Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 20.11.2012, 21:12   #1
paddy83
 
TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 - Standard

TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8



Hallo zusammen,

ich mir wohl u.a. durch Anschluss einer externen HDD mit älteren Daten ein paar Plagegeister eingefangen. Da waren wohl in einigen "Jugendsünden" noch ein paar Überraschungen versteckt.

MBAM OLT und ESET habe ich durchlaufen lassen, anbei die Logs.
Ich habe eine Hand voll Pfade aus den Logs aus privaten Gründen gekürzt, falls diese benötigt werden reiche ich sie nach oder füge sie selbst in das Script ein.

Vielen Dank für eure Hilfe!

Patrick



MBAM Durchlauf 1:

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Datenbank Version: v2012.11.13.07

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
egal :: EGAL-PC [Administrator]

13.11.2012 19:56:47
mbam-log-2012-11-13 (19-56-47).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|G:\|H:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 375594
Laufzeit: 44 Minute(n), 55 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\Patrick\AppData\Roaming\loaupdt.jpg (Extension.Mismatch) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Patrick\AppData\Roaming\appConf32.exe (Backdoor.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


MBAM Durchlauf 2:

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Datenbank Version: v2012.11.13.07

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
egal :: EGAL-PC [Administrator]

13.11.2012 19:56:47
mbam-log-2012-11-14 (00-03-39).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|G:\|H:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 375594
Laufzeit: 44 Minute(n), 55 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\Patrick\AppData\Roaming\loaupdt.jpg (Extension.Mismatch) -> Keine Aktion durchgeführt.
C:\Users\Patrick\AppData\Roaming\appConf32.exe (Backdoor.Agent) -> Keine Aktion durchgeführt.

(Ende)


OLT:

OTL logfile created on: 18.11.2012 15:11:17 - Run 2
OTL by OldTimer - Version 3.2.70.1 Folder = C:\Users\egal\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

2,85 Gb Total Physical Memory | 0,95 Gb Available Physical Memory | 33,24% Memory free
5,71 Gb Paging File | 2,84 Gb Available in Paging File | 49,81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 368,10 Gb Total Space | 298,23 Gb Free Space | 81,02% Space Free | Partition Type: NTFS
Drive D: | 97,66 Gb Total Space | 96,20 Gb Free Space | 98,51% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: EGAL-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 360 Days

========== Processes (SafeList) ==========

PRC - [2012.11.13 15:16:47 | 000,384,800 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.10.30 14:18:00 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2012.10.30 14:17:51 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.10.12 19:54:49 | 000,692,152 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe
PRC - [2012.10.08 09:37:24 | 000,748,704 | ---- | M] (Microsoft Corporation) -- C:\Programme\Internet Explorer\iexplore.exe
PRC - [2012.10.03 12:40:30 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\egal\Desktop\OTL.exe
PRC - [2012.09.19 18:20:40 | 000,079,136 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.08.31 15:02:03 | 002,754,984 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2012.07.09 19:51:26 | 001,672,008 | ---- | M] () -- C:\Programme\Twonky\TwonkyServer\twonkyserver.exe
PRC - [2012.07.09 19:51:02 | 000,545,608 | ---- | M] () -- C:\Programme\Twonky\TwonkyServer\twonkyproxy.exe
PRC - [2012.07.09 19:50:58 | 000,271,176 | ---- | M] () -- C:\Programme\Twonky\TwonkyServer\twonkywebdav.exe
PRC - [2012.07.09 19:50:56 | 000,594,760 | ---- | M] (PacketVideo) -- C:\Programme\Twonky\TwonkyServer\twonkytray.exe
PRC - [2012.07.09 19:50:56 | 000,549,704 | ---- | M] (PacketVideo) -- C:\Programme\Twonky\TwonkyServer\twonkystarter.exe
PRC - [2011.06.24 05:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 22:29:49 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010.11.20 22:29:19 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe


========== Modules (No Company Name) ==========

MOD - [2012.03.19 21:09:08 | 000,094,208 | ---- | M] () -- C:\Windows\System32\IccLibDll.dll


========== Services (SafeList) ==========

SRV - [2012.10.30 14:18:00 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.10.30 14:17:51 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.10.14 18:35:23 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.10.12 19:54:49 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.08.31 15:02:03 | 002,754,984 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012.07.09 19:51:02 | 000,545,608 | ---- | M] () [Auto | Running] -- C:\Programme\Twonky\TwonkyServer\twonkyproxy.exe -- (TwonkyProxy)
SRV - [2012.07.09 19:50:58 | 000,271,176 | ---- | M] () [Auto | Running] -- C:\Programme\Twonky\TwonkyServer\twonkywebdav.exe -- (TwonkyWebDav)
SRV - [2012.07.09 19:50:56 | 000,549,704 | ---- | M] (PacketVideo) [Auto | Running] -- C:\Programme\Twonky\TwonkyServer\twonkystarter.exe -- (TwonkyServer)
SRV - [2012.03.19 22:44:18 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IntelCpHeciSvc.exe -- (cphs)
SRV - [2010.11.20 22:29:49 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2009.07.14 02:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - [2012.11.13 15:16:54 | 000,133,824 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.11.13 15:16:54 | 000,083,432 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.11.13 15:16:54 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012.09.24 18:12:17 | 000,231,760 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\System32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2012.08.27 14:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.11.20 22:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 22:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 22:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc)
DRV - [2010.11.20 22:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 22:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 22:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2010.11.20 22:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 22:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010.10.19 22:33:40 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (MEI)
DRV - [2008.12.19 05:15:52 | 000,246,808 | ---- | M] (silex technology, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\sxuptp.sys -- (sxuptp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 78 11 9F 0F B9 B9 CD 01 [binary data]
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = EB DF 65 A1 12 C4 CD 01 [binary data]
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: {0153E448-190B-4987-BDE1-F256CADA672F}:15.0.6
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.6.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.6.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.10.03 14:05:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.14 18:35:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.14 18:35:21 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.14 18:35:23 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.14 18:35:21 | 000,000,000 | ---D | M]

[2012.09.26 15:22:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Extensions
[2012.10.14 18:35:20 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.10.03 14:05:04 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2012.10.14 18:35:23 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.08.14 16:49:30 | 000,171,136 | ---- | M] (Tracker Software Products (Canada) Ltd.) -- C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll

O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004..\Run: [ICQ] C:\Program Files\ICQ7M\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk = C:\Programme\silex technology\SX Virtual Link\Connect.exe (silex technology, Inc.)
O4 - Startup: C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk = C:\Programme\silex technology\SX Virtual Link\Connect.exe (silex technology, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Programme\ICQ7M\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Programme\ICQ7M\ICQ.exe (ICQ, LLC.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D64C20E-EA5D-4AEE-88CD-9A5819240691}: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 360 Days ==========

[2012.11.16 03:00:46 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.11.16 03:00:45 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.11.16 03:00:45 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.11.16 03:00:44 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012.11.16 03:00:44 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012.11.16 03:00:44 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.11.16 03:00:44 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.11.16 03:00:43 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012.11.15 03:52:10 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll
[2012.11.15 03:52:09 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012.11.13 19:55:39 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.10.26 18:49:08 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Avira
[2012.10.19 20:11:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.10.19 20:11:19 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2012.10.19 20:11:18 | 000,133,824 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012.10.19 20:11:18 | 000,083,432 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2012.10.19 20:11:18 | 000,036,552 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.10.19 20:11:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.10.19 20:11:15 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012.10.19 09:13:53 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\Handy
[2012.10.17 19:09:02 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\TeamViewer
[2012.10.15 19:00:17 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2012.10.14 19:37:21 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\QuickPar
[2012.10.14 18:39:44 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\UseNeXT
[2012.10.14 18:39:44 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\UseNeXT
[2012.10.14 18:35:20 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012.10.10 16:46:09 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012.10.10 16:45:55 | 003,968,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012.10.10 16:45:55 | 003,914,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012.10.07 19:19:59 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\TwonkyMedia
[2012.10.07 08:04:14 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\vlc
[2012.10.06 14:24:07 | 000,000,000 | ---D | C] -- C:\ProgramData\twonkyclient
[2012.10.03 19:28:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer
[2012.10.03 19:28:42 | 000,000,000 | ---D | C] -- C:\Program Files\Tracker Software
[2012.10.03 18:52:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Philips
[2012.10.03 18:52:35 | 000,000,000 | ---D | C] -- C:\Program Files\Philips
[2012.10.03 18:50:57 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2012.10.03 18:49:38 | 000,000,000 | ---D | C] -- C:\ProgramData\TwonkyServer
[2012.10.03 18:49:32 | 000,000,000 | ---D | C] -- C:\Program Files\Twonky
[2012.10.03 13:51:29 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Malwarebytes
[2012.10.03 13:49:11 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\GVU Logs
[2012.10.03 12:46:18 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.10.03 10:36:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.03 10:36:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.03 10:36:02 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.09.26 17:34:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7M
[2012.09.26 17:34:20 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\ICQ
[2012.09.26 17:34:13 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ7M
[2012.09.26 15:23:40 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Macromedia
[2012.09.26 15:22:42 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Mozilla
[2012.09.26 15:22:42 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Mozilla
[2012.09.24 21:24:40 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\
[2012.09.24 18:21:00 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Steganos
[2012.09.24 18:15:23 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Adobe
[2012.09.24 18:12:38 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\TrueCrypt
[2012.09.24 18:12:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrueCrypt
[2012.09.24 18:12:17 | 000,231,760 | ---- | C] (TrueCrypt Foundation) -- C:\Windows\System32\drivers\truecrypt.sys
[2012.09.24 18:12:04 | 000,000,000 | ---D | C] -- C:\Program Files\TrueCrypt
[2012.09.24 16:01:33 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Macromedia
[2012.09.22 22:39:18 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Canneverbe Limited
[2012.09.22 22:28:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited
[2012.09.22 22:28:14 | 000,000,000 | ---D | C] -- C:\Program Files\CDBurnerXP
[2012.09.22 22:22:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DeepBurner
[2012.09.22 22:22:33 | 000,000,000 | ---D | C] -- C:\Program Files\Astonsoft
[2012.09.22 22:03:53 | 000,000,000 | ---D | C] -- C:\Avis
[2012.09.22 22:02:42 | 000,360,448 | ---- | C] (FLV.com) -- C:\Windows\System32\TubeFinder.exe
[2012.09.22 22:02:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free FLV Converter
[2012.09.22 22:02:41 | 001,081,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscomctl.ocx
[2012.09.22 22:02:41 | 000,152,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\COMDLG32.OCX
[2012.09.22 22:02:41 | 000,141,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCMCFR.DLL
[2012.09.22 22:02:41 | 000,119,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6FR.DLL
[2012.09.22 22:02:41 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6STKIT.DLL
[2012.09.22 22:02:41 | 000,084,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PICCLP32.OCX
[2012.09.22 22:02:41 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CMDLGFR.DLL
[2012.09.22 22:02:41 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PCCLPFR.DLL
[2012.09.22 22:02:41 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\FreeFLVConverter
[2012.09.22 22:02:41 | 000,000,000 | ---D | C] -- C:\Program Files\Free FLV Converter
[2012.09.14 18:11:02 | 000,240,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2012.09.14 18:11:02 | 000,187,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
[2012.09.09 17:48:52 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickPar
[2012.09.09 17:48:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickPar
[2012.09.09 17:48:52 | 000,000,000 | ---D | C] -- C:\Program Files\QuickPar
[2012.09.02 11:38:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UseNeXT
[2012.09.02 11:38:16 | 000,000,000 | ---D | C] -- C:\Program Files\UseNeXT
[2012.08.30 22:06:25 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Adobe
[2012.08.30 22:05:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2012.08.30 22:05:31 | 000,198,864 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll
[2012.08.30 22:05:28 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2012.08.30 22:05:28 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2012.08.30 22:05:27 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2012.08.30 22:05:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2012.08.30 22:05:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2012.08.30 22:05:10 | 000,000,000 | ---D | C] -- C:\Program Files\Real
[2012.08.30 22:04:43 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Real
[2012.08.30 21:47:23 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012.08.30 21:47:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.08.30 21:01:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SX Virtual Link
[2012.08.30 21:01:27 | 000,000,000 | ---D | C] -- C:\Program Files\silex technology
[2012.08.30 21:01:05 | 000,246,808 | ---- | C] (silex technology, Inc.) -- C:\Windows\System32\drivers\sxuptp.sys
[2012.08.26 18:50:33 | 000,000,000 | R--D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.08.26 18:50:33 | 000,000,000 | R--D | C] -- C:\Users\Admin\Searches
[2012.08.26 18:50:33 | 000,000,000 | R--D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.08.26 18:50:26 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Identities
[2012.08.26 18:50:24 | 000,000,000 | R--D | C] -- C:\Users\Admin\Contacts
[2012.08.26 18:50:22 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\VirtualStore
[2012.08.26 18:47:11 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\ElevatedDiagnostics
[2012.08.26 17:48:42 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbport.sys
[2012.08.26 17:48:42 | 000,005,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbd.sys
[2012.08.26 17:48:40 | 000,148,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\storport.sys
[2012.08.26 17:48:40 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fsutil.exe
[2012.08.26 17:46:32 | 000,000,000 | --SD | C] -- C:\Users\Admin\AppData\Roaming\Microsoft
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Videos
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Saved Games
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Pictures
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Music
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Links
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Favorites
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Downloads
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Documents
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Desktop
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Vorlagen
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\AppData\Local\Verlauf
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\AppData\Local\Temporary Internet Files
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Startmenü
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\SendTo
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Recent
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Netzwerkumgebung
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Lokale Einstellungen
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Documents\Eigene Videos
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Documents\Eigene Musik
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Eigene Dateien
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Documents\Eigene Bilder
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Druckumgebung
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Cookies
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\AppData\Local\Anwendungsdaten
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Anwendungsdaten
[2012.08.26 17:46:32 | 000,000,000 | -H-D | C] -- C:\Users\Admin\AppData
[2012.08.26 17:46:32 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Temp
[2012.08.26 17:46:32 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Microsoft
[2012.08.26 17:46:32 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Media Center Programs
[2012.08.26 17:36:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012.08.26 17:36:14 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012.08.26 17:36:11 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012.08.26 17:36:11 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012.08.26 17:36:11 | 000,093,672 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2012.08.26 17:36:06 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012.08.26 17:35:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steganos Passwort-Manager Free
[2012.08.26 17:35:25 | 000,000,000 | ---D | C] -- C:\Program Files\Steganos Password Manager Free 11
[2012.08.26 17:33:18 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2012.08.26 17:33:18 | 000,000,000 | ---D | C] -- C:\Intel
[2012.08.26 17:30:29 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2012.08.26 17:30:28 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2012.08.26 17:30:28 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2012.08.26 17:30:28 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2012.08.26 17:30:28 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2012.08.26 17:30:28 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2012.08.26 17:30:28 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2012.08.26 17:30:28 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2012.08.26 17:30:28 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2012.08.26 17:30:28 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2012.08.26 17:30:28 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2012.08.26 17:30:28 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2012.08.26 17:30:28 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2012.08.26 17:30:28 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2012.08.26 17:30:28 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2012.08.26 17:30:28 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2012.08.26 17:30:28 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2012.08.26 17:30:28 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2012.08.26 17:30:28 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2012.08.26 17:30:28 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2012.08.26 17:30:28 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2012.08.26 17:30:28 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2012.08.26 17:30:28 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2012.08.26 17:30:28 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2012.08.26 17:30:28 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2012.08.26 17:30:28 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2012.08.26 17:30:28 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2012.08.26 17:30:28 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2012.08.26 17:30:28 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2012.08.26 17:27:41 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2012.08.26 17:27:40 | 001,549,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2012.08.26 17:27:40 | 001,401,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2012.08.26 17:27:40 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2012.08.26 17:27:40 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2012.08.26 17:27:40 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2012.08.26 17:27:40 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2012.08.26 17:27:40 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prevhost.exe
[2012.08.26 17:27:31 | 002,616,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2012.08.26 17:27:31 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2012.08.26 17:27:26 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
[2012.08.26 17:27:25 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl
[2012.08.26 17:27:24 | 000,870,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2012.08.26 17:27:24 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2012.08.26 17:27:21 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2012.08.26 17:27:21 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys
[2012.08.26 17:25:43 | 000,219,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2012.08.26 17:25:00 | 000,294,912 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2012.08.26 17:25:00 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
[2012.08.26 17:24:59 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2012.08.26 17:24:59 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2012.08.26 17:24:55 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2012.08.26 17:24:55 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2012.08.26 17:24:44 | 000,219,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2012.08.26 17:24:43 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3r.dll
[2012.08.26 17:24:33 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2012.08.26 17:24:32 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSCOVER.exe
[2012.08.26 17:24:30 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdosys.dll
[2012.08.26 17:24:23 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2012.08.26 17:24:23 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2012.08.26 17:24:23 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2012.08.26 17:24:22 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2012.08.26 17:24:22 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2012.08.26 17:24:20 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2012.08.26 17:24:16 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2012.08.26 17:24:16 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2012.08.26 17:24:15 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browcli.dll
[2012.08.26 17:24:15 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2012.08.26 17:24:15 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2012.08.26 17:24:14 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll
[2012.08.26 17:24:14 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
[2012.08.26 17:24:13 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcjt32.dll
[2012.08.26 17:24:13 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbctrac.dll
[2012.08.26 17:24:13 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2012.08.26 17:24:13 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccp32.dll
[2012.08.26 17:24:13 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccu32.dll
[2012.08.26 17:24:13 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccr32.dll
[2012.08.26 17:24:13 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2012.08.26 17:24:13 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2012.08.26 17:24:08 | 001,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2012.08.26 17:24:07 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
[2012.08.26 17:24:07 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
[2012.08.26 17:21:09 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\poqexec.exe
[2012.08.26 17:21:07 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2012.08.26 17:19:48 | 000,696,760 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.08.26 17:19:48 | 000,073,656 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.08.26 17:19:48 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2012.08.26 17:18:19 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll
[2012.08.26 17:15:23 | 002,422,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2012.08.26 17:15:23 | 000,045,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2012.08.26 17:15:20 | 000,577,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2012.08.26 17:15:20 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2012.08.26 17:15:20 | 000,035,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2012.08.26 17:15:18 | 000,171,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2012.08.26 17:15:18 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2012.08.26 17:14:22 | 000,100,896 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\System32\RTNUninst32.dll
[2012.08.26 17:14:04 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2012.08.26 17:14:02 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2012.08.26 17:11:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012.08.26 17:11:03 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2012.08.26 17:10:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2012.08.26 17:10:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2012.08.26 17:10:29 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2012.08.26 17:10:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2012.08.26 17:09:56 | 000,821,736 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll
[2012.08.26 17:09:56 | 000,746,984 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2012.08.26 17:08:11 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2012.08.26 13:17:53 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2012.08.26 13:17:39 | 000,000,000 | -HSD | C] -- C:\Boot
[2012.08.26 12:26:03 | 000,000,000 | -HSD | C] -- C:\Recovery
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Programme
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2012.08.26 12:26:00 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012.08.26 12:18:47 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2012.08.26 12:18:09 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012.03.19 22:44:18 | 000,276,248 | ---- | C] (Intel Corporation) -- C:\Windows\System32\IntelCpHeciSvc.exe
[2012.03.19 22:44:16 | 006,215,448 | ---- | C] (Intel Corporation) -- C:\Windows\System32\GfxUI.exe
[2012.03.19 22:40:34 | 000,081,920 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxCoIn_v2696.dll
[2012.03.19 22:26:56 | 006,120,960 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igdumd32.dll
[2012.03.19 22:11:38 | 007,795,200 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igd10umd32.dll
[2012.03.19 21:12:30 | 000,437,248 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrrom.lrc
[2012.03.19 21:12:28 | 000,437,760 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxresn.lrc
[2012.03.19 21:12:28 | 000,437,248 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrrus.lrc
[2012.03.19 21:12:28 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrhrv.lrc
[2012.03.19 21:12:28 | 000,436,224 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrsky.lrc
[2012.03.19 21:12:28 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrtrk.lrc
[2012.03.19 21:12:28 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrsve.lrc
[2012.03.19 21:12:28 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrslv.lrc
[2012.03.19 21:12:28 | 000,435,200 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrtha.lrc
[2012.03.19 21:12:26 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrptg.lrc
[2012.03.19 21:12:26 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrplk.lrc
[2012.03.19 21:12:26 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrita.lrc
[2012.03.19 21:12:26 | 000,436,224 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrhun.lrc
[2012.03.19 21:12:26 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrptb.lrc
[2012.03.19 21:12:26 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrnor.lrc
[2012.03.19 21:12:26 | 000,430,080 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrjpn.lrc
[2012.03.19 21:12:26 | 000,428,544 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrkor.lrc
[2012.03.19 21:12:24 | 000,438,272 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrell.lrc
[2012.03.19 21:12:24 | 000,437,760 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrfra.lrc
[2012.03.19 21:12:24 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrnld.lrc
[2012.03.19 21:12:24 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrdeu.lrc
[2012.03.19 21:12:24 | 000,436,224 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrfin.lrc
[2012.03.19 21:12:24 | 000,436,224 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrcsy.lrc
[2012.03.19 21:12:24 | 000,435,200 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrdan.lrc
[2012.03.19 21:12:24 | 000,433,664 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrheb.lrc
[2012.03.19 21:12:22 | 000,433,664 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrara.lrc
[2012.03.19 21:12:22 | 000,427,008 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrcht.lrc
[2012.03.19 21:12:22 | 000,426,496 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrchs.lrc
[2012.03.19 21:12:08 | 000,313,344 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxpph.dll
[2012.03.19 21:12:08 | 000,286,208 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxTMM.dll
[2012.03.19 21:12:08 | 000,120,320 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxcpl.cpl
[2012.03.19 21:12:06 | 000,025,088 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxexps.dll
[2012.03.19 21:11:52 | 000,059,392 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.dll
[2012.03.19 21:11:36 | 000,130,048 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxdo.dll
[2012.03.19 21:11:30 | 000,096,256 | ---- | C] (Intel Corporation) -- C:\Windows\System32\hccutils.dll
[2012.03.19 21:11:22 | 000,172,544 | ---- | C] (Intel Corporation) -- C:\Windows\System32\gfxSrvc.dll
[2012.03.19 21:10:56 | 009,023,488 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxress.dll
[2012.03.19 21:10:56 | 000,284,160 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrenu.lrc
[2012.03.19 21:09:08 | 002,321,408 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxcmjit32.dll
[2012.03.19 21:09:08 | 000,519,680 | ---- | C] (Intel Corporation) -- C:\Windows\System32\iglhsip32.dll
[2012.03.19 21:09:08 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2012.03.19 21:09:08 | 000,237,056 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxcmrt32.dll
[2012.03.19 21:09:08 | 000,177,152 | ---- | C] (Intel Corporation) -- C:\Windows\System32\iglhcp32.dll

========== Files - Modified Within 360 Days ==========

[2012.11.18 14:33:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.11.18 12:37:25 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.11.18 12:37:25 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.11.18 12:37:25 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.11.18 12:37:25 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.11.18 10:57:04 | 000,021,088 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.18 10:57:04 | 000,021,088 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.18 10:49:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.11.18 10:49:38 | 2298,261,504 | -HS- | M] () -- C:\hiberfil.sys
[2012.11.16 03:21:41 | 000,265,640 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.11.13 19:56:12 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.11.13 15:16:54 | 000,133,824 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012.11.13 15:16:54 | 000,083,432 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2012.11.13 15:16:54 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.10.18 18:59:05 | 002,345,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012.10.17 19:20:34 | 000,000,232 | ---- | M] () -- C:\Users\Admin\Documents\Kundenliste.rtf
[2012.10.15 20:36:49 | 000,000,420 | ---- | M] () -- C:\Users\Admin\Desktop\Wohnzimmer.rtf
[2012.10.15 19:00:31 | 000,001,124 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012.10.14 16:06:41 | 000,012,661 | ---- | M] () -- C:\Users\Admin\Desktop\
[2012.10.14 16:04:39 | 000,001,033 | ---- | M] () -- C:\Users\Admin\Desktop\
[2012.10.14 16:04:39 | 000,000,970 | ---- | M] () -- C:\Users\Admin\
[2012.10.12 19:54:49 | 000,696,760 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.10.12 19:54:49 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.10.08 08:56:24 | 001,800,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012.10.08 08:47:44 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012.10.08 08:46:32 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.10.08 08:45:17 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.10.08 08:44:05 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.10.08 08:42:31 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012.10.08 08:40:56 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.10.08 08:37:23 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.10.07 16:27:34 | 000,539,738 | ---- | M] () -- C:\Users\Admin\Desktop\kinderkekse.xps
[2012.10.07 16:27:11 | 000,718,181 | ---- | M] () -- C:\Users\Admin\Desktop\Pizzabrot.xps
[2012.10.03 18:52:52 | 000,001,930 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MediaServer.lnk
[2012.10.03 18:52:52 | 000,001,234 | ---- | M] () -- C:\Users\Public\Desktop\MediaManager.lnk
[2012.10.03 12:41:28 | 001,820,575 | ---- | M] () -- C:\Users\Admin\Desktop\gvu anleitung.xps
[2012.10.03 10:16:06 | 083,023,306 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.26 19:16:23 | 000,217,225 | ---- | M] () -- C:\Users\Admin\Desktop\Anschreiben m. Anforderungsformularen.pdf
[2012.09.25 23:47:43 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll
[2012.09.24 21:24:42 | 000,159,468 | ---- | M] () -- C:\Users\Admin\
[2012.09.24 18:12:22 | 000,001,032 | ---- | M] () -- C:\Users\Public\Desktop\TrueCrypt.lnk
[2012.09.24 18:12:17 | 000,231,760 | ---- | M] (TrueCrypt Foundation) -- C:\Windows\System32\drivers\truecrypt.sys
[2012.09.22 22:28:15 | 000,001,899 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2012.09.22 22:22:34 | 000,001,055 | ---- | M] () -- C:\Users\Admin\Desktop\DeepBurner.lnk
[2012.09.22 22:02:42 | 000,001,079 | ---- | M] () -- C:\Users\Admin\Desktop\Free FLV Converter.lnk
[2012.09.14 19:28:53 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012.09.09 17:48:52 | 000,000,969 | ---- | M] () -- C:\Users\Admin\Desktop\QuickPar.lnk
[2012.09.02 11:38:16 | 000,001,807 | ---- | M] () -- C:\Users\Admin\Desktop\
[2012.08.30 22:05:31 | 000,198,864 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll
[2012.08.30 22:05:28 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2012.08.30 22:05:28 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2012.08.30 22:05:27 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2012.08.30 21:11:25 | 000,001,234 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk
[2012.08.30 18:12:02 | 003,968,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012.08.30 18:12:02 | 003,914,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012.08.27 14:50:24 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2012.08.26 17:36:07 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll
[2012.08.26 17:36:07 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2012.08.26 17:36:07 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012.08.26 17:36:07 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012.08.26 17:36:07 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012.08.26 17:36:07 | 000,093,672 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2012.08.26 17:35:28 | 000,001,179 | ---- | M] () -- C:\Users\Public\Desktop\Passwort-Manager.lnk
[2012.08.26 17:30:29 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2012.08.26 17:30:28 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2012.08.26 17:30:28 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2012.08.26 17:30:28 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2012.08.26 17:30:28 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2012.08.26 17:30:28 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2012.08.26 17:30:28 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2012.08.26 17:30:28 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2012.08.26 17:30:28 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2012.08.26 17:30:28 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2012.08.26 17:30:28 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2012.08.26 17:30:28 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2012.08.26 17:30:28 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2012.08.26 17:30:28 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2012.08.26 17:30:28 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2012.08.26 17:30:28 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2012.08.26 17:30:28 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2012.08.26 17:30:28 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2012.08.26 17:30:28 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2012.08.26 17:30:28 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2012.08.26 17:30:28 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2012.08.26 17:30:28 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2012.08.26 17:30:28 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2012.08.26 17:30:28 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2012.08.26 17:30:28 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2012.08.26 17:30:28 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2012.08.26 17:30:28 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2012.08.26 17:30:28 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2012.08.26 17:30:28 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2012.08.26 17:30:28 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2012.08.26 13:17:41 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012.08.26 12:21:31 | 000,177,271 | ---- | M] () -- C:\Windows\System32\license.rtf
[2012.08.26 12:20:09 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.08.22 18:16:46 | 000,240,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2012.08.22 18:16:36 | 000,187,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
[2012.07.04 22:14:34 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\browcli.dll
[2012.06.06 06:03:06 | 000,805,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cdosys.dll
[2012.06.02 23:19:33 | 000,045,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2012.06.02 23:19:32 | 000,035,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2012.06.02 23:19:23 | 000,577,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2012.06.02 23:12:32 | 002,422,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2012.06.02 23:12:13 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2012.06.02 14:19:42 | 000,171,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2012.06.02 14:12:20 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2012.06.02 05:39:10 | 000,219,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2012.05.31 11:25:14 | 000,237,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2012.05.05 08:46:52 | 000,400,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
[2012.04.26 05:45:55 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2012.04.26 05:45:54 | 000,129,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2012.04.26 05:41:16 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2012.03.19 22:58:28 | 000,080,208 | ---- | M] () -- C:\Windows\System32\iglhxs32.vp
[2012.03.19 22:44:18 | 000,276,248 | ---- | M] (Intel Corporation) -- C:\Windows\System32\IntelCpHeciSvc.exe
[2012.03.19 22:44:16 | 006,215,448 | ---- | M] (Intel Corporation) -- C:\Windows\System32\GfxUI.exe
[2012.03.19 22:40:34 | 000,081,920 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxCoIn_v2696.dll
[2012.03.19 22:26:56 | 006,120,960 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igdumd32.dll
[2012.03.19 22:26:08 | 000,145,804 | ---- | M] () -- C:\Windows\System32\igcompkrng600.bin
[2012.03.19 22:26:06 | 000,963,912 | ---- | M] () -- C:\Windows\System32\igkrng600.bin
[2012.03.19 22:26:06 | 000,261,208 | ---- | M] () -- C:\Windows\System32\igfcg600m.bin
[2012.03.19 22:25:58 | 000,058,880 | ---- | M] () -- C:\Windows\System32\igdde32.dll
[2012.03.19 22:11:38 | 007,795,200 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igd10umd32.dll
[2012.03.19 21:21:14 | 013,212,672 | ---- | M] () -- C:\Windows\System32\ig4icd32.dll
[2012.03.19 21:12:48 | 000,144,790 | ---- | M] () -- C:\Windows\System32\Gfxres.ro-RO.resources
[2012.03.19 21:12:46 | 000,139,901 | ---- | M] () -- C:\Windows\System32\Gfxres.hr-HR.resources
[2012.03.19 21:12:46 | 000,125,306 | ---- | M] () -- C:\Windows\System32\Gfxres.zh-TW.resources
[2012.03.19 21:12:46 | 000,123,778 | ---- | M] () -- C:\Windows\System32\Gfxres.zh-CN.resources
[2012.03.19 21:12:44 | 000,221,877 | ---- | M] () -- C:\Windows\System32\Gfxres.th-TH.resources
[2012.03.19 21:12:44 | 000,143,564 | ---- | M] () -- C:\Windows\System32\Gfxres.tr-TR.resources
[2012.03.19 21:12:44 | 000,141,854 | ---- | M] () -- C:\Windows\System32\Gfxres.sv-SE.resources
[2012.03.19 21:12:42 | 000,192,378 | ---- | M] () -- C:\Windows\System32\Gfxres.ru-RU.resources
[2012.03.19 21:12:42 | 000,140,548 | ---- | M] () -- C:\Windows\System32\Gfxres.sk-SK.resources
[2012.03.19 21:12:42 | 000,136,850 | ---- | M] () -- C:\Windows\System32\Gfxres.sl-SI.resources
[2012.03.19 21:12:40 | 000,143,112 | ---- | M] () -- C:\Windows\System32\Gfxres.pt-BR.resources
[2012.03.19 21:12:40 | 000,142,079 | ---- | M] () -- C:\Windows\System32\Gfxres.pt-PT.resources
[2012.03.19 21:12:40 | 000,141,421 | ---- | M] () -- C:\Windows\System32\Gfxres.pl-PL.resources
[2012.03.19 21:12:38 | 000,147,116 | ---- | M] () -- C:\Windows\System32\Gfxres.ko-KR.resources
[2012.03.19 21:12:38 | 000,142,797 | ---- | M] () -- C:\Windows\System32\Gfxres.nl-NL.resources
[2012.03.19 21:12:38 | 000,136,778 | ---- | M] () -- C:\Windows\System32\Gfxres.nb-NO.resources
[2012.03.19 21:12:36 | 000,162,150 | ---- | M] () -- C:\Windows\System32\Gfxres.ja-JP.resources
[2012.03.19 21:12:36 | 000,148,461 | ---- | M] () -- C:\Windows\System32\Gfxres.it-IT.resources
[2012.03.19 21:12:36 | 000,142,606 | ---- | M] () -- C:\Windows\System32\Gfxres.hu-HU.resources
[2012.03.19 21:12:34 | 000,157,713 | ---- | M] () -- C:\Windows\System32\Gfxres.he-IL.resources
[2012.03.19 21:12:34 | 000,144,267 | ---- | M] () -- C:\Windows\System32\Gfxres.fr-FR.resources
[2012.03.19 21:12:34 | 000,140,949 | ---- | M] () -- C:\Windows\System32\Gfxres.fi-FI.resources
[2012.03.19 21:12:32 | 000,208,522 | ---- | M] () -- C:\Windows\System32\Gfxres.el-GR.resources
[2012.03.19 21:12:32 | 000,146,125 | ---- | M] () -- C:\Windows\System32\Gfxres.es-ES.resources
[2012.03.19 21:12:32 | 000,146,008 | ---- | M] () -- C:\Windows\System32\Gfxres.de-DE.resources
[2012.03.19 21:12:30 | 000,437,248 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrrom.lrc
[2012.03.19 21:12:30 | 000,164,821 | ---- | M] () -- C:\Windows\System32\Gfxres.ar-SA.resources
[2012.03.19 21:12:30 | 000,141,297 | ---- | M] () -- C:\Windows\System32\Gfxres.cs-CZ.resources
[2012.03.19 21:12:30 | 000,136,261 | ---- | M] () -- C:\Windows\System32\Gfxres.da-DK.resources
[2012.03.19 21:12:28 | 000,437,760 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxresn.lrc
[2012.03.19 21:12:28 | 000,437,248 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrrus.lrc
[2012.03.19 21:12:28 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrhrv.lrc
[2012.03.19 21:12:28 | 000,436,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrsky.lrc
[2012.03.19 21:12:28 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrtrk.lrc
[2012.03.19 21:12:28 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrsve.lrc
[2012.03.19 21:12:28 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrslv.lrc
[2012.03.19 21:12:28 | 000,435,200 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrtha.lrc
[2012.03.19 21:12:26 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrptg.lrc
[2012.03.19 21:12:26 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrplk.lrc
[2012.03.19 21:12:26 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrita.lrc
[2012.03.19 21:12:26 | 000,436,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrhun.lrc
[2012.03.19 21:12:26 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrptb.lrc
[2012.03.19 21:12:26 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrnor.lrc
[2012.03.19 21:12:26 | 000,430,080 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrjpn.lrc
[2012.03.19 21:12:26 | 000,428,544 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrkor.lrc
[2012.03.19 21:12:24 | 000,438,272 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrell.lrc
[2012.03.19 21:12:24 | 000,437,760 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrfra.lrc
[2012.03.19 21:12:24 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrnld.lrc
[2012.03.19 21:12:24 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrdeu.lrc
[2012.03.19 21:12:24 | 000,436,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrfin.lrc
[2012.03.19 21:12:24 | 000,436,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrcsy.lrc
[2012.03.19 21:12:24 | 000,435,200 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrdan.lrc
[2012.03.19 21:12:24 | 000,433,664 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrheb.lrc
[2012.03.19 21:12:22 | 000,433,664 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrara.lrc
[2012.03.19 21:12:22 | 000,427,008 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrcht.lrc
[2012.03.19 21:12:22 | 000,426,496 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrchs.lrc
[2012.03.19 21:12:22 | 000,131,674 | ---- | M] () -- C:\Windows\System32\Gfxres.en-US.resources
[2012.03.19 21:12:08 | 000,313,344 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxpph.dll
[2012.03.19 21:12:08 | 000,286,208 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxTMM.dll
[2012.03.19 21:12:08 | 000,120,320 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxcpl.cpl
[2012.03.19 21:12:06 | 000,025,088 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxexps.dll
[2012.03.19 21:11:52 | 000,059,392 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.dll
[2012.03.19 21:11:36 | 000,130,048 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxdo.dll
[2012.03.19 21:11:30 | 000,096,256 | ---- | M] (Intel Corporation) -- C:\Windows\System32\hccutils.dll
[2012.03.19 21:11:22 | 000,172,544 | ---- | M] (Intel Corporation) -- C:\Windows\System32\gfxSrvc.dll
[2012.03.19 21:11:22 | 000,009,216 | ---- | M] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2012.03.19 21:10:56 | 009,023,488 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxress.dll
[2012.03.19 21:10:56 | 000,284,160 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrenu.lrc
[2012.03.19 21:09:28 | 000,000,264 | ---- | M] () -- C:\Windows\System32\GfxUI.exe.config
[2012.03.19 21:09:08 | 002,321,408 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxcmjit32.dll
[2012.03.19 21:09:08 | 001,921,265 | ---- | M] () -- C:\Windows\System32\iglhxa32.cpa
[2012.03.19 21:09:08 | 000,519,680 | ---- | M] (Intel Corporation) -- C:\Windows\System32\iglhsip32.dll
[2012.03.19 21:09:08 | 000,452,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2012.03.19 21:09:08 | 000,237,056 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxcmrt32.dll
[2012.03.19 21:09:08 | 000,177,152 | ---- | M] (Intel Corporation) -- C:\Windows\System32\iglhcp32.dll
[2012.03.19 21:09:08 | 000,094,208 | ---- | M] () -- C:\Windows\System32\IccLibDll.dll
[2012.03.19 21:09:08 | 000,059,594 | ---- | M] () -- C:\Windows\System32\iglhxc32.vp
[2012.03.19 21:09:08 | 000,059,384 | ---- | M] () -- C:\Windows\System32\iglhxc32_dev.vp
[2012.03.19 21:09:08 | 000,059,328 | ---- | M] () -- C:\Windows\System32\iglhxg32_dev.vp
[2012.03.19 21:09:08 | 000,059,215 | ---- | M] () -- C:\Windows\System32\iglhxo32_dev.vp
[2012.03.19 21:09:08 | 000,058,781 | ---- | M] () -- C:\Windows\System32\iglhxo32.vp
[2012.03.19 21:09:08 | 000,058,684 | ---- | M] () -- C:\Windows\System32\iglhxg32.vp
[2012.03.19 21:09:08 | 000,001,074 | ---- | M] () -- C:\Windows\System32\iglhxa32.vp
[2012.03.03 06:31:19 | 001,077,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2012.02.17 06:34:22 | 000,826,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll
[2012.02.15 13:51:56 | 000,360,448 | ---- | M] (FLV.com) -- C:\Windows\System32\TubeFinder.exe
[2011.12.30 06:27:56 | 000,478,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl

========== Files Created - No Company Name ==========

[2012.11.13 19:55:41 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.10.17 19:20:33 | 000,000,232 | ---- | C] () -- C:\Users\Admin\Documents\Kundenliste.rtf
[2012.10.15 20:36:49 | 000,000,420 | ---- | C] () -- C:\Users\Admin\Desktop\Wohnzimmer.rtf
[2012.10.15 19:00:31 | 000,001,136 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012.10.15 19:00:31 | 000,001,124 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012.10.14 16:06:41 | 000,012,661 | ---- | C] () -- C:\Users\Admin\Desktop\
[2012.10.14 16:04:39 | 000,001,033 | ---- | C] () -- C:\Users\Admin\Desktop\
[2012.10.14 16:04:39 | 000,000,970 | ---- | C] () -- C:\Users\Admin\
[2012.10.07 16:27:34 | 000,539,738 | ---- | C] () -- C:\Users\Admin\Desktop\kinderkekse.xps
[2012.10.07 16:27:10 | 000,718,181 | ---- | C] () -- C:\Users\Admin\Desktop\Pizzabrot.xps
[2012.10.03 18:52:52 | 000,001,930 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MediaServer.lnk
[2012.10.03 18:52:52 | 000,001,234 | ---- | C] () -- C:\Users\Public\Desktop\MediaManager.lnk
[2012.10.03 12:42:14 | 001,820,575 | ---- | C] () -- C:\Users\Admin\Desktop\gvu anleitung.xps
[2012.10.03 10:05:31 | 083,023,306 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.09.26 19:16:22 | 000,217,225 | ---- | C] () -- C:\Users\Admin\Desktop\Anschreiben m. Anforderungsformularen.pdf
[2012.09.24 21:24:40 | 000,159,468 | ---- | C] () --
[2012.09.24 18:12:22 | 000,001,032 | ---- | C] () -- C:\Users\Public\Desktop\TrueCrypt.lnk
[2012.09.22 22:28:15 | 000,001,899 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2012.09.22 22:28:15 | 000,001,849 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
[2012.09.22 22:22:34 | 000,001,055 | ---- | C] () -- C:\Users\Admin\Desktop\DeepBurner.lnk
[2012.09.22 22:02:42 | 000,001,079 | ---- | C] () -- C:\Users\Admin\Desktop\Free FLV Converter.lnk
[2012.09.22 22:02:41 | 000,364,544 | ---- | C] () -- C:\Windows\System32\PropertyGrid.ocx
[2012.09.22 22:02:41 | 000,208,500 | ---- | C] () -- C:\Windows\System32\ReyXpBasics.tlb
[2012.09.22 22:02:41 | 000,024,576 | ---- | C] () -- C:\Windows\System32\ControlSubX.ocx
[2012.09.09 17:48:52 | 000,000,969 | ---- | C] () -- C:\Users\Admin\Desktop\QuickPar.lnk
[2012.09.02 11:38:16 | 000,001,807 | ---- | C] () -- C:\Users\Admin\Desktop\UseNeXT.lnk
[2012.08.30 21:01:31 | 000,001,234 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk
[2012.08.26 18:50:33 | 000,001,413 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.08.26 17:35:28 | 000,001,179 | ---- | C] () -- C:\Users\Public\Desktop\Passwort-Manager.lnk
[2012.08.26 17:30:28 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2012.08.26 17:19:50 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.08.26 17:14:22 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2012.08.26 17:10:34 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012.08.26 13:17:41 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
[2012.08.26 13:17:39 | 000,383,786 | RHS- | C] () -- C:\bootmgr
[2012.08.26 12:21:21 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012.08.26 12:21:15 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012.08.26 12:20:09 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.08.26 12:18:10 | 2298,261,504 | -HS- | C] () -- C:\hiberfil.sys
[2012.03.19 22:58:28 | 000,080,208 | ---- | C] () -- C:\Windows\System32\iglhxs32.vp
[2012.03.19 22:26:08 | 000,145,804 | ---- | C] () -- C:\Windows\System32\igcompkrng600.bin
[2012.03.19 22:26:06 | 000,963,912 | ---- | C] () -- C:\Windows\System32\igkrng600.bin
[2012.03.19 22:26:06 | 000,261,208 | ---- | C] () -- C:\Windows\System32\igfcg600m.bin
[2012.03.19 22:25:58 | 000,058,880 | ---- | C] () -- C:\Windows\System32\igdde32.dll
[2012.03.19 21:21:14 | 013,212,672 | ---- | C] () -- C:\Windows\System32\ig4icd32.dll
[2012.03.19 21:12:48 | 000,144,790 | ---- | C] () -- C:\Windows\System32\Gfxres.ro-RO.resources
[2012.03.19 21:12:46 | 000,139,901 | ---- | C] () -- C:\Windows\System32\Gfxres.hr-HR.resources
[2012.03.19 21:12:46 | 000,125,306 | ---- | C] () -- C:\Windows\System32\Gfxres.zh-TW.resources
[2012.03.19 21:12:46 | 000,123,778 | ---- | C] () -- C:\Windows\System32\Gfxres.zh-CN.resources
[2012.03.19 21:12:44 | 000,221,877 | ---- | C] () -- C:\Windows\System32\Gfxres.th-TH.resources
[2012.03.19 21:12:44 | 000,143,564 | ---- | C] () -- C:\Windows\System32\Gfxres.tr-TR.resources
[2012.03.19 21:12:44 | 000,141,854 | ---- | C] () -- C:\Windows\System32\Gfxres.sv-SE.resources
[2012.03.19 21:12:42 | 000,192,378 | ---- | C] () -- C:\Windows\System32\Gfxres.ru-RU.resources
[2012.03.19 21:12:42 | 000,140,548 | ---- | C] () -- C:\Windows\System32\Gfxres.sk-SK.resources
[2012.03.19 21:12:42 | 000,136,850 | ---- | C] () -- C:\Windows\System32\Gfxres.sl-SI.resources
[2012.03.19 21:12:40 | 000,143,112 | ---- | C] () -- C:\Windows\System32\Gfxres.pt-BR.resources
[2012.03.19 21:12:40 | 000,142,079 | ---- | C] () -- C:\Windows\System32\Gfxres.pt-PT.resources
[2012.03.19 21:12:40 | 000,141,421 | ---- | C] () -- C:\Windows\System32\Gfxres.pl-PL.resources
[2012.03.19 21:12:38 | 000,147,116 | ---- | C] () -- C:\Windows\System32\Gfxres.ko-KR.resources
[2012.03.19 21:12:38 | 000,142,797 | ---- | C] () -- C:\Windows\System32\Gfxres.nl-NL.resources
[2012.03.19 21:12:38 | 000,136,778 | ---- | C] () -- C:\Windows\System32\Gfxres.nb-NO.resources
[2012.03.19 21:12:36 | 000,162,150 | ---- | C] () -- C:\Windows\System32\Gfxres.ja-JP.resources
[2012.03.19 21:12:36 | 000,148,461 | ---- | C] () -- C:\Windows\System32\Gfxres.it-IT.resources
[2012.03.19 21:12:36 | 000,142,606 | ---- | C] () -- C:\Windows\System32\Gfxres.hu-HU.resources
[2012.03.19 21:12:34 | 000,157,713 | ---- | C] () -- C:\Windows\System32\Gfxres.he-IL.resources
[2012.03.19 21:12:34 | 000,144,267 | ---- | C] () -- C:\Windows\System32\Gfxres.fr-FR.resources
[2012.03.19 21:12:34 | 000,140,949 | ---- | C] () -- C:\Windows\System32\Gfxres.fi-FI.resources
[2012.03.19 21:12:32 | 000,208,522 | ---- | C] () -- C:\Windows\System32\Gfxres.el-GR.resources
[2012.03.19 21:12:32 | 000,146,125 | ---- | C] () -- C:\Windows\System32\Gfxres.es-ES.resources
[2012.03.19 21:12:32 | 000,146,008 | ---- | C] () -- C:\Windows\System32\Gfxres.de-DE.resources
[2012.03.19 21:12:30 | 000,164,821 | ---- | C] () -- C:\Windows\System32\Gfxres.ar-SA.resources
[2012.03.19 21:12:30 | 000,141,297 | ---- | C] () -- C:\Windows\System32\Gfxres.cs-CZ.resources
[2012.03.19 21:12:30 | 000,136,261 | ---- | C] () -- C:\Windows\System32\Gfxres.da-DK.resources
[2012.03.19 21:12:22 | 000,131,674 | ---- | C] () -- C:\Windows\System32\Gfxres.en-US.resources
[2012.03.19 21:11:22 | 000,009,216 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2012.03.19 21:09:28 | 000,000,264 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2012.03.19 21:09:08 | 001,921,265 | ---- | C] () -- C:\Windows\System32\iglhxa32.cpa
[2012.03.19 21:09:08 | 000,094,208 | ---- | C] () -- C:\Windows\System32\IccLibDll.dll
[2012.03.19 21:09:08 | 000,059,594 | ---- | C] () -- C:\Windows\System32\iglhxc32.vp
[2012.03.19 21:09:08 | 000,059,384 | ---- | C] () -- C:\Windows\System32\iglhxc32_dev.vp
[2012.03.19 21:09:08 | 000,059,328 | ---- | C] () -- C:\Windows\System32\iglhxg32_dev.vp
[2012.03.19 21:09:08 | 000,059,215 | ---- | C] () -- C:\Windows\System32\iglhxo32_dev.vp
[2012.03.19 21:09:08 | 000,058,781 | ---- | C] () -- C:\Windows\System32\iglhxo32.vp
[2012.03.19 21:09:08 | 000,058,684 | ---- | C] () -- C:\Windows\System32\iglhxg32.vp
[2012.03.19 21:09:08 | 000,001,074 | ---- | C] () -- C:\Windows\System32\iglhxa32.vp
[2010.11.21 01:46:14 | 000,653,928 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2010.11.21 01:46:14 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2010.11.21 01:46:14 | 000,129,800 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2010.11.21 01:46:14 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2010.11.20 22:29:26 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe

========== ZeroAccess Check ==========

[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 22:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >



ESET Log:

ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=12
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=97206b8cac1e69449988079e3006b1e2
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-11-18 09:52:51
# local_time=2012-11-18 10:52:51 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 2597649 2597649 0 0
# compatibility_mode=5893 16776573 100 94 42720 104902715 0 0
# compatibility_mode=8192 67108863 100 0 4647 4647 0 0
# scanned=142556
# found=6
# cleaned=0
# scan_time=4068
C:\Users\Patrick\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\738cd4bb-675ba20a a variant of Win32/Kryptik.AOPO trojan (unable to clean) 00000000000000000000000000000000 I
C:\Users\Patrick\AppData\Roaming\AcroIEHelpe231.dll Win32/Spy.Banker.YRG trojan (unable to clean) 00000000000000000000000000000000 I
F:\Filme\Filmchen\arkanum\Magma swingt im Lustschloss Arkanum.exe a variant of MSIL/Injector.ANA trojan (unable to clean) 00000000000000000000000000000000 I
F:\Filme\Filmchen\gr\Magma swingt im Lustschloss Arkanum gr.exe a variant of MSIL/Injector.ANA trojan (unable to clean) 00000000000000000000000000000000 I
F:\Wichtige Dokumente\p\Software\Babylon_Uebersetzer\Babylon8_setup.exe a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I
F:\Wichtige Dokumente\p\Software\pdf\PDF-Creator\PDFCreator-1_2_1_setup.exe Win32/Toolbar.Widgi application (unable to clean) 00000000000000000000000000000000 I

Alt 21.11.2012, 18:43   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 - Standard

TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8



Hallo und

Zitat:
Ich habe eine Hand voll Pfade aus den Logs aus privaten Gründen gekürzt,
Was hast du da gekürzt? Nur Namen unkenntlich gemacht? Bitte beschreiben
__________________

__________________

Alt 21.11.2012, 19:26   #3
paddy83
 
TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 - Standard

TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8



Hallo,

ich habe aus dem OLT-Log, im Abschnitt " Files/Folders - Created Within 360 Days" und im Abschnitt " Files - Modified Within 360 Days" ein paar Pfade gekürzt.
Beispiel:
[2012.09.24 21:24:40 | 000,159,468 | ---- | C] () -- !!!Hier fehlt der Pfad zu einer persönlichen Datei !!!


Gruß

Patrick
__________________

Alt 21.11.2012, 20:14   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 - Standard

TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8



Derartige Zensuraktionen sind kontraproduktiv, du solltest nur private Infos wie komplette Vor- und Nachnamen unkenntlich machen
__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 21.11.2012, 20:23   #5
paddy83
 
TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 - Standard

TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8



Ok, das nächste mal werde ich anders vorgehen.
Im Endeffekt macht es an der Stelle ja keinen Unterschied ob ich einen Pfad aus xxxe oder ihn Lösche, ungültig ist er in jedem Fall. Egal, ich werde das zukünftig beachten


Alt 22.11.2012, 11:05   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 - Standard

TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8



Bitte nun Logs mit GMER (<<< klick für Anleitung) und aswMBR (Anleitung etwas weiter unten) erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim zweiten Mal nicht will, lass es einfach weg und führ nur aswMBR aus.

aswMBR-Download => aswMBR.exe - speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe Vista und Win7 User mit Rechtsklick "als Admininstartor starten"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.
__________________
--> TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8

Antwort

Themen zu TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8
administrator, adobe, antivir, application/pdf:, autorun, avg, avira, bho, defender, downloader, explorer, firefox, flash player, format, helper, installation, logfile, mozilla, opera, programme, realtek, registry, scan, software, tracker, trojan



Ähnliche Themen: TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8


  1. TR/Crypt.EPACK.Gen8 in C:\Users\***\AppData\Roaming\45E4CC\45E4CC.exe
    Plagegeister aller Art und deren Bekämpfung - 27.03.2013 (14)
  2. TR/Crypt.EPACK.Gen2
    Plagegeister aller Art und deren Bekämpfung - 03.01.2013 (5)
  3. TR/Crypt.EPACK.Gen2
    Plagegeister aller Art und deren Bekämpfung - 19.12.2012 (9)
  4. TR/Crypt.EPACK.Gen2 auf dem pc
    Plagegeister aller Art und deren Bekämpfung - 19.12.2012 (7)
  5. TR/Crypt.EPACK.Gen2
    Plagegeister aller Art und deren Bekämpfung - 13.12.2012 (6)
  6. Avira findet TR/Spy.Banker.Gen8 und TR/Crypt.EPACK.Gen2 - wie werd ich die wieder los?
    Log-Analyse und Auswertung - 14.11.2012 (8)
  7. TR/Crypt.EPACK.Gen2
    Log-Analyse und Auswertung - 06.11.2012 (18)
  8. Verschlüsselungstrojaner noch auf PC? (TR/Crypt.EPACK.Gen8, wroui.dll)
    Plagegeister aller Art und deren Bekämpfung - 07.10.2012 (3)
  9. TR/Crypt.EPACK.Gen2 - Trojaner
    Plagegeister aller Art und deren Bekämpfung - 26.09.2012 (2)
  10. TR/Crypt.EPACK.Gen2
    Plagegeister aller Art und deren Bekämpfung - 22.09.2012 (5)
  11. Avira findet TR/Crypt.ZPACK.Gen8, TR/Vcaredrix.A.3 und Tr/Crpyt.EPACK.Gen8
    Plagegeister aller Art und deren Bekämpfung - 30.08.2012 (21)
  12. TR/Crypt.EPACK.Gen8, TR/Crypt.XPACK.Gen, TR/Vcaredrix.A.3 und einige EXP/CVE-xx, EXP/2010-xx Viren.
    Plagegeister aller Art und deren Bekämpfung - 26.07.2012 (7)
  13. TR/Crypt.XPACK.Gen8 - TR/Crypt.EPACK.Gen2 - TR/ATRAPS.Gen
    Plagegeister aller Art und deren Bekämpfung - 10.07.2012 (18)
  14. Virus TR/Crypt.EPACK.Gen8' [trojan] > Daten verschlüsselt
    Plagegeister aller Art und deren Bekämpfung - 19.06.2012 (1)
  15. TR/Crypt.EPACK.Gen2 gefunden!
    Plagegeister aller Art und deren Bekämpfung - 17.12.2011 (13)
  16. TR/Crypt.EPACK.Gen2
    Plagegeister aller Art und deren Bekämpfung - 15.12.2011 (17)
  17. TR/Crypt.EPACK.Gen2
    Plagegeister aller Art und deren Bekämpfung - 12.01.2011 (10)

Zum Thema TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 - Hallo zusammen, ich mir wohl u.a. durch Anschluss einer externen HDD mit älteren Daten ein paar Plagegeister eingefangen. Da waren wohl in einigen "Jugendsünden" noch ein paar Überraschungen versteckt. MBAM - TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8...
Archiv
Du betrachtest: TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.