Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Virus, den ich nicht finde. (https://www.trojaner-board.de/79572-virus-finde.html)

crippcid 19.11.2009 18:48

Virus, den ich nicht finde.
 
Ja.. ich hab heut, seitdem ich den PC anhab, i-wie schon fast im 20Mins.-Tackt einen Virus. Ich hab einfach mal ein Bildchen davon gemacht:

http://i46.tinypic.com/m9c1lt.jpg

Wie bekomm ich den weg? Ich klick mich dann immer durch den Defender, aber das Ding erscheint immer wieder.

Danke im voraus ;)

crippcid 19.11.2009 18:56

aso.. Hijack:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:56:03, on 19.11.2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_FATICAE.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\PingChanGeR\Program Files\DNA\btdna.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SHOUTcast Toolbar Search Class - {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: SHOUTcast Radio Toolbar - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [recinfo793] c:\RecInfo\RecInfo.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Cm106Sound] RunDll32 cm106.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe
O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S65EF.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\PingChanGeR\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O8 - Extra context menu item: &SHOUTcast Search - C:\ProgramData\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O13 - Gopher Prefix:
O16 - DPF: {3188FB46-456D-4C07-8A11-F5F3BBBA8AF2} (SeeTooControl Class) - http://www.seetoo.com/downloadAddon.php?platform=Win32&browser=ie&ref=justintv&c=c1fd32f2323559bc3&browserVersion=7.0
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ProtexisLicensing - Unknown owner - c:\Windows\system32\PSIService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: @C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
O23 - Service: UPnPService - Magix AG - C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe

--
End of file - 7076 bytes

Angel21 19.11.2009 19:32

Hallo, na alles klar? :)

Ich nehme mich dir an, da wir ja schonmal die Gesellschaft miteinander hatten ;)

So.....letz fetz the trojan :D


1. Starte Malwarebytes, inem du das Setup mit Rechtsklick -> Ziel speichern untr....-> Setup zu blubb.com umbenennst spoeicherst. Danach öffne das Setup, installiere dir Malwarebytes und lass es einen Vollständigen Systemscan durchziehen.

2. Starte die Gmer Rootkit Suche. Folge dem blau unterlegten Link und starte Gmer so, wie es in der Anleitung hierzu steht.

3. Starte einen Vollständigen Systemscan mit Avira in diesen folgenden Einstellungen: http://www.trojaner-board.de/54192-a...tellungen.html und lass es durchscannen.

Nundenn:
1. Malwarebytes Log
2. Gmer Log
3. Avira Log

Alles gefunde entfernen.....

crippcid 19.11.2009 19:39

ah hey Angel ;) Dann mach ich das mal eben :)

crippcid 19.11.2009 21:25

So.. bei mir is alles klar^^ Wie geht es denn dir?
Hier deine Logs:

Malware:
Malwarebytes' Anti-Malware 1.41
Datenbank Version: 2775
Windows 6.0.6002 Service Pack 2

19.11.2009 20:38:56
mbam-log-2009-11-19 (20-38-56).txt

Scan-Methode: Vollständiger Scan (C:\|D:\|)
Durchsuchte Objekte: 244182
Laufzeit: 54 minute(s), 47 second(s)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden

GMER:
GMER 1.0.15.15227 - http://www.gmer.net
Rootkit scan 2009-11-19 21:18:57
Windows 6.0.6002 Service Pack 2
Running: d9rj7u4b.exe; Driver: C:\Users\PINGCH~1\AppData\Local\Temp\fxlyiaob.sys


---- System - GMER 1.0.15 ----

SSDT 97A4147C ZwCreateThread
SSDT 97A41468 ZwOpenProcess
SSDT 97A4146D ZwOpenThread
SSDT 97A41477 ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!KeSetEvent + 221 81CAC964 4 Bytes [7C, 14, A4, 97] {JL 0x16; MOVSB ; XCHG EDI, EAX}
.text ntkrnlpa.exe!KeSetEvent + 3F1 81CACB34 4 Bytes [68, 14, A4, 97]
.text ntkrnlpa.exe!KeSetEvent + 40D 81CACB50 4 Bytes [6D, 14, A4, 97] {INSD ; ADC AL, 0xa4; XCHG EDI, EAX}
.text ntkrnlpa.exe!KeSetEvent + 621 81CACD64 4 Bytes [77, 14, A4, 97] {JA 0x16; MOVSB ; XCHG EDI, EAX}

---- Devices - GMER 1.0.15 ----

Device \Driver\ViPrt \Device\Ide\ViaIdePort0 [805BC80C] \SystemRoot\system32\DRIVERS\ViPrt.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\ViPrt \Device\Ide\ViaIdePort1 [805BC80C] \SystemRoot\system32\DRIVERS\ViPrt.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}

---- Files - GMER 1.0.15 ----

File C:\Windows\system32\drivers\ViPrt.sys suspicious modification

---- EOF - GMER 1.0.15 ----

AntiVir:
Suchlauf beendet [Der Suchlauf wurde vollständig durchgeführt.].
Anzahl Dateien: 309507
Anzahl Verzeichnisse: 20774
Anzahl Malware: 0
Anzahl Fehler: 2

Angel21 20.11.2009 14:22

CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
%SYSTEMDRIVE%\*.exe
%SYSTEMDRIVE%\eventlog.dll /s /md5
%SYSTEMDRIVE%\scecli.dll /s /md5
%SYSTEMDRIVE%\netlogon.dll /s /md5
%SYSTEMDRIVE%\cngaudit.dll /s /md5
%SYSTEMDRIVE%\sceclt.dll /s /md5
%SYSTEMDRIVE%\ntelogon.dll /s /md5
%SYSTEMDRIVE%\logevent.dll /s /md5
%SYSTEMDRIVE%\iaStor.sys /s /md5
%SYSTEMDRIVE%\nvstor.sys /s /md5
%SYSTEMDRIVE%\atapi.sys /s /md5
%SYSTEMDRIVE%\IdeChnDr.sys /s /md5
%SYSTEMDRIVE%\viasraid.sys /s /md5
%SYSTEMDRIVE%\AGP440.sys /s /md5
%SYSTEMDRIVE%\vaxscsi.sys /s /md5
%SYSTEMDRIVE%\nvatabus.sys /s /md5
%SYSTEMDRIVE%\ViPrt.sys /s /md5
CREATERESTOREPOINT


crippcid 20.11.2009 16:45

OTL.Txt:
Code:

OTL logfile created on: 20.11.2009 16:28:55 - Run 1
OTL by OldTimer - Version 3.1.6.0    Folder = C:\Users\PingChanGeR\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,06 Gb Available Physical Memory | 53,07% Memory free
4,00 Gb Paging File | 2,79 Gb Available in Paging File | 69,67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 216,90 Gb Total Space | 103,94 Gb Free Space | 47,92% Space Free | Partition Type: NTFS
Drive D: | 106,45 Gb Total Space | 106,36 Gb Free Space | 99,91% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: PINGCHANGER-PC
Current User Name: PingChanGeR
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
 
========== Processes (SafeList) ==========
 
PRC - [2009.11.20 16:27:47 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Users\PingChanGeR\Downloads\OTL.exe
PRC - [2009.11.06 21:38:32 | 00,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Users\PingChanGeR\Program Files\DNA\btdna.exe
PRC - [2009.11.06 05:33:05 | 00,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009.10.30 14:33:46 | 00,486,216 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
PRC - [2009.10.30 14:31:24 | 01,021,256 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
PRC - [2009.08.24 15:51:46 | 00,185,640 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
PRC - [2009.07.21 13:34:28 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009.05.13 15:48:18 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009.04.10 22:27:40 | 00,299,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\ieuser.exe
PRC - [2009.04.10 22:27:38 | 02,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.03.02 12:08:43 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2008.08.01 05:45:28 | 00,700,416 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\Ati2evxx.exe
PRC - [2008.08.01 05:45:28 | 00,700,416 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\Ati2evxx.exe
PRC - [2008.01.18 22:38:40 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008.01.18 22:33:42 | 00,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WUDFHost.exe
PRC - [2008.01.18 22:33:40 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe
PRC - [2008.01.18 22:33:40 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2008.01.18 22:33:16 | 00,095,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mobsync.exe
PRC - [2007.09.07 14:54:54 | 00,159,744 | ---- | M] () -- C:\Program Files\Razer\DeathAdder\razerhid.exe
PRC - [2007.07.17 10:13:56 | 00,049,152 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
PRC - [2007.07.17 10:13:34 | 00,049,152 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
PRC - [2007.05.07 14:35:14 | 00,163,840 | ---- | M] (Razer Inc.) -- C:\Program Files\Razer\DeathAdder\razerofa.exe
PRC - [2007.03.01 05:01:00 | 00,180,736 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\spool\drivers\w32x86\3\E_FATICAE.EXE
PRC - [2006.12.08 09:52:04 | 00,204,800 | ---- | M] (Fujitsu Siemens Computers) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe
PRC - [2006.11.03 10:01:16 | 00,319,488 | ---- | M] (PixArt Imaging Incorporation) -- C:\Windows\PixArt\Pac207\Monitor.exe
PRC - [2006.11.02 19:40:12 | 00,174,656 | ---- | M] () -- C:\Windows\System32\PSIService.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2009.11.20 16:27:47 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Users\PingChanGeR\Downloads\OTL.exe
MOD - [2009.04.10 22:21:40 | 01,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2009.11.04 16:59:18 | 00,435,016 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2009.11.02 22:12:28 | 00,320,760 | ---- | M] (Valve Corporation) -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009.10.30 14:31:24 | 01,021,256 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2009.10.30 14:27:34 | 00,030,024 | ---- | M] (TuneUp Software) -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2009.09.25 02:27:04 | 00,793,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009.08.24 15:51:46 | 00,185,640 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe -- (TeamViewer4)
SRV - [2009.07.21 13:34:28 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009.05.13 15:48:18 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2009.03.29 20:42:16 | 00,066,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.02.18 10:39:22 | 00,043,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0)
SRV - [2009.02.18 10:38:44 | 00,879,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)
SRV - [2009.02.18 10:38:44 | 00,129,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008.08.01 05:45:28 | 00,700,416 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\Ati2evxx.exe -- (Ati External Event Utility)
SRV - [2008.01.18 22:38:26 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008.01.18 22:33:40 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2008.01.18 22:33:10 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehrecvr.exe -- (ehRecvr)
SRV - [2007.02.26 18:16:22 | 00,267,824 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2006.12.14 16:00:00 | 00,544,768 | ---- | M] (Magix AG) -- C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe -- (UPnPService)
SRV - [2006.12.08 09:52:04 | 00,204,800 | ---- | M] (Fujitsu Siemens Computers) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler)
SRV - [2006.11.02 19:40:12 | 00,174,656 | ---- | M] () -- C:\Windows\System32\PSIService.exe -- (ProtexisLicensing)
SRV - [2006.11.02 13:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched)
SRV - [2006.11.02 13:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart)
SRV - [2005.11.17 14:18:52 | 01,527,900 | ---- | M] (MAGIX®) -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\..\URLSearchHook: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC)
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Winamp Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50-ff-shoutcast-chromesbox-en-us&query="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.de"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: anycolor.pavlos256@gmail.com:0.3.1
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17
FF - prefs.js..extensions.enabledItems: seetooaddon@seetoo.com:1.2
FF - prefs.js..extensions.enabledItems: {12e4c684-c03e-4e4d-85bc-0c065e7a9489}:5.23.2.10
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.11.2
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.5
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50-ff-shoutcast-ab-en-us&query="
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009.09.17 12:51:44 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009.11.06 05:33:07 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009.11.06 05:33:07 | 00,000,000 | ---D | M]
 
[2009.09.15 18:38:16 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\mozilla\Extensions
[2009.09.15 18:38:16 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009.11.19 17:28:45 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\mozilla\Firefox\Profiles\gsd41ghb.default\extensions
[2009.09.21 14:39:11 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\mozilla\Firefox\Profiles\gsd41ghb.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2009.09.17 16:54:51 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\mozilla\Firefox\Profiles\gsd41ghb.default\extensions\{12e4c684-c03e-4e4d-85bc-0c065e7a9489}
[2009.11.04 18:09:15 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\mozilla\Firefox\Profiles\gsd41ghb.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009.10.25 15:42:49 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\mozilla\Firefox\Profiles\gsd41ghb.default\extensions\anycolor.pavlos256@gmail.com
[2009.09.17 15:05:21 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\mozilla\Firefox\Profiles\gsd41ghb.default\extensions\seetooaddon@seetoo.com
[2009.09.21 14:39:17 | 00,001,201 | ---- | M] () -- C:\Users\PingChanGeR\AppData\Roaming\Mozilla\FireFox\Profiles\gsd41ghb.default\searchplugins\winamp-search.xml
[2009.11.09 18:12:04 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.11.04 18:08:59 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009.11.06 05:33:07 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009.09.15 19:16:46 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009.09.30 13:10:49 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
[2009.11.09 18:12:04 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2009.11.06 05:33:05 | 00,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2009.11.06 05:33:05 | 00,137,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2009.05.13 22:55:22 | 01,044,480 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\Mozilla Firefox\plugins\libdivx.dll
[2007.04.10 16:21:08 | 00,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
[2009.10.11 04:17:27 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
[2009.05.13 22:54:50 | 01,650,992 | ---- | M] (DivX,Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll
[2009.05.27 03:18:22 | 00,098,304 | ---- | M] (DivX, Inc) -- C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
[2009.11.06 05:33:05 | 00,064,984 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2009.02.27 11:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2009.05.13 22:55:22 | 00,200,704 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\Mozilla Firefox\plugins\ssldivx.dll
[2009.08.24 20:25:19 | 00,001,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2009.08.24 20:25:19 | 00,002,344 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml
[2009.08.24 20:25:19 | 00,002,371 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2009.08.24 20:25:19 | 00,006,805 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2009.08.24 20:25:19 | 00,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2009.08.24 20:25:19 | 00,000,801 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (SHOUTcast Loader) - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (SHOUTcast Radio Toolbar) - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (SHOUTcast Radio Toolbar) - {0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Cm106Sound]  File not found
O4 - HKLM..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe ()
O4 - HKLM..\Run: [Monitor] C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [recinfo793] c:\RecInfo\RecInfo.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Users\PingChanGeR\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [EPSON Stylus DX4400 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &SHOUTcast Search - C:\ProgramData\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html ()
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O13 - gopher Prefix: missing
O16 - DPF: {3188FB46-456D-4C07-8A11-F5F3BBBA8AF2} http://www.seetoo.com/downloadAddon.php?platform=Win32&browser=ie&ref=justintv&c=c1fd32f2323559bc3&browserVersion=7.0 (SeeTooControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) -  File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) -  File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
 
NetSvcs: UxTuneUp - C:\Windows\System32\uxtuneup.dll (TuneUp Software)
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009.09.16 13:25:43 | 00,000,000 | ---D | M]
NetSvcs: Irmon - C:\Windows\System32\irmon.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
OTL cannot create restorepoints on Vista OSs!


crippcid 20.11.2009 16:46

Teil 2 OTL.Txt:

Code:

========== Files/Folders - Created Within 14 Days ==========
 
[2009.11.19 19:42:04 | 00,000,000 | ---D | C] -- C:\Users\PingChanGeR\AppData\Roaming\Malwarebytes
[2009.11.19 19:41:59 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009.11.19 19:41:57 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009.11.19 19:41:57 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009.11.19 19:41:57 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009.11.19 19:41:56 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009.11.19 18:54:54 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009.11.18 00:22:47 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices
[2009.11.06 22:22:33 | 00,000,000 | ---D | C] -- C:\Users\PingChanGeR\AppData\Local\WarRockDF
[2009.11.06 21:38:32 | 00,000,000 | ---D | C] -- C:\Users\PingChanGeR\Program Files
[2009.11.06 21:12:06 | 00,000,000 | ---D | C] -- C:\Users\PingChanGeR\AppData\Local\DNA
[2009.11.06 21:12:03 | 00,000,000 | ---D | C] -- C:\Users\PingChanGeR\AppData\Roaming\DNA
[2009.11.06 21:12:03 | 00,000,000 | ---D | C] -- C:\Program Files\DNA
[2009.11.06 21:12:01 | 00,000,000 | ---D | C] -- C:\Program Files\GamersFirst
 
========== Files - Modified Within 14 Days ==========
 
[2009.11.20 16:28:29 | 02,359,296 | -HS- | M] () -- C:\Users\PingChanGeR\NTUSER.DAT
[2009.11.20 15:19:12 | 00,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009.11.20 15:19:12 | 00,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009.11.20 13:25:58 | 01,418,612 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009.11.20 13:25:58 | 00,618,204 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2009.11.20 13:25:58 | 00,586,980 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009.11.20 13:25:58 | 00,122,442 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2009.11.20 13:25:58 | 00,101,052 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009.11.20 13:19:13 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009.11.20 13:19:05 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009.11.20 13:19:02 | 21,438,21824 | -HS- | M] () -- C:\hiberfil.sys
[2009.11.19 23:02:03 | 00,524,288 | -HS- | M] () -- C:\Users\PingChanGeR\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2009.11.19 23:02:03 | 00,065,536 | -HS- | M] () -- C:\Users\PingChanGeR\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2009.11.19 23:01:55 | 02,629,969 | -H-- | M] () -- C:\Users\PingChanGeR\AppData\Local\IconCache.db
[2009.11.19 21:19:51 | 00,001,760 | ---- | M] () -- C:\Users\PingChanGeR\Desktop\Gmer.rtf
[2009.11.19 20:39:15 | 00,001,550 | ---- | M] () -- C:\Users\PingChanGeR\Desktop\AntiVir Log.rtf
[2009.11.19 19:42:01 | 00,000,784 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.11.19 19:40:37 | 00,044,477 | ---- | M] () -- C:\Users\PingChanGeR\Desktop\51187-anleitung-malwarebytes-anti-malware.html
[2009.11.19 18:54:54 | 00,001,840 | ---- | M] () -- C:\Users\PingChanGeR\Desktop\HijackThis.lnk
[2009.11.19 17:56:42 | 00,069,117 | ---- | M] () -- C:\Users\PingChanGeR\Desktop\Vire.jpg
[2009.11.19 13:33:56 | 00,046,762 | ---- | M] () -- C:\Users\PingChanGeR\Desktop\Unbenannt.jpg
[2009.11.18 00:22:34 | 00,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2009.11.16 21:49:49 | 00,008,704 | ---- | M] () -- C:\Users\PingChanGeR\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.11.12 17:50:34 | 00,265,976 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.11.10 22:50:56 | 03,250,500 | ---- | M] () -- C:\Users\PingChanGeR\Desktop\Subway_to_Sally_-_Sieben.mp3
[2009.11.06 21:42:31 | 00,000,735 | ---- | M] () -- C:\Users\Public\Desktop\War Rock.lnk
 
========== Files Created - No Company Name ==========
 
[2009.11.19 21:19:51 | 00,001,760 | ---- | C] () -- C:\Users\PingChanGeR\Desktop\Gmer.rtf
[2009.11.19 19:48:51 | 00,001,550 | ---- | C] () -- C:\Users\PingChanGeR\Desktop\AntiVir Log.rtf
[2009.11.19 19:42:01 | 00,000,784 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.11.19 19:40:36 | 00,044,477 | ---- | C] () -- C:\Users\PingChanGeR\Desktop\51187-anleitung-malwarebytes-anti-malware.html
[2009.11.19 18:54:54 | 00,001,840 | ---- | C] () -- C:\Users\PingChanGeR\Desktop\HijackThis.lnk
[2009.11.19 17:56:42 | 00,069,117 | ---- | C] () -- C:\Users\PingChanGeR\Desktop\Vire.jpg
[2009.11.19 13:33:56 | 00,046,762 | ---- | C] () -- C:\Users\PingChanGeR\Desktop\Unbenannt.jpg
[2009.11.18 00:22:34 | 00,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2009.11.10 22:50:49 | 03,250,500 | ---- | C] () -- C:\Users\PingChanGeR\Desktop\Subway_to_Sally_-_Sieben.mp3
[2009.11.06 21:42:31 | 00,000,735 | ---- | C] () -- C:\Users\Public\Desktop\War Rock.lnk
[2009.10.15 01:01:24 | 00,041,872 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2009.09.17 16:57:54 | 00,065,536 | ---- | C] () -- C:\Windows\VMix.dll
[2009.09.17 15:57:06 | 00,008,704 | ---- | C] () -- C:\Users\PingChanGeR\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.09.16 13:36:47 | 00,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.15 18:47:23 | 00,139,264 | R--- | C] () -- C:\Windows\Vmix106.dll
[2009.09.15 18:46:38 | 00,241,664 | R--- | C] () -- C:\Windows\System32\CmiInstallResAll.dll
[2009.09.15 18:46:38 | 00,004,601 | R--- | C] () -- C:\Windows\Cm106.ini.cfg
[2009.09.15 18:46:38 | 00,000,648 | ---- | C] () -- C:\Windows\Cm106.ini.imi
[2009.09.15 18:46:38 | 00,000,340 | ---- | C] () -- C:\Windows\Cm106.ini.cfl
[2009.09.15 18:46:36 | 00,002,758 | R--- | C] () -- C:\Windows\cm106.ini
[2009.09.15 18:28:06 | 02,629,969 | -H-- | C] () -- C:\Users\PingChanGeR\AppData\Local\IconCache.db
[2009.09.15 18:22:54 | 00,066,904 | ---- | C] () -- C:\Users\PingChanGeR\AppData\Local\GDIPFONTCACHEV1.DAT
[2009.09.15 18:22:35 | 00,000,680 | ---- | C] () -- C:\Users\PingChanGeR\AppData\Local\d3d9caps.dat
[2008.08.01 05:47:26 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2007.10.16 21:47:46 | 00,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2007.10.16 21:47:46 | 00,006,768 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2007.10.16 21:38:28 | 00,069,632 | ---- | C] () -- C:\Windows\System32\vuins32.dll
[2006.11.02 13:50:50 | 00,000,174 | -HS- | C] () -- C:\Program Files\desktop.ini
[2006.11.02 13:37:35 | 00,037,665 | ---- | C] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
[2006.11.02 13:37:35 | 00,029,779 | ---- | C] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006.11.02 13:37:35 | 00,026,489 | ---- | C] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006.11.02 13:37:35 | 00,026,040 | ---- | C] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006.11.02 13:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006.11.02 11:23:31 | 00,000,187 | ---- | C] () -- C:\Windows\win.ini
[2006.11.02 08:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:27:46 | 00,000,518 | ---- | C] () -- C:\Windows\System32\SP207.INI
[2006.08.11 08:52:02 | 00,012,288 | ---- | C] () -- C:\Windows\System32\EvOnlDiag.dll
 
========== LOP Check ==========
 
[2009.09.16 18:01:17 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\ATI
[2009.11.20 16:29:42 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\DNA
[2009.10.02 16:42:25 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\gtk-2.0
[2009.09.23 16:42:46 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\ICQ
[2009.09.19 14:01:29 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\MAGIX
[2009.09.30 15:27:29 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\OpenOffice.org
[2009.09.22 21:19:35 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\TeamViewer
[2009.11.04 16:58:47 | 00,000,000 | ---D | M] -- C:\Users\PingChanGeR\AppData\Roaming\TuneUp Software
[2009.11.20 13:19:13 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
[2009.11.19 23:02:11 | 00,032,570 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*.exe >
 
< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
 
< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2009.04.10 22:28:26 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2006.11.02 10:46:12 | 00,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2008.01.18 22:36:20 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.10 22:28:26 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2009.04.10 22:28:24 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2006.11.02 10:46:11 | 00,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2008.01.18 22:35:38 | 00,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
[2009.04.10 22:28:24 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
 
< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
[2006.11.02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< %SYSTEMDRIVE%\sceclt.dll /s /md5 >
 
< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >
 
< %SYSTEMDRIVE%\logevent.dll /s /md5 >
 
< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
[2007.07.12 15:35:02 | 00,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\Windows\System32\drivers\iaStor.sys
[2007.07.12 15:35:02 | 00,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_ec8a8d1b\iaStor.sys
 
< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
[2006.11.02 10:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2008.01.18 22:42:10 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2006.11.02 10:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.18 22:42:10 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2009.04.10 22:32:28 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.09.15 19:42:43 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_64dfd8ea\atapi.sys
[2009.09.15 19:42:43 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2007.10.16 20:56:31 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=DB44893AF257EBB912511B2042B2AD38 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7e854ec8\atapi.sys
[2009.04.10 22:32:28 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2006.11.02 10:49:36 | 00,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.01.18 22:41:32 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2009.09.15 19:42:43 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2007.10.16 20:56:31 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=DB44893AF257EBB912511B2042B2AD38 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20619_none_dbd9b7073d80e04e\atapi.sys
[2009.09.15 19:42:43 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
[2008.01.18 22:41:32 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2009.04.10 22:32:28 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
 
< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >
 
< %SYSTEMDRIVE%\viasraid.sys /s /md5 >
 
< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2006.11.02 10:49:52 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2008.01.18 22:42:26 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2006.11.02 10:49:52 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[2007.10.16 20:44:58 | 00,056,504 | ---- | M] (Microsoft Corporation) MD5=198636E76971EBC96404547EC0FD5E75 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_cb7c81c7\AGP440.sys
[2008.01.18 22:42:26 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2007.10.16 20:44:58 | 00,056,504 | ---- | M] (Microsoft Corporation) MD5=198636E76971EBC96404547EC0FD5E75 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20598_none_b85cfa98dae9b436\AGP440.sys
[2008.01.18 22:42:26 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.18 22:42:26 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
 
< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >
 
< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >
 
< %SYSTEMDRIVE%\ViPrt.sys /s /md5 >
[2007.03.26 14:26:00 | 00,052,224 | ---- | M] (VIA Technologies, Inc.) MD5=A1B7CFFE5F09B825FBA506C4DE9FDAC7 -- C:\DRIVER\SATA\VIA\ViPrt.sys
[2007.03.26 14:26:00 | 00,052,224 | ---- | M] (VIA Technologies, Inc.) MD5 -- C:\Windows\System32\drivers\ViPrt.sys
[2007.03.26 14:26:00 | 00,052,224 | ---- | M] (VIA Technologies, Inc.) MD5=A1B7CFFE5F09B825FBA506C4DE9FDAC7 -- C:\Windows\System32\DriverStore\FileRepository\viprt.inf_86543378\ViPrt.sys
< End of report >


crippcid 20.11.2009 16:47

Extras.Txt:

Code:

OTL Extras logfile created on: 20.11.2009 16:28:55 - Run 1
OTL by OldTimer - Version 3.1.6.0    Folder = C:\Users\PingChanGeR\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,06 Gb Available Physical Memory | 53,07% Memory free
4,00 Gb Paging File | 2,79 Gb Available in Paging File | 69,67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 216,90 Gb Total Space | 103,94 Gb Free Space | 47,92% Space Free | Partition Type: NTFS
Drive D: | 106,45 Gb Total Space | 106,36 Gb Free Space | 99,91% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: PINGCHANGER-PC
Current User Name: PingChanGeR
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- "%SystemRoot%\hh.exe" %1
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "%SystemRoot%\hh.exe" %1 File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{DB45FE8C-CAEB-4693-AB44-CF3F644EC757}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E3133B33-D366-446B-A20E-F7D75AD50D41}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01FB43A7-C266-4179-B9B6-2E4C8F4EC5A5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{0D6CACEC-3E4F-429A-97AD-C3D2AAB7B648}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-dede-downloader.exe |
"{1989C1C6-C279-4945-A02A-430BA31B5E27}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{21107AF7-FBD1-45E2-861C-70705D250D26}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-dede-downloader.exe |
"{28856146-B660-409E-95E1-5351ACD0291A}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-dede-downloader.exe |
"{2D957084-7A52-4004-BE6C-0FD56025247C}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-dede-downloader.exe |
"{370E667F-EC79-42F1-8824-13D4DD26E539}" = protocol=58 | dir=in | app=system |
"{55E37627-C1B6-466A-ACD4-816E74A5BC62}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{578285B9-BB5B-4A53-A0DB-A9539171D9AE}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{5B05E30E-E409-47A7-957B-5816C207146A}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version4\teamviewer.exe |
"{5FF1E0C0-D9B4-4608-9B35-07D058233A1B}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-dede-downloader.exe |
"{935FC3B7-1A23-4360-A2C4-80986A3AD071}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0-dede-downloader.exe |
"{951982E3-000E-4991-8AD5-DA3628B1C250}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version4\teamviewer.exe |
"{9B9DC92C-2E4A-4B26-8FD1-A05A91115578}" = protocol=6 | dir=in | app=c:\program files\electronic arts\die schlacht um mittelerde ii\game.dat |
"{C39B5BF3-F4C3-454C-9F57-1D50D6A7C753}" = protocol=17 | dir=in | app=c:\program files\electronic arts\die schlacht um mittelerde ii\game.dat |
"{C7FD25A0-0967-4E5F-9AFE-2DF52980D8ED}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-dede-downloader.exe |
"{CFEAEEC9-EC44-40D2-8BBD-6C521A21EB7A}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-dede-downloader.exe |
"{D58BB72F-EF52-49CB-BAE3-98155BFB779D}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{D59460FF-C977-4E97-A43C-DA76F3B0D667}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-dede-downloader.exe |
"{DA7EAB66-34A3-48E8-80AB-0EE2C00DA9A2}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-203 |
"{FA7E3FAF-65AB-4FE7-A0BC-695663126363}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{FBDF0C94-1F23-46D3-B428-6DFCA83FDAFB}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0-dede-downloader.exe |
"{FFCB80E1-3299-4E89-93D7-2045FFA4360B}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"TCP Query User{474F029F-F08A-4C84-B809-914F090CC47D}C:\program files\steam\steamapps\valtanator\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\valtanator\counter-strike source\hl2.exe |
"TCP Query User{4F694A95-3202-45BE-ACD9-BCD7C42022CD}C:\program files\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire\xfire.exe |
"TCP Query User{85BE16B1-CE0A-48E7-A34E-F1A57677EE90}C:\users\pingchanger\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\pingchanger\program files\dna\btdna.exe |
"TCP Query User{B8431452-24EA-4EDF-AF4B-8FAB988AAC6F}C:\program files\steam\steamapps\valtanator\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\valtanator\counter-strike source\hl2.exe |
"TCP Query User{BA506B42-4864-4D32-B233-CD9E91AB60FF}C:\users\pingchanger\saved games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\pingchanger\saved games\world of warcraft\launcher.exe |
"TCP Query User{CD5249D0-7BDB-4A9B-9D24-B16BD028A291}C:\users\pingchanger\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\pingchanger\program files\dna\btdna.exe |
"TCP Query User{D3487283-7CF8-493F-BD42-0EACE8B20F28}C:\program files\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire\xfire.exe |
"TCP Query User{E22A4628-9FDE-4D7C-AE54-339E940B37B6}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{27872218-0656-40B9-A443-7386EBDC44C2}C:\users\pingchanger\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\pingchanger\program files\dna\btdna.exe |
"UDP Query User{2B8D8BCF-CB2F-4C6F-B5F6-373E41E9251B}C:\users\pingchanger\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\pingchanger\program files\dna\btdna.exe |
"UDP Query User{468A4294-9B6D-4A3F-B9F5-9649421551CB}C:\program files\steam\steamapps\valtanator\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\valtanator\counter-strike source\hl2.exe |
"UDP Query User{5B0CE63E-1706-45E9-B7E4-7C1ED73A3658}C:\users\pingchanger\saved games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\pingchanger\saved games\world of warcraft\launcher.exe |
"UDP Query User{BEB249BC-8098-418B-A7B7-1F66C995503F}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{BF112310-029E-417F-994C-2145BC804B24}C:\program files\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files\xfire\xfire.exe |
"UDP Query User{C62335CF-78AD-42DD-9D31-A27747C9946F}C:\program files\steam\steamapps\valtanator\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\valtanator\counter-strike source\hl2.exe |
"UDP Query User{E23E26C5-1D51-4A44-B41C-71D566B7A6D2}C:\program files\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files\xfire\xfire.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{024CEFCD-E521-56D5-658F-ADF044846CF0}" = ccc-core-static
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0C11EA82-8E49-FB7D-4F79-7EDB6C826215}" = CCC Help English
"{1BF6531D-6A30-35DF-0C2D-DD4CFC2E4149}" = ccc-utility
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java(TM) 6 Update 17
"{288B75D7-08F0-8E9B-8C65-AEF18AF3E486}" = ATI Catalyst Install Manager
"{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}" = Die Schlacht um Mittelerde™ II
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{741FBF89-C33D-D6F7-814E-F60CBDDA915C}" = Catalyst Control Center Graphics Previews Vista
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7ECD470E-E0E3-B649-0C1D-91EB549689A3}" = Catalyst Control Center Graphics Previews Common
"{7EE873AF-46BB-4B5D-BA6F-CFE4B0566E22}" = TuneUp Utilities Language Pack (de-DE)
"{81CD6232-10F5-4832-B3DA-1B88B1571031}" = Nero 7 Essentials
"{88976C62-2B62-FFA0-52CF-272094FD5A9C}" = Catalyst Control Center InstallProxy
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{8A713DCA-792C-F4B0-8EA6-2142C2F88C05}" = Catalyst Control Center Localization German
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{94D66D71-12F0-48A5-B46A-D4B835A0F1B7}" = FirstSteps Diagnostics
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{99E862CC-6F69-4D39-99AA-DBF71BF3B585}" = OpenOffice.org 3.1
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A4055555-C23C-8945-934F-5DD64E632429}" = CCC Help German
"{A434533D-989F-0440-1D1F-A784F64E15F3}" = HydraVision
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AC76BA86-7AD7-1031-7B44-A91000000001}" = Adobe Reader 9.1.3 - Deutsch
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4C08007-598E-8CE0-4161-01078860235B}" = Skins
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser
"{C8DF44AC-B758-967A-E48C-9B352D4B6545}" = Catalyst Control Center Graphics Full Existing
"{CB84FC3F-5A5D-7E1D-0116-5803F58844ED}" = Catalyst Control Center Graphics Light
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities
"{E397F6F0-AEE4-4236-BB05-1351350F8365}" = War Rock
"{E9C13FD7-6D55-F919-E0BD-A02A2E1404F2}" = Catalyst Control Center Graphics Full New
"{EB1B8449-CD8F-485B-ADB6-02FBCFE180D3}" = Razer DeathAdder(TM) Mouse
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6D4FD3F-5C79-331D-1807-5B1480A1D98D}" = Catalyst Control Center HydraVision Full
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{FA3A247D-437A-455E-A88F-7EB6E5F9E799}" = Catalyst Control Center - Branding
"{FAE4CD9E-9EFD-A24B-296F-F6D4DF4C15D1}" = Catalyst Control Center Core Implementation
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"C-Media CM106 Like Sound Driver" = C-Media CM106 Like Sound Device
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"EPSON Printer and Utilities" = EPSON-Drucker-Software
"EPSON Scanner" = EPSON Scan
"Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition 2.0.0.1 (D)
"Hamachi" = Hamachi 1.0.3.0
"HijackThis" = HijackThis 2.0.2
"MAGIX Foto Manager 2007 D" = MAGIX Foto Manager 2007 4.2.0.79 (D)
"MAGIX Media Suite D" = MAGIX Media Suite 1.12.0.89 (D)
"MAGIX Music Manager 2007 D" = MAGIX Music Manager 2007 8.2.0.144 (D)
"MAGIX Online Druck Service D" = MAGIX Online Druck Service 2.3.2.0 (D)
"MAGIX Ringtone Maker SE D" = MAGIX Ringtone Maker SE 3.1.0.4 (D)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)
"NVIDIA Drivers" = NVIDIA Drivers
"SHOUTcast Radio Toolbar" = SHOUTcast Radio Toolbar
"SHOUTcastDSP" = SHOUTcast Source DSP 1.9.1 (remove only)
"Steam App 240" = Counter-Strike: Source
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"TeamViewer 4" = TeamViewer 4
"TuneUp Utilities" = TuneUp Utilities
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"Winamp" = Winamp
"WinGimp-2.0_is1" = GIMP 2.6.7
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"World of Warcraft" = World of Warcraft
"Xfire" = Xfire (remove only)
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent DNA" = DNA
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 07.11.2009 17:27:06 | Computer Name = PingChanGeR-PC | Source = Application Hang | ID = 1002
Description = Programm WarRock.exe, Version 0.0.0.0 arbeitet nicht mehr mit Windows
 zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen
 für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem
 zu suchen.  Prozess-ID: 11b8  Anfangszeit: 01ca5fe9e20095de  Zeitpunkt der Beendigung:
 222
 
Error - 09.11.2009 18:32:42 | Computer Name = PingChanGeR-PC | Source = EventSystem | ID = 4621
Description =
 
Error - 13.11.2009 08:51:04 | Computer Name = PingChanGeR-PC | Source = WindowsLiveMessenger | ID = 15728647
Description =
 
Error - 13.11.2009 08:51:04 | Computer Name = PingChanGeR-PC | Source = WindowsLiveMessenger | ID = 15728647
Description =
 
Error - 14.11.2009 11:51:25 | Computer Name = PingChanGeR-PC | Source = WindowsLiveMessenger | ID = 15728647
Description =
 
Error - 14.11.2009 11:51:25 | Computer Name = PingChanGeR-PC | Source = WindowsLiveMessenger | ID = 15728647
Description =
 
Error - 14.11.2009 13:21:17 | Computer Name = PingChanGeR-PC | Source = WindowsLiveMessenger | ID = 15728647
Description =
 
Error - 14.11.2009 13:21:38 | Computer Name = PingChanGeR-PC | Source = WindowsLiveMessenger | ID = 15728647
Description =
 
Error - 15.11.2009 07:06:33 | Computer Name = PingChanGeR-PC | Source = EventSystem | ID = 4621
Description =
 
Error - 15.11.2009 18:49:36 | Computer Name = PingChanGeR-PC | Source = EventSystem | ID = 4621
Description =
 
[ System Events ]
Error - 06.10.2009 15:26:38 | Computer Name = PingChanGeR-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 06.10.2009 um 21:25:05 unerwartet heruntergefahren.
 
Error - 07.10.2009 13:36:10 | Computer Name = PingChanGeR-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 07.10.2009 um 19:35:06 unerwartet heruntergefahren.
 
Error - 07.10.2009 13:42:26 | Computer Name = PingChanGeR-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 07.10.2009 um 19:41:02 unerwartet heruntergefahren.
 
Error - 07.10.2009 14:24:54 | Computer Name = PingChanGeR-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 07.10.2009 um 20:22:18 unerwartet heruntergefahren.
 
Error - 08.10.2009 07:30:53 | Computer Name = PingChanGeR-PC | Source = DCOM | ID = 10010
Description =
 
Error - 08.10.2009 08:51:36 | Computer Name = PingChanGeR-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 08.10.2009 um 14:42:48 unerwartet heruntergefahren.
 
Error - 08.10.2009 14:19:21 | Computer Name = PingChanGeR-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 08.10.2009 um 20:17:28 unerwartet heruntergefahren.
 
Error - 09.10.2009 05:50:54 | Computer Name = PingChanGeR-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 09.10.2009 um 11:49:25 unerwartet heruntergefahren.
 
Error - 09.10.2009 05:51:20 | Computer Name = PingChanGeR-PC | Source = Server | ID = 2505
Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht
 \Device\NetBT_Tcpip_{EB785E70-0C19-4C66-8BCA-229237954D47} vom Serverdienst nicht
 gebunden werden. Der Serverdienst konnte nicht gestartet werden.
 
Error - 09.10.2009 13:52:12 | Computer Name = PingChanGeR-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 09.10.2009 um 19:50:45 unerwartet heruntergefahren.
 
 
< End of report >


crippcid 20.11.2009 17:12

Noch eine kleine Frage: Kann es sein, dass ich mit diesem Vorgang i-welche Treiber ausgestellt habe? Merke nämlich, dass die Sondertasten meiner Maus nicht mehr funktionieren. (:

Angel21 20.11.2009 19:20

Hast Du eine Windows CD?

start --> ausführen (Vista User: suche starten) --> notepad (reinschreiben)
Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
Code:

@echo off
cd \
copy C:\Windows\System32\DriverStore\FileRepository\viprt.inf_86543378\ViPrt.sys C:\

Speichere diese unter service.bat auf Deinem Desktop.
Wähle bei Dateityp alle Dateien aus.
Bei Codierung bitte ANSI auswählen.
Doppelklick auf die service.bat
Vista- User: Mit Rechtsklick "als Administrator starten" ausführen.

......................................................................................................................

Anleitung Avenger (by swandog46)

Lade dir das Tool Hopsassa und speichere es auf dem Desktop:
  • Kopiere nun folgenden Text in das weiße Feld bei -> "input script here"
Code:

Files to move:
C:\ViPrt.sys | C:\Windows\System32\drivers\ViPrt.sys

http://saved.im/mzi3ndg3nta0/aven.jpg
  • Schliesse nun alle Programme und Browser-Fenster
  • Um den Avenger zu starten klicke auf -> Execute
  • Dann bestätigen mit "Yes" das der Rechner neu startet
  • Nachdem das System neu gestartet ist, findest du einen Report vom Avenger unter -> C:\avenger.txt
  • Öffne die Datei mit dem Editor und kopiere den gesamten Text in deinen Beitrag hier am Trojaner-Board.

crippcid 20.11.2009 19:28

Falls du diese RecoveryCDs meinst; Ja, die hab ich (:

Hier der Log:

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows Vista

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: could not move file "C:\ViPrt.sys"
File move operation "C:\ViPrt.sys|C:\Windows\System32\drivers\ViPrt.sys" failed!
Status: 0xc0000022 (STATUS_ACCESS_DENIED)


Completed script processing.

*******************

Finished! Terminate.

Angel21 20.11.2009 19:29

Hast du auch die Batch Datei ausgeführt? Also bevor Du Avenger startest.

crippcid 20.11.2009 19:31

Jap, hab ich. Ist es auch normal, dass die dann nur so 0,2sek. offen bleibt? :)

Angel21 20.11.2009 19:32

Ja. Batches sind nur kleine Datein.

crippcid 20.11.2009 19:33

Jap. Dann hat das so gepasst, hab ich auf jeden Fall vorher ausgeführt

Angel21 20.11.2009 19:52

Hast du in C:\ die sys Datei drinne?

crippcid 20.11.2009 19:54

Die was hab ich in C:\ ? Du weisst doch vllt. noch vom letzten mal, dass ich mich nicht soooo top auskenne :P

Angel21 20.11.2009 19:57

Zitat:

C:\ViPrt.sys
Schau ma nach, ob Du dies findest unter C was in der Box vorhanden ist.

crippcid 20.11.2009 19:58

Ja genau. gefunden.

Angel21 20.11.2009 20:07

Da du Vista User bist: CCleaner und Combofix per Rechtsklick -> "Ausführen Als Administrator" starten.


ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir das Tool hier herunter auf den Desktop -> KLICK
Wichtig! Bitte die combofix.exe per Rechtsklick, "Ziel speichern unter" unter smss.exe abspeichern!
Besonders hartnäckige Malware erkennt eine combofix.exe und würde sich vor ihr gezielt verstecken!


Das Programm jedoch noch nicht starten sondern zuerst folgendes tun:
  • Schliesse alle Anwendungen und Programme, vor allem deine Antiviren-Software und andere Hintergrundwächter, sowie deinen Internetbrowser.
    Vermeide es auch explizit während das Combofix läuft die Maus und Tastatur zu benutzen.
  • Starte nun die in smss.exe umbenannte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen und lass dein System durchsuchen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte abkopieren und in deinen Beitrag einfügen. Das log findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.
Hinweis: Combofix verhindert die Autostart Funktion aller CD / DVD und USB - Laufwerken um so eine Verbeitung einzudämmen. Wenn es hierdurch zu Problemen kommt, diese im Thread posten.

Poste alle Logfiles bitte mit Codetags umschlossen (#-Button) also so:

HTML-Code:

[code] Hier das Logfile rein! [/code]

crippcid 20.11.2009 20:37

Code:

ComboFix 09-11-20.01 - PingChanGeR 20.11.2009 20:24.1.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.2046.1071 [GMT 1:00]
ausgeführt von:: c:\users\PingChanGeR\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: AntiVir Desktop *enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: Windows-Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-3063004517-2785690171-23646899-500
c:\windows\system32\drivers\pciide.sys

Infizierte Kopie von c:\windows\System32\drivers\ViPrt.sys wurde gefunden und desinfiziert
Kopie von - Kitty ate it :p wurde wiederhergestellt
.
(((((((((((((((((((((((  Dateien erstellt von 2009-10-20 bis 2009-11-20  ))))))))))))))))))))))))))))))
.

2009-11-20 19:13 . 2009-11-20 19:13        --------        d-----w-        c:\program files\CCleaner
2009-11-20 18:22 . 2007-03-26 13:26        52224        ----a-w-        C:\ViPrt.sys
2009-11-20 17:03 . 2009-11-20 17:03        --------        d-----w-        c:\program files\Razer
2009-11-20 17:03 . 2009-11-20 17:03        --------        d-----w-        c:\users\PingChanGeR\AppData\Roaming\InstallShield
2009-11-20 15:50 . 2009-11-20 15:50        4096        d-----w-        c:\program files\ICQ6Toolbar
2009-11-20 15:50 . 2009-11-20 15:50        --------        d-----w-        c:\programdata\ICQ
2009-11-19 18:42 . 2009-11-19 18:42        --------        d-----w-        c:\users\PingChanGeR\AppData\Roaming\Malwarebytes
2009-11-19 18:41 . 2009-09-10 13:54        38224        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-19 18:41 . 2009-11-19 18:41        --------        d-----w-        c:\programdata\Malwarebytes
2009-11-19 18:41 . 2009-09-10 13:53        19160        ----a-w-        c:\windows\system32\drivers\mbam.sys
2009-11-19 18:41 . 2009-11-19 18:42        4096        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2009-11-19 17:54 . 2009-11-19 17:54        --------        d-----w-        c:\program files\Trend Micro
2009-11-17 23:22 . 2009-11-17 23:22        --------        d-----w-        c:\program files\Windows Portable Devices
2009-11-17 19:02 . 2009-10-01 01:02        30208        ----a-w-        c:\windows\system32\WPDShextAutoplay.exe
2009-11-17 19:02 . 2009-10-01 01:02        31232        ----a-w-        c:\windows\system32\BthMtpContextHandler.dll
2009-11-17 19:02 . 2009-10-01 01:01        81920        ----a-w-        c:\windows\system32\wpdbusenum.dll
2009-11-17 19:02 . 2009-10-01 01:01        60928        ----a-w-        c:\windows\system32\PortableDeviceConnectApi.dll
2009-11-17 19:02 . 2009-10-01 01:02        2537472        ----a-w-        c:\windows\system32\wpdshext.dll
2009-11-17 19:02 . 2009-10-01 01:02        334848        ----a-w-        c:\windows\system32\PortableDeviceApi.dll
2009-11-17 19:02 . 2009-10-01 01:02        87552        ----a-w-        c:\windows\system32\WPDShServiceObj.dll
2009-11-17 19:02 . 2009-10-01 01:01        546816        ----a-w-        c:\windows\system32\wpd_ci.dll
2009-11-17 19:02 . 2009-10-01 01:01        160256        ----a-w-        c:\windows\system32\PortableDeviceTypes.dll
2009-11-17 19:02 . 2009-10-01 01:01        350208        ----a-w-        c:\windows\system32\WPDSp.dll
2009-11-17 19:02 . 2009-10-01 01:01        196608        ----a-w-        c:\windows\system32\PortableDeviceWMDRM.dll
2009-11-17 19:02 . 2009-10-01 01:01        100864        ----a-w-        c:\windows\system32\PortableDeviceClassExtension.dll
2009-11-17 19:01 . 2009-10-08 21:08        555520        ----a-w-        c:\windows\system32\UIAutomationCore.dll
2009-11-17 19:01 . 2009-10-08 21:08        234496        ----a-w-        c:\windows\system32\oleacc.dll
2009-11-17 19:01 . 2009-10-08 21:07        4096        ----a-w-        c:\windows\system32\oleaccrc.dll
2009-11-11 12:16 . 2009-08-14 13:27        2036736        ----a-w-        c:\windows\system32\win32k.sys
2009-11-11 12:16 . 2009-08-10 12:35        355328        ----a-w-        c:\windows\system32\WSDApi.dll
2009-11-06 21:22 . 2009-11-14 06:34        4096        d-----w-        c:\users\PingChanGeR\AppData\Local\WarRockDF
2009-11-06 20:38 . 2009-11-06 20:38        --------        d-----w-        c:\users\PingChanGeR\Program Files
2009-11-06 20:12 . 2009-11-06 20:12        --------        d-----w-        c:\users\PingChanGeR\AppData\Local\DNA
2009-11-06 20:12 . 2009-11-20 19:23        4096        d-----w-        c:\users\PingChanGeR\AppData\Roaming\DNA
2009-11-06 20:12 . 2009-11-06 20:12        --------        d-----w-        c:\program files\DNA
2009-11-06 20:12 . 2009-11-18 11:58        --------        d-----w-        c:\program files\GamersFirst
2009-11-04 15:59 . 2009-10-30 13:34        29512        ----a-w-        c:\windows\system32\TURegOpt.exe
2009-11-04 15:59 . 2009-10-30 13:27        21320        ----a-w-        c:\windows\system32\authuitu.dll
2009-11-04 15:59 . 2009-10-30 13:27        30024        ----a-w-        c:\windows\system32\uxtuneup.dll
2009-11-04 15:58 . 2009-11-04 15:58        --------        d-----w-        c:\users\PingChanGeR\AppData\Roaming\TuneUp Software
2009-11-04 15:58 . 2009-11-04 15:59        49152        d-----w-        c:\program files\TuneUp Utilities 2010
2009-11-04 15:58 . 2009-11-04 15:58        --------        d-----w-        c:\programdata\TuneUp Software
2009-11-04 15:57 . 2009-11-04 15:57        --------        d-sh--w-        c:\programdata\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-11-03 15:12 . 2009-11-03 23:39        --------        d-----w-        c:\users\PingChanGeR\AppData\Roaming\Xfire
2009-11-03 15:12 . 2009-11-03 15:14        4096        d-----w-        c:\programdata\Xfire
2009-11-03 15:12 . 2009-11-03 15:12        8192        d-----w-        c:\program files\Xfire
2009-10-28 12:20 . 2009-09-10 14:58        310784        ----a-w-        c:\windows\system32\unregmp2.exe
2009-10-28 12:20 . 2009-09-10 14:59        8147456        ----a-w-        c:\windows\system32\wmploc.DLL
2009-10-21 19:42 . 2009-11-02 21:13        --------        d-----w-        c:\program files\Common Files\Steam
2009-10-21 19:42 . 2009-11-06 00:57        8192        d-----w-        c:\program files\Steam

.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-20 19:30 . 2006-11-02 15:33        618204        ----a-w-        c:\windows\system32\perfh007.dat
2009-11-20 19:30 . 2006-11-02 15:33        122442        ----a-w-        c:\windows\system32\perfc007.dat
2009-11-20 18:24 . 2009-09-15 18:17        4096        d-----w-        c:\users\PingChanGeR\AppData\Roaming\Skype
2009-11-20 18:12 . 2009-09-15 18:18        4096        d-----w-        c:\users\PingChanGeR\AppData\Roaming\skypePM
2009-11-20 17:03 . 2007-10-16 20:42        4096        d--h--w-        c:\program files\InstallShield Installation Information
2009-11-17 23:22 . 2006-11-02 10:25        665600        ----a-w-        c:\windows\inf\drvindex.dat
2009-11-17 23:22 . 2009-11-17 23:22        0        ---ha-w-        c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-12 16:48 . 2006-11-02 11:18        4096        d-----w-        c:\program files\Windows Mail
2009-11-09 17:11 . 2009-09-30 12:10        --------        d-----w-        c:\program files\Java
2009-11-04 15:59 . 2006-11-02 12:37        4096        d-----w-        c:\program files\Windows Sidebar
2009-11-02 19:42 . 2009-10-02 23:56        195456        ------w-        c:\windows\system32\MpSigStub.exe
2009-10-17 00:26 . 2009-09-21 13:37        4096        d-----w-        c:\users\PingChanGeR\AppData\Roaming\Winamp
2009-10-15 00:01 . 2009-10-15 00:01        41872        ----a-w-        c:\windows\system32\xfcodec.dll
2009-10-13 11:48 . 2009-09-16 13:51        4096        d-----w-        c:\users\PingChanGeR\AppData\Roaming\teamspeak2
2009-10-11 13:49 . 2009-10-11 13:49        --------        d-----w-        c:\programdata\Blizzard Entertainment
2009-10-11 03:17 . 2009-09-30 12:10        411368        ----a-w-        c:\windows\system32\deploytk.dll
2009-10-08 12:19 . 2009-10-08 12:19        --------        d-----w-        c:\programdata\WindowsSearch
2009-10-07 14:09 . 2009-09-30 14:28        1        ----a-w-        c:\users\PingChanGeR\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-10-04 16:01 . 2009-10-04 16:01        --------        d-----w-        c:\program files\Electronic Arts
2009-10-02 15:42 . 2009-10-02 15:42        --------        d-----w-        c:\users\PingChanGeR\AppData\Roaming\gtk-2.0
2009-10-02 15:39 . 2009-10-02 15:39        --------        d-----w-        c:\program files\GIMP-2.0
2009-10-01 03:22 . 2009-09-15 19:30        4096        d-----w-        c:\program files\Common Files\Blizzard Entertainment
2009-09-30 19:30 . 2009-09-15 17:22        66904        ----a-w-        c:\users\PingChanGeR\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-30 14:27 . 2009-09-30 14:27        --------        d-----w-        c:\users\PingChanGeR\AppData\Roaming\OpenOffice.org
2009-09-30 12:14 . 2009-09-30 12:14        7424000        ----a-r-        c:\users\PingChanGeR\AppData\Roaming\Microsoft\Installer\{99E862CC-6F69-4D39-99AA-DBF71BF3B585}\soffice.exe
2009-09-30 12:12 . 2009-09-30 12:12        --------        d-----w-        c:\program files\JRE
2009-09-30 12:12 . 2009-09-30 12:11        4096        d-----w-        c:\program files\OpenOffice.org 3
2009-09-27 20:04 . 2009-09-27 20:04        --------        d-----w-        c:\program files\Microsoft
2009-09-27 20:03 . 2009-09-27 20:03        --------        d-----w-        c:\program files\Windows Live
2009-09-27 20:03 . 2009-09-27 20:03        --------        d-----w-        c:\program files\Windows Live SkyDrive
2009-09-27 20:01 . 2009-09-27 20:01        --------        d-----w-        c:\program files\Common Files\Windows Live
2009-09-26 19:52 . 2009-09-17 15:44        4096        d-----w-        c:\program files\Winamp
2009-09-26 19:52 . 2009-09-26 19:52        4096        d-----w-        c:\program files\SHOUTcast Radio Toolbar
2009-09-26 19:52 . 2009-09-26 19:52        --------        d-----w-        c:\programdata\SHOUTcast Radio Toolbar
2009-09-25 23:38 . 2009-09-20 16:49        4096        d-----w-        c:\users\PingChanGeR\AppData\Roaming\Hamachi
2009-09-25 02:10 . 2009-11-17 19:03        974848        ----a-w-        c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-11-17 19:03        189440        ----a-w-        c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-11-17 19:03        321024        ----a-w-        c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-11-17 19:03        1554432        ----a-w-        c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-11-17 19:03        351232        ----a-w-        c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-11-17 19:03        847360        ----a-w-        c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-11-17 19:03        280064        ----a-w-        c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-11-17 19:03        135680        ----a-w-        c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-11-17 19:03        195584        ----a-w-        c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-11-17 19:03        829440        ----a-w-        c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-11-17 19:03        369664        ----a-w-        c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-11-17 19:03        252928        ----a-w-        c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-11-17 19:03        519680        ----a-w-        c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-11-17 19:03        486912        ----a-w-        c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-11-17 19:03        161280        ----a-w-        c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-11-17 19:03        218112        ----a-w-        c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-11-17 19:03        1030144        ----a-w-        c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-11-17 19:03        828928        ----a-w-        c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-11-17 19:03        481792        ----a-w-        c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-11-17 19:03        190464        ----a-w-        c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-11-17 19:03        634880        ----a-w-        c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-11-17 19:03        37888        ----a-w-        c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-11-17 19:03        793088        ----a-w-        c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-11-17 19:03        1064448        ----a-w-        c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-11-17 19:03        258048        ----a-w-        c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-11-17 19:03        667648        ----a-w-        c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-11-17 19:03        26112        ----a-w-        c:\windows\system32\printfilterpipelineprxy.dll
2009-09-23 16:40 . 2009-09-23 16:40        4096        d-----w-        c:\programdata\EPSON
2009-09-23 16:35 . 2009-09-23 16:35        --------        d-----w-        c:\program files\epson
2009-09-23 15:42 . 2009-09-23 15:40        12288        d-----w-        c:\program files\ICQ6.5
2009-09-23 15:42 . 2009-09-15 18:49        --------        d-----w-        c:\users\PingChanGeR\AppData\Roaming\ICQ
2009-09-22 20:19 . 2009-09-15 17:54        --------        d-----w-        c:\users\PingChanGeR\AppData\Roaming\TeamViewer
2009-09-20 16:49 . 2009-09-20 16:49        25280        ----a-w-        c:\windows\system32\drivers\hamachi.sys
2009-09-16 16:59 . 2009-09-16 16:59        0        ----a-w-        c:\windows\ativpsrm.bin
2009-09-16 15:42 . 2009-09-16 15:42        9158        ----a-r-        c:\users\PingChanGeR\AppData\Roaming\Microsoft\Installer\{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}\ARPPRODUCTICON.exe
2009-09-16 15:41 . 2009-09-16 15:41        10134        ----a-r-        c:\users\PingChanGeR\AppData\Roaming\Microsoft\Installer\{88976C62-2B62-FFA0-52CF-272094FD5A9C}\ARPPRODUCTICON.exe
2009-09-16 15:15 . 2009-09-15 17:22        680        ----a-w-        c:\users\PingChanGeR\AppData\Local\d3d9caps.dat
2009-09-16 12:14 . 2006-11-02 10:32        101888        ----a-w-        c:\windows\system32\ifxcardm.dll
2009-09-16 12:14 . 2006-11-02 10:32        82432        ----a-w-        c:\windows\system32\axaltocm.dll
2009-09-16 11:31 . 2009-09-16 11:31        6656        ----a-w-        c:\windows\system32\kbd106n.dll
2009-09-16 11:27 . 2009-09-16 11:27        72704        ----a-w-        c:\windows\system32\admparse.dll
2009-09-16 11:27 . 2009-09-16 11:27        48128        ----a-w-        c:\windows\system32\mshtmler.dll
2009-09-15 19:03 . 2009-09-15 19:03        2048        ----a-w-        c:\windows\system32\tzres.dll
2009-09-15 19:02 . 2009-09-15 19:02        61440        ----a-w-        c:\windows\system32\winipsec.dll
2009-09-15 19:02 . 2009-09-15 19:02        272896        ----a-w-        c:\windows\system32\polstore.dll
2009-09-15 18:59 . 2009-09-15 18:59        9728        ----a-w-        c:\windows\system32\TCPSVCS.EXE
2009-09-15 18:59 . 2009-09-15 18:59        8704        ----a-w-        c:\windows\system32\HOSTNAME.EXE
2009-09-15 18:59 . 2009-09-15 18:59        17920        ----a-w-        c:\windows\system32\netevent.dll
2009-09-15 18:59 . 2009-09-15 18:59        11264        ----a-w-        c:\windows\system32\MRINFO.EXE
2009-09-15 18:59 . 2009-09-15 18:59        904776        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2009-09-15 18:59 . 2009-09-15 18:59        27136        ----a-w-        c:\windows\system32\NETSTAT.EXE
2009-09-15 18:59 . 2009-09-15 18:59        19968        ----a-w-        c:\windows\system32\ARP.EXE
2009-09-15 18:59 . 2009-09-15 18:59        17920        ----a-w-        c:\windows\system32\ROUTE.EXE
2009-09-15 18:59 . 2009-09-15 18:59        105984        ----a-w-        c:\windows\system32\netiohlp.dll
2009-09-15 18:59 . 2009-09-15 18:59        10240        ----a-w-        c:\windows\system32\finger.exe
2009-09-15 18:59 . 2009-09-15 18:59        30720        ----a-w-        c:\windows\system32\drivers\tcpipreg.sys
2009-09-15 18:57 . 2009-09-15 18:57        127488        ----a-w-        c:\windows\system32\L2SecHC.dll
2009-09-15 18:57 . 2009-09-15 18:57        68096        ----a-w-        c:\windows\system32\wlanhlp.dll
2009-09-15 18:57 . 2009-09-15 18:57        65024        ----a-w-        c:\windows\system32\wlanapi.dll
2009-09-15 18:57 . 2009-09-15 18:57        513536        ----a-w-        c:\windows\system32\wlansvc.dll
2009-09-15 18:57 . 2009-09-15 18:57        302592        ----a-w-        c:\windows\system32\wlansec.dll
2009-09-15 18:57 . 2009-09-15 18:57        293376        ----a-w-        c:\windows\system32\wlanmsm.dll
2009-09-15 18:57 . 2009-09-15 18:57        15181        ----a-w-        c:\windows\system32\gatherWirelessInfo.vbs
2009-09-15 18:55 . 2009-09-15 18:55        72704        ----a-w-        c:\windows\system32\fontsub.dll
2009-09-15 18:55 . 2009-09-15 18:55        34304        ----a-w-        c:\windows\system32\atmlib.dll
2009-05-13 21:55 . 2009-05-13 21:55        1044480        ----a-w-        c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-13 21:55 . 2009-05-13 21:55        200704        ----a-w-        c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{14f0d511-36a2-41ca-ae01-ba4f87282c97}"= "c:\program files\SHOUTcast Radio Toolbar\shoutcasttb.dll" [2008-09-17 1275176]

[HKEY_CLASSES_ROOT\clsid\{14f0d511-36a2-41ca-ae01-ba4f87282c97}]
[HKEY_CLASSES_ROOT\SHOUTcastTb.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{8613efdf-b530-4b1d-b970-b09f99977813}]
[HKEY_CLASSES_ROOT\SHOUTcastTb.AOLTBSearch]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
"BitTorrent DNA"="c:\users\PingChanGeR\Program Files\DNA\btdna.exe" [2009-11-06 323392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-06-01 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-01 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-01 81920]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-26 153136]
"recinfo793"="c:\recinfo\RecInfo.exe" [2007-09-14 2768896]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-07-16 61440]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):1b,c5,ff,f3,cd,36,ca,01

R0 ViBus;ViBus;c:\windows\System32\drivers\ViBus.sys [16.10.2007 21:38 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\System32\drivers\ViPrt.sys [16.10.2007 21:38 52224]
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [15.09.2009 18:34 108289]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [24.08.2009 15:51 185640]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [30.10.2009 14:31 1021256]
R3 DAdderFltr;DeathAdder Mouse;c:\windows\System32\drivers\dadder.sys [15.09.2009 18:49 22784]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 07:24 10064]
S3 CM1063264;C-Media CM106 Like Sound UDAX Interface;c:\windows\System32\drivers\CM106.sys [17.09.2009 16:57 1307136]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [16.10.2007 21:48 1527900]
S3 FontCache;Windows-Dienst für Schriftartencache;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [16.09.2009 12:52 21504]
S3 PAC207;SoC PC-Camera;c:\windows\System32\drivers\PFC027.SYS [05.12.2006 10:34 507136]
S3 UPnPService;UPnPService;c:\program files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [16.10.2007 21:49 544768]
S3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\System32\drivers\CM106.sys [17.09.2009 16:57 1307136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
UxTuneUp
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.icq.com/skins/
IE: &SHOUTcast Search - c:\programdata\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html
DPF: {3188FB46-456D-4C07-8A11-F5F3BBBA8AF2} - hxxp://www.seetoo.com/downloadAddon.php?platform=Win32&browser=ie&ref=justintv&c=c1fd32f2323559bc3&browserVersion=7.0
FF - ProfilePath - c:\users\PingChanGeR\AppData\Roaming\Mozilla\Firefox\Profiles\gsd41ghb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50-ff-shoutcast-chromesbox-en-us&query=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - www.google.de
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=skin&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\users\PingChanGeR\AppData\Roaming\Mozilla\Firefox\Profiles\gsd41ghb.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\users\PingChanGeR\AppData\Roaming\Mozilla\Firefox\Profiles\gsd41ghb.default\extensions\{12e4c684-c03e-4e4d-85bc-0c065e7a9489}\components\WinampPlayer.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\PingChanGeR\AppData\Roaming\Mozilla\Firefox\Profiles\gsd41ghb.default\extensions\seetooaddon@seetoo.com\plugins\npSeeTooAddon.dll
FF - plugin: c:\users\PingChanGeR\Program Files\DNA\plugins\npbtdna.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX Richtlinien ----

FF - user.js: browser.sessionstore.resume_from_crash - false
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -

HKLM-Run-Cm106Sound - cm106.cpl



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-20 20:33
Windows 6.0.6002 Service Pack 2 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostarteinträge...

Scanne versteckte Dateien...

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************
.
Zeit der Fertigstellung: 2009-11-20 20:35
ComboFix-quarantined-files.txt  2009-11-20 19:35

Vor Suchlauf: 17 Verzeichnis(se), 113.032.888.320 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 112.995.151.872 Bytes frei

- - End Of File - - AE55A549FA2E816ED7D70EABC97D7001


Angel21 20.11.2009 20:47

Neues Gmer Log bitte erstellen.

crippcid 20.11.2009 20:58

Also.. ich habs 2x probiert. beim 1. Versuch hat sich das Programm aufgehängt und Bluescreen. Beim 2. Mal konnte ich mir merken wo, weil's beim 1. mal das selbe war.

Code:

C:\harddisk\VolumeShadowCopy1
Das dürft die stelle gewesen sein. bin mir nicht sicher wegen groß- und kleinschreibung.

Angel21 20.11.2009 21:31

Rootkitscan mit RootRepeal
  • Gehe hierhin, scrolle runter und downloade RootRepeal.zip.
  • Entpacke die Datei auf Deinen Desktop.
  • Doppelklicke die RootRepeal.exe, um den Scanner zu starten.
  • Klicke auf den Reiter Report und dann auf den Button Scan.
  • Mache einen Haken bei den folgenden Elementen und klicke Ok.
    .
    Drivers
    Files
    Processes
    SSDT
    Stealth Objects
    Hidden Services

    .
  • Im Anschluss wirst Du gefragt, welche Laufwerke gescannt werden sollen.
  • Wähle C:\ und klicke wieder Ok.
  • Der Suchlauf beginnt automatisch, es wird eine Weile dauern, bitte Geduld.
  • Wenn der Suchlauf beendet ist, klicke auf Save Report.
  • Speichere das Logfile als RootRepeal.txt auf dem Desktop.
  • Kopiere den Inhalt hier in den Thread.

crippcid 20.11.2009 21:45

Der Log:

Code:

ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time:                2009/11/20 21:34
Program Version:                Version 1.3.5.0
Windows Version:                Windows Vista SP2
==================================================

Drivers
-------------------
Name: dump_ViPrt.sys
Image Path: C:\Windows\System32\Drivers\dump_ViPrt.sys
Address: 0x8C5BE000        Size: 65536        File Visible: No        Signed: -
Status: -

Name: fxlyiaob.sys
Image Path: C:\Users\PINGCH~1\AppData\Local\Temp\fxlyiaob.sys
Address: 0x977A6000        Size: 91008        File Visible: No        Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x977BD000        Size: 49152        File Visible: No        Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\Documents and Settings
Status: Locked to the Windows API!

Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: C:\ProgramData\Application Data
Status: Locked to the Windows API!

Path: C:\ProgramData\Desktop
Status: Locked to the Windows API!

Path: C:\ProgramData\Documents
Status: Locked to the Windows API!

Path: C:\ProgramData\Favorites
Status: Locked to the Windows API!

Path: C:\ProgramData\Start Menu
Status: Locked to the Windows API!

Path: C:\ProgramData\Templates
Status: Locked to the Windows API!

Path: C:\System Volume Information\{06c263e8-d602-11de-9079-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{11212179-ca8a-11de-bea0-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{13d1aec3-d549-11de-9d1b-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{1e228749-d50e-11de-8fc2-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{20e974c2-d374-11de-abaa-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{213cc886-cebb-11de-bfbd-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{28a74ec2-cb14-11de-8912-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{2bb0d9d7-d5f6-11de-ba02-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{976ea9d1-d50f-11de-b203-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{bfa278e8-d504-11de-9c18-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{cc8e0142-d5ce-11de-b0c4-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{cc8e0146-d5ce-11de-b0c4-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{cc8e014a-d5ce-11de-b0c4-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{e17c2868-d5f6-11de-9946-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{e2ac8842-c965-11de-94ac-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{e589fbc2-cdf1-11de-bd93-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{ff223949-cd46-11de-8b48-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{382896cc-cb18-11de-aa51-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{4d4080d3-d056-11de-b7c4-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{59e312d1-d38f-11de-9de5-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{5c1e2950-cfab-11de-af74-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{645c9d0a-d142-11de-95a6-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{7299e978-cc5e-11de-88d6-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{86102542-cf84-11de-8845-0019dbf9b2a5}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\Users\All Users
Status: Locked to the Windows API!

Path: C:\Users\Default User
Status: Locked to the Windows API!

Path: C:\Users\Default\Application Data
Status: Locked to the Windows API!

Path: C:\Users\Default\Cookies
Status: Locked to the Windows API!

Path: C:\Users\Default\Local Settings
Status: Locked to the Windows API!

Path: C:\Users\Default\My Documents
Status: Locked to the Windows API!

Path: C:\Users\Default\NetHood
Status: Locked to the Windows API!

Path: C:\Users\Default\PrintHood
Status: Locked to the Windows API!

Path: C:\Users\Default\Recent
Status: Locked to the Windows API!

Path: C:\Users\Default\SendTo
Status: Locked to the Windows API!

Path: C:\Users\Default\Start Menu
Status: Locked to the Windows API!

Path: C:\Users\Default\Templates
Status: Locked to the Windows API!

Path: C:\Users\Default\Documents\My Music
Status: Locked to the Windows API!

Path: C:\Users\Default\Documents\My Pictures
Status: Locked to the Windows API!

Path: C:\Users\Default\Documents\My Videos
Status: Locked to the Windows API!

Path: C:\Users\PingChanGeR\Downloads\PIEPC-~1.AVI:Zone.Identifier
Status: Visible to the Windows API, but not on disk.

Path: C:\Users\PingChanGeR\Downloads\Step Up.avi:Zone.Identifier
Status: Visible to the Windows API, but not on disk.

Path: C:\Users\Public\Documents\My Music
Status: Locked to the Windows API!

Path: C:\Users\Public\Documents\My Pictures
Status: Locked to the Windows API!

Path: C:\Users\Public\Documents\My Videos
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_ecdf8c290e547f39.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_818f59bf601aa775.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_81c25f21d3d46d84.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_b7e00e6c7b30b69b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_f0efb442f8a0f46c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_dc990e4797f81af1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_a6dea5dc0ea08098.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_365945b9da656e4d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df56e60dc5df.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_54c11df268b7c6d9.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003bc63e949f6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_7658964504b9f3b6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_7dd1e0ebd6590e0b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_8550c6b5d18a9128.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_58b19c2866332652.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_58843c41d2730d3f.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_0e9c2a8d74fd3ce6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.1.microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_8b7b15c031cda6db.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_4ddfc6cd11929a02.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_d6c3e7af9bae13a2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_7ab8cc63a6e4c2a3.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9849.0_none_b7e911727b2899b7.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a620671dde41.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_45e008191e507087.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_51ca66a2bbe76806.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9849.0_none_a6e7a8e20e9863b4.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\a2f948df89c5a4090fb47a74b09ed39300f3a2d09a1cd13212bee8c7ee928959.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\9f4b272407008a230979f286064e895aa72cac13cd57d536a67ea34c9dd91a2c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\f3c343567eb07e928a24a5c8b8bf732a5523d0acd4762015ba309f48255a5baf.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-p..ting-spooler-client_31bf3856ad364e35_6.0.6002.18005_none_95196f2b15cf9bd2\$$DeleteMe.winspool.drv.01ca67dcdffc299e.0006
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-oleacc_31bf3856ad364e35_6.0.6001.18000_none_6a84bdce2263bb83\$$DeleteMe.oleacc.dll.01ca67dcdd0d24e0.0000
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SEC543~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE0F57~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE7561~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE4BA2~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE5F3C~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE5FBC~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE6DB5~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SEC6C7~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE9AEB~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE4F78~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE427A~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE9942~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE3B5D~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE54EE~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE5DF7~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-s..ent-sku-homepremium_31bf3856ad364e35_6.0.6002.18005_none_3d90d406f6a60fcd\SE1FB8~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_policy.1.2.microsof..op.security.azroles_31bf3856ad364e35_6.0.6000.16386_none_ea83414c2e75b887\Microsoft.Interop.Security.AzRoles.config
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-busenumservice_31bf3856ad364e35_6.0.6001.18000_none_77fe3055cc02641a\$$DeleteMe.wpdbusenum.dll.01ca67dcdee5367c.0002
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_presentationcore_31bf3856ad364e35_6.0.6002.18005_none_ae1c8b4b8d1614c8\PRESEN~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-oleaccrc_31bf3856ad364e35_6.0.6000.16386_none_76f32d528a780cf2\$$DeleteMe.oleaccrc.dll.01ca67dcdd0f873a.0001
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6002.18005_none_4cec3f51e92bbb79\$$DeleteMe.PortableDeviceApi.dll.01ca67dcdf3b0b24.0005
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6002.18005_none_4cec3f51e92bbb79\$$DeleteMe.PortableDeviceClassExtension.dll.01ca67dcdf2333a0.0004
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6002.18005_none_4cec3f51e92bbb79\$$DeleteMe.PortableDeviceTypes.dll.01ca67dcdf19aa38.0003
Status: Locked to the Windows API!

Path: C:\Users\Default\AppData\Local\Application Data
Status: Locked to the Windows API!

Path: C:\Users\Default\AppData\Local\History
Status: Locked to the Windows API!

Path: C:\Users\Default\AppData\Local\Temporary Internet Files
Status: Locked to the Windows API!

Path: C:\Users\PingChanGeR\AppData\Local\temp\flaF77D.tmp
Status: Invisible to the Windows API!

Path: C:\Users\PingChanGeR\AppData\Local\temp\fla2C10.tmp
Status: Visible to the Windows API, but not on disk.

Path: C:\Windows\assembly\GAC_32\Policy.1.2.Microsoft.Interop.Security.AzRoles\6.0.6000.16386__31bf3856ad364e35\Microsoft.Interop.Security.AzRoles.config
Status: Locked to the Windows API!

Path: C:\Windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PRESEN~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PRESEN~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SEC543~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE0F57~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE7561~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE427A~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE3B5D~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE54EE~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE1FB8~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE9942~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE4BA2~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE5F3C~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SECURI~4.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE5FBC~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE5DF7~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE6DB5~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SEC6C7~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SECURI~2.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE9AEB~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\System32\licensing\skus\Security-Licensing-SLC-Component-SKU-HomePremium\SE4F78~1.XRM
Status: Locked to the Windows API!

Path: c:\users\pingchanger\appdata\local\microsoft\windows live contacts\{466d247d-9c8d-4f2f-84c6-5e9ed0ff887c}\dbstore\tempedb.edb
Status: Allocation size mismatch (API: 262144, Raw: 131072)

Path: c:\users\pingchanger\appdata\local\microsoft\windows live contacts\{8fd3ab33-13b2-4431-8a4a-ad25e05bd524}\dbstore\tempedb.edb
Status: Allocation size mismatch (API: 262144, Raw: 131072)

Path: c:\users\pingchanger\appdata\local\mozilla\firefox\profiles\gsd41ghb.default\cache\_cache_001_
Status: Allocation size mismatch (API: 1310720, Raw: 1179648)

Path: c:\users\pingchanger\appdata\local\mozilla\firefox\profiles\gsd41ghb.default\cache\_cache_002_
Status: Allocation size mismatch (API: 1310720, Raw: 1245184)

Path: c:\users\pingchanger\appdata\local\mozilla\firefox\profiles\gsd41ghb.default\cache\_cache_003_
Status: Allocation size mismatch (API: 2359296, Raw: 2228224)

Processes
-------------------
Path: System
PID: 4        Status: Locked to the Windows API!

Path: C:\Windows\System32\audiodg.exe
PID: 1096        Status: Locked to the Windows API!

SSDT
-------------------
#: 078        Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0x966cdd74

#: 194        Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0x966cdd60

#: 201        Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0x966cdd65

#: 334        Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0x966cdd6f

Stealth Objects
-------------------
Object: Hidden Module [Name: msgsres.dll]
Process: msnmsgr.exe (PID: 3352)        Address: 0x62e30000        Size: 11403264

Object: Hidden Module [Name: msgslang.14.0.8089.0726.dll]
Process: msnmsgr.exe (PID: 3352)        Address: 0x66840000        Size: 372736

Object: Hidden Module [Name: msgrvsta.thm]
Process: msnmsgr.exe (PID: 3352)        Address: 0x70600000        Size: 20480

==EOF==


Angel21 20.11.2009 22:18

Starte nochmal Superantispyware und lass es Durchlaufen, Log hier her.

Malwarebytes bitte auch nochmal starten, durchsuchen lassen, Log hier her.

Zwischenfrage: wie geht es zur Zeit deinem PC?

Bin ab Morgen wieder da.

crippcid 21.11.2009 09:51

Ahm :) Wie es meinem PC geht? Du moment.. ich muss ihn erstmal fragen..
ne.. ähm.. läuft ganz normal wie immer UUUUUUND der Virus poppt nimmer auf :)

Angel21 21.11.2009 09:53

Trotzdem noch einige arbeitsanweisungen durchführen ;)

crippcid 21.11.2009 09:54

Joa :) Weiss ich ja noch vom letzten mal :D

Angel21 21.11.2009 10:09

Ja :)

*dir mal nen Kaffee reich* das des auch klappt ;)

crippcid 21.11.2009 10:17

ah ne danke :) Ich trink keinen Kaffee :D
Ich mach mir aber jetz was zu essen ;)

crippcid 21.11.2009 11:30

SUPERAntiSpyware Log:

Code:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/21/2009 at 11:29 AM

Application Version : 4.30.1004

Core Rules Database Version : 4300
Trace Rules Database Version: 2170

Scan type      : Complete Scan
Total Scan Time : 01:26:50

Memory items scanned      : 753
Memory threats detected  : 0
Registry items scanned    : 6497
Registry threats detected : 0
File items scanned        : 143923
File threats detected    : 6

Adware.Tracking Cookie
        C:\Users\PingChanGeR\AppData\Roaming\Microsoft\Windows\Cookies\pingchanger@atdmt[2].txt
        C:\Users\PingChanGeR\AppData\Roaming\Microsoft\Windows\Cookies\pingchanger@tracking.mindshare[1].txt
        C:\Users\PingChanGeR\AppData\Roaming\Microsoft\Windows\Cookies\pingchanger@doubleclick[2].txt
        C:\Users\PingChanGeR\AppData\Roaming\Microsoft\Windows\Cookies\pingchanger@atwola[1].txt

Trojan.Agent/Gen
        C:\USERS\PINGCHANGER\DOCUMENTS\WORLD OF WARCRAFT\WTF\ACCOUNT\PIINKI\ULTIMATE WOW FUN SERVER\GONE\SAVEDVARIABLES\BLIZZARD_TIMEMANAGER.LUA.BAK
        C:\USERS\PINGCHANGER\DOCUMENTS\WORLD OF WARCRAFT\WTF\ACCOUNT\PIINKI\ULTIMATE WOW FUN SERVER\TOXIIC\SAVEDVARIABLES\BLIZZARD_TIMEMANAGER.LUA


Angel21 21.11.2009 11:58

Schaut gut aus, alles gefundene löschen. Danach Malwarebytes nochmal ;)

crippcid 21.11.2009 12:00

Bin grad dabei^ Großer Meister oder Meisterin?

Angel21 21.11.2009 12:02

Ich war schon damals, als ich dich schonmal bearbeitet hatte w. xD

crippcid 21.11.2009 12:04

:O Das hast du niemals gesagt^^ Jetz weiss ich's aber :D Guuuuut

crippcid 21.11.2009 12:05

Zitat:

Zitat von Angel21 (Beitrag 481837)
als ich dich schonmal bearbeitet hatte

Das is gut :D *hust*

Angel21 21.11.2009 12:07

hehe....nu mach malwarebytes ;P

crippcid 21.11.2009 12:08

jaha Chefin ;) Ich kann auch net zaubern.. dauert hald.

crippcid 21.11.2009 13:37

Sodala:

Code:

Malwarebytes' Anti-Malware 1.41
Datenbank Version: 2775
Windows 6.0.6002 Service Pack 2

21.11.2009 13:37:20
mbam-log-2009-11-21 (13-37-20).txt

Scan-Methode: Vollständiger Scan (C:\|D:\|)
Durchsuchte Objekte: 239281
Laufzeit: 1 hour(s), 56 minute(s), 17 second(s)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


Angel21 21.11.2009 13:41

Deinstalliere Superantispyware bitte - mache nochmal folgende Scans:

1.) Überprüfe den Rechner mit PrevXCSI. Poste ein Screenshot falls etwas gefunden werden sollte oder poste Namen und Pfade.

2.) Panda Active Scan
Folgende Seite führt dich durch die Installation: PandaActiveScan2.0 Installation

Drücke auf Jetzt Scannen!

Eine Registrierung ist nicht erforderlich!

Nachdem der Scan abgeschlossen ist drücke auf das Text-Icon Export und speichere das log auf dem Desktop.
Öffne die Datei ActiveScan.txt die sich nun auf deinem Desktop befindet und poste uns den Inhalt.
3.) http://www.trojaner-board.de/59299-a...eb-cureit.html

4.) Rootkitsuche mit SysProt
  • Lade dir SysProt auf den Desktop und starte das Tool
  • Gehe dort auf den Reiter "Log"
  • Setze nun einen Haken bei:
    • Kernel Modules
    • Kernel Hooks
    • Hidden Files
    • Und unten bei "Hidden Objects Only"
  • Drücke nun auf "Create Log"
  • Es erscheint nach einem kurzen Scan die ein Dialogfenster. Wähle dort "Scan All Drives"
  • Wenn der Scan abgeschlossen ist, beende SysProt.
  • Poste den gesamten Inhalt der "SysProtLog.txt", die auf dem Desktop zu finden ist.

crippcid 21.11.2009 14:56

Hier Nr. 1:

Code:

;***********************************************************************************************************************************************************************************
ANALYSIS: 2009-11-21 14:56:17
PROTECTIONS: 1
MALWARE: 2
SUSPECTS: 1
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description                                  Version                      Active    Updated
;===================================================================================================================================================================================
AntiVir Desktop                                                            Yes      Yes
;===================================================================================================================================================================================
MALWARE
Id        Description                        Type                Active    Severity  Disinfectable  Disinfected Location
;===================================================================================================================================================================================
00139061  Cookie/Doubleclick                TrackingCookie      No        0        Yes            No          c:\users\pingchanger\appdata\roaming\microsoft\windows\cookies\pingchanger@doubleclick[1].txt
00262020  Cookie/Atwola                      TrackingCookie      No        0        Yes            No          c:\users\pingchanger\appdata\roaming\microsoft\windows\cookies\pingchanger@atwola[1].txt
;===================================================================================================================================================================================
SUSPECTS
Sent      Location
;===================================================================================================================================================================================
No        c:\users\pingchanger\downloads\fff-ea144.exe
;===================================================================================================================================================================================
VULNERABILITIES
Id        Severity      Description
;===================================================================================================================================================================================
;===================================================================================================================================================================================


Angel21 21.11.2009 14:59

Lade folgendes bei VirusTotal - Free Online Virus and Malware Scan hoch:
Zitat:

c:\users\pingchanger\downloads\fff-ea144.exe

crippcid 21.11.2009 15:06

Code:

a-squared        4.5.0.41        2009.11.21        Riskware.Keygen.EAGames-Multi!IK
AhnLab-V3        5.0.0.2        2009.11.20        -
AntiVir        7.9.1.72        2009.11.20        -
Antiy-AVL        2.0.3.7        2009.11.20        -
Authentium        5.2.0.5        2009.11.20        -
Avast        4.8.1351.0        2009.11.21        Win32:Trojan-gen
AVG        8.5.0.425        2009.11.21        -
BitDefender        7.2        2009.11.21        -
CAT-QuickHeal        10.00        2009.11.21        Trojan.Agent.ATV
ClamAV        0.94.1        2009.11.21        -
Comodo        2985        2009.11.21        -
DrWeb        5.0.0.12182        2009.11.21        -
eSafe        7.0.17.0        2009.11.19        Suspicious File
eTrust-Vet        35.1.7133        2009.11.20        -
F-Prot        4.5.1.85        2009.11.20        -
F-Secure        9.0.15370.0        2009.11.20        -
Fortinet        3.120.0.0        2009.11.21        -
GData        19        2009.11.21        Win32:Trojan-gen
Ikarus        T3.1.1.74.0        2009.11.21        not-a-virus.Keygen.EAGames-Multi
Jiangmin        11.0.800        2009.11.21        -
K7AntiVirus        7.10.901        2009.11.20        Trojan.Win32.Genhy
Kaspersky        7.0.0.125        2009.11.21        -
McAfee        5808        2009.11.20        -
McAfee+Artemis        5808        2009.11.20        -
McAfee-GW-Edition        6.8.5        2009.11.21        Heuristic.LooksLike.Win32.Trojan.C
Microsoft        1.5302        2009.11.21        -
NOD32        4626        2009.11.21        -
Norman        6.03.02        2009.11.21        -
nProtect        2009.1.8.0        2009.11.21        -
Panda        10.0.2.2        2009.11.21        Suspicious file
PCTools        7.0.3.5        2009.11.21        -
Prevx        3.0        2009.11.21        Medium Risk Malware
Rising        22.22.05.04        2009.11.21        -
Sophos        4.47.0        2009.11.21        -
Sunbelt        3.2.1858.2        2009.11.21        -
Symantec        1.4.4.12        2009.11.21        -
TheHacker        6.5.0.2.075        2009.11.20        -
TrendMicro        9.0.0.1003        2009.11.21        -
VBA32        3.12.12.0        2009.11.20        -
ViRobot        2009.11.20.2047        2009.11.20        -
VirusBuster        5.0.21.0        2009.11.20        -
weitere Informationen
File size: 148992 bytes
MD5...: 47447ddf16457f3b87ececbb284e79ad
SHA1..: bffb3dfc83a74755234d6e20a6cb5dfb9bde9acb
SHA256: 8f7ac2d64b5c3d597a38b6930d017fe642bc8a2027d5f97598b356c37a5b28c8
ssdeep: 3072:7ajPGiQM9b5sSJbcj1kR2TJYjcG5+37TRfS/S0dyNPDK:kGY9b51C1kR2TJ
mp6P1x0dyN7K
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1ada0
timedatestamp.....: 0x4609ad58 (Tue Mar 27 23:48:40 2007)
machinetype.......: 0x14c (I386)

( 2 sections )
name viradd virsiz rawdsiz ntrpy md5
.rdata 0x1000 0x79000 0x21a00 8.00 6e40928c4b6db1ffe544ac30421a1b39
.rsrc 0x7a000 0x3000 0x2800 5.77 d3f28c020d3bd225be17ff71b5bd9521

( 1 imports )
> kernel32.dll: LoadLibraryA, GetProcAddress, VirtualAlloc, VirtualFree

( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 EXE PECompact compressed (v2.x) (48.9%)
Win32 EXE PECompact compressed (generic) (34.4%)
Win32 Executable Generic (7.0%)
Win32 Dynamic Link Library (generic) (6.2%)
Generic Win/DOS Executable (1.6%)
<a href='http://info.prevx.com/aboutprogramtext.asp?PX5=4A2B805800C2159746FF02A9F89D6D00270D2D62' target='_blank'>http://info.prevx.com/aboutprogramtext.asp?PX5=4A2B805800C2159746FF02A9F89D6D00270D2D62</a>
packers (Kaspersky): PE_Patch.PECompact, PecBundle, PECompact
sigcheck:
publisher....: Fighting For Fun
copyright....: Copyright (c) 2003-2007 Fighting For Fun
product......: EA Games Generic Multi Keygen
description..: 144 Keygens for EA Games
original name: fff-ea144.exe
internal name: fff-ea144.exe
file version.: 2, 5, 0, 144
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned


Angel21 21.11.2009 15:08

Lade die Datei mal folgendermaßen hoch: http://www.trojaner-board.de/54791-a...ner-board.html

Mache es wie es in der Anleitung steht. :)

Angel21 21.11.2009 15:26

Du hattest diese fff......exe doch mal heruntergeladen gehabt, so wie es aussieht. Wofür ist sie denn gut? :)

crippcid 21.11.2009 15:49

Frag mich nicht.. ich glaub das war ein KeyGenerator für ein paar Spiele oder so.

Angel21 21.11.2009 16:33

Hallo,

seufz.....

Auch wenns mir hier schwer fällt, da du mir schon sympathisch bist, werde ich auch hier nicht weiter supporten. Bei Cracks und Keygens werden wir uns andere Foren nicht supporten, da dies illegal ist udn wir uns nicht der Mithilfe von Software-Diebstahl quasi schuldig amchen wollen.

Du hast eine Windows CD.
Bitte setze dein System neu auf und ändere deine Passwörter ab.

crippcid 21.11.2009 16:36

Jap. oK...


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:05 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55