| dropper.gen |  26.08.2010 01:19 |        Danke vorerst für die Antwort und Auskunft  
1. Logfile von OTL  
C:\Users\***\_\OTL  
OTL Logfile:   Code:  
 OTL logfile created on: 25.08.2010 16:51:53 - Run 1 
OTL by OldTimer - Version 3.2.10.0     Folder = C:\Users\Dursun\_ 
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation 
Internet Explorer (Version = 7.0.6001.18000) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
1.021,00 Mb Total Physical Memory | 267,00 Mb Available Physical Memory | 26,00% Memory free 
3,00 Gb Paging File | 2,00 Gb Available in Paging File | 56,00% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files 
Drive C: | 288,04 Gb Total Space | 237,84 Gb Free Space | 82,57% Space Free | Partition Type: NTFS 
Drive D: | 10,00 Gb Total Space | 0,20 Gb Free Space | 1,98% Space Free | Partition Type: NTFS 
E: Drive not present or media not loaded 
Drive F: | 465,11 Gb Total Space | 310,67 Gb Free Space | 66,80% Space Free | Partition Type: NTFS 
G: Drive not present or media not loaded 
H: Drive not present or media not loaded 
I: Drive not present or media not loaded 
Drive K: | 614,91 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF 
  
Computer Name: DURSUN-PC 
Current User Name: Dursun 
Logged in as Administrator. 
  
Current Boot Mode: Normal 
Scan Mode: Current user 
Company Name Whitelist: Off 
Skip Microsoft Files: Off 
File Age = 30 Days 
Output = Minimal 
   ========== Processes (SafeList) ========== 
  
PRC - C:\Users\Dursun\_\OTL.exe (OldTimer Tools) 
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) 
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) 
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) 
PRC - C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe (Logitech, Inc.) 
PRC - C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) 
PRC - C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.) 
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe (Western Digital) 
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (WDC) 
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC) 
PRC - C:\Sun\SDK\jdk\bin\javaw.exe (Sun Microsystems, Inc.) 
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe (Memeo) 
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) 
PRC - C:\Windows\explorer.exe (Microsoft Corporation) 
PRC - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe (Avira GmbH) 
PRC - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe (Avira GmbH) 
PRC - C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe (Avira GmbH) 
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) 
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation) 
PRC - C:\Program Files\OpenOffice.org 2.3\program\soffice.bin (OpenOffice.org) 
PRC - C:\Program Files\OpenOffice.org 2.3\program\soffice.exe (OpenOffice.org) 
PRC - C:\Program Files\Winamp\winampa.exe () 
PRC - C:\Windows\sttray.exe (SigmaTel, Inc.) 
PRC - C:\Program Files\Logitech\QuickCam10\QuickCam10.exe () 
PRC - C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe (Logitech Inc.) 
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe (Logitech Inc.) 
PRC - c:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.) 
PRC - C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe (Logitech Inc.) 
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions) 
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (Sonic Solutions) 
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation) 
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) 
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) 
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.) 
PRC - C:\Program Files\Microsoft Encarta\Encarta 2006 Enzyklopaedie DVD\EDICT.EXE (Microsoft Corporation) 
  
   ========== Modules (SafeList) ========== 
  
MOD - C:\Users\Dursun\_\OTL.exe (OldTimer Tools) 
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation) 
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation) 
MOD - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcInj.dll (Logitech Inc.) 
  
   ========== Win32 Services (SafeList) ========== 
  
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) 
SRV - (LBTServ) -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.) 
SRV - (Application Updater) -- C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.) 
SRV - (WDDMService) -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC) 
SRV - (fsssvc) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation) 
SRV - (WDSmartWareBackgroundService) -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe (Memeo) 
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) 
SRV - (AntiVirScheduler) -- C:\Program Files\AntiVir PersonalEdition Classic\sched.exe (Avira GmbH) 
SRV - (AntiVirService) -- C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe (Avira GmbH) 
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) 
SRV - (LVSrvLauncher) -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.) 
SRV - (LVPrcSrv) -- c:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.) 
SRV - (DSBrokerService) -- C:\Program Files\DellSupport\brkrsvc.exe () 
SRV - (IAANTMON) Intel(R) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) 
SRV - (ServiceLayer) -- C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe (Nokia.) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found 
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found 
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found 
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys File not found 
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys File not found 
DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys File not found 
DRV - (MBAMSwissArmy) -- C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation) 
DRV - (LMouFilt) -- C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.) 
DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.) 
DRV - (fssfltr) -- C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation) 
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) 
DRV - (avgntflt) -- C:\Program Files\AntiVir PersonalEdition Classic\avgntflt.sys (Avira GmbH) 
DRV - (avgio) -- C:\Program Files\AntiVir PersonalEdition Classic\avgio.sys (Avira GmbH) 
DRV - (WDC_SAM) -- C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies) 
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (AVIRA GmbH) 
DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation) 
DRV - (e1express) Intel(R) -- C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation) 
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.) 
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.) 
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.) 
DRV - (nmwcd) -- C:\Windows\System32\drivers\nmwcd.sys (Nokia) 
DRV - (nmwcdcm) -- C:\Windows\System32\drivers\nmwcdcm.sys (Nokia) 
DRV - (nmwcdcj) -- C:\Windows\System32\drivers\nmwcdcj.sys (Nokia) 
DRV - (nmwcdc) -- C:\Windows\System32\drivers\nmwcdc.sys (Nokia) 
DRV - (DRVNDDM) -- C:\Windows\System32\drivers\DRVNDDM.SYS (Roxio) 
DRV - (DLARTL_M) -- C:\Windows\System32\drivers\DLARTL_M.SYS (Roxio) 
DRV - (DLACDBHM) -- C:\Windows\System32\drivers\DLACDBHM.SYS (Roxio) 
DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (SigmaTel, Inc.) 
DRV - (LVPr2Mon) -- C:\Windows\System32\drivers\LVPr2Mon.sys () 
DRV - (LVMVDrv) -- C:\Windows\System32\drivers\LVMVdrv.sys (Logitech Inc.) 
DRV - (LVcKap) -- C:\Windows\System32\drivers\Lvckap.sys () 
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation) 
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.) 
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex) 
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.) 
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.) 
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation) 
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.) 
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.) 
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd) 
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation) 
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.) 
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.) 
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation) 
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation) 
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH) 
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems) 
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation) 
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.) 
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.) 
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic) 
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.) 
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company) 
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.) 
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.) 
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.) 
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic) 
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic) 
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic) 
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic) 
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation) 
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic) 
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation) 
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.) 
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.) 
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.) 
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.) 
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.) 
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.) 
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies) 
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation) 
DRV - (DLADResM) -- C:\Windows\System32\DLA\DLADResM.SYS (Roxio) 
DRV - (DLAUDFAM) -- C:\Windows\System32\DLA\DLAUDFAM.SYS (Roxio) 
DRV - (DLABMFSM) -- C:\Windows\System32\DLA\DLABMFSM.SYS (Roxio) 
DRV - (DLAUDF_M) -- C:\Windows\System32\DLA\DLAUDF_M.SYS (Roxio) 
DRV - (DLAOPIOM) -- C:\Windows\System32\DLA\DLAOPIOM.SYS (Roxio) 
DRV - (DLABOIOM) -- C:\Windows\System32\DLA\DLABOIOM.SYS (Roxio) 
DRV - (DLAPoolM) -- C:\Windows\System32\DLA\DLAPoolM.SYS (Roxio) 
DRV - (DLAIFS_M) -- C:\Windows\System32\DLA\DLAIFS_M.SYS (Roxio) 
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.) 
DRV - (DSproct) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.) 
DRV - (iaStor) -- C:\Windows\system32\drivers\iastor.sys (Intel Corporation) 
DRV - (dsunidrv) -- C:\Program Files\DellSupport\Drivers\dsunidrv.sys (Gteko Ltd.) 
DRV - (DRVMCDB) -- C:\Windows\System32\Drivers\DRVMCDB.SYS (Sonic Solutions) 
DRV - (AR5523) -- C:\Windows\System32\drivers\ar5523.sys (Atheros Communications, Inc.) 
DRV - (QCMerced) -- C:\Windows\System32\drivers\lvcm.sys () 
DRV - (LVUSBSta) -- C:\Windows\System32\drivers\LVUSBSta.sys (Logitech Inc.) 
DRV - (LHidKe) -- C:\Windows\System32\drivers\LHidKE.Sys (Logitech, Inc.) 
DRV - (LMouKE) -- C:\Windows\System32\drivers\LMOUKE.sys (Logitech, Inc.) 
DRV - (k750bus) Sony Ericsson 750 driver (WDM) -- C:\Windows\System32\drivers\k750bus.sys (MCCI) 
DRV - (odysseyIM4) -- C:\Windows\System32\drivers\odysseyIM4.sys (Funk Software, Inc.) 
  
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm 
IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.) 
  
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 
IE - HKCU\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.) 
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (Spigot, Inc.) 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local 
   ========== FireFox ========== 
  
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=302398" 
FF - prefs.js..extensions.enabledItems: pdfforge@mybrowserbar.com:1.1.2 
FF - prefs.js..extensions.enabledItems: searchsettings@spigot.com:1.2.3 
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655 
  
  
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.22 13:09:18 | 000,000,000 | ---D | M] 
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.22 13:09:18 | 000,000,000 | ---D | M] 
  
[2010.07.04 17:53:46 | 000,000,000 | ---D | M] -- C:\Users\Dursun\AppData\Roaming\mozilla\Extensions 
[2010.08.25 01:43:13 | 000,000,000 | ---D | M] -- C:\Users\Dursun\AppData\Roaming\mozilla\Firefox\Profiles\rss6sibs.default\extensions 
[2010.08.20 12:40:37 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Dursun\AppData\Roaming\mozilla\Firefox\Profiles\rss6sibs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} 
[2010.08.22 22:24:18 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Dursun\AppData\Roaming\mozilla\Firefox\Profiles\rss6sibs.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} 
[2010.08.20 12:16:30 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions 
[2007.05.30 23:12:57 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} 
[2010.08.20 12:16:30 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} 
[2010.07.17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll 
[2010.08.22 13:09:14 | 000,001,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml 
[2010.08.22 13:09:14 | 000,002,344 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml 
[2010.08.22 13:09:14 | 000,006,805 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml 
[2010.08.22 13:09:14 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml 
[2010.08.22 13:09:14 | 000,001,105 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml 
  
O1 HOSTS File: ([2007.11.25 16:00:04 | 000,213,378 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts 
O1 - Hosts: 127.0.0.1       localhost 
O1 - Hosts: ::1             localhost 
O1 - Hosts: 127.0.0.1        007guard.com 
O1 - Hosts: 127.0.0.1        www.007guard.com 
O1 - Hosts: 127.0.0.1        008i.com 
O1 - Hosts: 127.0.0.1        008k.com 
O1 - Hosts: 127.0.0.1        www.008k.com 
O1 - Hosts: 127.0.0.1        00hq.com 
O1 - Hosts: 127.0.0.1        www.00hq.com 
O1 - Hosts: 127.0.0.1        010402.com 
O1 - Hosts: 127.0.0.1        032439.com 
O1 - Hosts: 127.0.0.1        www.032439.com 
O1 - Hosts: 127.0.0.1        1001-search.info 
O1 - Hosts: 127.0.0.1        www.1001-search.info 
O1 - Hosts: 127.0.0.1        100888290cs.com 
O1 - Hosts: 127.0.0.1        www.100888290cs.com 
O1 - Hosts: 127.0.0.1        100sexlinks.com 
O1 - Hosts: 127.0.0.1        www.100sexlinks.com 
O1 - Hosts: 127.0.0.1        10sek.com 
O1 - Hosts: 127.0.0.1        www.10sek.com 
O1 - Hosts: 127.0.0.1        123topsearch.com 
O1 - Hosts: 127.0.0.1        www.123topsearch.com 
O1 - Hosts: 127.0.0.1        132.com 
O1 - Hosts: 127.0.0.1        www.132.com 
O1 - Hosts: 127.0.0.1        136136.net 
O1 - Hosts: 7504 more lines... 
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) 
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. 
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) 
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (Spigot, Inc.) 
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.) 
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.) 
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) 
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (Spigot, Inc.) 
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) 
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (Spigot, Inc.) 
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.) 
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) 
O3 - HKCU\..\Toolbar\WebBrowser: (softonic-de3 Toolbar) - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.) 
O4 - HKLM..\Run: []  File not found 
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.) 
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe () 
O4 - HKLM..\Run: [avgnt] C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe (Avira GmbH) 
O4 - HKLM..\Run: [ECenter] c:\DELL\E-Center\EULALauncher.exe ( ) 
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) 
O4 - HKLM..\Run: [fssui] C:\Program Files\Windows Live\Family Safety\fsui.exe (Microsoft Corporation) 
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation) 
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation) 
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation) 
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe (Logitech Inc.) 
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam10\QuickCam10.exe () 
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe File not found 
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions) 
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe (Spigot, Inc.) 
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Windows\sttray.exe (SigmaTel, Inc.) 
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) 
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe () 
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) 
O4 - HKCU..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe File not found 
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe File not found 
O4 - HKCU..\Run: [E06DXLRD_2567183] C:\Program Files\Microsoft Encarta\Encarta 2006 Enzyklopaedie DVD\EDICT.EXE (Microsoft Corporation) 
O4 - Startup: C:\Users\Dursun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe () 
O4 - Startup: C:\Users\Dursun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SDK Tray Menu.lnk = C:\Sun\SDK\jdk\bin\javaw.exe (Sun Microsystems, Inc.) 
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Dursun\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm () 
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) 
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) 
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) 
O13 - gopher Prefix: missing 
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} hxxp://gygf.spaces.live.com//PhotoUpload/VistaMsnPUpldde-de.cab (MSN Photo Upload Tool) 
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/DE-DE/a-UNO1/GAME_UNO1.cab (UnoCtrl Class) 
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} hxxp://gygf.spaces.live.com/PhotoUpload/VistaMsnPUpldde-de.cab (Windows Live Photo Upload Control) 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) 
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.) 
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer) 
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class) 
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Java Plug-in 1.6.0) 
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) 
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) 
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} hxxp://messenger.zone.msn.com/binary/Chess.cab57176.cab (ZoneChess Object) 
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class) 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.) 
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) 
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) 
O24 - Desktop WallPaper: C:\Users\Dursun\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg 
O24 - Desktop BackupWallPaper: C:\Users\Dursun\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg 
O32 - HKLM CDRom: AutoRun - 1 
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] 
O32 - AutoRun File - [2009.06.18 23:12:18 | 000,000,088 | ---- | M] () - K:\autorun.inf -- [ UDF ] 
O33 - MountPoints2\{439cd322-43ef-11df-93f2-0001e35ed2f6}\Shell - "" = AutoRun 
O33 - MountPoints2\{439cd322-43ef-11df-93f2-0001e35ed2f6}\Shell\AutoRun\command - "" = K:\WD SmartWare.exe -- [2009.11.13 21:25:22 | 003,280,672 | ---- | M] (Western Digital) 
O33 - MountPoints2\{cc57bc62-0944-11dc-a521-0019d14f17ef}\Shell\AutoRun\command - "" = ruozjp.exe 
O33 - MountPoints2\{cc57bc62-0944-11dc-a521-0019d14f17ef}\Shell\explore\Command - "" = ruozjp.exe 
O33 - MountPoints2\{cc57bc62-0944-11dc-a521-0019d14f17ef}\Shell\open\Command - "" = ruozjp.exe 
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O37 - HKLM\...com [@ = comfile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2010.08.25 16:49:13 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Dursun\_\OTL.exe 
[2010.08.22 22:29:47 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro 
[2010.08.22 22:29:45 | 000,000,000 | ---D | C] -- C:\rsit 
[2010.08.22 21:28:51 | 000,000,000 | ---D | C] -- C:\Users\Dursun\AppData\Roaming\Malwarebytes 
[2010.08.22 21:28:42 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys 
[2010.08.22 21:28:40 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys 
[2010.08.22 21:28:40 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware 
[2010.08.22 21:28:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes 
[2010.08.20 12:16:28 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll 
[2010.08.20 12:16:28 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe 
[2010.08.20 12:16:28 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe 
[2010.08.20 12:16:28 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe 
[2010.08.20 11:55:03 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime 
[2010.08.20 11:50:28 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes 
[2010.08.20 11:43:03 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour 
[2010.08.20 11:15:53 | 000,000,000 | ---D | C] -- C:\Users\Dursun\Documents\Downloads 
[2010.08.20 11:06:59 | 000,000,000 | ---D | C] -- C:\Users\Dursun\AppData\Local\Real 
[2010.08.20 11:04:50 | 000,185,920 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll 
[2010.08.20 11:04:23 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll 
[2010.08.20 11:04:23 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll 
[2010.08.20 11:03:54 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared 
[2010.08.20 11:02:06 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\System32\pncrt.dll 
[2010.08.15 14:08:52 | 000,081,920 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll 
[2010.08.15 14:08:48 | 000,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll 
[2010.08.15 14:08:45 | 000,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll 
[2010.08.15 14:08:45 | 000,458,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll 
[2010.08.15 14:08:45 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec 
[2010.08.15 14:08:45 | 000,389,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll 
[2010.08.15 14:08:45 | 000,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll 
[2010.08.15 14:08:44 | 001,383,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb 
[2010.08.15 14:08:44 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll 
[2010.08.15 14:08:44 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll 
[2010.08.15 14:08:44 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll 
[2010.08.15 14:08:33 | 002,036,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys 
[2010.08.15 14:08:29 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll 
[2010.08.15 14:08:24 | 003,598,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe 
[2010.08.15 14:08:24 | 003,545,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe 
[2010.08.10 05:15:58 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\Windows\System32\QuickTimeVR.qtx 
[2010.08.10 05:15:58 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\Windows\System32\QuickTime.qts 
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] 
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] 
   ========== Files - Modified Within 30 Days ========== 
  
[2010.08.25 16:55:19 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{119A1CD7-840F-4E88-9399-0680881DCD40}.job 
[2010.08.25 16:53:54 | 008,126,464 | -HS- | M] () -- C:\Users\Dursun\ntuser.dat 
[2010.08.25 16:49:25 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Dursun\_\OTL.exe 
[2010.08.25 16:00:01 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job 
[2010.08.25 15:12:32 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 
[2010.08.25 15:12:32 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 
[2010.08.25 11:12:34 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job 
[2010.08.25 11:12:33 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT 
[2010.08.25 11:12:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat 
[2010.08.25 02:34:06 | 000,524,288 | -HS- | M] () -- C:\Users\Dursun\ntuser.dat{6a71ca61-c3b6-11de-8e96-0001e35ed2f6}.TMContainer00000000000000000001.regtrans-ms 
[2010.08.25 02:34:06 | 000,065,536 | -HS- | M] () -- C:\Users\Dursun\ntuser.dat{6a71ca61-c3b6-11de-8e96-0001e35ed2f6}.TM.blf 
[2010.08.24 23:34:10 | 003,954,466 | -H-- | M] () -- C:\Users\Dursun\AppData\Local\IconCache.db 
[2010.08.23 14:50:21 | 001,300,524 | ---- | M] () -- C:\Users\Dursun\Documents\Sertab Erener - Rengarenk  HQ 169  Yeni Klip 2010.mp3 
[2010.08.23 12:57:28 | 001,461,286 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI 
[2010.08.23 12:57:28 | 000,633,510 | ---- | M] () -- C:\Windows\System32\perfh007.dat 
[2010.08.23 12:57:28 | 000,599,890 | ---- | M] () -- C:\Windows\System32\perfh009.dat 
[2010.08.23 12:57:28 | 000,129,742 | ---- | M] () -- C:\Windows\System32\perfc007.dat 
[2010.08.23 12:57:28 | 000,107,022 | ---- | M] () -- C:\Windows\System32\perfc009.dat 
[2010.08.22 21:28:45 | 000,000,780 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk 
[2010.08.22 21:24:39 | 000,000,766 | ---- | M] () -- C:\Users\Dursun\_\CCleaner.lnk 
[2010.08.21 22:45:12 | 000,182,784 | ---- | M] () -- C:\Users\Dursun\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 
[2010.08.20 11:28:42 | 000,371,456 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT 
[2010.08.20 11:04:50 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll 
[2010.08.20 11:04:23 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll 
[2010.08.20 11:04:23 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll 
[2010.08.20 11:02:06 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\Windows\System32\pncrt.dll 
[2010.08.10 05:15:58 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\Windows\System32\QuickTimeVR.qtx 
[2010.08.10 05:15:58 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\Windows\System32\QuickTime.qts 
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] 
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] 
   ========== Files Created - No Company Name ========== 
  
[2010.08.23 14:50:18 | 001,300,524 | ---- | C] () -- C:\Users\Dursun\Documents\Sertab Erener - Rengarenk  HQ 169  Yeni Klip 2010.mp3 
[2010.08.22 21:28:45 | 000,000,780 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk 
[2010.08.22 21:24:39 | 000,000,766 | ---- | C] () -- C:\Users\Dursun\_\CCleaner.lnk 
[2010.08.20 10:55:10 | 000,001,096 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job 
[2010.08.20 10:55:05 | 000,001,092 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job 
[2010.05.16 01:27:23 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll 
[2010.05.08 20:53:21 | 000,000,760 | ---- | C] () -- C:\Users\Dursun\AppData\Roaming\setup_ldm.iss 
[2010.04.06 01:06:57 | 000,000,094 | ---- | C] () -- C:\Users\Dursun\AppData\Local\fusioncache.dat 
[2009.03.07 15:51:20 | 000,000,000 | ---- | C] () -- C:\Users\Dursun\AppData\Roaming\wklnhst.dat 
[2008.09.13 16:46:39 | 000,056,056 | ---- | C] () -- C:\Windows\System32\DLAAPI_W.DLL 
[2008.08.22 21:07:45 | 000,442,368 | ---- | C] () -- C:\Windows\System32\dvmsg.dll 
[2008.03.12 19:17:17 | 000,000,000 | ---- | C] () -- C:\Windows\Irremote.ini 
[2007.12.03 20:01:38 | 000,012,009 | ---- | C] () -- C:\ProgramData\hpzinstall.log 
[2007.07.23 17:50:17 | 000,000,680 | ---- | C] () -- C:\Users\Dursun\AppData\Local\d3d9caps.dat 
[2007.07.09 21:07:50 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll 
[2007.06.01 15:47:37 | 000,198,144 | ---- | C] () -- C:\Windows\System32\_psisdecd.dll 
[2007.05.31 23:14:09 | 001,317,152 | ---- | C] () -- C:\Windows\System32\drivers\lvcm.sys 
[2007.05.31 23:14:08 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini 
[2007.05.31 00:19:01 | 000,000,365 | ---- | C] () -- C:\Windows\wininit.ini 
[2007.05.31 00:17:07 | 000,000,692 | ---- | C] () -- C:\ProgramData\Installer.log 
[2007.05.30 23:22:29 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html 
[2007.05.27 10:23:56 | 000,000,064 | ---- | C] () -- C:\Windows\init.ini 
[2007.05.24 15:53:58 | 000,182,784 | ---- | C] () -- C:\Users\Dursun\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 
[2007.04.30 00:56:37 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll 
[2007.02.06 17:45:04 | 000,025,632 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys 
[2007.02.06 17:42:40 | 001,691,808 | ---- | C] () -- C:\Windows\System32\drivers\Lvckap.sys 
[2006.11.29 21:08:27 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini 
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll 
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini 
[2006.09.20 23:02:32 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll 
[2006.09.20 23:02:32 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll 
[1999.01.27 13:39:06 | 000,065,024 | ---- | C] () -- C:\Windows\System32\indounin.dll 
[1997.06.13 07:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\Iyvu9_32.dll 
   ========== Alternate Data Streams ========== 
  
@Alternate Data Stream - 76 bytes -> C:\Users\Dursun\Documents\My Stationery:Roxio EMC Stream 
@Alternate Data Stream - 76 bytes -> C:\Users\Dursun\Documents\My Scans:Roxio EMC Stream 
@Alternate Data Stream - 76 bytes -> C:\Users\Dursun\Documents\Melih:Roxio EMC Stream 
@Alternate Data Stream - 76 bytes -> C:\Users\Dursun\Documents\Islam:Roxio EMC Stream 
@Alternate Data Stream - 76 bytes -> C:\Users\Dursun\Documents\Hasan Hüseyin:Roxio EMC Stream 
@Alternate Data Stream - 76 bytes -> C:\Users\Dursun\Documents\DVDVideoSoft:Roxio EMC Stream 
@Alternate Data Stream - 76 bytes -> C:\Users\Dursun\Documents\Bahn-,Buslinien:Roxio EMC Stream 
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:DB9F45AE 
< End of report >   --- --- ---   
[/CODE]   
2. Logfile von OTL  
C:\Users\***\_\Extras  
OTL Logfile:   Code:  
 OTL Extras logfile created on: 25.08.2010 16:51:53 - Run 1 
OTL by OldTimer - Version 3.2.10.0     Folder = C:\Users\Dursun\_ 
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation 
Internet Explorer (Version = 7.0.6001.18000) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
1.021,00 Mb Total Physical Memory | 267,00 Mb Available Physical Memory | 26,00% Memory free 
3,00 Gb Paging File | 2,00 Gb Available in Paging File | 56,00% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files 
Drive C: | 288,04 Gb Total Space | 237,84 Gb Free Space | 82,57% Space Free | Partition Type: NTFS 
Drive D: | 10,00 Gb Total Space | 0,20 Gb Free Space | 1,98% Space Free | Partition Type: NTFS 
E: Drive not present or media not loaded 
Drive F: | 465,11 Gb Total Space | 310,67 Gb Free Space | 66,80% Space Free | Partition Type: NTFS 
G: Drive not present or media not loaded 
H: Drive not present or media not loaded 
I: Drive not present or media not loaded 
Drive K: | 614,91 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF 
  
Computer Name: DURSUN-PC 
Current User Name: Dursun 
Logged in as Administrator. 
  
Current Boot Mode: Normal 
Scan Mode: Current user 
Company Name Whitelist: Off 
Skip Microsoft Files: Off 
File Age = 30 Days 
Output = Minimal 
   ========== Extra Registry (SafeList) ========== 
  
   ========== File Associations ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) 
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) 
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found 
  
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] 
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
   ========== Shell Spawning ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) 
htmlfile [edit] -- Reg Error: Key error. 
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" 
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) 
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
jsfile [edit] -- "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [AddToPlaylistVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" () 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Directory [PlayWithVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" () 
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) 
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft) 
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft) 
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) 
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
   ========== Security Center Settings ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
"cval" = 1 
"UacDisableNotify" = 1 
"InternetSettingsDisableNotify" = 1 
"AutoUpdateDisableNotify" = 1 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
"DisableMonitoring" = 1 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware] 
"DisableMonitoring" = 1 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] 
"DisableMonitoring" = 1 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] 
"DisableMonitoring" = 1 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
"AntiVirusOverride" = 1 
"AntiSpywareOverride" = 0 
"FirewallOverride" = 0 
"VistaSp1" = Reg Error: Unknown registry data type -- File not found 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 
"EnableFirewall" = 1 
"DisableNotifications" = 0 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 
"EnableFirewall" = 1 
"DisableNotifications" = 0 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] 
"EnableFirewall" = 1 
"DisableNotifications" = 0 
   ========== Authorized Applications List ========== 
  
   ========== Vista Active Open Ports Exception List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] 
"{0C92D81E-E1BC-4F61-93AA-003B7AADC066}" = lport=2869 | protocol=6 | dir=in | app=system |  
"{9A65781F-A19F-437A-803D-5E1090FE12CE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |  
   ========== Vista Active Application Exception List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] 
"{1E57518C-8690-40DC-ABA2-6697B2096C9B}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |  
"{2A23159F-9174-4BF3-81AB-52C51B42297D}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |  
"{53AAD966-2D9B-431B-8A2F-534A11A55880}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |  
"{566F3AA4-3C2E-4F96-ACB3-EDECA53DAD51}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |  
"{5BA99A1B-CE7C-40AE-943B-9015A3322916}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |  
"{815F1E16-763C-4ECB-8201-212353B6F429}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |  
"{84405729-140E-4EFC-BE65-AF7D1976AC91}" = protocol=6 | dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |  
"{AC690237-4071-4D92-8F16-83B388EAEFF5}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |  
"{B032F9CD-971E-4DCE-B6F0-853CA3753D07}" = protocol=17 | dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |  
"{B1C2392D-BF02-43BA-864F-7AE09B0DA102}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |  
"{C34CBDA6-4239-43FE-B763-4E53CA9933A3}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |  
"{C597BB2F-7F30-427A-B99C-C73AE930D660}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |  
"{EC115246-2C8F-416D-8D7C-3D7FDC2663B1}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |  
"TCP Query User{1341A4A7-A630-4B75-B1E6-667BDCEDD24A}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |  
"TCP Query User{2BD7CB4B-9C2D-4849-8583-717134FF51C8}C:\users\dursun\appdata\local\temp\java_ee_sdk-5_01-windows.exe2\package\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\users\dursun\appdata\local\temp\java_ee_sdk-5_01-windows.exe2\package\jre\bin\javaw.exe |  
"TCP Query User{2E5E6EE0-0DCE-4C4A-9AD2-8306362CBEEF}C:\users\dursun\downloads\touchfinder.exe" = protocol=6 | dir=in | app=c:\users\dursun\downloads\touchfinder.exe |  
"TCP Query User{3B7D52A4-933E-4339-B9DB-9BF61BA9315C}C:\program files\java\jdk1.6.0_14\jre\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jdk1.6.0_14\jre\bin\java.exe |  
"TCP Query User{3D12F672-D041-4ADB-9737-ADC125646D98}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |  
"TCP Query User{868CC6C1-2E4F-4BA3-8DD4-15BAEBE7282B}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=6 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe |  
"TCP Query User{8DA29035-C159-47BC-ACB5-B2FDB5D906EB}C:\program files\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe |  
"TCP Query User{90810765-396B-4790-A4C0-8CA69BCCED91}C:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |  
"TCP Query User{ACA4D69D-BB08-424B-B2C8-7B4D87BE5E9D}C:\program files\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\sopcast.exe |  
"TCP Query User{B67AC56C-6B55-48C0-B33D-7F1A1D7C45C5}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=6 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |  
"TCP Query User{BB6BA355-A7B9-41B2-A8AC-DBE86BDC2AB6}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |  
"TCP Query User{CFF63509-AAA6-4706-B123-7B2613340F48}C:\users\dursun\appdata\local\temp\rarsfx0\ppb.exe" = protocol=6 | dir=in | app=c:\users\dursun\appdata\local\temp\rarsfx0\ppb.exe |  
"TCP Query User{D2DDD88C-A2A9-4CAB-A540-E001A5D4019D}C:\program files\java\jdk1.6.0_14\jre\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jdk1.6.0_14\jre\bin\java.exe |  
"TCP Query User{F76554C9-CC08-42E0-9A72-B5EB585AA9F8}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |  
"UDP Query User{23F4F465-08B8-46C9-BD14-497F8E8BF5B5}C:\program files\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\sopcast.exe |  
"UDP Query User{28915A67-5FF9-4A72-A2B8-4E00309EC365}C:\program files\java\jdk1.6.0_14\jre\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jdk1.6.0_14\jre\bin\java.exe |  
"UDP Query User{3548D8DC-7A83-4F5C-9DA4-59CA94EC4B9B}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |  
"UDP Query User{3FAE9EB3-1D62-4773-96AC-877851AFD263}C:\program files\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe |  
"UDP Query User{568481B1-22FC-46CD-B8EB-454FC61E3A47}C:\users\dursun\appdata\local\temp\rarsfx0\ppb.exe" = protocol=17 | dir=in | app=c:\users\dursun\appdata\local\temp\rarsfx0\ppb.exe |  
"UDP Query User{7C6F1BF4-861E-43FF-B036-338AA673106C}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |  
"UDP Query User{98A6FE94-58D2-4FF9-82C4-05B133479F80}C:\program files\java\jdk1.6.0_14\jre\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jdk1.6.0_14\jre\bin\java.exe |  
"UDP Query User{AF417C0B-820D-4F5A-852B-495B36B4EAC9}C:\users\dursun\appdata\local\temp\java_ee_sdk-5_01-windows.exe2\package\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\users\dursun\appdata\local\temp\java_ee_sdk-5_01-windows.exe2\package\jre\bin\javaw.exe |  
"UDP Query User{B7CECA51-A999-4BC4-9C39-61514919C4CD}C:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |  
"UDP Query User{C665922C-1F3C-4CE4-ACDC-886B47A3DF05}C:\users\dursun\downloads\touchfinder.exe" = protocol=17 | dir=in | app=c:\users\dursun\downloads\touchfinder.exe |  
"UDP Query User{CBA10EF7-931D-4328-A545-109C0FD5C6B0}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |  
"UDP Query User{CC67890C-C546-414E-BCF4-EB21C2F14245}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=17 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe |  
"UDP Query User{DEF2487C-34EC-44A2-B3FD-F2D9AD766180}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |  
"UDP Query User{EBBBD711-2EF0-4CFF-A9BE-C086251A988E}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=17 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |  
   ========== HKEY_LOCAL_MACHINE Uninstall List ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator 
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 
"{00D0200F-3B4D-4A2F-869E-533ED835A943}" = Hervorhebe-Funktion (Windows Live Toolbar) 
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools 
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu 
"{06100081-3E21-46D6-9A91-D927BA08F41D}" = Microsoft Encarta 2006 Enzyklopädie DVD 
"{0A3D3C54-2EC0-4D67-B265-FF17926E6D67}" = Nokia Connectivity Cable Driver 
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour 
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data 
"{0D80391C-0A72-43BB-9BC2-143F63CC111D}" = Nokia PC Connectivity Solution 
"{0F022A2E-7022-497D-90A5-0F46746D8275}" = Macromedia Extension Manager 
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate 
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool 
"{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23 
"{218761F6-CBF6-4973-B910-A33E6563A1EA}" = Windows Live Toolbar-Erweiterung (Windows Live Toolbar) 
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT 
"{232DB76D-4751-41A9-9EC2-CDC0DAC1FAB6}" = WD SmartWare 
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 21 
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie 
"{2DD6C198-FA9A-40B4-8DE5-CE5206E3EB34}" = Smart Menus (Windows Live Toolbar) 
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc 
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager 
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java(TM) SE Runtime Environment 6 
"{32A3A4F4-B792-11D6-A78A-00B0D0160140}" = Java(TM) SE Development Kit 6 Update 14 
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision 
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module 
"{362BFFCD-8274-11D8-97C8-000129760CBE}" = MediaLife  
"{3741689E-584D-40C9-B011-373A0371846D}" = Nokia Software Updater 
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup 
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform 
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant 
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg 
"{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker 
"{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}" = Google Earth 
"{418EF145-944B-4EBC-A755-9F15AEDFB08B}" = Print Server Support 
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger 
"{44025BD7-AD10-4769-99AE-6378FD0303D6}" = Macromedia Dreamweaver 8 
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater 
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack 
"{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}" = Microsoft Works 
"{50D69C54-6963-49A6-B762-A9FF8F56AF0F}" = Brockhaus multimedial 2008 
"{552C83B7-0013-42EA-B285-1997D129DD53}" = SA31xx Device Manager & Media Converter 
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml 
"{5791B7D3-8B34-4218-9750-6A8E45D0AD32}" = pdfforge Toolbar v1.1.2 
"{59359B3D-ABE7-46BF-AB55-43B67A64DC68}" = Nokia MTP driver 
"{5aa47dba-b584-4d47-a626-76e53fc2987d}" = JavaFX(TM) 1.2 SDK 
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = Benutzerhandbuch 
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call 
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy 
"{65FBA21B-7F80-4E4E-B275-0958D2648F94}_is1" = Java-Editor 9.14j, 2010.02.21 
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 
"{70B7A167-0B88-445D-A3EA-97C73AA88CAC}" = Windows Live Toolbar 
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable 
"{73E30715-9EC4-4DAE-BE67-64500AEB8012}" = Nokia Nseries Skin for Microsoft Windows Media Player 
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync 
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 
"{77F5816C-64A6-4FBE-BBE5-52EFE5EB84E8}" = Nokia themes for your device 
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites für Windows Live Toolbar 
"{7D2370AC-D8E6-4996-986A-19824F8A167C}" = Logitech QuickCam 
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport 
"{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}" = Windows Live Anmelde-Assistent 
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio 
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support 
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight 
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) 
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player 
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger 
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel(R) Matrix Storage Manager 
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes 
"{926C96FB-9D0A-4504-8000-C6D3A4A3118E}" = Java DB 10.4.2.1 
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting 
"{994223F3-A99B-4DDD-9E1D-0190A17C6860}" = Windows Live Family Safety 
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio 
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT 
"{A625D45F-1DC4-47FB-ABCF-6B27684AA717}" = OpenOffice.org 2.3 
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper 
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support 
"{AC76BA86-7AD7-1031-7B44-A90000000001}" = Adobe Reader 9 - Deutsch 
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter 
"{B6E9A977-C2C7-4CA0-0001-98605B7C7D3E}" = MyTube Recorder 
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player 
"{BA165460-FCF7-4D6C-A7A2-F2321700720F}" = MobileMe Control Panel 
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) 
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component 
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update 
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail 
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE 
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE 
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser 
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer 
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update 
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 
"{E572B060-C98B-4984-A48E-E4FA56265903}" = SA31xx Device Manager & Media Converter 
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack 
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator 
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential 
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply 
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime 
"{EE565795-2776-415A-B31C-EB3A8D7C6FA4}" = Nokia Lifeblog 2.1 
"{F08F36A8-7EEA-DB4D-00D1-2CA68C2DD445}" = ATI Catalyst Control Center Ex 
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] 
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard 
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer 
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0 
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials 
"{FD023F61-65E9-465C-B558-7C64EB2B97E6}" = Assistant zum Anpassen des Dell-Systems 
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX 
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin 
"Adobe Shockwave Player" = Adobe Shockwave Player 
"Advanced WMA Workshop_is1" = Advanced WMA Workshop version 2.6.2 
"AntiVir PersonalEdition Classic" = Avira AntiVir Personal - Free Antivirus 
"AviSynth" = AviSynth 2.5 
"BlueJ_is1" = BlueJ 2.5.1 
"CCleaner" = CCleaner 
"ConTEXTEditor_is1" = ConTEXT 
"Diktattrainer plus 5-6_is1" = Diktattrainer plus 5-6 
"eMusic Promotion" = eMusic - 50 Free MP3 offer 
"Filzip 3.0.6.93_is1" = Filzip 3.06 
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.3 
"Free DVD Decrypter_is1" = Free DVD Decrypter version 1.2 
"Free Video Converter_is1" = Free Video Converter V 2.7 
"Free Video to iPod Converter_is1" = Free Video to iPod Converter version 3.5 
"Free YouTube Download_is1" = Free YouTube Download 2.3 
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.5 
"Google Chrome" = Google Chrome 
"InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23 
"InterActual Player" = InterActual Player 
"IpodConverter_is1" = IpodConverter 1.1 
"IsoBuster_is1" = IsoBuster 2.6 
"Java Platform, Enterprise Edition 5 SDK" = Java Platform, Enterprise Edition 5 SDK 
"LHTTSGED" = L&H TTS3000 Deutsch 
"Logitech Print Service" = Logitech Print Service 
"Macromedia Shockwave Player" = Macromedia Shockwave Player 
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware 
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1 
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU 
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8) 
"Mp3tag" = Mp3tag v2.46a 
"QcDrv" = Logitech® Camera-Treiber 
"RealPlayer 12.0" = RealPlayer 
"softonic-de3 Toolbar" = softonic-de3 Toolbar 
"SP6" = Logitech SetPoint 6.0 
"Uninstall_is1" = Uninstall 1.0.0.1 
"ViewpointMediaPlayer" = Viewpoint Media Player 
"VLC media player" = VLC media player 0.9.4 
"Winamp" = Winamp (remove only) 
"WinGimp-2.0_is1" = GIMP 2.6.5 
"WinLiveSuite_Wave3" = Windows Live Essentials 
   ========== Last 10 Event Log Errors ========== 
  
[ Application Events ] 
Error - 24.08.2010 17:28:27 | Computer Name = Dursun-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 
Description =  
  
Error - 24.08.2010 17:37:13 | Computer Name = Dursun-PC | Source = WDSmartWareBackgroundService | ID = 0 
Description =  
  
Error - 24.08.2010 17:37:19 | Computer Name = Dursun-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 
Description =  
  
Error - 24.08.2010 17:39:54 | Computer Name = Dursun-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 
Description =  
  
Error - 24.08.2010 18:14:54 | Computer Name = Dursun-PC | Source = WDSmartWareBackgroundService | ID = 0 
Description =  
  
Error - 24.08.2010 18:15:02 | Computer Name = Dursun-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 
Description =  
  
Error - 24.08.2010 18:17:42 | Computer Name = Dursun-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 
Description =  
  
Error - 25.08.2010 05:12:59 | Computer Name = Dursun-PC | Source = WDSmartWareBackgroundService | ID = 0 
Description =  
  
Error - 25.08.2010 05:13:09 | Computer Name = Dursun-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 
Description =  
  
Error - 25.08.2010 05:15:49 | Computer Name = Dursun-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 
Description =  
  
[ Media Center Events ] 
Error - 16.04.2008 12:52:02 | Computer Name = Dursun-PC | Source = MCUpdate | ID = 0 
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight 
 gescheitert. 
  
Error - 18.04.2008 05:51:25 | Computer Name = Dursun-PC | Source = MCUpdate | ID = 0 
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight 
 gescheitert. 
  
[ System Events ] 
Error - 24.08.2010 17:42:36 | Computer Name = Dursun-PC | Source = DCOM | ID = 10010 
Description =  
  
Error - 24.08.2010 17:44:36 | Computer Name = Dursun-PC | Source = Service Control Manager | ID = 7043 
Description =  
  
Error - 24.08.2010 18:14:19 | Computer Name = Dursun-PC | Source = HTTP | ID = 15016 
Description =  
  
Error - 24.08.2010 18:16:08 | Computer Name = Dursun-PC | Source = Service Control Manager | ID = 7026 
Description =  
  
Error - 24.08.2010 18:42:14 | Computer Name = Dursun-PC | Source = volsnap | ID = 393236 
Description = Die Schattenkopien von Volume "C:" wurden aufgrund von einem fehlgeschlagenen 
 Rechenvorgang bezüglich verfügbarem Speicher abgebrochen. 
  
Error - 25.08.2010 05:12:33 | Computer Name = Dursun-PC | Source = HTTP | ID = 15016 
Description =  
  
Error - 25.08.2010 05:14:19 | Computer Name = Dursun-PC | Source = Service Control Manager | ID = 7026 
Description =  
  
Error - 25.08.2010 06:33:37 | Computer Name = Dursun-PC | Source = DCOM | ID = 10005 
Description =  
  
Error - 25.08.2010 06:34:01 | Computer Name = Dursun-PC | Source = Service Control Manager | ID = 7009 
Description =  
  
Error - 25.08.2010 06:34:01 | Computer Name = Dursun-PC | Source = Service Control Manager | ID = 7000 
Description =  
  
  
< End of report >   --- --- ---  
[/CODE]   
Logfile von Malwarebytes  
C:\Users\Dursun\_\    Code:  
 Malwarebytes' Anti-Malware 1.46 
www.malwarebytes.org   
Datenbank Version: 4475   
Windows 6.0.6001 Service Pack 1 
Internet Explorer 7.0.6001.18000   
26.08.2010 01:43:47 
mbam-log-2010-08-26 (01-43-47).txt   
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|) 
Durchsuchte Objekte: 342311 
Laufzeit: 1 Stunde(n), 31 Minute(n), 56 Sekunde(n)   
Infizierte Speicherprozesse: 0 
Infizierte Speichermodule: 0 
Infizierte Registrierungsschlüssel: 4 
Infizierte Registrierungswerte: 2 
Infizierte Dateiobjekte der Registrierung: 0 
Infizierte Verzeichnisse: 0 
Infizierte Dateien: 3   
Infizierte Speicherprozesse: 
(Keine bösartigen Objekte gefunden)   
Infizierte Speichermodule: 
(Keine bösartigen Objekte gefunden)   
Infizierte Registrierungsschlüssel: 
HKEY_CLASSES_ROOT\CLSID\{b922d405-6d13-4a2b-ae89-08a030da4402} (Adware.WidgiToolbar) -> No action taken. 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b922d405-6d13-4a2b-ae89-08a030da4402} (Adware.WidgiToolbar) -> No action taken. 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b922d405-6d13-4a2b-ae89-08a030da4402} (Adware.WidgiToolbar) -> No action taken. 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b922d405-6d13-4a2b-ae89-08a030da4402} (Adware.WidgiToolbar) -> No action taken.   
Infizierte Registrierungswerte: 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\pdfforge Toolbar\FF\components\pdfforgeToolbarFF.dll (Adware.WidgiToolbar) -> No action taken. 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{b922d405-6d13-4a2b-ae89-08a030da4402} (Adware.WidgiToolbar) -> No action taken.   
Infizierte Dateiobjekte der Registrierung: 
(Keine bösartigen Objekte gefunden)   
Infizierte Verzeichnisse: 
(Keine bösartigen Objekte gefunden)   
Infizierte Dateien: 
C:\Program Files\pdfforge Toolbar\WidgiHelper.exe (Adware.WidgiToolbar) -> No action taken. 
C:\Program Files\pdfforge Toolbar\FF\components\pdfforgeToolbarFF.dll (Adware.WidgiToolbar) -> No action taken. 
C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (Adware.WidgiToolbar) -> No action taken.   Das wäre es.  
MfG dropper.gen    |