Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Mein Pc läuft nicht mehr richtig. (https://www.trojaner-board.de/92108-pc-laeuft-mehr-richtig.html)

billi12 22.10.2010 13:34

Mein Pc läuft nicht mehr richtig.
 
Guten Tag.Es geht darum,ich bin jetzt aussem Urlaub wieder gekommen.Wahr knapp zwei wochen nicht am pc und als ich dan wieder mal online wahr konnte ich nicht mehr mit Google was suchen.dort stand dan immer das mein computer automatisiert sei und ich müsste bestätigen das ich ein Mensch sei.Das andere Problemm ist,wenn ich Starcraft2 spiele ist mein Pc auf einmal total langsam und das Spiel zeigt an das ich die anderen Anwendungen ausschalten soll,obwohl nichts an ist.Das wahr vorher nicht.

Hier einmal das von malwarebytes
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4905

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

22.10.2010 08:57:24
mbam-log-2010-10-22 (08-57-24).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|H:\|J:\|K:\|)
Durchsuchte Objekte: 334896
Laufzeit: 9 Stunde(n), 4 Minute(n), 21 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 8

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
D:\Autorun.inf (Worm.Agent.H) -> Delete on reboot.
C:\Users\dusty\AppData\Local\Xenocode\Sandbox\Eclipse\0.0.1.0\2010.01.18T09.33\Native\STUBEXE\7.1.280\@PROGRAMFILES@\Internet Explorer\iexplore.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully.
C:\Users\dusty\AppData\Local\Xenocode\Sandbox\Eclipse\0.0.1.0\2010.01.18T09.33\Virtual\STUBEXE\7.1.280\@DESKTOPCOMMON@\Eclipse.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully.
C:\Users\dusty\AppData\Local\Xenocode\Sandbox\Eclipse\0.0.2.0\2010.03.29T04.09\Native\STUBEXE\7.1.280\@PROGRAMFILES@\Internet Explorer\iexplore.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully.
C:\Users\dusty\AppData\Local\Xenocode\Sandbox\Eclipse\0.0.2.0\2010.03.29T04.09\Virtual\STUBEXE\7.1.280\@DESKTOP@\Eclipse.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully.
C:\Users\dusty\AppData\Local\Xenocode\Sandbox\Updater\1.0.0.0\2010.05.10T06.09\Virtual\STUBEXE\7.1.280\@APPDIR@\Updater.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully.
C:\Users\patrick\AppData\Local\Xenocode\Sandbox\Eclipse\0.0.1.0\2010.01.18T09.33\Virtual\STUBEXE\7.1.280\@DESKTOPCOMMON@\Eclipse.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully.
C:\Users\patrick\AppData\Local\Xenocode\Sandbox\Eclipse\0.0.2.0\2010.03.29T04.09\Virtual\STUBEXE\7.1.280\@DESKTOP@\Eclipse.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully.OTL Logfile:
Code:

OTL logfile created on: 22.10.2010 13:56:19 - Run 3
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\dusty\Downloads\MFTools
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 64,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 923,02 Gb Total Space | 484,65 Gb Free Space | 52,51% Space Free | Partition Type: NTFS
Drive D: | 7,38 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: DUSTY-PC
Current User Name: dusty
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
 
========== Processes (SafeList) ==========
 
PRC - [2010.09.02 18:04:47 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\dusty\Downloads\MFTools\OTL.exe
PRC - [2010.07.03 10:43:28 | 000,075,064 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2010.06.28 09:20:30 | 000,173,352 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
PRC - [2010.04.16 22:12:28 | 003,872,080 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
PRC - [2010.04.16 18:36:42 | 000,026,480 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
PRC - [2010.02.26 02:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
PRC - [2009.05.19 12:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009.03.20 02:02:00 | 001,904,640 | ---- | M] (AVM Berlin) -- C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
PRC - [2009.03.20 02:02:00 | 000,368,640 | ---- | M] (AVM Berlin) -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
PRC - [2009.03.05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009.02.26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2010.09.02 18:04:47 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\dusty\Downloads\MFTools\OTL.exe
MOD - [2010.08.21 07:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2009.07.14 03:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - File not found [Auto | Running] -- C:\windows\SysNative\PnkBstrA.exe -- (PnkBstrA)
SRV:64bit: - File not found [Auto | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
SRV:64bit: - [2010.08.26 03:57:14 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009.08.18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV:64bit: - [2009.08.10 23:41:38 | 000,093,336 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1d\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2010.08.27 09:00:18 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010.07.03 10:43:28 | 000,075,064 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010.06.28 09:20:30 | 000,173,352 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5)
SRV - [2010.04.28 07:44:02 | 000,704,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2010.03.18 14:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.26 02:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe -- (N360)
SRV - [2009.05.19 12:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2009.03.20 02:02:00 | 000,368,640 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe -- (AVM WLAN Connection Service)
SRV - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2010.08.26 05:37:26 | 007,767,040 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2010.08.26 05:37:26 | 007,767,040 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010.08.26 03:20:56 | 000,279,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010.07.15 14:47:42 | 000,116,240 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010.07.08 14:42:53 | 000,173,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2010.05.06 11:21:46 | 000,125,456 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010.05.06 06:01:59 | 000,451,120 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\symtdiv.sys -- (SYMTDIv)
DRV:64bit: - [2010.04.29 07:03:51 | 000,150,064 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\ironx64.sys -- (SymIRON)
DRV:64bit: - [2010.04.27 08:32:22 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2010.04.27 08:32:21 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2010.04.22 05:02:20 | 000,221,232 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\symefa64.sys -- (SymEFA)
DRV:64bit: - [2010.04.22 04:29:51 | 000,505,392 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2010.04.22 04:29:51 | 000,032,304 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\srtspx64.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2010.04.12 16:32:55 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010.02.26 02:22:52 | 000,615,040 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\cchpx64.sys -- (ccHP)
DRV:64bit: - [2009.11.16 18:33:38 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
DRV:64bit: - [2009.11.05 23:15:40 | 000,291,328 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009.10.15 05:50:05 | 000,433,200 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0403000.005\symds64.sys -- (SymDS)
DRV:64bit: - [2009.08.09 23:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2009.08.07 23:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1d\WNt500x64\Sandra.sys -- (SANDRA)
DRV:64bit: - [2009.07.14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.19 00:17:08 | 000,034,152 | R--- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009.03.20 02:02:00 | 000,460,800 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\fwlanusb.sys -- (FWLANUSB)
DRV:64bit: - [2009.03.20 02:02:00 | 000,014,120 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avmeject.sys -- (avmeject)
DRV - [2010.10.19 22:36:20 | 000,476,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20101020.001\IDSviA64.sys -- (IDSVia64)
DRV - [2010.10.12 19:07:09 | 001,804,336 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20101021.025\EX64.SYS -- (NAVEX15)
DRV - [2010.10.12 19:07:09 | 000,117,808 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20101021.025\ENG64.SYS -- (NAVENG)
DRV - [2010.09.01 00:57:03 | 000,954,928 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20101001.001\BHDrvx64.sys -- (BHDrvx64)
DRV - [2010.07.07 01:00:00 | 000,475,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2010.07.07 01:00:00 | 000,132,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2007.02.07 20:27:46 | 000,014,104 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | Boot | Running] -- C:\windows\SysWOW64\speedfan.sys -- (speedfan)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.hyrican.de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaultthis.engineName: "Winload Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/firefox?client=firefox-a&rls=org.mozilla:de:official"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: piclens@cooliris.com:1.12.0.36949
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.3.5
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:3.3.5
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.48.3
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010.07.09 09:03:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010.07.08 14:43:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.10.20 13:42:41 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.10.20 13:42:41 | 000,000,000 | ---D | M]
 
[2010.04.23 12:02:03 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\mozilla\Extensions
[2010.10.22 10:23:09 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions
[2010.10.19 00:44:13 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010.09.23 08:48:04 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010.09.10 16:18:40 | 000,000,000 | ---D | M] (WOT) -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010.10.15 09:14:10 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.08.18 22:58:44 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.07.29 22:52:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010.06.24 12:38:23 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\piclens@cooliris.com
[2010.06.24 12:38:23 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\piclens@cooliris.com-trash
[2010.09.10 16:18:36 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\mozilla\Firefox\Profiles\78redm0s.default\extensions\smarterwiki@wikiatic.com
[2010.04.23 13:21:41 | 000,002,251 | ---- | M] () -- C:\Users\dusty\AppData\Roaming\Mozilla\FireFox\Profiles\78redm0s.default\searchplugins\askcom.xml
[2010.03.24 16:13:02 | 000,000,917 | ---- | M] () -- C:\Users\dusty\AppData\Roaming\Mozilla\FireFox\Profiles\78redm0s.default\searchplugins\conduit.xml
[2010.06.08 12:03:12 | 000,001,620 | ---- | M] () -- C:\Users\dusty\AppData\Roaming\Mozilla\FireFox\Profiles\78redm0s.default\searchplugins\mozilla-add-ons.xml
[2010.06.08 11:40:46 | 000,001,115 | ---- | M] () -- C:\Users\dusty\AppData\Roaming\Mozilla\FireFox\Profiles\78redm0s.default\searchplugins\rapidshare-filefinder.xml
[2010.10.22 10:23:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions
[2010.06.24 17:56:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.08.15 10:06:19 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.10.18 11:02:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010.09.15 04:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010.04.01 18:54:38 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.04.01 18:54:38 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.04.01 18:54:38 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.04.01 18:54:38 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.04.01 18:54:38 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010.09.07 15:36:07 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2:64bit: - BHO: (Windows Live ID-Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files (x86)\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [AVMWlanClient] C:\Program Files (x86)\avmwlanstick\wlangui.exe (AVM Berlin)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Eraser RiskMonitor] C:\Program Files (x86)\East-Tec Eraser 2010\Launch.exe File not found
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Users\dusty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files (x86)\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Users\dusty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\dusty\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\dusty\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files (x86)\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (livessp) - C:\windows\SysNative\livessp.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\windows\SysWow64\livessp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.05.08 17:37:40 | 000,587,992 | R--- | M] (Stardock Entertainment, Inc.) - D:\autorun.exe -- [ UDF ]
O32 - AutoRun File - [2010.07.08 14:34:26 | 000,000,081 | R--- | M] () - D:\Autorun.inf -- [ UDF ]
O32 - AutoRun File - [2008.05.21 21:53:55 | 000,002,680 | R--- | M] () - D:\AutorunText.txt -- [ UDF ]
O33 - MountPoints2\{5bd39de3-0f11-11df-a982-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{5bd39de3-0f11-11df-a982-806e6f6e6963}\Shell\AutoRun\command - "" = D:\0data\cbs.exe -- [2010.08.04 13:35:31 | 003,418,112 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
 
MsConfig:64bit - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
MsConfig:64bit - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
MsConfig:64bit - StartUpReg: Steam - hkey= - key= - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
MsConfig:64bit - State: "services" - Reg Error: Key error.
MsConfig:64bit - State: "startup" - Reg Error: Key error.
 
Drivers32:64bit: aux - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midimapper - midimap.dll (Microsoft Corporation)
Drivers32:64bit: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32:64bit: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32:64bit: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32:64bit: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.iyuv - iyuv_32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.uyvy - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: vidc.yuy2 - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: vidc.yvu9 - tsbyuv.dll (Microsoft Corporation)
Drivers32:64bit: vidc.yvyu - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: wave - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wavemapper - msacm32.drv (Microsoft Corporation)
Drivers32: aux - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux2 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\windows\SysWow64\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - C:\windows\SysWow64\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\windows\SysWow64\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\windows\SysWow64\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\windows\SysWow64\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - C:\windows\SysWow64\sirenacm.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FMVC - C:\windows\SysWow64\fmcodec.DLL (Fox Magic Software)
Drivers32: vidc.i420 - C:\windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.iyuv - C:\windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\windows\SysWow64\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\windows\SysWow64\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\windows\SysWow64\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\windows\SysWow64\msacm32.drv (Microsoft Corporation)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 90 Days ==========
 
[2010.10.22 13:52:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT
[2010.10.22 10:12:04 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2010.10.22 09:54:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2010.10.22 09:54:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2010.10.21 01:28:13 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\EAST Technologies
[2010.10.21 01:26:22 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010.10.20 19:35:12 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysWow64\drivers\mbamswissarmy.sys
[2010.10.13 10:51:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2010.10.13 10:51:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2010.09.27 21:35:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Ubisoft
[2010.09.27 14:31:59 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Ironclad Games
[2010.09.27 14:31:42 | 000,000,000 | -H-D | C] -- C:\ProgramData\{A4B500C8-F3EB-4AD9-9762-515CCA35FD16}
[2010.09.27 14:13:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Kalypso
[2010.09.27 14:12:35 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Stardock
[2010.09.26 14:24:15 | 000,000,000 | ---D | C] -- C:\windows\Minidump
[2010.09.24 12:49:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nobilis
[2010.09.20 18:56:46 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\PhotoFiltre
[2010.09.20 18:56:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PhotoFiltre
[2010.09.13 16:06:48 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\NCSoft
[2010.09.13 11:56:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\City of Heroes
[2010.09.11 12:40:41 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\XMedia Recode
[2010.09.11 12:01:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XMedia Recode
[2010.09.11 11:22:00 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\Any Video Converter
[2010.09.11 11:21:46 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\AnvSoft
[2010.09.11 11:21:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AnvSoft
[2010.09.11 11:07:54 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\Xilisoft Corporation
[2010.09.11 11:07:52 | 000,000,000 | ---D | C] -- C:\Users\dusty\Application Data
[2010.09.09 19:24:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2010.09.09 19:23:57 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2010.09.09 10:08:11 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\Opera
[2010.09.09 10:08:11 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Opera
[2010.09.09 10:08:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
[2010.09.08 21:54:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winload
[2010.09.07 16:00:48 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010.09.07 16:00:40 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE
[2010.09.07 08:57:44 | 000,000,000 | ---D | C] -- C:\_OTL
[2010.09.06 22:49:55 | 000,000,000 | ---D | C] -- C:\Darkfall [Beta]
[2010.09.05 01:41:19 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Team_Horizon
[2010.09.04 17:48:50 | 000,000,000 | R--D | C] -- C:\Users\Public\Documents\Videos
[2010.09.02 20:58:05 | 000,000,000 | -HSD | C] -- C:\windows\SysWow64\%APPDATA%
[2010.09.02 19:19:13 | 000,000,000 | ---D | C] -- C:\windows\ERDNT
[2010.09.02 18:06:50 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\Malwarebytes
[2010.09.02 18:06:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.09.02 18:06:33 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2010.09.02 18:06:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010.09.01 15:53:12 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\My Downloads
[2010.09.01 15:53:03 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\GetRightToGo
[2010.08.26 03:57:50 | 000,462,336 | ---- | C] (AMD) -- C:\windows\SysNative\atieclxx.exe
[2010.08.26 03:57:14 | 000,203,264 | ---- | C] (AMD) -- C:\windows\SysNative\atiesrxx.exe
[2010.08.26 03:56:06 | 000,120,320 | ---- | C] (AMD) -- C:\windows\SysNative\atitmm64.dll
[2010.08.26 03:55:50 | 000,421,376 | ---- | C] (ATI Technologies, Inc.) -- C:\windows\SysNative\atipdl64.dll
[2010.08.26 03:55:42 | 000,356,352 | ---- | C] (ATI Technologies, Inc.) -- C:\windows\SysWow64\atipdlxx.dll
[2010.08.26 03:55:32 | 000,278,528 | ---- | C] (ATI Technologies, Inc.) -- C:\windows\SysWow64\Oemdspif.dll
[2010.08.26 03:55:28 | 000,012,288 | ---- | C] (AMD) -- C:\windows\SysNative\atimuixx.dll
[2010.08.26 03:55:22 | 000,059,392 | ---- | C] (ATI Technologies, Inc.) -- C:\windows\SysNative\atiedu64.dll
[2010.08.26 03:55:18 | 000,043,520 | ---- | C] (ATI Technologies, Inc.) -- C:\windows\SysWow64\ati2edxx.dll
[2010.08.25 23:35:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR
[2010.08.24 23:11:56 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\Mael
[2010.08.24 23:08:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HxD
[2010.08.17 20:06:01 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\Datel
[2010.08.15 20:21:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Google
[2010.08.15 10:06:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2010.08.11 23:55:17 | 000,000,000 | -H-D | C] -- C:\windows\PIF
[2010.08.04 18:25:08 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Deployment
[2010.08.04 18:25:08 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Apps
[2010.08.02 22:55:55 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\o_TRiPPiNz_LTD
[2010.08.02 18:21:43 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\kevin_MountPt
[2010.08.02 16:50:42 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Local\Xenocode
[2010.08.02 16:50:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xenocode
[2010.08.01 22:57:33 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\Neuer Ordner
[2010.08.01 22:52:33 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\E00002B9FA4D6428_MountPt
[2010.08.01 22:34:44 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\hg pornoarzt_MountPt
[2010.07.31 09:17:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\mp3Tag 5
[2010.07.30 11:49:14 | 000,000,000 | ---D | C] -- C:\Users\dusty\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.07.27 08:47:38 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\StarCraft II
[2010.07.27 08:47:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\StarCraft II
[2010.07.27 08:47:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
[2010.07.26 12:26:36 | 000,000,000 | ---D | C] -- C:\Users\dusty\Documents\Extras
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
 
========== Files - Modified Within 90 Days ==========
 
[2010.10.22 13:58:15 | 000,015,568 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.10.22 13:58:15 | 000,015,568 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.10.22 13:57:59 | 001,209,278 | ---- | M] () -- C:\windows\SysNative\drivers\N360x64\0403000.005\Cat.DB
[2010.10.22 13:57:57 | 008,126,464 | -HS- | M] () -- C:\Users\dusty\NTUSER.DAT
[2010.10.22 13:53:05 | 000,001,111 | ---- | M] () -- C:\Users\dusty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010.10.22 13:51:00 | 000,065,536 | ---- | M] () -- C:\windows\SysNative\Ikeext.etl
[2010.10.22 13:50:55 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2010.10.22 13:50:52 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2010.10.22 13:50:41 | 3218,939,904 | -HS- | M] () -- C:\hiberfil.sys
[2010.10.22 13:49:48 | 004,128,830 | -H-- | M] () -- C:\Users\dusty\AppData\Local\IconCache.db
[2010.10.22 13:46:34 | 000,001,014 | ---- | M] () -- C:\Users\dusty\Contacts\Desktop\MFTools - Verknüpfung.lnk
[2010.10.22 05:05:09 | 001,498,506 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2010.10.22 05:05:09 | 000,653,928 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2010.10.22 05:05:09 | 000,615,810 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2010.10.22 05:05:09 | 000,129,800 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2010.10.22 05:05:09 | 000,106,190 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2010.10.21 21:12:20 | 000,079,152 | ---- | M] () -- C:\Users\dusty\AppData\Local\GDIPFONTCACHEV1.DAT
[2010.10.21 21:11:41 | 000,343,752 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2010.10.21 21:08:51 | 000,004,788 | ---- | M] () -- C:\Users\dusty\Documents\cc 21.010.2010.reg
[2010.10.21 21:07:41 | 000,037,600 | ---- | M] () -- C:\Users\dusty\Documents\cc_20101021_210638.reg
[2010.10.20 18:00:28 | 000,000,819 | ---- | M] () -- C:\Users\dusty\Contacts\Desktop\Xbox 360 - Verknüpfung.lnk
[2010.10.20 16:51:01 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2010.10.10 12:52:49 | 000,000,439 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts.ics
[2010.09.21 00:01:15 | 000,000,172 | ---- | M] () -- C:\windows\SysNative\drivers\N360x64\0403000.005\isolate.ini
[2010.09.13 16:55:13 | 000,002,560 | ---- | M] () -- C:\windows\_MSRSTRT.EXE
[2010.09.11 12:01:58 | 000,001,074 | ---- | M] () -- C:\Users\Public\Desktop\XMedia Recode.lnk
[2010.09.11 11:21:50 | 000,001,147 | ---- | M] () -- C:\Users\dusty\Contacts\Desktop\Any Video Converter.lnk
[2010.09.07 15:36:07 | 000,000,098 | ---- | M] () -- C:\windows\SysNative\drivers\etc\Hosts
[2010.09.02 17:13:58 | 000,051,976 | ---- | M] () -- C:\Users\dusty\Documents\cc_20100902_171333.reg
[2010.08.26 04:01:34 | 000,076,216 | ---- | M] () -- C:\windows\SysNative\atiapfxx.blb
[2010.08.26 03:57:50 | 000,462,336 | ---- | M] (AMD) -- C:\windows\SysNative\atieclxx.exe
[2010.08.26 03:57:14 | 000,203,264 | ---- | M] (AMD) -- C:\windows\SysNative\atiesrxx.exe
[2010.08.26 03:56:06 | 000,120,320 | ---- | M] (AMD) -- C:\windows\SysNative\atitmm64.dll
[2010.08.26 03:55:50 | 000,421,376 | ---- | M] (ATI Technologies, Inc.) -- C:\windows\SysNative\atipdl64.dll
[2010.08.26 03:55:42 | 000,356,352 | ---- | M] (ATI Technologies, Inc.) -- C:\windows\SysWow64\atipdlxx.dll
[2010.08.26 03:55:32 | 000,278,528 | ---- | M] (ATI Technologies, Inc.) -- C:\windows\SysWow64\Oemdspif.dll
[2010.08.26 03:55:28 | 000,012,288 | ---- | M] (AMD) -- C:\windows\SysNative\atimuixx.dll
[2010.08.26 03:55:22 | 000,059,392 | ---- | M] (ATI Technologies, Inc.) -- C:\windows\SysNative\atiedu64.dll
[2010.08.26 03:55:18 | 000,043,520 | ---- | M] (ATI Technologies, Inc.) -- C:\windows\SysWow64\ati2edxx.dll
[2010.08.26 03:30:40 | 000,583,888 | ---- | M] () -- C:\windows\SysNative\atiumd6a.cap
[2010.08.26 03:27:58 | 000,057,344 | ---- | M] (AMD) -- C:\windows\SysNative\coinst.dll
[2010.08.26 03:25:36 | 000,583,888 | ---- | M] () -- C:\windows\SysWow64\atiumdva.cap
[2010.08.15 20:28:54 | 000,000,020 | -HS- | M] () -- C:\Users\dusty\ntuser.ini
[2010.08.15 19:26:58 | 000,110,326 | ---- | M] () -- C:\Users\dusty\Documents\SICHERUNG 15.08.reg
[2010.08.06 18:34:14 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010.08.02 10:38:00 | 000,021,866 | ---- | M] () -- C:\windows\atiogl.xml
[2010.07.29 10:26:39 | 000,000,064 | ---- | M] () -- C:\ProgramData\sandra.ldb
[2010.07.26 12:26:36 | 000,000,124 | ---- | M] () -- C:\Users\dusty\Documents\Visit GameTuts.url
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010.10.22 13:53:05 | 000,001,111 | ---- | C] () -- C:\Users\dusty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010.10.22 13:46:34 | 000,001,014 | ---- | C] () -- C:\Users\dusty\Contacts\Desktop\MFTools - Verknüpfung.lnk
[2010.10.21 21:08:48 | 000,004,788 | ---- | C] () -- C:\Users\dusty\Documents\cc 21.010.2010.reg
[2010.10.21 21:06:41 | 000,037,600 | ---- | C] () -- C:\Users\dusty\Documents\cc_20101021_210638.reg
[2010.10.20 18:00:28 | 000,000,819 | ---- | C] () -- C:\Users\dusty\Contacts\Desktop\Xbox 360 - Verknüpfung.lnk
[2010.10.09 18:32:29 | 000,065,536 | ---- | C] () -- C:\windows\SysNative\Ikeext.etl
[2010.09.13 16:55:12 | 000,002,560 | ---- | C] () -- C:\windows\_MSRSTRT.EXE
[2010.09.11 12:01:58 | 000,001,074 | ---- | C] () -- C:\Users\Public\Desktop\XMedia Recode.lnk
[2010.09.11 11:21:50 | 000,001,147 | ---- | C] () -- C:\Users\dusty\Contacts\Desktop\Any Video Converter.lnk
[2010.09.02 17:13:38 | 000,051,976 | ---- | C] () -- C:\Users\dusty\Documents\cc_20100902_171333.reg
[2010.08.26 04:01:34 | 000,076,216 | ---- | C] () -- C:\windows\SysNative\atiapfxx.blb
[2010.08.26 03:30:40 | 000,583,888 | ---- | C] () -- C:\windows\SysNative\atiumd6a.cap
[2010.08.26 03:25:36 | 000,583,888 | ---- | C] () -- C:\windows\SysWow64\atiumdva.cap
[2010.08.15 20:28:54 | 000,000,020 | -HS- | C] () -- C:\Users\dusty\ntuser.ini
[2010.08.15 19:25:31 | 000,110,326 | ---- | C] () -- C:\Users\dusty\Documents\SICHERUNG 15.08.reg
[2010.08.06 18:34:14 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010.08.02 10:38:00 | 000,021,866 | ---- | C] () -- C:\windows\atiogl.xml
[2010.07.31 09:17:02 | 000,335,872 | ---- | C] () -- C:\windows\SysWow64\m4atag.dll
[2010.07.29 10:26:38 | 000,000,064 | ---- | C] () -- C:\ProgramData\sandra.ldb
[2010.05.31 15:49:27 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010.05.01 13:37:04 | 013,045,760 | ---- | C] () -- C:\ProgramData\sandra.mda
[2010.05.01 13:26:19 | 000,000,133 | ---- | C] () -- C:\Users\dusty\AppData\Roaming\burnaware.ini
[2010.04.26 16:01:01 | 000,005,120 | ---- | C] () -- C:\Users\dusty\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.04.08 21:22:13 | 000,000,000 | ---- | C] () -- C:\Users\dusty\AppData\Roaming\wklnhst.dat
[2010.04.02 17:17:34 | 000,179,091 | ---- | C] () -- C:\windows\SysWow64\xlive.dll.cat
[2009.11.16 18:33:38 | 000,053,299 | ---- | C] () -- C:\windows\SysWow64\pthreadVC.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll
[2009.06.07 13:27:20 | 000,073,728 | ---- | C] () -- C:\windows\SysWow64\vbzlib1.dll
 
========== LOP Check ==========
 
[2010.07.08 14:51:19 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\1&1
[2010.06.03 11:12:07 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\AceBIT
[2010.09.11 11:21:46 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\AnvSoft
[2010.07.01 10:03:20 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Ashampoo
[2010.06.02 13:57:02 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Blender Foundation
[2010.05.01 13:12:09 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Canneverbe Limited
[2010.06.14 09:47:13 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Command and Conquer 4
[2010.04.12 15:30:48 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\COMPUTERBILD-Abzockschutz
[2010.04.12 16:54:33 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\DAEMON Tools Lite
[2010.08.17 20:06:01 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Datel
[2010.04.25 17:39:12 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\DeepBurner
[2010.07.30 11:49:14 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.10.21 22:10:22 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\EAST Technologies
[2010.04.23 11:40:22 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\FinalMediaPlayer
[2010.04.26 15:12:44 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\FreeVideoConverter
[2010.07.01 17:06:44 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\GameTuts
[2010.09.01 15:54:54 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\GetRightToGo
[2010.09.21 15:28:34 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\ICQ
[2010.08.24 23:11:56 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Mael
[2010.07.22 16:24:45 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\OpenCandy
[2010.09.09 10:08:11 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Opera
[2010.09.20 18:59:16 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\PhotoFiltre
[2010.08.06 20:04:54 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\TeamViewer
[2010.05.26 08:18:22 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\The Creative Assembly
[2010.05.04 08:38:43 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Tific
[2010.06.14 13:07:49 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Tropico 3
[2010.07.22 16:25:15 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\Uniblue
[2010.04.27 09:20:36 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\uTorrent
[2010.09.11 12:40:41 | 000,000,000 | ---D | M] -- C:\Users\dusty\AppData\Roaming\XMedia Recode
[2010.08.05 23:21:47 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*.* >
[2010.10.22 13:50:41 | 3218,939,904 | -HS- | M] () -- C:\hiberfil.sys
[2006.12.02 00:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2010.10.22 13:50:49 | 4291,919,872 | -HS- | M] () -- C:\pagefile.sys
 
< %systemroot%\system32\*.wt >
 
< %systemroot%\system32\*.ruy >
 
< %systemroot%\Fonts\*.com >
[2009.07.14 07:32:31 | 000,026,040 | ---- | M] () -- C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009.07.14 07:32:31 | 000,026,489 | ---- | M] () -- C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009.07.14 07:32:31 | 000,029,779 | ---- | M] () -- C:\windows\Fonts\GlobalSerif.CompositeFont
[2009.07.14 07:32:31 | 000,043,318 | ---- | M] () -- C:\windows\Fonts\GlobalUserInterface.CompositeFont
 
< %systemroot%\Fonts\*.dll >
 
< %systemroot%\Fonts\*.ini >
[2009.06.10 22:49:50 | 000,000,065 | ---- | M] () -- C:\windows\Fonts\desktop.ini
 
< %systemroot%\Fonts\*.ini2 >
 
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
 
< %systemroot%\REPAIR\*.bak1 >
 
< %systemroot%\REPAIR\*.ini >
 
< %systemroot%\system32\*.jpg >
 
< %systemroot%\*.scr >
[2010.04.17 01:45:28 | 000,307,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
 
< %systemroot%\*._sy >
 
< %APPDATA%\Adobe\Update\*.* >
 
< %ALLUSERSPROFILE%\Favorites\*.* >
 
< %APPDATA%\Microsoft\*.* >
 
< %PROGRAMFILES%\*.* >
[2009.07.14 06:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
 
< %APPDATA%\Update\*.* >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
< %systemroot%\Tasks\*.job /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\system32\user32.dll /md5 >
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll
 
< %systemroot%\system32\ws2_32.dll /md5 >
[2009.07.14 03:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\SysWOW64\ws2_32.dll
 
< %systemroot%\system32\ws2help.dll /md5 >
[2009.07.14 03:11:26 | 000,004,608 | ---- | M] (Microsoft Corporation) MD5=808AABDF9337312195CAFF76D1804786 -- C:\Windows\SysWOW64\ws2help.dll
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C97C8631
< End of report >

--- --- ---


Alle Zeitangaben in WEZ +1. Es ist jetzt 18:50 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129