Logfile of random's system information tool 1.06 (written by random/random) Run by bksm at 2009-11-22 13:43:22 Microsoft Windows XP Home Edition Service Pack 3 System drive C: has 314 GB (82%) free of 382 GB Total RAM: 2047 MB (73% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:43:26, on 22.11.2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\Avira\AntiVir Desktop\sched.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\Rundll32.exe C:\Programme\Avira\AntiVir Desktop\avgnt.exe C:\Programme\Minimizor\Minimizor.exe C:\Programme\Creative\SBAudigy\Surround Mixer\CTSysVol.exe C:\WINDOWS\system32\RunDLL32.exe C:\Programme\Logitech\G-series Software\LGDCore.exe C:\Programme\Logitech\G-series Software\LCDMon.exe C:\Programme\Logitech\SetPoint II\SetpointII.exe C:\Programme\Gemeinsame Dateien\Logishrd\KHAL2\KHALMNPR.EXE C:\Programme\Logitech\G-series Software\Applets\LCDClock.exe C:\Programme\Logitech\G-series Software\Applets\LCDMedia.exe C:\Programme\Logitech\G-series Software\Applets\C2DtoG15.exe D:\Programme\installierte Programme\EazyToolz\EasyToolz.exe C:\Programme\Stardock\ObjectDock\ObjectDock.exe C:\Programme\Avira\AntiVir Desktop\avguard.exe C:\Programme\LogMeIn Hamachi\hamachi-2.exe C:\Programme\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\TUProgSt.exe C:\Programme\Tunngle\TnglCtrl.exe C:\Programme\Opera\opera.exe C:\Dokumente und Einstellungen\bksm\Desktop\RSIT.exe D:\Programme\installierte Programme\HijackThis\bksm.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [Minimizor] C:\Programme\Minimizor\Minimizor.exe O4 - HKLM\..\Run: [CTSysVol] C:\Programme\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [nwiz] C:\Programme\NVIDIA Corporation\nView\nwiz.exe /install O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [TrojanScanner] C:\Programme\Trojan Remover\Trjscan.exe /boot O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Programme\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\Run: [Launch LGDCore] "C:\Programme\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE O4 - HKLM\..\Run: [Launch LCDMon] "C:\Programme\Logitech\G-series Software\LCDMon.exe" O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [DefaultP17MIDI] MIDIDEF.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [DefaultP17MIDI] MIDIDEF.EXE (User 'Default user') O4 - Startup: EasyToolz.lnk = D:\Programme\installierte Programme\EazyToolz\EasyToolz.exe O4 - Startup: Stardock ObjectDock.lnk = C:\Programme\Stardock\ObjectDock\ObjectDock.exe O4 - Global Startup: SetPointII.lnk = ? O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - res://C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - res://C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - res://C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O16 - DPF: {4944924A-64E4-49C1-AC97-ABA3927262FE} (StWbUsa Control) - http://channel.dontblynk.com/Launcher/StWbUsa.CAB O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\avguard.exe O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Programme\LogMeIn Hamachi\hamachi-2.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: TuneUp Drive Defrag-Dienst (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe O23 - Service: TunngleService - Tunngle.net GmbH - C:\Programme\Tunngle\TnglCtrl.exe -- End of file - 6790 bytes ======Scheduled tasks folder====== C:\WINDOWS\tasks\1-Klick-Wartung.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}] Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Programme\Java\jre6\bin\jp2ssv.dll [2009-10-18 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] JQSIEStartDetectorImpl Class - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-18 73728] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "P17Helper"=Rundll32 P17.dll,P17Helper [] "avgnt"=C:\Programme\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153] "Minimizor"=C:\Programme\Minimizor\Minimizor.exe [2009-01-16 504320] "CTSysVol"=C:\Programme\Creative\SBAudigy\Surround Mixer\CTSysVol.exe [2005-10-31 57344] "nwiz"=C:\Programme\NVIDIA Corporation\nView\nwiz.exe [2009-09-23 1657448] "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-09-27 13918208] "NvMediaCenter"=NvMCTray.dll,NvTaskbarInit [] "KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k [] "TrojanScanner"=C:\Programme\Trojan Remover\Trjscan.exe [2009-08-04 1068424] "Malwarebytes Anti-Malware (reboot)"=C:\Programme\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080] ""= [] "Launch LGDCore"=C:\Programme\Logitech\G-series Software\LGDCore.exe [2006-03-06 1122304] "Launch LCDMon"=C:\Programme\Logitech\G-series Software\LCDMon.exe [2006-03-06 497152] "Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2009-06-17 55824] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] C:\Programme\Java\jre6\bin\jusched.exe [2009-10-18 149280] C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart SetPointII.lnk - C:\Programme\Logitech\SetPoint II\SetpointII.exe C:\Dokumente und Einstellungen\bksm\Startmenü\Programme\Autostart EasyToolz.lnk - D:\Programme\installierte Programme\EazyToolz\EasyToolz.exe Stardock ObjectDock.lnk - C:\Programme\Stardock\ObjectDock\ObjectDock.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=149 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "HonorAutoRunSetting"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\Programme\xchat\xchat.exe"="C:\Programme\xchat\xchat.exe:*:Enabled:XChat IRC Client" "C:\Programme\Xfire\Xfire.exe"="C:\Programme\Xfire\Xfire.exe:*:Enabled:Xfire" "C:\Programme\HLSW\hlsw.exe"="C:\Programme\HLSW\hlsw.exe:*:Enabled:HLSW Application" "C:\Programme\Enemy Territory\ET.exe"="C:\Programme\Enemy Territory\ET.exe:*:Enabled:ET" "C:\Programme\Opera\opera.exe"="C:\Programme\Opera\opera.exe:*:Enabled:Opera Internet Browser" "C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA" "C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB" "C:\Programme\Activision\Call of Duty - World at War\CoDWaW.exe"="C:\Programme\Activision\Call of Duty - World at War\CoDWaW.exe:*:Enabled:Call of Duty(R) - World at War(TM) " "C:\Programme\Trillian\trillian.exe"="C:\Programme\Trillian\trillian.exe:*:Enabled:Trillian" "C:\Programme\Steam\steam.exe"="C:\Programme\Steam\steam.exe:*:Enabled:Steam" "C:\Programme\Mozilla Firefox\firefox.exe"="C:\Programme\Mozilla Firefox\firefox.exe:*:Enabled:Firefox" "D:\Programme\installierte Programme\SFT Loader\leecher.exe"="D:\Programme\installierte Programme\SFT Loader\leecher.exe:*:Enabled:SFT Loader" "C:\Programme\Steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe"="C:\Programme\Steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe:*:Enabled:Call of Duty: Modern Warfare 2 - Multiplayer" "C:\Programme\Steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe"="C:\Programme\Steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe:*:Enabled:Call of Duty: Modern Warfare 2" "C:\Programme\uTorrent\uTorrent.exe"="C:\Programme\uTorrent\uTorrent.exe:*:Enabled:µTorrent" "C:\Programme\Activision\Call of Duty - World at War\CodWaw_LANFixed.exe"="C:\Programme\Activision\Call of Duty - World at War\CodWaw_LANFixed.exe:*:Enabled:Call of Duty(R): World at War Campaign/Coop" "C:\Programme\2K Games\Gearbox Software\Borderlands\Binaries\Borderlands.exe"="C:\Programme\2K Games\Gearbox Software\Borderlands\Binaries\Borderlands.exe:*:Enabled:Borderlands" "C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G] shell\AutoRun\command - G:\MSWorks\autorun.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae8a0c65-d4ee-11de-900a-00508db28ff4}] shell\AutoRun\command - E:\GETMYPIX.EXE ======File associations====== .js - edit - "C:\Programme\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" ======List of files/folders created in the last 1 months====== 2009-11-22 13:43:22 ----D---- C:\rsit 2009-11-22 11:43:15 ----A---- C:\WINDOWS\system32\TUProgSt.exe 2009-11-22 11:43:14 ----A---- C:\WINDOWS\system32\uxtuneup.dll 2009-11-22 11:43:13 ----A---- C:\WINDOWS\system32\TuneUpDefragService.exe 2009-11-21 18:44:56 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\nHancer 2009-11-21 18:44:50 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NVIDIA 2009-11-21 18:44:38 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\nHancer 2009-11-21 14:42:00 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Logitech 2009-11-21 14:06:15 ----D---- C:\WINDOWS\system32\appmgmt 2009-11-21 12:24:17 ----D---- C:\WINDOWS\system32\XPSViewer 2009-11-21 12:24:14 ----D---- C:\Programme\MSBuild 2009-11-21 12:24:12 ----D---- C:\WINDOWS\system32\en-US 2009-11-21 12:24:07 ----D---- C:\Programme\Reference Assemblies 2009-11-21 12:03:51 ----A---- C:\WINDOWS\system32\appmgmts.dll 2009-11-21 11:21:45 ----D---- C:\Programme\Panda Security 2009-11-20 13:44:51 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\KeePass 2009-11-20 13:02:20 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\PasswordSafe 2009-11-19 19:05:11 ----D---- C:\Programme\CCleaner 2009-11-19 10:34:09 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\Malwarebytes 2009-11-19 10:34:04 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes 2009-11-19 10:34:03 ----D---- C:\Programme\Malwarebytes' Anti-Malware 2009-11-19 08:27:36 ----D---- C:\Programme\ESET 2009-11-19 08:17:44 ----D---- C:\Programme\Trojan Remover 2009-11-19 08:17:44 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\Simply Super Software 2009-11-19 00:34:04 ----D---- C:\Program Files 2009-11-18 22:49:39 ----AD---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP 2009-11-18 22:49:10 ----A---- C:\WINDOWS\system32\ztvunrar36.dll 2009-11-18 22:49:10 ----A---- C:\WINDOWS\system32\ztvunace26.dll 2009-11-18 22:49:10 ----A---- C:\WINDOWS\system32\ztvcabinet.dll 2009-11-18 22:49:10 ----A---- C:\WINDOWS\system32\UNRAR3.dll 2009-11-18 22:49:10 ----A---- C:\WINDOWS\system32\unacev2.dll 2009-11-18 22:49:09 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Simply Super Software 2009-11-18 21:57:07 ----A---- C:\WINDOWS\wininit.ini 2009-11-18 13:22:30 ----D---- C:\Programme\NBA 2K10 RePack by Chikatila 2009-11-18 13:22:30 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\2K Sports 2009-11-18 11:22:19 ----D---- C:\WINDOWS\system32\AGEIA 2009-11-18 11:22:18 ----D---- C:\Programme\AGEIA Technologies 2009-11-18 11:15:38 ----D---- C:\Programme\SystemRequirementsLab 2009-11-18 10:50:30 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\Multi File Downloader 2009-11-17 16:19:24 ----A---- C:\WINDOWS\LCDMedia.INI 2009-11-17 11:42:14 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\Uniblue 2009-11-16 23:08:11 ----D---- C:\Programme\Steam 2009-11-12 14:55:30 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$ 2009-11-09 12:55:36 ----A---- C:\WINDOWS\EurekaLog.ini 2009-11-08 20:12:04 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\Tunngle 2009-11-08 20:12:04 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tunngle 2009-11-08 20:11:57 ----D---- C:\Programme\Tunngle 2009-11-06 10:11:10 ----D---- C:\Programme\TuneUp Utilities 2009 2009-11-06 03:14:42 ----A---- C:\WINDOWS\system32\xfcodec.dll 2009-11-05 08:02:36 ----D---- C:\Programme\LogMeIn Hamachi 2009-11-04 12:56:54 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\mirabyte 2009-11-04 12:56:54 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\IsolatedStorage 2009-11-04 12:07:42 ----A---- C:\WINDOWS\iun6002.exe 2009-11-03 18:26:08 ----SHD---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SecuROM 2009-11-03 18:17:55 ----D---- C:\Programme\2K Games 2009-11-03 18:17:13 ----D---- C:\Programme\DIFX 2009-11-03 18:17:12 ----DC---- C:\WINDOWS\system32\DRVSTORE 2009-11-03 18:17:09 ----D---- C:\WINDOWS\D56B0E274A3E46C9B5C1D93D580C099C.TMP 2009-11-03 15:11:56 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\EPSON 2009-10-27 10:51:38 ----A---- C:\WINDOWS\system32\nvunrm.exe 2009-10-27 10:51:38 ----A---- C:\WINDOWS\system32\cohelper.dll 2009-10-27 10:50:50 ----A---- C:\WINDOWS\system32\NVUNINST.EXE 2009-10-25 20:26:57 ----A---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\EasyToolz.ini 2009-10-25 18:40:30 ----RA---- C:\WINDOWS\system32\IMAGECFG.EXE 2009-10-25 18:18:37 ----D---- C:\Programme\Windows Resource Kits 2009-10-25 11:09:25 ----D---- C:\WINDOWS\pss 2009-10-25 10:26:52 ----HDC---- C:\WINDOWS\ie8 2009-10-24 17:20:54 ----D---- C:\Programme\SAW ======List of files/folders modified in the last 1 months====== 2009-11-22 13:43:23 ----D---- C:\WINDOWS\Prefetch 2009-11-22 13:38:24 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\Xfire 2009-11-22 12:49:02 ----SD---- C:\WINDOWS\Downloaded Program Files 2009-11-22 11:45:12 ----D---- C:\WINDOWS\system32\CatRoot2 2009-11-22 11:45:09 ----D---- C:\WINDOWS\Temp 2009-11-22 11:45:07 ----D---- C:\WINDOWS 2009-11-22 11:44:31 ----SHD---- C:\Config.Msi 2009-11-22 11:43:50 ----A---- C:\WINDOWS\SchedLgU.Txt 2009-11-22 11:43:17 ----SHD---- C:\WINDOWS\Installer 2009-11-22 11:43:16 ----SD---- C:\WINDOWS\Tasks 2009-11-22 11:43:15 ----D---- C:\WINDOWS\system32 2009-11-22 11:28:14 ----D---- C:\Programme\Mozilla Firefox 2009-11-22 11:16:00 ----RSHDC---- C:\WINDOWS\system32\dllcache 2009-11-22 11:15:59 ----D---- C:\WINDOWS\system32\drivers 2009-11-22 11:15:51 ----HD---- C:\WINDOWS\inf 2009-11-22 11:15:40 ----D---- C:\Programme\Gemeinsame Dateien\LogiShrd 2009-11-22 11:15:36 ----D---- C:\Programme\Logitech 2009-11-22 11:15:26 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LogiShrd 2009-11-22 10:39:14 ----RD---- C:\Programme 2009-11-22 00:10:36 ----A---- C:\WINDOWS\system32\PnkBstrB.exe 2009-11-22 00:10:24 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\HLSW 2009-11-21 15:07:20 ----D---- C:\WINDOWS\system32\ReinstallBackups 2009-11-21 14:01:05 ----RSD---- C:\WINDOWS\assembly 2009-11-21 13:59:45 ----D---- C:\WINDOWS\Microsoft.NET 2009-11-21 12:31:41 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2009-11-21 12:31:29 ----D---- C:\WINDOWS\WinSxS 2009-11-21 12:24:11 ----RSD---- C:\WINDOWS\Fonts 2009-11-21 12:23:05 ----D---- C:\WINDOWS\system32\mui 2009-11-21 12:23:05 ----D---- C:\Programme\Internet Explorer 2009-11-21 11:33:29 ----SHD---- C:\System Volume Information 2009-11-21 11:33:29 ----D---- C:\WINDOWS\system32\Restore 2009-11-20 13:12:39 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\uTorrent 2009-11-20 08:44:53 ----D---- C:\Programme\Trillian 2009-11-20 08:27:53 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\X-Chat 2 2009-11-20 08:24:33 ----D---- C:\Programme\xchat 2009-11-19 19:07:46 ----D---- C:\WINDOWS\Minidump 2009-11-19 19:07:46 ----D---- C:\WINDOWS\Debug 2009-11-18 21:43:47 ----SHD---- C:\RECYCLER 2009-11-18 21:42:44 ----D---- C:\Dokumente und Einstellungen 2009-11-18 15:17:51 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\vlc 2009-11-18 13:41:12 ----D---- C:\Programme\USB GAME PAD 2009-11-18 11:51:39 ----SD---- C:\Programme\Xfire 2009-11-18 11:22:04 ----D---- C:\Programme\Gemeinsame Dateien\Wise Installation Wizard 2009-11-17 21:40:50 ----D---- C:\WINDOWS\system32\config 2009-11-16 23:16:42 ----D---- C:\WINDOWS\system32\DirectX 2009-11-13 16:03:27 ----D---- C:\Programme\Spybot - Search & Destroy 2009-11-12 10:00:51 ----HD---- C:\WINDOWS\$hf_mig$ 2009-11-11 16:46:17 ----A---- C:\WINDOWS\WORDPAD.INI 2009-11-11 16:42:07 ----HD---- C:\Programme\InstallShield Installation Information 2009-11-06 10:08:30 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software 2009-11-05 18:36:21 ----A---- C:\WINDOWS\system32\MRT.exe 2009-11-05 09:35:35 ----D---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\dvdcss 2009-11-04 12:55:43 ----D---- C:\Programme\Gemeinsame Dateien\Microsoft Shared 2009-11-04 12:55:37 ----D---- C:\WINDOWS\pchealth 2009-11-04 08:04:36 ----D---- C:\WINDOWS\Help 2009-11-03 18:17:10 ----RSH---- C:\boot.ini 2009-11-01 12:02:52 ----D---- C:\Programme\Enemy Territory 2009-10-31 14:47:57 ----D---- C:\WINDOWS\system 2009-10-31 14:36:23 ----D---- C:\WINDOWS\system32\CatRoot 2009-10-30 15:35:07 ----D---- C:\Programme\Opera 2009-10-29 16:16:26 ----SD---- C:\Dokumente und Einstellungen\bksm\Anwendungsdaten\Microsoft 2009-10-27 10:56:16 ----D---- C:\Programme\NVIDIA Corporation 2009-10-27 10:50:37 ----D---- C:\NVIDIA 2009-10-26 09:24:27 ----D---- C:\Programme\Microsoft Works 2009-10-25 11:16:35 ----A---- C:\WINDOWS\win.ini 2009-10-25 11:16:35 ----A---- C:\WINDOWS\system.ini 2009-10-25 11:02:54 ----D---- C:\WINDOWS\ie8updates 2009-10-25 10:52:34 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Adobe 2009-10-25 10:51:32 ----D---- C:\Programme\Gemeinsame Dateien 2009-10-25 10:28:25 ----D---- C:\WINDOWS\system32\de-de 2009-10-25 10:27:07 ----D---- C:\WINDOWS\WBEM 2009-10-25 10:27:04 ----D---- C:\WINDOWS\Media ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 avgio;avgio; \??\C:\Programme\Avira\AntiVir Desktop\avgio.sys [] R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104] R1 intelppm;Intel-Prozessortreiber; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40448] R1 kbdhid;Tastatur-HID-Treiber; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720] R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520] R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-07-28 55656] R2 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368] R2 LBeepKE;LBeepKE; C:\WINDOWS\System32\Drivers\LBeepKE.sys [2009-06-17 10384] R3 atxboxfl;XboxCtrl_filt_Service; C:\WINDOWS\system32\DRIVERS\atxboxfl.sys [2003-12-01 25936] R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2005-01-10 138752] R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-09-23 26176] R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2009-06-17 35472] R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2009-06-17 37392] R3 mouhid;Maus-HID-Treiber; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-18 12288] R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-09-27 7655872] R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2009-07-01 66688] R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2009-07-01 13824] R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2005-01-10 106496] R3 P17;SB Live! 24-bit; C:\WINDOWS\system32\drivers\P17.sys [2005-07-07 1389056] R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\WINDOWS\system32\DRIVERS\tap0901t.sys [2009-09-16 27136] R3 usbccgp;Microsoft Standard-USB-Haupttreiber; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128] R3 usbehci;Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208] R3 usbhub;Microsoft USB-Standardhubtreiber; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520] R3 usbohci;Miniporttreiber für Microsoft USB Open Host-Controller; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152] R3 usbstor;USB-Massenspeichertreiber; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368] R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000] R3 WinRing0_1_1_1;WinRing0_1_1_1; \??\C:\Programme\Logitech\G-series Software\Applets\WinRing0.sys [] S3 cpuz130;cpuz130; C:\WINDOWS\system32\drivers\cpuz130.sys [] S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys [] S3 PnkBstrK;PnkBstrK; \??\C:\WINDOWS\system32\drivers\PnkBstrK.sys [] S3 usbprint;Microsoft USB-Druckerklasse; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856] S3 usbscan;USB-Scannertreiber; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104] S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AntiVirSchedulerService;Avira AntiVir Planer; C:\Programme\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289] R2 AntiVirService;Avira AntiVir Guard; C:\Programme\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089] R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Programme\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568] R2 JavaQuickStarterService;Java Quick Starter; C:\Programme\Java\jre6\bin\jqs.exe [2009-10-18 153376] R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-09-27 172100] R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-09-27 75064] R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2009-11-22 189744] R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\WINDOWS\System32\TUProgSt.exe [2009-11-22 604488] R2 TunngleService;TunngleService; C:\Programme\Tunngle\TnglCtrl.exe [2009-09-16 666360] R2 UxTuneUp;TuneUp Designerweiterung; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336] S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104] S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664] S3 TuneUp.Defrag;TuneUp Drive Defrag-Dienst; C:\WINDOWS\System32\TuneUpDefragService.exe [2009-11-22 361288] S3 WMPNetworkSvc;Windows Media Player-Netzwerkfreigabedienst; C:\Programme\Windows Media Player\WMPNetwk.exe [2006-11-03 920576] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096] -----------------EOF-----------------