Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Habe ich einen Virus (https://www.trojaner-board.de/86368-habe-virus.html)

Darkfilter 23.05.2010 22:34

Habe ich einen Virus
 
Hi Leute,
habe mein Vierenprogramm laufen lassen und er fand folgendes:TR/Spy.Bebloh.A.55 (2 mal)
'EXP/Java.3243

Dies wurde jedoch nur verschoben in die Quarantäne. Wie kann ich diese Vieren löschen?

Hijack:
HiJackthis Logfile:
Code:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:23:24, on 23.05.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
G:\Programme\Mozilla Firefox\firefox.exe
C:\Users\Nico\Downloads\jxpiinstall.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Nico\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "F:\Programme\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "G:\Programme\Adobe Reader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "F:\Programme\Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RGSC] F:\Programme\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Steam] "f:\programme\steam\steam.exe" -silent
O4 - HKCU\..\Run: [RTHDBPL] C:\Users\Nico\AppData\Roaming\SystemProc\lsass.exe
O4 - HKCU\..\Run: [iTap] C:\Program Files\HLW\iTap\iTap.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Product Registration.lnk = C:\Users\Nico\AppData\Local\Temp\is-OANTQ.tmp\ATR1.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: HP Smart Web Printing ein- oder ausblenden - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - F:\Program Files\ICQ6.5\ICQ.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - F:\Program Files\ICQ6.5\ICQ.exe (file missing)
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - Unknown owner - F:\Programme\Hamachi\hamachi-2.exe (file missing)
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 6588 bytes

Danke im Voraus

cosinus 23.05.2010 23:10

Hallo und :hallo:

Zitat:

Dies wurde jedoch nur verschoben in die Quarantäne. Wie kann ich diese Vieren löschen?
Was habt Ihr eigentlich alle nur mit der Quarantäne??
Ein schädliches Objekt in der Quarantäne ist isoliert, das kommt einem Löschen gleich mit der Ausnahme, dass man notfalls nochmal Dateien, die versehentlich gelöscht wurden (bei Fehlalarmen!!) wiederherstellen kann!

Bitte nen Vollscan mit malwarebytes machen und Log posten. Danach OTL:

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.

Darkfilter 25.05.2010 17:30

Logfile von OTL:

OTL Logfile:
Code:

OTL logfile created on: 25.05.2010 18:24:06 - Run 1
OTL by OldTimer - Version 3.2.5.0    Folder = C:\Users\Nico\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 58,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698,63 Gb Total Space | 453,44 Gb Free Space | 64,90% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 465,76 Gb Total Space | 224,37 Gb Free Space | 48,17% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: NICO-PC
Current User Name: Nico
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Nico\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - G:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\ATI\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)
PRC - C:\Program Files\ATI\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Nico\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Hamachi2Svc) --  File not found
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (npggsvc) -- C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (AtiHdmiService) -- C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (SSHDRV61) -- C:\Windows\System32\drivers\SSHDRV61.sys ()
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (SSHDRV76) -- C:\Windows\System32\drivers\SSHDRV76.sys ()
DRV - (SSHDRV51) -- C:\Windows\System32\drivers\SSHDRV51.sys ()
DRV - (SSHDRV52) -- C:\Windows\System32\drivers\SSHDRV52.sys ()
DRV - (StarOpen) -- C:\Windows\System32\drivers\StarOpen.sys ()
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (VClone) -- C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (ElbyCDIO) -- C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (JRAID) -- C:\Windows\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (NPPTNT2) -- C:\Windows\System32\npptNT2.sys (INCA Internet Co., Ltd.)
DRV - (prohlp02) -- C:\Windows\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prodrv06) -- C:\Windows\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (prosync1) -- C:\Windows\System32\drivers\prosync1.sys (Protection Technology)
DRV - (TIEHDUSB) -- C:\Windows\System32\drivers\tiehdusb.sys (Texas Instruments Incorporated)
DRV - (sfhlp01) -- C:\Windows\System32\drivers\sfhlp01.sys (Protection Technology)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DA 4E EF 96 36 0A CA 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledItems: autopager@mozilla.org:0.6.0.26
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.60
FF - prefs.js..extensions.enabledItems: NPDyyno@dyyno.com:1.0.0.24
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
 
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.02.11 21:29:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: F:\Programme\Mozilla Firefox\components
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: F:\Programme\Mozilla Firefox\plugins
 
[2009.04.29 20:00:21 | 000,000,000 | ---D | M] -- C:\Users\Nico\AppData\Roaming\mozilla\Extensions
[2010.05.24 15:22:19 | 000,000,000 | ---D | M] -- C:\Users\Nico\AppData\Roaming\mozilla\Firefox\Profiles\yv8unz8k.default\extensions
[2010.04.28 17:11:40 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Nico\AppData\Roaming\mozilla\Firefox\Profiles\yv8unz8k.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.04.28 17:11:40 | 000,000,000 | ---D | M] -- C:\Users\Nico\AppData\Roaming\mozilla\Firefox\Profiles\yv8unz8k.default\extensions\autopager@mozilla.org
[2009.06.14 21:37:11 | 000,000,000 | ---D | M] -- C:\Users\Nico\AppData\Roaming\mozilla\Firefox\Profiles\yv8unz8k.default\extensions\NPDyyno@dyyno.com
[2010.01.19 16:05:25 | 000,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2010.01.19 16:05:25 | 000,000,000 | ---D | M] (Internal security) -- C:\Program Files\mozilla firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] G:\Programme\Adobe Reader\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [hpqSRMon]  File not found
O4 - HKLM..\Run: [iTunesHelper] F:\Programme\iTunes\iTunesHelper.exe File not found
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] F:\Programme\Hamachi\hamachi-2-ui.exe File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Windows\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [iTap] C:\Program Files\HLW\iTap\iTap.exe File not found
O4 - HKCU..\Run: [RGSC] F:\Programme\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe File not found
O4 - HKCU..\Run: [RTHDBPL] C:\Users\Nico\AppData\Roaming\SystemProc\lsass.exe File not found
O4 - HKCU..\Run: [Steam] f:\programme\steam\steam.exe File not found
O4 - Startup: C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk = C:\Users\Nico\AppData\Local\Temp\is-OANTQ.tmp\ATR1.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra Button: HP Smart Web Printing ein- oder ausblenden - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - F:\Program Files\ICQ6.5\ICQ.exe File not found
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - F:\Program Files\ICQ6.5\ICQ.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Desert Landscape.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Desert Landscape.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0320e36e-7b6d-11de-9936-002185c17f27}\Shell - "" = AutoRun
O33 - MountPoints2\{0320e36e-7b6d-11de-9936-002185c17f27}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O33 - MountPoints2\{7daf253f-0eba-11df-beb7-002185c17f27}\Shell\AutoRun\command - "" = G:\Menu.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.05.23 23:25:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010.05.23 23:25:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010.05.23 23:24:45 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010.05.23 23:24:45 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.05.23 23:24:45 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.05.23 23:24:45 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.05.17 21:46:04 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Local\My Games
[2010.05.17 21:40:58 | 000,000,000 | ---D | C] -- C:\Program Files\2K Games
[2010.05.16 16:08:54 | 000,000,000 | ---D | C] -- C:\Die Sims 2
[2010.05.16 16:03:49 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Local\World in Conflict
[2010.05.16 16:03:38 | 000,000,000 | ---D | C] -- C:\Users\Nico\Documents\World in Conflict
[2010.05.16 15:48:02 | 000,000,000 | ---D | C] -- C:\Program Files\Sierra Games
[2010.05.15 20:59:25 | 000,000,000 | ---D | C] -- C:\Users\Nico\Documents\BFBC2
[2010.05.15 20:43:02 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2010.05.15 20:43:02 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2010.05.15 20:43:02 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2010.05.15 20:43:02 | 000,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2010.05.15 20:43:01 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2010.05.15 20:43:01 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2010.05.15 20:43:01 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2010.05.15 20:43:01 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2010.05.15 20:43:00 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2010.05.15 20:42:59 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2010.05.15 20:42:59 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2010.05.15 20:42:59 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2010.05.15 20:42:59 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2010.05.13 13:51:01 | 000,000,000 | ---D | C] -- C:\Users\Nico\Documents\RCT3
[2010.05.13 13:51:01 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\Atari
[2010.05.13 13:50:20 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\vlc
[2010.05.13 13:41:50 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\Leadertech
[2010.05.12 22:17:39 | 000,000,000 | ---D | C] -- C:\Users\Nico\Documents\NIKITA
[2010.05.12 22:17:29 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\NIKITA
[2010.05.03 13:28:22 | 000,000,000 | ---D | C] -- C:\Phenomedia AG
[2010.04.28 22:44:54 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2010.04.28 22:04:43 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\HPAppData
[2010.04.27 16:01:52 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
 
========== Files - Modified Within 30 Days ==========
 
[2010.05.25 18:25:36 | 002,883,584 | -HS- | M] () -- C:\Users\Nico\NTUSER.DAT
[2010.05.25 18:23:00 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{8D9D19FD-3BB5-49B2-A216-4F4719AB1F71}.job
[2010.05.25 18:20:39 | 001,418,806 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.05.25 18:20:39 | 000,618,204 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.05.25 18:20:39 | 000,586,980 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010.05.25 18:20:39 | 000,122,636 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.05.25 18:20:39 | 000,101,052 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.05.25 18:14:53 | 000,005,952 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.05.25 18:14:53 | 000,005,952 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.05.25 18:14:52 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.05.25 18:14:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.05.24 22:43:33 | 000,524,288 | -HS- | M] () -- C:\Users\Nico\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010.05.24 22:43:33 | 000,065,536 | -HS- | M] () -- C:\Users\Nico\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010.05.24 22:43:28 | 002,126,683 | -H-- | M] () -- C:\Users\Nico\AppData\Local\IconCache.db
[2010.05.24 15:12:02 | 000,002,379 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2010.05.23 16:27:12 | 000,000,116 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2010.05.23 13:25:09 | 000,000,312 | ---- | M] () -- C:\Windows\tasks\WebReg HP Photosmart C5300 series.job
[2010.05.23 02:31:05 | 000,139,128 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010.05.23 01:19:17 | 000,215,128 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2010.05.22 01:39:14 | 309,498,610 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010.05.17 21:52:28 | 000,001,337 | ---- | M] () -- C:\Users\Nico\Desktop\Civilization 4 - Colonization.lnk
[2010.05.16 15:57:43 | 000,000,801 | ---- | M] () -- C:\Users\Nico\Desktop\World in Conflict.lnk
[2010.05.15 20:58:49 | 000,001,104 | ---- | M] () -- C:\Users\Nico\Desktop\Battlefield Bad Company 2.lnk
[2010.05.15 20:57:42 | 000,138,056 | ---- | M] () -- C:\Users\Nico\AppData\Roaming\PnkBstrK.sys
[2010.05.15 20:57:26 | 002,434,856 | ---- | M] () -- C:\Windows\System32\pbsvc_bc2.exe
[2010.05.13 13:42:15 | 000,000,989 | ---- | M] () -- C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk
[2010.05.13 13:40:51 | 000,000,697 | ---- | M] () -- C:\Users\Public\Desktop\RollerCoaster Tycoon 3.lnk
[2010.05.12 21:46:53 | 000,024,576 | ---- | M] () -- C:\Users\Nico\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.12 11:21:16 | 000,221,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010.05.05 22:31:56 | 000,000,009 | ---- | M] () -- C:\Windows\pbase.dat
[2010.05.05 22:31:56 | 000,000,008 | ---- | M] () -- C:\Windows\npbase.dat
[2010.05.05 22:31:56 | 000,000,003 | ---- | M] () -- C:\Windows\ver.dat
[2010.04.28 22:44:33 | 000,272,168 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.04.28 22:24:06 | 000,000,680 | ---- | M] () -- C:\Users\Nico\AppData\Local\d3d9caps.dat
 
========== Files Created - No Company Name ==========
 
[2010.05.23 13:25:08 | 000,000,312 | ---- | C] () -- C:\Windows\tasks\WebReg HP Photosmart C5300 series.job
[2010.05.22 01:39:14 | 309,498,610 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010.05.17 21:51:37 | 000,001,337 | ---- | C] () -- C:\Users\Nico\Desktop\Civilization 4 - Colonization.lnk
[2010.05.16 15:57:16 | 000,000,801 | ---- | C] () -- C:\Users\Nico\Desktop\World in Conflict.lnk
[2010.05.15 20:58:28 | 000,001,104 | ---- | C] () -- C:\Users\Nico\Desktop\Battlefield Bad Company 2.lnk
[2010.05.15 20:57:42 | 000,138,056 | ---- | C] () -- C:\Users\Nico\AppData\Roaming\PnkBstrK.sys
[2010.05.15 20:57:26 | 002,434,856 | ---- | C] () -- C:\Windows\System32\pbsvc_bc2.exe
[2010.05.13 13:42:15 | 000,000,989 | ---- | C] () -- C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk
[2010.05.13 13:40:51 | 000,000,697 | ---- | C] () -- C:\Users\Public\Desktop\RollerCoaster Tycoon 3.lnk
[2010.04.07 03:22:08 | 000,023,040 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2010.03.05 02:11:22 | 000,041,872 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2010.02.04 16:53:07 | 001,970,176 | ---- | C] () -- C:\Windows\System32\d3dx9.dll
[2010.01.22 23:01:19 | 000,000,083 | ---- | C] () -- C:\Windows\WA.INI
[2009.11.28 12:19:53 | 000,000,040 | ---- | C] () -- C:\Windows\WeatherSet.ini
[2009.11.27 22:42:38 | 000,036,864 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV61.sys
[2009.10.16 13:54:05 | 000,000,280 | ---- | C] () -- C:\Windows\game.ini
[2009.09.25 19:17:47 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.07 20:37:01 | 000,000,004 | ---- | C] () -- C:\Windows\info147.sys
[2009.09.07 20:06:19 | 000,053,760 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV76.sys
[2009.09.06 18:52:02 | 000,021,504 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV51.sys
[2009.09.06 13:42:20 | 000,029,184 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV52.sys
[2009.08.02 12:41:22 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009.07.17 14:19:55 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2009.07.14 02:48:04 | 000,020,480 | ---- | C] () -- C:\Windows\System32\H@tKeysH@@k.DLL
[2009.07.07 21:31:32 | 000,144,384 | ---- | C] () -- C:\Windows\System32\miccyhook.dll
[2009.06.12 18:38:11 | 000,139,128 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2009.05.17 18:15:47 | 000,000,510 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2007.08.07 19:22:22 | 000,141,180 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[1997.11.17 18:13:16 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll
[1997.06.14 10:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll
< End of report >


Darkfilter 25.05.2010 17:30

2. Logfile:


OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 25.05.2010 18:24:06 - Run 1
OTL by OldTimer - Version 3.2.5.0    Folder = C:\Users\Nico\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 58,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698,63 Gb Total Space | 453,44 Gb Free Space | 64,90% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 465,76 Gb Total Space | 224,37 Gb Free Space | 48,17% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: NICO-PC
Current User Name: Nico
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- G:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "G:\Programme\Microsoft Viewer\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "G:\Programme\Microsoft Viewer\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "G:\Programme\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "G:\Programme\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-442773238-3665067095-4225304131-1000]
"EnableNotifications" = 1
"EnableNotificationsRef" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02AE2E85-F4DC-40C2-8FB4-D0E6046763F1}" = lport=10244 | protocol=6 | dir=in | app=system |
"{02E39A3D-A442-461D-BBF0-757515213DAD}" = lport=3390 | protocol=6 | dir=in | app=system |
"{06837C40-FF4C-465D-834B-85CA8093D46F}" = rport=10243 | protocol=6 | dir=out | app=system |
"{07CB54D0-0201-43D1-852A-9CDF899C79E1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{0ED49805-8EFB-40EE-BD53-E367C5E6E697}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{115C2BA7-2233-4322-8A32-B86B647422F9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{17C44A58-E42D-4801-AF3F-4F236C68BF2E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{1E04E061-B32F-404A-9CB5-9A49DBD7889C}" = lport=10244 | protocol=6 | dir=in | app=system |
"{24BC0501-E1DC-4822-9E13-8B5D054EC445}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{28CC590E-D41C-4380-8A9D-CD38429D2D9C}" = rport=138 | protocol=17 | dir=out | app=system |
"{29732F88-429C-497C-8D61-833D3861A7EB}" = rport=139 | protocol=6 | dir=out | app=system |
"{3433C4F7-6BB4-44F5-B37B-A2521739FC3D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{37263DE8-9CCC-4F0D-8440-2E74D3670993}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4063555D-277F-4977-96F7-692DC10A2545}" = rport=445 | protocol=6 | dir=out | app=system |
"{49969AAF-D9F4-4CDA-8C17-58579A46A3E3}" = lport=10243 | protocol=6 | dir=in | app=system |
"{4C920637-E15D-4F41-B765-F8FCDF4CF6E7}" = lport=445 | protocol=6 | dir=in | app=system |
"{51657973-419D-40D0-81EF-E94C6C3885F1}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{537A3742-1226-47F4-BE7F-6D8BC60F4F5C}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{53C4AAC8-6B76-4599-A065-2C8F2D0F56FB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5678D6BF-EA96-4DA6-A7E9-02ED1304E9F8}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{63B0B5BF-78E3-4D41-9E4C-538B5882CCDA}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{65789E52-29BD-4BA5-9F8A-58D5364F2CEA}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6849E627-1BDD-4246-BA98-8B9018C963C2}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{68E75825-6C86-4BF5-8CF0-0788FEF60A78}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{6CBA7093-F5CA-4B35-B126-783AD5F69D9E}" = rport=10244 | protocol=6 | dir=out | app=system |
"{6CF4D255-99A5-42A5-9158-BB65FBA25C59}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{6D8222DB-2330-4A38-A007-DF7AA94242EA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{747E57D4-ED60-4964-99C1-547D77BE48B2}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{7D2E965C-0C5E-43FC-BFC0-1A96513A7F56}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{899378CE-D96D-4BF4-8541-6F0CBABA4288}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{93913F85-7A30-413E-9342-FC4C37D9848B}" = lport=137 | protocol=17 | dir=in | app=system |
"{94579499-69C1-4987-B7B2-BDBFFB780024}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{95D1C9E9-D724-4F69-8B70-9C30392CEAAE}" = rport=10244 | protocol=6 | dir=out | app=system |
"{A029C1A0-4C27-417F-9D0A-6A6963EFB7EA}" = rport=137 | protocol=17 | dir=out | app=system |
"{A0E425D5-5485-4EA1-B455-AB9AF843ADEB}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{B17EC995-1BFB-4AB4-B865-5E59C2D05B09}" = lport=139 | protocol=6 | dir=in | app=system |
"{B4E6009D-085D-4512-93C9-D9DDA1F8CFAA}" = lport=138 | protocol=17 | dir=in | app=system |
"{BADEF0A2-29AC-4732-A456-99656AC753D0}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C440558E-B8ED-4760-949C-BDCFE5E7A693}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{CACEA92B-822D-4D1A-A54E-648BDD3419D8}" = lport=3390 | protocol=6 | dir=in | app=system |
"{CCBAFFB2-1129-4B23-8B1E-77B289C95615}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D9B24D8D-5F20-49D1-BCB9-E44A0F4255DF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E2E61CBE-1B8F-4D35-BA1E-C10CC0D68B9D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{E8EA674A-F1F4-438F-8ABD-8D0595DCEA0F}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{EA31851D-F54F-45E9-8A1C-D1FF5836487E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EBD159E3-0639-4332-BD0C-DB0836E0762B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F8786D21-4A2A-48F6-AA7E-700438077CE5}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FAD3EDED-7CA5-40E3-86F7-C9EFFE880C1F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FDB43EA3-0AA7-42D5-9954-4EF4D32B3C0D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E622DBC-ED75-4318-BDFE-ABA8582C3189}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{10CD0016-3968-4E30-8485-022828DD04FD}" = protocol=6 | dir=in | app=f:\programme\ubisoft\shaunwhite\shaunwhitesnowboardinggame.exe |
"{1634D116-6D18-4F9A-A62D-9E2DD14C5210}" = protocol=6 | dir=in | app=c:\program files\sierra games\wic_ds.exe |
"{184503D7-4E14-4AA4-957B-28C0FCAB061C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe |
"{1853A475-C03B-47F5-8AE4-1F5F20FBAF3B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{1B39EC54-2059-4735-80D2-9E472EE95CA0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{20818E8C-4BD5-4DFA-8010-8BA451E3E6F8}" = protocol=17 | dir=in | app=c:\program files\sierra games\wic_ds.exe |
"{212D0B65-8938-4698-BEF4-F8AD3A0E7AA7}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{21C38210-3C63-45B2-8C67-1C4E9509FFE7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{22960918-ED57-416C-ADED-1CC39C0112C1}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{23E44FA8-25BE-4D4D-8F5A-BC13065AFBF0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{26528D43-E4C7-4807-A1B6-92B32AC9F4E8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{285DC7A4-832E-4ECF-9F31-45BC6E817FE0}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{2CF1121A-DDB1-48EA-9B94-A24DD6826424}" = protocol=17 | dir=in | app=f:\programme\itunes\itunes.exe |
"{2F36DF23-D079-4AB3-AA51-0C5D914DD9C3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{31F73A4F-CA1F-4F22-8BA5-8796514869D7}" = protocol=17 | dir=in | app=f:\programme\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{363674AD-E4F8-4562-B265-4E6A17915D99}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{3CCB0CDD-8105-46FA-BD43-EC5ADFCD1143}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{421CCCA8-B77B-4F58-9016-18EFA99BEBE1}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{4308B23E-BAD6-475C-8A38-FCF27AC09351}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{44AE1CC7-6372-4A71-A424-96AD12884344}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{4F647465-0C2F-44E8-A1E5-40C1C0C9FB90}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{4F6F7A46-5D51-4F5E-9EA7-C300CB812D35}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{516E691A-0D0A-4BF8-825A-EEE6E27223C2}" = protocol=6 | dir=in | app=f:\programme\itunes\itunes.exe |
"{54BF8067-353F-4789-A579-19F74A0B8181}" = protocol=6 | dir=in | app=f:\program files\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{58CE0B16-50D2-4743-A41E-43BFD256DCC0}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{5ADCB0CC-C6B7-4ECC-8D7C-AEF4690A4E78}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5B2657E6-70D9-48BF-94F4-DD21D1D7939F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5D24E30B-2035-4A1A-9C9B-CBA06DF669E1}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{6492189D-D1B8-4FF2-9195-4F9643C2279B}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{69CA568C-67A2-4107-BEFD-86F9DD8E1CBD}" = protocol=6 | dir=out | app=system |
"{69EA3BA1-85F4-4AD5-AC07-48ABF2BA13FE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6A6E8455-A074-465D-9EB1-CB9E40433405}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{718BB000-440E-4DEE-BA20-17AAA085E470}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{71B4403E-2DDD-491D-BF1B-4FA499CD55D2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{753474C5-F1E6-4619-9083-5B644B70DCF5}" = protocol=6 | dir=in | app=c:\program files\activision\cod4\iw3mp.exe |
"{79ACE57B-93B4-4216-869C-B6AA10AF131A}" = protocol=17 | dir=in | app=c:\program files\midway games\rise and fall\riseandfall.exe |
"{7A437381-8981-4C12-9BDF-19D9615701CF}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{80538A2C-1B26-46FF-9EFA-591B7961B6A0}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{875186CD-2A59-44BC-AE0F-5DE2BF3EA945}" = protocol=6 | dir=in | app=c:\program files\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{882B0E4B-9E9D-4BB7-9954-91DB2A79E4DD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8B3938FB-2845-489A-AA59-45A88D12B0F0}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{8C22B901-5664-45F3-BC84-0EC309BB3CD7}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8CA407F9-8560-4E66-A588-CE465AA9BD28}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{9C8C870B-CC1A-4DFF-BB5F-04475C68D457}" = protocol=17 | dir=in | app=c:\users\nico\appdata\locallow\dyyno receiver\dppm.exe |
"{9CD2B854-92EA-4324-AF25-D6DBDBF74B65}" = protocol=6 | dir=in | app=f:\programme\ubisoft\shaunwhite\shaunwhitesnowboarding.exe |
"{9DA2B874-D77B-4A88-B137-35C91ED730FF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A2DACCE1-E27D-46BD-B869-3955D3B903BA}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A48F14D5-96B1-4976-B59A-D0D615BE51E9}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A6EC7876-7AA5-4A73-AD14-46D813118E53}" = protocol=17 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
"{A9C0319F-2C91-4863-8EE3-2061455881A0}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-dede-downloader.exe |
"{AC9CE1FF-3C90-446A-8229-823CA51F19D0}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{AE4ACB50-5660-4A8E-A919-6DF4D0966081}" = protocol=17 | dir=in | app=f:\programme\ubisoft\shaunwhite\shaunwhitesnowboarding.exe |
"{AEBD2AE3-A5B1-4129-BB4D-C0BECF348204}" = protocol=17 | dir=in | app=c:\program files\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{AFE886E0-4B18-45B3-B455-EC108009DE72}" = protocol=6 | dir=in | app=f:\programme\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{B015F6FF-2E90-4E23-B079-12122609DCD3}" = protocol=17 | dir=in | app=f:\programme\ubisoft\shaunwhite\shaunwhitesnowboardinggame.exe |
"{B8D5E00E-8277-4801-AEC5-604D67CFA48B}" = protocol=6 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
"{B9D5A4CC-32BD-4CBB-B48C-A4F822C2010F}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"{BBADE287-1BBA-497B-BB4E-27A7F209B482}" = protocol=17 | dir=in | app=c:\program files\sierra games\wic_online.exe |
"{BDB715CF-C5D0-4206-AAB6-16FAB249EA0F}" = protocol=6 | dir=in | app=c:\program files\sierra games\wic.exe |
"{BF6A4CFE-C534-4BF4-913A-14A4F802F3A0}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{BFDFD884-43DC-4040-BD2A-C0961EC39FF4}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{C20F8C31-5F20-490D-8EA4-53F609282A9B}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{C27ED155-9556-4E01-B45C-27B4603B95E1}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{C60ED85D-7B20-4B39-97F1-30D3FAEE3210}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CA3F72E1-0DDA-49C2-8E3F-2C87CE1D42CA}" = protocol=6 | dir=in | app=c:\users\nico\appdata\locallow\dyyno receiver\dppm.exe |
"{CA8FDE01-23C9-4D67-92EA-0FBE60832146}" = protocol=17 | dir=in | app=c:\program files\sierra games\wic.exe |
"{CADB7677-50B3-4A6D-872C-E3859DC9A66B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{CDB770A8-363E-4C55-9AE7-0AC399EF1F31}" = protocol=6 | dir=in | app=c:\program files\midway games\rise and fall\riseandfall.exe |
"{D0592BDA-AF6D-4782-AC54-B2462B84AECE}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{D2FDDBFE-FC88-4B7B-AC7A-4A4AFFED81D8}" = protocol=6 | dir=in | app=c:\program files\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe |
"{DAA6F83A-0139-4080-90C5-CFC8C1CDB12E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{DF0E44F2-6C81-453D-94C2-5B36DFE9A7C3}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{E23BFAD7-2890-4120-BA8F-AA5997DFD262}" = protocol=17 | dir=in | app=f:\program files\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{E47D85F5-B22D-4C97-8655-3880773E8E60}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-dede-downloader.exe |
"{E5270183-632A-4CF4-80A1-AA0E0A3A63F2}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{E71B8BB3-3D9E-4F55-A0B1-1B8F4BDDB1F8}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{EBE354B6-51D8-4461-953C-0EF5794A7AF7}" = protocol=17 | dir=in | app=c:\program files\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe |
"{EF8B480C-EC80-41DF-BCB5-5F272D372550}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{F2BAE327-765A-402B-AF47-CE9E571F11D5}" = dir=in | app=f:\programme\electronic arts\command and conquer tiberium wars\retailexe\1.9\cnc3game.dat |
"{F3E2C6F7-7FAB-472D-901B-5C8EDF8C5261}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F48989DD-0325-43AB-B1D8-7D7A857F49AB}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{F50E3981-D58A-430B-AC2F-6BCF68F93013}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{F527DBC3-7E15-4944-8A76-4C3D0C685449}" = protocol=17 | dir=in | app=c:\program files\activision\cod4\iw3mp.exe |
"{F9269BAF-4DE7-4AA9-B85D-024BD616274C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FC5E660B-4D7C-4DF0-9EA3-97BC86A0DCDE}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{FDA732FB-5664-4E6A-97CD-FC5476D3CAFA}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{FE3AEA0E-5474-487E-B316-649E77D0EC72}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{FEF9E9F4-A3C3-4A35-A302-ED0A421A44C4}" = protocol=6 | dir=in | app=c:\program files\sierra games\wic_online.exe |
"TCP Query User{03D7814F-5E6F-46F4-84FE-78048805EDA9}F:\programme\activision\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=f:\programme\activision\call of duty 2\cod2mp_s.exe |
"TCP Query User{0E2A9752-3FC5-4A7D-ABC1-DA9D5E0F0C66}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"TCP Query User{27D98D36-8826-4EDB-8F64-C79D54C12BCC}F:\programme\activision\call of duty 4 - modern warfare\iw3mp.exe" = protocol=6 | dir=in | app=f:\programme\activision\call of duty 4 - modern warfare\iw3mp.exe |
"TCP Query User{28BB3054-CC82-4FA3-8425-F8C89CE01A79}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{2A82EC34-2E5E-48FB-B505-8DD000885F6D}C:\program files\java\jre6\launch4j-tmp\jdownloader.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\launch4j-tmp\jdownloader.exe |
"TCP Query User{2C61F42C-5320-4F4D-8195-02916E3B2EA1}F:\programme\worms armageddon\wa.exe" = protocol=6 | dir=in | app=f:\programme\worms armageddon\wa.exe |
"TCP Query User{3349B1D8-47DB-4203-9CCB-1B5EB83F2B5A}F:\programme\activision\cod\codmp.exe" = protocol=6 | dir=in | app=f:\programme\activision\cod\codmp.exe |
"TCP Query User{3DBB8869-B3DD-485D-AE09-BC7B3A9E8549}C:\program files\activision\cod\codmp.exe" = protocol=6 | dir=in | app=c:\program files\activision\cod\codmp.exe |
"TCP Query User{3F699397-5447-4D89-8C8C-46EBD379E1A2}C:\program files\postal2stp\system\postal2.exe" = protocol=6 | dir=in | app=c:\program files\postal2stp\system\postal2.exe |
"TCP Query User{3FCC6601-673B-4373-9488-5E9A1620FB69}F:\programme\microsoft games\age of empires 2 the age of kings\empires2.exe" = protocol=6 | dir=in | app=f:\programme\microsoft games\age of empires 2 the age of kings\empires2.exe |
"TCP Query User{41E78F66-F1BE-4B6E-9933-179B5042BC9C}F:\programme\metin2\metin2.bin" = protocol=6 | dir=in | app=f:\programme\metin2\metin2.bin |
"TCP Query User{48344DDA-927A-4172-BCB0-0DBC38391791}C:\users\nico\desktop\neuer ordner\coduomp.exe" = protocol=6 | dir=in | app=c:\users\nico\desktop\neuer ordner\coduomp.exe |
"TCP Query User{4917B38A-8BE7-4B03-BCB8-8B5DFC26872C}F:\programme\metin2\metin2client.bin" = protocol=6 | dir=in | app=f:\programme\metin2\metin2client.bin |
"TCP Query User{4A242EA3-0D8C-415E-8FD7-9A50E3E8E9AE}F:\programme\dead space\dead space.exe" = protocol=6 | dir=in | app=f:\programme\dead space\dead space.exe |
"TCP Query User{5E47DFE3-9F89-4353-96DD-D52D934DA735}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{6A78EB0E-986A-4631-A66B-DBD7F86F660C}C:\program files\wow\repair.exe" = protocol=6 | dir=in | app=c:\program files\wow\repair.exe |
"TCP Query User{74B98BE2-0707-4254-A158-FC10493F37D9}C:\program files\left 4 dead\left4dead.exe" = protocol=6 | dir=in | app=c:\program files\left 4 dead\left4dead.exe |
"TCP Query User{79131458-1A9B-4BD2-A678-474904C09927}F:\programme\battlefield vietnam\bfvietnam.exe" = protocol=6 | dir=in | app=f:\programme\battlefield vietnam\bfvietnam.exe |
"TCP Query User{7E9285ED-D436-4A1E-9E0E-3A07C8B79FF3}F:\programme\electronic arts\command & conquer 3\retailexe\1.9\cnc3game.dat" = protocol=6 | dir=in | app=f:\programme\electronic arts\command & conquer 3\retailexe\1.9\cnc3game.dat |
"TCP Query User{80B38D5E-89D2-4638-A37A-4F133DDBEC12}F:\programme\tom clancy's h.a.w.x\hawx.exe" = protocol=6 | dir=in | app=f:\programme\tom clancy's h.a.w.x\hawx.exe |
"TCP Query User{8820DC4B-94DF-4C69-99B5-60A31DE2C44C}C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\german\setup.exe" = protocol=6 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\german\setup.exe |
"TCP Query User{993397FF-DB0A-40E9-B41F-26D711FE4420}C:\program files\activision\cod\coduomp.exe" = protocol=6 | dir=in | app=c:\program files\activision\cod\coduomp.exe |
"TCP Query User{A85664EE-CF49-4CAB-8412-8D88AB7F80E6}C:\program files\wow\launcher.exe" = protocol=6 | dir=in | app=c:\program files\wow\launcher.exe |
"TCP Query User{A9E53ACF-476C-4D7E-A729-3560AD3A4477}C:\users\nico\appdata\local\temp\electronicarts_patcher_000.exe" = protocol=6 | dir=in | app=c:\users\nico\appdata\local\temp\electronicarts_patcher_000.exe |
"TCP Query User{B2BAE860-49B7-494F-999C-3F128281A40E}F:\programme\far cry 2\bin\farcry2.exe" = protocol=6 | dir=in | app=f:\programme\far cry 2\bin\farcry2.exe |
"TCP Query User{B5A54A0A-4FD5-4C71-AED4-B795E5F5688F}C:\program files\activision\cod4\iw3mp.exe" = protocol=6 | dir=in | app=c:\program files\activision\cod4\iw3mp.exe |
"TCP Query User{BA4063EE-9AD8-4AFB-B943-E9D2D67E92A3}F:\programme\steam\steamapps\optiolol\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=f:\programme\steam\steamapps\optiolol\counter-strike source\hl2.exe |
"TCP Query User{C1515480-ABF8-4B11-96AE-DDF1B8E865FC}C:\program files\activision\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 2\cod2mp_s.exe |
"TCP Query User{D6382914-4211-441C-BC7D-1E149C671738}G:\spiele\command & conquer 3\retailexe\1.9\cnc3game.dat" = protocol=6 | dir=in | app=g:\spiele\command & conquer 3\retailexe\1.9\cnc3game.dat |
"TCP Query User{D81F15B1-47C3-4A6B-AC27-23794C912F63}F:\programme\firefly studios\stronghold crusader\stronghold crusader.exe" = protocol=6 | dir=in | app=f:\programme\firefly studios\stronghold crusader\stronghold crusader.exe |
"TCP Query User{DD9E953A-706A-46AA-8529-C781A79C5054}C:\program files\activision\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 2\cod2mp_s.exe |
"TCP Query User{DE79D49F-E6E2-4E79-BD38-1A208F94FDB3}F:\programme\activision\cod\coduomp.exe" = protocol=6 | dir=in | app=f:\programme\activision\cod\coduomp.exe |
"TCP Query User{EB976354-E18D-427B-9729-71A4FE3E5241}F:\programme\xfire\xfire.exe" = protocol=6 | dir=in | app=f:\programme\xfire\xfire.exe |
"TCP Query User{EEBE6567-9A87-46BE-996D-93D55BB457A0}F:\programme\icq6.5\icq.exe" = protocol=6 | dir=in | app=f:\programme\icq6.5\icq.exe |
"TCP Query User{F07A5F1D-CCEC-4DD3-AE3B-8B91A0728509}F:\programme\xfire\xfire.exe" = protocol=6 | dir=in | app=f:\programme\xfire\xfire.exe |
"TCP Query User{F3CA7FB6-7D62-4E25-8DB6-0B08EB0BBD23}F:\programme\hlsw\hlsw.exe" = protocol=6 | dir=in | app=f:\programme\hlsw\hlsw.exe |
"TCP Query User{FAB910C6-7385-4B29-B3E1-78EB8D1F0222}F:\programme\halo\halo.exe" = protocol=6 | dir=in | app=f:\programme\halo\halo.exe |
"UDP Query User{095C3AB0-C7D0-4E38-B204-0B0233D8F4E6}C:\program files\left 4 dead\left4dead.exe" = protocol=17 | dir=in | app=c:\program files\left 4 dead\left4dead.exe |
"UDP Query User{0B76F548-B64A-49F8-865E-2AAEEAA86838}C:\program files\wow\repair.exe" = protocol=17 | dir=in | app=c:\program files\wow\repair.exe |
"UDP Query User{16C0336B-1320-4846-839C-4136F1CD327D}F:\programme\icq6.5\icq.exe" = protocol=17 | dir=in | app=f:\programme\icq6.5\icq.exe |
"UDP Query User{18BB681D-7076-458D-8F9C-67969908CB6B}F:\programme\metin2\metin2client.bin" = protocol=17 | dir=in | app=f:\programme\metin2\metin2client.bin |
"UDP Query User{19A89B58-9D24-4B3E-BE78-7A8BABDBE249}C:\program files\activision\cod4\iw3mp.exe" = protocol=17 | dir=in | app=c:\program files\activision\cod4\iw3mp.exe |
"UDP Query User{35D8A1D3-F2BC-4DD0-AA17-995354BA070F}F:\programme\activision\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=f:\programme\activision\call of duty 2\cod2mp_s.exe |
"UDP Query User{3D731044-6B25-409D-A04E-86CC0C7FECF5}F:\programme\hlsw\hlsw.exe" = protocol=17 | dir=in | app=f:\programme\hlsw\hlsw.exe |
"UDP Query User{4C999404-F378-4C22-B790-B262A1AFCE7D}C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\german\setup.exe" = protocol=17 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\german\setup.exe |
"UDP Query User{4F0EAA92-6B50-4D06-B204-2CC1055B80FD}C:\program files\java\jre6\launch4j-tmp\jdownloader.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\launch4j-tmp\jdownloader.exe |
"UDP Query User{4F24F115-08A9-4CB0-A94F-BD4EB94052B9}F:\programme\activision\cod\coduomp.exe" = protocol=17 | dir=in | app=f:\programme\activision\cod\coduomp.exe |
"UDP Query User{671E443F-A832-4E25-85CF-4245955C0E7D}C:\program files\activision\cod\codmp.exe" = protocol=17 | dir=in | app=c:\program files\activision\cod\codmp.exe |
"UDP Query User{672A4D49-E844-402E-9988-FE843AAE266D}F:\programme\far cry 2\bin\farcry2.exe" = protocol=17 | dir=in | app=f:\programme\far cry 2\bin\farcry2.exe |
"UDP Query User{79197F36-C3E7-4707-95FC-06B28F581A09}C:\program files\activision\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 2\cod2mp_s.exe |
"UDP Query User{7CF6C659-F6FA-4C8C-AC03-17E77D03FAE0}C:\program files\wow\launcher.exe" = protocol=17 | dir=in | app=c:\program files\wow\launcher.exe |
"UDP Query User{7D0849E4-4895-4F15-AF19-CFB02AFEE749}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{7E8D4DB1-5979-4FF6-851B-36D328FD92C0}C:\users\nico\appdata\local\temp\electronicarts_patcher_000.exe" = protocol=17 | dir=in | app=c:\users\nico\appdata\local\temp\electronicarts_patcher_000.exe |
"UDP Query User{86634CE6-1170-4738-974E-B558A276F15A}F:\programme\electronic arts\command & conquer 3\retailexe\1.9\cnc3game.dat" = protocol=17 | dir=in | app=f:\programme\electronic arts\command & conquer 3\retailexe\1.9\cnc3game.dat |
"UDP Query User{8DA1B81C-024C-420E-8D00-09818BAE6428}F:\programme\microsoft games\age of empires 2 the age of kings\empires2.exe" = protocol=17 | dir=in | app=f:\programme\microsoft games\age of empires 2 the age of kings\empires2.exe |
"UDP Query User{8F65452A-B4E7-4987-B0B8-7E8831FF2FB9}F:\programme\dead space\dead space.exe" = protocol=17 | dir=in | app=f:\programme\dead space\dead space.exe |
"UDP Query User{9A734DE8-1C32-49AE-915F-7775CC853CCF}F:\programme\firefly studios\stronghold crusader\stronghold crusader.exe" = protocol=17 | dir=in | app=f:\programme\firefly studios\stronghold crusader\stronghold crusader.exe |
"UDP Query User{A566035F-83A2-4EE2-8B55-EF5937FC7463}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{B1AFD9F4-CDC8-43AE-986D-61202C4E60A2}G:\spiele\command & conquer 3\retailexe\1.9\cnc3game.dat" = protocol=17 | dir=in | app=g:\spiele\command & conquer 3\retailexe\1.9\cnc3game.dat |
"UDP Query User{B23C8BF4-1ECC-4BA3-BA7F-AF194FC5DE4A}F:\programme\xfire\xfire.exe" = protocol=17 | dir=in | app=f:\programme\xfire\xfire.exe |
"UDP Query User{B60CC65B-5F7D-457D-987A-13B86ADC9428}F:\programme\halo\halo.exe" = protocol=17 | dir=in | app=f:\programme\halo\halo.exe |
"UDP Query User{B76DC34F-35D7-4E20-A0D4-52C72AC7CA22}C:\users\nico\desktop\neuer ordner\coduomp.exe" = protocol=17 | dir=in | app=c:\users\nico\desktop\neuer ordner\coduomp.exe |
"UDP Query User{B83AB61B-1A12-4874-8E8F-ED16322F243B}F:\programme\battlefield vietnam\bfvietnam.exe" = protocol=17 | dir=in | app=f:\programme\battlefield vietnam\bfvietnam.exe |
"UDP Query User{BA7E8B1E-EC86-44AD-9272-E7F05A4D196C}F:\programme\activision\cod\codmp.exe" = protocol=17 | dir=in | app=f:\programme\activision\cod\codmp.exe |
"UDP Query User{BC659AA2-13DF-43CE-9D13-93378DCEB9B6}C:\program files\postal2stp\system\postal2.exe" = protocol=17 | dir=in | app=c:\program files\postal2stp\system\postal2.exe |
"UDP Query User{C80AD029-E05F-4CAE-AD39-A8F0302C7A19}C:\program files\activision\cod\coduomp.exe" = protocol=17 | dir=in | app=c:\program files\activision\cod\coduomp.exe |
"UDP Query User{CD0E34D6-80ED-46C4-9232-2841F98C0F41}C:\program files\activision\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 2\cod2mp_s.exe |
"UDP Query User{CDBB0EFE-0E49-428F-8E8F-79C556D0116D}F:\programme\tom clancy's h.a.w.x\hawx.exe" = protocol=17 | dir=in | app=f:\programme\tom clancy's h.a.w.x\hawx.exe |
"UDP Query User{D4876D4C-903F-4707-9AE5-6BF602B98B16}F:\programme\xfire\xfire.exe" = protocol=17 | dir=in | app=f:\programme\xfire\xfire.exe |
"UDP Query User{E4D89834-32E8-4CCF-934C-ECCB80848907}F:\programme\metin2\metin2.bin" = protocol=17 | dir=in | app=f:\programme\metin2\metin2.bin |
"UDP Query User{F3BA5037-B25B-4E47-A156-D2797058141A}F:\programme\activision\call of duty 4 - modern warfare\iw3mp.exe" = protocol=17 | dir=in | app=f:\programme\activision\call of duty 4 - modern warfare\iw3mp.exe |
"UDP Query User{F573619F-4530-4ED9-ABC8-8D0BB616F105}F:\programme\steam\steamapps\optiolol\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=f:\programme\steam\steamapps\optiolol\counter-strike source\hl2.exe |
"UDP Query User{F7A5C010-16EE-4E68-BCA3-403F1F9F6416}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{F7B7EB9D-AAA6-45C9-9DF1-D426C95F594A}F:\programme\worms armageddon\wa.exe" = protocol=17 | dir=in | app=f:\programme\worms armageddon\wa.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01521746-02A6-4A72-00BD-A285DF6B80C6}" = Die Sims 2: Wilde Campus-Jahre
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{03B0D67B-36C9-C2CD-B63B-7B526138BA52}" = ccc-utility
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04FC2E4C-0E41-9D39-4E58-1EF29D4EF09D}" = ccc-core-static
"{04FE63AC-AC7B-4C80-83AA-CCACA48C0C19}" = PS_AIO_04_C5300_Software
"{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{086BADF8-9B1F-4E89-B207-2EDA520972D6}" = Grand Theft Auto San Andreas
"{0949C078-58B4-CAF1-9A63-A4545145806D}" = Catalyst Control Center Graphics Previews Common
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{09725E0F-6406-4500-8296-DBF6E697E9D7}" = C5300
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation(R)Store
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{14574B7F-75D1-4718-B7F2-EBF6E2862A35}" = Company of Heroes - FAKEMSI
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{199E6632-EB28-4F73-AECB-3E192EB92D18}" = Company of Heroes - FAKEMSI
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20DEB77C-21D6-4D22-BB47-233E47613D57}" = Microsoft Games for Windows - LIVE Redistributable
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{25724802-CC14-4B90-9F3B-3D6955EE27B1}" = Company of Heroes - FAKEMSI
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 20
"{26BEE28E-C285-4532-82D3-7CE3C5F805D4}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{2AFEAA03-2DFE-4519-A629-EDAB6541ABE9}" = HPSSupply
"{32C4A4EB-C97D-414E-99C5-38F8DFD31D5D}" = Company of Heroes - FAKEMSI
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{38D9575F-6228-6A54-3A92-D902739B6541}" = Catalyst Control Center InstallProxy
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMB36X Raid Configurer
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3AD56302-2ADE-4A1C-864A-CB9FFF040576}" = PS_AIO_04_C5300_ProductContext
"{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{489CA990-9FFB-495A-B5F6-027199E65405}" = PS_AIO_04_C5300_Software_Min
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A3D0CF8-60FF-4CEF-91A4-A1F001424602}" = DocProc
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{50193078-F553-4EBA-AA77-64C9FAA12F98}" = Company of Heroes - FAKEMSI
"{51D718D1-DA81-4FAD-919F-5C1CE3C33379}" = Company of Heroes - FAKEMSI
"{573F1931-08F7-9222-704E-841C391794C5}" = ATI Catalyst Install Manager
"{5D7767FA-7FE8-4627-9F09-AEF7A25F1E07}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.1 Patch
"{5E8B45A0-072C-91F7-BC80-29374194B452}" = Catalyst Control Center Graphics Previews Vista
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{66F78C51-D108-4F0C-A93C-1CBE74CE338F}" = Company of Heroes - FAKEMSI
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69C57747-551F-4e4f-AB60-13358DC4F00A}" = HP Photosmart C5300 All-In-One Driver Software 11.0 Rel .4
"{6CC1EE94-B426-478B-AE83-F83EBB4EF66A}" = HPPhotoSmartDiscLabel_PaperLabel
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = Die Sims 2
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70E1E357-E57C-4284-B04E-58196DC27BC1}" = PanoStandAlone
"{74DC0593-6BC6-4001-AD5F-D810AFB68D86}" = HP Update
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = Die Sims 2: Open For Business
"{7B4A5C13-069F-4AFE-AE57-C497B4E33C7E}" = Call of Duty(R) 2 Patch 1.3
"{7BA01D2D-E25C-0C2C-5779-7A8E02A4BE7D}" = Catalyst Control Center Core Implementation
"{7ED180E1-ADE9-4C69-8845-BDF518D763B8}" = hpphotosmartdisclabelplugin
"{7F4B1592-222F-4E5F-A100-E5AFD61A0BB3}" = Company of Heroes - FAKEMSI
"{80D03817-7943-4839-8E96-B9F924C5E67D}" = Company of Heroes - FAKEMSI
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Patch
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding
"{8FF4E834-DCAD-29E7-1EE8-9D817A3FA15B}" = CCC Help English
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90850407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{9580813D-94B1-4C28-9426-A441E2BB29A5}" = Counter-Strike: Source
"{97E5205F-EA4F-438F-B211-F1846419F1C1}" = Company of Heroes - FAKEMSI
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{99A7722D-9ACB-43F3-A222-ABC7133F159E}" = Company of Heroes - FAKEMSI
"{99E862CC-6F69-4D39-99AA-DBF71BF3B585}" = OpenOffice.org 3.1
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9F4EE72A-C5C9-42ad-ABEF-427690843577}" = MarketResearch
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A8B94669-8654-4126-BD28-D0D2412CDED6}" = TI Connect 1.6
"{AA2E8A46-B45E-4aea-8A23-88AB57D04523}" = WebReg
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.2 - Deutsch
"{AEDBD563-24BB-4EE3-8366-A654DAC2D988}" = Mirror's Edge™
"{B3276CB1-20B6-4AF9-AAEC-E72C83816495}" = IKEA Home Planner
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BA801B94-C28D-46EE-B806-E1E021A3D519}" = Company of Heroes - FAKEMSI
"{BC4CA8FA-41D2-4B81-8680-E9B7573D6500}" = PlayStation(R)Network Downloader
"{BCC09E9C-3340-473D-A4FE-8580992CA77A}" = HPPhotoSmartDiscLabelContent1
"{BF08AB1C-3357-4f20-A200-8EBB8EF27C59}" = BufferChm
"{C03A56EE-2715-5F54-69C4-A1CDB7602354}" = Catalyst Control Center Graphics Full New
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die Sims™ 3
"{C307DD64-1C69-8C52-D2C9-02D38995A269}" = Catalyst Control Center HydraVision Full
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C89B5E3A-690F-4CEE-909A-BF869E198B0A}" = Scan
"{C9933E93-8653-447E-9A19-9BCF658E3AE9}" = C5300_Help
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D078226E-83F2-45FD-9CDE-5DA66E5ADB51}" = Rise and Fall
"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D16B4BE6-8B10-422f-8034-96D1CA9483B5}" = GPBaseService
"{D4D244D1-05E0-4D24-86A2-B2433C435671}" = Company of Heroes - FAKEMSI
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{D99223D4-1F48-47BD-ADFD-D43C91CDFD00}" = S4 League
"{DDEDAF6C-488E-4CDA-8276-1CCF5F3C5C32}" = Command & Conquer 3
"{E3E1398E-8FF2-0154-6D8F-7FC26299EBED}" = Catalyst Control Center Graphics Full Existing
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E5141379-B2D9-4BBC-BB2A-5805541571DD}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{EAF636A9-F664-4703-A659-85A894DA264F}" = Company of Heroes - FAKEMSI
"{ED1390DC-6910-4C77-97E2-579CAFE82F5B}" = Moorhuhn 4 Teile
"{ED3866E9-4F50-4A47-9945-58D5C97AB56F}" = Media Go
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{EF36A836-BF89-4A4F-B079-057B0C68C1E0}" = Sid Meier's Civilization IV Colonization
"{EF9E56EE-0243-4BAD-88F4-5E7508AA7D96}" = Destination Component
"{F11ADC64-C89E-47F4-A0B3-3665FF859397}" = WORLD IN CONFLICT
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = Die Sims 2: Nightlife
"{FBEF69BB-829C-8D4D-B299-497147916039}" = Catalyst Control Center Graphics Light
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CEP - Colour Enable Packages_is1" = CEP - Color Enable Package
"Cheat Engine 5.4_is1" = Cheat Engine 5.4
"Command and Conquer™ 3 Tiberium Wars™ Sprachsteuerung" = Command and Conquer™ 3 Tiberium Wars™ Sprachsteuerung 1.0.0.0
"Company of Heroes" = Company of Heroes
"Free Video to iPod Converter_is1" = Free Video to iPod Converter version 3.2
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 11.0
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 11.0
"HPOCR" = OCR Software by I.R.I.S. 11.0
"ImgBurn" = ImgBurn
"InstallShield_{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch
"InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
"InstallShield_{5D7767FA-7FE8-4627-9F09-AEF7A25F1E07}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.1 Patch
"InstallShield_{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"InstallShield_{E5141379-B2D9-4BBC-BB2A-5805541571DD}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch
"Left 4 Dead" = Left 4 Dead
"LogMeIn Hamachi" = LogMeIn Hamachi
"Metin2_is1" = Metin2
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.9)" = Mozilla Firefox (3.5.9)
"NeroMultiInstaller!UninstallKey" = Nero Suite
"oZone3D.Net FurMark_is1" = oZone3D.Net FurMark v1.8.0
"Postal 2 Share The Pain" = Postal 2 Share The Pain
"PunkBusterSvc" = PunkBuster Services
"RollerCoaster Tycoon 3_is1" = RollerCoaster Tycoon 3
"Shop for HP Supplies" = Shop for HP Supplies
"Sims2Pack Clean Installer " = Sims2Pack Clean Installer
"Steam App 240" = Counter-Strike: Source
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.0.5
"WinRAR archiver" = WinRAR archiver
"Zygor Guides" = Zygor Guides
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"TeamSpeak 3 Client" = TeamSpeak 3 Client
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 23.05.2010 05:17:25 | Computer Name = Nico-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 23.05.2010 09:59:06 | Computer Name = Nico-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung RunDLL32.exe, Version 6.0.6000.16386, Zeitstempel
 0x4549b0e1, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000,
 Ausnahmecode 0xc0000005, Fehleroffset 0x024da8ed,  Prozess-ID 0xf6c, Anwendungsstartzeit
 01cafa801b3c29fc.
 
Error - 23.05.2010 09:59:18 | Computer Name = Nico-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung RunDLL32.exe, Version 6.0.6000.16386, Zeitstempel
 0x4549b0e1, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000,
 Ausnahmecode 0xc0000005, Fehleroffset 0x00c7a8ed,  Prozess-ID 0x12f4, Anwendungsstartzeit
 01cafa80230432ec.
 
Error - 23.05.2010 10:27:09 | Computer Name = Nico-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung RunDLL32.exe, Version 6.0.6000.16386, Zeitstempel
 0x4549b0e1, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000,
 Ausnahmecode 0xc0000005, Fehleroffset 0x01bca8ed,  Prozess-ID 0x1044, Anwendungsstartzeit
 01cafa84072de62c.
 
Error - 23.05.2010 10:27:11 | Computer Name = Nico-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung RunDLL32.exe, Version 6.0.6000.16386, Zeitstempel
 0x4549b0e1, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000,
 Ausnahmecode 0xc0000005, Fehleroffset 0x01ada8ed,  Prozess-ID 0x1720, Anwendungsstartzeit
 01cafa840833212c.
 
Error - 23.05.2010 17:53:44 | Computer Name = Nico-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 24.05.2010 09:10:07 | Computer Name = Nico-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 24.05.2010 09:10:32 | Computer Name = Nico-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung hpqpsapp.exe, Version 110.0.226.11, Zeitstempel
 0x47e22104, fehlerhaftes Modul hpqpsapp.exe, Version 110.0.226.11, Zeitstempel
0x47e22104, Ausnahmecode 0xc0000005, Fehleroffset 0x00176e77,  Prozess-ID 0xfb8, Anwendungsstartzeit
 01cafb427743b6a0.
 
Error - 24.05.2010 14:09:05 | Computer Name = Nico-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung javaw.exe, Version 6.0.200.2, Zeitstempel 0x4bc398b3,
 fehlerhaftes Modul java.dll, Version 6.0.200.2, Zeitstempel 0x4bc3c8dc, Ausnahmecode
 0xc0000005, Fehleroffset 0x00005875,  Prozess-ID 0x1158, Anwendungsstartzeit 01cafb6c31c7f4e0.
 
Error - 25.05.2010 12:16:20 | Computer Name = Nico-PC | Source = WinMgmt | ID = 10
Description =
 
[ Media Center Events ]
Error - 18.05.2009 08:45:55 | Computer Name = Nico-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 09.08.2009 11:27:51 | Computer Name = Nico-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 16.10.2009 06:39:03 | Computer Name = Nico-PC | Source = Mcx2Dvcs | ID = 401
Description =
 
[ System Events ]
Error - 25.05.2010 12:21:22 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 25.05.2010 12:21:25 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 25.05.2010 12:22:43 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 25.05.2010 12:22:46 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 25.05.2010 12:23:49 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 25.05.2010 12:23:52 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 25.05.2010 12:24:59 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 25.05.2010 12:25:02 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 25.05.2010 12:26:07 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 25.05.2010 12:26:10 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
 
< End of report >


cosinus 25.05.2010 20:23

Was ist mit Malwarebytes? Das solltest Du vor OTL ausführen.

Darkfilter 25.05.2010 20:29

Sry, da es länger gedauert hat, habe ich es erst jetzt ausgeführt nun hier: (Soll ich jetzt noch einmal OTL ausführen?)
Gruß Nico

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4142

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18904

25.05.2010 21:25:02
mbam-log-2010-05-25 (21-25-02).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|G:\|)
Durchsuchte Objekte: 530080
Laufzeit: 1 Stunde(n), 48 Minute(n), 43 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 1
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 6
Infizierte Dateien: 9

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\SOFTWARE\WS9E3IQBKY (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rthdbpl (Trojan.Agent) -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
C:\ProgramData\MPK (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\ProgramData\MPK\1 (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D} (Trojan.Swisyn) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome (Trojan.Swisyn) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content (Trojan.Swisyn) -> Quarantined and deleted successfully.
C:\Users\Nico\AppData\Roaming\SystemProc (Trojan.Agent) -> Quarantined and deleted successfully.

Infizierte Dateien:
C:\System Volume Information\_restore{9A487E93-5CF2-48B1-8774-5D5682EECE5E}\RP103\A0025076.dll (Keylogger.PerfectKeylogger) -> Quarantined and deleted successfully.
C:\ProgramData\MPK\M0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\ProgramData\MPK\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\ProgramData\MPK\1\D0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\ProgramData\MPK\1\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest (Trojan.Swisyn) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf (Trojan.Swisyn) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul (Trojan.Swisyn) -> Quarantined and deleted successfully.
C:\Windows\System32\h@tkeysh@@k.dll (Trojan.Agent) -> Quarantined and deleted successfully.

cosinus 25.05.2010 20:51

Ja, ein frisches OTL-Log wäre gut, da sich durch Malwarebytes ja wieder das System verändert hat.

Darkfilter 25.05.2010 21:55

So, ich hoffe jetzt ist alles vorhanden was Du benötigst

OTL Logfile:
Code:

OTL logfile created on: 25.05.2010 22:52:08 - Run 2
OTL by OldTimer - Version 3.2.5.0    Folder = C:\Users\Nico\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 64,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 82,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698,63 Gb Total Space | 454,65 Gb Free Space | 65,08% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 465,76 Gb Total Space | 224,36 Gb Free Space | 48,17% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: NICO-PC
Current User Name: Nico
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Nico\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - G:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\ATI\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)
PRC - C:\Program Files\ATI\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Nico\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Hamachi2Svc) --  File not found
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (npggsvc) -- C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (AtiHdmiService) -- C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (SSHDRV61) -- C:\Windows\System32\drivers\SSHDRV61.sys ()
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (SSHDRV76) -- C:\Windows\System32\drivers\SSHDRV76.sys ()
DRV - (SSHDRV51) -- C:\Windows\System32\drivers\SSHDRV51.sys ()
DRV - (SSHDRV52) -- C:\Windows\System32\drivers\SSHDRV52.sys ()
DRV - (StarOpen) -- C:\Windows\System32\drivers\StarOpen.sys ()
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (VClone) -- C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (ElbyCDIO) -- C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (JRAID) -- C:\Windows\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (NPPTNT2) -- C:\Windows\System32\npptNT2.sys (INCA Internet Co., Ltd.)
DRV - (prohlp02) -- C:\Windows\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prodrv06) -- C:\Windows\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (prosync1) -- C:\Windows\System32\drivers\prosync1.sys (Protection Technology)
DRV - (TIEHDUSB) -- C:\Windows\System32\drivers\tiehdusb.sys (Texas Instruments Incorporated)
DRV - (sfhlp01) -- C:\Windows\System32\drivers\sfhlp01.sys (Protection Technology)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DA 4E EF 96 36 0A CA 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledItems: autopager@mozilla.org:0.6.0.26
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.60
FF - prefs.js..extensions.enabledItems: NPDyyno@dyyno.com:1.0.0.24
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
 
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.02.11 21:29:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: F:\Programme\Mozilla Firefox\components
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: F:\Programme\Mozilla Firefox\plugins
 
[2009.04.29 20:00:21 | 000,000,000 | ---D | M] -- C:\Users\Nico\AppData\Roaming\mozilla\Extensions
[2010.05.25 18:25:54 | 000,000,000 | ---D | M] -- C:\Users\Nico\AppData\Roaming\mozilla\Firefox\Profiles\yv8unz8k.default\extensions
[2010.04.28 17:11:40 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Nico\AppData\Roaming\mozilla\Firefox\Profiles\yv8unz8k.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.04.28 17:11:40 | 000,000,000 | ---D | M] -- C:\Users\Nico\AppData\Roaming\mozilla\Firefox\Profiles\yv8unz8k.default\extensions\autopager@mozilla.org
[2009.06.14 21:37:11 | 000,000,000 | ---D | M] -- C:\Users\Nico\AppData\Roaming\mozilla\Firefox\Profiles\yv8unz8k.default\extensions\NPDyyno@dyyno.com
[2010.05.25 21:25:02 | 000,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] G:\Programme\Adobe Reader\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [hpqSRMon]  File not found
O4 - HKLM..\Run: [iTunesHelper] F:\Programme\iTunes\iTunesHelper.exe File not found
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] F:\Programme\Hamachi\hamachi-2-ui.exe File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Windows\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [iTap] C:\Program Files\HLW\iTap\iTap.exe File not found
O4 - HKCU..\Run: [RGSC] F:\Programme\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe File not found
O4 - HKCU..\Run: [Steam] f:\programme\steam\steam.exe File not found
O4 - Startup: C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk = C:\Users\Nico\AppData\Local\Temp\is-OANTQ.tmp\ATR1.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra Button: HP Smart Web Printing ein- oder ausblenden - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - F:\Program Files\ICQ6.5\ICQ.exe File not found
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - F:\Program Files\ICQ6.5\ICQ.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Desert Landscape.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Desert Landscape.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0320e36e-7b6d-11de-9936-002185c17f27}\Shell - "" = AutoRun
O33 - MountPoints2\{0320e36e-7b6d-11de-9936-002185c17f27}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O33 - MountPoints2\{7daf253f-0eba-11df-beb7-002185c17f27}\Shell\AutoRun\command - "" = G:\Menu.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.05.25 18:33:17 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\Malwarebytes
[2010.05.25 18:33:09 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.05.25 18:33:07 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.05.25 18:33:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.05.23 23:25:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010.05.23 23:25:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010.05.23 23:24:45 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010.05.23 23:24:45 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.05.23 23:24:45 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.05.23 23:24:45 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.05.17 21:46:04 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Local\My Games
[2010.05.17 21:40:58 | 000,000,000 | ---D | C] -- C:\Program Files\2K Games
[2010.05.16 16:08:54 | 000,000,000 | ---D | C] -- C:\Die Sims 2
[2010.05.16 16:03:49 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Local\World in Conflict
[2010.05.16 16:03:38 | 000,000,000 | ---D | C] -- C:\Users\Nico\Documents\World in Conflict
[2010.05.16 15:48:02 | 000,000,000 | ---D | C] -- C:\Program Files\Sierra Games
[2010.05.15 20:59:25 | 000,000,000 | ---D | C] -- C:\Users\Nico\Documents\BFBC2
[2010.05.15 20:43:02 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2010.05.15 20:43:02 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2010.05.15 20:43:02 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2010.05.15 20:43:02 | 000,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2010.05.15 20:43:01 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2010.05.15 20:43:01 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2010.05.15 20:43:01 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2010.05.15 20:43:01 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2010.05.15 20:43:00 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2010.05.15 20:42:59 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2010.05.15 20:42:59 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2010.05.15 20:42:59 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2010.05.15 20:42:59 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2010.05.13 13:51:01 | 000,000,000 | ---D | C] -- C:\Users\Nico\Documents\RCT3
[2010.05.13 13:51:01 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\Atari
[2010.05.13 13:50:20 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\vlc
[2010.05.13 13:41:50 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\Leadertech
[2010.05.12 22:17:39 | 000,000,000 | ---D | C] -- C:\Users\Nico\Documents\NIKITA
[2010.05.12 22:17:29 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\NIKITA
[2010.05.03 13:28:22 | 000,000,000 | ---D | C] -- C:\Phenomedia AG
[2010.04.28 22:44:54 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2010.04.28 22:04:43 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\HPAppData
[2010.04.27 16:01:52 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
 
========== Files - Modified Within 30 Days ==========
 
[2010.05.25 22:53:00 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{8D9D19FD-3BB5-49B2-A216-4F4719AB1F71}.job
[2010.05.25 22:52:18 | 002,883,584 | -HS- | M] () -- C:\Users\Nico\NTUSER.DAT
[2010.05.25 21:32:44 | 001,418,806 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.05.25 21:32:44 | 000,618,204 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.05.25 21:32:44 | 000,586,980 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010.05.25 21:32:44 | 000,122,636 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.05.25 21:32:44 | 000,101,052 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.05.25 21:26:54 | 000,005,952 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.05.25 21:26:54 | 000,005,952 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.05.25 21:26:50 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.05.25 21:26:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.05.25 21:25:45 | 000,065,536 | -HS- | M] () -- C:\Users\Nico\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010.05.25 21:25:44 | 002,127,119 | -H-- | M] () -- C:\Users\Nico\AppData\Local\IconCache.db
[2010.05.25 21:25:44 | 000,524,288 | -HS- | M] () -- C:\Users\Nico\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010.05.25 18:33:11 | 000,000,621 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.05.24 15:12:02 | 000,002,379 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2010.05.23 16:27:12 | 000,000,116 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2010.05.23 13:25:09 | 000,000,312 | ---- | M] () -- C:\Windows\tasks\WebReg HP Photosmart C5300 series.job
[2010.05.23 02:31:05 | 000,139,128 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010.05.23 01:19:17 | 000,215,128 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2010.05.22 01:39:14 | 309,498,610 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010.05.17 21:52:28 | 000,001,337 | ---- | M] () -- C:\Users\Nico\Desktop\Civilization 4 - Colonization.lnk
[2010.05.16 15:57:43 | 000,000,801 | ---- | M] () -- C:\Users\Nico\Desktop\World in Conflict.lnk
[2010.05.15 20:58:49 | 000,001,104 | ---- | M] () -- C:\Users\Nico\Desktop\Battlefield Bad Company 2.lnk
[2010.05.15 20:57:42 | 000,138,056 | ---- | M] () -- C:\Users\Nico\AppData\Roaming\PnkBstrK.sys
[2010.05.15 20:57:26 | 002,434,856 | ---- | M] () -- C:\Windows\System32\pbsvc_bc2.exe
[2010.05.13 13:42:15 | 000,000,989 | ---- | M] () -- C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk
[2010.05.13 13:40:51 | 000,000,697 | ---- | M] () -- C:\Users\Public\Desktop\RollerCoaster Tycoon 3.lnk
[2010.05.12 21:46:53 | 000,024,576 | ---- | M] () -- C:\Users\Nico\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.12 11:21:16 | 000,221,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010.05.05 22:31:56 | 000,000,009 | ---- | M] () -- C:\Windows\pbase.dat
[2010.05.05 22:31:56 | 000,000,008 | ---- | M] () -- C:\Windows\npbase.dat
[2010.05.05 22:31:56 | 000,000,003 | ---- | M] () -- C:\Windows\ver.dat
[2010.04.29 12:19:24 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.04.29 12:19:14 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.04.28 22:44:33 | 000,272,168 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.04.28 22:24:06 | 000,000,680 | ---- | M] () -- C:\Users\Nico\AppData\Local\d3d9caps.dat
 
========== Files Created - No Company Name ==========
 
[2010.05.25 18:33:11 | 000,000,621 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.05.23 13:25:08 | 000,000,312 | ---- | C] () -- C:\Windows\tasks\WebReg HP Photosmart C5300 series.job
[2010.05.22 01:39:14 | 309,498,610 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010.05.17 21:51:37 | 000,001,337 | ---- | C] () -- C:\Users\Nico\Desktop\Civilization 4 - Colonization.lnk
[2010.05.16 15:57:16 | 000,000,801 | ---- | C] () -- C:\Users\Nico\Desktop\World in Conflict.lnk
[2010.05.15 20:58:28 | 000,001,104 | ---- | C] () -- C:\Users\Nico\Desktop\Battlefield Bad Company 2.lnk
[2010.05.15 20:57:42 | 000,138,056 | ---- | C] () -- C:\Users\Nico\AppData\Roaming\PnkBstrK.sys
[2010.05.15 20:57:26 | 002,434,856 | ---- | C] () -- C:\Windows\System32\pbsvc_bc2.exe
[2010.05.13 13:42:15 | 000,000,989 | ---- | C] () -- C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk
[2010.05.13 13:40:51 | 000,000,697 | ---- | C] () -- C:\Users\Public\Desktop\RollerCoaster Tycoon 3.lnk
[2010.04.07 03:22:08 | 000,023,040 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2010.03.05 02:11:22 | 000,041,872 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2010.02.04 16:53:07 | 001,970,176 | ---- | C] () -- C:\Windows\System32\d3dx9.dll
[2010.01.22 23:01:19 | 000,000,083 | ---- | C] () -- C:\Windows\WA.INI
[2009.11.28 12:19:53 | 000,000,040 | ---- | C] () -- C:\Windows\WeatherSet.ini
[2009.11.27 22:42:38 | 000,036,864 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV61.sys
[2009.10.16 13:54:05 | 000,000,280 | ---- | C] () -- C:\Windows\game.ini
[2009.09.25 19:17:47 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.07 20:37:01 | 000,000,004 | ---- | C] () -- C:\Windows\info147.sys
[2009.09.07 20:06:19 | 000,053,760 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV76.sys
[2009.09.06 18:52:02 | 000,021,504 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV51.sys
[2009.09.06 13:42:20 | 000,029,184 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV52.sys
[2009.08.02 12:41:22 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009.07.17 14:19:55 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2009.07.07 21:31:32 | 000,144,384 | ---- | C] () -- C:\Windows\System32\miccyhook.dll
[2009.06.12 18:38:11 | 000,139,128 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2009.05.17 18:15:47 | 000,000,510 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2007.08.07 19:22:22 | 000,141,180 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[1997.11.17 18:13:16 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll
[1997.06.14 10:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll
< End of report >


Darkfilter 25.05.2010 21:56

2. logfile

OTL Logfile:
Code:

OTL logfile created on: 25.05.2010 22:52:08 - Run 2
OTL by OldTimer - Version 3.2.5.0    Folder = C:\Users\Nico\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 64,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 82,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698,63 Gb Total Space | 454,65 Gb Free Space | 65,08% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 465,76 Gb Total Space | 224,36 Gb Free Space | 48,17% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: NICO-PC
Current User Name: Nico
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Nico\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - G:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\ATI\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)
PRC - C:\Program Files\ATI\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Nico\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Hamachi2Svc) --  File not found
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (npggsvc) -- C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (AtiHdmiService) -- C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (SSHDRV61) -- C:\Windows\System32\drivers\SSHDRV61.sys ()
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (SSHDRV76) -- C:\Windows\System32\drivers\SSHDRV76.sys ()
DRV - (SSHDRV51) -- C:\Windows\System32\drivers\SSHDRV51.sys ()
DRV - (SSHDRV52) -- C:\Windows\System32\drivers\SSHDRV52.sys ()
DRV - (StarOpen) -- C:\Windows\System32\drivers\StarOpen.sys ()
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (VClone) -- C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (ElbyCDIO) -- C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (JRAID) -- C:\Windows\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (NPPTNT2) -- C:\Windows\System32\npptNT2.sys (INCA Internet Co., Ltd.)
DRV - (prohlp02) -- C:\Windows\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prodrv06) -- C:\Windows\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (prosync1) -- C:\Windows\System32\drivers\prosync1.sys (Protection Technology)
DRV - (TIEHDUSB) -- C:\Windows\System32\drivers\tiehdusb.sys (Texas Instruments Incorporated)
DRV - (sfhlp01) -- C:\Windows\System32\drivers\sfhlp01.sys (Protection Technology)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DA 4E EF 96 36 0A CA 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledItems: autopager@mozilla.org:0.6.0.26
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.60
FF - prefs.js..extensions.enabledItems: NPDyyno@dyyno.com:1.0.0.24
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
 
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.02.11 21:29:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: F:\Programme\Mozilla Firefox\components
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: F:\Programme\Mozilla Firefox\plugins
 
[2009.04.29 20:00:21 | 000,000,000 | ---D | M] -- C:\Users\Nico\AppData\Roaming\mozilla\Extensions
[2010.05.25 18:25:54 | 000,000,000 | ---D | M] -- C:\Users\Nico\AppData\Roaming\mozilla\Firefox\Profiles\yv8unz8k.default\extensions
[2010.04.28 17:11:40 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Nico\AppData\Roaming\mozilla\Firefox\Profiles\yv8unz8k.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.04.28 17:11:40 | 000,000,000 | ---D | M] -- C:\Users\Nico\AppData\Roaming\mozilla\Firefox\Profiles\yv8unz8k.default\extensions\autopager@mozilla.org
[2009.06.14 21:37:11 | 000,000,000 | ---D | M] -- C:\Users\Nico\AppData\Roaming\mozilla\Firefox\Profiles\yv8unz8k.default\extensions\NPDyyno@dyyno.com
[2010.05.25 21:25:02 | 000,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] G:\Programme\Adobe Reader\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [hpqSRMon]  File not found
O4 - HKLM..\Run: [iTunesHelper] F:\Programme\iTunes\iTunesHelper.exe File not found
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] F:\Programme\Hamachi\hamachi-2-ui.exe File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Windows\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [iTap] C:\Program Files\HLW\iTap\iTap.exe File not found
O4 - HKCU..\Run: [RGSC] F:\Programme\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe File not found
O4 - HKCU..\Run: [Steam] f:\programme\steam\steam.exe File not found
O4 - Startup: C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk = C:\Users\Nico\AppData\Local\Temp\is-OANTQ.tmp\ATR1.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra Button: HP Smart Web Printing ein- oder ausblenden - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - F:\Program Files\ICQ6.5\ICQ.exe File not found
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - F:\Program Files\ICQ6.5\ICQ.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Desert Landscape.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Desert Landscape.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0320e36e-7b6d-11de-9936-002185c17f27}\Shell - "" = AutoRun
O33 - MountPoints2\{0320e36e-7b6d-11de-9936-002185c17f27}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O33 - MountPoints2\{7daf253f-0eba-11df-beb7-002185c17f27}\Shell\AutoRun\command - "" = G:\Menu.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.05.25 18:33:17 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\Malwarebytes
[2010.05.25 18:33:09 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.05.25 18:33:07 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.05.25 18:33:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.05.23 23:25:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010.05.23 23:25:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010.05.23 23:24:45 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010.05.23 23:24:45 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.05.23 23:24:45 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.05.23 23:24:45 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.05.17 21:46:04 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Local\My Games
[2010.05.17 21:40:58 | 000,000,000 | ---D | C] -- C:\Program Files\2K Games
[2010.05.16 16:08:54 | 000,000,000 | ---D | C] -- C:\Die Sims 2
[2010.05.16 16:03:49 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Local\World in Conflict
[2010.05.16 16:03:38 | 000,000,000 | ---D | C] -- C:\Users\Nico\Documents\World in Conflict
[2010.05.16 15:48:02 | 000,000,000 | ---D | C] -- C:\Program Files\Sierra Games
[2010.05.15 20:59:25 | 000,000,000 | ---D | C] -- C:\Users\Nico\Documents\BFBC2
[2010.05.15 20:43:02 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2010.05.15 20:43:02 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2010.05.15 20:43:02 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2010.05.15 20:43:02 | 000,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2010.05.15 20:43:01 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2010.05.15 20:43:01 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2010.05.15 20:43:01 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2010.05.15 20:43:01 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2010.05.15 20:43:00 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2010.05.15 20:42:59 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2010.05.15 20:42:59 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2010.05.15 20:42:59 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2010.05.15 20:42:59 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2010.05.13 13:51:01 | 000,000,000 | ---D | C] -- C:\Users\Nico\Documents\RCT3
[2010.05.13 13:51:01 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\Atari
[2010.05.13 13:50:20 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\vlc
[2010.05.13 13:41:50 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\Leadertech
[2010.05.12 22:17:39 | 000,000,000 | ---D | C] -- C:\Users\Nico\Documents\NIKITA
[2010.05.12 22:17:29 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\NIKITA
[2010.05.03 13:28:22 | 000,000,000 | ---D | C] -- C:\Phenomedia AG
[2010.04.28 22:44:54 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2010.04.28 22:04:43 | 000,000,000 | ---D | C] -- C:\Users\Nico\AppData\Roaming\HPAppData
[2010.04.27 16:01:52 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
 
========== Files - Modified Within 30 Days ==========
 
[2010.05.25 22:53:00 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{8D9D19FD-3BB5-49B2-A216-4F4719AB1F71}.job
[2010.05.25 22:52:18 | 002,883,584 | -HS- | M] () -- C:\Users\Nico\NTUSER.DAT
[2010.05.25 21:32:44 | 001,418,806 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.05.25 21:32:44 | 000,618,204 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.05.25 21:32:44 | 000,586,980 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010.05.25 21:32:44 | 000,122,636 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.05.25 21:32:44 | 000,101,052 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.05.25 21:26:54 | 000,005,952 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.05.25 21:26:54 | 000,005,952 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.05.25 21:26:50 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.05.25 21:26:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.05.25 21:25:45 | 000,065,536 | -HS- | M] () -- C:\Users\Nico\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010.05.25 21:25:44 | 002,127,119 | -H-- | M] () -- C:\Users\Nico\AppData\Local\IconCache.db
[2010.05.25 21:25:44 | 000,524,288 | -HS- | M] () -- C:\Users\Nico\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010.05.25 18:33:11 | 000,000,621 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.05.24 15:12:02 | 000,002,379 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2010.05.23 16:27:12 | 000,000,116 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2010.05.23 13:25:09 | 000,000,312 | ---- | M] () -- C:\Windows\tasks\WebReg HP Photosmart C5300 series.job
[2010.05.23 02:31:05 | 000,139,128 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010.05.23 01:19:17 | 000,215,128 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2010.05.22 01:39:14 | 309,498,610 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010.05.17 21:52:28 | 000,001,337 | ---- | M] () -- C:\Users\Nico\Desktop\Civilization 4 - Colonization.lnk
[2010.05.16 15:57:43 | 000,000,801 | ---- | M] () -- C:\Users\Nico\Desktop\World in Conflict.lnk
[2010.05.15 20:58:49 | 000,001,104 | ---- | M] () -- C:\Users\Nico\Desktop\Battlefield Bad Company 2.lnk
[2010.05.15 20:57:42 | 000,138,056 | ---- | M] () -- C:\Users\Nico\AppData\Roaming\PnkBstrK.sys
[2010.05.15 20:57:26 | 002,434,856 | ---- | M] () -- C:\Windows\System32\pbsvc_bc2.exe
[2010.05.13 13:42:15 | 000,000,989 | ---- | M] () -- C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk
[2010.05.13 13:40:51 | 000,000,697 | ---- | M] () -- C:\Users\Public\Desktop\RollerCoaster Tycoon 3.lnk
[2010.05.12 21:46:53 | 000,024,576 | ---- | M] () -- C:\Users\Nico\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.12 11:21:16 | 000,221,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010.05.05 22:31:56 | 000,000,009 | ---- | M] () -- C:\Windows\pbase.dat
[2010.05.05 22:31:56 | 000,000,008 | ---- | M] () -- C:\Windows\npbase.dat
[2010.05.05 22:31:56 | 000,000,003 | ---- | M] () -- C:\Windows\ver.dat
[2010.04.29 12:19:24 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.04.29 12:19:14 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.04.28 22:44:33 | 000,272,168 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.04.28 22:24:06 | 000,000,680 | ---- | M] () -- C:\Users\Nico\AppData\Local\d3d9caps.dat
 
========== Files Created - No Company Name ==========
 
[2010.05.25 18:33:11 | 000,000,621 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.05.23 13:25:08 | 000,000,312 | ---- | C] () -- C:\Windows\tasks\WebReg HP Photosmart C5300 series.job
[2010.05.22 01:39:14 | 309,498,610 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010.05.17 21:51:37 | 000,001,337 | ---- | C] () -- C:\Users\Nico\Desktop\Civilization 4 - Colonization.lnk
[2010.05.16 15:57:16 | 000,000,801 | ---- | C] () -- C:\Users\Nico\Desktop\World in Conflict.lnk
[2010.05.15 20:58:28 | 000,001,104 | ---- | C] () -- C:\Users\Nico\Desktop\Battlefield Bad Company 2.lnk
[2010.05.15 20:57:42 | 000,138,056 | ---- | C] () -- C:\Users\Nico\AppData\Roaming\PnkBstrK.sys
[2010.05.15 20:57:26 | 002,434,856 | ---- | C] () -- C:\Windows\System32\pbsvc_bc2.exe
[2010.05.13 13:42:15 | 000,000,989 | ---- | C] () -- C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk
[2010.05.13 13:40:51 | 000,000,697 | ---- | C] () -- C:\Users\Public\Desktop\RollerCoaster Tycoon 3.lnk
[2010.04.07 03:22:08 | 000,023,040 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2010.03.05 02:11:22 | 000,041,872 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2010.02.04 16:53:07 | 001,970,176 | ---- | C] () -- C:\Windows\System32\d3dx9.dll
[2010.01.22 23:01:19 | 000,000,083 | ---- | C] () -- C:\Windows\WA.INI
[2009.11.28 12:19:53 | 000,000,040 | ---- | C] () -- C:\Windows\WeatherSet.ini
[2009.11.27 22:42:38 | 000,036,864 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV61.sys
[2009.10.16 13:54:05 | 000,000,280 | ---- | C] () -- C:\Windows\game.ini
[2009.09.25 19:17:47 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.07 20:37:01 | 000,000,004 | ---- | C] () -- C:\Windows\info147.sys
[2009.09.07 20:06:19 | 000,053,760 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV76.sys
[2009.09.06 18:52:02 | 000,021,504 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV51.sys
[2009.09.06 13:42:20 | 000,029,184 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV52.sys
[2009.08.02 12:41:22 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009.07.17 14:19:55 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2009.07.07 21:31:32 | 000,144,384 | ---- | C] () -- C:\Windows\System32\miccyhook.dll
[2009.06.12 18:38:11 | 000,139,128 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2009.05.17 18:15:47 | 000,000,510 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2007.08.07 19:22:22 | 000,141,180 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[1997.11.17 18:13:16 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll
[1997.06.14 10:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll
< End of report >


cosinus 26.05.2010 13:08

Das OTL-Log sieht ok aus, aber kannst Du nochmal das extras Log nachreichen? Du hast 2x das gleiche Log gepostet.

Darkfilter 26.05.2010 16:46

So, aber jetzt!^^

OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 26.05.2010 17:42:58 - Run 3
OTL by OldTimer - Version 3.2.5.0    Folder = C:\Users\Nico\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 59,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 81,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698,63 Gb Total Space | 454,63 Gb Free Space | 65,07% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 465,76 Gb Total Space | 224,36 Gb Free Space | 48,17% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: NICO-PC
Current User Name: Nico
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- G:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "G:\Programme\Microsoft Viewer\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "G:\Programme\Microsoft Viewer\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "G:\Programme\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "G:\Programme\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-442773238-3665067095-4225304131-1000]
"EnableNotifications" = 1
"EnableNotificationsRef" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02AE2E85-F4DC-40C2-8FB4-D0E6046763F1}" = lport=10244 | protocol=6 | dir=in | app=system |
"{02E39A3D-A442-461D-BBF0-757515213DAD}" = lport=3390 | protocol=6 | dir=in | app=system |
"{06837C40-FF4C-465D-834B-85CA8093D46F}" = rport=10243 | protocol=6 | dir=out | app=system |
"{07CB54D0-0201-43D1-852A-9CDF899C79E1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{0ED49805-8EFB-40EE-BD53-E367C5E6E697}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{115C2BA7-2233-4322-8A32-B86B647422F9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{17C44A58-E42D-4801-AF3F-4F236C68BF2E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{1E04E061-B32F-404A-9CB5-9A49DBD7889C}" = lport=10244 | protocol=6 | dir=in | app=system |
"{24BC0501-E1DC-4822-9E13-8B5D054EC445}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{28CC590E-D41C-4380-8A9D-CD38429D2D9C}" = rport=138 | protocol=17 | dir=out | app=system |
"{29732F88-429C-497C-8D61-833D3861A7EB}" = rport=139 | protocol=6 | dir=out | app=system |
"{3433C4F7-6BB4-44F5-B37B-A2521739FC3D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{37263DE8-9CCC-4F0D-8440-2E74D3670993}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4063555D-277F-4977-96F7-692DC10A2545}" = rport=445 | protocol=6 | dir=out | app=system |
"{49969AAF-D9F4-4CDA-8C17-58579A46A3E3}" = lport=10243 | protocol=6 | dir=in | app=system |
"{4C920637-E15D-4F41-B765-F8FCDF4CF6E7}" = lport=445 | protocol=6 | dir=in | app=system |
"{51657973-419D-40D0-81EF-E94C6C3885F1}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{537A3742-1226-47F4-BE7F-6D8BC60F4F5C}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{53C4AAC8-6B76-4599-A065-2C8F2D0F56FB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5678D6BF-EA96-4DA6-A7E9-02ED1304E9F8}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{63B0B5BF-78E3-4D41-9E4C-538B5882CCDA}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{65789E52-29BD-4BA5-9F8A-58D5364F2CEA}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6849E627-1BDD-4246-BA98-8B9018C963C2}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{68E75825-6C86-4BF5-8CF0-0788FEF60A78}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{6CBA7093-F5CA-4B35-B126-783AD5F69D9E}" = rport=10244 | protocol=6 | dir=out | app=system |
"{6CF4D255-99A5-42A5-9158-BB65FBA25C59}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{6D8222DB-2330-4A38-A007-DF7AA94242EA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{747E57D4-ED60-4964-99C1-547D77BE48B2}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{7D2E965C-0C5E-43FC-BFC0-1A96513A7F56}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{899378CE-D96D-4BF4-8541-6F0CBABA4288}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{93913F85-7A30-413E-9342-FC4C37D9848B}" = lport=137 | protocol=17 | dir=in | app=system |
"{94579499-69C1-4987-B7B2-BDBFFB780024}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{95D1C9E9-D724-4F69-8B70-9C30392CEAAE}" = rport=10244 | protocol=6 | dir=out | app=system |
"{A029C1A0-4C27-417F-9D0A-6A6963EFB7EA}" = rport=137 | protocol=17 | dir=out | app=system |
"{A0E425D5-5485-4EA1-B455-AB9AF843ADEB}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{B17EC995-1BFB-4AB4-B865-5E59C2D05B09}" = lport=139 | protocol=6 | dir=in | app=system |
"{B4E6009D-085D-4512-93C9-D9DDA1F8CFAA}" = lport=138 | protocol=17 | dir=in | app=system |
"{BADEF0A2-29AC-4732-A456-99656AC753D0}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C440558E-B8ED-4760-949C-BDCFE5E7A693}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{CACEA92B-822D-4D1A-A54E-648BDD3419D8}" = lport=3390 | protocol=6 | dir=in | app=system |
"{CCBAFFB2-1129-4B23-8B1E-77B289C95615}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D9B24D8D-5F20-49D1-BCB9-E44A0F4255DF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E2E61CBE-1B8F-4D35-BA1E-C10CC0D68B9D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{E8EA674A-F1F4-438F-8ABD-8D0595DCEA0F}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{EA31851D-F54F-45E9-8A1C-D1FF5836487E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EBD159E3-0639-4332-BD0C-DB0836E0762B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F8786D21-4A2A-48F6-AA7E-700438077CE5}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FAD3EDED-7CA5-40E3-86F7-C9EFFE880C1F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FDB43EA3-0AA7-42D5-9954-4EF4D32B3C0D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E622DBC-ED75-4318-BDFE-ABA8582C3189}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{10CD0016-3968-4E30-8485-022828DD04FD}" = protocol=6 | dir=in | app=f:\programme\ubisoft\shaunwhite\shaunwhitesnowboardinggame.exe |
"{1634D116-6D18-4F9A-A62D-9E2DD14C5210}" = protocol=6 | dir=in | app=c:\program files\sierra games\wic_ds.exe |
"{184503D7-4E14-4AA4-957B-28C0FCAB061C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe |
"{1853A475-C03B-47F5-8AE4-1F5F20FBAF3B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{1B39EC54-2059-4735-80D2-9E472EE95CA0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{20818E8C-4BD5-4DFA-8010-8BA451E3E6F8}" = protocol=17 | dir=in | app=c:\program files\sierra games\wic_ds.exe |
"{212D0B65-8938-4698-BEF4-F8AD3A0E7AA7}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{21C38210-3C63-45B2-8C67-1C4E9509FFE7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{22960918-ED57-416C-ADED-1CC39C0112C1}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{23E44FA8-25BE-4D4D-8F5A-BC13065AFBF0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{26528D43-E4C7-4807-A1B6-92B32AC9F4E8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{285DC7A4-832E-4ECF-9F31-45BC6E817FE0}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{2CF1121A-DDB1-48EA-9B94-A24DD6826424}" = protocol=17 | dir=in | app=f:\programme\itunes\itunes.exe |
"{2F36DF23-D079-4AB3-AA51-0C5D914DD9C3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{31F73A4F-CA1F-4F22-8BA5-8796514869D7}" = protocol=17 | dir=in | app=f:\programme\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{363674AD-E4F8-4562-B265-4E6A17915D99}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{3CCB0CDD-8105-46FA-BD43-EC5ADFCD1143}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{421CCCA8-B77B-4F58-9016-18EFA99BEBE1}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{4308B23E-BAD6-475C-8A38-FCF27AC09351}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{44AE1CC7-6372-4A71-A424-96AD12884344}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{4F647465-0C2F-44E8-A1E5-40C1C0C9FB90}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{4F6F7A46-5D51-4F5E-9EA7-C300CB812D35}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{516E691A-0D0A-4BF8-825A-EEE6E27223C2}" = protocol=6 | dir=in | app=f:\programme\itunes\itunes.exe |
"{54BF8067-353F-4789-A579-19F74A0B8181}" = protocol=6 | dir=in | app=f:\program files\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{58CE0B16-50D2-4743-A41E-43BFD256DCC0}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{5ADCB0CC-C6B7-4ECC-8D7C-AEF4690A4E78}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5B2657E6-70D9-48BF-94F4-DD21D1D7939F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5D24E30B-2035-4A1A-9C9B-CBA06DF669E1}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{6492189D-D1B8-4FF2-9195-4F9643C2279B}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{69CA568C-67A2-4107-BEFD-86F9DD8E1CBD}" = protocol=6 | dir=out | app=system |
"{69EA3BA1-85F4-4AD5-AC07-48ABF2BA13FE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6A6E8455-A074-465D-9EB1-CB9E40433405}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{718BB000-440E-4DEE-BA20-17AAA085E470}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{71B4403E-2DDD-491D-BF1B-4FA499CD55D2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{753474C5-F1E6-4619-9083-5B644B70DCF5}" = protocol=6 | dir=in | app=c:\program files\activision\cod4\iw3mp.exe |
"{79ACE57B-93B4-4216-869C-B6AA10AF131A}" = protocol=17 | dir=in | app=c:\program files\midway games\rise and fall\riseandfall.exe |
"{7A437381-8981-4C12-9BDF-19D9615701CF}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{80538A2C-1B26-46FF-9EFA-591B7961B6A0}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{875186CD-2A59-44BC-AE0F-5DE2BF3EA945}" = protocol=6 | dir=in | app=c:\program files\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{882B0E4B-9E9D-4BB7-9954-91DB2A79E4DD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8B3938FB-2845-489A-AA59-45A88D12B0F0}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{8C22B901-5664-45F3-BC84-0EC309BB3CD7}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8CA407F9-8560-4E66-A588-CE465AA9BD28}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{9C8C870B-CC1A-4DFF-BB5F-04475C68D457}" = protocol=17 | dir=in | app=c:\users\nico\appdata\locallow\dyyno receiver\dppm.exe |
"{9CD2B854-92EA-4324-AF25-D6DBDBF74B65}" = protocol=6 | dir=in | app=f:\programme\ubisoft\shaunwhite\shaunwhitesnowboarding.exe |
"{9DA2B874-D77B-4A88-B137-35C91ED730FF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A2DACCE1-E27D-46BD-B869-3955D3B903BA}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A48F14D5-96B1-4976-B59A-D0D615BE51E9}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A6EC7876-7AA5-4A73-AD14-46D813118E53}" = protocol=17 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
"{A9C0319F-2C91-4863-8EE3-2061455881A0}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-dede-downloader.exe |
"{AC9CE1FF-3C90-446A-8229-823CA51F19D0}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{AE4ACB50-5660-4A8E-A919-6DF4D0966081}" = protocol=17 | dir=in | app=f:\programme\ubisoft\shaunwhite\shaunwhitesnowboarding.exe |
"{AEBD2AE3-A5B1-4129-BB4D-C0BECF348204}" = protocol=17 | dir=in | app=c:\program files\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{AFE886E0-4B18-45B3-B455-EC108009DE72}" = protocol=6 | dir=in | app=f:\programme\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{B015F6FF-2E90-4E23-B079-12122609DCD3}" = protocol=17 | dir=in | app=f:\programme\ubisoft\shaunwhite\shaunwhitesnowboardinggame.exe |
"{B8D5E00E-8277-4801-AEC5-604D67CFA48B}" = protocol=6 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
"{B9D5A4CC-32BD-4CBB-B48C-A4F822C2010F}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"{BBADE287-1BBA-497B-BB4E-27A7F209B482}" = protocol=17 | dir=in | app=c:\program files\sierra games\wic_online.exe |
"{BDB715CF-C5D0-4206-AAB6-16FAB249EA0F}" = protocol=6 | dir=in | app=c:\program files\sierra games\wic.exe |
"{BF6A4CFE-C534-4BF4-913A-14A4F802F3A0}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{BFDFD884-43DC-4040-BD2A-C0961EC39FF4}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{C20F8C31-5F20-490D-8EA4-53F609282A9B}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{C27ED155-9556-4E01-B45C-27B4603B95E1}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{C60ED85D-7B20-4B39-97F1-30D3FAEE3210}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CA3F72E1-0DDA-49C2-8E3F-2C87CE1D42CA}" = protocol=6 | dir=in | app=c:\users\nico\appdata\locallow\dyyno receiver\dppm.exe |
"{CA8FDE01-23C9-4D67-92EA-0FBE60832146}" = protocol=17 | dir=in | app=c:\program files\sierra games\wic.exe |
"{CADB7677-50B3-4A6D-872C-E3859DC9A66B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{CDB770A8-363E-4C55-9AE7-0AC399EF1F31}" = protocol=6 | dir=in | app=c:\program files\midway games\rise and fall\riseandfall.exe |
"{D0592BDA-AF6D-4782-AC54-B2462B84AECE}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{D2FDDBFE-FC88-4B7B-AC7A-4A4AFFED81D8}" = protocol=6 | dir=in | app=c:\program files\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe |
"{DAA6F83A-0139-4080-90C5-CFC8C1CDB12E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{DF0E44F2-6C81-453D-94C2-5B36DFE9A7C3}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{E23BFAD7-2890-4120-BA8F-AA5997DFD262}" = protocol=17 | dir=in | app=f:\program files\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{E47D85F5-B22D-4C97-8655-3880773E8E60}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-dede-downloader.exe |
"{E5270183-632A-4CF4-80A1-AA0E0A3A63F2}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{E71B8BB3-3D9E-4F55-A0B1-1B8F4BDDB1F8}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{EBE354B6-51D8-4461-953C-0EF5794A7AF7}" = protocol=17 | dir=in | app=c:\program files\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe |
"{EF8B480C-EC80-41DF-BCB5-5F272D372550}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{F2BAE327-765A-402B-AF47-CE9E571F11D5}" = dir=in | app=f:\programme\electronic arts\command and conquer tiberium wars\retailexe\1.9\cnc3game.dat |
"{F3E2C6F7-7FAB-472D-901B-5C8EDF8C5261}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F48989DD-0325-43AB-B1D8-7D7A857F49AB}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{F50E3981-D58A-430B-AC2F-6BCF68F93013}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{F527DBC3-7E15-4944-8A76-4C3D0C685449}" = protocol=17 | dir=in | app=c:\program files\activision\cod4\iw3mp.exe |
"{F9269BAF-4DE7-4AA9-B85D-024BD616274C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FC5E660B-4D7C-4DF0-9EA3-97BC86A0DCDE}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{FDA732FB-5664-4E6A-97CD-FC5476D3CAFA}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{FE3AEA0E-5474-487E-B316-649E77D0EC72}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{FEF9E9F4-A3C3-4A35-A302-ED0A421A44C4}" = protocol=6 | dir=in | app=c:\program files\sierra games\wic_online.exe |
"TCP Query User{03D7814F-5E6F-46F4-84FE-78048805EDA9}F:\programme\activision\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=f:\programme\activision\call of duty 2\cod2mp_s.exe |
"TCP Query User{0E2A9752-3FC5-4A7D-ABC1-DA9D5E0F0C66}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"TCP Query User{27D98D36-8826-4EDB-8F64-C79D54C12BCC}F:\programme\activision\call of duty 4 - modern warfare\iw3mp.exe" = protocol=6 | dir=in | app=f:\programme\activision\call of duty 4 - modern warfare\iw3mp.exe |
"TCP Query User{28BB3054-CC82-4FA3-8425-F8C89CE01A79}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{2A82EC34-2E5E-48FB-B505-8DD000885F6D}C:\program files\java\jre6\launch4j-tmp\jdownloader.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\launch4j-tmp\jdownloader.exe |
"TCP Query User{2C61F42C-5320-4F4D-8195-02916E3B2EA1}F:\programme\worms armageddon\wa.exe" = protocol=6 | dir=in | app=f:\programme\worms armageddon\wa.exe |
"TCP Query User{3349B1D8-47DB-4203-9CCB-1B5EB83F2B5A}F:\programme\activision\cod\codmp.exe" = protocol=6 | dir=in | app=f:\programme\activision\cod\codmp.exe |
"TCP Query User{3DBB8869-B3DD-485D-AE09-BC7B3A9E8549}C:\program files\activision\cod\codmp.exe" = protocol=6 | dir=in | app=c:\program files\activision\cod\codmp.exe |
"TCP Query User{3F699397-5447-4D89-8C8C-46EBD379E1A2}C:\program files\postal2stp\system\postal2.exe" = protocol=6 | dir=in | app=c:\program files\postal2stp\system\postal2.exe |
"TCP Query User{3FCC6601-673B-4373-9488-5E9A1620FB69}F:\programme\microsoft games\age of empires 2 the age of kings\empires2.exe" = protocol=6 | dir=in | app=f:\programme\microsoft games\age of empires 2 the age of kings\empires2.exe |
"TCP Query User{41E78F66-F1BE-4B6E-9933-179B5042BC9C}F:\programme\metin2\metin2.bin" = protocol=6 | dir=in | app=f:\programme\metin2\metin2.bin |
"TCP Query User{48344DDA-927A-4172-BCB0-0DBC38391791}C:\users\nico\desktop\neuer ordner\coduomp.exe" = protocol=6 | dir=in | app=c:\users\nico\desktop\neuer ordner\coduomp.exe |
"TCP Query User{4917B38A-8BE7-4B03-BCB8-8B5DFC26872C}F:\programme\metin2\metin2client.bin" = protocol=6 | dir=in | app=f:\programme\metin2\metin2client.bin |
"TCP Query User{4A242EA3-0D8C-415E-8FD7-9A50E3E8E9AE}F:\programme\dead space\dead space.exe" = protocol=6 | dir=in | app=f:\programme\dead space\dead space.exe |
"TCP Query User{5E47DFE3-9F89-4353-96DD-D52D934DA735}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{6A78EB0E-986A-4631-A66B-DBD7F86F660C}C:\program files\wow\repair.exe" = protocol=6 | dir=in | app=c:\program files\wow\repair.exe |
"TCP Query User{74B98BE2-0707-4254-A158-FC10493F37D9}C:\program files\left 4 dead\left4dead.exe" = protocol=6 | dir=in | app=c:\program files\left 4 dead\left4dead.exe |
"TCP Query User{79131458-1A9B-4BD2-A678-474904C09927}F:\programme\battlefield vietnam\bfvietnam.exe" = protocol=6 | dir=in | app=f:\programme\battlefield vietnam\bfvietnam.exe |
"TCP Query User{7E9285ED-D436-4A1E-9E0E-3A07C8B79FF3}F:\programme\electronic arts\command & conquer 3\retailexe\1.9\cnc3game.dat" = protocol=6 | dir=in | app=f:\programme\electronic arts\command & conquer 3\retailexe\1.9\cnc3game.dat |
"TCP Query User{80B38D5E-89D2-4638-A37A-4F133DDBEC12}F:\programme\tom clancy's h.a.w.x\hawx.exe" = protocol=6 | dir=in | app=f:\programme\tom clancy's h.a.w.x\hawx.exe |
"TCP Query User{8820DC4B-94DF-4C69-99B5-60A31DE2C44C}C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\german\setup.exe" = protocol=6 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\german\setup.exe |
"TCP Query User{993397FF-DB0A-40E9-B41F-26D711FE4420}C:\program files\activision\cod\coduomp.exe" = protocol=6 | dir=in | app=c:\program files\activision\cod\coduomp.exe |
"TCP Query User{A85664EE-CF49-4CAB-8412-8D88AB7F80E6}C:\program files\wow\launcher.exe" = protocol=6 | dir=in | app=c:\program files\wow\launcher.exe |
"TCP Query User{A9E53ACF-476C-4D7E-A729-3560AD3A4477}C:\users\nico\appdata\local\temp\electronicarts_patcher_000.exe" = protocol=6 | dir=in | app=c:\users\nico\appdata\local\temp\electronicarts_patcher_000.exe |
"TCP Query User{B2BAE860-49B7-494F-999C-3F128281A40E}F:\programme\far cry 2\bin\farcry2.exe" = protocol=6 | dir=in | app=f:\programme\far cry 2\bin\farcry2.exe |
"TCP Query User{B5A54A0A-4FD5-4C71-AED4-B795E5F5688F}C:\program files\activision\cod4\iw3mp.exe" = protocol=6 | dir=in | app=c:\program files\activision\cod4\iw3mp.exe |
"TCP Query User{BA4063EE-9AD8-4AFB-B943-E9D2D67E92A3}F:\programme\steam\steamapps\optiolol\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=f:\programme\steam\steamapps\optiolol\counter-strike source\hl2.exe |
"TCP Query User{C1515480-ABF8-4B11-96AE-DDF1B8E865FC}C:\program files\activision\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 2\cod2mp_s.exe |
"TCP Query User{D6382914-4211-441C-BC7D-1E149C671738}G:\spiele\command & conquer 3\retailexe\1.9\cnc3game.dat" = protocol=6 | dir=in | app=g:\spiele\command & conquer 3\retailexe\1.9\cnc3game.dat |
"TCP Query User{D81F15B1-47C3-4A6B-AC27-23794C912F63}F:\programme\firefly studios\stronghold crusader\stronghold crusader.exe" = protocol=6 | dir=in | app=f:\programme\firefly studios\stronghold crusader\stronghold crusader.exe |
"TCP Query User{DD9E953A-706A-46AA-8529-C781A79C5054}C:\program files\activision\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 2\cod2mp_s.exe |
"TCP Query User{DE79D49F-E6E2-4E79-BD38-1A208F94FDB3}F:\programme\activision\cod\coduomp.exe" = protocol=6 | dir=in | app=f:\programme\activision\cod\coduomp.exe |
"TCP Query User{EB976354-E18D-427B-9729-71A4FE3E5241}F:\programme\xfire\xfire.exe" = protocol=6 | dir=in | app=f:\programme\xfire\xfire.exe |
"TCP Query User{EEBE6567-9A87-46BE-996D-93D55BB457A0}F:\programme\icq6.5\icq.exe" = protocol=6 | dir=in | app=f:\programme\icq6.5\icq.exe |
"TCP Query User{F07A5F1D-CCEC-4DD3-AE3B-8B91A0728509}F:\programme\xfire\xfire.exe" = protocol=6 | dir=in | app=f:\programme\xfire\xfire.exe |
"TCP Query User{F3CA7FB6-7D62-4E25-8DB6-0B08EB0BBD23}F:\programme\hlsw\hlsw.exe" = protocol=6 | dir=in | app=f:\programme\hlsw\hlsw.exe |
"TCP Query User{FAB910C6-7385-4B29-B3E1-78EB8D1F0222}F:\programme\halo\halo.exe" = protocol=6 | dir=in | app=f:\programme\halo\halo.exe |
"UDP Query User{095C3AB0-C7D0-4E38-B204-0B0233D8F4E6}C:\program files\left 4 dead\left4dead.exe" = protocol=17 | dir=in | app=c:\program files\left 4 dead\left4dead.exe |
"UDP Query User{0B76F548-B64A-49F8-865E-2AAEEAA86838}C:\program files\wow\repair.exe" = protocol=17 | dir=in | app=c:\program files\wow\repair.exe |
"UDP Query User{16C0336B-1320-4846-839C-4136F1CD327D}F:\programme\icq6.5\icq.exe" = protocol=17 | dir=in | app=f:\programme\icq6.5\icq.exe |
"UDP Query User{18BB681D-7076-458D-8F9C-67969908CB6B}F:\programme\metin2\metin2client.bin" = protocol=17 | dir=in | app=f:\programme\metin2\metin2client.bin |
"UDP Query User{19A89B58-9D24-4B3E-BE78-7A8BABDBE249}C:\program files\activision\cod4\iw3mp.exe" = protocol=17 | dir=in | app=c:\program files\activision\cod4\iw3mp.exe |
"UDP Query User{35D8A1D3-F2BC-4DD0-AA17-995354BA070F}F:\programme\activision\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=f:\programme\activision\call of duty 2\cod2mp_s.exe |
"UDP Query User{3D731044-6B25-409D-A04E-86CC0C7FECF5}F:\programme\hlsw\hlsw.exe" = protocol=17 | dir=in | app=f:\programme\hlsw\hlsw.exe |
"UDP Query User{4C999404-F378-4C22-B790-B262A1AFCE7D}C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\german\setup.exe" = protocol=17 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\german\setup.exe |
"UDP Query User{4F0EAA92-6B50-4D06-B204-2CC1055B80FD}C:\program files\java\jre6\launch4j-tmp\jdownloader.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\launch4j-tmp\jdownloader.exe |
"UDP Query User{4F24F115-08A9-4CB0-A94F-BD4EB94052B9}F:\programme\activision\cod\coduomp.exe" = protocol=17 | dir=in | app=f:\programme\activision\cod\coduomp.exe |
"UDP Query User{671E443F-A832-4E25-85CF-4245955C0E7D}C:\program files\activision\cod\codmp.exe" = protocol=17 | dir=in | app=c:\program files\activision\cod\codmp.exe |
"UDP Query User{672A4D49-E844-402E-9988-FE843AAE266D}F:\programme\far cry 2\bin\farcry2.exe" = protocol=17 | dir=in | app=f:\programme\far cry 2\bin\farcry2.exe |
"UDP Query User{79197F36-C3E7-4707-95FC-06B28F581A09}C:\program files\activision\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 2\cod2mp_s.exe |
"UDP Query User{7CF6C659-F6FA-4C8C-AC03-17E77D03FAE0}C:\program files\wow\launcher.exe" = protocol=17 | dir=in | app=c:\program files\wow\launcher.exe |
"UDP Query User{7D0849E4-4895-4F15-AF19-CFB02AFEE749}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{7E8D4DB1-5979-4FF6-851B-36D328FD92C0}C:\users\nico\appdata\local\temp\electronicarts_patcher_000.exe" = protocol=17 | dir=in | app=c:\users\nico\appdata\local\temp\electronicarts_patcher_000.exe |
"UDP Query User{86634CE6-1170-4738-974E-B558A276F15A}F:\programme\electronic arts\command & conquer 3\retailexe\1.9\cnc3game.dat" = protocol=17 | dir=in | app=f:\programme\electronic arts\command & conquer 3\retailexe\1.9\cnc3game.dat |
"UDP Query User{8DA1B81C-024C-420E-8D00-09818BAE6428}F:\programme\microsoft games\age of empires 2 the age of kings\empires2.exe" = protocol=17 | dir=in | app=f:\programme\microsoft games\age of empires 2 the age of kings\empires2.exe |
"UDP Query User{8F65452A-B4E7-4987-B0B8-7E8831FF2FB9}F:\programme\dead space\dead space.exe" = protocol=17 | dir=in | app=f:\programme\dead space\dead space.exe |
"UDP Query User{9A734DE8-1C32-49AE-915F-7775CC853CCF}F:\programme\firefly studios\stronghold crusader\stronghold crusader.exe" = protocol=17 | dir=in | app=f:\programme\firefly studios\stronghold crusader\stronghold crusader.exe |
"UDP Query User{A566035F-83A2-4EE2-8B55-EF5937FC7463}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{B1AFD9F4-CDC8-43AE-986D-61202C4E60A2}G:\spiele\command & conquer 3\retailexe\1.9\cnc3game.dat" = protocol=17 | dir=in | app=g:\spiele\command & conquer 3\retailexe\1.9\cnc3game.dat |
"UDP Query User{B23C8BF4-1ECC-4BA3-BA7F-AF194FC5DE4A}F:\programme\xfire\xfire.exe" = protocol=17 | dir=in | app=f:\programme\xfire\xfire.exe |
"UDP Query User{B60CC65B-5F7D-457D-987A-13B86ADC9428}F:\programme\halo\halo.exe" = protocol=17 | dir=in | app=f:\programme\halo\halo.exe |
"UDP Query User{B76DC34F-35D7-4E20-A0D4-52C72AC7CA22}C:\users\nico\desktop\neuer ordner\coduomp.exe" = protocol=17 | dir=in | app=c:\users\nico\desktop\neuer ordner\coduomp.exe |
"UDP Query User{B83AB61B-1A12-4874-8E8F-ED16322F243B}F:\programme\battlefield vietnam\bfvietnam.exe" = protocol=17 | dir=in | app=f:\programme\battlefield vietnam\bfvietnam.exe |
"UDP Query User{BA7E8B1E-EC86-44AD-9272-E7F05A4D196C}F:\programme\activision\cod\codmp.exe" = protocol=17 | dir=in | app=f:\programme\activision\cod\codmp.exe |
"UDP Query User{BC659AA2-13DF-43CE-9D13-93378DCEB9B6}C:\program files\postal2stp\system\postal2.exe" = protocol=17 | dir=in | app=c:\program files\postal2stp\system\postal2.exe |
"UDP Query User{C80AD029-E05F-4CAE-AD39-A8F0302C7A19}C:\program files\activision\cod\coduomp.exe" = protocol=17 | dir=in | app=c:\program files\activision\cod\coduomp.exe |
"UDP Query User{CD0E34D6-80ED-46C4-9232-2841F98C0F41}C:\program files\activision\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 2\cod2mp_s.exe |
"UDP Query User{CDBB0EFE-0E49-428F-8E8F-79C556D0116D}F:\programme\tom clancy's h.a.w.x\hawx.exe" = protocol=17 | dir=in | app=f:\programme\tom clancy's h.a.w.x\hawx.exe |
"UDP Query User{D4876D4C-903F-4707-9AE5-6BF602B98B16}F:\programme\xfire\xfire.exe" = protocol=17 | dir=in | app=f:\programme\xfire\xfire.exe |
"UDP Query User{E4D89834-32E8-4CCF-934C-ECCB80848907}F:\programme\metin2\metin2.bin" = protocol=17 | dir=in | app=f:\programme\metin2\metin2.bin |
"UDP Query User{F3BA5037-B25B-4E47-A156-D2797058141A}F:\programme\activision\call of duty 4 - modern warfare\iw3mp.exe" = protocol=17 | dir=in | app=f:\programme\activision\call of duty 4 - modern warfare\iw3mp.exe |
"UDP Query User{F573619F-4530-4ED9-ABC8-8D0BB616F105}F:\programme\steam\steamapps\optiolol\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=f:\programme\steam\steamapps\optiolol\counter-strike source\hl2.exe |
"UDP Query User{F7A5C010-16EE-4E68-BCA3-403F1F9F6416}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{F7B7EB9D-AAA6-45C9-9DF1-D426C95F594A}F:\programme\worms armageddon\wa.exe" = protocol=17 | dir=in | app=f:\programme\worms armageddon\wa.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01521746-02A6-4A72-00BD-A285DF6B80C6}" = Die Sims 2: Wilde Campus-Jahre
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{03B0D67B-36C9-C2CD-B63B-7B526138BA52}" = ccc-utility
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04FC2E4C-0E41-9D39-4E58-1EF29D4EF09D}" = ccc-core-static
"{04FE63AC-AC7B-4C80-83AA-CCACA48C0C19}" = PS_AIO_04_C5300_Software
"{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{086BADF8-9B1F-4E89-B207-2EDA520972D6}" = Grand Theft Auto San Andreas
"{0949C078-58B4-CAF1-9A63-A4545145806D}" = Catalyst Control Center Graphics Previews Common
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{09725E0F-6406-4500-8296-DBF6E697E9D7}" = C5300
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation(R)Store
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{14574B7F-75D1-4718-B7F2-EBF6E2862A35}" = Company of Heroes - FAKEMSI
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{199E6632-EB28-4F73-AECB-3E192EB92D18}" = Company of Heroes - FAKEMSI
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20DEB77C-21D6-4D22-BB47-233E47613D57}" = Microsoft Games for Windows - LIVE Redistributable
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{25724802-CC14-4B90-9F3B-3D6955EE27B1}" = Company of Heroes - FAKEMSI
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 20
"{26BEE28E-C285-4532-82D3-7CE3C5F805D4}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{2AFEAA03-2DFE-4519-A629-EDAB6541ABE9}" = HPSSupply
"{32C4A4EB-C97D-414E-99C5-38F8DFD31D5D}" = Company of Heroes - FAKEMSI
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{38D9575F-6228-6A54-3A92-D902739B6541}" = Catalyst Control Center InstallProxy
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMB36X Raid Configurer
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3AD56302-2ADE-4A1C-864A-CB9FFF040576}" = PS_AIO_04_C5300_ProductContext
"{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{489CA990-9FFB-495A-B5F6-027199E65405}" = PS_AIO_04_C5300_Software_Min
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A3D0CF8-60FF-4CEF-91A4-A1F001424602}" = DocProc
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{50193078-F553-4EBA-AA77-64C9FAA12F98}" = Company of Heroes - FAKEMSI
"{51D718D1-DA81-4FAD-919F-5C1CE3C33379}" = Company of Heroes - FAKEMSI
"{573F1931-08F7-9222-704E-841C391794C5}" = ATI Catalyst Install Manager
"{5D7767FA-7FE8-4627-9F09-AEF7A25F1E07}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.1 Patch
"{5E8B45A0-072C-91F7-BC80-29374194B452}" = Catalyst Control Center Graphics Previews Vista
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{66F78C51-D108-4F0C-A93C-1CBE74CE338F}" = Company of Heroes - FAKEMSI
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69C57747-551F-4e4f-AB60-13358DC4F00A}" = HP Photosmart C5300 All-In-One Driver Software 11.0 Rel .4
"{6CC1EE94-B426-478B-AE83-F83EBB4EF66A}" = HPPhotoSmartDiscLabel_PaperLabel
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = Die Sims 2
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70E1E357-E57C-4284-B04E-58196DC27BC1}" = PanoStandAlone
"{74DC0593-6BC6-4001-AD5F-D810AFB68D86}" = HP Update
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = Die Sims 2: Open For Business
"{7B4A5C13-069F-4AFE-AE57-C497B4E33C7E}" = Call of Duty(R) 2 Patch 1.3
"{7BA01D2D-E25C-0C2C-5779-7A8E02A4BE7D}" = Catalyst Control Center Core Implementation
"{7ED180E1-ADE9-4C69-8845-BDF518D763B8}" = hpphotosmartdisclabelplugin
"{7F4B1592-222F-4E5F-A100-E5AFD61A0BB3}" = Company of Heroes - FAKEMSI
"{80D03817-7943-4839-8E96-B9F924C5E67D}" = Company of Heroes - FAKEMSI
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Patch
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding
"{8FF4E834-DCAD-29E7-1EE8-9D817A3FA15B}" = CCC Help English
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90850407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{9580813D-94B1-4C28-9426-A441E2BB29A5}" = Counter-Strike: Source
"{97E5205F-EA4F-438F-B211-F1846419F1C1}" = Company of Heroes - FAKEMSI
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{99A7722D-9ACB-43F3-A222-ABC7133F159E}" = Company of Heroes - FAKEMSI
"{99E862CC-6F69-4D39-99AA-DBF71BF3B585}" = OpenOffice.org 3.1
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9F4EE72A-C5C9-42ad-ABEF-427690843577}" = MarketResearch
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A8B94669-8654-4126-BD28-D0D2412CDED6}" = TI Connect 1.6
"{AA2E8A46-B45E-4aea-8A23-88AB57D04523}" = WebReg
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.2 - Deutsch
"{AEDBD563-24BB-4EE3-8366-A654DAC2D988}" = Mirror's Edge™
"{B3276CB1-20B6-4AF9-AAEC-E72C83816495}" = IKEA Home Planner
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BA801B94-C28D-46EE-B806-E1E021A3D519}" = Company of Heroes - FAKEMSI
"{BC4CA8FA-41D2-4B81-8680-E9B7573D6500}" = PlayStation(R)Network Downloader
"{BCC09E9C-3340-473D-A4FE-8580992CA77A}" = HPPhotoSmartDiscLabelContent1
"{BF08AB1C-3357-4f20-A200-8EBB8EF27C59}" = BufferChm
"{C03A56EE-2715-5F54-69C4-A1CDB7602354}" = Catalyst Control Center Graphics Full New
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die*Sims™*3
"{C307DD64-1C69-8C52-D2C9-02D38995A269}" = Catalyst Control Center HydraVision Full
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C89B5E3A-690F-4CEE-909A-BF869E198B0A}" = Scan
"{C9933E93-8653-447E-9A19-9BCF658E3AE9}" = C5300_Help
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D078226E-83F2-45FD-9CDE-5DA66E5ADB51}" = Rise and Fall
"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D16B4BE6-8B10-422f-8034-96D1CA9483B5}" = GPBaseService
"{D4D244D1-05E0-4D24-86A2-B2433C435671}" = Company of Heroes - FAKEMSI
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{D99223D4-1F48-47BD-ADFD-D43C91CDFD00}" = S4 League
"{DDEDAF6C-488E-4CDA-8276-1CCF5F3C5C32}" = Command & Conquer 3
"{E3E1398E-8FF2-0154-6D8F-7FC26299EBED}" = Catalyst Control Center Graphics Full Existing
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E5141379-B2D9-4BBC-BB2A-5805541571DD}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{EAF636A9-F664-4703-A659-85A894DA264F}" = Company of Heroes - FAKEMSI
"{ED1390DC-6910-4C77-97E2-579CAFE82F5B}" = Moorhuhn 4 Teile
"{ED3866E9-4F50-4A47-9945-58D5C97AB56F}" = Media Go
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{EF36A836-BF89-4A4F-B079-057B0C68C1E0}" = Sid Meier's Civilization IV Colonization
"{EF9E56EE-0243-4BAD-88F4-5E7508AA7D96}" = Destination Component
"{F11ADC64-C89E-47F4-A0B3-3665FF859397}" = WORLD IN CONFLICT
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = Die Sims 2: Nightlife
"{FBEF69BB-829C-8D4D-B299-497147916039}" = Catalyst Control Center Graphics Light
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CEP - Colour Enable Packages_is1" = CEP - Color Enable Package
"Cheat Engine 5.4_is1" = Cheat Engine 5.4
"Command and Conquer™ 3 Tiberium Wars™ Sprachsteuerung" = Command and Conquer™ 3 Tiberium Wars™ Sprachsteuerung 1.0.0.0
"Company of Heroes" = Company of Heroes
"Free Video to iPod Converter_is1" = Free Video to iPod Converter version 3.2
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 11.0
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 11.0
"HPOCR" = OCR Software by I.R.I.S. 11.0
"ImgBurn" = ImgBurn
"InstallShield_{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch
"InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
"InstallShield_{5D7767FA-7FE8-4627-9F09-AEF7A25F1E07}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.1 Patch
"InstallShield_{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"InstallShield_{E5141379-B2D9-4BBC-BB2A-5805541571DD}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch
"Left 4 Dead" = Left 4 Dead
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Metin2_is1" = Metin2
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.9)" = Mozilla Firefox (3.5.9)
"NeroMultiInstaller!UninstallKey" = Nero Suite
"oZone3D.Net FurMark_is1" = oZone3D.Net FurMark v1.8.0
"Postal 2 Share The Pain" = Postal 2 Share The Pain
"PunkBusterSvc" = PunkBuster Services
"RollerCoaster Tycoon 3_is1" = RollerCoaster Tycoon 3
"Shop for HP Supplies" = Shop for HP Supplies
"Sims2Pack Clean Installer " = Sims2Pack Clean Installer
"Steam App 240" = Counter-Strike: Source
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.0.5
"WinRAR archiver" = WinRAR archiver
"Zygor Guides" = Zygor Guides
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"TeamSpeak 3 Client" = TeamSpeak 3 Client
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 23.05.2010 10:27:11 | Computer Name = Nico-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung RunDLL32.exe, Version 6.0.6000.16386, Zeitstempel
 0x4549b0e1, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000,
 Ausnahmecode 0xc0000005, Fehleroffset 0x01ada8ed,  Prozess-ID 0x1720, Anwendungsstartzeit
 01cafa840833212c.
 
Error - 23.05.2010 17:53:44 | Computer Name = Nico-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 24.05.2010 09:10:07 | Computer Name = Nico-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 24.05.2010 09:10:32 | Computer Name = Nico-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung hpqpsapp.exe, Version 110.0.226.11, Zeitstempel
 0x47e22104, fehlerhaftes Modul hpqpsapp.exe, Version 110.0.226.11, Zeitstempel
0x47e22104, Ausnahmecode 0xc0000005, Fehleroffset 0x00176e77,  Prozess-ID 0xfb8, Anwendungsstartzeit
 01cafb427743b6a0.
 
Error - 24.05.2010 14:09:05 | Computer Name = Nico-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung javaw.exe, Version 6.0.200.2, Zeitstempel 0x4bc398b3,
 fehlerhaftes Modul java.dll, Version 6.0.200.2, Zeitstempel 0x4bc3c8dc, Ausnahmecode
 0xc0000005, Fehleroffset 0x00005875,  Prozess-ID 0x1158, Anwendungsstartzeit 01cafb6c31c7f4e0.
 
Error - 25.05.2010 12:16:20 | Computer Name = Nico-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 25.05.2010 13:51:32 | Computer Name = Nico-PC | Source = Application Hang | ID = 1002
Description = Programm gta_sa.exe, Version 0.0.0.0 arbeitet nicht mehr mit Windows
 zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen
 für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem
 zu suchen.  Prozess-ID: 860  Anfangszeit: 01cafc310e6120fd  Zeitpunkt der Beendigung:
 206
 
Error - 25.05.2010 14:07:49 | Computer Name = Nico-PC | Source = Avira AntiVir | ID = 4118
Description = AUSNAHMEFEHLER beim Aufruf der Funktion <Scan> für die Datei  G:\Programme\AquaSoft\lol\a\r\Katie_Price_042[1].jpg.

 [ACCESS_VIOLATION Exception!! EIP = 0x218c258]  Bitte Avira informieren und die
obige Datei übersenden!
 
Error - 25.05.2010 15:28:16 | Computer Name = Nico-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 26.05.2010 04:48:47 | Computer Name = Nico-PC | Source = WinMgmt | ID = 10
Description =
 
[ Media Center Events ]
Error - 18.05.2009 08:45:55 | Computer Name = Nico-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 09.08.2009 11:27:51 | Computer Name = Nico-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 16.10.2009 06:39:03 | Computer Name = Nico-PC | Source = Mcx2Dvcs | ID = 401
Description =
 
[ System Events ]
Error - 26.05.2010 11:40:33 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 26.05.2010 11:40:36 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 26.05.2010 11:41:39 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 26.05.2010 11:41:42 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 26.05.2010 11:42:48 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 26.05.2010 11:42:51 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 26.05.2010 11:43:54 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 26.05.2010 11:43:57 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 26.05.2010 11:45:00 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
Error - 26.05.2010 11:45:03 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
 
 
< End of report >


cosinus 26.05.2010 18:41

Zitat:

Error - 26.05.2010 11:43:57 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error - 26.05.2010 11:45:00 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error - 26.05.2010 11:45:03 | Computer Name = Nico-PC | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.
Scheint so als hätte eine Deiner Festplatten ein Problem. Harddisk1 müsste die 2. Platte sein (Zählung fängt bei 0 an!) als diese hier:

Code:

Drive G: | 465,76 Gb Total Space | 224,36 Gb Free Space | 48,17% Space Free | Partition Type: NTFS
Ist das eine externe Platte?

Darkfilter 26.05.2010 21:29

Jup, ich glaube ich kenne das Problem. Die Festplatte ist mal ein Platz verrutscht! Also sie war mal F und jetzt ist sie G. Musste die Pfade bei den Programmen ändern die auf F waren. Jedoch tat ich das nicht bei allen. Vielleicht wüsstest du noch eine Lösung für´s Problem.
Gruß Nico

cosinus 27.05.2010 18:10

Eine Laufwerksbuchstabenänderung ist so kein Hinweis auf ein echtes Problem. Was ich aus dem Ereisgnisprotokoll gefischt habe aber eher, denn das deutet auf ein Hardwareproblem hin! Das sollten wir im Hinterkopf behalten, lass und erstmal nach noch verbliebenen Schdälingen Ausschau halten, mach dazu bitte Logs mit GMER und OSAM - falls GMER auch beim 2. Mal abstürzt einfach nur OSAM ausführen.

Darkfilter 27.05.2010 21:41

Hier, Report von OSAM

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 22:34:37 on 27.05.2010
OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 3.5.9

Scanner Settings
Rootkits detection (hidden registry)
Rootkits detection (hidden files)
Retrieve files information
Check Microsoft signatures

Filters
Trusted entries
Empty entries
Hidden registry entries (rootkit activity)
Exclusively opened files
Not found files
Files without detailed information
Existing files
Non-startable services
Non-startable drivers
Active entries
Disabled entries

Risk Name Publisher Full Path Status
Common
%SystemRoot%\Tasks
|||| "WebReg HP Photosmart C5300 series.job" "Hewlett-Packard Co." C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe File exists
Control Panel Objects
%SystemRoot%\system32
|||||| "TIControlPanel.cpl" "Texas Instruments Incorporated" C:\Windows\system32\TIControlPanel.cpl File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls
|||||| "Pando" "Pando Networks" C:\Program Files\Pando Networks\Media Booster\PMB.cpl File exists
|||||| "QuickTime" "Apple Inc." C:\Program Files\QuickTime\QTSystem\QuickTime.cpl File exists
Drivers
HKLM\SYSTEM\CurrentControlSet\Services
|||||| "avgntflt" (avgntflt) "Avira GmbH" C:\Windows\System32\DRIVERS\avgntflt.sys File exists
|||||| "avipbb" (avipbb) "Avira GmbH" C:\Windows\System32\DRIVERS\avipbb.sys File exists
"cdrmkaun" (cdrmkaun) C:\Users\Nico\AppData\Local\Temp\cdrmkaun.sys File not found
"DBKDRVR54" (DBKDRVR54) F:\Program Files\Cheat Engine\dbk32.sys File not found
"dump_wmimmc" (dump_wmimmc) F:\Programme\Cossfire\CrossFire\GameGuard\dump_wmimmc.sys File not found
"EagleNT" (EagleNT) C:\Windows\system32\drivers\EagleNT.sys File not found
|||||| "ElbyCDIO Driver" (ElbyCDIO) "Elaborate Bytes AG" C:\Windows\System32\Drivers\ElbyCDIO.sys File exists
"GMSIPCI" (GMSIPCI) E:\INSTALL\GMSIPCI.SYS File not found
|||||| "Hamachi Network Interface" (hamachi) "LogMeIn, Inc." C:\Windows\System32\DRIVERS\hamachi.sys File exists
"IP in IP Tunnel Driver" (IpInIp) C:\Windows\System32\DRIVERS\ipinip.sys File not found
"IPX Traffic Filter Driver" (NwlnkFlt) C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
"IPX Traffic Forwarder Driver" (NwlnkFwd) C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
|||||| "NPPTNT2" (NPPTNT2) "INCA Internet Co., Ltd." C:\Windows\system32\npptNT2.sys File exists
"PCD52X2" (PCD52X2) C:\Users\Nico\AppData\Local\Temp\PCD52X2.sys File not found
"PCD52X3" (PCD52X3) C:\Users\Nico\AppData\Local\Temp\PCD52X3.sys File not found
"PCD61X2" (PCD61X2) C:\Users\Nico\AppData\Local\Temp\PCD61X2.sys File not found
"PCD61X3" (PCD61X3) C:\Users\Nico\AppData\Local\Temp\PCD61X3.sys File not found
"SSHDRV51" (SSHDRV51) C:\Windows\system32\drivers\SSHDRV51.sys File found, but it contains no detailed information
|||||| "SSHDRV52" (SSHDRV52) C:\Windows\system32\drivers\SSHDRV52.sys File found, but it contains no detailed information
|||||| "SSHDRV61" (SSHDRV61) C:\Windows\system32\drivers\SSHDRV61.sys File found, but it contains no detailed information
|||||| "SSHDRV76" (SSHDRV76) C:\Windows\system32\drivers\SSHDRV76.sys File exists
|||||| "ssmdrv" (ssmdrv) "Avira GmbH" C:\Windows\System32\DRIVERS\ssmdrv.sys File exists
|||||| "StarForce Protection Environment Driver v6" (prodrv06) "Protection Technology" C:\Windows\System32\drivers\prodrv06.sys File exists
|||||| "StarForce Protection Helper Driver" (sfhlp01) "Protection Technology" C:\Windows\System32\drivers\sfhlp01.sys File exists
|||||| "StarForce Protection Helper Driver v2" (prohlp02) "Protection Technology" C:\Windows\System32\drivers\prohlp02.sys File exists
|||||| "StarForce Protection Synchronization Driver v1" (prosync1) "Protection Technology" C:\Windows\System32\drivers\prosync1.sys File exists
|||||| "StarOpen" (StarOpen) C:\Windows\system32\drivers\StarOpen.sys File found, but it contains no detailed information
|||||| "TIEHDUSB" (TIEHDUSB) "Texas Instruments Incorporated" C:\Windows\System32\drivers\tiehdusb.sys File exists
Explorer
HKLM\Software\Classes\Folder\shellex\ColumnHandlers
|||||| {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" "Adobe Systems, Inc." C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll File exists
|||||| {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists
HKLM\Software\Classes\Protocols\Handler
|||||| {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" "Skype Technologies" C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" File not found | COM-object registry key not found
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" File not found | COM-object registry key not found
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" File not found | COM-object registry key not found
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" File not found | COM-object registry key not found
|||||| {872A9397-E0D6-4e28-B64D-52B8D0A7EA35} "DisplayCplExt Class" "Advanced Micro Devices, Inc." C:\Program Files\ATI\ATI.ACE\Core-Static\atiamaxx.dll File exists
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" File not found | COM-object registry key not found
|||||| {3FCEF010-09A4-11D4-8D3B-D12F9D3D8B02} "FileTimeShlExt Class" "Texas Instruments Incorporated" C:\PROGRA~2\COMMON~1\TISHAR~1\TICONN~1\TIShlExt.dll File exists
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" File not found | COM-object registry key not found
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" F:\Programme\iTunes\iTunesMiniPlayer.dll File not found
{00020d75-0000-0000-c000-000000000046} "lnkfile" File not found | COM-object registry key not found
|||||| {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" "Microsoft Corporation" G:\PROGRA~1\MICROS~2\OFFICE11\msohev.dll File exists
|||||| {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" "Microsoft Corporation" C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\msoshext.dll File exists
|||||| {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" "Microsoft Corporation" C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\msoshext.dll File exists
|||||| {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists
|||||| {087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists
|||||| {63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists
|||||| {3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" File not found | COM-object registry key not found
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" File not found | COM-object registry key not found
|||||| {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\shlext.dll File exists
|||||| {5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" "Advanced Micro Devices, Inc." C:\Program Files\ATI\ATI.ACE\Core-Static\atiacmxx.dll File exists
|||||| {B7056B8E-4F99-44f8-8CBD-282390FE5428} "VirtualCloneDrive Shell Extension" "Elaborate Bytes AG" C:\Program Files\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll File exists
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" File not found | COM-object registry key not found
|||||| {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" C:\Program Files\WinRAR\rarext.dll File exists
Internet Explorer
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars
|||| {555D4D79-4BD2-4094-A395-CFC534424A05} "HP Smart Web Printing" "Hewlett-Packard Co." C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll File exists
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
"ITBar7Layout" File not found | COM-object registry key not found
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units
|||| {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_20"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2iexp.dll File exists
|||| {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2iexp.dll File exists
|||| {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\npjpi160_20.dll File exists
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars
|||| {555D4D79-4BD2-4094-A395-CFC534424A05} "HP Smart Web Printing" "Hewlett-Packard Co." C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll File exists
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
|||| {DDE87865-83C5-48c4-8357-2F5B1AA84522} "HP Smart Web Printing ein- oder ausblenden" "Hewlett-Packard Co." C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll File exists
"ICQ6" F:\Program Files\ICQ6.5\ICQ.exe File not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
|||||| {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" "Adobe Systems Incorporated" C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll File exists
|||| {0347C33E-8762-4905-BF09-768834316C61} "HP Print Enhancer" "Hewlett-Packard Co." C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll File exists
|||| {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} "HP Smart BHO Class" "Hewlett-Packard Co." C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll File exists
|||| {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2ssv.dll File exists
Logon
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
|||||| "desktop.ini" C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini File exists
|||| "OpenOffice.org 3.1.lnk" C:\Program Files\OpenOffice.org 3\program\quickstart.exe Shortcut exists | File found, but it contains no detailed information | File exists
"Product Registration.lnk" C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk Shortcut exists | File not found
%AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup
|||||| "desktop.ini" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini File exists
|||| "HP Digital Imaging Monitor.lnk" "Hewlett-Packard Co." C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe Shortcut exists | File exists
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"iTap" C:\Program Files\HLW\iTap\iTap.exe File not found
"RGSC" F:\Programme\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent File not found
"Steam" "f:\programme\steam\steam.exe" -silent File not found
HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd
"StartupPrograms" rdpclip File not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
|||| "Adobe ARM" "Adobe Systems Incorporated" "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" File exists
|||| "Adobe Reader Speed Launcher" "Adobe Systems Incorporated" "G:\Programme\Adobe Reader\Reader\Reader_sl.exe" File exists
|||||| "avgnt" "Avira GmbH" "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min File exists
|||| "HP Software Update" "Hewlett-Packard" C:\Program Files\HP\HP Software Update\HPWuSchd2.exe File exists
"iTunesHelper" "F:\Programme\iTunes\iTunesHelper.exe" File not found
|||||| "JMB36X IDE Setup" C:\Windows\RaidTool\xInsIDE.exe File found, but it contains no detailed information
"LogMeIn Hamachi Ui" "F:\Programme\Hamachi\hamachi-2-ui.exe" --auto-start File not found
|||| "NeroFilterCheck" "Ahead Software Gmbh" C:\Windows\system32\NeroCheck.exe File exists
|||| "StartCCC" "Advanced Micro Devices, Inc." "C:\Program Files\ATI\ATI.ACE\Core-Static\CLIStart.exe" MSRun File exists
|||| "SunJavaUpdateSched" "Sun Microsystems, Inc." "C:\Program Files\Common Files\Java\Java Update\jusched.exe" File exists
|||| "VirtualCloneDrive" "Elaborate Bytes AG" "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s File exists
Print Monitors
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
|||||| "PCL Language Monitor" "Hewlett-Packard Company" C:\Windows\system32\hpz3l692.dll File exists
Services
HKLM\SYSTEM\CurrentControlSet\Services
|||||| "Apple Mobile Device" (Apple Mobile Device) "Apple Inc." C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe File exists
|||||| "Avira AntiVir Guard" (AntiVirService) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\avguard.exe File exists
|||||| "Avira AntiVir Planer" (AntiVirSchedulerService) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\sched.exe File exists
|||||| "Bonjour-Dienst" (Bonjour Service) "Apple Inc." C:\Program Files\Bonjour\mDNSResponder.exe File exists
|||||| "HP CUE DeviceDiscovery Service" (hpqddsvc) "Hewlett-Packard Co." C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll File exists
|||||| "hpqcxs08" (hpqcxs08) "Hewlett-Packard Co." C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll File exists
|||||| "iPod-Dienst" (iPod Service) "Apple Inc." C:\Program Files\iPod\bin\iPodService.exe File exists
"LogMeIn Hamachi 2.0 Tunneling Engine" (Hamachi2Svc) F:\Programme\Hamachi\hamachi-2.exe -s File not found
|||||| "Net Driver HPZ12" (Net Driver HPZ12) "Hewlett-Packard" C:\Windows\system32\HPZinw12.dll File exists
|||| "nProtect GameGuard Service" (npggsvc) "INCA Internet Co., Ltd." C:\Windows\system32\GameMon.des File exists
|||||| "Office Source Engine" (ose) "Microsoft Corporation" C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE File exists
|||||| "Pml Driver HPZ12" (Pml Driver HPZ12) "Hewlett-Packard" C:\Windows\system32\HPZipm12.dll File exists
|||||| "PnkBstrA" (PnkBstrA) C:\Windows\system32\PnkBstrA.exe File found, but it contains no detailed information
"PnkBstrB" (PnkBstrB) C:\Windows\system32\PnkBstrB.exe File found, but it contains no detailed information
|||||| "Steam Client Service" (Steam Client Service) "Valve Corporation" C:\Program Files\Common Files\Steam\SteamService.exe File exists
Winsock Providers
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries
|||||| "mdnsNSP" "Apple Inc." C:\Program Files\Bonjour\mdnsNSP.dll File exists

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

Darkfilter 30.05.2010 16:42

hi, habe die nächsten logs gepostet warte auf Antwort!
Gruß Nico

cosinus 30.05.2010 16:54

Hab Deinen Strang übersehen. Das osam Logfile sieht unauffällig aus, ich würde jetzt mal CF vorschlagen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Darkfilter 30.05.2010 21:52

Hier das Logfile von ComboFix

Combofix Logfile:
Code:

ComboFix 10-05-29.05 - Nico 30.05.2010  22:38:12.1.4 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3070.2000 [GMT 2:00]
ausgeführt von:: c:\users\Nico\Desktop\cofi.exe.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.

G:\install.exe

.
(((((((((((((((((((((((  Dateien erstellt von 2010-04-28 bis 2010-05-30  ))))))))))))))))))))))))))))))
.

2010-05-30 20:45 . 2010-05-30 20:46        --------        d-----w-        c:\users\Nico\AppData\Local\temp
2010-05-30 20:45 . 2010-05-30 20:45        --------        d-----w-        c:\users\Mama\AppData\Local\temp
2010-05-30 20:45 . 2010-05-30 20:45        --------        d-----w-        c:\users\Default\AppData\Local\temp
2010-05-29 20:36 . 2010-05-29 20:36        --------        d-----w-        c:\users\Nico\AppData\Roaming\HPAppData
2010-05-26 10:12 . 2010-04-23 14:13        2048        ----a-w-        c:\windows\system32\tzres.dll
2010-05-25 16:33 . 2010-05-25 16:33        --------        d-----w-        c:\users\Nico\AppData\Roaming\Malwarebytes
2010-05-25 16:33 . 2010-04-29 10:19        38224        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-25 16:33 . 2010-05-25 16:33        --------        d-----w-        c:\programdata\Malwarebytes
2010-05-25 16:33 . 2010-04-29 10:19        20952        ----a-w-        c:\windows\system32\drivers\mbam.sys
2010-05-23 21:25 . 2010-05-23 21:25        --------        d-----w-        c:\program files\Common Files\Java
2010-05-23 21:24 . 2010-04-12 15:29        411368        ----a-w-        c:\windows\system32\deployJava1.dll
2010-05-17 19:46 . 2010-05-17 19:46        --------        d-----w-        c:\users\Nico\AppData\Local\My Games
2010-05-17 19:40 . 2010-05-17 19:40        --------        d-----w-        c:\program files\2K Games
2010-05-16 14:08 . 2010-05-16 14:17        --------        d-----w-        C:\Die Sims 2
2010-05-16 14:03 . 2010-05-16 14:03        --------        d-----w-        c:\users\Nico\AppData\Local\World in Conflict
2010-05-16 13:48 . 2010-05-16 14:03        --------        d-----w-        c:\program files\Sierra Games
2010-05-15 18:57 . 2010-05-15 18:57        138056        ----a-w-        c:\users\Nico\AppData\Roaming\PnkBstrK.sys
2010-05-15 18:57 . 2010-05-15 18:57        2434856        ----a-w-        c:\windows\system32\pbsvc_bc2.exe
2010-05-15 18:43 . 2010-05-15 18:43        --------        d-----w-        c:\program files\Electronic Arts
2010-05-15 18:43 . 2009-09-04 15:44        515416        ----a-w-        c:\windows\system32\XAudio2_5.dll
2010-05-15 18:43 . 2009-09-04 15:44        238936        ----a-w-        c:\windows\system32\xactengine3_5.dll
2010-05-15 18:43 . 2009-09-04 15:29        1974616        ----a-w-        c:\windows\system32\D3DCompiler_42.dll
2010-05-15 18:43 . 2009-09-04 15:29        453456        ----a-w-        c:\windows\system32\d3dx10_42.dll
2010-05-15 18:43 . 2009-09-04 15:29        235344        ----a-w-        c:\windows\system32\d3dx11_42.dll
2010-05-15 18:43 . 2009-09-04 15:29        5501792        ----a-w-        c:\windows\system32\d3dcsx_42.dll
2010-05-15 18:43 . 2009-09-04 15:29        1892184        ----a-w-        c:\windows\system32\D3DX9_42.dll
2010-05-15 18:43 . 2009-09-04 15:44        69464        ----a-w-        c:\windows\system32\XAPOFX1_3.dll
2010-05-15 18:42 . 2008-10-27 08:04        514384        ----a-w-        c:\windows\system32\XAudio2_3.dll
2010-05-15 18:42 . 2008-10-27 08:04        235856        ----a-w-        c:\windows\system32\xactengine3_3.dll
2010-05-15 18:42 . 2008-10-27 08:04        23376        ----a-w-        c:\windows\system32\X3DAudio1_5.dll
2010-05-15 18:42 . 2008-10-27 08:04        70992        ----a-w-        c:\windows\system32\XAPOFX1_2.dll
2010-05-15 16:34 . 2010-05-15 16:34        --------        d-----w-        c:\users\Mama\AppData\Roaming\HPAppData
2010-05-13 11:51 . 2010-05-13 11:51        --------        d-----w-        c:\users\Nico\AppData\Roaming\Atari
2010-05-13 11:50 . 2010-05-28 20:06        --------        d-----w-        c:\users\Nico\AppData\Roaming\vlc
2010-05-13 11:41 . 2010-05-13 11:41        --------        d-----w-        c:\users\Nico\AppData\Roaming\Leadertech
2010-05-12 19:25 . 2010-01-29 15:40        738816        ----a-w-        c:\windows\system32\inetcomm.dll
2010-05-11 18:37 . 2010-05-11 18:37        41872        ----a-w-        c:\windows\system32\xfcodec.dll
2010-05-03 11:28 . 2010-05-03 11:28        --------        d-----w-        C:\Phenomedia AG

.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-30 20:15 . 2009-05-28 19:25        1        ----a-w-        c:\users\Nico\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-30 20:15 . 2009-04-29 18:02        --------        d-----w-        c:\users\Nico\AppData\Roaming\Xfire
2010-05-30 20:07 . 2009-11-15 16:53        --------        d-----w-        c:\users\Nico\AppData\Roaming\Skype
2010-05-30 19:21 . 2009-06-12 16:38        137464        ----a-w-        c:\windows\system32\drivers\PnkBstrK.sys
2010-05-30 19:21 . 2009-06-12 16:38        214520        ----a-w-        c:\windows\system32\PnkBstrB.exe
2010-05-30 16:52 . 2009-11-15 16:55        --------        d-----w-        c:\users\Nico\AppData\Roaming\skypePM
2010-05-30 15:35 . 2008-01-21 07:15        618204        ----a-w-        c:\windows\system32\perfh007.dat
2010-05-30 15:35 . 2008-01-21 07:15        122636        ----a-w-        c:\windows\system32\perfc007.dat
2010-05-30 15:29 . 2009-04-29 18:02        --------        d-----w-        c:\programdata\Xfire
2010-05-29 21:47 . 2009-03-01 15:56        --------        d---a-w-        c:\program files\WoW
2010-05-23 21:24 . 2009-05-09 18:29        --------        d-----w-        c:\program files\Java
2010-05-17 19:42 . 2009-04-29 17:34        --------        d--h--w-        c:\program files\InstallShield Installation Information
2010-05-16 14:22 . 2009-08-02 10:40        --------        d-----w-        c:\program files\EA GAMES
2010-05-16 13:56 . 2009-05-18 13:16        --------        d-----w-        c:\programdata\Media Center Programs
2010-05-15 18:57 . 2009-06-05 12:50        75064        ----a-w-        c:\windows\system32\PnkBstrA.exe
2010-05-15 16:43 . 2009-08-25 07:32        1        ----a-w-        c:\users\Mama\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-12 19:49 . 2006-11-02 11:18        --------        d-----w-        c:\program files\Windows Mail
2010-05-12 09:21 . 2009-10-02 16:32        221568        ------w-        c:\windows\system32\MpSigStub.exe
2010-05-08 15:44 . 2009-08-28 15:36        --------        d-----w-        c:\users\Nico\AppData\Roaming\HpUpdate
2010-05-06 18:43 . 2009-04-29 17:52        --------        d-----w-        c:\users\Nico\AppData\Roaming\teamspeak2
2010-05-05 20:31 . 2009-12-24 01:13        9        ----a-w-        c:\windows\pbase.dat
2010-05-05 20:31 . 2009-12-24 01:13        8        ----a-w-        c:\windows\npbase.dat
2010-05-05 20:31 . 2009-12-24 01:13        3        ----a-w-        c:\windows\ver.dat
2010-04-29 18:34 . 2009-04-29 17:13        --------        d-----w-        c:\program files\ATI
2010-04-28 20:44 . 2010-04-28 20:44        --------        d-----w-        c:\programdata\ATI
2010-04-28 20:24 . 2010-02-11 21:37        680        ----a-w-        c:\users\Nico\AppData\Local\d3d9caps.dat
2010-04-27 14:01 . 2010-02-24 14:48        --------        d-----w-        c:\program files\MSECache
2010-04-25 11:36 . 2010-04-25 11:36        3584        ----a-r-        c:\users\Nico\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-04-25 11:36 . 2010-04-25 11:36        --------        d-----w-        c:\program files\Windows Installer Clean Up
2010-04-25 10:54 . 2009-07-17 12:05        --------        d-----w-        c:\program files\Common Files\Adobe
2010-04-24 16:24 . 2010-04-24 16:20        --------        d-----w-        c:\users\Nico\AppData\Roaming\Sony
2010-04-24 16:23 . 2010-04-24 16:23        --------        d-----w-        c:\program files\Common Files\Sony Shared
2010-04-24 16:22 . 2010-04-24 16:22        10134        ----a-r-        c:\users\Nico\AppData\Roaming\Microsoft\Installer\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}\ARPPRODUCTICON.exe
2010-04-24 16:22 . 2010-04-24 16:22        --------        d-----w-        c:\program files\Sony
2010-04-24 16:22 . 2010-04-24 16:22        --------        d-----w-        c:\programdata\Sony Corporation
2010-04-23 21:14 . 2010-04-23 21:14        --------        d-----w-        c:\users\Nico\AppData\Roaming\Avira
2010-04-23 21:13 . 2010-04-23 21:13        --------        d-----w-        c:\programdata\Avira
2010-04-23 21:07 . 2009-04-29 19:44        --------        d-----w-        c:\program files\Bonjour
2010-04-23 20:58 . 2009-08-22 17:19        --------        d-----w-        c:\program files\Common Files\DVDVideoSoft
2010-04-23 20:52 . 2009-05-09 09:51        --------        d-----w-        c:\program files\Common Files\Wise Installation Wizard
2010-04-20 18:25 . 2010-04-20 18:25        --------        d-----w-        c:\program files\Common Files\Skype
2010-04-16 14:29 . 2009-05-22 16:24        196608        ----a-w-        c:\users\Nico\AppData\Roaming\Acreon\WowMatrix\Libraries\wmweb.dll
2010-04-16 14:29 . 2009-05-22 16:24        258048        ----a-w-        c:\users\Nico\AppData\Roaming\Acreon\WowMatrix\Libraries\wmzip.dll
2010-04-07 02:43 . 2010-04-07 02:43        5430272        ----a-w-        c:\windows\system32\drivers\atikmdag.sys
2010-04-07 02:16 . 2010-04-07 02:16        143360        ----a-w-        c:\windows\system32\atiapfxx.exe
2010-04-07 02:16 . 2010-04-07 02:16        489472        ----a-w-        c:\windows\system32\aticfx32.dll
2010-04-07 02:13 . 2010-04-07 02:13        446464        ----a-w-        c:\windows\system32\ATIDEMGX.dll
2010-04-07 02:12 . 2010-04-07 02:12        372736        ----a-w-        c:\windows\system32\atieclxx.exe
2010-04-07 02:12 . 2010-04-07 02:12        14321664        ----a-w-        c:\windows\system32\atioglxx.dll
2010-04-07 02:12 . 2010-04-07 02:12        172032        ----a-w-        c:\windows\system32\atiesrxx.exe
2010-04-07 02:10 . 2010-04-07 02:10        159744        ----a-w-        c:\windows\system32\atitmmxx.dll
2010-04-07 02:10 . 2010-04-07 02:10        356352        ----a-w-        c:\windows\system32\atipdlxx.dll
2010-04-07 02:10 . 2010-04-07 02:10        278528        ----a-w-        c:\windows\system32\Oemdspif.dll
2010-04-07 02:10 . 2010-04-07 02:10        11776        ----a-w-        c:\windows\system32\atimuixx.dll
2010-04-07 02:10 . 2010-04-07 02:10        43520        ----a-w-        c:\windows\system32\ati2edxx.dll
2010-04-07 02:06 . 2010-04-07 02:06        3164160        ----a-w-        c:\windows\system32\atidxx32.dll
2010-04-07 01:46 . 2010-04-07 01:46        50176        ----a-w-        c:\windows\system32\coinst.dll
2010-04-07 01:40 . 2010-04-07 01:40        3707904        ----a-w-        c:\windows\system32\atiumdag.dll
2010-04-07 01:40 . 2010-04-07 01:40        53248        ----a-w-        c:\windows\system32\aticalrt.dll
2010-04-07 01:40 . 2010-04-07 01:40        53248        ----a-w-        c:\windows\system32\aticalcl.dll
2010-04-07 01:38 . 2010-04-07 01:38        4018176        ----a-w-        c:\windows\system32\aticaldd.dll
2010-04-07 01:23 . 2010-04-07 01:23        237568        ----a-w-        c:\windows\system32\atiadlxx.dll
2010-04-07 01:23 . 2010-04-07 01:23        12800        ----a-w-        c:\windows\system32\atiglpxx.dll
2010-04-07 01:23 . 2010-04-07 01:23        14848        ----a-w-        c:\windows\system32\atigktxx.dll
2010-04-07 01:23 . 2010-04-07 01:23        157184        ----a-w-        c:\windows\system32\drivers\atikmpag.sys
2010-04-07 01:22 . 2010-04-07 01:22        28160        ----a-w-        c:\windows\system32\atiuxpag.dll
2010-04-07 01:22 . 2010-04-07 01:22        20480        ----a-w-        c:\windows\system32\atiu9pag.dll
2010-04-07 01:22 . 2010-04-07 01:22        23040        ----a-w-        c:\windows\system32\atitmpxx.dll
2010-04-07 01:22 . 2010-04-07 01:22        53248        ----a-w-        c:\windows\system32\drivers\ati2erec.dll
2010-04-07 01:21 . 2010-04-07 01:21        2983936        ----a-w-        c:\windows\system32\atiumdva.dll
2010-04-07 01:08 . 2010-04-07 01:08        52224        ----a-w-        c:\windows\system32\atimpc32.dll
2010-04-07 01:08 . 2010-04-07 01:08        52224        ----a-w-        c:\windows\system32\amdpcom32.dll
2010-04-02 16:09 . 2010-04-02 16:09        2023        ----a-w-        c:\windows\system32\atipblag.dat
2010-03-22 10:25 . 2009-05-03 17:02        61736        ----a-w-        c:\users\Mama\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-17 15:06 . 2010-03-17 15:06        202234        ----a-w-        c:\windows\system32\atiicdxx.dat
2010-03-09 10:20 . 2010-03-09 10:20        104464        ----a-w-        c:\windows\system32\drivers\AtiHdmi.sys
2010-03-05 14:01 . 2010-04-16 13:17        420352        ----a-w-        c:\windows\system32\vbscript.dll
.

((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-25 49152]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-01-29 52392]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="g:\programme\Adobe Reader\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"StartCCC"="c:\program files\ATI\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-06 102400]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

c:\users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]

c:\users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08        417792        ----a-w-        c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):cc,27,92,6f,61,40,ca,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-442773238-3665067095-4225304131-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001

R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;f:\programme\Hamachi\hamachi-2.exe [x]
R3 cdrmkaun;cdrmkaun;c:\users\Nico\AppData\Local\Temp\cdrmkaun.sys [x]
R3 DBKDRVR54;DBKDRVR54;f:\program files\Cheat Engine\dbk32.sys [x]
R3 dump_wmimmc;dump_wmimmc;f:\programme\Cossfire\CrossFire\GameGuard\dump_wmimmc.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-05-06 2785582]
R3 PCD52X2;PCD52X2;c:\users\Nico\AppData\Local\Temp\PCD52X2.sys [x]
R3 PCD52X3;PCD52X3;c:\users\Nico\AppData\Local\Temp\PCD52X3.sys [x]
R3 PCD61X2;PCD61X2;c:\users\Nico\AppData\Local\Temp\PCD61X2.sys [x]
R3 PCD61X3;PCD61X3;c:\users\Nico\AppData\Local\Temp\PCD61X3.sys [x]
S1 SSHDRV51;SSHDRV51;c:\windows\system32\drivers\SSHDRV51.sys [2009-09-06 21504]
S1 SSHDRV52;SSHDRV52;c:\windows\system32\drivers\SSHDRV52.sys [2009-09-06 29184]
S1 SSHDRV76;SSHDRV76;c:\windows\system32\drivers\SSHDRV76.sys [2009-09-07 53760]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-04-07 172032]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-04-07 5430272]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-04-07 157184]


--- Andere Dienste/Treiber im Speicher ---

*Deregistered* - avgntflt

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners

2010-05-30 c:\windows\Tasks\User_Feed_Synchronization-{8D9D19FD-3BB5-49B2-A216-4F4719AB1F71}.job
- c:\windows\system32\msfeedssync.exe [2010-03-30 04:54]

2010-05-26 c:\windows\Tasks\WebReg HP Photosmart C5300 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2008-03-25 18:42]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -

HKCU-Run-RGSC - f:\programme\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
HKCU-Run-Steam - f:\programme\steam\steam.exe
HKLM-Run-hpqSRMon - (no file)
HKLM-Run-iTunesHelper - f:\programme\iTunes\iTunesHelper.exe
HKLM-Run-LogMeIn Hamachi Ui - f:\programme\Hamachi\hamachi-2-ui.exe
MSConfigStartUp-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
MSConfigStartUp-iTunesHelper - f:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
AddRemove-Cheat Engine 5.4_is1 - f:\programme\Cheat Engine\unins000.exe
AddRemove-Company of Heroes - f:\programme\THQ\Company of Heroes\Uninstall_German.exe
AddRemove-Free Video to iPod Converter_is1 - f:\programme\Free Video to iPod Converter\unins000.exe
AddRemove-ImgBurn - f:\programme\ImgBurn\uninstall.exe
AddRemove-Metin2_is1 - f:\programme\Metin2\unins000.exe
AddRemove-Mozilla Firefox (3.5.9) - f:\programme\Mozilla Firefox\uninstall\helper.exe
AddRemove-Nero - Burning Rom!UninstallKey - f:\programme\Ahead\Nero\nero\uninstall\UNNERO.exe
AddRemove-Steam App 240 - f:\program files\Steam\steam.exe
AddRemove-Teamspeak 2 RC2_is1 - f:\program files\Teamspeak2_RC2\unins000.exe
AddRemove-{B7050CBDB2504B34BC2A9CA0A692CC29} - f:\programme\DivX\DivXWebPlayerUninstall.exe
AddRemove-TeamSpeak 3 Client - f:\programme\Teamspeak3\uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2010-05-30 22:46
Windows 6.0.6002 Service Pack 2 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostarteinträge...

Scanne versteckte Dateien...


c:\users\Nico\AppData\Local\Temp\catchme.dll 53248 bytes executable

Scan erfolgreich abgeschlossen
versteckte Dateien: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------

[HKEY_USERS\S-1-5-21-442773238-3665067095-4225304131-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:69,70,b8,17,8f,94,fb,03,84,08,d1,71,6e,d1,51,c0,9c,7e,64,7f,cc,c7,f0,
  58,84,cd,0f,87,94,bb,a2,c7,51,98,d5,56,d7,c3,d5,68,96,95,35,88,b5,ec,bd,85,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d

[HKEY_USERS\S-1-5-21-442773238-3665067095-4225304131-1000\Software\SecuROM\License information*]
"datasecu"=hex:36,58,8f,04,77,95,da,de,48,ea,04,ee,f5,23,45,55,8b,21,d1,12,53,
  a6,3f,58,55,3a,ad,da,bc,54,5a,fb,4b,e7,bd,b1,4e,d2,5a,76,05,6a,af,72,4d,12,\
"rkeysecu"=hex:5a,b9,86,93,7b,45,50,27,2f,20,20,d5,0b,14,e6,dd
.
Zeit der Fertigstellung: 2010-05-30  22:47:56
ComboFix-quarantined-files.txt  2010-05-30 20:47

Vor Suchlauf: 12 Verzeichnis(se), 487.017.054.208 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 487.149.494.272 Bytes frei

- - End Of File - - 68BD7E59EA53BE5C6EC3CAA9B834D4FD

--- --- ---

cosinus 31.05.2010 08:50

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

Darkfilter 31.05.2010 23:44

Erst einmal das Logfile von SUPERAntiSpyware
nächstes folgt heute oder morgen


SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 06/01/2010 at 00:33 AM

Application Version : 4.38.1004

Core Rules Database Version : 5011
Trace Rules Database Version: 2823

Scan type : Complete Scan
Total Scan Time : 04:15:43

Memory items scanned : 781
Memory threats detected : 0
Registry items scanned : 6425
Registry threats detected : 121
File items scanned : 397517
File threats detected : 34

Keylogger.Actual Spy
HKLM\Software\ACSPMonitor
HKLM\Software\ACSPMonitor\Application
HKLM\Software\ACSPMonitor\Application#enabled
HKLM\Software\ACSPMonitor\Application#path
HKLM\Software\ACSPMonitor\Application#start
HKLM\Software\ACSPMonitor\Application#stop
HKLM\Software\ACSPMonitor\Clipboard
HKLM\Software\ACSPMonitor\Clipboard#enabled
HKLM\Software\ACSPMonitor\Clipboard#isborder
HKLM\Software\ACSPMonitor\Clipboard#numborder
HKLM\Software\ACSPMonitor\Clipboard#razmborder
HKLM\Software\ACSPMonitor\Clipboard#notspy
HKLM\Software\ACSPMonitor\Clipboard#path
HKLM\Software\ACSPMonitor\Computer
HKLM\Software\ACSPMonitor\Computer#enabled
HKLM\Software\ACSPMonitor\Computer#path
HKLM\Software\ACSPMonitor\Email
HKLM\Software\ACSPMonitor\Email#enabled
HKLM\Software\ACSPMonitor\Email#address
HKLM\Software\ACSPMonitor\Email#subject
HKLM\Software\ACSPMonitor\Email#fromaddress
HKLM\Software\ACSPMonitor\Email#smtpserver
HKLM\Software\ACSPMonitor\Email#username
HKLM\Software\ACSPMonitor\Email#port
HKLM\Software\ACSPMonitor\Email#smtpdefault
HKLM\Software\ACSPMonitor\Email#sendkey
HKLM\Software\ACSPMonitor\Email#sendscr
HKLM\Software\ACSPMonitor\Email#sendapp
HKLM\Software\ACSPMonitor\Email#sendclipb
HKLM\Software\ACSPMonitor\Email#sendprnt
HKLM\Software\ACSPMonitor\Email#sendcomputer
HKLM\Software\ACSPMonitor\Email#sendfiledir
HKLM\Software\ACSPMonitor\Email#sendinetcon
HKLM\Software\ACSPMonitor\Email#sendurl
HKLM\Software\ACSPMonitor\Email#delalllogs
HKLM\Software\ACSPMonitor\Email#sendtimeinterval
HKLM\Software\ACSPMonitor\Email#timeinterval
HKLM\Software\ACSPMonitor\Email#timeminutes
HKLM\Software\ACSPMonitor\Email#sizelogs
HKLM\Software\ACSPMonitor\Email#mode
HKLM\Software\ACSPMonitor\Email#code
HKLM\Software\ACSPMonitor\Email#sendtimemoment
HKLM\Software\ACSPMonitor\Email#timesend
HKLM\Software\ACSPMonitor\Email#authentication
HKLM\Software\ACSPMonitor\Email#password
HKLM\Software\ACSPMonitor\Filedir
HKLM\Software\ACSPMonitor\Filedir#enabled
HKLM\Software\ACSPMonitor\Filedir#filecreate
HKLM\Software\ACSPMonitor\Filedir#filedelete
HKLM\Software\ACSPMonitor\Filedir#filerename
HKLM\Software\ACSPMonitor\Filedir#spyfiles
HKLM\Software\ACSPMonitor\Filedir#filesystem
HKLM\Software\ACSPMonitor\Filedir#dirpath
HKLM\Software\ACSPMonitor\Filedir#subdir
HKLM\Software\ACSPMonitor\Filedir#path
HKLM\Software\ACSPMonitor\FTP
HKLM\Software\ACSPMonitor\FTP#enabled
HKLM\Software\ACSPMonitor\FTP#host
HKLM\Software\ACSPMonitor\FTP#username
HKLM\Software\ACSPMonitor\FTP#password
HKLM\Software\ACSPMonitor\FTP#port
HKLM\Software\ACSPMonitor\Inetcon
HKLM\Software\ACSPMonitor\Inetcon#enabled
HKLM\Software\ACSPMonitor\Inetcon#path
HKLM\Software\ACSPMonitor\Keylogger
HKLM\Software\ACSPMonitor\Keylogger#enabled
HKLM\Software\ACSPMonitor\Keylogger#spy_only_char
HKLM\Software\ACSPMonitor\Keylogger#show_only_char
HKLM\Software\ACSPMonitor\Keylogger#path
HKLM\Software\ACSPMonitor\LAN
HKLM\Software\ACSPMonitor\LAN#enabled
HKLM\Software\ACSPMonitor\LAN#path
HKLM\Software\ACSPMonitor\Main
HKLM\Software\ACSPMonitor\Main#spy
HKLM\Software\ACSPMonitor\Main#hotkey
HKLM\Software\ACSPMonitor\Main#path_log
HKLM\Software\ACSPMonitor\Main#encrypt
HKLM\Software\ACSPMonitor\Main#search_case
HKLM\Software\ACSPMonitor\Main#pass
HKLM\Software\ACSPMonitor\Main#pass_txt
HKLM\Software\ACSPMonitor\Main#run_word
HKLM\Software\ACSPMonitor\Main#max_text
HKLM\Software\ACSPMonitor\Main#max_scr
HKLM\Software\ACSPMonitor\Main#clear
HKLM\Software\ACSPMonitor\Main#start_on_startup
HKLM\Software\ACSPMonitor\Main#spy_on_start
HKLM\Software\ACSPMonitor\Main#hide_on_startup
HKLM\Software\ACSPMonitor\Main#hide_desktop
HKLM\Software\ACSPMonitor\Main#hide_start
HKLM\Software\ACSPMonitor\Main#hide_uninstall
HKLM\Software\ACSPMonitor\Main#hide_folder
HKLM\Software\ACSPMonitor\Main#remind
HKLM\Software\ACSPMonitor\Main#shutdown
HKLM\Software\ACSPMonitor\Main#path_app2
HKLM\Software\ACSPMonitor\Printer
HKLM\Software\ACSPMonitor\Printer#enabled
HKLM\Software\ACSPMonitor\Printer#path
HKLM\Software\ACSPMonitor\Report
HKLM\Software\ACSPMonitor\Report#mode
HKLM\Software\ACSPMonitor\Report#logs
HKLM\Software\ACSPMonitor\Report#onepage
HKLM\Software\ACSPMonitor\Report#reccount
HKLM\Software\ACSPMonitor\Screenshot
HKLM\Software\ACSPMonitor\Screenshot#enabled
HKLM\Software\ACSPMonitor\Screenshot#active_window
HKLM\Software\ACSPMonitor\Screenshot#cursor
HKLM\Software\ACSPMonitor\Screenshot#quality
HKLM\Software\ACSPMonitor\Screenshot#interval
HKLM\Software\ACSPMonitor\Screenshot#timeminutes
HKLM\Software\ACSPMonitor\Screenshot#idle
HKLM\Software\ACSPMonitor\Screenshot#idle_time
HKLM\Software\ACSPMonitor\Screenshot#path
HKLM\Software\ACSPMonitor\Screenshot#path_pic
HKLM\Software\ACSPMonitor\Test
HKLM\Software\ACSPMonitor\Url
HKLM\Software\ACSPMonitor\Url#enabled
HKLM\Software\ACSPMonitor\Url#http
HKLM\Software\ACSPMonitor\Url#https
HKLM\Software\ACSPMonitor\Url#ftp
HKLM\Software\ACSPMonitor\Url#other
HKLM\Software\ACSPMonitor\Url#path
C:\Windows\system\actualspystart.lnk
C:\Program Files\ACSPMonitor\ActualSpy.chm
C:\Program Files\ACSPMonitor\ASMonitor.exe
C:\Program Files\ACSPMonitor\asmonitor.exe.manifest
C:\Program Files\ACSPMonitor\f.bat
C:\Program Files\ACSPMonitor\FILE_ID.DIZ
C:\Program Files\ACSPMonitor\hk.dll
C:\Program Files\ACSPMonitor\hprog.dll
C:\Program Files\ACSPMonitor\libeay32.dll
C:\Program Files\ACSPMonitor\license.txt
C:\Program Files\ACSPMonitor\logs\app.dat
C:\Program Files\ACSPMonitor\logs\clipboard.dat
C:\Program Files\ACSPMonitor\logs\computer.dat
C:\Program Files\ACSPMonitor\logs\filedir.dat
C:\Program Files\ACSPMonitor\logs\inetcon.dat
C:\Program Files\ACSPMonitor\logs\key.dat
C:\Program Files\ACSPMonitor\logs\pic
C:\Program Files\ACSPMonitor\logs\prnt.dat
C:\Program Files\ACSPMonitor\logs\screenshots.dat
C:\Program Files\ACSPMonitor\logs\url.dat
C:\Program Files\ACSPMonitor\logs
C:\Program Files\ACSPMonitor\readme.txt
C:\Program Files\ACSPMonitor\rights.bat
C:\Program Files\ACSPMonitor\ssleay32.dll
C:\Program Files\ACSPMonitor\unins000.dat
C:\Program Files\ACSPMonitor\unins000.exe
C:\Program Files\ACSPMonitor
C:\DOKUMENTE UND EINSTELLUNGEN\NICO\DESKTOP\COMPUTER\PROGRAMME\ACTUALSPY.LNK
C:\USERS\NICO\DESKTOP\COMPUTER\PROGRAMME\ACTUALSPY.LNK

Trojan.Agent/CDesc[Generic]
C:\PROGRAM FILES\SONY\PLAYSTATION STORE\NPAAC_WIN.DLL
C:\PROGRAM FILES\SONY\PLAYSTATION STORE\NPCOMMERCE2LIB.DLL

Trojan.Unclassified-Packed/Suspicious
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9A487E93-5CF2-48B1-8774-5D5682EECE5E}\RP92\A0024627.DLL

Trojan.Agent/Gen-PennyStockChaser
G:\PROGRAMME\CHEAT ENGINE\SYSTEMCALLSIGNAL.EXE

Trojan.Agent/Gen-Krpytik
G:\PROGRAMME\JOWOOD\BöSE NACHBARN 2\BIN\AR.EXE

Darkfilter 01.06.2010 13:58

So der letzte Logfile

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4160

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18904

01.06.2010 14:56:32
mbam-log-2010-06-01 (14-56-32).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|G:\|)
Durchsuchte Objekte: 526249
Laufzeit: 1 Stunde(n), 46 Minute(n), 38 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

cosinus 01.06.2010 18:39

Zitat:

Keylogger.Actual Spy
HKLM\Software\ACSPMonitor
Wie kommt dieser Keylogger da rauf? Selbst installiert oder haben noch andere Zugang zu diesem Rechner (vllt mal gehabt) ?
Die anderen Funde von SASW sehen nach Fehlalarmen aus.

Darkfilter 01.06.2010 20:53

Hi, den habe ich selber einmal installiert zur Überwachung!

cosinus 01.06.2010 20:55

Zur Überwachung von wem? Find ich unschön, andere Personen an den Rechner zu lassen und dann deren Tastaturanschläge aufzuzeichnen :pfui:

Darkfilter 02.06.2010 21:48

Nein, nicht um andere an den Rechner zu lassen usw..... Jedoch geht mein Bruder gern an meinen PC und versucht sich an irgendwelchen Passwörtern wenn ich nicht da bin. Um dies zu vermeiden habe ich den mal installiert.
Gruß Nico

cosinus 03.06.2010 12:04

Zitat:

Jedoch geht mein Bruder gern an meinen PC und versucht sich an irgendwelchen Passwörtern wenn ich nicht da bin. Um dies zu vermeiden habe ich den mal installiert.
Und wie soll ein Keylogger das verhindern?

Darkfilter 03.06.2010 22:09

Nein, verhindern nicht! JEdoch sehe ich das er was gemacht hat. Denn er gibt es nie zu.....!


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:36 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58