Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Trojaner aus Email-Anhang

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 10.04.2013, 16:23   #1
foxyyy
 
Trojaner aus Email-Anhang - Standard

Trojaner aus Email-Anhang



Hallo zusammen,

meine Mutter hat sich auf ihrem Rechner scheinbar ein schönes Paket von Trojanern extrahiert. Sie hat den Anhang einer Email geöffnet, da sie reingelegt wurde, dass dies eine Rechnung sei.
Danach hatte sie Update-Probleme mit Avira Antivir. Offensichtlich haben sich die Trojaner im Firefox Browser in ihren GMX Email Account eingeloggt und Spam Emails versendet. Sie hat diverse Mailer-Daemons erhalten. Avira Antivir hat ein knappes Dutzend Trojanische Pferde identifiziert und in Quarantäne verschoben. Dinge wie online Banking und Amazon Accounts hat meine Mutter bereits sperren lassen.


OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 10.04.2013 16:23:34 - Run 3
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Marion\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,86 Gb Total Physical Memory | 1,28 Gb Available Physical Memory | 44,89% Memory free
5,71 Gb Paging File | 3,71 Gb Available in Paging File | 64,93% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 72,69 Gb Total Space | 15,45 Gb Free Space | 21,25% Space Free | Partition Type: NTFS
Drive D: | 205,87 Gb Total Space | 174,67 Gb Free Space | 84,84% Space Free | Partition Type: NTFS
 
Computer Name: MARION-PC | User Name: Marion | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013.04.01 15:31:17 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Marion\Downloads\OTL.exe
PRC - [2013.03.28 21:55:47 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2013.03.28 21:55:31 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2013.03.28 21:55:30 | 000,345,312 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2013.03.22 06:07:18 | 000,093,072 | ---- | M] (TomTom) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2013.03.22 06:07:16 | 000,248,208 | ---- | M] (TomTom) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2013.03.09 23:10:20 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.10.17 19:29:53 | 000,684,024 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
PRC - [2012.10.17 19:29:39 | 000,544,248 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
PRC - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010.08.17 23:55:42 | 005,732,992 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
PRC - [2010.06.09 18:55:54 | 001,080,448 | ---- | M] (asus) -- C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
PRC - [2010.05.03 23:45:50 | 000,182,912 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
PRC - [2010.05.03 23:41:46 | 000,170,624 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
PRC - [2009.12.15 19:39:38 | 000,096,896 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
PRC - [2009.10.01 04:34:22 | 002,314,240 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009.10.01 04:33:08 | 000,262,144 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009.07.31 19:38:24 | 000,305,720 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
PRC - [2009.06.19 19:29:42 | 000,105,016 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
PRC - [2009.06.19 19:29:26 | 002,488,888 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
PRC - [2009.06.16 02:30:42 | 000,084,536 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
PRC - [2008.12.23 02:15:34 | 000,174,648 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2013.03.09 23:10:20 | 003,069,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2013.02.13 23:16:46 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll
MOD - [2013.01.10 15:32:24 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\302207b4fa3083899fd8ab4db98cecc5\System.Management.ni.dll
MOD - [2013.01.10 15:06:40 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll
MOD - [2013.01.10 15:06:09 | 014,340,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll
MOD - [2013.01.10 15:05:46 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll
MOD - [2013.01.10 15:05:43 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll
MOD - [2013.01.10 15:05:33 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll
MOD - [2013.01.10 15:05:27 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
MOD - [2013.01.10 15:05:23 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll
MOD - [2013.01.10 15:05:22 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
MOD - [2013.01.10 15:05:14 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2012.10.17 19:30:22 | 000,062,968 | ---- | M] () -- C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
MOD - [2010.02.24 00:14:22 | 000,071,680 | ---- | M] () -- C:\Program Files (x86)\ASUS\ControlDeck\Brightness.dll
MOD - [2010.02.24 00:14:18 | 000,041,472 | ---- | M] () -- C:\Program Files (x86)\ASUS\ControlDeck\HelpFunc.dll
MOD - [2010.02.24 00:14:10 | 000,050,688 | ---- | M] () -- C:\Program Files (x86)\ASUS\ControlDeck\P4GControl.dll
MOD - [2010.02.24 00:12:22 | 000,186,880 | ---- | M] () -- C:\Program Files (x86)\ASUS\ControlDeck\Resolution.dll
MOD - [2010.02.24 00:11:46 | 000,076,288 | ---- | M] () -- C:\Program Files (x86)\ASUS\ControlDeck\Volume.dll
MOD - [2009.08.04 11:50:05 | 000,110,592 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationCore.resources\3.0.0.0_de_31bf3856ad364e35\PresentationCore.resources.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2010.06.22 20:20:42 | 000,379,520 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Windows\SysNative\FBAgent.exe -- (AFBAgent)
SRV:64bit: - [2010.03.05 19:26:38 | 001,425,168 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2010.03.05 19:07:58 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2010.03.05 19:06:22 | 000,831,760 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2013.03.28 21:55:47 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013.03.28 21:55:31 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2013.03.22 06:07:18 | 000,093,072 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2013.03.14 00:20:16 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.03.09 23:10:20 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.11.09 12:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.10.17 19:29:39 | 000,544,248 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe -- (vpnagent)
SRV - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010.10.09 01:52:04 | 000,332,272 | ---- | M] (Google Inc.) [Disabled | Stopped] -- C:\ProgramData\Partner\Partner.exe -- (Partner Service)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.12.15 19:39:38 | 000,096,896 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
SRV - [2009.10.01 04:34:22 | 002,314,240 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009.10.01 04:33:08 | 000,262,144 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009.06.16 02:30:42 | 000,084,536 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe -- (ASLDRService)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.05.14 18:07:14 | 000,759,048 | ---- | M] (ABBYY) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)
SRV - [2009.04.23 13:20:14 | 000,031,744 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\RWTH OpenVPN Client\bin\openvpnserv.exe -- (OpenVPNService)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2013.03.28 21:55:54 | 000,130,016 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2013.03.28 21:55:54 | 000,100,712 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2013.03.28 21:55:54 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2012.10.17 19:13:36 | 000,027,048 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpnva64.sys -- (vpnva)
DRV:64bit: - [2012.10.17 19:11:37 | 000,107,432 | R--- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acsock64.sys -- (acsock)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.10 22:28:18 | 012,311,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011.10.01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011.10.01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011.10.01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011.10.01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011.03.23 17:20:32 | 000,030,720 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tapoas.sys -- (tapoas)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 11:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010.07.21 07:33:49 | 000,129,024 | ---- | M] (ELAN Microelectronic Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2010.06.18 19:38:06 | 000,039,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDKMD.sys -- (wdkmd)
DRV:64bit: - [2010.03.18 07:21:58 | 007,680,512 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64)
DRV:64bit: - [2010.02.26 10:32:11 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010.02.25 05:26:57 | 000,115,312 | ---- | M] (JMicron Technology Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\JME.sys -- (JME)
DRV:64bit: - [2010.02.03 00:38:29 | 000,271,872 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010.01.18 11:45:49 | 000,717,368 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2009.09.17 21:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009.08.20 04:41:37 | 001,800,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\snp2uvc.sys -- (SNP2UVC)
DRV:64bit: - [2009.08.18 10:23:31 | 000,143,472 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR)
DRV:64bit: - [2009.08.06 23:24:13 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.07.20 11:29:39 | 000,015,416 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbfiltr.sys -- (kbfiltr)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.20 04:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009.06.18 21:18:10 | 000,015,928 | ---- | M] (Windows (R) Win 7 DDK provider) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\lullaby.sys -- (lullaby)
DRV:64bit: - [2009.06.10 22:35:57 | 000,056,832 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SiSG664.sys -- (SiSGbeLH)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009.05.13 18:07:20 | 000,015,928 | ---- | M] (ASUS) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ATK64AMD.sys -- (MTsensor)
DRV:64bit: - [2008.10.08 07:15:12 | 000,029,696 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2008.05.24 02:27:28 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV:64bit: - [2008.05.16 12:33:06 | 000,158,760 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mdm.sys -- (s0016mdm)
DRV:64bit: - [2008.05.16 12:33:06 | 000,151,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016unic.sys -- (s0016unic)
DRV:64bit: - [2008.05.16 12:33:06 | 000,137,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mgmt.sys -- (s0016mgmt)
DRV:64bit: - [2008.05.16 12:33:06 | 000,136,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016obex.sys -- (s0016obex)
DRV:64bit: - [2008.05.16 12:33:06 | 000,034,344 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016nd5.sys -- (s0016nd5)
DRV:64bit: - [2008.05.16 12:33:04 | 000,019,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mdfl.sys -- (s0016mdfl)
DRV:64bit: - [2008.05.16 12:32:56 | 000,115,240 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016bus.sys -- (s0016bus)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009.07.03 02:36:14 | 000,015,416 | ---- | M] (ASUS) [Kernel | Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.ask.com?o=15003&l=dis
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=SPC2&o=15000&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=PV&apn_dtid=YYYYYYYYDE&apn_uid=273D7526-4DAA-4E18-831F-F098A9FC3836&apn_sauid=1D8674CE-46B2-44DF-9617-434AA1B15827
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "gmx.de"
FF - prefs.js..extensions.enabledAddons: win32-64%40anonymous.org:0.1
FF - prefs.js..extensions.enabledAddons: ich%40maltegoetz.de:1.4.8
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: win32-64@anonymous.org:0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011.03.23 20:58:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011.03.23 20:58:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.09 23:10:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.03.09 23:10:17 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.09 23:10:20 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.03.09 23:10:17 | 000,000,000 | ---D | M]
 
[2013.03.31 15:21:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marion\AppData\Roaming\mozilla\Extensions
[2013.03.31 15:21:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marion\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2013.04.09 18:45:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marion\AppData\Roaming\mozilla\Firefox\Profiles\mm369dl9.default\extensions
[2013.04.09 18:45:26 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Marion\AppData\Roaming\mozilla\Firefox\Profiles\mm369dl9.default\extensions\ich@maltegoetz.de
[2013.02.14 13:21:40 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Marion\AppData\Roaming\mozilla\firefox\profiles\mm369dl9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.10.02 10:47:46 | 000,001,836 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\mozilla\firefox\profiles\mm369dl9.default\searchplugins\leo-deu-ita.xml
[2013.03.09 23:10:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2013.03.09 23:10:16 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013.03.09 23:10:16 | 000,000,000 | ---D | M] (Facebook Connect) -- C:\Program Files (x86)\mozilla firefox\extensions\{9a4e42f4-ee19-467a-ad67-3c31ed29837b}
[2013.03.09 23:10:16 | 000,000,000 | ---D | M] (Win32+64) -- C:\Program Files (x86)\mozilla firefox\extensions\win32-64@anonymous.org
[2013.03.09 23:10:20 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.01.17 18:46:16 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.08.14 01:01:18 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.31 12:26:24 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.08.14 01:01:18 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.08.14 01:01:18 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.08.14 01:01:18 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.08.14 01:01:18 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.08.11 02:29:51 | 000,000,994 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.94.0.1	client.openvpn.net
O1 - Hosts: 127.94.0.2	openvpn-client.us.shieldexchange.com
O2:64bit: - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner64.dll (Google Inc.)
O2 - BHO: (Facebook Connect) - {11DCAFD6-DDBA-4ADA-998B-996B7B691AE0} - C:\Users\Marion\AppData\Roaming\FBConnect\IE\FBConnect.dll (Facebook Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll (Google Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKCU..\Run: [EPSON SX125 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGGE.EXE /FU "C:\Windows\TEMP\E_S6279.tmp" /EF "HKCU" File not found
O4 - HKCU..\Run: [playmvideo] "C:\Users\Marion\AppData\Roaming\playmvideo.exe" -autorun File not found
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4A7DD8F9-7F40-4345-ABC7-76B19E425DE2}: NameServer = 62.220.18.8 89.246.64.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{869122B7-BB77-4799-B361-F33131F31EC7}: DhcpNameServer = 134.130.4.1 134.130.5.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.03.31 15:23:32 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\Downloaded Installations
[2013.03.31 15:21:52 | 000,000,000 | ---D | C] -- C:\Users\Marion\Documents\TomTom
[2013.03.31 15:21:50 | 000,000,000 | ---D | C] -- C:\ProgramData\TomTom
[2013.03.31 15:21:39 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\TomTom
[2013.03.31 15:21:39 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\TomTom
[2013.03.31 15:21:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TomTom
[2013.03.31 15:21:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TomTom International B.V
[2013.03.31 15:21:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TomTom HOME 2
[2013.03.31 14:45:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TomTom DesktopSuite
[2013.03.28 21:56:20 | 000,130,016 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2013.03.28 21:56:20 | 000,100,712 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2013.03.28 21:56:20 | 000,028,600 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2013.03.24 13:08:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2008.08.12 06:45:20 | 000,155,648 | ---- | C] (ASUS) -- C:\Program Files (x86)\Common Files\MSIactionall.dll
[4 C:\Users\Marion\Documents\*.tmp files -> C:\Users\Marion\Documents\*.tmp -> ]
[1 C:\Users\Marion\Desktop\*.tmp files -> C:\Users\Marion\Desktop\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.04.10 16:20:49 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.04.10 16:20:49 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.04.10 16:19:02 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.04.10 16:18:26 | 001,529,274 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.04.10 16:18:26 | 000,669,644 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.04.10 16:18:26 | 000,621,156 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.04.10 16:18:26 | 000,135,170 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.04.10 16:18:26 | 000,111,086 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.04.10 16:13:25 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.04.10 16:13:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.04.10 16:13:01 | 2299,965,440 | -HS- | M] () -- C:\hiberfil.sys
[2013.04.09 18:32:01 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.04.01 15:29:57 | 000,000,000 | ---- | M] () -- C:\Users\Marion\defogger_reenable
[2013.03.28 21:55:54 | 000,130,016 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2013.03.28 21:55:54 | 000,100,712 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2013.03.28 21:55:54 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[4 C:\Users\Marion\Documents\*.tmp files -> C:\Users\Marion\Documents\*.tmp -> ]
[1 C:\Users\Marion\Desktop\*.tmp files -> C:\Users\Marion\Desktop\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.04.01 15:29:57 | 000,000,000 | ---- | C] () -- C:\Users\Marion\defogger_reenable
[2012.02.01 23:48:02 | 000,094,775 | R-S- | C] () -- C:\Users\Marion\AppData\Roaming\igfxtray.dat
[2012.01.10 22:27:26 | 000,867,020 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2012.01.10 22:27:26 | 000,128,204 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2012.01.10 22:27:26 | 000,105,608 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2012.01.10 21:29:54 | 013,904,384 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011.06.13 16:05:38 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.05.14 23:05:15 | 000,000,000 | ---- | C] () -- C:\Users\Marion\AppData\Local\{0E2F1BAA-88A4-4385-A5DF-75D91B0C869C}
[2011.01.25 15:50:21 | 000,003,584 | ---- | C] () -- C:\Users\Marion\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.04.08 19:31:56 | 000,106,496 | ---- | C] () -- C:\Program Files (x86)\Common Files\CPInstallAction.dll
[2008.05.22 17:35:54 | 000,051,962 | ---- | C] () -- C:\Program Files (x86)\Common Files\banner.jpg
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013.02.22 22:55:05 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Apsio
[2011.01.12 12:23:36 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Asus WebStorage
[2011.01.25 14:12:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\EeeStorageUploader
[2011.04.22 14:35:53 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Epson
[2011.01.12 12:22:16 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\FBConnect
[2013.02.22 19:36:24 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Iscyib
[2012.02.01 23:47:46 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\MicroST
[2011.12.26 16:11:44 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\MyPhoneExplorer
[2013.02.22 14:21:34 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Obuqd
[2013.02.23 13:31:51 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Roabn
[2013.04.05 21:18:39 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\SoftGrid Client
[2013.03.31 15:21:39 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\TomTom
[2013.02.03 01:08:54 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\TP
[2013.02.22 19:36:24 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Wyud
 
========== Purity Check ==========
 
 

< End of report >
         
--- --- ---


OTL Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 01.04.2013 15:33:26 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Marion\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,86 Gb Total Physical Memory | 1,85 Gb Available Physical Memory | 64,67% Memory free
5,71 Gb Paging File | 4,11 Gb Available in Paging File | 72,06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 72,69 Gb Total Space | 17,21 Gb Free Space | 23,68% Space Free | Partition Type: NTFS
Drive D: | 205,87 Gb Total Space | 174,67 Gb Free Space | 84,84% Space Free | Partition Type: NTFS
 
Computer Name: MARION-PC | User Name: Marion | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{DA8CFE4C-E69A-4616-A900-124540C30917}" = lport=8182 | protocol=6 | dir=in | name=java(tm) platform se binary | 
"{E270D8E8-C23E-4C91-BBCF-C2161428AE45}" = lport=5353 | protocol=17 | dir=in | name=java(tm) platform se binary | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02F9E8C1-5818-4B3D-A38E-011475F8B081}" = dir=in | app=c:\program files (x86)\intel corporation\intel wireless display\widiapp.exe | 
"{073DD3CA-4177-4EFE-852E-FC5F54716162}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe | 
"{0D5E7867-E5E1-4D33-A6AE-B3D12D5E3F1D}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe | 
"{1764983A-678B-4A9B-BA35-EAF1679E088A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1DF7335E-A36E-4F2C-B24D-5D82CC42CEC3}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{272F3E88-61B3-4DCE-9971-6C6A40DF8FE6}" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe | 
"{2BDF8430-79C1-4A1E-B47F-C8AD2304CF8C}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{2E9473FC-6D44-4B03-BA01-0BFB408DDE77}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{3018D7FD-93F8-4824-B985-FBD8FA938B0C}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | 
"{32DB47EF-C854-4A22-825E-9753C14C7233}" = protocol=6 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe | 
"{47223510-06B6-4F8A-9344-4753B74F5892}" = protocol=6 | dir=in | app=c:\program files (x86)\sopcast\sopcast.exe | 
"{484C9E73-AE90-4ADF-B216-6E28A5ADC787}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{49C6D52F-8FC8-441B-83E1-4032A5A64E6D}" = protocol=6 | dir=in | app=c:\program files (x86)\sopcast\adv\sopadver.exe | 
"{6455A3B2-5EE9-4DB2-BEC2-5579C0012E60}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe | 
"{79FEAA26-262B-4C59-869C-C6D52D4481ED}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe | 
"{7ADB67BC-EF41-4D61-9C3C-E0910EF92B10}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd cinema\powerdvdcinema.exe | 
"{7D846FAA-4B74-4C72-964F-0D40572F8769}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | 
"{8097FB7B-3D9C-4603-B4EE-80DFFE1ECD3F}" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe | 
"{89433613-9E6D-44AD-B028-117BEEE40B8F}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | 
"{9E5DBBE2-993E-4D71-A62F-60E137C63263}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 
"{A825EF39-62C8-47FC-993F-0203CD23ECA0}" = protocol=17 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe | 
"{AA3376A5-F7A5-4A7B-9E7E-7D8FDF95E676}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe | 
"{B9B6406A-05A5-4DF0-9167-07132C243B8D}" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe | 
"{C20630D4-434B-4118-825D-01A71DE2DF1E}" = protocol=17 | dir=in | app=c:\program files (x86)\sopcast\adv\sopadver.exe | 
"{C44D3A69-8385-410F-8F49-DAD62F6174D6}" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe | 
"{FBC57777-FB67-49A0-A96E-020DAD1CB762}" = protocol=17 | dir=in | app=c:\program files (x86)\sopcast\sopcast.exe | 
"TCP Query User{0A081515-9D5B-474F-898C-7A5FD60AB112}C:\users\marion\appdata\roaming\roabn\abry.exe" = protocol=6 | dir=in | app=c:\users\marion\appdata\roaming\roabn\abry.exe | 
"TCP Query User{0A825A85-79F9-4C5D-AC16-69D653A3568A}C:\program files (x86)\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\sopcast\adv\sopadver.exe | 
"TCP Query User{2C9CBAF5-FE9A-41E3-B9E1-937B64E1AC98}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe | 
"TCP Query User{3547B793-0AD0-4C59-87E5-B36E0F644A6F}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | 
"TCP Query User{6564ED02-4220-435F-8C2B-D3C9809C16FF}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe | 
"TCP Query User{A4B4EECC-C5AF-41CC-AA02-E3793A2CE53E}C:\program files (x86)\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files (x86)\sopcast\sopcast.exe | 
"TCP Query User{E37D077F-EC67-4DF9-B640-31AD6B25D9A8}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe | 
"TCP Query User{FFDC56B5-91F9-48DD-97C6-C9D3E84D76FE}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe | 
"UDP Query User{0DAAC95B-718F-4118-A02F-F053070F70F7}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe | 
"UDP Query User{1EBA2CB2-7984-465A-BE51-563AC32B7ECB}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe | 
"UDP Query User{2370D2A4-7BA1-4FB7-95BE-77CCBAF20E3B}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe | 
"UDP Query User{7ECCA540-AF95-4DF4-894C-FB841EE2ED72}C:\program files (x86)\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\sopcast\adv\sopadver.exe | 
"UDP Query User{99F62D00-2590-4BD7-8806-A7E6353F5DDB}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe | 
"UDP Query User{9FD99139-7C5D-4799-819F-4831D2498E12}C:\users\marion\appdata\roaming\roabn\abry.exe" = protocol=17 | dir=in | app=c:\users\marion\appdata\roaming\roabn\abry.exe | 
"UDP Query User{BCA23606-1808-45E2-BD0A-1B24427B26FD}C:\program files (x86)\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files (x86)\sopcast\sopcast.exe | 
"UDP Query User{FF27DA29-4620-4384-BC7C-9D6EE1F26415}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4300" = Canon iP4300
"{13F4A7F3-EABC-4261-AF6B-1317777F0755}" = Fast Boot
"{1A8BA6CE-822D-4888-89E2-ACBF4308F271}" = Intel(R) PROSet/Wireless WiFi Software
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6CFB1B20-ECAE-488F-9FFB-6AD420882E71}" = iTunes
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{91EFE3A1-585E-4F66-B5F6-F118F56C4C47}" = ASUS Power4Gear Hybrid
"{C298FF86-AB23-4B58-AC53-A23383C07B3A}" = Intel(R) Wireless Display
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CNXT_AUDIO_HDA" = Conexant HD Audio
"Elantech" = ETDWare PS/2-x64 7.0.5.13_WHQL
"EPSON SX125 Series" = Druckerdeinstallation für EPSON SX125 Series
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"ProInst" = Intel PROSet Wireless
"USB2.0 UVC VGA WebCam" = USB2.0 UVC VGA WebCam
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}" = ASUS AI Recovery
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = ASUS Video Magic
"{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}" = Wireless Console 3
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 22
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{34B32B70-8081-11E2-89AF-B8AC6F98CCE3}" = Google Earth Plug-in
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5B65EF64-1DFA-414A-8C94-7BB726158E21}" = ControlDeck
"{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{69BCC264-0D43-469F-8434-31E738982E7B}" = Cisco AnyConnect Secure Mobility Client
"{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}" = ASUS CopyProtect
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{95140000-00AF-0407-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{96DCEE2F-98EE-4F80-8C0F-7C04D1FB9D7F}" = JMicron Ethernet Adapter NDIS Driver
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D48531D-2135-49FC-BC29-ACCDA5396A76}" = ASUS MultiFrame
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.2 MUI
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
"{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaShow Espresso
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{EC5F4C1B-F838-4CB7-8561-8F809296428B}" = TomTom HOME
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint
"7-Zip" = 7-Zip 9.20
"ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ASUS WebStorage" = ASUS WebStorage
"Avira AntiVir Desktop" = Avira Free Antivirus
"CameraWindowDC8" = Canon Utilities CameraWindow DC 8
"CameraWindowLauncher" = Canon Utilities CameraWindow Launcher
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon iP4300 Benutzerregistrierung" = Canon iP4300 Benutzerregistrierung
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"Canon Setup Utility 2.3" = Canon Setup Utility 2.3
"Cisco AnyConnect Secure Mobility Client" = Cisco AnyConnect Secure Mobility Client 
"DivX Setup" = DivX-Setup
"DVD Shrink DE_is1" = DVD Shrink 3.2 deutsch (DeCSS-frei)
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-PrintToolBox" = Canon Utilities Easy-PrintToolBox
"EPSON Scanner" = EPSON Scan
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = ASUS Video Magic
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
"InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaShow Espresso
"K_Series_ScreenSaver_EN" = K_Series_ScreenSaver_EN
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"MovieUploaderForYouTube" = Canon Utilities Movie Uploader for YouTube
"Mozilla Firefox 19.0.2 (x86 de)" = Mozilla Firefox 19.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MPE" = MyPhoneExplorer
"MyCamera" = Canon Utilities MyCamera
"MyCamera Download Plugin" = CANON iMAGE GATEWAY MyCamera Download Plugin
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"PhotoStitch" = Canon Utilities PhotoStitch
"RWTH OpenVPN Client" = RWTH OpenVPN Client 2.1_rc15e
"Veetle TV" = Veetle TV 0.9.18
"VLC media player" = VLC media player 1.1.9
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 31.03.2013 11:40:41 | Computer Name = Marion-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 5415590
 
Error - 31.03.2013 11:40:41 | Computer Name = Marion-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5415590
 
Error - 31.03.2013 18:00:52 | Computer Name = Marion-PC | Source = Windows Backup | ID = 4103
Description = 
 
Error - 01.04.2013 08:47:19 | Computer Name = Marion-PC | Source = RasClient | ID = 20227
Description = 
 
Error - 01.04.2013 08:48:40 | Computer Name = Marion-PC | Source = RasClient | ID = 20227
Description = 
 
Error - 01.04.2013 08:50:02 | Computer Name = Marion-PC | Source = RasClient | ID = 20227
Description = 
 
Error - 01.04.2013 09:17:43 | Computer Name = Marion-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 01.04.2013 09:17:43 | Computer Name = Marion-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1660444
 
Error - 01.04.2013 09:17:43 | Computer Name = Marion-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1660444
 
Error - 01.04.2013 09:20:59 | Computer Name = Marion-PC | Source = RasClient | ID = 20227
Description = 
 
Error - 01.04.2013 09:22:20 | Computer Name = Marion-PC | Source = RasClient | ID = 20227
Description = 
 
[ Cisco AnyConnect Secure Mobility Client Events ]
Error - 01.04.2013 09:22:50 | Computer Name = Marion-PC | Source = acvpnagent | ID = 67108866
Description = Function: CNetEnvironment::testNetwork File: .\NetEnvironment.cpp Line:
 772 Invoked Function: CNetEnvironment::IsSGAccessible Return Code: -28966899 (0xFE46000D)
Description:
 NETENVIRONMENT_ERROR_PROBE_INCOMPLETE:Network Probe could not contact target 
 
Error - 01.04.2013 09:22:50 | Computer Name = Marion-PC | Source = acvpnagent | ID = 67108866
Description = Function: CNetEnvironment::TestNetEnv File: .\NetEnvironment.cpp Line:
 225 Invoked Function: CNetEnvironment::testNetwork Return Code: -28966899 (0xFE46000D)
Description:
 NETENVIRONMENT_ERROR_PROBE_INCOMPLETE:Network Probe could not contact target 
 
Error - 01.04.2013 09:23:11 | Computer Name = Marion-PC | Source = acvpnagent | ID = 67108866
Description = Function: CNetEnvironment::analyzeHttpResponse File: .\NetEnvironment.cpp
Line:
 1509 Invoked Function: CCertHelper::VerifyServerCertificate Return Code: -31391706
 (0xFE210026) Description: CERTIFICATE_ERROR_VERIFY_POLICY_FAILED:Certificate failed
 a policy check server name: vpn-unidsl.rwth-aachen.de
 
Error - 01.04.2013 09:23:13 | Computer Name = Marion-PC | Source = acvpnagent | ID = 67108866
Description = Function: CHttpProbeAsync::OnOpenRequestComplete File: .\IP\HttpProbeAsync.cpp
Line:
 303 Invoked Function: CHttpSessionAsync::OnOpenRequestComplete Return Code: -31588307
 (0xFE1E002D) Description: SOCKETTRANSPORT_ERROR_CONNECT_CANCELED:An asynchronous
 connection has been canceled during its initiation. 
 
Error - 01.04.2013 09:23:13 | Computer Name = Marion-PC | Source = acvpnagent | ID = 67108866
Description = Function: CNetEnvironment::TestAccessToSG File: .\NetEnvironment.cpp
Line:
 1323 Invoked Function: CNetEnvironment::analyzeHttpResponse Return Code: -28966899
 (0xFE46000D) Description: NETENVIRONMENT_ERROR_PROBE_INCOMPLETE:Network Probe could
 not contact target 
 
Error - 01.04.2013 09:23:13 | Computer Name = Marion-PC | Source = acvpnagent | ID = 67108866
Description = Function: CNetEnvironment::testNetwork File: .\NetEnvironment.cpp Line:
 772 Invoked Function: CNetEnvironment::IsSGAccessible Return Code: -28966899 (0xFE46000D)
Description:
 NETENVIRONMENT_ERROR_PROBE_INCOMPLETE:Network Probe could not contact target 
 
Error - 01.04.2013 09:23:43 | Computer Name = Marion-PC | Source = acvpnagent | ID = 67108866
Description = Function: CNetEnvironment::analyzeHttpResponse File: .\NetEnvironment.cpp
Line:
 1509 Invoked Function: CCertHelper::VerifyServerCertificate Return Code: -31391706
 (0xFE210026) Description: CERTIFICATE_ERROR_VERIFY_POLICY_FAILED:Certificate failed
 a policy check server name: vpn-unidsl.rwth-aachen.de
 
Error - 01.04.2013 09:23:45 | Computer Name = Marion-PC | Source = acvpnagent | ID = 67108866
Description = Function: CHttpProbeAsync::OnOpenRequestComplete File: .\IP\HttpProbeAsync.cpp
Line:
 303 Invoked Function: CHttpSessionAsync::OnOpenRequestComplete Return Code: -31588307
 (0xFE1E002D) Description: SOCKETTRANSPORT_ERROR_CONNECT_CANCELED:An asynchronous
 connection has been canceled during its initiation. 
 
Error - 01.04.2013 09:23:45 | Computer Name = Marion-PC | Source = acvpnagent | ID = 67108866
Description = Function: CNetEnvironment::TestAccessToSG File: .\NetEnvironment.cpp
Line:
 1323 Invoked Function: CNetEnvironment::analyzeHttpResponse Return Code: -28966899
 (0xFE46000D) Description: NETENVIRONMENT_ERROR_PROBE_INCOMPLETE:Network Probe could
 not contact target 
 
Error - 01.04.2013 09:23:45 | Computer Name = Marion-PC | Source = acvpnagent | ID = 67108866
Description = Function: CNetEnvironment::testNetwork File: .\NetEnvironment.cpp Line:
 772 Invoked Function: CNetEnvironment::IsSGAccessible Return Code: -28966899 (0xFE46000D)
Description:
 NETENVIRONMENT_ERROR_PROBE_INCOMPLETE:Network Probe could not contact target 
 
[ Media Center Events ]
Error - 08.10.2012 17:30:03 | Computer Name = Marion-PC | Source = MCUpdate | ID = 0
Description = 23:29:55 - Fehler beim Herstellen der Internetverbindung.  23:29:55 
-     Serververbindung konnte nicht hergestellt werden..  
 
Error - 15.10.2012 05:22:10 | Computer Name = Marion-PC | Source = MCUpdate | ID = 0
Description = 11:22:10 - Fehler beim Herstellen der Internetverbindung.  11:22:10 
-     Serververbindung konnte nicht hergestellt werden..  
 
Error - 15.10.2012 05:22:23 | Computer Name = Marion-PC | Source = MCUpdate | ID = 0
Description = 11:22:16 - Fehler beim Herstellen der Internetverbindung.  11:22:16 
-     Serververbindung konnte nicht hergestellt werden..  
 
Error - 20.10.2012 11:00:48 | Computer Name = Marion-PC | Source = MCUpdate | ID = 0
Description = 17:00:48 - Fehler beim Herstellen der Internetverbindung.  17:00:48 
-     Serververbindung konnte nicht hergestellt werden..  
 
Error - 20.10.2012 11:01:01 | Computer Name = Marion-PC | Source = MCUpdate | ID = 0
Description = 17:00:53 - Fehler beim Herstellen der Internetverbindung.  17:00:53 
-     Serververbindung konnte nicht hergestellt werden..  
 
Error - 25.10.2012 08:37:18 | Computer Name = Marion-PC | Source = MCUpdate | ID = 0
Description = 14:37:18 - Fehler beim Herstellen der Internetverbindung.  14:37:18 
-     Serververbindung konnte nicht hergestellt werden..  
 
Error - 25.10.2012 08:37:28 | Computer Name = Marion-PC | Source = MCUpdate | ID = 0
Description = 14:37:23 - Fehler beim Herstellen der Internetverbindung.  14:37:23 
-     Serververbindung konnte nicht hergestellt werden..  
 
Error - 27.10.2012 07:32:38 | Computer Name = Marion-PC | Source = MCUpdate | ID = 0
Description = 13:32:37 - Fehler beim Herstellen der Internetverbindung.  13:32:38 
-     Serververbindung konnte nicht hergestellt werden..  
 
Error - 27.10.2012 07:32:51 | Computer Name = Marion-PC | Source = MCUpdate | ID = 0
Description = 13:32:43 - Fehler beim Herstellen der Internetverbindung.  13:32:43 
-     Serververbindung konnte nicht hergestellt werden..  
 
Error - 04.11.2012 06:22:39 | Computer Name = Marion-PC | Source = MCUpdate | ID = 0
Description = 11:22:34 - Fehler beim Herstellen der Internetverbindung.  11:22:34 
-     Serververbindung konnte nicht hergestellt werden..  
 
[ System Events ]
Error - 24.03.2013 04:40:14 | Computer Name = Marion-PC | Source = Service Control Manager | ID = 7043
Description = Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements
 nicht richtig heruntergefahren werden.
 
Error - 24.03.2013 12:21:11 | Computer Name = Marion-PC | Source = DCOM | ID = 10010
Description = 
 
Error - 28.03.2013 09:42:48 | Computer Name = Marion-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10003
Description = Das WLAN-Erweiterungsmodul wurde unerwartet beendet.    Modulpfad: C:\Windows\System32\IWMSSvc.dll

 
Error - 28.03.2013 16:05:04 | Computer Name = Marion-PC | Source = Service Control Manager | ID = 7022
Description = Der Dienst "Windows Update" wurde nicht richtig gestartet.
 
Error - 30.03.2013 12:13:34 | Computer Name = Marion-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 31.03.2013 08:43:37 | Computer Name = Marion-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 31.03.2013 08:43:37 | Computer Name = Marion-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 31.03.2013 08:43:38 | Computer Name = Marion-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 31.03.2013 09:24:56 | Computer Name = Marion-PC | Source = Service Control Manager | ID = 7034
Description = Dienst "TomTomHOMEService" wurde unerwartet beendet. Dies ist bereits
 1 Mal passiert.
 
Error - 31.03.2013 09:25:00 | Computer Name = Marion-PC | Source = Service Control Manager | ID = 7030
Description = Der Dienst "TomTomHOMEService" ist als interaktiver Dienst gekennzeichnet.
 Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich
 sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
 
 
< End of report >
         
--- --- ---


GMER Logfile:
Code:
ATTFilter
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-04-10 17:10:55
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST932032 rev.0003 298,09GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Marion\AppData\Local\Temp\uxdiypod.sys


---- User code sections - GMER 2.1 ----

.text   C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE[3156] C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE!?SparseBitMask@DataSourceDescription@FlexUI@@2HB + 961  000000002d945985 3 bytes [AC, D5, 60]
.text   C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE[3156] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                     0000000075f61465 2 bytes [F6, 75]
.text   C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE[3156] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                    0000000075f614bb 2 bytes [F6, 75]
.text   ...                                                                                                                                                                                                                                   * 2
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                                                000000007786f9c0 5 bytes JMP 000000016b545f49
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtQueryObject                                                                                          000000007786f9d8 5 bytes JMP 000000016b546411
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtOpenKey                                                                                              000000007786fa08 5 bytes JMP 000000016b54016d
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtEnumerateValueKey                                                                                    000000007786fa20 5 bytes JMP 000000016b53fbca
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtQueryKey                                                                                             000000007786fa70 5 bytes JMP 000000016b53fa44
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtQueryValueKey                                                                                        000000007786fa88 2 bytes JMP 000000016b53fb52
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtQueryValueKey + 3                                                                                    000000007786fa8b 2 bytes [CD, F3]
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtCreateKey                                                                                            000000007786fb20 5 bytes JMP 000000016b540424
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile                                                                                   000000007786fc18 5 bytes JMP 000000016b544369
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtEnumerateKey                                                                                         000000007786fd2c 5 bytes JMP 000000016b53f9cc
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                                             000000007786fd44 5 bytes JMP 000000016b544959
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtQueryDirectoryFile                                                                                   000000007786fd78 5 bytes JMP 000000016b5439de
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtDuplicateObject                                                                                      000000007786fe24 5 bytes JMP 000000016b545fc4
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile                                                                                  000000007786fe3c 5 bytes JMP 000000016b544adb
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                                                           0000000077870094 5 bytes JMP 000000016b544791
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtSetValueKey                                                                                          00000000778701a4 5 bytes JMP 000000016b53fc42
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtDeleteFile                                                                                           00000000778709c4 5 bytes JMP 000000016b544584
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtDeleteKey                                                                                            00000000778709dc 5 bytes JMP 000000016b53cc5b
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtDeleteValueKey                                                                                       0000000077870a24 5 bytes JMP 000000016b53cd29
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtFlushKey                                                                                             0000000077870b60 5 bytes JMP 000000016b53ccc2
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtNotifyChangeKey                                                                                      0000000077870f50 5 bytes JMP 000000016b53fcba
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtNotifyChangeMultipleKeys                                                                             0000000077870f68 5 bytes JMP 000000016b53ff45
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtOpenKeyEx                                                                                            0000000077870ff8 5 bytes JMP 000000016b5401fd
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile                                                                              000000007787131c 5 bytes JMP 000000016b544b6b
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtQueryMultipleValueKey                                                                                000000007787145c 5 bytes JMP 000000016b53fec9
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtQuerySecurityObject                                                                                  0000000077871508 5 bytes JMP 000000016b546389
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtRenameKey                                                                                            00000000778716f8 1 byte JMP 000000016b53d138
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtRenameKey + 2                                                                                        00000000778716fa 3 bytes {JMP 0xfffffffff3ccba40}
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationKey                                                                                    0000000077871a38 5 bytes JMP 000000016b53facc
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtSetSecurityObject                                                                                    0000000077871b7c 5 bytes JMP 000000016b54616c
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                                                                      0000000075f8103d 5 bytes JMP 000000016b5193a9
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                                                                      0000000075f81072 5 bytes JMP 000000016b5194e7
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                                                                                0000000075fac9b5 5 bytes JMP 000000016b51971d
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\kernel32.dll!SetDllDirectoryW                                                                                    00000000760000c3 5 bytes JMP 000000016b519efe
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\kernel32.dll!SetDllDirectoryA                                                                                    000000007600016b 5 bytes JMP 000000016b51a231
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\kernel32.dll!WinExec                                                                                             0000000076002c91 5 bytes JMP 000000016b519aa0
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\kernel32.dll!AllocConsole                                                                                        0000000076026b3e 5 bytes JMP 000000016b547431
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\kernel32.dll!AttachConsole                                                                                       0000000076026c02 5 bytes JMP 000000016b547443
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                                    00000000761b2aa4 5 bytes JMP 000000016b51a43c
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                                       0000000075348a29 5 bytes JMP 000000016b547419
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\USER32.dll!CreateWindowExA                                                                                       000000007534d22e 5 bytes JMP 000000016b547401
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\GDI32.dll!AddFontResourceW                                                                                       0000000075d7d2b2 5 bytes JMP 000000016b527617
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\GDI32.dll!AddFontResourceA                                                                                       0000000075d7d7bb 5 bytes JMP 000000016b5275fb
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ADVAPI32.dll!EnumDependentServicesW                                                                              00000000751b1e3a 7 bytes JMP 000000016b52a3b9
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ADVAPI32.dll!EnumServicesStatusExW                                                                               00000000751bb466 7 bytes JMP 000000016b52b2da
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ADVAPI32.dll!GetServiceKeyNameW                                                                                  00000000751d78ff 7 bytes JMP 000000016b52aa60
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ADVAPI32.dll!GetServiceDisplayNameW                                                                              00000000751d79bb 7 bytes JMP 000000016b52ac11
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ADVAPI32.dll!EnumServicesStatusExA                                                                               00000000751da3e2 7 bytes JMP 000000016b52b3a0
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                                                                00000000751f2538 5 bytes JMP 000000016b51985f
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ADVAPI32.dll!GetServiceKeyNameA                                                                                  0000000075211b94 7 bytes JMP 000000016b52ab18
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ADVAPI32.dll!GetServiceDisplayNameA                                                                              0000000075211c31 7 bytes JMP 000000016b52acc9
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ADVAPI32.dll!EnumServicesStatusA                                                                                 0000000075212021 7 bytes JMP 000000016b52b21c
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ADVAPI32.dll!EnumDependentServicesA                                                                              0000000075212104 7 bytes JMP 000000016b52a470
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ADVAPI32.dll!EnumServicesStatusW                                                                                 0000000075212221 5 bytes JMP 000000016b52b15e
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!ControlService                                                                                       0000000075e24d5c 7 bytes JMP 000000016b52a1fe
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!CloseServiceHandle                                                                                   0000000075e24dc3 7 bytes JMP 000000016b52a527
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!QueryServiceStatus                                                                                   0000000075e24e4b 7 bytes JMP 000000016b52a28a
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!QueryServiceStatusEx                                                                                 0000000075e24eaf 7 bytes JMP 000000016b52a31d
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!StartServiceW                                                                                        0000000075e24f35 7 bytes JMP 000000016b52a079
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!StartServiceA                                                                                        0000000075e2508d 7 bytes JMP 000000016b52a10f
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!QueryServiceObjectSecurity                                                                           0000000075e250f4 7 bytes JMP 000000016b52b02c
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity                                                                             0000000075e25181 7 bytes JMP 000000016b52b0c8
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA                                                                                 0000000075e25254 7 bytes JMP 000000016b52a728
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW                                                                                 0000000075e253d5 7 bytes JMP 000000016b52a643
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A                                                                                0000000075e254c2 7 bytes JMP 000000016b52a9ca
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W                                                                                0000000075e255e2 7 bytes JMP 000000016b52a934
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                                                                                       0000000075e2567c 3 bytes JMP 000000016b529e5b
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 4                                                                                   0000000075e25680 3 bytes [F5, CC, CC]
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                                                                                       0000000075e2589f 7 bytes JMP 000000016b529d85
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!DeleteService                                                                                        0000000075e25a22 7 bytes JMP 000000016b52a5b5
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigA                                                                                  0000000075e25a83 7 bytes JMP 000000016b52ae5b
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW                                                                                  0000000075e25b29 7 bytes JMP 000000016b52adc2
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA                                                                                    0000000075e25ca0 7 bytes JMP 000000016b529535
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!ControlServiceExW                                                                                    0000000075e25d8c 7 bytes JMP 000000016b5294bc
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!OpenSCManagerW                                                                                       0000000075e263ad 7 bytes JMP 000000016b529a83
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!OpenSCManagerA                                                                                       0000000075e264f0 7 bytes JMP 000000016b529b0f
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfig2A                                                                                 0000000075e26633 7 bytes JMP 000000016b52af90
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfig2W                                                                                 0000000075e2680c 7 bytes JMP 000000016b52aef4
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!OpenServiceW                                                                                         0000000075e2714b 7 bytes JMP 000000016b529bf8
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\SysWOW64\sechost.dll!OpenServiceA                                                                                         0000000075e27245 7 bytes JMP 000000016b529c84
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!CoRegisterPSClsid                                                                                      000000007562c56e 5 bytes JMP 000000016b5311c4
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!CoResumeClassObjects + 7                                                                               000000007562ea09 7 bytes JMP 000000016b531795
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!OleRun                                                                                                 00000000756307de 5 bytes JMP 000000016b531650
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!CoRegisterClassObject                                                                                  00000000756321e1 5 bytes JMP 000000016b5322c5
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!OleUninitialize                                                                                        000000007563eba1 6 bytes JMP 000000016b53156f
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!OleInitialize                                                                                          000000007563efd7 5 bytes JMP 000000016b5314ff
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!CoGetPSClsid                                                                                           00000000756426b9 5 bytes JMP 000000016b53133c
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!CoGetClassObject                                                                                       00000000756554ad 5 bytes JMP 000000016b532853
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!CoInitializeEx                                                                                         00000000756609ad 5 bytes JMP 000000016b5313af
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!CoUninitialize                                                                                         00000000756686d3 5 bytes JMP 000000016b531431
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                                       0000000075669d0b 5 bytes JMP 000000016b533b21
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx                                                                                     0000000075669d4e 5 bytes JMP 000000016b531c5c
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!CoSuspendClassObjects + 7                                                                              000000007568bb09 7 bytes JMP 000000016b5316c0
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!CoRevokeClassObject                                                                                    00000000756aeacf 5 bytes JMP 000000016b530c21
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!CoGetInstanceFromFile                                                                                  00000000756e340b 5 bytes JMP 000000016b532d13
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\ole32.dll!OleRegEnumFormatEtc                                                                                    000000007572cfd9 5 bytes JMP 000000016b5315da
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\oleaut32.dll!RegisterActiveObject                                                                                0000000075ed279e 5 bytes JMP 000000016b530eb4
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\oleaut32.dll!RevokeActiveObject                                                                                  0000000075ed3294 5 bytes JMP 000000016b530fd5
.text   C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe[2112] C:\Windows\syswow64\oleaut32.dll!GetActiveObject                                                                                     0000000075ee8f40 5 bytes JMP 000000016b531048

---- Threads - GMER 2.1 ----

Thread  C:\Windows\System32\spoolsv.exe [1404:764]                                                                                                                                                                                            000007fef85810c8
Thread  C:\Windows\System32\spoolsv.exe [1404:1956]                                                                                                                                                                                           000007fef8546144
Thread  C:\Windows\System32\spoolsv.exe [1404:3104]                                                                                                                                                                                           000007fef8215fd0
Thread  C:\Windows\System32\spoolsv.exe [1404:3108]                                                                                                                                                                                           000007fef8113438
Thread  C:\Windows\System32\spoolsv.exe [1404:3112]                                                                                                                                                                                           000007fef82163ec
Thread  C:\Windows\System32\spoolsv.exe [1404:3124]                                                                                                                                                                                           000007fef8b05e5c
Thread  C:\Windows\System32\spoolsv.exe [1404:3128]                                                                                                                                                                                           000007fef8b85074
Thread  C:\Windows\System32\spoolsv.exe [1404:3408]                                                                                                                                                                                           000000000038e0bc
Thread  C:\Windows\System32\spoolsv.exe [1404:3132]                                                                                                                                                                                           00000000003881fc

---- Registry - GMER 2.1 ----

Reg     HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind                                                                                              \Device\{45C528B0-EDA6-43CA-8F5F-02430A2EEBDF}?\Device\{368D2B9E-0377-43C8-A6D8-F51114621404}?\Device\{34218AF1-048B-4B5A-A67F-5CBEE06E530B}?\Device\{0C17FECA-90C2-4EA4-B8D1-7F10B55ADD12}?\Device\{EEED9EBC-A496-43FE-9985-1B3491C500A2}?
Reg     HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route                                                                                             "{45C528B0-EDA6-43CA-8F5F-02430A2EEBDF}"?"{368D2B9E-0377-43C8-A6D8-F51114621404}"?"{34218AF1-048B-4B5A-A67F-5CBEE06E530B}"?"{0C17FECA-90C2-4EA4-B8D1-7F10B55ADD12}"?"{EEED9EBC-A496-43FE-9985-1B3491C500A2}"?
Reg     HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export                                                                                            \Device\TCPIP6TUNNEL_{45C528B0-EDA6-43CA-8F5F-02430A2EEBDF}?\Device\TCPIP6TUNNEL_{368D2B9E-0377-43C8-A6D8-F51114621404}?\Device\TCPIP6TUNNEL_{34218AF1-048B-4B5A-A67F-5CBEE06E530B}?\Device\TCPIP6TUNNEL_{0C17FECA-90C2-4EA4-B8D1-7F10B55ADD12}?\Device\TCPIP6TUNNEL_{EEED9EBC-A496-43FE-9985-1B3491C500A2}?
Reg     HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{0C17FECA-90C2-4EA4-B8D1-7F10B55ADD12}@InterfaceName                                                                                                                isatap.{60D90CC8-F5CA-4B17-88F4-BD0166CB77D2}
Reg     HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{0C17FECA-90C2-4EA4-B8D1-7F10B55ADD12}@ReusableType                                                                                                                 0

---- EOF - GMER 2.1 ----
         
--- --- ---


Vielen herzlichen Dank schon mal für eure Hilfe!

 

Themen zu Trojaner aus Email-Anhang
7-zip, avira, bho, bonjour, browser, desktop, email, error, failed, fehler, firefox, flash player, format, gmx.de, google, helper, home, install.exe, logfile, microsoft office starter 2010, mozilla, ntdll.dll, ntopenkeyex, plug-in, registry, rundll, scan, security, software, trojaner, trojaner email anhang spam daemon, trojanische pferde, tunnel, visual studio, windows




Ähnliche Themen: Trojaner aus Email-Anhang


  1. DHL-Trojaner-EMail mit PDF-Anhang geöffnet
    Log-Analyse und Auswertung - 17.05.2015 (7)
  2. Anhang (zip) von gefälschter Email geöffnet - Trojaner eingefangen?
    Plagegeister aller Art und deren Bekämpfung - 13.05.2015 (1)
  3. Email - Win32/Kryptik.CSHO Trojaner im Anhang - kritisch?
    Antiviren-, Firewall- und andere Schutzprogramme - 28.12.2014 (3)
  4. Anhang von falscher Zalando-Email geöffnet, Virus oder Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 18.11.2014 (11)
  5. Anhang in einer Email geöffnet, Zip-Datei ausversehen ausgeführt, jetzt deutliche Leistungseinbußen, Trojaner
    Plagegeister aller Art und deren Bekämpfung - 24.07.2014 (13)
  6. Windows 8.1 32bit Email der Anwalt Ebay GmbH Anhang geöffnet -> Trojaner?
    Log-Analyse und Auswertung - 09.07.2014 (13)
  7. Email von Michael Friedrich<sonnengitta@web.de> enthält Anhang Rechnung-April.exe mit Trojaner Artemis!
    Plagegeister aller Art und deren Bekämpfung - 06.04.2014 (5)
  8. Email von Michael Friedrich<sonnengitta@web.de> enthält Anhang Rechnung-April.exe mit Trojaner Artemis!
    Plagegeister aller Art und deren Bekämpfung - 04.04.2014 (1)
  9. MAC OSX 10.7.5 Trojaner.GenericKD. Email-ZIP-Anhang geöffnet.
    Plagegeister aller Art und deren Bekämpfung - 03.10.2013 (3)
  10. Windows 7: Trojaner o.ä. aus eMail Anhang
    Log-Analyse und Auswertung - 06.09.2013 (13)
  11. WIN32/Trustezeb.C Trojaner im Email Anhang
    Log-Analyse und Auswertung - 28.06.2013 (8)
  12. Anhang von Fake-Groupon-Email geöffnet - Trojaner
    Log-Analyse und Auswertung - 11.03.2013 (11)
  13. Email-Anhang (.zip Datei) geöffnet; Gefälschte Email über Mahngebühren
    Log-Analyse und Auswertung - 25.02.2013 (19)
  14. Verschlüsselungs-Trojaner Trojan.Ransomlock.P durch Anhang einer Email-Mahnung
    Log-Analyse und Auswertung - 14.06.2012 (4)
  15. verschlüsselungs-trojaner über email anhang eingefangen
    Log-Analyse und Auswertung - 30.05.2012 (2)
  16. Ukash Trojaner in email-Anhang
    Log-Analyse und Auswertung - 30.04.2012 (5)
  17. email anhang
    Plagegeister aller Art und deren Bekämpfung - 06.01.2004 (3)

Zum Thema Trojaner aus Email-Anhang - Hallo zusammen, meine Mutter hat sich auf ihrem Rechner scheinbar ein schönes Paket von Trojanern extrahiert. Sie hat den Anhang einer Email geöffnet, da sie reingelegt wurde, dass dies eine - Trojaner aus Email-Anhang...
Archiv
Du betrachtest: Trojaner aus Email-Anhang auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.