dante3307 | 12.06.2012 12:18 | Hallo, danke für deine Antwort.
Hatte den Thread gelesen aber nicht daran gedacht zu scrollen, sry, mein Fehler.
Dateien wie dds.txt oder attach.txt, kann ich leider bieten, es war mir nicht ersichtlich in welchem der Schritte ich diese erstelle.
Aber hier die beiden OTL Logfiles und das Gmer Logfile:
OTL Logfile: Code:
OTL logfile created on: 12.06.2012 12:37:01 - Run 2
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\*****\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 1,33 Gb Available Physical Memory | 67,01% Memory free
3,98 Gb Paging File | 3,16 Gb Available in Paging File | 79,27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,79 Gb Total Space | 87,60 Gb Free Space | 37,63% Space Free | Partition Type: NTFS
Computer Name: *****-PC | User Name: ***** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.06.12 12:26:50 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\*****\Downloads\OTL.exe
PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.02 00:31:35 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.04.24 02:11:55 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.07.16 06:31:12 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2009.10.31 07:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.07.14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.07.14 03:14:41 | 000,354,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\StikyNot.exe
========== Modules (No Company Name) ==========
MOD - [2012.02.17 20:55:35 | 000,166,912 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
========== Win32 Services (SafeList) ==========
SRV - [2012.06.10 21:55:08 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
========== Driver Services (SafeList) ==========
DRV - [2012.06.07 20:59:22 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2012.04.27 10:20:04 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.04.25 00:32:27 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.04.16 21:17:40 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.07.14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009.07.14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009.07.14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009.07.14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009.07.14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2009.07.14 00:02:46 | 001,096,704 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 54 1F 4C 90 FC 3B CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (de)"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.10 21:55:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.10 21:55:08 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012.05.27 13:35:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Extensions
[2012.06.01 08:18:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\ksaiw8yu.default\extensions
[2012.05.27 13:35:21 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.05.29 10:38:14 | 000,005,739 | ---- | M] () (No name found) -- C:\USERS\*****\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KSAIW8YU.DEFAULT\EXTENSIONS\{1DE0DE3C-0B5C-4F67-90C6-689623894991}.XPI
[2012.05.28 21:49:57 | 000,634,964 | ---- | M] () (No name found) -- C:\USERS\*****\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KSAIW8YU.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012.06.10 21:55:08 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.06.10 21:55:06 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.10 21:55:06 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.10 21:55:06 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.10 21:55:06 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.10 21:55:06 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.10 21:55:06 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{594B5A83-8F84-492E-808D-944BFA1D4675}: DhcpNameServer = 192.168.178.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{c45e09da-b0af-11e1-a15b-00247e859655}\Shell - "" = AutoRun
O33 - MountPoints2\{c45e09da-b0af-11e1-a15b-00247e859655}\Shell\AutoRun\command - "" = E:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012.06.10 18:45:31 | 000,000,000 | ---D | C] -- C:\Users\*****\Desktop\musicradar-female-vocal-samples
[2012.06.10 17:48:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ReCycle
[2012.06.10 17:47:13 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner
[2012.06.10 17:47:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner
[2012.06.10 17:47:12 | 000,000,000 | ---D | C] -- C:\Program Files\Eusing Free Registry Cleaner
[2012.06.10 17:38:44 | 000,000,000 | ---D | C] -- C:\Program Files\Recycle
[2012.06.10 17:38:23 | 000,000,000 | ---D | C] -- C:\Users\*****\Desktop\Neuer Ordner
[2012.06.10 14:31:20 | 000,000,000 | ---D | C] -- C:\Users\*****\Desktop\yamaha_rx120
[2012.06.08 21:43:39 | 000,000,000 | ---D | C] -- C:\DRIVERS
[2012.06.07 21:09:28 | 000,338,432 | ---- | C] (Propellerhead Software AB) -- C:\Windows\System32\REX Shared Library.dll
[2012.06.07 21:09:27 | 000,406,528 | ---- | C] (Propellerhead Software AB) -- C:\Windows\System32\ReWire.dll
[2012.06.07 21:05:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Propellerhead Software
[2012.06.07 21:05:24 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Propellerhead Software
[2012.06.07 21:05:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Propellerhead
[2012.06.07 21:04:10 | 000,000,000 | ---D | C] -- C:\Program Files\Propellerhead
[2012.06.07 21:00:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2012.06.07 20:59:22 | 000,242,240 | ---- | C] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2012.06.07 20:59:15 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2012.06.07 20:53:34 | 000,000,000 | ---D | C] -- C:\Users\*****\Kram
[2012.06.07 20:51:14 | 000,000,000 | ---D | C] -- C:\Users\*****\Documents\OS
[2012.06.07 20:50:05 | 000,000,000 | ---D | C] -- C:\Users\*****\Selfmade
[2012.06.07 20:49:34 | 000,000,000 | ---D | C] -- C:\Users\*****\Dateien
[2012.06.05 02:00:30 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Microsoft Games
[2012.06.04 22:46:12 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Diagnostics
[2012.06.04 11:31:48 | 000,000,000 | ---D | C] -- C:\Program Files\Foxit Software
[2012.06.03 19:49:56 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012.05.29 10:27:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\Lang
[2012.05.29 10:27:23 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2012.05.29 00:15:29 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Macromedia
[2012.05.29 00:15:29 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Adobe
[2012.05.28 22:10:44 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2012.05.28 21:56:08 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Avira
[2012.05.28 21:52:32 | 000,000,000 | -HSD | C] -- C:\Users\*****\AppData\Local\{1e04b9d7-d6c9-a06b-0e99-a35701b8650e}
[2012.05.28 21:50:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.05.28 21:50:22 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2012.05.28 21:50:21 | 000,137,928 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2012.05.28 21:50:21 | 000,083,392 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2012.05.28 21:50:21 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.05.28 21:50:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.05.28 21:50:19 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012.05.28 21:49:39 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2012.05.28 21:43:46 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\xp-AntiSpy
[2012.05.28 21:43:46 | 000,000,000 | ---D | C] -- C:\Program Files\xp-AntiSpy
[2012.05.28 21:43:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012.05.28 21:43:08 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2012.05.28 21:42:41 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\WinRAR
[2012.05.28 21:42:41 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012.05.28 21:42:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012.05.28 21:42:02 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2012.05.28 21:40:06 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\DAEMON Tools Lite
[2012.05.28 21:39:25 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2012.05.28 21:36:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\x64
[2012.05.27 13:35:27 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Mozilla
[2012.05.27 13:35:27 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Mozilla
[2012.05.27 13:35:21 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012.05.27 13:35:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.05.27 13:35:20 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012.05.27 13:33:05 | 000,000,000 | R--D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.05.27 13:33:05 | 000,000,000 | R--D | C] -- C:\Users\*****\Searches
[2012.05.27 13:33:05 | 000,000,000 | R--D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.05.27 13:32:57 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Identities
[2012.05.27 13:32:55 | 000,000,000 | R--D | C] -- C:\Users\*****\Contacts
[2012.05.27 13:32:45 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\VirtualStore
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\Vorlagen
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\AppData\Local\Verlauf
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\AppData\Local\Temporary Internet Files
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\Startmenü
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\SendTo
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\Recent
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\Netzwerkumgebung
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\Lokale Einstellungen
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\Documents\Eigene Videos
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\Documents\Eigene Bilder
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\Druckumgebung
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\Cookies
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\AppData\Local\Anwendungsdaten
[2012.05.27 13:32:39 | 000,000,000 | -HSD | C] -- C:\Users\*****\Anwendungsdaten
[2012.05.27 13:32:38 | 000,000,000 | -HSD | C] -- C:\Users\*****\Documents\Eigene Musik
[2012.05.27 13:32:38 | 000,000,000 | -HSD | C] -- C:\Users\*****\Eigene Dateien
[2012.05.27 13:32:36 | 000,000,000 | --SD | C] -- C:\Users\*****\AppData\Roaming\Microsoft
[2012.05.27 13:32:36 | 000,000,000 | R--D | C] -- C:\Users\*****\Videos
[2012.05.27 13:32:36 | 000,000,000 | R--D | C] -- C:\Users\*****\Saved Games
[2012.05.27 13:32:36 | 000,000,000 | R--D | C] -- C:\Users\*****\Pictures
[2012.05.27 13:32:36 | 000,000,000 | R--D | C] -- C:\Users\*****\Music
[2012.05.27 13:32:36 | 000,000,000 | R--D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.05.27 13:32:36 | 000,000,000 | R--D | C] -- C:\Users\*****\Links
[2012.05.27 13:32:36 | 000,000,000 | R--D | C] -- C:\Users\*****\Favorites
[2012.05.27 13:32:36 | 000,000,000 | R--D | C] -- C:\Users\*****\Downloads
[2012.05.27 13:32:36 | 000,000,000 | R--D | C] -- C:\Users\*****\Documents
[2012.05.27 13:32:36 | 000,000,000 | R--D | C] -- C:\Users\*****\Desktop
[2012.05.27 13:32:36 | 000,000,000 | R--D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.05.27 13:32:36 | 000,000,000 | -H-D | C] -- C:\Users\*****\AppData
[2012.05.27 13:32:36 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Temp
[2012.05.27 13:32:36 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Microsoft
[2012.05.27 13:32:36 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Media Center Programs
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\Recovery
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\Programme
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Desktop
[2012.05.27 13:31:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2012.05.27 13:31:00 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012.05.27 13:22:31 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012.05.27 13:22:26 | 000,000,000 | ---D | C] -- C:\Windows\CSC
========== Files - Modified Within 30 Days ==========
[2012.06.12 12:28:29 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.06.12 12:28:29 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.06.12 12:27:45 | 000,000,156 | ---- | M] () -- C:\Users\*****\defogger_reenable
[2012.06.12 12:21:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.12 12:21:03 | 1603,039,232 | -HS- | M] () -- C:\hiberfil.sys
[2012.06.10 19:00:43 | 003,354,222 | ---- | M] () -- C:\Users\*****\Desktop\109193__juskiddink__leq-acappella.rx2
[2012.06.10 17:48:56 | 000,000,903 | ---- | M] () -- C:\Users\*****\Desktop\ReCycle.lnk
[2012.06.10 17:47:13 | 000,001,027 | ---- | M] () -- C:\Users\*****\Desktop\Eusing Free Registry Cleaner.lnk
[2012.06.10 16:24:32 | 000,087,120 | ---- | M] () -- C:\Users\*****\Desktop\rhodesstudentfishtalemodel1968.cmb
[2012.06.10 16:24:26 | 000,061,084 | ---- | M] () -- C:\Users\*****\Desktop\rhodesmarkiisuitcase.cmb
[2012.06.10 16:24:24 | 000,062,418 | ---- | M] () -- C:\Users\*****\Desktop\rhodesmarkvchickcoreaschorus.cmb
[2012.06.10 16:24:16 | 000,026,348 | ---- | M] () -- C:\Users\*****\Desktop\resinsoldskoolpiano.cmb
[2012.06.10 16:24:10 | 000,139,098 | ---- | M] () -- C:\Users\*****\Desktop\thunderrainpiano.cmb
[2012.06.10 15:15:04 | 000,004,621 | ---- | M] () -- C:\Users\*****\Desktop\titel.jpg
[2012.06.10 14:31:13 | 002,268,893 | ---- | M] () -- C:\Users\*****\Desktop\PAD_yamaha_rx120.zip
[2012.06.10 14:30:46 | 000,083,160 | ---- | M] () -- C:\Users\*****\Desktop\PAD_Yamaha_RX120_Triphop.cmb
[2012.06.08 21:47:51 | 000,643,866 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.06.08 21:47:51 | 000,607,190 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.06.08 21:47:51 | 000,126,394 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.06.08 21:47:51 | 000,103,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.06.07 21:09:28 | 000,338,432 | ---- | M] (Propellerhead Software AB) -- C:\Windows\System32\REX Shared Library.dll
[2012.06.07 21:09:27 | 000,406,528 | ---- | M] (Propellerhead Software AB) -- C:\Windows\System32\ReWire.dll
[2012.06.07 21:05:02 | 000,001,031 | ---- | M] () -- C:\Users\Public\Desktop\Reason.lnk
[2012.06.07 20:59:22 | 000,242,240 | ---- | M] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2012.06.07 19:41:40 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.06.05 01:25:50 | 000,001,288 | ---- | M] () -- C:\Users\*****\Desktop\shutdown - Verknüpfung.lnk
[2012.06.03 19:49:50 | 147,070,682 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.05.29 12:51:57 | 000,265,640 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.05.29 10:36:22 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2012.05.27 13:35:22 | 000,001,092 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.05.27 13:24:32 | 000,057,050 | ---- | M] () -- C:\Windows\System32\license.rtf
========== Files Created - No Company Name ==========
[2012.06.12 12:27:41 | 000,000,156 | ---- | C] () -- C:\Users\*****\defogger_reenable
[2012.06.11 17:56:17 | 000,001,584 | ---- | C] () -- C:\Users\*****\AppData\Local\{1e04b9d7-d6c9-a06b-0e99-a35701b8650e}\U\000000cb.@
[2012.06.11 17:04:52 | 000,093,696 | ---- | C] () -- C:\Users\*****\AppData\Local\{1e04b9d7-d6c9-a06b-0e99-a35701b8650e}\U\80000032.@
[2012.06.10 18:55:55 | 003,354,222 | ---- | C] () -- C:\Users\*****\Desktop\109193__juskiddink__leq-acappella.rx2
[2012.06.10 18:45:53 | 000,315,392 | ---- | C] () -- C:\Users\*****\Desktop\it an't over soft h2.wav
[2012.06.10 17:48:56 | 000,000,903 | ---- | C] () -- C:\Users\*****\Desktop\ReCycle.lnk
[2012.06.10 17:47:13 | 000,001,027 | ---- | C] () -- C:\Users\*****\Desktop\Eusing Free Registry Cleaner.lnk
[2012.06.10 17:36:17 | 000,000,740 | ---- | C] () -- C:\Users\*****\AppData\Local\{1e04b9d7-d6c9-a06b-0e99-a35701b8650e}\L\00000004.@
[2012.06.10 17:32:52 | 000,232,960 | ---- | C] () -- C:\Users\*****\AppData\Local\{1e04b9d7-d6c9-a06b-0e99-a35701b8650e}\U\00000008.@
[2012.06.10 17:32:32 | 000,001,536 | ---- | C] () -- C:\Users\*****\AppData\Local\{1e04b9d7-d6c9-a06b-0e99-a35701b8650e}\U\00000004.@
[2012.06.10 16:24:32 | 000,087,120 | ---- | C] () -- C:\Users\*****\Desktop\rhodesstudentfishtalemodel1968.cmb
[2012.06.10 16:24:26 | 000,061,084 | ---- | C] () -- C:\Users\*****\Desktop\rhodesmarkiisuitcase.cmb
[2012.06.10 16:24:24 | 000,062,418 | ---- | C] () -- C:\Users\*****\Desktop\rhodesmarkvchickcoreaschorus.cmb
[2012.06.10 16:24:16 | 000,026,348 | ---- | C] () -- C:\Users\*****\Desktop\resinsoldskoolpiano.cmb
[2012.06.10 16:24:09 | 000,139,098 | ---- | C] () -- C:\Users\*****\Desktop\thunderrainpiano.cmb
[2012.06.10 15:15:03 | 000,004,621 | ---- | C] () -- C:\Users\*****\Desktop\titel.jpg
[2012.06.10 14:31:10 | 002,268,893 | ---- | C] () -- C:\Users\*****\Desktop\PAD_yamaha_rx120.zip
[2012.06.10 14:30:45 | 000,083,160 | ---- | C] () -- C:\Users\*****\Desktop\PAD_Yamaha_RX120_Triphop.cmb
[2012.06.07 21:09:43 | 000,331,263 | ---- | C] () -- C:\Windows\LOOP.exe
[2012.06.07 21:05:02 | 000,001,031 | ---- | C] () -- C:\Users\Public\Desktop\Reason.lnk
[2012.06.07 19:41:40 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.06.03 19:49:50 | 147,070,682 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012.05.29 10:36:22 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2012.05.29 10:27:24 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2012.05.29 10:27:24 | 000,121,232 | ---- | C] () -- C:\Windows\System32\IScrNB.bmp
[2012.05.29 00:43:52 | 000,001,288 | ---- | C] () -- C:\Users\*****\Desktop\shutdown - Verknüpfung.lnk
[2012.05.28 21:52:32 | 000,002,048 | -HS- | C] () -- C:\Users\*****\AppData\Local\{1e04b9d7-d6c9-a06b-0e99-a35701b8650e}\@
[2012.05.27 13:35:22 | 000,001,104 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.05.27 13:35:22 | 000,001,092 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.05.27 13:33:07 | 000,001,413 | ---- | C] () -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.05.27 13:21:47 | 1603,039,232 | -HS- | C] () -- C:\hiberfil.sys
========== LOP Check ==========
[2012.06.07 21:03:39 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\DAEMON Tools Lite
[2012.06.10 19:08:39 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Propellerhead Software
[2009.07.14 06:53:46 | 000,007,684 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > --- --- ---
Extras.txt
OTL Logfile: Code:
OTL Extras logfile created on: 12.06.2012 12:27:57 - Run 1
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\*****\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 1,12 Gb Available Physical Memory | 56,49% Memory free
3,98 Gb Paging File | 2,89 Gb Available in Paging File | 72,68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,79 Gb Total Space | 87,60 Gb Free Space | 37,63% Space Free | Partition Type: NTFS
Computer Name: *****-PC | User Name: ***** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{224AC48A-4CB8-4157-B29D-BCDAAF87AFA8}" = lport=10243 | protocol=6 | dir=in | app=system |
"{2D164C9C-BDB8-40AF-A994-D2B2AA28C0A0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{34169379-6DBF-429C-BCA8-6FDBE719116F}" = rport=138 | protocol=17 | dir=out | app=system |
"{37915EA7-0963-4923-9369-CBE264B65E6D}" = lport=445 | protocol=6 | dir=in | app=system |
"{388E2E01-7386-4C03-B92A-7058CE2FF8CD}" = rport=137 | protocol=17 | dir=out | app=system |
"{45F2A936-794B-484C-A64D-485AE45E5485}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4AE01997-EEDF-4DD6-8FDA-F3E7EB3D665B}" = lport=137 | protocol=17 | dir=in | app=system |
"{4F79BA03-65AA-4D19-88BF-FFB750730182}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{57572822-BC95-4339-AC88-05E13A03EFEA}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5798E177-4FFC-4EE5-A4BD-A93FA421C443}" = rport=10243 | protocol=6 | dir=out | app=system |
"{8D6DA20D-D1D9-4B2C-8EA7-B2AD8F70D791}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9766EDBB-CBBA-43D8-BE76-B8F9504372AA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9EFBA775-E6DC-46D7-9EF7-22C338B7252A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{A6A7BA8E-4EDC-44B0-8AE3-2F27DC32726A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B1D29487-6998-4AA1-AAE9-BC61A40D5460}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{B7C9CCCC-269F-4044-8422-24DA47D59D27}" = rport=445 | protocol=6 | dir=out | app=system |
"{CDE0B44F-04D3-487F-8114-49D45176A24D}" = rport=139 | protocol=6 | dir=out | app=system |
"{E49ADF53-2389-4881-9EA7-6AC0BD47DE71}" = lport=138 | protocol=17 | dir=in | app=system |
"{E68A0A5D-C8CF-478C-920C-1B3B1A744E49}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{ED278F44-4A11-4260-BA4E-C0A4F1DAC027}" = lport=139 | protocol=6 | dir=in | app=system |
"{EF655B7A-1434-4509-818C-E8CD67225F8E}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04B1B93A-64F4-4B46-8961-5457650FED81}" = protocol=6 | dir=out | app=system |
"{0842C576-6ADD-41F4-8864-6C69F482E787}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{219932B8-4C7A-42BB-B50A-A9F410DF7358}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{31E2C0EC-F57F-456B-89C3-6A821803E44E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{40BEAFF6-DD14-425B-B824-F01397F5D539}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{54C06F43-FEC4-446F-84E9-8C273322B774}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5BCA6D7D-3EF3-48D3-A965-467787995B01}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{86FABE9D-AFB9-4DF7-86D9-E17688BA222E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{881F61F6-C7BE-430A-9B56-6E26E4996C8F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8D0F4C0A-2554-42BE-AD05-818C8C3E4DE0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9A60FE39-1CBC-4C0D-A392-6F6042B84073}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A28A5E47-FFF3-4FD4-AA58-A4F4CE319B74}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C1D34794-8747-47D3-B1D1-9E8891F233FB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C5EF265F-1895-434D-AC6C-809CCA135A49}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{C9B405CA-8F05-43AF-9A8F-36A02A35E9D0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F9834CE7-E772-49DF-AB29-A9FFF2C3F386}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{237C186E-66CC-4F20-A848-13B0AD262D50}C:\program files\recycle\recycle.exe" = protocol=6 | dir=in | app=c:\program files\recycle\recycle.exe |
"TCP Query User{F277DDAE-DA07-48D9-9FF8-077D78242C1C}C:\program files\recycle\keygen.exe" = protocol=6 | dir=in | app=c:\program files\recycle\keygen.exe |
"TCP Query User{FD405F09-8B99-4AF7-8B32-A6115A092B31}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{0AF420B1-42CF-4C1D-AB24-B013A641543D}C:\program files\recycle\keygen.exe" = protocol=17 | dir=in | app=c:\program files\recycle\keygen.exe |
"UDP Query User{37191032-A413-4292-8F3A-3A36619F61E0}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{D266BF76-4C6F-4738-B7A8-9AB545402032}C:\program files\recycle\recycle.exe" = protocol=17 | dir=in | app=c:\program files\recycle\recycle.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"DAEMON Tools Lite" = DAEMON Tools Lite
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"Foxit Reader_is1" = Foxit Reader 5.1
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"Mozilla Firefox 13.0 (x86 de)" = Mozilla Firefox 13.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Reason5_is1" = Reason 5.0
"ReCycle v2.1" = ReCycle v2.1
"TVWiz" = Intel(R) TV Wizard
"VLC media player" = VLC media player 2.0.1
"WinRAR archiver" = WinRAR 4.11 (32-Bit)
"xp-AntiSpy" = xp-AntiSpy 3.98-2
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 29.05.2012 07:45:59 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
Error - 07.06.2012 14:59:23 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
Error - 07.06.2012 14:59:23 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
Error - 07.06.2012 14:59:23 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
Error - 07.06.2012 14:59:23 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
Error - 07.06.2012 15:00:09 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
Error - 07.06.2012 15:00:09 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
Error - 07.06.2012 15:00:09 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
Error - 07.06.2012 15:00:09 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
Error - 07.06.2012 15:00:09 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
[ System Events ]
Error - 07.06.2012 10:50:25 | Computer Name = *****-PC | Source = WMPNetworkSvc | ID = 866287
Description =
Error - 07.06.2012 10:54:51 | Computer Name = *****-PC | Source = WMPNetworkSvc | ID = 866287
Description =
Error - 07.06.2012 14:18:34 | Computer Name = *****-PC | Source = WMPNetworkSvc | ID = 866287
Description =
Error - 07.06.2012 18:35:27 | Computer Name = *****-PC | Source = WMPNetworkSvc | ID = 866287
Description =
Error - 08.06.2012 05:14:55 | Computer Name = *****-PC | Source = WMPNetworkSvc | ID = 866287
Description =
Error - 08.06.2012 05:16:13 | Computer Name = *****-PC | Source = WMPNetworkSvc | ID = 866287
Description =
Error - 08.06.2012 15:42:13 | Computer Name = *****-PC | Source = WMPNetworkSvc | ID = 866287
Description =
Error - 08.06.2012 15:43:26 | Computer Name = *****-PC | Source = WMPNetworkSvc | ID = 866287
Description =
Error - 09.06.2012 20:24:10 | Computer Name = *****-PC | Source = WMPNetworkSvc | ID = 866287
Description =
Error - 09.06.2012 20:25:06 | Computer Name = *****-PC | Source = WMPNetworkSvc | ID = 866287
Description =
< End of report > --- --- ---
Gmer.txt
GMER Logfile: Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-06-12 13:09:14
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST9250315AS rev.0003DEM1
Running: dong4oq9.exe; Driver: C:\Users\*****\AppData\Local\Temp\ugloypog.sys
---- System - GMER 1.0.15 ----
SSDT 907D0C0E ZwCreateSection
SSDT 907D0C18 ZwRequestWaitReplyPort
SSDT 907D0C13 ZwSetContextThread
SSDT 907D0C1D ZwSetSecurityObject
SSDT 907D0C22 ZwSystemDebugControl
SSDT 907D0BAF ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwRollbackTransaction + 13E9 82860599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82885092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 340 8288C990 4 Bytes [0E, 0C, 7D, 90] {PUSH CS; OR AL, 0x7d; NOP }
.text ntkrnlpa.exe!RtlSidHashLookup + 69C 8288CCEC 4 Bytes [18, 0C, 7D, 90]
.text ntkrnlpa.exe!RtlSidHashLookup + 6E0 8288CD30 4 Bytes [13, 0C, 7D, 90]
.text ntkrnlpa.exe!RtlSidHashLookup + 75C 8288CDAC 4 Bytes [1D, 0C, 7D, 90]
.text ntkrnlpa.exe!RtlSidHashLookup + 7B0 8288CE00 4 Bytes [22, 0C, 7D, 90]
.text ...
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000047 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e859655
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e859655 (not active ControlSet)
---- EOF - GMER 1.0.15 ---- --- --- ---
Ich hoffe damit kann man etwas anfangen.
Grüße |