Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 22.07.2012, 02:34   #1
RIpchip
 
Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht - Standard

Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht



Hallo,

der PC meiner Freundin hat seit gestern immer wieder eine Meldung (Avira) über ein und den selben Trojaner gebracht. Die Meldung kam auch als er in Quarantänte verschoben wurde.
Habe anschließend mal Malwarebytes installiert und einen Quick- bzw. Vollscan durchgeführt wo er dann edliche Trojaner/Viren entdeckt und entfernt hat.
Logfiles davon habe ich leider nicht gespeichert.

Nun habe ich heute mal nen Vollscan mit Malwarebytes durchgeführt wo dann nichts mehr gefunden wurde aber Avira hat 8 schädliche Datein/Software etc. gefunden und hab sie dann in Quarantäne verschoben.

Vor ein paar Stunden ist dann aufeinmal das Internet kurz am PC ausgefallen. Hatte mir nichts dabei gedacht nur als ich dann versucht habe erneut ins Netz zu gehen konnte keine Verbindung mehr aufgebaut werden bzw. ist immer nach 2 Sekunden wenn eine seite geladen hat das Internet ausgefallen.
Jetzt gerade funktioniert es wieder aber erst nachdem ich "Defrogger" benutzt habe und "Disable" gedrückt habe, "OTL" scan durchgeführt habe und "Gmer" auch. Keine Ahnung ob das zusammenhängt.

Hier der OTL Log:

OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 21.07.2012 20:33:36 - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\sarah\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

3,50 Gb Total Physical Memory | 2,28 Gb Available Physical Memory | 65,10% Memory free
7,23 Gb Paging File | 5,84 Gb Available in Paging File | 80,71% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 153,38 Gb Total Space | 38,20 Gb Free Space | 24,91% Space Free | Partition Type: NTFS
Drive D: | 727,56 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF

Computer Name: SARAH-PC | User Name: sarah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.07.21 20:27:13 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\sarah\Desktop\OTL.exe
PRC - [2012.07.03 20:37:20 | 001,192,664 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.07.03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.05.06 21:33:31 | 001,564,368 | ---- | M] () -- C:\Program Files\Guard-ICQ\GuardICQ.exe
PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.02 00:48:48 | 000,466,896 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\program files\avira\antivir desktop\avscan.exe
PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.02 00:31:35 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.05.02 00:22:53 | 000,391,632 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\program files\avira\antivir desktop\avcenter.exe
PRC - [2012.04.24 02:11:55 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.03.20 11:16:08 | 000,247,872 | ---- | M] () -- C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE
PRC - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.03.21 20:56:16 | 001,230,704 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2009.12.04 15:48:54 | 001,728,512 | ---- | M] (VIA) -- C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2009.04.27 15:20:02 | 000,074,408 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files\Lexmark 1200 Series\LXCZbmgr.exe
PRC - [2009.04.27 15:19:38 | 000,058,024 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
PRC - [2009.04.11 00:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 00:27:30 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2009.04.11 00:27:22 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
PRC - [2007.04.19 15:43:42 | 000,537,520 | ---- | M] ( ) -- C:\Windows\System32\lxczcoms.exe


========== Modules (No Company Name) ==========

MOD - [2012.07.03 20:37:20 | 001,192,664 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
MOD - [2012.05.06 21:33:31 | 001,564,368 | ---- | M] () -- C:\Program Files\Guard-ICQ\GuardICQ.exe
MOD - [2011.05.28 22:04:56 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\rarext.dll
MOD - [2011.03.21 20:57:34 | 000,096,112 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.03.21 20:56:16 | 001,230,704 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2009.11.03 11:11:50 | 047,628,288 | ---- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\Skin.dll
MOD - [2009.05.07 16:53:18 | 000,106,496 | ---- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
MOD - [2009.05.07 16:50:46 | 000,073,728 | ---- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll
MOD - [2008.02.14 13:57:00 | 000,094,208 | ---- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\VMicApi.dll


========== Win32 Services (SafeList) ==========

SRV - [2012.07.16 17:59:06 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.06.18 13:59:14 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.05.06 21:33:31 | 001,564,368 | ---- | M] () [Auto | Running] -- C:\Program Files\Guard-ICQ\GuardICQ.exe -- (Guard.Mail.ru)
SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.03.20 11:16:08 | 000,247,872 | ---- | M] () [Auto | Running] -- C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE -- (ICQ Service)
SRV - [2012.02.19 18:53:49 | 000,481,064 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2007.04.19 15:43:42 | 000,537,520 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxczcoms.exe -- (lxcz_device)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\Drivers\AsrCDDrv.sys -- (AsrCDDrv)
DRV - [2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.04.27 10:20:04 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.04.25 00:32:27 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.04.16 21:17:40 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.07.10 05:37:00 | 011,008,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.11.25 21:02:46 | 001,108,480 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2006.11.02 09:30:56 | 000,429,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm60x32.sys -- (NVENETFD)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=334&systemid=406&sr=0&q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.searchnu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 36 40 8F E5 70 30 CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=334&systemid=406&sr=0&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaulturl: "hxxp://www.searchcanvas.com/web?ot=7&q="
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de"
FF - prefs.js..keyword.URL: "hxxp://dts.search-results.com/sr?src=ffb&appid=334&systemid=406&sr=0&q="
FF - prefs.js..network.proxy.http: "193.84.22.97"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.no_proxies_on: "localhost, 127.0.0.1, stealthy.co"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\sarah\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.07.06 22:14:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.18 13:59:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.10 18:49:05 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.18 13:59:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.10 18:49:05 | 000,000,000 | ---D | M]

[2012.07.03 23:26:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\sarah\AppData\Roaming\mozilla\Extensions
[2012.07.08 14:12:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\sarah\AppData\Roaming\mozilla\Firefox\Profiles\r8v3ln8a.default\extensions
[2012.05.09 22:05:29 | 000,000,000 | ---D | M] (FT SleekDark) -- C:\Users\sarah\AppData\Roaming\mozilla\Firefox\Profiles\r8v3ln8a.default\extensions\{a21cd440-41d6-11e0-9207-0800200c9a66}
[2012.07.20 18:06:17 | 000,000,950 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\searchplugins\icqplugin-1.xml
[2011.09.07 15:04:05 | 000,000,950 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\searchplugins\icqplugin-3.xml
[2011.09.07 21:18:50 | 000,000,950 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\searchplugins\icqplugin-4.xml
[2011.03.30 15:14:34 | 000,001,042 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\searchplugins\icqplugin.xml
[2012.07.03 23:26:02 | 000,002,519 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\searchplugins\Search_Results.xml
[2012.07.17 18:42:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2012.07.03 23:26:08 | 000,000,000 | ---D | M] (DataMngr) -- C:\PROGRAM FILES\SEARCHQU TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2012.02.29 17:13:28 | 000,258,567 | ---- | M] () (No name found) -- C:\USERS\SARAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R8V3LN8A.DEFAULT\EXTENSIONS\{46551EC9-40F0-4E47-8E18-8E5CF550CFB8}.XPI
[2012.06.15 15:44:44 | 000,182,698 | ---- | M] () (No name found) -- C:\USERS\SARAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R8V3LN8A.DEFAULT\EXTENSIONS\STEALTHYEXTENSION@GMAIL.COM.XPI
[2012.06.18 13:59:15 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.04.09 16:36:09 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.11.10 18:48:07 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.11.10 18:48:07 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.11.10 18:48:07 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.11.10 18:48:07 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.03 23:26:02 | 000,002,519 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2011.11.10 18:48:07 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.11.10 18:48:07 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml

O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (ICQ Sparberater) - {0766C1B9-B2DC-46E5-8934-4F3D6B42B1BD} - C:\Program Files\icq\Internet Explorer\icq.dll (solute gmbh)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll (facemoods.com BHO)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~1\SEARCH~1\Datamngr\BROWSE~1.DLL (Bandoo Media, inc)
O2 - BHO: ([verify-U]_Add-on) - {F4552A56-119C-478E-AB3F-2C850F78B72E} - C:\Program Files\[verify-U]_AVS_IE_Add-on\[verify-U]_AVS.dll (Cybits AG)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll (facemoods.com)
O3 - HKLM\..\Toolbar: (Reg Error: Value error.) - 10 - Reg Error: Value error. File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Guard.Mail.ru.gui] C:\Program Files\Guard-ICQ\GuardICQ.exe ()
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [lxczbmgr.exe] C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [Facebook Update] C:\Users\sarah\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Spotify] C:\Users\sarah\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\sarah\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\sarah\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe (ICQ, LLC.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 82.212.62.62 78.42.43.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3E2341BC-7121-4792-A4CF-EA2D259D491E}: DhcpNameServer = 82.212.62.62 78.42.43.62
O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\Datamngr\datamngr.dll) - C:\PROGRA~1\SEARCH~1\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\Datamngr\IEBHO.dll) - C:\PROGRA~1\SEARCH~1\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\sarah\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\sarah\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2007.01.26 10:41:23 | 000,000,000 | R--D | M] - D:\AutoRun -- [ UDF ]
O32 - AutoRun File - [2007.01.26 10:36:30 | 000,700,416 | R--- | M] (Electronic Arts Inc.) - D:\AutoRun.exe -- [ UDF ]
O32 - AutoRun File - [2007.01.26 10:40:58 | 000,000,149 | R--- | M] () - D:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2007.01.26 09:06:20 | 000,651,264 | R--- | M] (Electronic Arts Inc.) - D:\AutoRunGUI.dll -- [ UDF ]
O33 - MountPoints2\{00201398-8620-11e0-a05d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{00201398-8620-11e0-a05d-806e6f6e6963}\Shell\AutoRun\command - "" = D:\AutoRun.exe -- [2007.01.26 10:36:30 | 000,700,416 | R--- | M] (Electronic Arts Inc.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012.07.21 20:27:11 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\sarah\Desktop\OTL.exe
[2012.07.20 19:24:43 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2012.07.20 19:24:09 | 000,000,000 | ---D | C] -- C:\Users\sarah\Documents\Simply Super Software
[2012.07.20 19:24:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2012.07.20 19:04:24 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2012.07.20 19:01:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.07.17 18:33:21 | 000,000,000 | ---D | C] -- C:\Users\sarah\AppData\Roaming\Malwarebytes
[2012.07.17 18:33:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.17 18:33:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.17 18:33:13 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.07.17 18:33:13 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.07.16 18:08:18 | 000,000,000 | ---D | C] -- C:\Users\sarah\AppData\Local\Macromedia
[2012.07.15 21:14:45 | 000,107,888 | ---- | C] (Sony DADC Austria AG.) -- C:\Windows\System32\CmdLineExt.dll
[2012.07.15 21:14:45 | 000,000,000 | RH-D | C] -- C:\Users\sarah\AppData\Roaming\SecuROM
[2012.07.15 00:50:19 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\EA Games
[2012.07.14 22:41:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
[2012.07.14 22:39:43 | 000,000,000 | ---D | C] -- C:\Users\sarah\Documents\EA Games
[2012.07.04 13:51:55 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
[2012.07.03 23:23:18 | 000,000,000 | ---D | C] -- C:\Users\sarah\AppData\Local\Ilivid Player
[2012.07.03 23:22:37 | 000,000,000 | ---D | C] -- C:\Program Files\iLivid
[2012.07.03 23:21:19 | 000,000,000 | ---D | C] -- C:\Program Files\Searchqu Toolbar
[2012.07.02 17:48:26 | 000,000,000 | ---D | C] -- C:\Users\sarah\AppData\Roaming\.minecraft
[2012.07.02 17:40:27 | 000,000,000 | ---D | C] -- C:\Users\sarah\AppData\Roaming\.Nitrous

========== Files - Modified Within 30 Days ==========

File not found -- C:\Windows\System32\
[2012.07.21 20:32:34 | 000,000,000 | ---- | M] () -- C:\Users\sarah\defogger_reenable
[2012.07.21 20:27:13 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\sarah\Desktop\OTL.exe
[2012.07.21 20:25:46 | 000,050,477 | ---- | M] () -- C:\Users\sarah\Desktop\Defogger.exe
[2012.07.21 19:59:41 | 000,001,138 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2778025260-2901813310-1566513995-1000UA.job
[2012.07.21 19:59:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.21 19:54:37 | 000,008,704 | ---- | M] () -- C:\Users\sarah\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.07.21 19:44:42 | 000,003,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.21 19:44:42 | 000,003,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.21 17:44:55 | 000,105,719 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2012.07.21 17:44:55 | 000,105,719 | ---- | M] () -- C:\ProgramData\nvModes.001
[2012.07.21 17:44:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.21 17:44:35 | 3757,367,296 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.20 20:00:27 | 000,002,708 | ---- | M] () -- C:\Users\sarah\.recently-used.xbel
[2012.07.20 19:51:11 | 000,652,528 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.07.20 19:51:11 | 000,607,406 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.07.20 19:51:11 | 000,134,766 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.07.20 19:51:11 | 000,113,694 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.07.20 19:09:23 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.07.18 23:09:27 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2778025260-2901813310-1566513995-1000Core.job
[2012.07.17 18:55:59 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.07.15 21:14:45 | 000,107,888 | ---- | M] (Sony DADC Austria AG.) -- C:\Windows\System32\CmdLineExt.dll
[2012.07.15 21:12:18 | 000,002,103 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims™ 2 Glamour-Accessoires.lnk
[2012.07.15 21:08:37 | 000,002,155 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims™ 2 Teen Style-Accessoires.lnk
[2012.07.15 21:03:20 | 000,002,085 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims™ 2 Vier Jahreszeiten.lnk
[2012.07.15 20:59:36 | 000,002,013 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims™ 2 Haustiere.lnk
[2012.07.15 20:53:16 | 000,002,013 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims 2 Nightlife.lnk
[2012.07.14 22:41:14 | 000,001,898 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims 2.lnk
[2012.07.13 23:55:45 | 000,257,592 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.07.02 17:37:10 | 000,278,561 | ---- | M] () -- C:\Users\sarah\Desktop\Minecraft.exe

========== Files Created - No Company Name ==========

File not found -- C:\Windows\System32\
[2012.07.21 20:32:34 | 000,000,000 | ---- | C] () -- C:\Users\sarah\defogger_reenable
[2012.07.21 20:25:46 | 000,050,477 | ---- | C] () -- C:\Users\sarah\Desktop\Defogger.exe
[2012.07.20 20:00:27 | 000,002,708 | ---- | C] () -- C:\Users\sarah\.recently-used.xbel
[2012.07.20 19:01:39 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.07.17 19:00:30 | 000,013,312 | ---- | C] () -- C:\Windows\Installer\{25089251-7a80-c313-294e-90f4e8342035}\U\80000000.@
[2012.07.17 18:33:14 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.07.16 17:43:04 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.15 21:12:18 | 000,002,103 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims™ 2 Glamour-Accessoires.lnk
[2012.07.15 21:08:37 | 000,002,155 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims™ 2 Teen Style-Accessoires.lnk
[2012.07.15 21:03:20 | 000,002,085 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims™ 2 Vier Jahreszeiten.lnk
[2012.07.15 20:59:36 | 000,002,013 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims™ 2 Haustiere.lnk
[2012.07.15 20:53:16 | 000,002,013 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims 2 Nightlife.lnk
[2012.07.14 22:41:14 | 000,001,898 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims 2.lnk
[2012.07.02 17:37:09 | 000,278,561 | ---- | C] () -- C:\Users\sarah\Desktop\Minecraft.exe
[2012.06.01 17:27:12 | 000,000,100 | ---- | C] () -- C:\Windows\Lexstat.ini
[2012.06.01 17:25:03 | 001,224,704 | ---- | C] ( ) -- C:\Windows\System32\lxczserv.dll
[2012.06.01 17:25:03 | 000,991,232 | ---- | C] ( ) -- C:\Windows\System32\lxczusb1.dll
[2012.06.01 17:25:03 | 000,696,320 | ---- | C] ( ) -- C:\Windows\System32\lxczhbn3.dll
[2012.06.01 17:25:03 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxczcomc.dll
[2012.06.01 17:25:03 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxczpmui.dll
[2012.06.01 17:25:03 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxczlmpm.dll
[2012.06.01 17:25:03 | 000,537,520 | ---- | C] ( ) -- C:\Windows\System32\lxczcoms.exe
[2012.06.01 17:25:03 | 000,421,888 | ---- | C] ( ) -- C:\Windows\System32\lxczcomm.dll
[2012.06.01 17:25:03 | 000,413,696 | ---- | C] () -- C:\Windows\System32\lxczutil.dll
[2012.06.01 17:25:03 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxczinpa.dll
[2012.06.01 17:25:03 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxcziesc.dll
[2012.06.01 17:25:03 | 000,385,968 | ---- | C] ( ) -- C:\Windows\System32\lxczih.exe
[2012.06.01 17:25:03 | 000,381,872 | ---- | C] ( ) -- C:\Windows\System32\lxczcfg.exe
[2012.06.01 17:25:03 | 000,323,584 | ---- | C] ( ) -- C:\Windows\System32\LXCZhcp.dll
[2012.06.01 17:25:03 | 000,274,432 | ---- | C] () -- C:\Windows\System32\LXCZinst.dll
[2012.06.01 17:25:03 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxczprox.dll
[2012.06.01 17:25:03 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxczpplc.dll
[2012.01.11 16:43:32 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{25089251-7a80-c313-294e-90f4e8342035}\@
[2012.01.11 16:43:32 | 000,002,048 | -HS- | C] () -- C:\Users\sarah\AppData\Local\{25089251-7a80-c313-294e-90f4e8342035}\@
[2011.11.01 19:48:48 | 000,062,976 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.11.01 19:48:35 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011.11.01 19:47:25 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.11.01 18:29:02 | 000,138,056 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011.11.01 18:29:02 | 000,138,056 | ---- | C] () -- C:\Users\sarah\AppData\Roaming\PnkBstrK.sys
[2011.11.01 18:28:51 | 000,189,248 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.11.01 18:28:50 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011.09.04 16:57:29 | 000,000,538 | RHS- | C] () -- C:\Users\sarah\ntuser.pol
[2011.09.02 16:42:52 | 000,008,704 | ---- | C] () -- C:\Users\sarah\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.05.25 17:50:04 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2011.05.25 17:50:03 | 000,652,528 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2011.05.25 17:50:03 | 000,134,766 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2011.05.25 17:50:03 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2011.05.24 22:03:36 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011.05.24 20:29:21 | 000,105,719 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2011.05.24 20:29:21 | 000,105,719 | ---- | C] () -- C:\ProgramData\nvModes.001
[2011.05.24 18:25:34 | 000,000,680 | ---- | C] () -- C:\Users\sarah\AppData\Local\d3d9caps.dat

========== LOP Check ==========

[2012.07.02 17:55:24 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\.minecraft
[2012.07.02 17:40:42 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\.Nitrous
[2011.09.14 20:31:58 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\DVDVideoSoft
[2011.09.14 20:31:02 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.07.20 20:00:27 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\gtk-2.0
[2012.06.07 02:24:59 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\ICQ
[2012.05.06 21:33:46 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\ICQ Search
[2012.01.04 23:11:12 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\LolClient
[2011.08.21 20:32:53 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\OpenOffice.org
[2011.07.04 19:53:51 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\Skip-Bo
[2012.07.21 17:45:13 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\Spotify
[2012.07.18 23:09:27 | 000,001,116 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2778025260-2901813310-1566513995-1000Core.job
[2012.07.21 19:59:41 | 000,001,138 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2778025260-2901813310-1566513995-1000UA.job
[2012.07.21 17:43:44 | 000,032,624 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
         
--- --- ---

Hier der OTL Extra Log:

OTL Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 21.07.2012 20:33:36 - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\sarah\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

3,50 Gb Total Physical Memory | 2,28 Gb Available Physical Memory | 65,10% Memory free
7,23 Gb Paging File | 5,84 Gb Available in Paging File | 80,71% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 153,38 Gb Total Space | 38,20 Gb Free Space | 24,91% Space Free | Partition Type: NTFS
Drive D: | 727,56 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF

Computer Name: SARAH-PC | User Name: sarah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

========== Firewall Settings ==========

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"[verify-U]_AVS_IE_Add-on" = [verify-U]_AVS_IE_Add-on
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0766C1B9-B2DC-46E5-8934-4F3D6B42B1BD}" = ICQ Sparberater
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{4817189D-1785-4627-A33C-39FD90919300}" = Die Sims™ 2 Haustiere
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5C648FDB-0138-4619-B66E-230EF53E8E2C}" = Die Sims™ 2 Teen Style-Accessoires
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = Die Sims 2
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{781B39EC-2E18-41FC-9B00-B84E4FFCA85F}" = ICQ7M
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{83A606F5-BF6F-42ED-9F33-B9F74297CDED}" = Need for Speed(TM) Hot Pursuit
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}" = Die Sims™ 2: Glamour-Accessoires
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.0) - Deutsch
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die*Sims™*3
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = Die Sims™ 2 Vier Jahreszeiten
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = Die Sims 2: Nightlife
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"CCleaner" = CCleaner
"DivX Setup.divx.com" = DivX-Setup
"facemoods" = Facemoods Toolbar
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.9.908
"Guard.Mail.ru" = Guard.ICQ
"ICQToolbar" = ICQ Toolbar
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Plattform-Geräte-Manager
"Lexmark 1200 Series" = Lexmark 1200 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.62.0.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 13.0.1 (x86 de)" = Mozilla Firefox 13.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Searchqu Toolbar" = Searchqu Toolbar
"Skip-Bo: Castaway Caper" = Skip-Bo: Castaway Caper (entfernen)
"Steam App 12220" = Grand Theft Auto: Episodes from Liberty City
"WinGimp-2.0_is1" = GIMP 2.6.12
"WinRAR archiver" = WinRAR 4.01 (32-Bit)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Spotify" = Spotify

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 17.07.2012 19:10:37 | Computer Name = sarah-PC | Source = WinMgmt | ID = 10
Description = 

Error - 18.07.2012 07:21:35 | Computer Name = sarah-PC | Source = WinMgmt | ID = 10
Description = 

Error - 18.07.2012 18:57:33 | Computer Name = sarah-PC | Source = WinMgmt | ID = 10
Description = 

Error - 19.07.2012 01:54:51 | Computer Name = sarah-PC | Source = WinMgmt | ID = 10
Description = 

Error - 20.07.2012 05:55:19 | Computer Name = sarah-PC | Source = WinMgmt | ID = 10
Description = 

Error - 20.07.2012 13:21:48 | Computer Name = sarah-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung tc6.exe, Version 6.0.0.0, Zeitstempel 0x2a425e19,
fehlerhaftes Modul kernel32.dll, Version 6.0.6002.18449, Zeitstempel 0x4da47967,
Ausnahmecode 0xc0000005, Fehleroffset 0x000bfea5, Prozess-ID 0x16b8, Anwendungsstartzeit
01cd669c23936e45.

Error - 20.07.2012 13:21:57 | Computer Name = sarah-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung tc6.exe, Version 6.0.0.0, Zeitstempel 0x2a425e19,
fehlerhaftes Modul kernel32.dll, Version 6.0.6002.18449, Zeitstempel 0x4da47967,
Ausnahmecode 0xc0000005, Fehleroffset 0x000bfea5, Prozess-ID 0x898, Anwendungsstartzeit
01cd669c28045cf0.

Error - 21.07.2012 07:35:19 | Computer Name = sarah-PC | Source = WinMgmt | ID = 10
Description = 

Error - 21.07.2012 10:56:26 | Computer Name = sarah-PC | Source = Application Hang | ID = 1002
Description = Programm firefox.exe, Version 13.0.1.4548 arbeitet nicht mehr mit 
Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet 
"Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über
das Problem zu suchen. Prozess-ID: d14 Anfangszeit: 01cd673518b8515c Zeitpunkt der
Beendigung: 87

Error - 21.07.2012 11:46:21 | Computer Name = sarah-PC | Source = WinMgmt | ID = 10
Description = 

[ System Events ]
Error - 21.07.2012 07:35:19 | Computer Name = sarah-PC | Source = Service Control Manager | ID = 7023
Description = 

Error - 21.07.2012 07:35:19 | Computer Name = sarah-PC | Source = Service Control Manager | ID = 7003
Description = 

Error - 21.07.2012 07:35:19 | Computer Name = sarah-PC | Source = Service Control Manager | ID = 7003
Description = 

Error - 21.07.2012 11:42:31 | Computer Name = sarah-PC | Source = DCOM | ID = 10016
Description = 

Error - 21.07.2012 11:45:25 | Computer Name = sarah-PC | Source = Print | ID = 19
Description = Der Druckspooler konnte den Drucker Apollo P-1200 nicht unter dem 
Namen Apollo P-1200 freigeben. Fehler: 1753. Der Drucker kann nicht von anderen 
Benutzern im Netzwerk verwendet werden.

Error - 21.07.2012 11:46:21 | Computer Name = sarah-PC | Source = Service Control Manager | ID = 7023
Description = 

Error - 21.07.2012 11:46:21 | Computer Name = sarah-PC | Source = Service Control Manager | ID = 7003
Description = 

Error - 21.07.2012 11:46:21 | Computer Name = sarah-PC | Source = Service Control Manager | ID = 7003
Description = 

Error - 21.07.2012 11:46:47 | Computer Name = sarah-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description = 

Error - 21.07.2012 11:55:35 | Computer Name = sarah-PC | Source = DCOM | ID = 10016
Description = 


< End of report >
         
--- --- ---

Hier der GMER Log:
Zitat:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-07-22 02:13:20
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-3 Hitachi_HDS721616PLAT80 rev.P22OA8BA
Running: 67ys2l3q.exe; Driver: C:\Users\sarah\AppData\Local\Temp\fgloypow.sys


---- System - GMER 1.0.15 ----

SSDT 8E356266 ZwCreateSection
SSDT 8E356270 ZwRequestWaitReplyPort
SSDT 8E35626B ZwSetContextThread
SSDT 8E356275 ZwSetSecurityObject
SSDT 8E35627A ZwSystemDebugControl
SSDT 8E356207 ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!KeSetEvent + 215 826AD8D8 4 Bytes [66, 62, 35, 8E]
.text ntkrnlpa.exe!KeSetEvent + 539 826ADBFC 4 Bytes [70, 62, 35, 8E]
.text ntkrnlpa.exe!KeSetEvent + 56D 826ADC30 4 Bytes [6B, 62, 35, 8E] {IMUL ESP, [EDX+0x35], 0x8e}
.text ntkrnlpa.exe!KeSetEvent + 5D1 826ADC94 4 Bytes [75, 62, 35, 8E]
.text ntkrnlpa.exe!KeSetEvent + 619 826ADCDC 4 Bytes [7A, 62, 35, 8E]
.text ...

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3E2341BC-7121-4792-A4CF-EA2D259D491E}@LeaseObtainedTime 1342885482
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3E2341BC-7121-4792-A4CF-EA2D259D491E}@T1 1342928682
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3E2341BC-7121-4792-A4CF-EA2D259D491E}@T2 1342961082
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3E2341BC-7121-4792-A4CF-EA2D259D491E}@LeaseTerminatesTime 1342971882

---- EOF - GMER 1.0.15 ----
Vllt könnte mal einer drüber schauen und mir sagen ob da was mit dem Internet zusammen hängt?
In Avira komm ich seit dem ich Defrogger benutzt habe nicht mehr in das AviraCenter um zu schauen welche TR/Viren in Quarantäne sind.

MfG

Alt 22.07.2012, 10:57   #2
Chris4You
 
Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht - Standard

Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht



Hi,

Reste eines Rootkits, das Sicherheitscenter ist ausgeschaltet...

OTL:
  • Doppelklick auf die OTL.exe, um das Programm auszuführen.
  • Vista/Win7-User bitte per Rechtsklick und "Ausführen als Administrator" starten.
  • Kopiere den Inhalt der folgenden Codebox komplett in die OTL-Box unter "Custom Scan/Fixes"

Code:
ATTFilter
:OTL
[2012.01.11 16:43:32 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{25089251-7a80-c313-294e-90f4e8342035}\@
[2012.01.11 16:43:32 | 000,002,048 | -HS- | C] () -- C:\Users\sarah\AppData\Local\{25089251-7a80-c313-294e-90f4e8342035}\@

:REG
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = dword:0x01

:Commands
[purity]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
         
  • Den roten Run Fixes! Button anklicken.
  • Bitte alles aus dem Ergebnisfenster (Results) herauskopieren.
  • Eine Kopie eines OTL-Fix-Logs wird in einer Textdatei in folgendem Ordner gespeichert:
  • %systemroot%\_OTL

TDSS-Killer
Download und Anweisung unter: Wie werden Schadprogramme der Familie Rootkit.Win32.TDSS bekämpft?
Entpacke alle Dateien in einem eigenen Verzeichnis (z. B: C:\TDSS)!
Aufruf über den Explorer duch Doppelklick auf die TDSSKiller.exe.
Stelle den Killer wir folgt ein:

Dann den Scan starten durch (Start Scan).
Wenn der Scan fertig ist bitte "Report" anwählen (eventuelle Funde erstmal mit Skip übergehen). Es öffnet sich ein Fenster (Report anklicken), den Text abkopieren und hier posten...

Combofix
Lade Combo Fix von http://download.bleepingcomputer.com/sUBs/ComboFix.exe und speichert es auf den Desktop.

Achtung: In einigen wenigen Fällen kann es vorkommen, das der Rechner nicht mehr booten kann und Neuaufgesetzt werden muß!

Alle Fenster schliessen und combofix.exe starten und bestätige die folgende Abfrage mit 1 und drücke Enter.

Der Scan mit Combofix kann einige Zeit in Anspruch nehmen, also habe etwas Geduld. Während des Scans bitte nichts am Rechner unternehmen
Es kann möglich sein, dass der Rechner zwischendurch neu gestartet wird.
Nach Scanende wird ein Report (ComboFix.txt) angezeigt, den bitte kopieren und in deinem Thread einfuegen. Das Log solltest Du unter C:\ComboFix.txt finden...

AdwareCleaner (AdwCleaner)
Wichtig: Alle Befehle bitte als Administrator ausführen! rechte Maustaste auf die Eingabeaufforderung und "als Administrator ausführen" auswählen
Auf der angewählten Anwendung einen Rechtsklick (rechte Maustaste) und "Als Administrator ausführen" wählen!
Poste die Logfiles in Code-Tags
Download über AdwCleaner by Xplode zum Desktop.

Starte AdwCleaner und klicke Search
Nach einiger zeit öffnet ein Logfile (C:\AdwCleaner[xx].txt) poste dessen Inhalt hier ins Forum.

chris
__________________

__________________

Alt 22.07.2012, 16:52   #3
RIpchip
 
Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht - Standard

Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht



Hallo,

bin nur bis zum Punkt "ComboFix" gekommen.
Der Pc startete neu und meinte das die Log Datei nicht gefunden wurde und fragte in eine erstellt werden solle. Habe "Ja" gedrückt aber die Log Datei war komplett leer.
Jetzt öffnet er keine Programme und soweiter mehr..
Fehlermedlung: es wurde versucht, einen Registrierungsschlüssel einem unzulässigem Vorgang zu unterziehen, der zum löschen markiert wurde.

Unter C:/ ist eine Log Datei von Combo fix die ich aber wegen der Fehlermeldung nicht öffnen kann.

MfG

Schuldigung für einen Doppelpost aber der Fehler hat sich durch einen Simplen Neustart behoben
Hier die geforderten Logs:

Hi, hier das was nach dem FIX geöffnet wurde: (%systemroot%\_OTL gibts bei mir nicht)

Zitat:
All processes killed
========== OTL ==========
C:\Windows\Installer\{25089251-7a80-c313-294e-90f4e8342035}\@ moved successfully.
C:\Users\sarah\AppData\Local\{25089251-7a80-c313-294e-90f4e8342035}\@ moved successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"cval" | dword:0x01 /E : value set successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: sarah
->Temp folder emptied: 1373577 bytes
->Temporary Internet Files folder emptied: 18908650 bytes
->Java cache emptied: 14756571 bytes
->FireFox cache emptied: 133624641 bytes
->Flash cache emptied: 2381 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 134094 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 161,00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.54.0 log created on 07222012_155227

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Hier der Report von TDSS:

Zitat:
16:08:10.0702 2132 TDSS rootkit removing tool 2.7.46.0 Jul 16 2012 22:10:11
16:08:10.0767 2132 ============================================================
16:08:10.0767 2132 Current date / time: 2012/07/22 16:08:10.0767
16:08:10.0767 2132 SystemInfo:
16:08:10.0767 2132
16:08:10.0767 2132 OS Version: 6.0.6002 ServicePack: 2.0
16:08:10.0767 2132 Product type: Workstation
16:08:10.0768 2132 ComputerName: SARAH-PC
16:08:10.0768 2132 UserName: sarah
16:08:10.0768 2132 Windows directory: C:\Windows
16:08:10.0768 2132 System windows directory: C:\Windows
16:08:10.0768 2132 Processor architecture: Intel x86
16:08:10.0768 2132 Number of processors: 2
16:08:10.0768 2132 Page size: 0x1000
16:08:10.0768 2132 Boot type: Normal boot
16:08:10.0768 2132 ============================================================
16:08:11.0899 2132 Drive \Device\Harddisk0\DR0 - Size: 0x2658AE0000 (153.39 Gb), SectorSize: 0x200, Cylinders: 0x4E37, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
16:08:11.0900 2132 ============================================================
16:08:11.0900 2132 \Device\Harddisk0\DR0:
16:08:11.0901 2132 MBR partitions:
16:08:11.0901 2132 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x132C4000
16:08:11.0901 2132 ============================================================
16:08:11.0920 2132 C: <-> \Device\Harddisk0\DR0\Partition0
16:08:11.0920 2132 ============================================================
16:08:11.0920 2132 Initialize success
16:08:11.0920 2132 ============================================================
16:08:25.0372 3656 ============================================================
16:08:25.0372 3656 Scan started
16:08:25.0372 3656 Mode: Manual; SigCheck; TDLFS;
16:08:25.0372 3656 ============================================================
16:08:25.0989 3656 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
16:08:26.0085 3656 ACPI - ok
16:08:26.0163 3656 AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
16:08:26.0175 3656 AdobeARMservice - ok
16:08:26.0237 3656 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
16:08:26.0254 3656 AdobeFlashPlayerUpdateSvc - ok
16:08:26.0313 3656 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
16:08:26.0339 3656 adp94xx - ok
16:08:26.0375 3656 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
16:08:26.0397 3656 adpahci - ok
16:08:26.0414 3656 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
16:08:26.0431 3656 adpu160m - ok
16:08:26.0449 3656 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
16:08:26.0465 3656 adpu320 - ok
16:08:26.0512 3656 AeLookupSvc (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll
16:08:26.0567 3656 AeLookupSvc - ok
16:08:26.0630 3656 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
16:08:26.0673 3656 AFD - ok
16:08:26.0735 3656 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
16:08:26.0755 3656 agp440 - ok
16:08:26.0799 3656 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
16:08:26.0815 3656 aic78xx - ok
16:08:26.0835 3656 ALG (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe
16:08:26.0892 3656 ALG - ok
16:08:26.0912 3656 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
16:08:26.0926 3656 aliide - ok
16:08:26.0947 3656 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
16:08:26.0962 3656 amdagp - ok
16:08:26.0977 3656 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
16:08:26.0992 3656 amdide - ok
16:08:27.0013 3656 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
16:08:27.0068 3656 AmdK7 - ok
16:08:27.0105 3656 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
16:08:27.0176 3656 AmdK8 - ok
16:08:27.0315 3656 AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files\Avira\AntiVir Desktop\sched.exe
16:08:27.0336 3656 AntiVirSchedulerService - ok
16:08:27.0349 3656 AntiVirService (a489be6bb0aa1ff406b488b60542314b) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
16:08:27.0372 3656 AntiVirService - ok
16:08:27.0426 3656 Appinfo (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll
16:08:27.0463 3656 Appinfo - ok
16:08:27.0514 3656 AppMgmt (0fe769cae5855b53c90e23f85e7e89ff) C:\Windows\System32\appmgmts.dll
16:08:27.0565 3656 AppMgmt - ok
16:08:27.0589 3656 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
16:08:27.0604 3656 arc - ok
16:08:27.0644 3656 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
16:08:27.0660 3656 arcsas - ok
16:08:27.0672 3656 AsrCDDrv - ok
16:08:27.0692 3656 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
16:08:27.0744 3656 AsyncMac - ok
16:08:27.0772 3656 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
16:08:27.0787 3656 atapi - ok
16:08:27.0833 3656 AudioEndpointBuilder (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
16:08:27.0874 3656 AudioEndpointBuilder - ok
16:08:27.0879 3656 Audiosrv (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
16:08:27.0905 3656 Audiosrv - ok
16:08:27.0945 3656 avgntflt (d5541f0afb767e85fc412fc609d96a74) C:\Windows\system32\DRIVERS\avgntflt.sys
16:08:27.0973 3656 avgntflt - ok
16:08:28.0020 3656 avipbb (7d967a682d4694df7fa57d63a2db01fe) C:\Windows\system32\DRIVERS\avipbb.sys
16:08:28.0044 3656 avipbb - ok
16:08:28.0054 3656 avkmgr (53e56450da16a1a7f0d002f511113f67) C:\Windows\system32\DRIVERS\avkmgr.sys
16:08:28.0073 3656 avkmgr - ok
16:08:28.0138 3656 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
16:08:28.0182 3656 Beep - ok
16:08:28.0205 3656 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
16:08:28.0253 3656 blbdrive - ok
16:08:28.0305 3656 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
16:08:28.0321 3656 bowser - ok
16:08:28.0384 3656 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
16:08:28.0420 3656 BrFiltLo - ok
16:08:28.0460 3656 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
16:08:28.0507 3656 BrFiltUp - ok
16:08:28.0543 3656 Browser (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll
16:08:28.0609 3656 Browser - ok
16:08:28.0631 3656 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
16:08:28.0702 3656 Brserid - ok
16:08:28.0729 3656 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
16:08:28.0771 3656 BrSerWdm - ok
16:08:28.0810 3656 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
16:08:28.0871 3656 BrUsbMdm - ok
16:08:28.0889 3656 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
16:08:28.0946 3656 BrUsbSer - ok
16:08:28.0992 3656 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
16:08:29.0053 3656 BTHMODEM - ok
16:08:29.0097 3656 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
16:08:29.0145 3656 cdfs - ok
16:08:29.0181 3656 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
16:08:29.0241 3656 cdrom - ok
16:08:29.0287 3656 CertPropSvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
16:08:29.0335 3656 CertPropSvc - ok
16:08:29.0363 3656 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
16:08:29.0401 3656 circlass - ok
16:08:29.0434 3656 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
16:08:29.0453 3656 CLFS - ok
16:08:29.0524 3656 clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:08:29.0537 3656 clr_optimization_v2.0.50727_32 - ok
16:08:29.0597 3656 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:08:29.0611 3656 clr_optimization_v4.0.30319_32 - ok
16:08:29.0644 3656 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
16:08:29.0658 3656 cmdide - ok
16:08:29.0668 3656 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys
16:08:29.0682 3656 Compbatt - ok
16:08:29.0691 3656 COMSysApp - ok
16:08:29.0706 3656 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
16:08:29.0721 3656 crcdisk - ok
16:08:29.0738 3656 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
16:08:29.0786 3656 Crusoe - ok
16:08:29.0858 3656 CryptSvc (75c6a297e364014840b48eccd7525e30) C:\Windows\system32\cryptsvc.dll
16:08:29.0893 3656 CryptSvc - ok
16:08:29.0944 3656 CSC (9bdb2e89be8d0ef37b1f25c3d3fc192c) C:\Windows\system32\drivers\csc.sys
16:08:30.0018 3656 CSC - ok
16:08:30.0091 3656 CscService (0a2095f92f6ae4fe6484d911b0c21e95) C:\Windows\System32\cscsvc.dll
16:08:30.0161 3656 CscService - ok
16:08:30.0250 3656 DcomLaunch (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
16:08:30.0362 3656 DcomLaunch - ok
16:08:30.0429 3656 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
16:08:30.0476 3656 DfsC - ok
16:08:30.0625 3656 DFSR (2cc3dcfb533a1035b13dcab6160ab38b) C:\Windows\system32\DFSR.exe
16:08:31.0077 3656 DFSR - ok
16:08:31.0272 3656 Dhcp (9028559c132146fb75eb7acf384b086a) C:\Windows\System32\dhcpcsvc.dll
16:08:31.0311 3656 Dhcp - ok
16:08:31.0375 3656 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
16:08:31.0390 3656 disk - ok
16:08:31.0422 3656 Dnscache (57d762f6f5974af0da2be88a3349baaa) C:\Windows\System32\dnsrslvr.dll
16:08:31.0454 3656 Dnscache - ok
16:08:31.0483 3656 dot3svc (324fd74686b1ef5e7c19a8af49e748f6) C:\Windows\System32\dot3svc.dll
16:08:31.0520 3656 dot3svc - ok
16:08:31.0558 3656 DPS (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll
16:08:31.0609 3656 DPS - ok
16:08:31.0664 3656 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
16:08:31.0699 3656 drmkaud - ok
16:08:31.0755 3656 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
16:08:31.0785 3656 DXGKrnl - ok
16:08:31.0828 3656 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
16:08:31.0875 3656 E1G60 - ok
16:08:31.0932 3656 EapHost (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll
16:08:31.0975 3656 EapHost - ok
16:08:32.0019 3656 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
16:08:32.0035 3656 Ecache - ok
16:08:32.0114 3656 ehRecvr (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe
16:08:32.0132 3656 ehRecvr - ok
16:08:32.0157 3656 ehSched (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe
16:08:32.0173 3656 ehSched - ok
16:08:32.0180 3656 ehstart (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll
16:08:32.0212 3656 ehstart - ok
16:08:32.0277 3656 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
16:08:32.0300 3656 elxstor - ok
16:08:32.0356 3656 EMDMgmt (4e6b23dfc917ea39306b529b773950f4) C:\Windows\system32\emdmgmt.dll
16:08:32.0399 3656 EMDMgmt - ok
16:08:32.0429 3656 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
16:08:32.0479 3656 ErrDev - ok
16:08:32.0516 3656 EventSystem (67058c46504bc12d821f38cf99b7b28f) C:\Windows\system32\es.dll
16:08:32.0560 3656 EventSystem - ok
16:08:32.0609 3656 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
16:08:32.0655 3656 exfat - ok
16:08:32.0692 3656 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
16:08:32.0733 3656 fastfat - ok
16:08:32.0779 3656 Fax (dfba0f60fa301e5b1bfb1403a93ee23e) C:\Windows\system32\fxssvc.exe
16:08:32.0803 3656 Fax - ok
16:08:32.0849 3656 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
16:08:32.0917 3656 fdc - ok
16:08:32.0937 3656 fdPHost (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll
16:08:32.0984 3656 fdPHost - ok
16:08:32.0998 3656 FDResPub (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll
16:08:33.0043 3656 FDResPub - ok
16:08:33.0073 3656 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
16:08:33.0083 3656 FileInfo - ok
16:08:33.0095 3656 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
16:08:33.0113 3656 Filetrace - ok
16:08:33.0126 3656 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
16:08:33.0163 3656 flpydisk - ok
16:08:33.0210 3656 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
16:08:33.0221 3656 FltMgr - ok
16:08:33.0285 3656 FontCache (8ce364388c8eca59b14b539179276d44) C:\Windows\system32\FntCache.dll
16:08:33.0328 3656 FontCache - ok
16:08:33.0486 3656 FontCache3.0.0.0 (c7fbdd1ed42f82bfa35167a5c9803ea3) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
16:08:33.0496 3656 FontCache3.0.0.0 - ok
16:08:33.0544 3656 Fs_Rec (b972a66758577e0bfd1de0f91aaa27b5) C:\Windows\system32\drivers\Fs_Rec.sys
16:08:33.0578 3656 Fs_Rec - ok
16:08:33.0617 3656 fvevol (fecf4c2e42440a8d132bf94eee3c3fc9) C:\Windows\system32\DRIVERS\fvevol.sys
16:08:33.0630 3656 fvevol - ok
16:08:33.0668 3656 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
16:08:33.0679 3656 gagp30kx - ok
16:08:33.0721 3656 gpsvc (cd5d0aeee35dfd4e986a5aa1500a6e66) C:\Windows\System32\gpsvc.dll
16:08:33.0778 3656 gpsvc - ok
16:08:33.0942 3656 Guard.Mail.ru (e859ca020ed61899f3c74a8d0032d05c) C:\Program Files\Guard-ICQ\GuardICQ.exe
16:08:34.0030 3656 Guard.Mail.ru - ok
16:08:34.0270 3656 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
16:08:34.0295 3656 HdAudAddService - ok
16:08:34.0358 3656 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
16:08:34.0451 3656 HDAudBus - ok
16:08:34.0490 3656 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
16:08:34.0585 3656 HidBth - ok
16:08:34.0594 3656 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
16:08:34.0642 3656 HidIr - ok
16:08:34.0672 3656 hidserv (84067081f3318162797385e11a8f0582) C:\Windows\system32\hidserv.dll
16:08:34.0696 3656 hidserv - ok
16:08:34.0720 3656 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
16:08:34.0748 3656 HidUsb - ok
16:08:34.0783 3656 hkmsvc (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll
16:08:34.0823 3656 hkmsvc - ok
16:08:34.0855 3656 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
16:08:34.0864 3656 HpCISSs - ok
16:08:34.0906 3656 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
16:08:34.0944 3656 HTTP - ok
16:08:34.0972 3656 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
16:08:34.0982 3656 i2omp - ok
16:08:35.0020 3656 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
16:08:35.0060 3656 i8042prt - ok
16:08:35.0101 3656 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
16:08:35.0115 3656 iaStorV - ok
16:08:35.0191 3656 ICQ Service (9ac1e19d77ba038f24e2fab5d95f70d3) C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE
16:08:35.0214 3656 ICQ Service - ok
16:08:35.0343 3656 idsvc (98477b08e61945f974ed9fdc4cb6bdab) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
16:08:35.0378 3656 idsvc - ok
16:08:35.0502 3656 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
16:08:35.0523 3656 iirsp - ok
16:08:35.0571 3656 IKEEXT (9908d8a397b76cd8d31d0d383c5773c9) C:\Windows\System32\ikeext.dll
16:08:35.0641 3656 IKEEXT - ok
16:08:35.0670 3656 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
16:08:35.0692 3656 intelide - ok
16:08:35.0711 3656 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
16:08:35.0756 3656 intelppm - ok
16:08:35.0795 3656 IPBusEnum (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll
16:08:35.0857 3656 IPBusEnum - ok
16:08:35.0880 3656 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:08:35.0910 3656 IpFilterDriver - ok
16:08:35.0914 3656 IpInIp - ok
16:08:35.0960 3656 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
16:08:36.0006 3656 IPMIDRV - ok
16:08:36.0035 3656 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
16:08:36.0084 3656 IPNAT - ok
16:08:36.0105 3656 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
16:08:36.0134 3656 IRENUM - ok
16:08:36.0152 3656 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
16:08:36.0167 3656 isapnp - ok
16:08:36.0196 3656 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
16:08:36.0213 3656 iScsiPrt - ok
16:08:36.0222 3656 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
16:08:36.0234 3656 iteatapi - ok
16:08:36.0244 3656 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
16:08:36.0257 3656 iteraid - ok
16:08:36.0297 3656 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
16:08:36.0317 3656 kbdclass - ok
16:08:36.0336 3656 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
16:08:36.0372 3656 kbdhid - ok
16:08:36.0409 3656 KeyIso (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
16:08:36.0447 3656 KeyIso - ok
16:08:36.0500 3656 KSecDD (4a1445efa932a3baf5bdb02d7131ee20) C:\Windows\system32\Drivers\ksecdd.sys
16:08:36.0524 3656 KSecDD - ok
16:08:36.0600 3656 KtmRm (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll
16:08:36.0639 3656 KtmRm - ok
16:08:36.0673 3656 LanmanServer (1bf5eebfd518dd7298434d8c862f825d) C:\Windows\system32\srvsvc.dll
16:08:36.0708 3656 LanmanServer - ok
16:08:36.0758 3656 LanmanWorkstation (1db69705b695b987082c8baec0c6b34f) C:\Windows\System32\wkssvc.dll
16:08:36.0794 3656 LanmanWorkstation - ok
16:08:36.0827 3656 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
16:08:36.0870 3656 lltdio - ok
16:08:36.0911 3656 lltdsvc (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll
16:08:36.0962 3656 lltdsvc - ok
16:08:36.0988 3656 lmhosts (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll
16:08:37.0039 3656 lmhosts - ok
16:08:37.0057 3656 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
16:08:37.0074 3656 LSI_FC - ok
16:08:37.0088 3656 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
16:08:37.0103 3656 LSI_SAS - ok
16:08:37.0124 3656 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
16:08:37.0134 3656 LSI_SCSI - ok
16:08:37.0172 3656 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
16:08:37.0209 3656 luafv - ok
16:08:37.0237 3656 lxcz_device - ok
16:08:37.0276 3656 MBAMProtector (6dfe7f2e8e8a337263aa5c92a215f161) C:\Windows\system32\drivers\mbam.sys
16:08:37.0285 3656 MBAMProtector - ok
16:08:37.0426 3656 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
16:08:37.0467 3656 MBAMService - ok
16:08:37.0499 3656 Mcx2Svc (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll
16:08:37.0537 3656 Mcx2Svc - ok
16:08:37.0584 3656 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
16:08:37.0595 3656 megasas - ok
16:08:37.0618 3656 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
16:08:37.0637 3656 MegaSR - ok
16:08:37.0665 3656 MMCSS (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
16:08:37.0707 3656 MMCSS - ok
16:08:37.0724 3656 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
16:08:37.0768 3656 Modem - ok
16:08:37.0801 3656 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
16:08:37.0848 3656 monitor - ok
16:08:37.0883 3656 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
16:08:37.0903 3656 mouclass - ok
16:08:37.0909 3656 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
16:08:37.0955 3656 mouhid - ok
16:08:37.0979 3656 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
16:08:37.0994 3656 MountMgr - ok
16:08:38.0083 3656 MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
16:08:38.0096 3656 MozillaMaintenance - ok
16:08:38.0143 3656 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
16:08:38.0159 3656 mpio - ok
16:08:38.0176 3656 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
16:08:38.0198 3656 mpsdrv - ok
16:08:38.0213 3656 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
16:08:38.0226 3656 Mraid35x - ok
16:08:38.0260 3656 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
16:08:38.0296 3656 MRxDAV - ok
16:08:38.0334 3656 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
16:08:38.0367 3656 mrxsmb - ok
16:08:38.0406 3656 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:08:38.0442 3656 mrxsmb10 - ok
16:08:38.0469 3656 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:08:38.0483 3656 mrxsmb20 - ok
16:08:38.0516 3656 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
16:08:38.0530 3656 msahci - ok
16:08:38.0550 3656 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
16:08:38.0564 3656 msdsm - ok
16:08:38.0608 3656 MSDTC (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe
16:08:38.0653 3656 MSDTC - ok
16:08:38.0683 3656 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
16:08:38.0733 3656 Msfs - ok
16:08:38.0763 3656 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
16:08:38.0777 3656 msisadrv - ok
16:08:38.0820 3656 MSiSCSI (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll
16:08:38.0867 3656 MSiSCSI - ok
16:08:38.0871 3656 msiserver - ok
16:08:38.0933 3656 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
16:08:38.0976 3656 MSKSSRV - ok
16:08:39.0002 3656 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
16:08:39.0030 3656 MSPCLOCK - ok
16:08:39.0042 3656 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
16:08:39.0090 3656 MSPQM - ok
16:08:39.0135 3656 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
16:08:39.0153 3656 MsRPC - ok
16:08:39.0169 3656 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
16:08:39.0182 3656 mssmbios - ok
16:08:39.0187 3656 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
16:08:39.0231 3656 MSTEE - ok
16:08:39.0254 3656 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
16:08:39.0269 3656 Mup - ok
16:08:39.0308 3656 napagent (e4eaf0c5c1b41b5c83386cf212ca9584) C:\Windows\system32\qagentRT.dll
16:08:39.0355 3656 napagent - ok
16:08:39.0417 3656 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
16:08:39.0434 3656 NativeWifiP - ok
16:08:39.0522 3656 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
16:08:39.0569 3656 NDIS - ok
16:08:39.0613 3656 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
16:08:39.0650 3656 NdisTapi - ok
16:08:39.0668 3656 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
16:08:39.0713 3656 Ndisuio - ok
16:08:39.0742 3656 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
16:08:39.0766 3656 NdisWan - ok
16:08:39.0772 3656 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
16:08:39.0796 3656 NDProxy - ok
16:08:39.0804 3656 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
16:08:39.0853 3656 NetBIOS - ok
16:08:39.0890 3656 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
16:08:39.0945 3656 netbt - ok
16:08:39.0986 3656 Netlogon (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
16:08:40.0002 3656 Netlogon - ok
16:08:40.0055 3656 Netman (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll
16:08:40.0110 3656 Netman - ok
16:08:40.0138 3656 netprofm (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll
16:08:40.0186 3656 netprofm - ok
16:08:40.0288 3656 NetTcpPortSharing (d6c4e4a39a36029ac0813d476fbd0248) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
16:08:40.0301 3656 NetTcpPortSharing - ok
16:08:40.0341 3656 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
16:08:40.0354 3656 nfrd960 - ok
16:08:40.0392 3656 NlaSvc (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll
16:08:40.0439 3656 NlaSvc - ok
16:08:40.0460 3656 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
16:08:40.0496 3656 Npfs - ok
16:08:40.0533 3656 nsi (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll
16:08:40.0578 3656 nsi - ok
16:08:40.0595 3656 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
16:08:40.0641 3656 nsiproxy - ok
16:08:40.0716 3656 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
16:08:40.0768 3656 Ntfs - ok
16:08:40.0815 3656 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
16:08:40.0868 3656 ntrigdigi - ok
16:08:40.0892 3656 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
16:08:40.0911 3656 Null - ok
16:08:40.0968 3656 NVENETFD (1657f3fbd9061526c14ff37e79306f98) C:\Windows\system32\DRIVERS\nvm60x32.sys
16:08:41.0025 3656 NVENETFD - ok
16:08:41.0712 3656 nvlddmkm (377140a534d013bd661c69f1741de43c) C:\Windows\system32\DRIVERS\nvlddmkm.sys
16:08:42.0115 3656 nvlddmkm - ok
16:08:42.0290 3656 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
16:08:42.0319 3656 nvraid - ok
16:08:42.0332 3656 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
16:08:42.0356 3656 nvstor - ok
16:08:42.0384 3656 nvsvc (4ed813efd77a9b7e57e341cdc1c5cbc4) C:\Windows\system32\nvvsvc.exe
16:08:42.0417 3656 nvsvc - ok
16:08:42.0433 3656 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
16:08:42.0449 3656 nv_agp - ok
16:08:42.0453 3656 NwlnkFlt - ok
16:08:42.0459 3656 NwlnkFwd - ok
16:08:42.0478 3656 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
16:08:42.0543 3656 ohci1394 - ok
16:08:42.0597 3656 p2pimsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
16:08:42.0665 3656 p2pimsvc - ok
16:08:42.0671 3656 p2psvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
16:08:42.0714 3656 p2psvc - ok
16:08:42.0756 3656 Parport (8a79fdf04a73428597e2caf9d0d67850) C:\Windows\system32\DRIVERS\parport.sys
16:08:42.0804 3656 Parport - ok
16:08:42.0834 3656 partmgr (b9c2b89f08670e159f7181891e449cd9) C:\Windows\system32\drivers\partmgr.sys
16:08:42.0843 3656 partmgr - ok
16:08:42.0853 3656 Parvdm (6c580025c81caf3ae9e3617c22cad00e) C:\Windows\system32\DRIVERS\parvdm.sys
16:08:42.0875 3656 Parvdm - ok
16:08:42.0916 3656 PcaSvc (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll
16:08:42.0949 3656 PcaSvc - ok
16:08:42.0985 3656 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
16:08:42.0999 3656 pci - ok
16:08:43.0006 3656 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
16:08:43.0017 3656 pciide - ok
16:08:43.0060 3656 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
16:08:43.0073 3656 pcmcia - ok
16:08:43.0136 3656 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
16:08:43.0217 3656 PEAUTH - ok
16:08:43.0319 3656 pla (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll
16:08:43.0433 3656 pla - ok
16:08:43.0574 3656 PlugPlay (c5e7f8a996ec0a82d508fd9064a5569e) C:\Windows\system32\umpnpmgr.dll
16:08:43.0621 3656 PlugPlay - ok
16:08:43.0673 3656 PnkBstrA (3a2bdd76e7d2a5f40a7174793d1ba794) C:\Windows\system32\PnkBstrA.exe
16:08:43.0694 3656 PnkBstrA - ok
16:08:43.0752 3656 PnkBstrB (27f1be4a53441c9f1f48b9adc145b0a5) C:\Windows\system32\PnkBstrB.exe
16:08:43.0841 3656 PnkBstrB - ok
16:08:43.0886 3656 PNRPAutoReg (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
16:08:43.0909 3656 PNRPAutoReg - ok
16:08:43.0919 3656 PNRPsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
16:08:43.0947 3656 PNRPsvc - ok
16:08:44.0012 3656 PolicyAgent (d0494460421a03cd5225cca0059aa146) C:\Windows\System32\ipsecsvc.dll
16:08:44.0071 3656 PolicyAgent - ok
16:08:44.0192 3656 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
16:08:44.0236 3656 PptpMiniport - ok
16:08:44.0258 3656 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\DRIVERS\processr.sys
16:08:44.0281 3656 Processor - ok
16:08:44.0315 3656 ProfSvc (0508faa222d28835310b7bfca7a77346) C:\Windows\system32\profsvc.dll
16:08:44.0357 3656 ProfSvc - ok
16:08:44.0373 3656 ProtectedStorage (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
16:08:44.0385 3656 ProtectedStorage - ok
16:08:44.0413 3656 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
16:08:44.0446 3656 PSched - ok
16:08:44.0516 3656 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
16:08:44.0552 3656 ql2300 - ok
16:08:44.0603 3656 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
16:08:44.0618 3656 ql40xx - ok
16:08:44.0662 3656 QWAVE (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll
16:08:44.0681 3656 QWAVE - ok
16:08:44.0690 3656 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
16:08:44.0722 3656 QWAVEdrv - ok
16:08:44.0746 3656 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
16:08:44.0790 3656 RasAcd - ok
16:08:44.0812 3656 RasAuto (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll
16:08:44.0857 3656 RasAuto - ok
16:08:44.0891 3656 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
16:08:44.0921 3656 Rasl2tp - ok
16:08:44.0968 3656 RasMan (75d47445d70ca6f9f894b032fbc64fcf) C:\Windows\System32\rasmans.dll
16:08:45.0009 3656 RasMan - ok
16:08:45.0034 3656 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
16:08:45.0071 3656 RasPppoe - ok
16:08:45.0097 3656 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
16:08:45.0137 3656 RasSstp - ok
16:08:45.0165 3656 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
16:08:45.0190 3656 rdbss - ok
16:08:45.0228 3656 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
16:08:45.0257 3656 RDPCDD - ok
16:08:45.0292 3656 rdpdr (943b18305eae3935598a9b4a3d560b4c) C:\Windows\system32\DRIVERS\rdpdr.sys
16:08:45.0333 3656 rdpdr - ok
16:08:45.0338 3656 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
16:08:45.0375 3656 RDPENCDD - ok
16:08:45.0424 3656 RDPWD (c127ebd5afab31524662c48dfceb773a) C:\Windows\system32\drivers\RDPWD.sys
16:08:45.0456 3656 RDPWD - ok
16:08:45.0489 3656 RemoteAccess (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll
16:08:45.0519 3656 RemoteAccess - ok
16:08:45.0552 3656 RemoteRegistry (9e6894ea18daff37b63e1005f83ae4ab) C:\Windows\system32\regsvc.dll
16:08:45.0597 3656 RemoteRegistry - ok
16:08:45.0627 3656 RpcLocator (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe
16:08:45.0662 3656 RpcLocator - ok
16:08:45.0717 3656 RpcSs (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
16:08:45.0750 3656 RpcSs - ok
16:08:45.0792 3656 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
16:08:45.0842 3656 rspndr - ok
16:08:45.0868 3656 SamSs (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
16:08:45.0883 3656 SamSs - ok
16:08:45.0898 3656 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
16:08:45.0912 3656 sbp2port - ok
16:08:45.0932 3656 SCardSvr (77b7a11a0c3d78d3386398fbbea1b632) C:\Windows\System32\SCardSvr.dll
16:08:45.0977 3656 SCardSvr - ok
16:08:46.0039 3656 Schedule (1a58069db21d05eb2ab58ee5753ebe8d) C:\Windows\system32\schedsvc.dll
16:08:46.0104 3656 Schedule - ok
16:08:46.0210 3656 SCPolicySvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
16:08:46.0247 3656 SCPolicySvc - ok
16:08:46.0292 3656 SDRSVC (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll
16:08:46.0344 3656 SDRSVC - ok
16:08:46.0394 3656 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
16:08:46.0489 3656 secdrv - ok
16:08:46.0500 3656 seclogon (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll
16:08:46.0557 3656 seclogon - ok
16:08:46.0573 3656 SENS (a9bbab5759771e523f55563d6cbe140f) C:\Windows\System32\sens.dll
16:08:46.0604 3656 SENS - ok
16:08:46.0648 3656 Serenum (ce9ec966638ef0b10b864ddedf62a099) C:\Windows\system32\DRIVERS\serenum.sys
16:08:46.0685 3656 Serenum - ok
16:08:46.0718 3656 Serial (6d663022db3e7058907784ae14b69898) C:\Windows\system32\DRIVERS\serial.sys
16:08:46.0755 3656 Serial - ok
16:08:46.0777 3656 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
16:08:46.0794 3656 sermouse - ok
16:08:46.0837 3656 SessionEnv (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll
16:08:46.0883 3656 SessionEnv - ok
16:08:46.0916 3656 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
16:08:46.0930 3656 sffdisk - ok
16:08:46.0938 3656 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
16:08:46.0982 3656 sffp_mmc - ok
16:08:46.0986 3656 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
16:08:47.0014 3656 sffp_sd - ok
16:08:47.0032 3656 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
16:08:47.0088 3656 sfloppy - ok
16:08:47.0137 3656 ShellHWDetection (c7230fbee14437716701c15be02c27b8) C:\Windows\System32\shsvcs.dll
16:08:47.0152 3656 ShellHWDetection - ok
16:08:47.0164 3656 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
16:08:47.0176 3656 sisagp - ok
16:08:47.0221 3656 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
16:08:47.0232 3656 SiSRaid2 - ok
16:08:47.0241 3656 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
16:08:47.0254 3656 SiSRaid4 - ok
16:08:47.0417 3656 slsvc (862bb4cbc05d80c5b45be430e5ef872f) C:\Windows\system32\SLsvc.exe
16:08:47.0599 3656 slsvc - ok
16:08:47.0729 3656 SLUINotify (6edc422215cd78aa8a9cde6b30abbd35) C:\Windows\system32\SLUINotify.dll
16:08:47.0753 3656 SLUINotify - ok
16:08:47.0795 3656 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
16:08:47.0834 3656 Smb - ok
16:08:47.0873 3656 SNMPTRAP (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe
16:08:47.0889 3656 SNMPTRAP - ok
16:08:47.0935 3656 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
16:08:47.0952 3656 spldr - ok
16:08:47.0985 3656 Spooler (8554097e5136c3bf9f69fe578a1b35f4) C:\Windows\System32\spoolsv.exe
16:08:48.0002 3656 Spooler - ok
16:08:48.0044 3656 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
16:08:48.0076 3656 srv - ok
16:08:48.0114 3656 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
16:08:48.0150 3656 srv2 - ok
16:08:48.0185 3656 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
16:08:48.0228 3656 srvnet - ok
16:08:48.0272 3656 SSDPSRV (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll
16:08:48.0358 3656 SSDPSRV - ok
16:08:48.0397 3656 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
16:08:48.0412 3656 ssmdrv - ok
16:08:48.0434 3656 SstpSvc (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll
16:08:48.0451 3656 SstpSvc - ok
16:08:48.0518 3656 Steam Client Service - ok
16:08:48.0575 3656 stisvc (5de7d67e49b88f5f07f3e53c4b92a352) C:\Windows\System32\wiaservc.dll
16:08:48.0643 3656 stisvc - ok
16:08:48.0692 3656 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
16:08:48.0712 3656 swenum - ok
16:08:48.0762 3656 swprv (f21fd248040681cca1fb6c9a03aaa93d) C:\Windows\System32\swprv.dll
16:08:48.0810 3656 swprv - ok
16:08:48.0830 3656 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
16:08:48.0843 3656 Symc8xx - ok
16:08:48.0855 3656 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
16:08:48.0868 3656 Sym_hi - ok
16:08:48.0884 3656 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
16:08:48.0898 3656 Sym_u3 - ok
16:08:48.0937 3656 SysMain (9a51b04e9886aa4ee90093586b0ba88d) C:\Windows\system32\sysmain.dll
16:08:48.0972 3656 SysMain - ok
16:08:49.0010 3656 TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll
16:08:49.0028 3656 TabletInputService - ok
16:08:49.0065 3656 TapiSrv (d7673e4b38ce21ee54c59eeeb65e2483) C:\Windows\System32\tapisrv.dll
16:08:49.0091 3656 TapiSrv - ok
16:08:49.0121 3656 TBS (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll
16:08:49.0152 3656 TBS - ok
16:08:49.0233 3656 Tcpip (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\drivers\tcpip.sys
16:08:49.0308 3656 Tcpip - ok
16:08:49.0325 3656 Tcpip6 (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\DRIVERS\tcpip.sys
16:08:49.0387 3656 Tcpip6 - ok
16:08:49.0420 3656 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
16:08:49.0461 3656 tcpipreg - ok
16:08:49.0496 3656 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
16:08:49.0537 3656 TDPIPE - ok
16:08:49.0549 3656 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
16:08:49.0578 3656 TDTCP - ok
16:08:49.0605 3656 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
16:08:49.0648 3656 tdx - ok
16:08:49.0679 3656 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
16:08:49.0701 3656 TermDD - ok
16:08:49.0732 3656 TermService (bb95da09bef6e7a131bff3ba5032090d) C:\Windows\System32\termsrv.dll
16:08:49.0784 3656 TermService - ok
16:08:49.0815 3656 Themes (c7230fbee14437716701c15be02c27b8) C:\Windows\system32\shsvcs.dll
16:08:49.0835 3656 Themes - ok
16:08:49.0878 3656 THREADORDER (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
16:08:49.0908 3656 THREADORDER - ok
16:08:49.0952 3656 TrkWks (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll
16:08:49.0983 3656 TrkWks - ok
16:08:50.0032 3656 TrustedInstaller (97d9d6a04e3ad9b6c626b9931db78dba) C:\Windows\servicing\TrustedInstaller.exe
16:08:50.0060 3656 TrustedInstaller - ok
16:08:50.0105 3656 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
16:08:50.0163 3656 tssecsrv - ok
16:08:50.0188 3656 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
16:08:50.0220 3656 tunmp - ok
16:08:50.0261 3656 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
16:08:50.0285 3656 tunnel - ok
16:08:50.0310 3656 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
16:08:50.0324 3656 uagp35 - ok
16:08:50.0362 3656 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
16:08:50.0387 3656 udfs - ok
16:08:50.0438 3656 UI0Detect (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe
16:08:50.0469 3656 UI0Detect - ok
16:08:50.0507 3656 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
16:08:50.0521 3656 uliagpkx - ok
16:08:50.0548 3656 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
16:08:50.0565 3656 uliahci - ok
16:08:50.0587 3656 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
16:08:50.0602 3656 UlSata - ok
16:08:50.0619 3656 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
16:08:50.0633 3656 ulsata2 - ok
16:08:50.0649 3656 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
16:08:50.0696 3656 umbus - ok
16:08:50.0730 3656 UmRdpService (8a66360f38f81e960e2367b428cbd5d9) C:\Windows\System32\umrdp.dll
16:08:50.0766 3656 UmRdpService - ok
16:08:50.0801 3656 upnphost (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll
16:08:50.0852 3656 upnphost - ok
16:08:50.0895 3656 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
16:08:50.0919 3656 usbccgp - ok
16:08:50.0951 3656 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
16:08:51.0015 3656 usbcir - ok
16:08:51.0101 3656 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
16:08:51.0122 3656 usbehci - ok
16:08:51.0157 3656 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
16:08:51.0182 3656 usbhub - ok
16:08:51.0257 3656 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
16:08:51.0279 3656 usbohci - ok
16:08:51.0318 3656 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
16:08:51.0348 3656 usbprint - ok
16:08:51.0391 3656 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
16:08:51.0426 3656 usbscan - ok
16:08:51.0452 3656 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:08:51.0473 3656 USBSTOR - ok
16:08:51.0510 3656 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
16:08:51.0532 3656 usbuhci - ok
16:08:51.0560 3656 UxSms (1509e705f3ac1d474c92454a5c2dd81f) C:\Windows\System32\uxsms.dll
16:08:51.0610 3656 UxSms - ok
16:08:51.0654 3656 vds (cd88d1b7776dc17a119049742ec07eb4) C:\Windows\System32\vds.exe
16:08:51.0709 3656 vds - ok
16:08:51.0732 3656 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
16:08:51.0762 3656 vga - ok
16:08:51.0775 3656 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
16:08:51.0805 3656 VgaSave - ok
16:08:51.0853 3656 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
16:08:51.0868 3656 viaagp - ok
16:08:51.0884 3656 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
16:08:51.0933 3656 ViaC7 - ok
16:08:52.0025 3656 VIAHdAudAddService (4b1c025d194bbb41b1d7e86b54d88dc1) C:\Windows\system32\drivers\viahduaa.sys
16:08:52.0087 3656 VIAHdAudAddService - ok
16:08:52.0119 3656 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
16:08:52.0133 3656 viaide - ok
16:08:52.0151 3656 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
16:08:52.0166 3656 volmgr - ok
16:08:52.0203 3656 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
16:08:52.0223 3656 volmgrx - ok
16:08:52.0243 3656 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
16:08:52.0262 3656 volsnap - ok
16:08:52.0283 3656 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
16:08:52.0300 3656 vsmraid - ok
16:08:52.0357 3656 VSS (db3d19f850c6eb32bdcb9bc0836acddb) C:\Windows\system32\vssvc.exe
16:08:52.0428 3656 VSS - ok
16:08:52.0465 3656 W32Time (96ea68b9eb310a69c25ebb0282b2b9de) C:\Windows\system32\w32time.dll
16:08:52.0513 3656 W32Time - ok
16:08:52.0585 3656 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
16:08:52.0649 3656 WacomPen - ok
16:08:52.0675 3656 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
16:08:52.0698 3656 Wanarp - ok
16:08:52.0702 3656 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
16:08:52.0725 3656 Wanarpv6 - ok
16:08:52.0787 3656 wbengine (20b23332885dfb93fe0185362ee811e9) C:\Windows\system32\wbengine.exe
16:08:52.0873 3656 wbengine - ok
16:08:52.0957 3656 wcncsvc (a3cd60fd826381b49f03832590e069af) C:\Windows\System32\wcncsvc.dll
16:08:53.0023 3656 wcncsvc - ok
16:08:53.0072 3656 WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll
16:08:53.0120 3656 WcsPlugInService - ok
16:08:53.0189 3656 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
16:08:53.0203 3656 Wd - ok
16:08:53.0236 3656 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
16:08:53.0262 3656 Wdf01000 - ok
16:08:53.0280 3656 WdiServiceHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
16:08:53.0328 3656 WdiServiceHost - ok
16:08:53.0333 3656 WdiSystemHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
16:08:53.0364 3656 WdiSystemHost - ok
16:08:53.0408 3656 WebClient (04c37d8107320312fbae09926103d5e2) C:\Windows\System32\webclnt.dll
16:08:53.0448 3656 WebClient - ok
16:08:53.0484 3656 Wecsvc (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll
16:08:53.0520 3656 Wecsvc - ok
16:08:53.0548 3656 wercplsupport (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll
16:08:53.0588 3656 wercplsupport - ok
16:08:53.0626 3656 WerSvc (32b88481d3b326da6deb07b1d03481e7) C:\Windows\System32\WerSvc.dll
16:08:53.0651 3656 WerSvc - ok
16:08:53.0659 3656 WinHttpAutoProxySvc - ok
16:08:53.0728 3656 Winmgmt (6b2a1d0e80110e3d04e6863c6e62fd8a) C:\Windows\system32\wbem\WMIsvc.dll
16:08:53.0752 3656 Winmgmt - ok
16:08:53.0829 3656 WinRM (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll
16:08:53.0880 3656 WinRM - ok
16:08:53.0940 3656 Wlansvc (c008405e4feeb069e30da1d823910234) C:\Windows\System32\wlansvc.dll
16:08:53.0990 3656 Wlansvc - ok
16:08:54.0094 3656 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
16:08:54.0154 3656 WmiAcpi - ok
16:08:54.0219 3656 wmiApSrv (43be3875207dcb62a85c8c49970b66cc) C:\Windows\system32\wbem\WmiApSrv.exe
16:08:54.0263 3656 wmiApSrv - ok
16:08:54.0394 3656 WMPNetworkSvc (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe
16:08:54.0460 3656 WMPNetworkSvc - ok
16:08:54.0507 3656 WPCSvc (cfc5a04558f5070cee3e3a7809f3ff52) C:\Windows\System32\wpcsvc.dll
16:08:54.0558 3656 WPCSvc - ok
16:08:54.0621 3656 WPDBusEnum (801fbdb89d472b3c467eb112a0fc9246) C:\Windows\system32\wpdbusenum.dll
16:08:54.0638 3656 WPDBusEnum - ok
16:08:54.0709 3656 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
16:08:54.0744 3656 WpdUsb - ok
16:08:54.0884 3656 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
16:08:54.0940 3656 WPFFontCache_v0400 - ok
16:08:54.0981 3656 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
16:08:55.0034 3656 ws2ifsl - ok
16:08:55.0040 3656 WSearch - ok
16:08:55.0064 3656 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
16:08:55.0122 3656 WUDFRd - ok
16:08:55.0165 3656 wudfsvc (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll
16:08:55.0196 3656 wudfsvc - ok
16:08:55.0220 3656 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
16:08:55.0399 3656 \Device\Harddisk0\DR0 - ok
16:08:55.0404 3656 Boot (0x1200) (1d0fce0bb2f401ce42290cf23c895435) \Device\Harddisk0\DR0\Partition0
16:08:55.0407 3656 \Device\Harddisk0\DR0\Partition0 - ok
16:08:55.0409 3656 ============================================================
16:08:55.0409 3656 Scan finished
16:08:55.0409 3656 ============================================================
16:08:55.0427 1780 Detected object count: 0
16:08:55.0427 1780 Actual detected object count: 0

Hier der Log von ComboFix:

Combofix Logfile:
Code:
ATTFilter
ComboFix 12-07-21.01 - sarah 22.07.2012  16:27:58.1.2 - x86
Microsoft® Windows Vista™ Ultimate   6.0.6002.2.1252.49.1033.18.3582.2510 [GMT 2:00]
ausgeführt von:: c:\users\sarah\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\facemoods.com
c:\program files\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
c:\program files\facemoods.com\facemoods\1.4.17.11\facemoods.crx
c:\program files\facemoods.com\facemoods\1.4.17.11\facemoods.png
c:\program files\facemoods.com\facemoods\1.4.17.11\facemoodsApp.dll
c:\program files\facemoods.com\facemoods\1.4.17.11\facemoodsEng.dll
c:\program files\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe
c:\program files\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
c:\program files\facemoods.com\facemoods\1.4.17.11\uninstall.exe
c:\windows\system32\ 
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-06-22 bis 2012-07-22  ))))))))))))))))))))))))))))))
.
.
2012-07-22 14:33 . 2012-07-22 14:33	--------	d-----w-	c:\users\Default\AppData\Local\temp
2012-07-22 14:07 . 2012-07-22 14:07	--------	d-----w-	C:\TDSS
2012-07-22 13:52 . 2012-07-22 13:52	--------	d-----w-	C:\_OTL
2012-07-20 17:24 . 2012-07-20 17:24	--------	d-----w-	c:\programdata\Simply Super Software
2012-07-17 16:33 . 2012-07-17 16:33	--------	d-----w-	c:\users\sarah\AppData\Roaming\Malwarebytes
2012-07-17 16:33 . 2012-07-17 16:33	--------	d-----w-	c:\programdata\Malwarebytes
2012-07-17 16:33 . 2012-07-17 16:55	--------	d-----w-	c:\program files\Malwarebytes' Anti-Malware
2012-07-17 16:33 . 2012-07-03 11:46	22344	----a-w-	c:\windows\system32\drivers\mbam.sys
2012-07-16 16:08 . 2012-07-16 16:08	--------	d-----w-	c:\users\sarah\AppData\Local\Macromedia
2012-07-15 19:14 . 2012-07-15 19:14	107888	----a-w-	c:\windows\system32\CmdLineExt.dll
2012-07-15 19:14 . 2012-07-15 19:14	--------	d--h--r-	c:\users\sarah\AppData\Roaming\SecuROM
2012-07-13 11:47 . 2012-06-13 13:40	2047488	----a-w-	c:\windows\system32\win32k.sys
2012-07-12 12:42 . 2012-06-05 16:47	708608	----a-w-	c:\program files\Common Files\System\ado\msado15.dll
2012-07-12 12:42 . 2012-06-05 16:47	1401856	----a-w-	c:\windows\system32\msxml6.dll
2012-07-12 12:42 . 2012-06-05 16:47	1248768	----a-w-	c:\windows\system32\msxml3.dll
2012-07-12 12:42 . 2012-06-04 15:26	440704	----a-w-	c:\windows\system32\drivers\ksecdd.sys
2012-07-12 12:42 . 2012-06-02 00:04	278528	----a-w-	c:\windows\system32\schannel.dll
2012-07-12 12:42 . 2012-06-02 00:03	204288	----a-w-	c:\windows\system32\ncrypt.dll
2012-07-04 11:51 . 2012-07-04 11:51	--------	d-----w-	c:\programdata\boost_interprocess
2012-07-03 21:23 . 2012-07-03 21:23	--------	d-----w-	c:\users\sarah\AppData\Local\Ilivid Player
2012-07-03 21:22 . 2012-07-20 17:10	--------	d-----w-	c:\program files\iLivid
2012-07-03 21:21 . 2012-07-03 21:26	--------	d-----w-	c:\program files\Searchqu Toolbar
2012-07-02 15:48 . 2012-07-02 15:55	--------	d-----w-	c:\users\sarah\AppData\Roaming\.minecraft
2012-07-02 15:40 . 2012-07-02 15:40	--------	d-----w-	c:\users\sarah\AppData\Roaming\.Nitrous
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-16 15:59 . 2012-05-07 13:27	426184	----a-w-	c:\windows\system32\FlashPlayerApp.exe
2012-07-16 15:59 . 2011-06-02 12:24	70344	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-16 15:43 . 2011-11-01 17:48	279552	----a-w-	c:\windows\system32\services.exe
2012-06-02 22:19 . 2012-06-21 10:25	53784	----a-w-	c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-21 10:25	45080	----a-w-	c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-21 10:25	35864	----a-w-	c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-21 10:25	577048	----a-w-	c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-21 10:25	1933848	----a-w-	c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-21 10:25	2422272	----a-w-	c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-21 10:25	88576	----a-w-	c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-21 10:25	171904	----a-w-	c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-06-21 10:25	33792	----a-w-	c:\windows\system32\wuapp.exe
2012-05-08 16:40 . 2012-06-01 11:06	6737808	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{07B34BDB-A0E8-4BD5-8190-6D6233015301}\mpengine.dll
2012-05-01 14:03 . 2012-06-14 05:09	180736	----a-w-	c:\windows\system32\drivers\rdpwd.sys
2012-04-27 08:20 . 2012-06-04 16:01	137928	----a-w-	c:\windows\system32\drivers\avipbb.sys
2012-04-24 22:32 . 2012-06-04 16:01	83392	----a-w-	c:\windows\system32\drivers\avgntflt.sys
2012-04-23 16:00 . 2012-06-14 05:09	984064	----a-w-	c:\windows\system32\crypt32.dll
2012-04-23 16:00 . 2012-06-14 05:09	98304	----a-w-	c:\windows\system32\cryptnet.dll
2012-04-23 16:00 . 2012-06-14 05:09	133120	----a-w-	c:\windows\system32\cryptsvc.dll
2012-06-18 11:59 . 2011-07-04 14:38	85472	----a-w-	c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0766C1B9-B2DC-46E5-8934-4F3D6B42B1BD}]
2011-12-28 12:21	128064	----a-w-	c:\program files\icq\Internet Explorer\icq.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spotify"="c:\users\sarah\AppData\Roaming\Spotify\Spotify.exe" [2012-07-03 7609560]
"Facebook Update"="c:\users\sarah\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096]
"Spotify Web Helper"="c:\users\sarah\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-07-03 1192664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2009-12-04 1728512]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Guard.Mail.ru.gui"="c:\program files\Guard-ICQ\GuardICQ.exe" [2012-05-06 1564368]
"lxczbmgr.exe"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2009-04-27 74408]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-05-01 348624]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\SEARCH~1\Datamngr\datamngr.dll c:\progra~1\SEARCH~1\Datamngr\IEBHO.dll
.
[HKLM\~\startupfolder\C:^Users^sarah^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]
path=c:\users\sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
backup=c:\windows\pss\OpenOffice.org 3.3.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2012-05-06 19:33	127040	----a-w-	c:\program files\ICQ7M\ICQ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-10-11 17:09	1242448	----a-w-	c:\program files\Steam\Steam.exe
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation	REG_MULTI_SZ   	FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2012-07-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-07 15:59]
.
2012-07-21 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2778025260-2901813310-1566513995-1000Core.job
- c:\users\sarah\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-07 20:54]
.
2012-07-21 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2778025260-2901813310-1566513995-1000UA.job
- c:\users\sarah\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-07 20:54]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.searchnu.com/406
IE: Free YouTube to MP3 Converter - c:\users\sarah\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files\ICQ7M\ICQ.exe
TCP: DhcpNameServer = 82.212.62.62 78.42.43.62
FF - ProfilePath - c:\users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.searchcanvas.com/web?ot=7&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=334&systemid=406&sr=0&q=
FF - prefs.js: network.proxy.http - 193.84.22.97
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.type - 0
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-10 - (no file)
AddRemove-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.11\uninstall.exe
.
.
.
**************************************************************************
Scanne versteckte Prozesse... 
.
Scanne versteckte Autostarteinträge... 
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  HDAudDeck = c:\program files\VIA\VIAudioi\VDeck\VDeck.exe -r??????????????????????????????????????????????? 
.
Scanne versteckte Dateien... 
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 
.
**************************************************************************
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\AUDIODG.EXE
c:\windows\system32\nvvsvc.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\progra~1\ICQ6TO~1\ICQSER~1.EXE
c:\windows\system32\lxczcoms.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conime.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files\Lexmark 1200 Series\lxczbmon.exe
c:\windows\system32\vssvc.exe
c:\program files\avira\antivir desktop\ipmGui.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-07-22  16:44:56 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-07-22 14:43
.
Vor Suchlauf: 10 Verzeichnis(se), 40.750.092.288 Bytes frei
Nach Suchlauf: 13 Verzeichnis(se), 40.254.488.576 Bytes frei
.
- - End Of File - - 6A7533BD383421DAA06F5E82DF4BFD6E[/QUOTE]
         
--- --- ---


Hier der Log von AdwCleaner:

Zitat:
# AdwCleaner v1.703 - Logfile created 07/22/2012 at 18:05:39
# Updated 20/07/2012 by Xplode
# Operating system : Windows Vista (TM) Ultimate Service Pack 2 (32 bits)
# User : sarah - SARAH-PC
# Running from : C:\Users\sarah\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Users\sarah\AppData\Local\Ilivid Player
Folder Found : C:\Users\sarah\AppData\LocalLow\boost_interprocess
Folder Found : C:\Users\sarah\AppData\LocalLow\facemoods.com
Folder Found : C:\Users\sarah\AppData\LocalLow\Searchqutoolbar
Folder Found : C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\Searchqutoolbar
Folder Found : C:\ProgramData\boost_interprocess
Folder Found : C:\Program Files\Ilivid
Folder Found : C:\Program Files\Searchqu Toolbar
File Found : C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\searchplugins\Search_Results.xml
File Found : C:\Program Files\Mozilla FireFox\searchplugins\Search_Results.xml

***** [Registry] *****

Key Found : HKCU\Software\AppDataLow\Software\ShopperReports3
Key Found : HKCU\Software\DataMngr_Toolbar
Key Found : HKCU\Software\facemoods.com
Key Found : HKCU\Software\ilivid
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Found : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc
Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1
Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl
Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1
Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore
Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1
Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
Key Found : HKLM\SOFTWARE\facemoods.com
Key Found : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37}
Key Found : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}
Key Found : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}
Key Found : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.searchnu.com/406

-\\ Mozilla Firefox v13.0.1 (de)

Profile name : default
File : C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\prefs.js

Found : user_pref("browser.search.defaultenginename", "Search Results");
Found : user_pref("browser.search.order.1", "Search Results");
Found : user_pref("extensions.facemoods._xpiupdate", true);
Found : user_pref("extensions.facemoods.aflt", "_#wbst");
Found : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.3");
Found : user_pref("extensions.facemoods.id", "_#1bd7121b4fd743e4a037d7d22f19cf19");
Found : user_pref("extensions.facemoods.instlDay", "_#15240");
Found : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com");
Found : user_pref("extensions.facemoods.sid", "_#1bd7121b4fd743e4a037d7d22f19cf19");
Found : user_pref("extensions.facemoods.uninst", true);
Found : user_pref("extensions.facemoods.update", "_#v1.4.0");
Found : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5");

*************************

AdwCleaner[R1].txt - [6333 octets] - [22/07/2012 18:05:39]

########## EOF - C:\AdwCleaner[R1].txt - [6461 octets] ##########
MfG
__________________

Alt 22.07.2012, 19:57   #4
Chris4You
 
Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht - Standard

Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht



Hi,

sieht recht ordentlich aus...

AdwareCleaner
Schliesse alle offenstehende Fenster und starte AdwCleaner (Win7/Vista: Als Administrator ausführen)
  • Klicke Delete
  • Klicke bei:AdwCleaner-Information OK
  • Klicke bei:AdwCleaner-Restart Required OK
Alle Icons werden kurzzeitig verschwinden...
Dein Rechner wird neu gestartet und es öffnet sich ein Logfile (C:\AdwCleaner[xx].txt), poste dessen Inhalt hier ins Forum.

Erstelle und poste ein neues OTL-Log...

chris
__________________
Don't bring me down
Vor dem posten beachten!
Spenden
(Wer spenden will, kann sich gerne melden )

Alt 22.07.2012, 20:36   #5
RIpchip
 
Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht - Standard

Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht



Hey, hier der AdwareCleaner Log nach dem "Delete":

Zitat:
# AdwCleaner v1.703 - Logfile created 07/22/2012 at 20:24:12
# Updated 20/07/2012 by Xplode
# Operating system : Windows Vista (TM) Ultimate Service Pack 2 (32 bits)
# User : sarah - SARAH-PC
# Running from : C:\Users\sarah\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\sarah\AppData\Local\Ilivid Player
Folder Deleted : C:\Users\sarah\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\sarah\AppData\LocalLow\facemoods.com
Folder Deleted : C:\Users\sarah\AppData\LocalLow\Searchqutoolbar
Folder Deleted : C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\Searchqutoolbar
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\Program Files\Ilivid
Folder Deleted : C:\Program Files\Searchqu Toolbar
File Deleted : C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\searchplugins\Search_Results.xml
File Deleted : C:\Program Files\Mozilla FireFox\searchplugins\Search_Results.xml

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\ShopperReports3
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\facemoods.com
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore
Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1
Key Deleted : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
Key Deleted : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
Key Deleted : HKLM\SOFTWARE\facemoods.com
Key Deleted : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.searchnu.com/406 --> hxxp://www.google.com

-\\ Mozilla Firefox v13.0.1 (de)

Profile name : default
File : C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\prefs.js

C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\user.js ... Deleted !

Deleted : user_pref("browser.search.defaultenginename", "Search Results");
Deleted : user_pref("browser.search.order.1", "Search Results");
Deleted : user_pref("extensions.facemoods._xpiupdate", true);
Deleted : user_pref("extensions.facemoods.aflt", "_#wbst");
Deleted : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.3");
Deleted : user_pref("extensions.facemoods.id", "_#1bd7121b4fd743e4a037d7d22f19cf19");
Deleted : user_pref("extensions.facemoods.instlDay", "_#15240");
Deleted : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com");
Deleted : user_pref("extensions.facemoods.sid", "_#1bd7121b4fd743e4a037d7d22f19cf19");
Deleted : user_pref("extensions.facemoods.uninst", true);
Deleted : user_pref("extensions.facemoods.update", "_#v1.4.0");
Deleted : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5");

*************************

AdwCleaner[R1].txt - [6462 octets] - [22/07/2012 18:05:39]
AdwCleaner[S1].txt - [6680 octets] - [22/07/2012 20:24:12]

########## EOF - C:\AdwCleaner[S1].txt - [6808 octets] ##########

Und hier nochmal ein neuer OTL Log:

OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 22.07.2012 20:32:41 - Run 2
OTL by OldTimer - Version 3.2.54.0     Folder = C:\Users\sarah\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,50 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 68,17% Memory free
7,18 Gb Paging File | 5,98 Gb Available in Paging File | 83,30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 153,38 Gb Total Space | 36,76 Gb Free Space | 23,97% Space Free | Partition Type: NTFS
Drive D: | 727,56 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF
 
Computer Name: SARAH-PC | User Name: sarah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.07.21 20:27:13 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\sarah\Desktop\OTL.exe
PRC - [2012.07.16 17:59:05 | 001,536,712 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
PRC - [2012.07.03 20:37:20 | 001,192,664 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.07.03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.06.18 13:59:15 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012.05.06 21:33:31 | 001,564,368 | ---- | M] () -- C:\Program Files\Guard-ICQ\GuardICQ.exe
PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.02 00:31:35 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.04.24 02:11:55 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.03.20 11:16:08 | 000,247,872 | ---- | M] () -- C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE
PRC - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.03.21 20:56:16 | 001,230,704 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2009.12.04 15:48:54 | 001,728,512 | ---- | M] (VIA) -- C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2009.04.27 15:20:02 | 000,074,408 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files\Lexmark 1200 Series\LXCZbmgr.exe
PRC - [2009.04.27 15:19:38 | 000,058,024 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
PRC - [2009.04.11 00:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 00:27:22 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
PRC - [2007.04.19 15:43:42 | 000,537,520 | ---- | M] ( ) -- C:\Windows\System32\lxczcoms.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.07.16 17:59:05 | 009,465,032 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_265.dll
MOD - [2012.07.03 20:37:20 | 001,192,664 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
MOD - [2012.06.18 13:59:14 | 002,042,848 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012.05.06 21:33:31 | 001,564,368 | ---- | M] () -- C:\Program Files\Guard-ICQ\GuardICQ.exe
MOD - [2011.05.28 22:04:56 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\rarext.dll
MOD - [2011.03.21 20:57:34 | 000,096,112 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.03.21 20:56:16 | 001,230,704 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2009.11.03 11:11:50 | 047,628,288 | ---- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\Skin.dll
MOD - [2009.05.07 16:53:18 | 000,106,496 | ---- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
MOD - [2009.05.07 16:50:46 | 000,073,728 | ---- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll
MOD - [2008.02.14 13:57:00 | 000,094,208 | ---- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\VMicApi.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012.07.16 17:59:06 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.06.18 13:59:14 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.05.06 21:33:31 | 001,564,368 | ---- | M] () [Auto | Running] -- C:\Program Files\Guard-ICQ\GuardICQ.exe -- (Guard.Mail.ru)
SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.03.20 11:16:08 | 000,247,872 | ---- | M] () [Auto | Running] -- C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE -- (ICQ Service)
SRV - [2012.02.19 18:53:49 | 000,481,064 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2008.01.21 04:21:41 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2007.04.19 15:43:42 | 000,537,520 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxczcoms.exe -- (lxcz_device)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\Drivers\AsrCDDrv.sys -- (AsrCDDrv)
DRV - [2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.04.27 10:20:04 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.04.25 00:32:27 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.04.16 21:17:40 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.07.10 05:37:00 | 011,008,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.11.25 21:02:46 | 001,108,480 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2006.11.02 09:30:56 | 000,429,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm60x32.sys -- (NVENETFD)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 36 40 8F E5 70 30 CC 01  [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaulturl: "hxxp://www.searchcanvas.com/web?ot=7&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de"
FF - prefs.js..network.proxy.http: "193.84.22.97"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.no_proxies_on: "localhost, 127.0.0.1, stealthy.co"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\sarah\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.07.06 22:14:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.18 13:59:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.10 18:49:05 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.18 13:59:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.10 18:49:05 | 000,000,000 | ---D | M]
 
[2012.07.03 23:26:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\sarah\AppData\Roaming\mozilla\Extensions
[2012.07.22 20:26:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\sarah\AppData\Roaming\mozilla\Firefox\Profiles\r8v3ln8a.default\extensions
[2012.05.09 22:05:29 | 000,000,000 | ---D | M] (FT SleekDark) -- C:\Users\sarah\AppData\Roaming\mozilla\Firefox\Profiles\r8v3ln8a.default\extensions\{a21cd440-41d6-11e0-9207-0800200c9a66}
[2012.07.20 18:06:17 | 000,000,950 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\searchplugins\icqplugin-1.xml
[2011.09.07 15:04:05 | 000,000,950 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\searchplugins\icqplugin-3.xml
[2011.09.07 21:18:50 | 000,000,950 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\searchplugins\icqplugin-4.xml
[2011.03.30 15:14:34 | 000,001,042 | ---- | M] () -- C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\r8v3ln8a.default\searchplugins\icqplugin.xml
[2012.07.17 18:42:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2012.02.29 17:13:28 | 000,258,567 | ---- | M] () (No name found) -- C:\USERS\SARAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R8V3LN8A.DEFAULT\EXTENSIONS\{46551EC9-40F0-4E47-8E18-8E5CF550CFB8}.XPI
[2012.06.15 15:44:44 | 000,182,698 | ---- | M] () (No name found) -- C:\USERS\SARAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R8V3LN8A.DEFAULT\EXTENSIONS\STEALTHYEXTENSION@GMAIL.COM.XPI
[2012.06.18 13:59:15 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.04.09 16:36:09 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.11.10 18:48:07 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.11.10 18:48:07 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.11.10 18:48:07 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.11.10 18:48:07 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.11.10 18:48:07 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.11.10 18:48:07 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.07.22 16:34:00 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (ICQ Sparberater) - {0766C1B9-B2DC-46E5-8934-4F3D6B42B1BD} - C:\Program Files\icq\Internet Explorer\icq.dll (solute gmbh)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: ([verify-U]_Add-on) - {F4552A56-119C-478E-AB3F-2C850F78B72E} - C:\Program Files\[verify-U]_AVS_IE_Add-on\[verify-U]_AVS.dll (Cybits AG)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Guard.Mail.ru.gui] C:\Program Files\Guard-ICQ\GuardICQ.exe ()
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [lxczbmgr.exe] C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [Facebook Update] C:\Users\sarah\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Spotify] C:\Users\sarah\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\sarah\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\sarah\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe (ICQ, LLC.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 82.212.62.62 78.42.43.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3E2341BC-7121-4792-A4CF-EA2D259D491E}: DhcpNameServer = 82.212.62.62 78.42.43.62
O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\Datamngr\datamngr.dll) -  File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\Datamngr\IEBHO.dll) -  File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\sarah\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\sarah\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2007.01.26 10:41:23 | 000,000,000 | R--D | M] - D:\AutoRun -- [ UDF ]
O32 - AutoRun File - [2007.01.26 10:36:30 | 000,700,416 | R--- | M] (Electronic Arts Inc.) - D:\AutoRun.exe -- [ UDF ]
O32 - AutoRun File - [2007.01.26 10:40:58 | 000,000,149 | R--- | M] () - D:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2007.01.26 09:06:20 | 000,651,264 | R--- | M] (Electronic Arts Inc.) - D:\AutoRunGUI.dll -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.22 16:44:59 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.07.22 16:35:47 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.07.22 16:25:28 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.07.22 16:25:28 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.07.22 16:25:28 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.07.22 16:24:20 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.07.22 16:23:55 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012.07.22 16:16:20 | 004,582,474 | R--- | C] (Swearware) -- C:\Users\sarah\Desktop\ComboFix.exe
[2012.07.22 16:07:06 | 000,000,000 | ---D | C] -- C:\TDSS
[2012.07.22 15:52:27 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.07.21 20:27:11 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\sarah\Desktop\OTL.exe
[2012.07.20 19:24:43 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2012.07.20 19:24:09 | 000,000,000 | ---D | C] -- C:\Users\sarah\Documents\Simply Super Software
[2012.07.20 19:24:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2012.07.20 19:04:24 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2012.07.20 19:01:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.07.17 18:33:21 | 000,000,000 | ---D | C] -- C:\Users\sarah\AppData\Roaming\Malwarebytes
[2012.07.17 18:33:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.17 18:33:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.17 18:33:13 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.07.17 18:33:13 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.07.16 18:08:18 | 000,000,000 | ---D | C] -- C:\Users\sarah\AppData\Local\Macromedia
[2012.07.15 21:14:45 | 000,107,888 | ---- | C] (Sony DADC Austria AG.) -- C:\Windows\System32\CmdLineExt.dll
[2012.07.15 21:14:45 | 000,000,000 | RH-D | C] -- C:\Users\sarah\AppData\Roaming\SecuROM
[2012.07.15 00:50:19 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\EA Games
[2012.07.14 22:41:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
[2012.07.14 22:39:43 | 000,000,000 | ---D | C] -- C:\Users\sarah\Documents\EA Games
[2012.07.02 17:48:26 | 000,000,000 | ---D | C] -- C:\Users\sarah\AppData\Roaming\.minecraft
[2012.07.02 17:40:27 | 000,000,000 | ---D | C] -- C:\Users\sarah\AppData\Roaming\.Nitrous
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.22 20:26:00 | 000,105,719 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2012.07.22 20:25:59 | 000,105,719 | ---- | M] () -- C:\ProgramData\nvModes.001
[2012.07.22 20:25:49 | 000,003,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.22 20:25:49 | 000,003,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.22 20:25:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.22 20:25:39 | 3757,367,296 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.22 17:59:17 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.22 16:59:05 | 000,001,138 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2778025260-2901813310-1566513995-1000UA.job
[2012.07.22 16:34:00 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012.07.22 16:16:47 | 000,632,049 | ---- | M] () -- C:\Users\sarah\Desktop\adwcleaner.exe
[2012.07.22 16:16:29 | 004,582,474 | R--- | M] (Swearware) -- C:\Users\sarah\Desktop\ComboFix.exe
[2012.07.22 16:14:07 | 000,652,528 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.07.22 16:14:07 | 000,607,406 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.07.22 16:14:07 | 000,134,766 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.07.22 16:14:07 | 000,113,694 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.07.21 22:59:00 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2778025260-2901813310-1566513995-1000Core.job
[2012.07.21 20:45:46 | 000,302,592 | ---- | M] () -- C:\Users\sarah\Desktop\67ys2l3q.exe
[2012.07.21 20:32:34 | 000,000,000 | ---- | M] () -- C:\Users\sarah\defogger_reenable
[2012.07.21 20:27:13 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\sarah\Desktop\OTL.exe
[2012.07.21 20:25:46 | 000,050,477 | ---- | M] () -- C:\Users\sarah\Desktop\Defogger.exe
[2012.07.21 19:54:37 | 000,008,704 | ---- | M] () -- C:\Users\sarah\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.07.20 20:00:27 | 000,002,708 | ---- | M] () -- C:\Users\sarah\.recently-used.xbel
[2012.07.20 19:09:23 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.07.17 18:55:59 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.07.15 21:14:45 | 000,107,888 | ---- | M] (Sony DADC Austria AG.) -- C:\Windows\System32\CmdLineExt.dll
[2012.07.15 21:12:18 | 000,002,103 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims™ 2 Glamour-Accessoires.lnk
[2012.07.15 21:08:37 | 000,002,155 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims™ 2 Teen Style-Accessoires.lnk
[2012.07.15 21:03:20 | 000,002,085 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims™ 2 Vier Jahreszeiten.lnk
[2012.07.15 20:59:36 | 000,002,013 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims™ 2 Haustiere.lnk
[2012.07.15 20:53:16 | 000,002,013 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims 2 Nightlife.lnk
[2012.07.14 22:41:14 | 000,001,898 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims 2.lnk
[2012.07.13 23:55:45 | 000,257,592 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.07.02 17:37:10 | 000,278,561 | ---- | M] () -- C:\Users\sarah\Desktop\Minecraft.exe
 
========== Files Created - No Company Name ==========
 
[2012.07.22 16:25:28 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.07.22 16:25:28 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.07.22 16:25:28 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.07.22 16:25:28 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.07.22 16:25:28 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.07.22 16:16:47 | 000,632,049 | ---- | C] () -- C:\Users\sarah\Desktop\adwcleaner.exe
[2012.07.21 20:45:46 | 000,302,592 | ---- | C] () -- C:\Users\sarah\Desktop\67ys2l3q.exe
[2012.07.21 20:32:34 | 000,000,000 | ---- | C] () -- C:\Users\sarah\defogger_reenable
[2012.07.21 20:25:46 | 000,050,477 | ---- | C] () -- C:\Users\sarah\Desktop\Defogger.exe
[2012.07.20 20:00:27 | 000,002,708 | ---- | C] () -- C:\Users\sarah\.recently-used.xbel
[2012.07.20 19:01:39 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.07.17 18:33:14 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.07.16 17:43:04 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.15 21:12:18 | 000,002,103 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims™ 2 Glamour-Accessoires.lnk
[2012.07.15 21:08:37 | 000,002,155 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims™ 2 Teen Style-Accessoires.lnk
[2012.07.15 21:03:20 | 000,002,085 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims™ 2 Vier Jahreszeiten.lnk
[2012.07.15 20:59:36 | 000,002,013 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims™ 2 Haustiere.lnk
[2012.07.15 20:53:16 | 000,002,013 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims 2 Nightlife.lnk
[2012.07.14 22:41:14 | 000,001,898 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims 2.lnk
[2012.07.02 17:37:09 | 000,278,561 | ---- | C] () -- C:\Users\sarah\Desktop\Minecraft.exe
[2012.06.01 17:27:12 | 000,000,100 | ---- | C] () -- C:\Windows\Lexstat.ini
[2012.06.01 17:25:03 | 001,224,704 | ---- | C] ( ) -- C:\Windows\System32\lxczserv.dll
[2012.06.01 17:25:03 | 000,991,232 | ---- | C] ( ) -- C:\Windows\System32\lxczusb1.dll
[2012.06.01 17:25:03 | 000,696,320 | ---- | C] ( ) -- C:\Windows\System32\lxczhbn3.dll
[2012.06.01 17:25:03 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxczcomc.dll
[2012.06.01 17:25:03 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxczpmui.dll
[2012.06.01 17:25:03 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxczlmpm.dll
[2012.06.01 17:25:03 | 000,537,520 | ---- | C] ( ) -- C:\Windows\System32\lxczcoms.exe
[2012.06.01 17:25:03 | 000,421,888 | ---- | C] ( ) -- C:\Windows\System32\lxczcomm.dll
[2012.06.01 17:25:03 | 000,413,696 | ---- | C] () -- C:\Windows\System32\lxczutil.dll
[2012.06.01 17:25:03 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxczinpa.dll
[2012.06.01 17:25:03 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxcziesc.dll
[2012.06.01 17:25:03 | 000,385,968 | ---- | C] ( ) -- C:\Windows\System32\lxczih.exe
[2012.06.01 17:25:03 | 000,381,872 | ---- | C] ( ) -- C:\Windows\System32\lxczcfg.exe
[2012.06.01 17:25:03 | 000,323,584 | ---- | C] ( ) -- C:\Windows\System32\LXCZhcp.dll
[2012.06.01 17:25:03 | 000,274,432 | ---- | C] () -- C:\Windows\System32\LXCZinst.dll
[2012.06.01 17:25:03 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxczprox.dll
[2012.06.01 17:25:03 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxczpplc.dll
[2011.11.01 19:48:48 | 000,062,976 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.11.01 19:48:35 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011.11.01 19:47:25 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.11.01 18:29:02 | 000,138,056 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011.11.01 18:29:02 | 000,138,056 | ---- | C] () -- C:\Users\sarah\AppData\Roaming\PnkBstrK.sys
[2011.11.01 18:28:51 | 000,189,248 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.11.01 18:28:50 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011.09.04 16:57:29 | 000,000,538 | RHS- | C] () -- C:\Users\sarah\ntuser.pol
[2011.09.02 16:42:52 | 000,008,704 | ---- | C] () -- C:\Users\sarah\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.05.25 17:50:04 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2011.05.25 17:50:03 | 000,652,528 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2011.05.25 17:50:03 | 000,134,766 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2011.05.25 17:50:03 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2011.05.24 22:03:36 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011.05.24 20:29:21 | 000,105,719 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2011.05.24 20:29:21 | 000,105,719 | ---- | C] () -- C:\ProgramData\nvModes.001
[2011.05.24 18:25:34 | 000,000,680 | ---- | C] () -- C:\Users\sarah\AppData\Local\d3d9caps.dat
 
========== LOP Check ==========
 
[2012.07.02 17:55:24 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\.minecraft
[2012.07.02 17:40:42 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\.Nitrous
[2011.09.14 20:31:58 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\DVDVideoSoft
[2011.09.14 20:31:02 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.07.20 20:00:27 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\gtk-2.0
[2012.06.07 02:24:59 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\ICQ
[2012.05.06 21:33:46 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\ICQ Search
[2012.01.04 23:11:12 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\LolClient
[2011.08.21 20:32:53 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\OpenOffice.org
[2011.07.04 19:53:51 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\Skip-Bo
[2012.07.22 20:26:12 | 000,000,000 | ---D | M] -- C:\Users\sarah\AppData\Roaming\Spotify
[2012.07.21 22:59:00 | 000,001,116 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2778025260-2901813310-1566513995-1000Core.job
[2012.07.22 16:59:05 | 000,001,138 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2778025260-2901813310-1566513995-1000UA.job
[2012.07.22 20:24:37 | 000,032,624 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >
         
--- --- ---


MfG


Alt 22.07.2012, 20:43   #6
Chris4You
 
Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht - Standard

Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht



Hi,

Gruß an Sahra, wir sind durch:

Combofix deinstallieren:
Klicke auf Start (Windows 7 Start Button) und tippe dann in das Suchfeld combofix /uninstall, wie im Piktogram unter diesem Text mit dem blauen Pfeil. Bitte sicherstellen, dass ein Leerzeichen zwischen Combofix und /uninstall ist.
Combofix deinstallieren

OTL und das Verzeichnis C:\_OTL löschen.... Die restlichen Tools je nach Geschmack behalten und ab und zu updaten und Fullscann (MAM etc.)...

chris
__________________
--> Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht

Alt 22.07.2012, 20:53   #7
RIpchip
 
Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht - Icon26

Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht



Perfekt, danke dir vielmals für deine Hilf und Mühe ihr Problem zu lösen
Jetzt kann ich den Pc auch wieder ohne Ängste benutzt .

Wünsch dir einen schönen Abend!

MfG

Antwort

Themen zu Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht
adobe, antivir, avira, bandoo, bho, converter, entfernen, error, firefox, flash player, format, google, grand theft auto, install.exe, internet, jdownloader, langs, limited.com/facebook, locker, mozilla, mp3, netzwerk, object, port, programm, realtek, registry, rundll, searchqu toolbar, searchscopes, security, sekunden, spotify web helper, super, trojaner, vista



Ähnliche Themen: Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht


  1. ADWARE - Trojaner - Internet funktioniert nicht mehr
    Plagegeister aller Art und deren Bekämpfung - 04.11.2014 (3)
  2. GVU Trojaner auf dem Laptop entfernen, abgesicherter Modus funktioniert nicht mehr
    Log-Analyse und Auswertung - 01.05.2014 (15)
  3. internet funktioniert nicht mehr ... aufgrund von trojaner?
    Plagegeister aller Art und deren Bekämpfung - 07.03.2014 (11)
  4. GVU Trojaner entfernen, Kaspersky Rescue CD funktioniert nicht mehr
    Plagegeister aller Art und deren Bekämpfung - 28.10.2013 (25)
  5. 2x | Trojaner aufm Rechner und Internet Explorer funktioniert nicht
    Mülltonne - 24.04.2013 (1)
  6. GVU-Trojaner entfernen (abgesicherter Modus funktioniert nicht)
    Plagegeister aller Art und deren Bekämpfung - 10.04.2013 (12)
  7. Mehrere Viren, ich weiß nicht weiter !
    Log-Analyse und Auswertung - 15.03.2013 (2)
  8. Mehrere unbekannte Viren und Trojaner, nicht entfernbar durch AntiVirenProgramm
    Log-Analyse und Auswertung - 09.08.2011 (1)
  9. Internet Brouser funktioniert nicht mehr, habe evtl. Trojaner TR/Crypt.IR.41, HTML
    Plagegeister aller Art und deren Bekämpfung - 06.09.2010 (19)
  10. Mehrere Viren und Trojaner!!!Hilfe!!!!
    Log-Analyse und Auswertung - 08.04.2010 (39)
  11. Mehrere Viren/Trojaner eingefangen
    Plagegeister aller Art und deren Bekämpfung - 20.07.2009 (5)
  12. Dringend Hilfe - Mehrere Trojaner die nicht zu entfernen sind TR/Dropper.Gen usw
    Log-Analyse und Auswertung - 07.07.2009 (3)
  13. Hab 1 oder mehrere Viren auf den PC, weiß aber nicht wie ich sie los werde
    Plagegeister aller Art und deren Bekämpfung - 21.09.2008 (19)
  14. mehrere Trojaner und Viren? Hijacklog hilfe
    Log-Analyse und Auswertung - 31.03.2008 (8)
  15. smitfraud entfernen hat nicht funktioniert (escan zeigt noch mehr viren)
    Log-Analyse und Auswertung - 11.02.2008 (13)
  16. Internet Explorer funktioniert nicht mehr - Trojaner?!
    Log-Analyse und Auswertung - 11.04.2007 (7)
  17. Trojaner gelöscht, Internet funktioniert nicht mehr!!!
    Plagegeister aller Art und deren Bekämpfung - 07.01.2007 (3)

Zum Thema Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht - Hallo, der PC meiner Freundin hat seit gestern immer wieder eine Meldung (Avira) über ein und den selben Trojaner gebracht. Die Meldung kam auch als er in Quarantänte verschoben wurde. - Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht...
Archiv
Du betrachtest: Mehrere Trojaner/Viren entfernen?, Internet funktioniert nicht auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.