd624-7c9a-11df-8f76-001e101f7fb6}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{aecf2474-f176-11e0-ab1e-001e101f3315}\Shell - "" = AutoRun
O33 - MountPoints2\{aecf2474-f176-11e0-ab1e-001e101f3315}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{aecf2480-f176-11e0-ab1e-00235a49e57f}\Shell - "" = AutoRun
O33 - MountPoints2\{aecf2480-f176-11e0-ab1e-00235a49e57f}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{cb0ca924-2f98-11e1-8c52-00235a49e57f}\Shell - "" = AutoRun
O33 - MountPoints2\{cb0ca924-2f98-11e1-8c52-00235a49e57f}\Shell\AutoRun\command - "" = G:\AP.exe
O33 - MountPoints2\{cc26ef88-f255-11e0-a122-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{cc26ef88-f255-11e0-a122-806e6f6e6963}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{cc26efd3-f255-11e0-a122-00242b4db9a8}\Shell - "" = AutoRun
O33 - MountPoints2\{cc26efd3-f255-11e0-a122-00242b4db9a8}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011.12.30 20:29:20 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\standard\Desktop\OTL.exe
[2011.12.27 16:42:39 | 000,000,000 | RHSD | C] -- C:\Users\standard\M-1-25-5432-6437-5685
[2011.12.08 17:25:58 | 000,000,000 | ---D | C] -- C:\Users\standard\AppData\Local\PackageAware
[2008.12.12 20:24:21 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll
[1 C:\Users\standard\AppData\Local\*.tmp files -> C:\Users\standard\AppData\Local\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011.12.30 20:30:13 | 000,028,124 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011.12.30 20:29:21 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\standard\Desktop\OTL.exe
[2011.12.30 20:28:26 | 000,618,442 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.12.30 20:28:26 | 000,587,178 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.12.30 20:28:26 | 000,122,842 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.12.30 20:28:26 | 000,101,250 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.12.30 20:25:06 | 000,000,432 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{C6F5F648-2C17-4450-981D-FCA22CBD87C9}.job
[2011.12.30 20:21:21 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.12.30 20:21:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.30 20:20:50 | 2951,094,272 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.30 20:19:56 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.30 20:19:55 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.30 20:18:11 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.12.30 19:38:06 | 000,028,124 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2011.12.08 19:17:17 | 000,134,856 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[1 C:\Users\standard\AppData\Local\*.tmp files -> C:\Users\standard\AppData\Local\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.12.29 20:37:36 | 2951,094,272 | -HS- | C] () -- C:\hiberfil.sys
[2011.08.13 15:09:24 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2011.03.03 08:00:48 | 000,000,361 | ---- | C] () -- C:\Windows\wininit.ini
[2011.02.03 09:43:12 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010.11.11 20:19:24 | 000,021,080 | ---- | C] () -- C:\Windows\System32\drivers\ntiopnp.sys
[2010.08.10 14:49:36 | 000,011,392 | ---- | C] () -- C:\Windows\System32\drivers\ntiomin.sys
[2010.06.12 20:49:51 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009.12.24 17:32:56 | 000,000,000 | ---- | C] () -- C:\Windows\PTWebCam.INI
[2009.10.18 18:28:52 | 000,000,340 | ---- | C] () -- C:\ProgramData\fillup
[2009.09.24 06:31:15 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.24 06:31:15 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.08.04 18:18:58 | 000,010,938 | ---- | C] () -- C:\Users\standard\AppData\Roaming\antje.xml
[2009.08.04 18:15:51 | 000,000,377 | ---- | C] () -- C:\Users\standard\AppData\Roaming\users.xml
[2009.07.04 19:33:28 | 000,000,056 | ---- | C] () -- C:\Users\standard\AppData\Roaming\wklnhst.dat
[2009.06.25 11:58:49 | 000,008,192 | ---- | C] () -- C:\Windows\d3dx.dat
[2009.06.19 16:19:05 | 000,032,608 | ---- | C] () -- C:\Windows\king-uninstall.exe
[2009.06.16 12:25:02 | 000,121,512 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2009.03.06 19:51:04 | 000,026,624 | ---- | C] () -- C:\Users\standard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.03.06 14:37:02 | 000,028,124 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009.03.06 14:17:47 | 000,028,124 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009.03.06 13:57:53 | 000,007,592 | ---- | C] () -- C:\Users\standard\AppData\Local\d3d9caps.dat
[2009.03.06 13:52:36 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2009.03.06 13:52:36 | 000,200,704 | ---- | C] () -- C:\Windows\PLFSetI.exe
[2009.03.06 13:52:36 | 000,009,216 | ---- | C] () -- C:\Windows\usbvideo_reg.exe
[2009.03.06 13:52:36 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini
[2008.12.12 20:22:50 | 000,014,640 | ---- | C] () -- C:\Windows\System32\RaCoInst.dat
[2008.12.12 13:42:34 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIOFM4.dll
[2008.12.12 13:42:34 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN5.dll
[2008.12.12 13:02:37 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX2.dat
[2008.12.12 13:02:37 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX1.dat
[2008.12.12 13:02:37 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX0.dat
[2008.12.12 13:02:37 | 000,000,008 | ---- | C] () -- C:\Windows\System32\drivers\rtkhdaud.dat
[2008.12.12 12:11:45 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008.01.21 08:15:58 | 000,618,442 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008.01.21 08:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008.01.21 08:15:58 | 000,122,842 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008.01.21 08:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:47:37 | 000,383,720 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:33:01 | 000,587,178 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,101,250 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2001.12.26 16:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001.09.03 23:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001.07.30 16:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001.07.23 22:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll

========== LOP Check ==========

[2010.02.15 15:33:50 | 000,000,000 | -HSD | M] -- C:\Users\standard\AppData\Roaming\.#
[2010.10.17 12:26:05 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\A Gypsy's Tale - Der Turm des Schicksals
[2008.12.12 13:29:07 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Acer GameZone Console
[2009.09.20 09:28:49 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Aisle 5 Games, Inc
[2010.02.09 13:30:01 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Alawar
[2009.09.13 15:04:53 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Anabel
[2011.03.03 08:01:21 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Artogon
[2009.09.13 16:14:31 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Babylonia
[2009.11.04 07:16:30 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Batovi
[2009.06.19 13:10:47 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\BeachPartyCraze
[2009.09.10 10:14:09 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Big Fish
[2010.05.20 19:50:40 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Big Fish Games
[2009.09.28 20:32:14 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\BlamGames
[2010.01.02 20:15:19 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\blg
[2009.07.01 11:52:50 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Boolat Games
[2011.03.31 10:00:29 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Boomzap
[2009.07.29 09:27:42 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\BrandX Games
[2009.11.15 14:42:39 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Burdaloo
[2010.06.20 19:40:24 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Bytemobile
[2009.09.08 20:07:02 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Camel101
[2011.08.09 20:13:26 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Canneverbe Limited
[2009.10.13 09:49:33 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\CasualForge
[2009.11.16 19:21:35 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\cerasus.media
[2010.08.06 07:41:15 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\DarkParablesBriarRose_BFG_SE
[2010.07.12 09:26:01 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\de.myphotobook.creator.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1
[2009.12.14 19:54:13 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Dekovir
[2009.12.09 19:22:04 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\DivoGames
[2009.12.30 21:35:31 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\DruidsBattleOfMagic
[2009.12.21 19:05:25 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\EleFun Games
[2009.12.28 19:40:04 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\ElementalsTheMagicKey
[2010.11.20 20:31:56 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Enki Games
[2010.01.02 18:30:19 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Enlightenus
[2010.10.17 10:34:55 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Enlightenus2SE_BFG
[2009.12.02 09:10:53 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\ERS G-Studio
[2009.09.20 13:31:10 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\EscapeFromParadise2
[2009.06.18 14:01:48 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\eSobi
[2009.10.18 18:28:25 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\fillup
[2009.06.30 09:34:03 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\FirstColony
[2009.08.11 07:02:28 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Flood Light Games
[2009.12.15 19:09:56 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\FlyWheelGames
[2009.12.31 15:06:03 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Gaijin Ent
[2009.06.29 19:30:44 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\GameInvest
[2010.01.25 12:46:24 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Gamelab
[2009.09.07 18:04:48 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Gamers Digital
[2009.08.30 12:08:52 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\GAMESHASTRA
[2009.08.30 07:43:53 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Gogii Games
[2009.12.02 13:19:51 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Gold Casual Games
[2009.12.16 11:54:11 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\GraveyardShift
[2009.09.28 07:36:58 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Hidden Island Data
[2009.07.30 08:09:27 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\HiT-MM
[2011.11.04 18:11:03 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\ICQ
[2009.10.04 16:09:22 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\IronCode
[2009.11.11 13:20:00 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Island
[2009.07.18 19:34:50 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Jane s Hotel Family Hero
[2009.10.09 17:41:12 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\JewelMatch2
[2009.09.12 12:14:49 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Little Games Company
[2009.08.15 22:42:18 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Lost in the City
[2009.12.03 07:21:14 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\MA
[2010.08.06 15:25:02 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\MagicIndie
[2009.09.12 21:00:30 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Mean Hamster
[2009.11.17 21:45:37 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\MegaplexMadnessSummerBlockbuster
[2009.06.15 12:06:38 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Meridian93
[2010.02.10 16:07:44 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Merscom
[2010.02.08 17:07:58 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Oberon Games
[2009.06.29 22:29:49 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\panoramik
[2009.11.23 21:01:04 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Peace Craft
[2009.07.21 19:38:51 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\PetShowCraze
[2009.12.07 08:49:37 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Ph03nixNewMedia
[2011.03.03 12:14:47 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Phantasmat_bf_se1
[2011.12.30 17:36:53 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\PhotoScape
[2010.08.05 11:38:21 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\PlayFirst
[2010.01.18 13:42:48 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Playrix Entertainment
[2009.10.06 18:45:31 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Princess Isabella
[2009.07.07 22:09:32 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\RobinsonCrusoe
[2009.07.25 14:28:15 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\RobinsonCrusoeBFGDE
[2009.12.31 14:04:57 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Sanna
[2009.10.17 11:07:25 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\she_is_a_shadow
[2009.08.17 20:27:15 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\ShinyTales
[2009.07.27 12:36:07 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Skunk Studios
[2009.04.23 07:01:39 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\SoftDMA
[2009.11.04 13:04:26 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\SprillRichiGerman
[2009.09.21 18:58:30 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\SultansLabyrinth
[2009.10.16 13:43:08 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\SulusGames
[2011.10.07 11:56:58 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\TeamViewer
[2009.10.16 18:17:28 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Template
[2011.10.03 20:38:49 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\TuneUp Software
[2009.08.22 18:16:24 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Twintale Entertainment
[2009.07.11 13:21:37 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\UClick
[2010.01.01 19:29:05 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\URSE Games
[2009.09.25 16:09:25 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\V-Games
[2009.07.19 20:18:18 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Valusoft
[2010.01.19 15:34:24 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\VampireSaga
[2009.07.15 14:33:02 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\ViquaSoft
[2010.02.12 14:40:49 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Virtual City
[2010.06.20 19:40:23 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Vodafone
[2011.03.02 11:04:22 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\WhiteBirdsProductions
[2009.06.25 11:58:53 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\World-LooM
[2009.09.30 19:37:15 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\YoudaGames
[2011.12.30 20:19:55 | 000,032,538 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.12.30 20:25:06 | 000,000,432 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{C6F5F648-2C17-4450-981D-FCA22CBD87C9}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\ProgramData\Temp: DAFD38AE
@Alternate Data Stream - 99 bytes -> C:\ProgramData\Temp:9E3E060F
@Alternate Data Stream - 98 bytes -> C:\ProgramData\Temp:5D351BC6
@Alternate Data Stream - 96 bytes -> C:\ProgramData\Temp:B6DD2C7E
@Alternate Data Stream - 96 bytes -> C:\ProgramData\Temp:B2CD146E
@Alternate Data Stream - 96 bytes -> C:\ProgramData\Temp:8CCDAB14
@Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:6D635C5B
@Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:52E1DB1D
@Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:46700142
@Alternate Data Stream - 208 bytes -> C:\ProgramData\Temp:7B52659E
@Alternate Data Stream - 201 bytes -> C:\ProgramData\Temp:24FECE50
@Alternate Data Stream - 197 bytes -> C:\ProgramData\Temp:331B76C7
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:8C81B36D
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:966CEAE7
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:23834E1E
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:17F7AEA3
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:CEE4A457
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:AC73CDCE
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:22741C1F
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:F43B7E8F
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp: DC0B1070
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:0BBF232A
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:EEB25EAE
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:28CDD861
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:FB647F34
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:F78CC2A2
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:5A27D490
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:550179F5
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:178093AE
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:10F6E97E
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:FDAF118C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:CBEB737E
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:A4076A3B
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:89C28CF6
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:02B823FE
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:981884E7
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:5E413CD6
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:E14FA16F
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:9026FFAC
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp: D0D17155
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:74456BF5
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:6247E766
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:3095BD69
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:EDC744FB
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:EA701346
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:C10635F6
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:F45F3031
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:55C54F7C
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:4D7FCCD3
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:1C6CB897
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:FED25C29
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:A5584049
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:88B61AC3
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:737160C1
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:5425B7F5
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:FF7D915E
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:FDDD8917
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp: DE47A3DA
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:B845F669
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:AD727397
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:943E8182
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:93226FE3
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:697DDE2B
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:43E95997
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:2AE74FF9
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp: D31BE97C
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:C0A2E219
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:6FDE1666
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:69E3AF64
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:1DEE6B65
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp: D02FBAEC
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:A561576B
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:101708D3
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:0DFE2AE1
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:BE6DC701
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:A26AFC00
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:7AF9CAEB
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:5335CE76
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:45F3AD49
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:33384BC0
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:25249477
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:FEEEFFAD
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:BB71BBA2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:4CF76F21
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:490BCC52
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:3B4DA230
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:1B7E2022
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:FB97DB91
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:AB6E0B6B
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:85C3B823
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:E6D148BC
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:CB16385F
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:C74009E5
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:B6285236
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:B3942462
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:A8F2382B
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:89A5891E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:896E1EFF
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:5C6EBC69
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:4DCAC4BC
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:41D1C7CB
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:35C78DCC
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:0E22C5DB
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:008586AE
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:957E9765
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:8C6D2EC3
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:7B2BB690
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:69AF9D20
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:615435BE
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:38849DE5
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:122B409D
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:FECEF728
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:E91ADC66
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:A3E39C6A
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:98DFF516
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:969C0C96
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:57EE48CA
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:3E06C78F
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:3BF63E4A
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:375FC7E7
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:30376ACC
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:A7B70C4E
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:870649A4
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:2FC7B9E4
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:059167AF
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:F986CC21
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:E7C9DAAE
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:CFDE7852
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:CB0FEE2B
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:C0DFB793
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:BD9F7E4E
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:B1FBA7E1
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:5EF1AD34
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:4D066AD2
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:1ECED34B
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:17C48B08
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:0D52F295
@Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp: DE9F4320
@Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:B6FD7157
@Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:72E6616C
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:E3CEEC4C
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:C3C72D5F
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:9ACE4E8E
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:9ACB70D7
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:66AA0486
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:439E3411
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:2495D97A
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:237E4B91
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:FE66A7BB
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:FC2E567F
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:C22674B6
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:B093E177
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:A02025CE
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:8DF68137
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:7C412B92
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:2B1EA607
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp: D2397415
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:69FD6BF0
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:483AC68A
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:3815BC84
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:0F0A5896
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:AC116044
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:6677D85A
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:4A2862FF
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:FC2D0F32
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:F35AE645
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:99A29126
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:7920E530
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:5E9B629B
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:3FD496E1
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:109734F6
@Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:A0A7408F
@Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:33611CFB
@Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:12EA4DC9
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:AF54CFFD
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:A688EF17
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:8B4B9596
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:7FCB9D0D
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:6FE17A89
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:51F17BB8
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:FDCAE7B5
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp: D994162E
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:CEF2A14E
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:B12D1A7D
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:73933431
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:663B62CA
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:4FE30352
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:4F96D8E6
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:471AD3D0
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:3D36932D
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:8BCF4DE2
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:70E897B5
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:537E6E55
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:1A4BF204
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:097FF903
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:F2AF86D9
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp: DF0BC727
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:C4A1F01E
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:708BB0FA
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:561568A4
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:4A1628E5
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:2F141B68
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:12D2EB9C
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:7A0FEE87
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:1B927722
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:0ED4AC2F
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:05113FB9
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp: D0668210
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:554C6431
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:10D98D98
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:97C4F81F
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:8F00BFC0
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:6BF0805F
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:523B97A0
@Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:CC7738DB
@Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:52206035
@Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:4FE42FFC
@Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp: D8DB81DC
@Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:92A815D8
@Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:1CE87230
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:FFD42BAF
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp: D92485C9
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:BFAD7A5D
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:B1FCBEB0
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:569CEE83
@Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:9E4F05ED
@Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:71FA8B7F
@Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:67BA17B9
@Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:5A437AC3
@Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:53DF59D1
@Alternate Data Stream - 102 bytes -> C:\ProgramData\Temp:5A8F8A0C
@Alternate Data Stream - 102 bytes -> C:\ProgramData\Temp:213AFE42
@Alternate Data Stream - 101 bytes -> C:\ProgramData\Temp:E32966C0
@Alternate Data Stream - 101 bytes -> C:\ProgramData\Temp:CF61CE5A
@Alternate Data Stream - 101 bytes -> C:\ProgramData\Temp:C07A6A6B
@Alternate Data Stream - 101 bytes -> C:\ProgramData\Temp:BDCD0530
@Alternate Data Stream - 101 bytes -> C:\ProgramData\Temp:9C8D5426
@Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:BDF08FAF
@Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:A745DB5D
@Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:8DA9DB01

< End of report >

cosinus 30.12.2011 23:24

Zitat:

Cannot determine boot mode.
Funktioniert noch der abgesicherte Modus mit Netzwerktreibern?




Abgesicherter Modus zur Bereinigung
  • Windows mit F8-Taste beim Start in den abgesicherten Modus bringen.
  • Starte den Rechner in den abgesicherten Modus mit Netzwerktreibern:

    Windows im abgesicherten Modusstarten

cbone11 02.01.2012 10:53

guten morgen und noch ein gesundes neues

abgesicherter modus mit netzwerktreibern funktioniert, bekomme die meldung so nicht angezeigt.

wie soll ich weiter verfahren?

gruss

cbone11 02.01.2012 11:20

jetzt kam die meldung auch im abgesicherten modus mit netzwerktreibern.

die protokolle wurden im modus verzeichnisdienstwiederherstellung erstellt.

bin für jede hilfe dankbar

gruss

cosinus 02.01.2012 14:10

Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

cbone11 05.01.2012 13:42

hallo, malware lief problemlos.
hier das log:

Code:

Malwarebytes Anti-Malware (Test) 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.03.01

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19120
standard :: STANDARD-PC [Administrator]

Schutz: Aktiviert

03.01.2012 15:15:24
mbam-log-2012-01-03 (15-15-24).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 294245
Laufzeit: 1 Stunde(n), 20 Minute(n), 44 Sekunde(n)

Infizierte Speicherprozesse: 1
C:\Users\standard\M-1-25-5432-6437-5685\winmgr.exe (Trojan.MSIL) -> 2724 -> Löschen bei Neustart.

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Microsoft® Windows Manager (Trojan.MSIL) -> Daten: C:\Users\standard\M-1-25-5432-6437-5685\winmgr.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 2
C:\Recycle.Bin (Trojan.Spyeyes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\standard\M-1-25-5432-6437-5685 (Trojan.Agent.Gen) -> Löschen bei Neustart.

Infizierte Dateien: 14
C:\Users\standard\M-1-25-5432-6437-5685\winmgr.exe (Trojan.MSIL) -> Löschen bei Neustart.
C:\Program Files\CPUCooL\instser.exe (Adware.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\standard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1ORBYN5O\fa[2].exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\standard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H5CGXN6X\b[1].exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\standard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H5CGXN6X\st[1].exe (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\standard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCIG6OC3\fa[1].exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\standard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCIG6OC3\fa[2].exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\standard\AppData\Local\Temp\4160436.exe (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\standard\AppData\Local\Temp\4283528.exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\standard\AppData\Local\Temp\0336126.exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\standard\AppData\Local\Temp\78673.exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\standard\Downloads\IMG28057850.JPEG.scr (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt.
D:\Downloads\IMG28057850.JPEG.scr (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Recycle.Bin\BAE4C87C70DDC49 (Trojan.Spyeyes) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

bei ESET geht der Laptop immer aus, 10 versuche gestartet und bei einer Stunde 10 geht der laptop immer aus.

hoffe das reicht erstmal, ansonsten versuch ichs nochmal. habe aber wenig hoffnung da er immer ausgeht.

gruss

cosinus 05.01.2012 15:08

Zitat:

C:\Recycle.Bin (Trojan.Spyeyes)
Wenn du auch noch andere Dinge erledigen willst als nur Zocken oder Solitär spielen wie zB E-Mails abrufen oder alles was Logins erfordert dann solltest du deine Daten sichern, den Rechner komplett plätten und eine Neuinstallation von Windows durchführen.
Anschließend auch sämtliche Passwörter ändern!!!

Mit komplett plätten wird gemeint: alle Partitionen auflösen, neu erstellen und formatieren. Helfen kann dabei ein Tool wie DBAN oder die Laufwerksverwaltung in einem Ubuntu im Ausprobiermodus.

Praktischerweise kann man mit diesem Live-Linux auch ziemlich gefahrlos all seine wichtigen Daten auf eine externe Platte sichern.
kopiere nur persönliche Dateien, Musik, Videos, etc. auf die Backupplatte, KEINE ausführbaren Dateien wie Programme/Spiele/Setups!!


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:43 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129