Logfile of random's system information tool 1.05 (written by random/random) Run by Loxagon at 2008-12-30 14:22:30 Microsoft Windows XP Professional Service Pack 2 System drive F: has 2 GB (14%) free of 13 GB Total RAM: 1535 MB (63% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:22:42, on 30.12.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\Ati2evxx.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\Ati2evxx.exe F:\WINDOWS\Explorer.EXE L:\Programme\Lavasoft\Ad-Aware\aawservice.exe F:\WINDOWS\system32\spoolsv.exe F:\WINDOWS\system32\cisvc.exe F:\Programme\Gemeinsame Dateien\MicroWorld\Agent\MWASER.EXE F:\Programme\Gemeinsame Dateien\MicroWorld\Agent\MWAgent.exe F:\WINDOWS\System32\svchost.exe F:\Programme\Gemeinsame Dateien\AOL\1180704905\ee\AOLSoftware.exe F:\Programme\FreePDF_XP\fpassist.exe L:\Programme\SlySoft\CloneCD\CloneCDTray.exe F:\Programme\Java\jre1.6.0_07\bin\jusched.exe F:\WINDOWS\system32\ctfmon.exe L:\Programme\Spybot - Search & Destroy\TeaTimer.exe F:\Programme\DAEMON Tools Lite\daemon.exe F:\Programme\OpenOffice.org 2.4\program\soffice.exe F:\Programme\OpenOffice.org 2.4\program\soffice.BIN F:\WINDOWS\system32\wscntfy.exe F:\Programme\Java\jre1.6.0_07\bin\jucheck.exe F:\WINDOWS\system32\cidaemon.exe F:\Programme\internet explorer\iexplore.exe F:\WINDOWS\system32\NOTEPAD.EXE F:\Programme\FlashGet\flashget.exe F:\Dokumente und Einstellungen\Loxagon\Lokale Einstellungen\Temporary Internet Files\Content.IE5\P8SU05J1\RSIT[1].exe L:\Programme\Trend Micro\HijackThis\Loxagon.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - F:\Programme\FlashGet\jccatch.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - L:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Programme\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - F:\Programme\FlashGet\getflash.dll O4 - HKLM\..\Run: [ATIPTA] F:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [HostManager] F:\Programme\Gemeinsame Dateien\AOL\1180704905\ee\AOLSoftware.exe O4 - HKLM\..\Run: [IPHSend] F:\Programme\Gemeinsame Dateien\AOL\IPHSend\IPHSend.exe O4 - HKLM\..\Run: [ATICCC] "F:\Programme\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay O4 - HKLM\..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [FreePDF Assistant] F:\Programme\FreePDF_XP\fpassist.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [CloneCDTray] "l:\Programme\SlySoft\CloneCD\CloneCDTray.exe" /s O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Programme\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [NBJ] "F:\Programme\Ahead\Nero BackItUp\NBJ.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] l:\Programme\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "F:\Programme\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = F:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: OpenOffice.org 2.4.lnk = F:\Programme\OpenOffice.org 2.4\program\quickstart.exe O8 - Extra context menu item: &Alles mit FlashGet laden - F:\Programme\FlashGet\jc_all.htm O8 - Extra context menu item: &Mit FlashGet laden - F:\Programme\FlashGet\jc_link.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Programme\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Programme\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - F:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - F:\WINDOWS\bdoscandel.exe O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - F:\Programme\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - F:\Programme\FlashGet\FlashGet.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - L:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - L:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - F:\Programme\ICQ6\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - F:\Programme\ICQ6\ICQ.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Programme\Messenger\msmsgs.exe O15 - Trusted IP range: http://192.168.0.1 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.de/scan_de/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227291726310 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1227291715107 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game01.zylom.com/activex/zylomgamesplayer.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - L:\Programme\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - F:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - F:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe O23 - Service: MWAgent - MicroWorld Technologies Inc. - F:\Programme\Gemeinsame Dateien\MicroWorld\Agent\MWASER.EXE O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - F:\Programme\WinPcap\rpcapd.exe O23 - Service: TuneUp Drive Defrag-Dienst (TuneUp.Defrag) - TuneUp Software GmbH - F:\WINDOWS\System32\TuneUpDefragService.exe -- End of file - 7787 bytes ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - F:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}] FGCatchUrl - F:\Programme\FlashGet\jccatch.dll [2007-06-28 94308] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}] Spybot-S&D IE Protection - L:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] SSVHelper Class - F:\Programme\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}] FlashGet GetFlash Class - F:\Programme\FlashGet\getflash.dll [2007-05-18 163840] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"=F:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-05-03 344064] "HostManager"=F:\Programme\Gemeinsame Dateien\AOL\1180704905\ee\AOLSoftware.exe [2006-05-23 50760] "IPHSend"=F:\Programme\Gemeinsame Dateien\AOL\IPHSend\IPHSend.exe [2006-02-17 124520] "ATICCC"=F:\Programme\ATI Technologies\ATI.ACE\cli.exe [2006-01-02 45056] "NeroFilterCheck"=F:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648] "FreePDF Assistant"=F:\Programme\FreePDF_XP\fpassist.exe [2007-06-26 312320] "Adobe Reader Speed Launcher"=F:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672] "CloneCDTray"=l:\Programme\SlySoft\CloneCD\CloneCDTray.exe [2006-09-28 57344] "SunJavaUpdateSched"=F:\Programme\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"=F:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360] "NBJ"=F:\Programme\Ahead\Nero BackItUp\NBJ.exe [2004-07-26 1867776] "SpybotSD TeaTimer"=l:\Programme\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296] "DAEMON Tools Lite"=F:\Programme\DAEMON Tools Lite\daemon.exe [2008-02-14 486856] F:\Dokumente und Einstellungen\Loxagon\Startmenü\Programme\Autostart Adobe Gamma.lnk - F:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe OpenOffice.org 2.4.lnk - F:\Programme\OpenOffice.org 2.4\program\quickstart.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent] F:\WINDOWS\system32\Ati2evxx.dll [2005-05-04 46080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avldr] F:\WINDOWS\system32\avldr.dll [2008-03-18 58672] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] F:\WINDOWS\system32\WgaLogon.dll [2007-04-10 236928] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - F:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "SynchronousMachineGroupPolicy"=0 "SynchronousUserGroupPolicy"=0 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 "NoDriveAutoRun"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "F:\Programme\Azureus\Azureus.exe"="F:\Programme\Azureus\Azureus.exe:*:Enabled:Azureus" "F:\Programme\Trillian\trillian.exe"="F:\Programme\Trillian\trillian.exe:*:Enabled:Trillian" "F:\Programme\FlashGet\flashget.exe"="F:\Programme\FlashGet\flashget.exe:*:Enabled:Flashget" "K:\mIRC\mirc.exe"="K:\mIRC\mirc.exe:*:Enabled:mIRC" "F:\Programme\Gemeinsame Dateien\AOL\Loader\aolload.exe"="F:\Programme\Gemeinsame Dateien\AOL\Loader\aolload.exe:*:Enabled:AOL Loader" "F:\Programme\Gemeinsame Dateien\AOL\1180704905\ee\aolsoftware.exe"="F:\Programme\Gemeinsame Dateien\AOL\1180704905\ee\aolsoftware.exe:*:Enabled:AOL Services" "F:\Programme\Gemeinsame Dateien\AOL\1180704905\ee\aim6.exe"="F:\Programme\Gemeinsame Dateien\AOL\1180704905\ee\aim6.exe:*:Enabled:AIM" "D:\snes\zsnesw.exe"="D:\snes\zsnesw.exe:*:Enabled:zsnesw" "F:\Programme\AIM6\aim6.exe"="F:\Programme\AIM6\aim6.exe:*:Enabled:AIM" "F:\Programme\ICQ6\ICQ.exe"="F:\Programme\ICQ6\ICQ.exe:*:Enabled:ICQ6" "F:\PROGRA~1\GEMEIN~1\MICROW~1\Agent\MWAGENT.EXE"="F:\PROGRA~1\GEMEIN~1\MICROW~1\Agent\MWAGENT.EXE:*:Enabled:MicroWorld Management Agent" "F:\PROGRA~1\GEMEIN~1\MICROW~1\eScanRAD\ESCANRAD.EXE"="F:\PROGRA~1\GEMEIN~1\MICROW~1\eScanRAD\ESCANRAD.EXE:*:Enabled:eScan Remote Administration Tool" "F:\Programme\VideoLAN\VLC\vlc.exe"="F:\Programme\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "F:\PROGRA~1\GEMEIN~1\MICROW~1\Agent\MWAGENT.EXE"="F:\PROGRA~1\GEMEIN~1\MICROW~1\Agent\MWAGENT.EXE:*:Enabled:MicroWorld Management Agent" "F:\PROGRA~1\GEMEIN~1\MICROW~1\eScanRAD\ESCANRAD.EXE"="F:\PROGRA~1\GEMEIN~1\MICROW~1\eScanRAD\ESCANRAD.EXE:*:Enabled:eScan Remote Administration Tool" ======List of files/folders created in the last 1 months====== 2008-12-30 14:22:30 ----D---- F:\rsit 2008-12-30 13:56:38 ----A---- F:\WINDOWS\gmer.ini 2008-12-30 13:56:34 ----A---- F:\WINDOWS\gmer_uninstall.cmd 2008-12-30 13:56:34 ----A---- F:\WINDOWS\gmer.exe 2008-12-30 13:56:34 ----A---- F:\WINDOWS\gmer.dll 2008-12-30 12:54:00 ----SH---- F:\WINDOWS\SAEC6D29F.tmp 2008-12-30 12:47:42 ----D---- F:\Programme\CCleaner 2008-12-06 16:25:36 ----D---- F:\Dokumente und Einstellungen\Loxagon\Anwendungsdaten\Moyea 2008-12-06 15:46:48 ----D---- F:\Dokumente und Einstellungen\Loxagon\Anwendungsdaten\DonationCoder 2008-12-06 15:46:20 ----D---- F:\Programme\WinPcap 2008-12-05 18:21:01 ----D---- F:\WINDOWS\BDOSCAN8 ======List of files/folders modified in the last 1 months====== 2008-12-30 14:22:37 ----D---- F:\WINDOWS\Prefetch 2008-12-30 13:57:20 ----D---- F:\Programme\FlashGet 2008-12-30 13:56:38 ----D---- F:\WINDOWS 2008-12-30 13:56:34 ----D---- F:\WINDOWS\system32\drivers 2008-12-30 13:40:20 ----D---- F:\Dokumente und Einstellungen\Loxagon\Anwendungsdaten\OpenOffice.org2 2008-12-30 13:38:18 ----D---- F:\WINDOWS\temp 2008-12-30 13:35:03 ----A---- F:\WINDOWS\SchedLgU.Txt 2008-12-30 13:33:22 ----D---- F:\WINDOWS\Downloaded Program Files 2008-12-30 12:51:00 ----D---- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy 2008-12-30 12:50:49 ----D---- F:\WINDOWS\Debug 2008-12-30 12:47:42 ----RD---- F:\Programme 2008-12-29 23:12:34 ----HD---- F:\Programme\InstallShield Installation Information 2008-12-29 22:45:17 ----D---- F:\Programme\Trillian 2008-12-28 16:25:22 ----D---- F:\WINDOWS\system32\CatRoot2 2008-12-28 16:20:35 ----D---- F:\WINDOWS\system32\Restore 2008-12-28 14:38:14 ----D---- F:\WINDOWS\system32 2008-12-28 00:00:00 ----D---- F:\Dokumente und Einstellungen\Loxagon\Anwendungsdaten\Azureus 2008-12-27 22:09:15 ----D---- F:\Programme\Mozilla Firefox 2008-12-27 22:01:54 ----SHD---- F:\WINDOWS\Installer 2008-12-27 12:24:13 ----D---- F:\Dokumente und Einstellungen\Loxagon\Anwendungsdaten\dvdcss 2008-12-25 20:08:43 ----D---- F:\WINDOWS\inf 2008-12-22 20:49:59 ----SHD---- F:\System Volume Information 2008-12-19 22:44:36 ----A---- F:\WINDOWS\NeroDigital.ini 2008-12-05 11:22:44 ----D---- F:\WINDOWS\Tasks 2008-12-05 11:21:26 ----D---- F:\Programme\TuneUp Utilities 2008 ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 AmdK7;AMD K7-Prozessortreiber; F:\WINDOWS\System32\DRIVERS\amdk7.sys [2004-08-04 41472] R1 DLARTL_M;DLARTL_M; F:\WINDOWS\System32\Drivers\DLARTL_M.SYS [2007-02-02 30296] R1 ElbyCDIO;ElbyCDIO Driver; F:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2007-08-07 25160] R1 PQNTDrv;PQNTDrv; F:\WINDOWS\system32\drivers\PQNTDrv.sys [2004-05-05 4228] R1 ssmdrv;ssmdrv; F:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-11-08 21248] R2 DLABMFSM;DLABMFSM; F:\WINDOWS\System32\Drivers\DLABMFSM.SYS [2007-03-10 35800] R2 DLABOIOM;DLABOIOM; F:\WINDOWS\System32\Drivers\DLABOIOM.SYS [2007-03-10 33112] R2 DLADResM;DLADResM; F:\WINDOWS\System32\Drivers\DLADResM.SYS [2007-03-10 9368] R2 DLAIFS_M;DLAIFS_M; F:\WINDOWS\System32\Drivers\DLAIFS_M.SYS [2007-03-10 108696] R2 DLAOPIOM;DLAOPIOM; F:\WINDOWS\System32\Drivers\DLAOPIOM.SYS [2007-03-10 27416] R2 DLAPoolM;DLAPoolM; F:\WINDOWS\System32\Drivers\DLAPoolM.SYS [2007-03-10 16568] R2 DLAUDF_M;DLAUDF_M; F:\WINDOWS\System32\Drivers\DLAUDF_M.SYS [2007-03-10 98648] R2 DLAUDFAM;DLAUDFAM; F:\WINDOWS\System32\Drivers\DLAUDFAM.SYS [2007-03-10 94296] R2 DRVNDDM;DRVNDDM; F:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2007-01-27 52168] R2 PARCLASS1;PARCLASS1; \??\F:\WINDOWS\system32\drivers\PARCLASS1.sys [] R2 sentinel;sentinel; \??\F:\WINDOWS\system32\drivers\sentinel.sys [] R3 ati2mtag;ati2mtag; F:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2005-05-04 1133056] R3 ElbyCDFL;ElbyCDFL; F:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2007-02-16 34760] R3 ElbyDelay;ElbyDelay; F:\WINDOWS\System32\Drivers\ElbyDelay.sys [2007-02-16 11984] R3 FETNDIS;VIA Rhine Family Fast Ethernet Adapter Driver; F:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2002-07-05 40448] R3 hamachi;Hamachi Network Interface; F:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-01-09 25280] R3 pcouffin;VSO Software pcouffin; F:\WINDOWS\System32\Drivers\pcouffin.sys [2008-07-25 47360] R3 usbehci;Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller; F:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624] R3 usbhub;USB2-aktivierter Hub; F:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-04 57600] R3 USBSTOR;USB-Massenspeichertreiber; F:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496] R3 usbuhci;Miniporttreiber für universellen Microsoft USB-Hostcontroller; F:\WINDOWS\System32\DRIVERS\usbuhci.sys [2001-08-23 18944] R3 VIAudio;VIA AC'97 Enhanced Audio Controller (WDM); F:\WINDOWS\system32\drivers\viaudio.sys [2002-03-11 43776] S1 Uim_IM;UIM Drive Backup Image Plugin; F:\WINDOWS\System32\Drivers\Uim_IM.sys [2005-04-24 120995] S1 UimBus;Universal Image Mounter Controller; F:\WINDOWS\system32\DRIVERS\UimBus.sys [2005-04-25 26672] S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter; \??\F:\WINDOWS\system32\drivers\NSDriver.sys [] S3 Ad-Watch Real-Time Scanner;AW Real-Time Scanner; \??\F:\WINDOWS\system32\drivers\AWRTPD.sys [] S3 Ad-Watch Registry Filter;Ad-Watch Registry Kernel Filter; \??\F:\WINDOWS\system32\drivers\AWRTRD.sys [] S3 agfcpfvm;agfcpfvm; F:\WINDOWS\system32\drivers\agfcpfvm.sys [] S3 CrystalSysInfo;CrystalSysInfo; \??\L:\Programme\MediaCoder\SysInfo.sys [] S3 gmer;gmer; F:\WINDOWS\System32\DRIVERS\gmer.sys [2008-12-30 85969] S3 GVCplDrv;GVCplDrv; F:\WINDOWS\system32\drivers\GVCplDrv.sys [2004-05-02 23040] S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120; F:\WINDOWS\system32\DRIVERS\libusb0.sys [2007-05-10 29184] S3 nm;Netzwerkmonitortreiber; F:\WINDOWS\system32\DRIVERS\NMnt.sys [2004-08-04 40320] S3 NPF;NetGroup Packet Filter Driver; F:\WINDOWS\system32\drivers\npf.sys [2008-05-22 34576] S3 NTSIM;NTSIM; \??\F:\WINDOWS\system32\ntsim.sys [] S3 sermouse;Serieller Maustreiber; F:\WINDOWS\System32\DRIVERS\sermouse.sys [2001-08-23 18176] S3 usbccgp;Microsoft Standard-USB-Haupttreiber; F:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616] S3 usbprint;Microsoft USB-Druckerklasse; F:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856] S3 usbscan;USB-Scannertreiber; F:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 15104] S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; F:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; F:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944] S4 IntelIde;IntelIde; F:\WINDOWS\system32\drivers\IntelIde.sys [] S4 WS2IFSL;Windows Socket 2.0 Non-IFS-Dienstanbieter-Unterstützungsumgebung; F:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-23 12032] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 aawservice;Lavasoft Ad-Aware Service; L:\Programme\Lavasoft\Ad-Aware\aawservice.exe [2008-07-19 611664] R2 Ati HotKey Poller;Ati HotKey Poller; F:\WINDOWS\system32\Ati2evxx.exe [2005-05-04 364544] R2 MWAgent;MWAgent; F:\Programme\Gemeinsame Dateien\MicroWorld\Agent\MWASER.EXE [2007-04-07 414208] R2 UxTuneUp;TuneUp Designerweiterung; F:\WINDOWS\System32\svchost.exe [2004-08-04 14336] S2 ATI Smart;ATI Smart; F:\WINDOWS\system32\ati2sgag.exe [2005-05-03 516096] S3 Adobe LM Service;Adobe LM Service; F:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe [2007-10-26 72704] S3 aspnet_state;ASP.NET-Zustandsdienst; F:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; F:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; F:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864] S3 idsvc;Windows CardSpace; F:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256] S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); F:\Programme\WinPcap\rpcapd.exe [2008-05-22 92792] S3 TuneUp.Defrag;TuneUp Drive Defrag-Dienst; F:\WINDOWS\System32\TuneUpDefragService.exe [2008-09-27 361728] S3 WMPNetworkSvc;Windows Media Player-Netzwerkfreigabedienst; F:\Programme\Windows Media Player\WMPNetwk.exe [2006-11-03 920576] S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; F:\WINDOWS\system32\svchost.exe [2004-08-04 14336] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; F:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880] -----------------EOF-----------------