Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte (https://www.trojaner-board.de/96763-windows-recovery-gibt-staendig-warnungen-kein-zugriff-mehr-festplatte.html)

shaiko 23.03.2011 17:45

Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte
 
Hallo,
habe gestern abend seit Dezember mein Laptop wieder benutzt. Habe Antivir aktualisiert und bin im Internet gewesen. Zudem hat mir der PC angezeigt, dass Windows updates vorliegen würden. Ich habe mich sehr gewundert, weil es insgesamt nur 3 waren, obwohl ich seit so langer Zeit das Laptop nicht benutzt habe. Ich habe auch nur die Märzversion Windows tool for removal of malicious... zum Download ausgewählt. Meines Erachtens ist der Download auch gar nicht erfolgt, da mir heute bei einem der zahlreichen Versuche Herunterzufahren bzw. Neuzustarten mehrfach die Option Install updates and shut down angeboten wurde...
In der Folge traten in rascher Folge Fehlermeldungen auf, erst bezgl. der Festplatte, dann mit der Warnung, dass private Daten gefährdet seien. Windows Recovery öffnete sich spontan und führte wiederholt Scans durch, die multiple Probleme anzeigten, die natürlich so nicht gefixt werden konnte. Es erfolgte die Aufforderung die advanced version runterzuladen und Zone alarm zeigte an, dass eine "18865972.exe"-Anwendung Zugriff verlange. Ich habe das abgelehnt. Das Desktop war bis auf den Papierkorb und einen Bluetooth-Symbol komplett leer. Ich habe den Computer runtergefahren und heute erneut gestartet, aber es hatte sich nichts getan. Ich habe dann mit meinem anderen Laptop ge-googlet und Eure Anleitung zur Entfernung von Windows Recovery gefunden.

Bei mir ist Windows XP installiert sowie Antivir Produktversion 10.0.0.635 und Zone Alarm.
Folgendes habe ich gemacht:
rkill.com heruntergeladen und laufen lassen,
dann Malwarebytes-vollständiger Scan (file s. unten),
die gefundenen Sachen gelöscht,
OTH-Othelper installiert und Malwarebytes nochmal-diesmal Quickscan (file-s.unten),
dann habe ich auch einen OTL-Scan gemacht- file s. unten.

Es wurde nur beim 1. Mal Malwarebytes etwas gefunden, beim 2. Mal nach OTH nicht mehr.
Wenn ich den PC jetzt starte: sind alle Dateien wieder auf dem Desktop, aber nur das Malwarebytes-Icon ist normal, alle anderen sehe aus wie markiert. Ich kann aber alle Dateien normal öffnen. Das Hintergrundbild ist weg, die Schnellstartleiste ist leer, die Symbole sind weg und es befindet sich noch ein Shortcut auf dem Desktop mit eben dem NAmen "Windows Recovery", unter Eigenschaften verweist der auf:
"C:\Documents and Settings\All Users\Application Data\18865972.exe".


Meine Frage nun:
1. ist mein System wegen des verbliebenen Shortcuts immer noch infiziert und was kann ich tun oder habe ich irgendwann mal vergessen neuzustarten und es ist daher nicht ordentlich gelöscht?

Vielen, vielen Dank schon mal !

PS: Sorry, ich muss gleich zur Arbeit, bin aber ab 22.30h wieder da, falls ich nicht sofort antworte !

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6140

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

23.03.2011 15:17:11
mbam-log-2011-03-23 (15-17-11).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 291918
Laufzeit: 1 Stunde(n), 27 Minute(n), 29 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 0
Infizierte Dateien: 3

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\XyeIUNjAcxCNDqR (Trojan.Downloader) -> Value: XyeIUNjAcxCNDqR -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\documents and settings\all users\application data\xyeiunjacxcndqr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\18865972.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\documents and settings\***\local settings\Temp\jar_cache1484479699214413479.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6141

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

23.03.2011 16:02:44
mbam-log-2011-03-23 (16-02-44).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 206921
Laufzeit: 28 Minute(n), 4 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)





LogOTL Logfile:
Code:

OTL logfile created on: 23.03.2011 16:44:05 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\***\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy
 
1.022,00 Mb Total Physical Memory | 418,00 Mb Available Physical Memory | 41,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 74,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 82,62 Gb Total Space | 33,49 Gb Free Space | 40,53% Space Free | Partition Type: NTFS
 
Computer Name: *** | User Name: *** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Documents and Settings\***\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SAMSUNG\AVStation Premium 3.75\AVSAgent.exe ()
PRC - C:\Program Files\SAMSUNG\Samsung Battery Manager\BatteryManager.exe ()
PRC - C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe (SAMSUNG Electronics Co., Ltd.)
PRC - C:\Program Files\SAMSUNG\DisplayManager\DisplayManager.exe (SAMSUNG)
PRC - C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
PRC - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.)
PRC - C:\Program Files\SAMSUNG\Samsung Network Manager\SNMWLANService.exe ()
PRC - C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
PRC - C:\Program Files\SAMSUNG\Samsung Update Plus\SLUTrayNotifier.exe ()
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe (SafeNet)
PRC - C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe (SafeNet)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Documents and Settings\***\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
MOD - C:\WINDOWS\system32\SynTPFcs.dll (Synaptics, Inc.)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (HidServ) -- File not found
SRV - (gupdate) Google Update Service (gupdate) -- File not found
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (vsmon) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) -- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (getPlusHelper) getPlus(R) -- C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (SRS_PostInstaller) -- C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.)
SRV - (SNM WLAN Service) -- C:\Program Files\SAMSUNG\Samsung Network Manager\SNMWLANService.exe ()
SRV - (bgsvcgen) -- C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
SRV - (Samsung Update Plus) -- C:\Program Files\SAMSUNG\Samsung Update Plus\SLUBackgroundService.exe ()
SRV - (IPSECMON) -- C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe (SafeNet)
SRV - (IreIKE) -- C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe (SafeNet)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ISWKL) -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (vsdatant) -- C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (motmodem) -- C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (w39n51) Intel(R) -- C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (BTSERIAL) -- C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BsStor) -- C:\WINDOWS\System32\drivers\BsStor.sys (Cyberlink Co.,Ltd.)
DRV - (BsUDF) -- C:\WINDOWS\System32\drivers\BsUDF.sys (CyberLink Corporation.)
DRV - (wowfilter) -- C:\WINDOWS\system32\drivers\WOWFilter.sys ()
DRV - (rimmptsk) -- C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) -- C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) -- C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (SUEPD) -- C:\WINDOWS\system32\drivers\SUE_PD.sys (Samsung)
DRV - (HdAudAddService) -- C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows (R) Server 2003 DDK provider)
DRV - (IPSECDRV) -- C:\WINDOWS\system32\drivers\IpSecDrv.sys (SafeNet)
DRV - (Crypto) -- C:\WINDOWS\System32\drivers\Crypto.sig ()
DRV - (DNE) -- C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (DniVap) SafeNet WAN Miniport (VA) -- C:\WINDOWS\system32\drivers\vap.sys (Deterministic Networks Inc.)
DRV - (DOSMEMIO) -- C:\WINDOWS\system32\MEMIO.SYS ()
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://de.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:de:official"
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011.03.22 22:49:42 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.23 13:24:47 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.12.18 00:12:09 | 000,000,000 | -H-D | M]
 
[2009.01.20 23:33:40 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Extensions
[2007.02.12 10:18:16 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\gn1x3wbj.default\extensions
[2011.03.23 13:25:02 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions
[2010.02.09 19:40:21 | 000,000,000 | -H-D | M] (F5 Networks Cache Cleaner Plugin) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\{3191E4CE-790E-42be-B2E0-223475263B7E}
[2010.11.05 17:48:23 | 000,000,000 | -H-D | M] (Adblock Plus) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.06.25 17:27:05 | 000,000,000 | -H-D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011.03.23 13:26:36 | 000,000,000 | -H-D | M] (IE Tab Plus) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\ietab@ip.cn
[2010.02.22 20:29:08 | 000,000,000 | -H-D | M] (Advertising Cookie Opt-out) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\optout@google.com
[2011.03.22 23:12:03 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2007.03.10 00:16:44 | 000,189,496 | -H-- | M] (Yahoo! Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
[2010.11.04 22:17:04 | 000,001,392 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.11.04 22:17:04 | 000,002,344 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.11.04 22:17:04 | 000,006,805 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.11.04 22:17:04 | 000,001,178 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.11.04 22:17:04 | 000,001,105 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010.08.05 22:47:22 | 000,396,932 | RH-- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1    www.007guard.com
O1 - Hosts: 127.0.0.1    007guard.com
O1 - Hosts: 127.0.0.1    008i.com
O1 - Hosts: 127.0.0.1    www.008k.com
O1 - Hosts: 127.0.0.1    008k.com
O1 - Hosts: 127.0.0.1    www.00hq.com
O1 - Hosts: 127.0.0.1    00hq.com
O1 - Hosts: 127.0.0.1    010402.com
O1 - Hosts: 127.0.0.1    www.032439.com
O1 - Hosts: 127.0.0.1    032439.com
O1 - Hosts: 127.0.0.1    www.0scan.com
O1 - Hosts: 127.0.0.1    0scan.com
O1 - Hosts: 127.0.0.1    www.1000gratisproben.com
O1 - Hosts: 127.0.0.1    1000gratisproben.com
O1 - Hosts: 127.0.0.1    www.1001namen.com
O1 - Hosts: 127.0.0.1    1001namen.com
O1 - Hosts: 127.0.0.1    www.100888290cs.com
O1 - Hosts: 127.0.0.1    100888290cs.com
O1 - Hosts: 127.0.0.1    www.100sexlinks.com
O1 - Hosts: 127.0.0.1    100sexlinks.com
O1 - Hosts: 127.0.0.1    10sek.com
O1 - Hosts: 127.0.0.1    www.10sek.com
O1 - Hosts: 127.0.0.1    1-2005-search.com
O1 - Hosts: 127.0.0.1    www.1-2005-search.com
O1 - Hosts: 13702 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [AVStation Premium 3.75] C:\Program Files\SAMSUNG\AVStation Premium 3.75\AVSAgent.exe ()
O4 - HKLM..\Run: [BatteryManager] C:\Program Files\SAMSUNG\Samsung Battery Manager\BatteryManager.exe ()
O4 - HKLM..\Run: [B'sCLiP] C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation)
O4 - HKLM..\Run: [DisplayManager] C:\Program Files\SAMSUNG\DisplayManager\DMLoader.exe (SAMSUNG)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows (R) Server 2003 DDK provider)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKbd.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [Power2GoExpress] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher 2.lnk = C:\Programme\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NetScreen-Remote.lnk = C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe (SafeNet)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe ()
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} https://access.uke.de/vdesk/cachecleaner.cab#version=6031,2009,1010,0301 (F5 Networks CacheCleaner)
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} https://access.uke.de/vdesk/terminal/InstallerControl.cab (F5 Networks Auto Update)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1171391294718 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} https://***
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mfi.ku.dk
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\***\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\***\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.04.05 12:49:33 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.03.23 15:32:35 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\***\Desktop\mbam-setup.exe
[2011.03.23 13:46:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\Application Data\Malwarebytes
[2011.03.23 13:46:02 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.03.23 13:46:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.03.23 13:46:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011.03.23 13:45:57 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.03.23 13:45:56 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.03.23 13:27:15 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\***\Recent
[2011.03.23 00:51:46 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\***\Start Menu\Programs\Windows Recovery
[2011.03.22 22:34:02 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\***\Application Data\Avira
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.03.23 16:40:00 | 000,001,102 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011.03.23 16:12:41 | 000,000,077 | -HS- | M] () -- C:\cj.ini
[2011.03.23 16:11:58 | 000,001,098 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011.03.23 16:11:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.03.23 15:33:50 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.03.23 15:32:35 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\***\Desktop\mbam-setup.exe
[2011.03.23 13:21:58 | 000,043,616 | -H-- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011.03.23 00:53:27 | 000,000,400 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\18865972
[2011.03.23 00:51:48 | 000,000,813 | -H-- | M] () -- C:\Documents and Settings\***\Desktop\Windows Recovery.lnk
[2011.03.22 22:39:06 | 000,000,990 | -H-- | M] () -- C:\Documents and Settings\***\Desktop\Install PartyPoker.net.lnk
[2011.03.22 22:35:14 | 000,137,656 | -H-- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011.03.22 22:32:33 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.03.23 13:46:02 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.03.23 00:51:48 | 000,000,813 | -H-- | C] () -- C:\Documents and Settings\***\Desktop\Windows Recovery.lnk
[2011.03.23 00:51:41 | 000,000,400 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\18865972
[2011.03.22 22:39:05 | 000,000,990 | -H-- | C] () -- C:\Documents and Settings\***\Desktop\Install PartyPoker.net.lnk
[2009.12.06 12:55:46 | 000,006,656 | -H-- | C] () -- C:\WINDOWS\System32\CNMVS58.DLL
[2009.11.25 19:42:23 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2009.07.17 20:34:28 | 000,007,168 | -H-- | C] () -- C:\Documents and Settings\***\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.06.29 11:27:37 | 000,116,224 | -H-- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2008.12.27 21:13:04 | 000,003,286 | -H-- | C] () -- C:\WINDOWS\tm.ini
[2008.07.17 20:43:16 | 000,000,016 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\obtf501
[2007.10.24 16:48:08 | 000,001,755 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007.09.16 15:32:31 | 000,000,025 | -H-- | C] () -- C:\WINDOWS\cdplayer.ini
[2007.03.04 00:33:12 | 000,000,116 | -H-- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007.02.18 14:59:33 | 000,335,872 | -H-- | C] () -- C:\WINDOWS\System32\ldf252.dll
[2007.02.12 11:47:48 | 000,003,183 | -H-- | C] () -- C:\WINDOWS\mozver.dat
[2007.02.12 10:18:17 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\nsreg.dat
[2007.02.07 22:35:50 | 000,006,550 | -H-- | C] () -- C:\WINDOWS\jautoexp.dat
[2007.01.31 11:01:53 | 000,143,360 | -H-- | C] () -- C:\WINDOWS\System32\nsldap32v50.dll
[2007.01.31 11:01:47 | 000,000,342 | -H-- | C] () -- C:\WINDOWS\OemOut.ini
[2007.01.27 22:18:35 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2007.01.27 22:16:36 | 000,192,976 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007.01.27 22:08:14 | 000,363,520 | -H-- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007.01.27 21:59:31 | 000,000,135 | RH-- | C] () -- C:\WINDOWS\System32\lngEng.ini
[2007.01.27 21:59:31 | 000,000,117 | -H-- | C] () -- C:\WINDOWS\System32\lngKor.ini
[2007.01.27 21:57:10 | 000,001,522 | -H-- | C] () -- C:\WINDOWS\System32\MagicKBD.INI
[2007.01.27 21:57:10 | 000,001,520 | ---- | C] () -- C:\WINDOWS\System32\***_KBD.ini
[2007.01.27 21:57:08 | 000,004,300 | -H-- | C] () -- C:\WINDOWS\System32\MEMIO.SYS
[2007.01.27 21:57:08 | 000,003,425 | -H-- | C] () -- C:\WINDOWS\System32\KBDR.INI
[2007.01.27 21:57:08 | 000,002,741 | -H-- | C] () -- C:\WINDOWS\System32\KBDD.INI
[2007.01.27 21:57:08 | 000,002,699 | -H-- | C] () -- C:\WINDOWS\System32\KBDO.INI
[2007.01.27 21:57:08 | 000,002,699 | -H-- | C] () -- C:\WINDOWS\System32\KBDC.INI
[2007.01.27 21:57:08 | 000,002,606 | -H-- | C] () -- C:\WINDOWS\System32\KBDB.INI
[2007.01.27 21:57:08 | 000,002,236 | -H-- | C] () -- C:\WINDOWS\System32\KBDQ.INI
[2007.01.27 21:57:08 | 000,001,956 | -H-- | C] () -- C:\WINDOWS\System32\KBDE.INI
[2007.01.27 21:57:08 | 000,001,885 | -H-- | C] () -- C:\WINDOWS\System32\KBDP.INI
[2007.01.27 21:57:08 | 000,001,835 | -H-- | C] () -- C:\WINDOWS\System32\KBDG.INI
[2007.01.27 21:57:08 | 000,001,835 | -H-- | C] () -- C:\WINDOWS\System32\KBDA.INI
[2007.01.27 21:57:08 | 000,001,834 | -H-- | C] () -- C:\WINDOWS\System32\KBDU.INI
[2007.01.27 21:57:08 | 000,001,819 | -H-- | C] () -- C:\WINDOWS\System32\KBDN.INI
[2007.01.27 21:57:08 | 000,001,699 | -H-- | C] () -- C:\WINDOWS\System32\KBDT.INI
[2007.01.27 21:57:08 | 000,001,697 | -H-- | C] () -- C:\WINDOWS\System32\KBDV.INI
[2007.01.27 21:57:08 | 000,001,522 | -H-- | C] () -- C:\WINDOWS\System32\KBDS.INI
[2007.01.27 21:57:08 | 000,001,476 | -H-- | C] () -- C:\WINDOWS\System32\KBDF.INI
[2007.01.27 21:45:43 | 000,016,480 | -H-- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2007.01.27 21:34:36 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2007.01.27 21:28:03 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006.01.25 15:00:50 | 000,081,920 | -H-- | C] () -- C:\WINDOWS\System32\AVSAudioAmp.dll
[2006.01.25 15:00:50 | 000,061,440 | -H-- | C] () -- C:\WINDOWS\System32\AVSAudioWideStereoDMO.dll
[2005.12.08 02:53:00 | 001,662,976 | -H-- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2005.12.08 02:53:00 | 001,519,616 | -H-- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2005.12.08 02:53:00 | 001,466,368 | -H-- | C] () -- C:\WINDOWS\System32\nview.dll
[2005.12.08 02:53:00 | 001,339,392 | -H-- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2005.12.08 02:53:00 | 001,019,904 | -H-- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2005.12.08 02:53:00 | 000,466,944 | -H-- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2005.12.08 02:53:00 | 000,442,368 | -H-- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2005.12.08 02:53:00 | 000,110,592 | -H-- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2005.12.02 14:14:56 | 000,090,112 | -H-- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2005.11.28 12:06:22 | 000,038,144 | -H-- | C] () -- C:\WINDOWS\System32\drivers\WOWXT_kern_i386.sys
[2005.11.28 12:06:22 | 000,019,456 | -H-- | C] () -- C:\WINDOWS\System32\drivers\WOWFilter.sys
[2005.11.28 12:06:20 | 000,031,232 | -H-- | C] () -- C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2004.08.02 14:20:40 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat
[2003.07.07 17:00:00 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin
[2003.07.07 17:00:00 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat
[2003.07.07 17:00:00 | 000,432,690 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2003.07.07 17:00:00 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2003.07.07 17:00:00 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat
[2003.07.07 17:00:00 | 000,067,646 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2003.07.07 17:00:00 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin
[2003.07.07 17:00:00 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2003.07.07 17:00:00 | 000,004,463 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat
[2003.07.07 17:00:00 | 000,001,788 | -H-- | C] () -- C:\WINDOWS\System32\dcache.bin
[2003.07.07 17:00:00 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat
[2002.09.17 23:45:00 | 000,119,808 | -H-- | C] () -- C:\WINDOWS\lsb_un20.exe
[2001.11.14 12:56:00 | 001,802,240 | -H-- | C] () -- C:\WINDOWS\System32\lcppn21.dll
 
========== LOP Check ==========
 
[2010.11.21 23:19:30 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009.12.17 14:48:31 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\e-Safekey
[2009.11.25 19:42:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2010.10.03 20:20:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\RapidTyping
[2009.11.25 18:05:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Sophos
[2007.02.18 15:00:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\ACD Systems
[2009.10.21 22:39:16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\Amazon
[2010.08.16 13:56:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\CheckPoint
[2007.08.29 14:42:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\FUJIFILM
[2008.07.17 20:43:15 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\GraphPad Software
[2007.01.28 16:27:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\ISI ResearchSoft
[2010.10.03 20:20:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\RapidTyping
[2009.11.25 18:05:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\stickies
 
========== Purity Check ==========
 
 
 
< End of report >

--- --- ---
OTL Logfile:
Code:

OTL Extras logfile created on: 23.03.2011 16:44:05 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\***\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy
 
1.022,00 Mb Total Physical Memory | 418,00 Mb Available Physical Memory | 41,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 74,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 82,62 Gb Total Space | 33,49 Gb Free Space | 40,53% Space Free | Partition Type: NTFS
 
Computer Name: *** | User Name: ***| Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] -- "C:\PROGRA~2\ACDSYS~1\ACDSee\ACDSee.exe" "%1"
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [FinePix] -- "C:\Programme\FinePixViewer\FinePixViewer.exe" "%1" (FUJIFILM Corporation.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe" = C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe:*:Enabled:IreIke -- (SafeNet)
"C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe" = C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog -- (SafeNet)
"C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe" = C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp -- (SafeNet)
"C:\Program Files\Juniper\NetScreen-Remote\vpn.exe" = C:\Program Files\Juniper\NetScreen-Remote\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager -- (SafeNet)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon -- (Check Point Software Technologies LTD)
"C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe" = C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe:*:Enabled:IreIke -- (SafeNet)
"C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe" = C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog -- (SafeNet)
"C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe" = C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp -- (SafeNet)
"C:\Program Files\Juniper\NetScreen-Remote\vpn.exe" = C:\Program Files\Juniper\NetScreen-Remote\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager -- (SafeNet)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{17283B95-21A8-4996-97DA-547A48DB266F}" = DisplayManager
"{17CA6206-7109-4426-8EE0-1BD0BE54BCC9}" = Management Center
"{19C64880-BBCA-11D4-9EEE-0004ACDDDB3B}" = CyberLink InstantBurn
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = PowerStarter
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.5.3
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 13
"{2F931B84-0CEE-11D1-AA7D-0080AD1AC47A}" = NetScreen-Remote
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 4.0
"{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver
"{55B1E4FA-F2E0-45DF-9B36-0B30A7949984}" = NWZ-S540 WALKMAN Guide
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Samsung Battery Manager
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38}" = Microsoft .NET Framework 2.0 Language Pack - DEU
"{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (German) 12
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007
"{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A48A8684-A104-44DA-B3DF-0178A125D8D9}" = WOW XT and TSXT Filter Driver
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A999CE76-D054-4684-80C7-53FC9243E019}" = EasyBox
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{B093990A-AAF2-44AC-9216-14BB7A2189B6}" = ImageMixer VCD2 LE for FinePix
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B44529FF-501E-47CD-A06D-223C161BE058}" = FinePixViewer Resource
"{B5924CA6-24A7-48F5-BC9C-8BFA94ED4564}" = LightScribe 1.4.67.1
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75
"{BC892294-7616-49A2-B165-0E60305CB6EA}" = Eudora
"{BD723E53-A42C-4702-AA04-1D74A0311590}" = Magic Keyboard
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0B0893D-6DA2-4F14-B1D0-3C0F1272B398}" = Reference Manager 11.0.1
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint 1.0
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer
"{D5A9B7C0-8751-11D8-9D75-000129760D75}" = MediaShow 3.0
"{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime
"{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}" = FinePix Studio
"{E5E54037-31CD-4EBD-9211-4C384F4E7E79}" = e-Safekey
"{E96FF910-1BC9-4EE5-BC12-0A30D4E20F37}" = NWZ-E440 WALKMAN Guide
"{EF99C14B-17C2-4994-B5C1-EB204A343A6F}" = User's Guide
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AFPL Ghostscript 8.54" = AFPL Ghostscript 8.54
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"Agere Systems Soft Modem" = SENS LT56ADW Modem
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.5
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CANONBJ_Deinstall_CNMCP58.DLL" = Canon i560
"CDex" = CDex extraction audio
"ENTERPRISE" = Microsoft Office Enterprise 2007
"InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"InstallShield_{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75
"InstallShield_{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0
"ISI ResearchSoft - Export Helper" = ISI ResearchSoft - Export Helper
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0 Language Pack - DEU" = Microsoft .NET Framework 2.0 Language Pack - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NVIDIA Drivers" = NVIDIA Drivers
"PartyPoker" = PartyPoker
"PartyPokerNet" = PartyPokerNet
"PDF Blender" = PDF Blender
"ProInst" = Intel(R) PROSet/Wireless Software
"RapidTyping" = RapidTyping
"RealPlayer 6.0" = RealPlayer
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinLems_is1" = WinLems 1.24
"WinRAR archiver" = WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Widget Engine" = Yahoo! Widgets
"ZoneAlarm" = ZoneAlarm
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 23.03.2011 07:49:54 | Computer Name = MF2249 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
 
Error - 23.03.2011 07:50:56 | Computer Name = MF2249 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
 
Error - 23.03.2011 07:59:13 | Computer Name = MF2249 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
 
Error - 23.03.2011 08:00:24 | Computer Name = MF2249 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
 
Error - 23.03.2011 08:22:13 | Computer Name = *** | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
 
Error - 23.03.2011 08:23:14 | Computer Name = MF2249 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
 
Error - 23.03.2011 10:21:12 | Computer Name = *** | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
 
Error - 23.03.2011 10:22:12 | Computer Name = *** | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
 
Error - 23.03.2011 11:12:14 | Computer Name = *** | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
 
Error - 23.03.2011 11:13:14 | Computer Name = *** | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
 
[ OSession Events ]
Error - 10.06.2007 13:27:03 | Computer Name = *** | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 20380 seconds with 8580 seconds of active time. This session ended with
a crash.
 
[ System Events ]
Error - 23.03.2011 10:25:40 | Computer Name = *** | Source = Service Control Manager | ID = 7034
Description = The SNM WLAN Service service terminated unexpectedly. It has done
this 1 time(s).
 
Error - 23.03.2011 10:25:40 | Computer Name = *** | Source = Service Control Manager | ID = 7034
Description = The SRS PostInstaller Service service terminated unexpectedly. It
has done this 1 time(s).
 
Error - 23.03.2011 10:29:59 | Computer Name = ***| Source = Service Control Manager | ID = 7031
Description = The Bluetooth Service service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.
 
Error - 23.03.2011 10:36:16 | Computer Name = ***| Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.
 
Error - 23.03.2011 11:06:22 | Computer Name = ***| Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 59 minutes. NtpClient has no source of accurate
time.
 
Error - 23.03.2011 11:12:14 | Computer Name = ***| Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
 
Error - 23.03.2011 11:12:14 | Computer Name = ***| Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
 
Error - 23.03.2011 11:12:15 | Computer Name = ***| Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CSAM due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.
 
Error - 23.03.2011 11:13:18 | Computer Name = ***| Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
the following error: %%3
 
Error - 23.03.2011 11:27:23 | Computer Name = ***| Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.
 
 
< End of report >

--- --- ---

cosinus 24.03.2011 10:30

Zitat:

Bei mir ist Windows XP installiert sowie Antivir Produktversion 10.0.0.635 und Zone Alarm.
ZoneAlarm ist Quatsch mit Soße. Bitte deinstallieren und die Windows-Firewall verwenden.
Mach danach bitte frische Logs mit OTL.exe und poste sie.

shaiko 24.03.2011 22:27

Hallo Arne,
vielen Dank erstmal für Deine Antwort. Ich habe Zone Alarm deinstalliert und die Windows Firewall aktiviert.
Nun kann ich nicht mehr auf das Internet zugreifen, obwohl ich unter Exceptions firefox.exe angegeben habe. Mache ich etwas falsch oder hängt das eine mit dem anderen nicht zusammen ?

Vielen Dank schon mal
shaiko

shaiko 24.03.2011 22:32

Hi Arne,
Jetzt geht es wieder.
Und Danke nochmal für Deine zukünftigen Antworten.

Hier sind die neuen Logfiles nach Deinstallation von Zone Alarm und Aktivierung der Windows Firewall:OTL Logfile:
Code:

OTL logfile created on: 24.03.2011 22:00:10 - Run 2
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Documents and Settings\***\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy
 
1.022,00 Mb Total Physical Memory | 561,00 Mb Available Physical Memory | 55,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 83,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 82,62 Gb Total Space | 33,61 Gb Free Space | 40,68% Space Free | Partition Type: NTFS
 
Computer Name: ***| User Name: *** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Documents and Settings\***\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SAMSUNG\AVStation Premium 3.75\AVSAgent.exe ()
PRC - C:\Program Files\SAMSUNG\Samsung Battery Manager\BatteryManager.exe ()
PRC - C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe (SAMSUNG Electronics Co., Ltd.)
PRC - C:\Program Files\SAMSUNG\DisplayManager\DisplayManager.exe (SAMSUNG)
PRC - C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
PRC - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.)
PRC - C:\Program Files\SAMSUNG\Samsung Network Manager\SNMWLANService.exe ()
PRC - C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
PRC - C:\Program Files\SAMSUNG\Samsung Update Plus\SLUTrayNotifier.exe ()
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe (SafeNet)
PRC - C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe (SafeNet)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Documents and Settings\***\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\SynTPFcs.dll (Synaptics, Inc.)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (HidServ) --  File not found
SRV - (gupdate) Google Update Service (gupdate) --  File not found
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (getPlusHelper) getPlus(R) -- C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (SRS_PostInstaller) -- C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.)
SRV - (SNM WLAN Service) -- C:\Program Files\SAMSUNG\Samsung Network Manager\SNMWLANService.exe ()
SRV - (bgsvcgen) -- C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
SRV - (Samsung Update Plus) -- C:\Program Files\SAMSUNG\Samsung Update Plus\SLUBackgroundService.exe ()
SRV - (IPSECMON) -- C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe (SafeNet)
SRV - (IreIKE) -- C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe (SafeNet)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (motmodem) -- C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (w39n51) Intel(R) -- C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (BTSERIAL) -- C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BsStor) -- C:\WINDOWS\System32\drivers\BsStor.sys (Cyberlink Co.,Ltd.)
DRV - (BsUDF) -- C:\WINDOWS\System32\drivers\BsUDF.sys (CyberLink Corporation.)
DRV - (wowfilter) -- C:\WINDOWS\system32\drivers\WOWFilter.sys ()
DRV - (rimmptsk) -- C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) -- C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) -- C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (SUEPD) -- C:\WINDOWS\system32\drivers\SUE_PD.sys (Samsung)
DRV - (HdAudAddService) -- C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows (R) Server 2003 DDK provider)
DRV - (IPSECDRV) -- C:\WINDOWS\system32\drivers\IpSecDrv.sys (SafeNet)
DRV - (Crypto) -- C:\WINDOWS\System32\drivers\Crypto.sig ()
DRV - (DNE) -- C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (DniVap) SafeNet WAN Miniport (VA) -- C:\WINDOWS\system32\drivers\vap.sys (Deterministic Networks Inc.)
DRV - (DOSMEMIO) -- C:\WINDOWS\system32\MEMIO.SYS ()
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://de.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:de:official"
 
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.23 13:24:47 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.12.18 00:12:09 | 000,000,000 | -H-D | M]
 
[2009.01.20 23:33:40 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Extensions
[2007.02.12 10:18:16 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\gn1x3wbj.default\extensions
[2011.03.23 13:25:02 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions
[2010.02.09 19:40:21 | 000,000,000 | -H-D | M] (F5 Networks Cache Cleaner Plugin) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\{3191E4CE-790E-42be-B2E0-223475263B7E}
[2010.11.05 17:48:23 | 000,000,000 | -H-D | M] (Adblock Plus) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.06.25 17:27:05 | 000,000,000 | -H-D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011.03.23 13:26:36 | 000,000,000 | -H-D | M] (IE Tab Plus) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\ietab@ip.cn
[2010.02.22 20:29:08 | 000,000,000 | -H-D | M] (Advertising Cookie Opt-out) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\optout@google.com
[2011.03.22 23:12:03 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2007.03.10 00:16:44 | 000,189,496 | -H-- | M] (Yahoo! Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
[2010.11.04 22:17:04 | 000,001,392 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.11.04 22:17:04 | 000,002,344 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.11.04 22:17:04 | 000,006,805 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.11.04 22:17:04 | 000,001,178 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.11.04 22:17:04 | 000,001,105 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010.08.05 22:47:22 | 000,396,932 | RH-- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        www.0scan.com
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        www.1000gratisproben.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        www.1001namen.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        1-2005-search.com
O1 - Hosts: 127.0.0.1        www.1-2005-search.com
O1 - Hosts: 13702 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [AVStation Premium 3.75] C:\Program Files\SAMSUNG\AVStation Premium 3.75\AVSAgent.exe ()
O4 - HKLM..\Run: [BatteryManager] C:\Program Files\SAMSUNG\Samsung Battery Manager\BatteryManager.exe ()
O4 - HKLM..\Run: [B'sCLiP] C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation)
O4 - HKLM..\Run: [DisplayManager] C:\Program Files\SAMSUNG\DisplayManager\DMLoader.exe (SAMSUNG)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows (R) Server 2003 DDK provider)
O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKbd.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [Power2GoExpress]  File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher 2.lnk = C:\Programme\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NetScreen-Remote.lnk = C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe (SafeNet)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe ()
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} https://access.uke.de/vdesk/cachecleaner.cab#version=6031,2009,1010,0301 (F5 Networks CacheCleaner)
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} https://access.uke.de/vdesk/terminal/InstallerControl.cab (F5 Networks Auto Update)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1171391294718 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} https://***
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mfi.ku.dk
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\***\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\***\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.04.05 12:49:33 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.03.24 21:51:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Internet Logs
[2011.03.23 16:14:22 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\***\Desktop\OTL.exe
[2011.03.23 15:32:35 | 007,734,208 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Documents and Settings\***\Desktop\mbam-setup.exe
[2011.03.23 13:46:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\Application Data\Malwarebytes
[2011.03.23 13:46:02 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.03.23 13:46:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.03.23 13:46:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011.03.23 13:45:57 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.03.23 13:45:56 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.03.23 13:27:15 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\***\Recent
[2011.03.23 00:51:46 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\***\Start Menu\Programs\Windows Recovery
[2011.03.22 22:34:02 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\***\Application Data\Avira
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.03.24 21:51:59 | 000,000,077 | -HS- | M] () -- C:\cj.ini
[2011.03.24 21:51:41 | 000,001,098 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011.03.24 21:51:33 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.03.24 21:44:17 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.03.23 17:40:00 | 000,001,102 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011.03.23 16:14:26 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\***\Desktop\OTL.exe
[2011.03.23 15:33:50 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.03.23 15:32:35 | 007,734,208 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Documents and Settings\***\Desktop\mbam-setup.exe
[2011.03.23 13:21:58 | 000,043,616 | -H-- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011.03.23 00:53:27 | 000,000,400 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\18865972
[2011.03.23 00:51:48 | 000,000,813 | -H-- | M] () -- C:\Documents and Settings\***\Desktop\Windows Recovery.lnk
[2011.03.22 22:39:06 | 000,000,990 | -H-- | M] () -- C:\Documents and Settings\***\Desktop\Install PartyPoker.net.lnk
[2011.03.22 22:35:14 | 000,137,656 | -H-- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.03.23 13:46:02 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.03.23 00:51:48 | 000,000,813 | -H-- | C] () -- C:\Documents and Settings\***\Desktop\Windows Recovery.lnk
[2011.03.23 00:51:41 | 000,000,400 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\18865972
[2011.03.22 22:39:05 | 000,000,990 | -H-- | C] () -- C:\Documents and Settings\***\Desktop\Install PartyPoker.net.lnk
[2009.12.06 12:55:46 | 000,006,656 | -H-- | C] () -- C:\WINDOWS\System32\CNMVS58.DLL
[2009.11.25 19:42:23 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2009.07.17 20:34:28 | 000,007,168 | -H-- | C] () -- C:\Documents and Settings\***\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.06.29 11:27:37 | 000,116,224 | -H-- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2008.12.27 21:13:04 | 000,003,286 | -H-- | C] () -- C:\WINDOWS\tm.ini
[2008.07.17 20:43:16 | 000,000,016 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\obtf501
[2007.10.24 16:48:08 | 000,001,755 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007.09.16 15:32:31 | 000,000,025 | -H-- | C] () -- C:\WINDOWS\cdplayer.ini
[2007.03.04 00:33:12 | 000,000,116 | -H-- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007.02.18 14:59:33 | 000,335,872 | -H-- | C] () -- C:\WINDOWS\System32\ldf252.dll
[2007.02.12 11:47:48 | 000,003,183 | -H-- | C] () -- C:\WINDOWS\mozver.dat
[2007.02.12 10:18:17 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\nsreg.dat
[2007.02.07 22:35:50 | 000,006,550 | -H-- | C] () -- C:\WINDOWS\jautoexp.dat
[2007.01.31 11:01:53 | 000,143,360 | -H-- | C] () -- C:\WINDOWS\System32\nsldap32v50.dll
[2007.01.31 11:01:47 | 000,000,342 | -H-- | C] () -- C:\WINDOWS\OemOut.ini
[2007.01.27 22:18:35 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2007.01.27 22:16:36 | 000,192,976 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007.01.27 22:08:14 | 000,363,520 | -H-- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007.01.27 21:59:31 | 000,000,135 | RH-- | C] () -- C:\WINDOWS\System32\lngEng.ini
[2007.01.27 21:59:31 | 000,000,117 | -H-- | C] () -- C:\WINDOWS\System32\lngKor.ini
[2007.01.27 21:57:10 | 000,001,522 | -H-- | C] () -- C:\WINDOWS\System32\MagicKBD.INI
[2007.01.27 21:57:10 | 000,001,520 | ---- | C] () -- C:\WINDOWS\System32\***_KBD.ini
[2007.01.27 21:57:08 | 000,004,300 | -H-- | C] () -- C:\WINDOWS\System32\MEMIO.SYS
[2007.01.27 21:57:08 | 000,003,425 | -H-- | C] () -- C:\WINDOWS\System32\KBDR.INI
[2007.01.27 21:57:08 | 000,002,741 | -H-- | C] () -- C:\WINDOWS\System32\KBDD.INI
[2007.01.27 21:57:08 | 000,002,699 | -H-- | C] () -- C:\WINDOWS\System32\KBDO.INI
[2007.01.27 21:57:08 | 000,002,699 | -H-- | C] () -- C:\WINDOWS\System32\KBDC.INI
[2007.01.27 21:57:08 | 000,002,606 | -H-- | C] () -- C:\WINDOWS\System32\KBDB.INI
[2007.01.27 21:57:08 | 000,002,236 | -H-- | C] () -- C:\WINDOWS\System32\KBDQ.INI
[2007.01.27 21:57:08 | 000,001,956 | -H-- | C] () -- C:\WINDOWS\System32\KBDE.INI
[2007.01.27 21:57:08 | 000,001,885 | -H-- | C] () -- C:\WINDOWS\System32\KBDP.INI
[2007.01.27 21:57:08 | 000,001,835 | -H-- | C] () -- C:\WINDOWS\System32\KBDG.INI
[2007.01.27 21:57:08 | 000,001,835 | -H-- | C] () -- C:\WINDOWS\System32\KBDA.INI
[2007.01.27 21:57:08 | 000,001,834 | -H-- | C] () -- C:\WINDOWS\System32\KBDU.INI
[2007.01.27 21:57:08 | 000,001,819 | -H-- | C] () -- C:\WINDOWS\System32\KBDN.INI
[2007.01.27 21:57:08 | 000,001,699 | -H-- | C] () -- C:\WINDOWS\System32\KBDT.INI
[2007.01.27 21:57:08 | 000,001,697 | -H-- | C] () -- C:\WINDOWS\System32\KBDV.INI
[2007.01.27 21:57:08 | 000,001,522 | -H-- | C] () -- C:\WINDOWS\System32\KBDS.INI
[2007.01.27 21:57:08 | 000,001,476 | -H-- | C] () -- C:\WINDOWS\System32\KBDF.INI
[2007.01.27 21:45:43 | 000,016,480 | -H-- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2007.01.27 21:34:36 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2007.01.27 21:28:03 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006.01.25 15:00:50 | 000,081,920 | -H-- | C] () -- C:\WINDOWS\System32\AVSAudioAmp.dll
[2006.01.25 15:00:50 | 000,061,440 | -H-- | C] () -- C:\WINDOWS\System32\AVSAudioWideStereoDMO.dll
[2005.12.08 02:53:00 | 001,662,976 | -H-- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2005.12.08 02:53:00 | 001,519,616 | -H-- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2005.12.08 02:53:00 | 001,466,368 | -H-- | C] () -- C:\WINDOWS\System32\nview.dll
[2005.12.08 02:53:00 | 001,339,392 | -H-- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2005.12.08 02:53:00 | 001,019,904 | -H-- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2005.12.08 02:53:00 | 000,466,944 | -H-- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2005.12.08 02:53:00 | 000,442,368 | -H-- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2005.12.08 02:53:00 | 000,110,592 | -H-- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2005.12.02 14:14:56 | 000,090,112 | -H-- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2005.11.28 12:06:22 | 000,038,144 | -H-- | C] () -- C:\WINDOWS\System32\drivers\WOWXT_kern_i386.sys
[2005.11.28 12:06:22 | 000,019,456 | -H-- | C] () -- C:\WINDOWS\System32\drivers\WOWFilter.sys
[2005.11.28 12:06:20 | 000,031,232 | -H-- | C] () -- C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2004.08.02 14:20:40 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat
[2003.07.07 17:00:00 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin
[2003.07.07 17:00:00 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat
[2003.07.07 17:00:00 | 000,432,690 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2003.07.07 17:00:00 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2003.07.07 17:00:00 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat
[2003.07.07 17:00:00 | 000,067,646 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2003.07.07 17:00:00 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin
[2003.07.07 17:00:00 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2003.07.07 17:00:00 | 000,004,463 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat
[2003.07.07 17:00:00 | 000,001,788 | -H-- | C] () -- C:\WINDOWS\System32\dcache.bin
[2003.07.07 17:00:00 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat
[2002.09.17 23:45:00 | 000,119,808 | -H-- | C] () -- C:\WINDOWS\lsb_un20.exe
[2001.11.14 12:56:00 | 001,802,240 | -H-- | C] () -- C:\WINDOWS\System32\lcppn21.dll
 
========== LOP Check ==========
 
[2010.11.21 23:19:30 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009.12.17 14:48:31 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\e-Safekey
[2009.11.25 19:42:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2010.10.03 20:20:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\RapidTyping
[2009.11.25 18:05:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Sophos
[2007.02.18 15:00:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\ACD Systems
[2009.10.21 22:39:16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\Amazon
[2010.08.16 13:56:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\CheckPoint
[2007.08.29 14:42:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\FUJIFILM
[2008.07.17 20:43:15 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\GraphPad Software
[2007.01.28 16:27:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\ISI ResearchSoft
[2010.10.03 20:20:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\RapidTyping
[2009.11.25 18:05:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\stickies
 
========== Purity Check ==========
 
 

< End of report >

--- --- ---
OTL Logfile:
Code:

OTL Extras logfile created on: 24.03.2011 22:00:10 - Run 2
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Documents and Settings\***\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy
 
1.022,00 Mb Total Physical Memory | 561,00 Mb Available Physical Memory | 55,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 83,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 82,62 Gb Total Space | 33,61 Gb Free Space | 40,68% Space Free | Partition Type: NTFS
 
Computer Name: *** | User Name: ***| Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] -- "C:\PROGRA~2\ACDSYS~1\ACDSee\ACDSee.exe" "%1"
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [FinePix] -- "C:\Programme\FinePixViewer\FinePixViewer.exe" "%1" (FUJIFILM Corporation.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe" = C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe:*:Enabled:IreIke -- (SafeNet)
"C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe" = C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog -- (SafeNet)
"C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe" = C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp -- (SafeNet)
"C:\Program Files\Juniper\NetScreen-Remote\vpn.exe" = C:\Program Files\Juniper\NetScreen-Remote\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager -- (SafeNet)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe" = C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe:*:Enabled:IreIke -- (SafeNet)
"C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe" = C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog -- (SafeNet)
"C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe" = C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp -- (SafeNet)
"C:\Program Files\Juniper\NetScreen-Remote\vpn.exe" = C:\Program Files\Juniper\NetScreen-Remote\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager -- (SafeNet)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{17283B95-21A8-4996-97DA-547A48DB266F}" = DisplayManager
"{17CA6206-7109-4426-8EE0-1BD0BE54BCC9}" = Management Center
"{19C64880-BBCA-11D4-9EEE-0004ACDDDB3B}" = CyberLink InstantBurn
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = PowerStarter
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.5.3
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 13
"{2F931B84-0CEE-11D1-AA7D-0080AD1AC47A}" = NetScreen-Remote
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 4.0
"{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver
"{55B1E4FA-F2E0-45DF-9B36-0B30A7949984}" = NWZ-S540 WALKMAN Guide
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Samsung Battery Manager
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38}" = Microsoft .NET Framework 2.0 Language Pack - DEU
"{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders  (German) 12
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007
"{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A48A8684-A104-44DA-B3DF-0178A125D8D9}" = WOW XT and TSXT Filter Driver
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A999CE76-D054-4684-80C7-53FC9243E019}" = EasyBox
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{B093990A-AAF2-44AC-9216-14BB7A2189B6}" = ImageMixer VCD2 LE for FinePix
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B44529FF-501E-47CD-A06D-223C161BE058}" = FinePixViewer Resource
"{B5924CA6-24A7-48F5-BC9C-8BFA94ED4564}" = LightScribe  1.4.67.1
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75
"{BC892294-7616-49A2-B165-0E60305CB6EA}" = Eudora
"{BD723E53-A42C-4702-AA04-1D74A0311590}" = Magic Keyboard
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0B0893D-6DA2-4F14-B1D0-3C0F1272B398}" = Reference Manager 11.0.1
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint 1.0
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer
"{D5A9B7C0-8751-11D8-9D75-000129760D75}" = MediaShow 3.0
"{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime
"{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}" = FinePix Studio
"{E5E54037-31CD-4EBD-9211-4C384F4E7E79}" = e-Safekey
"{E96FF910-1BC9-4EE5-BC12-0A30D4E20F37}" = NWZ-E440 WALKMAN Guide
"{EF99C14B-17C2-4994-B5C1-EB204A343A6F}" = User's Guide
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AFPL Ghostscript 8.54" = AFPL Ghostscript 8.54
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"Agere Systems Soft Modem" = SENS LT56ADW Modem
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.5
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CANONBJ_Deinstall_CNMCP58.DLL" = Canon i560
"CDex" = CDex extraction audio
"ENTERPRISE" = Microsoft Office Enterprise 2007
"InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"InstallShield_{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75
"InstallShield_{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0
"ISI ResearchSoft - Export Helper" = ISI ResearchSoft - Export Helper
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0 Language Pack - DEU" = Microsoft .NET Framework 2.0 Language Pack - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NVIDIA Drivers" = NVIDIA Drivers
"PartyPoker" = PartyPoker
"PartyPokerNet" = PartyPokerNet
"PDF Blender" = PDF Blender
"ProInst" = Intel(R) PROSet/Wireless Software
"RapidTyping" = RapidTyping
"RealPlayer 6.0" = RealPlayer
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinLems_is1" = WinLems 1.24
"WinRAR archiver" = WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 23.03.2011 10:21:12 | Computer Name = MF2249 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
 network. (The specified domain either does not exist or could not be contacted.
 ). Group Policy processing aborted.
 
Error - 23.03.2011 10:22:12 | Computer Name = MF2249 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
 the active directory (0x8007054b).  The specified domain either does not exist
or could not be contacted.    Enrollment will not be performed.
 
Error - 23.03.2011 11:12:14 | Computer Name = MF2249 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
 network. (The specified domain either does not exist or could not be contacted.
 ). Group Policy processing aborted.
 
Error - 23.03.2011 11:13:14 | Computer Name = ***| Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
 the active directory (0x8007054b).  The specified domain either does not exist
or could not be contacted.    Enrollment will not be performed.
 
Error - 23.03.2011 12:49:31 | Computer Name = ***| Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
 network. (The specified domain either does not exist or could not be contacted.
 ). Group Policy processing aborted.
 
Error - 23.03.2011 12:50:31 | Computer Name = ***| Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
 the active directory (0x8007054b).  The specified domain either does not exist
or could not be contacted.    Enrollment will not be performed.
 
Error - 24.03.2011 16:44:49 | Computer Name = ***| Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
 network. (The specified domain either does not exist or could not be contacted.
 ). Group Policy processing aborted.
 
Error - 24.03.2011 16:45:49 | Computer Name = ***| Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
 the active directory (0x8007054b).  The specified domain either does not exist
or could not be contacted.    Enrollment will not be performed.
 
Error - 24.03.2011 16:52:04 | Computer Name = ***| Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
 network. (The specified domain either does not exist or could not be contacted.
 ). Group Policy processing aborted.
 
Error - 24.03.2011 16:53:04 | Computer Name = ***| Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
 the active directory (0x8007054b).  The specified domain either does not exist
or could not be contacted.    Enrollment will not be performed.
 
[ OSession Events ]
Error - 10.06.2007 13:27:03 | Computer Name = ***| Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 20380 seconds with 8580 seconds of active time.  This session ended with
a crash.
 
[ System Events ]
Error - 23.03.2011 12:49:34 | Computer Name = ***| Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CSAM due to the following:
  %%1311.    Make sure that the computer is connected to the network and try  again. If
 the problem persists, please contact your domain administrator.
 
Error - 23.03.2011 12:50:36 | Computer Name = ***| Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
 the following error:  %%3
 
Error - 24.03.2011 16:44:49 | Computer Name = ***| Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CSAM due to the following:
  %%1311.    Make sure that the computer is connected to the network and try  again. If
 the problem persists, please contact your domain administrator.
 
Error - 24.03.2011 16:44:50 | Computer Name = ***| Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
 or more  time sources, however none of the sources are currently accessible.  No attempt
 to contact a source will be made for 14 minutes.  NtpClient has no source of accurate
 time.
 
Error - 24.03.2011 16:44:50 | Computer Name = ***| Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
 or more  time sources, however none of the sources are currently accessible.  No attempt
 to contact a source will be made for 15 minutes.  NtpClient has no source of accurate
 time.
 
Error - 24.03.2011 16:45:50 | Computer Name = ***| Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
 the following error:  %%3
 
Error - 24.03.2011 16:52:03 | Computer Name = ***| Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CSAM due to the following:
  %%1311.    Make sure that the computer is connected to the network and try  again. If
 the problem persists, please contact your domain administrator.
 
Error - 24.03.2011 16:52:04 | Computer Name = ***| Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
 or more  time sources, however none of the sources are currently accessible.  No attempt
 to contact a source will be made for 14 minutes.  NtpClient has no source of accurate
 time.
 
Error - 24.03.2011 16:52:04 | Computer Name = ***| Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
 or more  time sources, however none of the sources are currently accessible.  No attempt
 to contact a source will be made for 15 minutes.  NtpClient has no source of accurate
 time.
 
Error - 24.03.2011 16:53:08 | Computer Name = ***| Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
 the following error:  %%3
 
 
< End of report >

--- --- ---

cosinus 24.03.2011 22:47

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
[2011.03.24 21:51:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Internet Logs
[2011.03.24 21:51:59 | 000,000,077 | -HS- | M] () -- C:\cj.ini
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

shaiko 24.03.2011 23:39

Sollen die Einstellungen in OTL so wie vorher sein, d.h.
LOP Prüfung und Purity Prüfung aktiviert sowie bei Extra-Registrierung "Benutze SafeList" ?

Danke
und Gruß
shaiko

cosinus 25.03.2011 09:14

Ja lass es so.

shaiko 25.03.2011 15:47

Hi,
ich habe es so gemacht wie beschrieben:

All processes killed
========== OTL ==========
C:\WINDOWS\Internet Logs folder moved successfully.
C:\cj.ini moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: ***
->Temp folder emptied: 1082521008 bytes
->Temporary Internet Files folder emptied: 171016015 bytes
->Java cache emptied: 47030067 bytes
->FireFox cache emptied: 47632263 bytes
->Flash cache emptied: 1250 bytes

User: LocalService
->Temp folder emptied: 2046690 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 1978776 bytes
->Temporary Internet Files folder emptied: 2216765 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1119318 bytes
%systemroot%\System32 .tmp files removed: 2832913 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 114589941 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23442704 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1.427,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 03252011_153849

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

cosinus 25.03.2011 16:04

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

shaiko 25.03.2011 17:02

Soll während das Programm arbeitet, auch die Internetverbindung gekappt werden ?

Vielen Dank
shaiko

cosinus 25.03.2011 18:16

Nein, die bitte aktiv lassen, damit CF sich ggf. selbst aktualisieren kann.

shaiko 25.03.2011 22:16

Hi Arne,
hier das Logfile:
Combofix Logfile:
Code:

ComboFix 11-03-24.06 - ***25.03.2011  21:53:07.1.2 - x86
Microsoft Windows XP Professional  5.1.2600.2.1252.49.1033.18.1022.682 [GMT 1:00]
ausgeführt von:: c:\documents and settings\***\Desktop\cofi.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\ntuser.pol
c:\documents and settings\***\Application Data\ACD Systems\ACDSee\ImageDB.ddf
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-02-25 bis 2011-03-25  ))))))))))))))))))))))))))))))
.
.
2011-03-25 20:41 . 2011-03-25 20:41        --------        d-----w-        c:\program files\CCleaner
2011-03-25 14:38 . 2011-03-25 14:38        --------        d-----w-        C:\_OTL
2011-03-23 12:46 . 2011-03-23 12:46        --------        d-----w-        c:\documents and settings\***\Application Data\Malwarebytes
2011-03-23 12:46 . 2010-12-20 17:09        38224        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-23 12:46 . 2011-03-23 12:46        --------        d-----w-        c:\documents and settings\All Users\Application Data\Malwarebytes
2011-03-23 12:45 . 2010-12-20 17:08        20952        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-03-23 12:45 . 2011-03-23 14:33        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2011-03-22 21:34 . 2011-03-22 21:34        --------        d--h--w-        c:\documents and settings\***\Application Data\Avira
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-22 21:35 . 2009-11-26 11:02        137656        ---ha-w-        c:\windows\system32\drivers\avipbb.sys
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2005-12-08 7340032]
"nwiz"="nwiz.exe" [2005-12-08 1519616]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-19 925696]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 102492]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 692316]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 88204]
"MagicKeyboard"="c:\program files\SAMSUNG\MagicKBD\PreMKBD.exe" [2005-04-11 151552]
"DisplayManager"="c:\program files\Samsung\DisplayManager\DMLoader.exe" [2005-11-16 356352]
"AVStation Premium 3.75"="c:\program files\Samsung\AVStation Premium 3.75\AVSAgent.exe" [2006-04-27 155648]
"BatteryManager"="c:\program files\Samsung\Samsung Battery Manager\BatteryManager.exe" [2006-04-25 2764800]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"B'sCLiP"="c:\progra~2\CYBERL~1\INSTAN~1\Win2K\IBurn.exe" [2005-11-30 700416]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-06 148888]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"ContentTransferWMDetector.exe"="c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe" [2009-07-30 497000]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-23 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360]
.
c:\documents and settings\***\Start Menu\Programs\Startup\
OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-12-2 618557]
Exif Launcher 2.lnk - c:\programme\FinePixViewer\QuickDCF2.exe [2007-8-29 294912]
NetScreen-Remote.lnk - c:\program files\Juniper\NetScreen-Remote\SafeCfg.exe [2007-1-31 65588]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\Qualcomm\Eudora\EuShlExt.dll" [2005-06-08 86016]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Juniper\\NetScreen-Remote\\IreIKE.exe"=
"c:\program files\Juniper\NetScreen-Remote\ViewLog.exe"= c:\program files\Juniper\NetScreen-Remote\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog
"c:\program files\Juniper\NetScreen-Remote\CmonApp.exe"= c:\program files\Juniper\NetScreen-Remote\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp
"c:\program files\Juniper\NetScreen-Remote\vpn.exe"= c:\program files\Juniper\NetScreen-Remote\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager
.
R0 BsStor;B.H.A Storage Helper Driver;c:\windows\system32\drivers\BsStor.sys [27.01.2007 22:14 10368]
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [26.11.2009 12:02 135336]
R2 BsUDF;B.H.A UDF Filesystem;c:\windows\system32\drivers\BsUDF.sys [27.01.2007 22:14 164480]
R2 Crypto;Crypto;c:\windows\system32\drivers\Crypto.sys [31.01.2007 11:02 521786]
R2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [27.01.2007 21:57 4300]
R2 IPSECDRV;SafeNet IPSec Plugin;c:\windows\system32\drivers\IpSecDrv.sys [31.01.2007 11:02 119864]
R2 SRS_PostInstaller;SRS PostInstaller Service;c:\program files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe [28.11.2005 12:06 31744]
R3 DniVap;SafeNet WAN Miniport (VA);c:\windows\system32\drivers\vap.sys [31.01.2007 11:01 36188]
R3 wowfilter;WOW XT Filter Driver;c:\windows\system32\drivers\WOWFilter.sys [28.11.2005 12:06 19456]
S2 gupdate;Google Update Service (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S2 SNM WLAN Service;SNM WLAN Service;c:\program files\SAMSUNG\Samsung Network Manager\SNMWLANService.exe [28.05.2005 08:35 36864]
S3 SUEPD;SUE NDIS Protocol Driver;c:\windows\system32\drivers\SUE_PD.sys [20.06.2008 23:07 19840]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper        REG_MULTI_SZ          getPlusHelper
.
Inhalt des "geplante Tasks" Ordners
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Senden an &Bluetooth-Gerät... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {695B57C1-1A75-454E-B7F7-AA7A0E90A072} = 192.168.2.1
TCP: {A933426E-4E69-43A5-B75C-A4EEE9D6F76A} = 192.168.2.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Advertising Cookie Opt-out: optout@google.com - %profile%\extensions\optout@google.com
FF - Ext: IE Tab Plus: ietab@ip.cn - %profile%\extensions\ietab@ip.cn
FF - Ext: Adobe DLM (powered by getPlus(R)): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
ShellIconOverlayIdentifiers-{8ABABC80-67A4-4494-BF3F-A0D2AB31D39F} - (no file)
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9b.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2011-03-25 21:57
Windows 5.1.2600 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\
.
Zeit der Fertigstellung: 2011-03-25  21:59:27
ComboFix-quarantined-files.txt  2011-03-25 20:59
.
Vor Suchlauf: 37.604.007.936 bytes free
Nach Suchlauf: 37.592.354.816 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 77DB21B80FF0DC03377D0A623FB464AE

--- --- ---

cosinus 26.03.2011 18:15

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

shaiko 26.03.2011 20:58

Hi Arne,
hier das Logfile und nochmal vielen, vielen Dank für Deine Mühen bisher.
Gruß
shaiko

2011/03/26 20:55:46.0484 0368 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/03/26 20:55:46.0843 0368 ================================================================================
2011/03/26 20:55:46.0843 0368 SystemInfo:
2011/03/26 20:55:46.0843 0368
2011/03/26 20:55:46.0843 0368 OS Version: 5.1.2600 ServicePack: 2.0
2011/03/26 20:55:46.0843 0368 Product type: Workstation
2011/03/26 20:55:46.0843 0368 ComputerName: ***
2011/03/26 20:55:46.0843 0368 UserName: ***
2011/03/26 20:55:46.0843 0368 Windows directory: C:\WINDOWS
2011/03/26 20:55:46.0843 0368 System windows directory: C:\WINDOWS
2011/03/26 20:55:46.0843 0368 Processor architecture: Intel x86
2011/03/26 20:55:46.0843 0368 Number of processors: 2
2011/03/26 20:55:46.0843 0368 Page size: 0x1000
2011/03/26 20:55:46.0843 0368 Boot type: Normal boot
2011/03/26 20:55:46.0843 0368 ================================================================================
2011/03/26 20:55:47.0078 0368 Initialize success
2011/03/26 20:56:12.0078 2504 ================================================================================
2011/03/26 20:56:12.0078 2504 Scan started
2011/03/26 20:56:12.0078 2504 Mode: Manual;
2011/03/26 20:56:12.0078 2504 ================================================================================
2011/03/26 20:56:12.0390 2504 61883 (86d7b1e70661d754685b9ac6d749aae5) C:\WINDOWS\system32\DRIVERS\61883.sys
2011/03/26 20:56:12.0500 2504 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/03/26 20:56:12.0531 2504 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2011/03/26 20:56:12.0578 2504 ADIHdAudAddService (ff1c174f7d55da14e04d561a5a181a02) C:\WINDOWS\system32\drivers\ADIHdAud.sys
2011/03/26 20:56:12.0656 2504 AEAudioService (c984de22ed71414abc42c1e03d412e33) C:\WINDOWS\system32\drivers\AEAudio.sys
2011/03/26 20:56:12.0734 2504 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
2011/03/26 20:56:12.0781 2504 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
2011/03/26 20:56:12.0890 2504 AgereSoftModem (c41a5740468d0b9cb46e6390a0e15ce3) C:\WINDOWS\system32\DRIVERS\AGRSM.sys
2011/03/26 20:56:13.0234 2504 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/03/26 20:56:13.0343 2504 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/03/26 20:56:13.0375 2504 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/03/26 20:56:13.0421 2504 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/03/26 20:56:13.0468 2504 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/03/26 20:56:13.0578 2504 Avc (87c223adb8f7596b31caae3c67b16ddd) C:\WINDOWS\system32\DRIVERS\avc.sys
2011/03/26 20:56:13.0703 2504 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys
2011/03/26 20:56:13.0765 2504 avgntflt (47b879406246ffdced59e18d331a0e7d) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
2011/03/26 20:56:13.0828 2504 avipbb (5fedef54757b34fb611b9ec8fb399364) C:\WINDOWS\system32\DRIVERS\avipbb.sys
2011/03/26 20:56:13.0875 2504 bcm4sbxp (78e7b52da292fa90bad2f887bbf22159) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
2011/03/26 20:56:13.0906 2504 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/03/26 20:56:13.0953 2504 BsStor (c7552016bb1349be87324637c4d8a89f) C:\WINDOWS\system32\drivers\BsStor.sys
2011/03/26 20:56:14.0031 2504 BsUDF (a2afd1a4b56b6ae4351587c77e10658d) C:\WINDOWS\system32\drivers\BsUDF.sys
2011/03/26 20:56:14.0125 2504 BTKRNL (54e368a1768c627f2adb8ab5624d0bc4) C:\WINDOWS\system32\DRIVERS\btkrnl.sys
2011/03/26 20:56:14.0234 2504 BTSERIAL (8aeca4330654da58423e7fe03a704513) C:\WINDOWS\System32\drivers\btserial.sys
2011/03/26 20:56:14.0265 2504 BTWUSB (fca94255e0a0e65c7c93530bdf10adca) C:\WINDOWS\system32\Drivers\btwusb.sys
2011/03/26 20:56:14.0359 2504 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/03/26 20:56:14.0406 2504 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/03/26 20:56:14.0484 2504 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/03/26 20:56:14.0546 2504 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/03/26 20:56:14.0593 2504 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/03/26 20:56:14.0640 2504 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/03/26 20:56:14.0718 2504 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/03/26 20:56:14.0828 2504 Crypto (c56a413535292d9e43c563bbf946cbc1) C:\WINDOWS\system32\drivers\Crypto.sys
2011/03/26 20:56:14.0953 2504 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/03/26 20:56:15.0015 2504 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys
2011/03/26 20:56:15.0156 2504 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys
2011/03/26 20:56:15.0203 2504 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/03/26 20:56:15.0250 2504 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
2011/03/26 20:56:15.0328 2504 DNE (c86fbf607445bf693450d84b775f168c) C:\WINDOWS\system32\DRIVERS\dne2000.sys
2011/03/26 20:56:15.0375 2504 DniVap (88ea1b2acdd0536661d67fdd2f030dd2) C:\WINDOWS\system32\DRIVERS\vap.sys
2011/03/26 20:56:15.0437 2504 DOSMEMIO (8a4cb9438571814b128b6dc30d698064) C:\WINDOWS\System32\MEMIO.SYS
2011/03/26 20:56:15.0515 2504 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/03/26 20:56:15.0562 2504 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/03/26 20:56:15.0593 2504 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys
2011/03/26 20:56:15.0656 2504 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys
2011/03/26 20:56:15.0718 2504 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/03/26 20:56:15.0781 2504 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/03/26 20:56:15.0828 2504 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/03/26 20:56:15.0875 2504 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/03/26 20:56:15.0906 2504 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/03/26 20:56:15.0968 2504 HdAudAddService (2a013e7530beab6e569faa83f517e836) C:\WINDOWS\system32\drivers\HdAudio.sys
2011/03/26 20:56:16.0015 2504 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/03/26 20:56:16.0078 2504 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/03/26 20:56:16.0218 2504 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/03/26 20:56:16.0328 2504 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/03/26 20:56:16.0375 2504 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/03/26 20:56:16.0484 2504 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/03/26 20:56:16.0500 2504 ip6fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/03/26 20:56:16.0531 2504 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/03/26 20:56:16.0562 2504 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/03/26 20:56:16.0609 2504 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/03/26 20:56:16.0640 2504 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/03/26 20:56:16.0703 2504 IPSECDRV (e101e53684f0f3da7558e0c2dbee2a6f) C:\WINDOWS\system32\Drivers\IPSECDRV.sys
2011/03/26 20:56:16.0781 2504 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/03/26 20:56:16.0843 2504 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/03/26 20:56:16.0906 2504 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/03/26 20:56:16.0968 2504 kbdhid (e182fa8e49e8ee41b4adc53093f3c7e6) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/03/26 20:56:17.0031 2504 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
2011/03/26 20:56:17.0062 2504 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/03/26 20:56:17.0171 2504 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/03/26 20:56:17.0203 2504 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys
2011/03/26 20:56:17.0312 2504 motmodem (c9f96f5c50bcdfa2a6ee996291ea062a) C:\WINDOWS\system32\DRIVERS\motmodem.sys
2011/03/26 20:56:17.0328 2504 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/03/26 20:56:17.0390 2504 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/03/26 20:56:17.0421 2504 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/03/26 20:56:17.0500 2504 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/03/26 20:56:17.0578 2504 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/03/26 20:56:17.0640 2504 MSDV (6dd721dfd2648f3f6d5808b5ba6cb095) C:\WINDOWS\system32\DRIVERS\msdv.sys
2011/03/26 20:56:17.0656 2504 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
2011/03/26 20:56:17.0718 2504 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/03/26 20:56:17.0765 2504 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/03/26 20:56:17.0828 2504 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/03/26 20:56:17.0890 2504 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/03/26 20:56:17.0921 2504 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/03/26 20:56:17.0953 2504 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
2011/03/26 20:56:18.0000 2504 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/03/26 20:56:18.0031 2504 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
2011/03/26 20:56:18.0078 2504 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/03/26 20:56:18.0125 2504 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/03/26 20:56:18.0187 2504 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/03/26 20:56:18.0203 2504 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/03/26 20:56:18.0234 2504 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/03/26 20:56:18.0265 2504 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/03/26 20:56:18.0343 2504 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/03/26 20:56:18.0390 2504 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/03/26 20:56:18.0421 2504 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
2011/03/26 20:56:18.0500 2504 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/03/26 20:56:18.0546 2504 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/03/26 20:56:18.0765 2504 nv (3070eb78e5b7f48d390d32c40437335e) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/03/26 20:56:18.0968 2504 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/03/26 20:56:19.0046 2504 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/03/26 20:56:19.0109 2504 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/03/26 20:56:19.0140 2504 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\drivers\Parport.sys
2011/03/26 20:56:19.0171 2504 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/03/26 20:56:19.0234 2504 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/03/26 20:56:19.0250 2504 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/03/26 20:56:19.0328 2504 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/03/26 20:56:19.0359 2504 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/03/26 20:56:19.0546 2504 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/03/26 20:56:19.0609 2504 Processor (0d97d88720a4087ec93af7dbb303b30a) C:\WINDOWS\system32\DRIVERS\processr.sys
2011/03/26 20:56:19.0640 2504 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/03/26 20:56:19.0687 2504 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/03/26 20:56:19.0812 2504 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/03/26 20:56:19.0859 2504 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/03/26 20:56:19.0906 2504 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/03/26 20:56:19.0921 2504 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/03/26 20:56:19.0984 2504 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/03/26 20:56:20.0000 2504 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/03/26 20:56:20.0031 2504 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/03/26 20:56:20.0125 2504 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/03/26 20:56:20.0203 2504 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/03/26 20:56:20.0281 2504 rimmptsk (7a6648b61661b1421ffab762e391e33f) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
2011/03/26 20:56:20.0312 2504 rimsptsk (8f7012d1b6a71ee9c23ce93dcdbf9f4b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
2011/03/26 20:56:20.0359 2504 rismxdp (3ac17802740c3a4764dc9750e92e6233) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
2011/03/26 20:56:20.0437 2504 sdbus (02fc71b020ec8700ee8a46c58bc6f276) C:\WINDOWS\system32\DRIVERS\sdbus.sys
2011/03/26 20:56:20.0484 2504 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/03/26 20:56:20.0546 2504 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\drivers\Serial.sys
2011/03/26 20:56:20.0578 2504 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/03/26 20:56:20.0703 2504 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/03/26 20:56:20.0781 2504 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
2011/03/26 20:56:20.0828 2504 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/03/26 20:56:20.0890 2504 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/03/26 20:56:20.0937 2504 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
2011/03/26 20:56:20.0984 2504 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/03/26 20:56:21.0046 2504 SUEPD (c0137b5947ae3d3fc1c17ba6fdfb3dad) C:\WINDOWS\system32\DRIVERS\SUE_PD.sys
2011/03/26 20:56:21.0093 2504 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/03/26 20:56:21.0156 2504 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
2011/03/26 20:56:21.0421 2504 SynTP (1dbc86da355b5db35174f862c110fd09) C:\WINDOWS\system32\DRIVERS\SynTP.sys
2011/03/26 20:56:21.0468 2504 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/03/26 20:56:21.0531 2504 Tcpip (90caff4b094573449a0872a0f919b178) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/03/26 20:56:21.0593 2504 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/03/26 20:56:21.0625 2504 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/03/26 20:56:21.0640 2504 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/03/26 20:56:21.0718 2504 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
2011/03/26 20:56:21.0875 2504 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
2011/03/26 20:56:21.0953 2504 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/03/26 20:56:22.0000 2504 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/03/26 20:56:22.0031 2504 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/03/26 20:56:22.0078 2504 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/03/26 20:56:22.0140 2504 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/03/26 20:56:22.0187 2504 usbser (49106ee29074e6a3d3ac9e24c6d791d8) C:\WINDOWS\system32\DRIVERS\usbser.sys
2011/03/26 20:56:22.0265 2504 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/03/26 20:56:22.0343 2504 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/03/26 20:56:22.0390 2504 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
2011/03/26 20:56:22.0453 2504 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/03/26 20:56:22.0593 2504 w39n51 (b1f126e7e28877106d60e6ff3998d033) C:\WINDOWS\system32\DRIVERS\w39n51.sys
2011/03/26 20:56:22.0703 2504 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/03/26 20:56:22.0781 2504 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
2011/03/26 20:56:22.0859 2504 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/03/26 20:56:22.0953 2504 WmiAcpi (ae2c8544e747c20062db27456ea2d67a) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
2011/03/26 20:56:23.0031 2504 wowfilter (bc69c990fa6be63d0af3719f92e0936d) C:\WINDOWS\system32\drivers\wowfilter.sys
2011/03/26 20:56:23.0093 2504 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2011/03/26 20:56:23.0125 2504 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/03/26 20:56:23.0203 2504 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/03/26 20:56:23.0234 2504 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/03/26 20:56:23.0468 2504 ================================================================================
2011/03/26 20:56:23.0468 2504 Scan finished
2011/03/26 20:56:23.0468 2504 ================================================================================

cosinus 26.03.2011 21:24

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.


Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

shaiko 26.03.2011 22:19

Kurze Idiotenfrage: GMER läuft gerade, jetzt ist allerdings der Bildschirmschoner angegangen. Kann ich kurz die Maus bewegen, um zu schauen, wie weit es ist oder soll ich länger warten oder soll ich dann erneut den Scan machen, mit ausgeschaltetem Bildschirmschoner ?

shaiko 27.03.2011 01:37

Hallo,
hier das GMERLogfile:GMER Logfile:
Code:

GMER 1.0.15.15570 - GMER - Rootkit Detector and Remover
Rootkit scan 2011-03-27 01:28:26
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 FUJITSU_MHV2100AH_PL rev.004200A0
Running: uf0oi7dv.exe; Driver: C:\DOCUME~1\***\LOCALS~1\Temp\kxtdypob.sys


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwClose [0xBA37DA1C]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwCreateDirectoryObject [0xBA37DA48]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwCreateFile [0xBA37DA7C]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwCreateKey [0xBA37DAD0]
SSDT            F7E99BFC                                                                ZwCreateThread
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwDeleteKey [0xBA37DB14]
SSDT            F7E99C15                                                                ZwDeleteValueKey
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwEnumerateKey [0xBA37DB40]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwEnumerateValueKey [0xBA37DB80]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwFlushKey [0xBA37DBC0]
SSDT            F7E99C1A                                                                ZwLoadKey
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwMakeTemporaryObject [0xBA37DBEC]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwMapViewOfSection [0xBA37DC18]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwOpenKey [0xBA37DC68]
SSDT            F7E99BE8                                                                ZwOpenProcess
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwOpenSection [0xBA37DC9C]
SSDT            F7E99BED                                                                ZwOpenThread
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwQueryInformationFile [0xBA37DCD0]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwQueryKey [0xBA37DD0C]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwQueryValueKey [0xBA37DD48]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwReadFile [0xBA37DD88]
SSDT            F7E99C24                                                                ZwReplaceKey
SSDT            F7E99C1F                                                                ZwRestoreKey
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwSetInformationFile [0xBA37DDD4]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwSetInformationThread [0xBA37DE10]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwSetValueKey [0xBA37DE48]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwUnmapViewOfSection [0xBA37DE88]
SSDT            \SystemRoot\System32\Drivers\Crypto.SYS (SafeNet Crypto Driver/SafeNet)  ZwWriteFile [0xBA37DEB8]

---- Kernel code sections - GMER 1.0.15 ----

.text          ntoskrnl.exe!ZwYieldExecution + 25E                                      804E4AB8 4 Bytes  CALL 33463458
.text          C:\WINDOWS\System32\DRIVERS\nv4_mini.sys                                section is writeable [0xF6B64360, 0x2154AD, 0xE8000020]

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Udfs \UdfsCdRom                                              BsUDF.SYS (UDF File System Driver (Windows2000)/CyberLink Corporation.)
Device          \FileSystem\Udfs \UdfsDisk                                              BsUDF.SYS (UDF File System Driver (Windows2000)/CyberLink Corporation.)

AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass0                                  SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass1                                  SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device          \FileSystem\Cdfs \Cdfs                                                  BsUDF.SYS (UDF File System Driver (Windows2000)/CyberLink Corporation.)

---- EOF - GMER 1.0.15 ----

--- --- ---

shaiko 27.03.2011 01:50

Hier das OSAMLogfile:OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
Online Solutions. Complex Protection for Information Systems
Saved at 01:49:42 on 27.03.2011

OS: Windows XP Professional Service Pack 2 (Build 2600)
Default Browser: Mozilla Corporation Firefox 3.6.13

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"btcpl.cpl" - "Broadcom Corporation." - C:\WINDOWS\system32\btcpl.cpl
"infocardcpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\infocardcpl.cpl
"javacpl.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\javacpl.cpl
"MagicKBD.cpl" - "SAMSUNG Electronics Co., Ltd." - C:\WINDOWS\system32\MagicKBD.cpl
"nvtuicpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvtuicpl.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Avira AntiVir Personal - Free Antivirus " - "Avira GmbH" - C:\PROGRA~2\Avira\ANTIVI~1\avconfig.cpl
"SMAX4CP" - "Analog Devices, Inc." - C:\Program Files\Analog Devices\SoundMAX\SMax4.cpl
"SRSCpl" - "SRS Labs, Inc." - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\srscpl.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgio" (avgio) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avipbb.sys
"B.H.A Storage Helper Driver" (BsStor) - "Cyberlink Co.,Ltd." - C:\WINDOWS\system32\drivers\BsStor.sys
"B.H.A UDF Filesystem" (BsUDF) - "CyberLink Corporation." - C:\WINDOWS\system32\drivers\BsUDF.sys
"Bluetooth Serial Driver" (BTSERIAL) - "Broadcom Corporation." - C:\WINDOWS\System32\drivers\btserial.sys
"Bluetooth-Bus-Enumerator" (BTKRNL) - "Broadcom Corporation." - C:\WINDOWS\System32\DRIVERS\btkrnl.sys
"catchme" (catchme) - ? - C:\DOCUME~1\***\LOCALS~1\Temp\catchme.sys  (File not found)
"Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys  (File not found)
"Crypto" (Crypto) - "SafeNet" - C:\WINDOWS\system32\drivers\Crypto.sys
"i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys  (File not found)
"lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys  (File not found)
"MEMIO" (DOSMEMIO) - ? - C:\WINDOWS\System32\MEMIO.SYS  (File found, but it contains no detailed information)
"Motorola USB CDC ACM Driver" (motmodem) - "Motorola" - C:\WINDOWS\System32\DRIVERS\motmodem.sys
"PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys  (File not found)
"PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys  (File not found)
"PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys  (File not found)
"PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys  (File not found)
"PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys  (File not found)
"SafeNet IPSec Plugin" (IPSECDRV) - "SafeNet" - C:\WINDOWS\system32\Drivers\IPSECDRV.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\ssmdrv.sys
"SUE NDIS Protocol Driver" (SUEPD) - "Samsung" - C:\WINDOWS\System32\DRIVERS\SUE_PD.sys
"WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys  (File not found)
"WIDCOMM USB Bluetooth Driver" (BTWUSB) - "Broadcom Corporation." - C:\WINDOWS\System32\Drivers\btwusb.sys
"WOW XT Filter Driver" (wowfilter) - ? - C:\WINDOWS\System32\drivers\wowfilter.sys

[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} "Eudora's Shell Extension" - "Qualcomm Inc." - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{6af09ec9-b429-11d4-a1fb-0090960218cb} "Bluetooth-Umgebung" - "Broadcom Corporation." - C:\WINDOWS\System32\btneighborhood.dll
{1CDB2949-8F65-4355-8456-263E7C208A5D} "Desktop Explorer" - "NVIDIA Corporation" - C:\WINDOWS\System32\nvshell.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A47} "Desktop Explorer Menu" - "NVIDIA Corporation" - C:\WINDOWS\System32\nvshell.dll
{42071714-76d4-11d1-8b24-00a0c9068ff3} "Display Panning CPL Extension" - ? - deskpan.dll  (File not found)
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Encryption Context Menu" - ? -  (File not found | COM-object registry key not found)
{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} "Eudora's Shell Extension" - "Qualcomm Inc." - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll
{32683183-48a0-441b-a342-7c2a440a9478} "Media Band" - ? -  (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office12\ONFILTER.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} "nView Desktop Context Menu" - "NVIDIA Corporation" - C:\WINDOWS\System32\nvshell.dll
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - C:\Program Files\Real\RealPlayer\rpshell.dll
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shell extensions for file compression" - ? -  (File not found | COM-object registry key not found)
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - c:\WINDOWS\system32\dfshim.dll
{e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - c:\WINDOWS\system32\dfshim.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Web Folders" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSONSEXT.DLL
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Program Files\WinRAR\rarext.dll  (File found, but it contains no detailed information)

[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{32683183-48a0-441b-a342-7c2a440a9478} "{32683183-48a0-441b-a342-7c2a440a9478}" - ? -  (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "ITBarLayout" - ? -  (File not found | COM-object registry key not found)
<binary data> "{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
DirectAnimation Java Classes "DirectAnimation Java Classes" - ? -  (File not found | COM-object registry key not found) / file://C:\WINDOWS\Java\classes\dajava.cab
{D8575CE3-3432-4540-88A9-85A1325D3375} "e-Safekey" - "Danske Bank Group" - C:\Program Files\Common Files\e-Safekey\e-Safekey.dll / https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
{45B69029-F3AB-4204-92DE-D5140C3E8E74} "F5 Networks Auto Update" - "F5 Networks" - C:\WINDOWS\Downloaded Program Files\InstallerControl.dll / https://access.uke.de/vdesk/terminal/InstallerControl.cab
{2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} "F5 Networks CacheCleaner" - "F5 Networks" - C:\WINDOWS\Downloaded Program Files\cachecleaner.dll / https://access.uke.de/vdesk/cachecleaner.cab#version=6031,2009,1010,0301
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} "Java Plug-in 1.5.0_11" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll / hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} "Java Plug-in 1.6.0_02" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_13" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_13.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} "Java Plug-in 1.6.0_13" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_13.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_13" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_13.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Microsoft XML Parser for Java "Microsoft XML Parser for Java" - ? -  (File not found | COM-object registry key not found) / file://C:\WINDOWS\Java\classes\xmldso.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx / https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
{17492023-C23A-453E-A040-C7C580BBF700} "Windows Genuine Advantage Validation Tool" - "Microsoft Corporation" - C:\WINDOWS\system32\LegitCheckControl.DLL / hxxp://go.microsoft.com/fwlink/?linkid=39204
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} "{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" - ? -  (File not found | COM-object registry key not found) / hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
{53707962-6F74-2D53-2644-206D7942484F} "ClsidExtension" - "Safer Networking Limited" - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
"PartyPoker.com" - ? - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
"PartyPoker.net" - ? - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{53707962-6F74-2D53-2644-206D7942484F} "Spybot-S&D IE Protection" - "Safer Networking Limited" - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} "{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}" - ? -  (File not found | COM-object registry key not found)

[Logon]
-----( %AllUsersProfile%\Start Menu\Programs\Startup )-----
"Adobe Reader Speed Launch.lnk" - "Adobe Systems Incorporated" - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
"Exif Launcher 2.lnk" - "FUJIFILM Corporation." - C:\Programme\FinePixViewer\QuickDCF2.exe  (Shortcut exists | File exists)
"NetScreen-Remote.lnk" - "SafeNet" - C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe  (Shortcut exists | File exists)
"BTTray.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File exists)
-----( %UserProfile%\Start Menu\Programs\Startup )-----
"OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\Documents and Settings\***\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Power2GoExpress" - ? - NA  (File not found)
"SpybotSD TeaTimer" - "Safer-Networking Ltd." - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"AVStation Premium 3.75" - ? - C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe
"B'sCLiP" - "CyberLink Corporation." - C:\PROGRA~2\CYBERL~1\INSTAN~1\Win2K\IBurn.exe
"BatteryManager" - ? - C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
"ContentTransferWMDetector.exe" - "Sony Corporation" - C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
"DisplayManager" - "SAMSUNG" - C:\Program Files\Samsung\DisplayManager\DMLoader.exe
"MagicKeyboard" - ? - C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
"NeroFilterCheck" - "Ahead Software Gmbh" - C:\WINDOWS\system32\NeroCheck.exe
"nwiz" - "NVIDIA Corporation" - nwiz.exe /install
"REGSHAVE" - "FUJI PHOTO FILM CO., LTD." - C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
"RemoteControl" - "Cyberlink Corp." - "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Java\jre6\bin\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Bluetooth-Druckeranschluss" - "Broadcom Corporation." - C:\WINDOWS\system32\bthcrp.dll
"PDFCreator" - ? - C:\WINDOWS\system32\pdfcmnnt.dll  (File found, but it contains no detailed information)
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\WINDOWS\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
"ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"B's Recorder GOLD Library General Service" (bgsvcgen) - "B.H.A Corporation" - C:\WINDOWS\system32\bgsvcgen.exe
"Bluetooth Service" (btwdins) - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
"getPlus(R) Helper" (getPlusHelper) - "NOS Microsystems Ltd." - C:\Program Files\NOS\bin\getPlus_Helper.dll
"Google Update Service (gupdate)" (gupdate) - ? - "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc  (File not found)
"Java Quick Starter" (JavaQuickStarterService) - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jqs.exe
"LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"SafeNet IKE Service" (IreIKE) - "SafeNet" - C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe
"SafeNet Monitor Service" (IPSECMON) - "SafeNet" - C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe
"Samsung Update Plus" (Samsung Update Plus) - ? - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe  (File found, but it contains no detailed information)
"SNM WLAN Service" (SNM WLAN Service) - ? - C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe  (File found, but it contains no detailed information)
"SRS PostInstaller Service" (SRS_PostInstaller) - "SRS Labs, Inc." - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe
"Windows CardSpace" (idsvc) - "Microsoft Corporation" - c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
"Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0) - "Microsoft Corporation" - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe

[Winlogon]
-----( HKCU\Control Panel\IOProcs )-----
"MVB" - ? - mvfs32.dll  (File not found)

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---
If You have questions or want to get some help, You can visit Online Solutions :: Index

shaiko 27.03.2011 01:53

Hier der MBRCheck.txt
MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 2 (build 2600)
Logical Drives Mask: 0x0000000c

Kernel Drivers (total 137):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806FD000 \WINDOWS\system32\hal.dll
0xF7D64000 \WINDOWS\system32\KDCOM.DLL
0xF7C74000 \WINDOWS\system32\BOOTVID.dll
0xF7815000 ACPI.sys
0xF7D66000 \WINDOWS\System32\DRIVERS\WMILIB.SYS
0xF7804000 pci.sys
0xF7864000 isapnp.sys
0xF7874000 ohci1394.sys
0xF7884000 \WINDOWS\System32\DRIVERS\1394BUS.SYS
0xF7C78000 compbatt.sys
0xF7C7C000 \WINDOWS\System32\DRIVERS\BATTC.SYS
0xF7E2C000 pciide.sys
0xF7AE4000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
0xF77E6000 pcmcia.sys
0xF7894000 MountMgr.sys
0xF77C7000 ftdisk.sys
0xF7C80000 ACPIEC.sys
0xF7E2D000 \WINDOWS\System32\DRIVERS\OPRGHDLR.SYS
0xF7AEC000 PartMgr.sys
0xF78A4000 VolSnap.sys
0xF77AF000 atapi.sys
0xF78B4000 disk.sys
0xF78C4000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
0xF778F000 fltmgr.sys
0xF777D000 sr.sys
0xF7C84000 BsStor.sys
0xF7766000 KSecDD.sys
0xF7753000 WudfPf.sys
0xF76C6000 Ntfs.sys
0xF7699000 NDIS.sys
0xF767E000 Mup.sys
0xF78F4000 \SystemRoot\System32\DRIVERS\nic1394.sys
0xF6FC1000 \SystemRoot\System32\DRIVERS\intelppm.sys
0xF7D50000 \SystemRoot\System32\DRIVERS\CmBatt.sys
0xF6C0F000 \SystemRoot\System32\DRIVERS\nv4_mini.sys
0xF6BFB000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
0xF6BD6000 \SystemRoot\System32\DRIVERS\HDAudBus.sys
0xF6A79000 \SystemRoot\System32\DRIVERS\w39n51.sys
0xF7BD4000 \SystemRoot\System32\DRIVERS\usbuhci.sys
0xF6A56000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
0xF7BDC000 \SystemRoot\System32\DRIVERS\usbehci.sys
0xF6FB1000 \SystemRoot\System32\DRIVERS\bcm4sbxp.sys
0xF6A45000 \SystemRoot\System32\DRIVERS\sdbus.sys
0xF7BE4000 \SystemRoot\System32\DRIVERS\rimmptsk.sys
0xF6FA1000 \SystemRoot\System32\DRIVERS\rimsptsk.sys
0xF69F9000 \SystemRoot\System32\DRIVERS\rixdptsk.sys
0xF6F91000 \SystemRoot\System32\DRIVERS\i8042prt.sys
0xF7BEC000 \SystemRoot\System32\DRIVERS\kbdclass.sys
0xF69CA000 \SystemRoot\System32\DRIVERS\SynTP.sys
0xF7D88000 \SystemRoot\System32\DRIVERS\USBD.SYS
0xF7BF4000 \SystemRoot\System32\DRIVERS\mouclass.sys
0xF6F81000 \SystemRoot\System32\DRIVERS\imapi.sys
0xF7964000 \SystemRoot\System32\DRIVERS\cdrom.sys
0xF7974000 \SystemRoot\System32\DRIVERS\redbook.sys
0xF69A7000 \SystemRoot\System32\DRIVERS\ks.sys
0xF68DA000 \SystemRoot\System32\DRIVERS\btkrnl.sys
0xF68BF000 \SystemRoot\system32\DRIVERS\dne2000.sys
0xF7BFC000 \SystemRoot\system32\DRIVERS\vap.sys
0xF7F61000 \SystemRoot\System32\DRIVERS\audstub.sys
0xF7984000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
0xF7646000 \SystemRoot\System32\DRIVERS\ndistapi.sys
0xF68A8000 \SystemRoot\System32\DRIVERS\ndiswan.sys
0xF7994000 \SystemRoot\System32\DRIVERS\raspppoe.sys
0xF79A4000 \SystemRoot\System32\DRIVERS\raspptp.sys
0xF7C04000 \SystemRoot\System32\DRIVERS\TDI.SYS
0xF6897000 \SystemRoot\System32\DRIVERS\psched.sys
0xF79B4000 \SystemRoot\System32\DRIVERS\msgpc.sys
0xF7C0C000 \SystemRoot\System32\DRIVERS\ptilink.sys
0xF7C14000 \SystemRoot\System32\DRIVERS\raspti.sys
0xF6866000 \SystemRoot\System32\DRIVERS\rdpdr.sys
0xF79C4000 \SystemRoot\System32\DRIVERS\termdd.sys
0xF7D8A000 \SystemRoot\System32\DRIVERS\swenum.sys
0xF67E5000 \SystemRoot\System32\DRIVERS\update.sys
0xF706C000 \SystemRoot\System32\DRIVERS\mssmbios.sys
0xF79D4000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF7058000 \SystemRoot\System32\DRIVERS\wmiacpi.sys
0xF4767000 \SystemRoot\system32\drivers\ADIHdAud.sys
0xF4743000 \SystemRoot\system32\drivers\portcls.sys
0xF79E4000 \SystemRoot\system32\drivers\drmk.sys
0xF7C1C000 \SystemRoot\system32\drivers\wowfilter.sys
0xF79F4000 \SystemRoot\system32\drivers\wowxt_kern_i386.sys
0xF7C24000 \SystemRoot\system32\drivers\tsxt_kern_i386.sys
0xF471D000 \SystemRoot\system32\drivers\AEAudio.sys
0xF460A000 \SystemRoot\System32\DRIVERS\AGRSM.sys
0xF7C2C000 \SystemRoot\System32\Drivers\Modem.SYS
0xF7A14000 \SystemRoot\System32\DRIVERS\usbhub.sys
0xF7D96000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7EAD000 \SystemRoot\System32\Drivers\Null.SYS
0xF7D98000 \SystemRoot\System32\Drivers\Beep.SYS
0xF7C4C000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF7C54000 \SystemRoot\System32\drivers\vga.sys
0xF7D9A000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7D9C000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF7C5C000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF7C64000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF7D44000 \SystemRoot\System32\DRIVERS\rasacd.sys
0xF45AF000 \SystemRoot\System32\DRIVERS\ipsec.sys
0xF4557000 \SystemRoot\System32\DRIVERS\tcpip.sys
0xF452F000 \SystemRoot\System32\DRIVERS\netbt.sys
0xF450E000 \SystemRoot\System32\DRIVERS\ipnat.sys
0xF44EC000 \SystemRoot\System32\drivers\afd.sys
0xF7A24000 \SystemRoot\System32\DRIVERS\netbios.sys
0xF7C6C000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0xF44C1000 \SystemRoot\System32\DRIVERS\rdbss.sys
0xF4452000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
0xF7A44000 \SystemRoot\System32\Drivers\Fips.SYS
0xF7A64000 \SystemRoot\System32\DRIVERS\wanarp.sys
0xF7A74000 \SystemRoot\System32\DRIVERS\arp1394.sys
0xF7A84000 \SystemRoot\System32\Drivers\btwusb.sys
0xF4364000 \SystemRoot\system32\DRIVERS\avipbb.sys
0xF7DA2000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
0xF78E4000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xF434C000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF7DB4000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xF45E6000 \SystemRoot\System32\drivers\Dxapi.sys
0xF7B1C000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7F44000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xBA4D3000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0xBA4AA000 \SystemRoot\System32\Drivers\BsUDF.SYS
0xBA471000 \SystemRoot\System32\Drivers\Udfs.SYS
0xF7F14000 \??\C:\WINDOWS\System32\MEMIO.SYS
0xBA4E8000 \SystemRoot\System32\DRIVERS\ndisuio.sys
0xBA38A000 \SystemRoot\System32\Drivers\Crypto.SYS
0xBA2A0000 \??\C:\WINDOWS\system32\Drivers\IPSECDRV.sys
0xBA134000 \SystemRoot\System32\DRIVERS\mrxdav.sys
0xBA0A7000 \SystemRoot\system32\drivers\wdmaud.sys
0xBA1E0000 \SystemRoot\system32\drivers\sysaudio.sys
0xF7C44000 \??\C:\WINDOWS\System32\drivers\btserial.sys
0xB916A000 \SystemRoot\System32\DRIVERS\srv.sys
0xB8E81000 \SystemRoot\System32\Drivers\HTTP.sys
0xB82A5000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 54):
0 System Idle Process
4 System
1252 C:\WINDOWS\system32\smss.exe
1360 csrss.exe
1388 C:\WINDOWS\system32\winlogon.exe
1436 C:\WINDOWS\system32\services.exe
1448 C:\WINDOWS\system32\lsass.exe
1640 C:\WINDOWS\system32\svchost.exe
1728 svchost.exe
1768 C:\WINDOWS\system32\svchost.exe
1808 C:\WINDOWS\system32\svchost.exe
1996 svchost.exe
2020 svchost.exe
2040 C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe
744 C:\WINDOWS\system32\spoolsv.exe
792 C:\Program Files\Avira\AntiVir Desktop\sched.exe
804 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
868 svchost.exe
888 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
1928 C:\WINDOWS\explorer.exe
304 C:\Program Files\Analog Devices\Core\smax4pnp.exe
312 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
328 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
336 C:\WINDOWS\AGRSMMSG.exe
600 C:\Program Files\SAMSUNG\DisplayManager\DisplayManager.exe
940 C:\Program Files\SAMSUNG\AVStation Premium 3.75\AVSAgent.exe
956 C:\Program Files\SAMSUNG\Samsung Battery Manager\BatteryManager.exe
976 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
980 C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe
1000 C:\Program Files\Java\jre6\bin\jusched.exe
1044 C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
1048 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
1060 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
1084 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
1104 C:\Programme\FinePixViewer\QuickDCF2.exe
1128 C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe
1172 C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
1260 C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
1304 C:\WINDOWS\system32\bgsvcgen.exe
1348 C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
1244 C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe
1176 C:\Program Files\Java\jre6\bin\jqs.exe
2060 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
2080 C:\WINDOWS\system32\nvsvc32.exe
2104 C:\Program Files\CyberLink\Shared Files\RichVideo.exe
2232 C:\Program Files\SAMSUNG\Samsung Network Manager\SNMWLANService.exe
2356 C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe
2388 C:\WINDOWS\system32\svchost.exe
3172 alg.exe
3736 C:\WINDOWS\system32\svchost.exe
3304 C:\Program Files\Mozilla Firefox\firefox.exe
3200 C:\WINDOWS\system32\wuauclt.exe
2828 C:\Program Files\SAMSUNG\Samsung Update Plus\SLUTrayNotifier.exe
2272 C:\Documents and Settings\***\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`db25fe00 (NTFS)

PhysicalDrive0 Model Number: FUJITSUMHV2100AHPL, Rev: 004200A0

Size Device Name MBR Status
--------------------------------------------
86 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: 61EB192C7F71BD66D2BE49CB9ECF6B9D7E483E82


Done!

cosinus 27.03.2011 19:54

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

shaiko 27.03.2011 20:11

Hallo,
wird erledigt. Mein Hintergrundbild ist allerdings weiterhin verschwunden und es liegt immer noch ein Shortcut "Windows Recovery" auf dem Desktop.
Soll ich wegen des Shortcuts etwas machen ?
Vielen Dank
shaiko

shaiko 27.03.2011 21:01

Hallo,
während der Voll-Scan mit Malwarebytes läuft, hat AVIRA Malware gefunden. Und zwar in der Datei C:\System volume information\...\A0561872.exe "TR/Drop.Softomat.AN".
Hätte ich das Virusprogramm deaktivieren sollen ?
Soll ich das mit Avira entfernen oder ist es eine Fehlmeldung, weil ich Avira nicht deaktiviert habe ?
Malwarebytes hat bisher noch nichts angezeigt.
Ich werde das Logfile aber auch gleich posten.

Vielen Dank
shaiko

shaiko 27.03.2011 21:22

Hier der Malwarebytes-Logfile:
Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes

Datenbank Version: 6185

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

27.03.2011 22:20:06
mbam-log-2011-03-27 (22-20-06).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 234037
Laufzeit: 1 Stunde(n), 1 Minute(n), 54 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

cosinus 27.03.2011 21:32

Deaktiviere die Systemwiederherstellung, im Verlauf der Infektion wurden auch Malwaredateien in Wiederherstellungspunkten mitgesichert - die sind alle nun unbrauchbar, da ein Zurücksetzen des Systems durch einen Wiederherstellungspunkt wahrscheinlich wieder eine Infektion nach sich ziehen würde.

shaiko 27.03.2011 22:00

Kann ich das nach Beendigung des Scans mit SuperAntiSpyware machen oder soll ich abbrechen, die Systemwiederherstellung deaktivieren und dann nochmal scannen ?

shaiko 27.03.2011 23:28

Hier das Logfile von SuperAntiSpyware:

SUPERAntiSpyware Scan Log
SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

Generated 03/28/2011 at 00:22 AM

Application Version : 4.50.1002

Core Rules Database Version : 6687
Trace Rules Database Version: 4499

Scan type : Complete Scan
Total Scan Time : 01:40:53

Memory items scanned : 536
Memory threats detected : 0
Registry items scanned : 6943
Registry threats detected : 0
File items scanned : 87041
File threats detected : 2

Trojan.Agent/Gen-Nullo[Short]
C:\SYSTEM VOLUME INFORMATION\_RESTORE{87F62899-E242-4152-9C18-1748202C0077}\RP373\A0561872.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{87F62899-E242-4152-9C18-1748202C0077}\RP373\A0561871.EXE

shaiko 27.03.2011 23:35

Die Systemwiederherstellung habe ich jetzt deaktiviert. Soll sie ausbleiben ?

cosinus 28.03.2011 09:34

Sieht soweit ok aus. Die SWH kannst du wieder aktivieren.
Rechner sonst soweit wieder ok?

shaiko 28.03.2011 20:23

Das einzige, was noch auffällt, ist, dass weiterhin ein Shortcut auf dem Desktop zu finden ist, mit dem Namen "Windos Recovery". Soll ich den einfach löschen ?

Und ein leider anderes Problem : ich habe noch ein 2. Laptop, das neuer ist und auf dem gerade heute Avira Antivir folgenden Virus gefunden hat:
HTML/Vaej.A.
Mir ist an dem Laptop eigentlich nichts aufgefallen, nur dass die Internetverbindung mehrfach unterbrochen wurde. Ich dachte es liege am Router, aber mit Laptop Nr.1 gab es keine Probleme.
Soll ich dafür einen eigenen Thread aufmachen ? Löschen mit AVIRA allein ist ja wahrscheinlich nicht ausreichend oder ?
Vielen Dank
shaiko

cosinus 29.03.2011 08:53

Zitat:

Soll ich den einfach löschen ?
Jup mach mal.

Zitat:

Soll ich dafür einen eigenen Thread aufmachen ?
ja ich bitte darum!!

Anonsten wären wir mit diesem Rechner in diesem Strang durch! :abklatsch:

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update



PDF-Reader aktualisieren
Dein Adobe Reader ist nicht aktuell, was ein großes Sicherheitsrisiko darstellt. Du solltest daher besser die alte Version über Systemsteuerung => Software deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst.

Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

shaiko 29.03.2011 17:05

Alles klar, vielen, vielen Dank nochmal für Deine Hilfe !!!


Alle Zeitangaben in WEZ +1. Es ist jetzt 17:25 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131