Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Ist mein PC Sauber? (https://www.trojaner-board.de/111376-pc-sauber.html)

RoXii 13.03.2012 11:03

Ist mein PC Sauber?
 
Hallo,

Und zwar möchte ich gerne wissen ob mein PC Trojaner und Viren frei ist. Ich habe Windows 7 64bit Edition.

Ich poste jetzt mal den DDS log + Attach

Code:

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 1.6.0_31
Run by Robin at 10:54:53 on 2012-03-13
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4095.2497 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\taskhost.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{D246AA05-B192-4ADE-9E16-6595A44BBE02} : DhcpNameServer = 192.168.0.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
IE-X64: {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://de.ask.com/?l=dis&o=102869&gct=hp
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.3&q=
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-3-8 44768]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-3-2 2348352]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-2-9 382272]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\system32\DRIVERS\ManyCam_x64.sys --> C:\Windows\system32\DRIVERS\ManyCam_x64.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
.
=============== Created Last 30 ================
.
.
==================== Find3M  ====================
.
2012-03-08 22:17:23        414368        ----a-w-        C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-03-07 04:59:34        55384        ----a-w-        C:\Windows\System32\drivers\SBREDrv.sys
2012-03-07 01:52:04        472808        ----a-w-        C:\Windows\SysWow64\deployJava1.dll
2012-03-07 00:15:19        41184        ----a-w-        C:\Windows\avastSS.scr
2012-03-07 00:04:06        819032        ----a-w-        C:\Windows\System32\drivers\aswSnx.sys
2012-03-07 00:02:20        53080        ----a-w-        C:\Windows\System32\drivers\aswRdr2.sys
2012-03-07 00:01:52        69976        ----a-w-        C:\Windows\System32\drivers\aswMonFlt.sys
2012-03-05 09:24:47        175616        ----a-w-        C:\Windows\System32\msclmd.dll
2012-03-05 09:24:47        152576        ----a-w-        C:\Windows\SysWow64\msclmd.dll
2012-03-02 11:04:51        283200        ----a-w-        C:\Windows\System32\drivers\dtsoftbus01.sys
2012-03-02 09:24:38        178800        ----a-w-        C:\Windows\SysWow64\CmdLineExt_x64.dll
2012-02-24 09:36:50        230952        ----a-w-        C:\Windows\System32\drivers\PCTSD64.sys
2012-02-23 08:18:36        279656        ------w-        C:\Windows\System32\MpSigStub.exe
2012-02-10 03:14:04        6074176        ----a-w-        C:\Windows\System32\nvcpl.dll
2012-02-10 03:14:01        3089728        ----a-w-        C:\Windows\System32\nvsvc64.dll
2012-02-10 03:07:03        2561856        ----a-w-        C:\Windows\System32\nvsvcr.dll
2012-02-10 03:07:00        889664        ----a-w-        C:\Windows\System32\nvvsvc.exe
2012-02-10 03:07:00        63296        ----a-w-        C:\Windows\System32\nvshext.dll
2012-02-10 03:07:00        118080        ----a-w-        C:\Windows\System32\nvmctray.dll
2012-02-10 03:05:59        2497985        ----a-w-        C:\Windows\System32\nvcoproc.bin
2012-02-09 19:05:44        416064        ----a-w-        C:\Windows\SysWow64\nvStreaming.exe
2012-01-17 12:46:01        31040        ----a-w-        C:\Windows\System32\nvhdap64.dll
2012-01-17 12:45:56        188224        ----a-w-        C:\Windows\System32\drivers\nvhda64v.sys
2012-01-17 12:45:55        1451840        ----a-w-        C:\Windows\System32\nvhdagenco6420103.dll
2012-01-14 04:06:27        3145728        ----a-w-        C:\Windows\System32\win32k.sys
2012-01-04 10:44:20        509952        ----a-w-        C:\Windows\System32\ntshrui.dll
2012-01-04 08:58:41        442880        ----a-w-        C:\Windows\SysWow64\ntshrui.dll
2012-01-03 07:03:12        810496        ----a-w-        C:\Windows\System32\xvidcore.dll
2012-01-03 07:03:12        80896        ----a-w-        C:\Windows\System32\ff_vfw.dll
2012-01-03 07:03:12        183808        ----a-w-        C:\Windows\System32\xvidvfw.dll
2012-01-03 07:03:10        389120        ----a-w-        C:\Windows\SysWow64\actskn43.ocx
2012-01-03 07:03:10        389120        ----a-w-        C:\Windows\System32\actskn43.ocx
2011-12-30 06:26:08        515584        ----a-w-        C:\Windows\System32\timedate.cpl
2011-12-30 05:27:56        478720        ----a-w-        C:\Windows\SysWow64\timedate.cpl
2011-12-28 03:59:24        498688        ----a-w-        C:\Windows\System32\drivers\afd.sys
2011-12-16 08:46:06        634880        ----a-w-        C:\Windows\System32\msvcrt.dll
2011-12-16 07:52:58        690688        ----a-w-        C:\Windows\SysWow64\msvcrt.dll
.
============= FINISH: 10:55:52,69 ===============



Attach:

Code:

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 02.03.2012 09:13:31
System Uptime: 12.03.2012 19:50:37 (15 hours ago)
.
Motherboard: ASUSTeK Computer INC. |  | M4A88TD-V EVO/USB3
Processor: AMD Phenom(tm) II X4 965 Processor | AM3 | 792/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 217 GiB total, 123,889 GiB free.
D: is FIXED (NTFS) - 106 GiB total, 21,553 GiB free.
E: is CDROM (UDF)
F: is CDROM ()
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description:
Device ID: NUSB3\ROOT_HUB30\5&36403F85&0
Manufacturer:
Name:
PNP Device ID: NUSB3\ROOT_HUB30\5&36403F85&0
Service:
.
==== System Restore Points ===================
.
RP24: 08.03.2012 02:48:56 - Windows Update
RP25: 09.03.2012 03:00:12 - Windows Update
RP26: 13.03.2012 02:37:04 - Windows Update
.
==== Installed Programs ======================
.
avast! Free Antivirus
Camtasia Studio 7
DAEMON Tools Lite
Die Sims™ 3
Die Sims™ 3 Einfach tierisch
FlashPeak SlimBrowser
Google Chrome
Grand Theft Auto IV
ICQ7.7
IrfanView (remove only)
Java Auto Updater
Java(TM) 6 Update 31
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft WSE 3.0 Runtime
Mozilla Firefox 10.0.2 (x86 de)
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
PhotoScape
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870)
Skype™ 5.8
SplitCam
Spybot - Search & Destroy
TRFormersMOD
TRFormersMOD - CLOTHES
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WinRAR 4.11 (32-Bit)
.
==== End Of File ===========================



Ich hoffe ihr könnt mir helfen!
PS. ich habe Avast Vollversion.
:-)
und spybot search und destroy


Mit freundlichen Grüßen

Roxii

cosinus 13.03.2012 18:32

Warum willst du das wissen? Gibt es irgendwelche Vorgeschichten zu diesem System?

RoXii 13.03.2012 20:42

hi

Nicht unbedingt,
aber in letzter zeit habe ich eine ASK toolbar gehabt!
Und das ist doch ein virus oder?

Ich kriege die seite im Firefox als Starseite nicht mehr raus :(
In google chrome hab ich sie rausbekommen.


Und wie sieht mein log aus? ist mein pc sauber?

EDIT: ich habe auch manchmal ein paar cookies die ich finde!!
Die mich verfolgen.

Könnt ihr mir sagen ob mein pc komplett viren frei ist?
PS..


Ich habe einen trainer mal verwendet, um in Games zu cheaten...
aber das mache ich nun nicht mehr...
könnt ihr mal nachgucken ob da ein trojaner drauf ist auf meinem pc?





Mfg
RoXii

cosinus 14.03.2012 14:55

Zitat:

aber in letzter zeit habe ich eine ASK toolbar gehabt!
Und das ist doch ein virus oder?
Findest du sowas nicht über Google raus :balla:
Eine Toolbar ist kein Virus, wenn überhaupt ist das unnötiger Ballast, Crapware, nich gewollte Software (PUP)
Du musst mal genauer lesen wenn du irgendwelche Setups startest, viele Programmsetups installieren diesen Mist einfach mit!

Zitat:

EDIT: ich habe auch manchmal ein paar cookies die ich finde!!
Die mich verfolgen.
Ja und? Cookies sind keine Schädlinge!

Zitat:

Ich habe einen trainer mal verwendet, um in Games zu cheaten...
aber das mache ich nun nicht mehr...
Eine weise Entscheidung diese Dinger NICHT mehr zu verwenden

Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

RoXii 14.03.2012 22:24

hi

habe nun malewarebytes ausgeführt, und er hat das hier gefunden:
log

Code:

Malwarebytes Anti-Malware (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.14.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Robin :: ROBIN-PC [Administrator]

Schutz: Aktiviert

14.03.2012 20:11:48
mbam-log-2012-03-14 (20-11-48).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 360229
Laufzeit: 34 Minute(n), 35 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 4
C:\Users\Robin\Desktop\DEViATED.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Robin\Downloads\Firefox_Setup_10.0.2.exe (Trojan.FakeFireFox) -> Erfolgreich gelöscht und in Quarantäne gestellt.
D:\DEViATED.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
D:\Neuer Ordner\Neuer Ordner (2)\Neuer Ordner\hauptverzeichniss\3. VERZEICHNIS ( Ordner 05 )\WEB.DE_Firefox_Setup.exe (Trojan.FakeFireFox) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

EDIT: Deviated.exe war mein trainer den ich jetzt nie wieder benutzen werde!!! Mein Pc soll ja sauber sein


hilfe trojaner aber da steht ja das sie jetzt weg sind, heißt das es ist alles wieder ok?


Eset :

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=3381d60fa6a437469b443b2b35ba6938
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-03-14 08:59:10
# local_time=2012-03-14 09:59:10 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 48175 83386210 0 0
# compatibility_mode=8192 67108863 100 0 3729 3729 0 0
# scanned=166190
# found=0
# cleaned=0
# scan_time=2390


MFG Roxii:crazy:

cosinus 14.03.2012 22:26

Zitat:

C:\Users\Robin\Desktop\DEViATED.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Robin\Downloads\Firefox_Setup_10.0.2.exe (Trojan.FakeFireFox) -> Erfolgreich gelöscht und in Quarantäne gestellt.
D:\DEViATED.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Was bitte soll das sein :balla: wo hast du DEViATED.exe her?
Und von wo hast du den Firefox runtergeladen?

RoXii 14.03.2012 22:33

hi cosinus
danke für deine schnelle antwort,

ich habe den trainer von einer webseite die ich nicht mehr weiß :(

Die meinten der Trainer wäre in Ordnung und es ist normal das dass Anti viren programm anschlägt.

da es dateien verändert im Spiel ordner oder so damit man god mode bekommt und unendlich munition.

Firefox habe ich glaube von chip
es wundert mich so weil bei chip habe ich immer nur gute software bekommen keine viren oder trojaner

nochmal edit:

ich lass ab nun die finger von trainern...
man weiss ja nie was man doch installiert wenn man die .exe klickt.

EDIT2 : darf ich hier links posten? hab grade ein forum gefunden da wird über deviated in englisch diskutiert :D

cosinus 14.03.2012 23:04

Das soll der Trainer sein?

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


RoXii 14.03.2012 23:34

hi hab den scan nun ausgeführ:

Code:

OTL logfile created on: 14.03.2012 23:09:24 - Run 1
OTL by OldTimer - Version 3.2.37.0    Folder = C:\Users\Robin\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,93 Gb Available Physical Memory | 73,18% Memory free
8,00 Gb Paging File | 6,78 Gb Available in Paging File | 84,81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 216,80 Gb Total Space | 108,14 Gb Free Space | 49,88% Space Free | Partition Type: NTFS
Drive D: | 106,45 Gb Total Space | 21,57 Gb Free Space | 20,26% Space Free | Partition Type: NTFS
Drive E: | 7,03 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive G: | 5,12 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
 
Computer Name: ROBIN-PC | User Name: Robin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.03.14 23:07:03 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\Robin\Downloads\OTL.exe
PRC - [2012.03.07 01:15:17 | 004,241,512 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe
PRC - [2012.03.07 01:15:14 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.03.01 01:02:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012.02.29 13:26:46 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.02.28 18:11:20 | 000,018,432 | ---- | M] () -- C:\Users\Robin\AppData\LocalLow\Flagfox\IE\FlagfoxUpdater.exe
PRC - [2012.01.13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.01.13 14:53:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
 
 
========== Modules (No Company Name) ==========
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012.03.07 01:15:14 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012.03.01 01:02:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.02.29 13:26:46 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.02.29 08:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.02.28 18:11:20 | 000,018,432 | ---- | M] () [Auto | Running] -- C:\Users\Robin\AppData\LocalLow\Flagfox\IE\FlagfoxUpdater.exe -- (FlagfoxUpdater)
SRV - [2012.01.13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.08.18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.03.07 01:04:06 | 000,819,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2012.03.07 01:04:04 | 000,337,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2012.03.07 01:02:20 | 000,053,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2012.03.07 01:01:57 | 000,059,224 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2012.03.07 01:01:52 | 000,069,976 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2012.03.07 01:01:32 | 000,024,408 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2012.03.02 12:04:51 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012.01.17 13:45:56 | 000,188,224 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011.12.10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011.09.29 08:04:22 | 000,027,136 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ManyCam_x64.sys -- (ManyCam)
DRV:64bit: - [2011.06.10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.04.27 09:30:52 | 000,184,968 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2009.07.16 04:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 10 2C 97 5B 4D F8 CC 01  [binary data]
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\..\SearchScopes\{31736BAB-7BFB-43A9-BA0D-82651305DB62}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=MYC-ST&o=102869&src=crm&q={searchTerms}&locale=&apn_ptnrs=5J&apn_dtid=YYYYYYYYDE&apn_uid=95fa6c67-9d21-4d3c-b6dd-5e5349787c5e&apn_sauid=B9EEA00D-CC31-4D80-807C-06826F78973D
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://de.ask.com/?l=dis&o=102869&gct=hp"
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.3&q="
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012.03.08 20:09:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.03.02 09:46:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2012.03.02 09:46:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robin\AppData\Roaming\mozilla\Extensions
[2012.03.13 11:16:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robin\AppData\Roaming\mozilla\Firefox\Profiles\sz5n2qep.default\extensions
[2012.03.02 20:44:48 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Robin\AppData\Roaming\mozilla\Firefox\Profiles\sz5n2qep.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.03.13 11:16:43 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\Robin\AppData\Roaming\mozilla\Firefox\Profiles\sz5n2qep.default\extensions\info@flagfox.net
[2012.01.03 16:27:44 | 000,002,333 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\searchplugins\askcom.xml
[2012.03.02 21:24:48 | 000,000,950 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\searchplugins\icqplugin-1.xml
[2011.03.30 14:14:34 | 000,001,042 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\searchplugins\icqplugin.xml
[2012.03.07 02:52:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.03.07 02:52:26 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2012.03.08 20:09:44 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012.02.16 15:55:53 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.02.16 12:02:53 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.02.16 11:48:01 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.16 12:02:53 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.16 12:02:53 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.16 12:02:53 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.16 12:02:53 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Robin\AppData\Local\Google\Chrome\Application\17.0.963.66\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Robin\AppData\Local\Google\Chrome\Application\17.0.963.66\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Robin\AppData\Local\Google\Chrome\Application\17.0.963.66\gcswf32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: AdBlock = C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.20_0\
CHR - Extension: avast! WebRep = C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\
CHR - Extension: Flagfox = C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ildldcbkkbkhnjghnbidklpepakbepnd\4.1.129_0\
CHR - Extension: Google Mail = C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Flagfox) - {A02B5E09-122E-4A2D-B996-D997485B8C9E} - C:\Users\Robin\AppData\LocalLow\Flagfox\IE\Flagfox.dll (Dave G)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3752288333-708083476-1710006870-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-3752288333-708083476-1710006870-1003..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-3752288333-708083476-1710006870-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe (ICQ, LLC.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D246AA05-B192-4ADE-9E16-6595A44BBE02}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.11.15 10:52:50 | 000,161,088 | R--- | M] (Take-Two Interactive Software, Inc.) - E:\Autorun.exe -- [ UDF ]
O32 - AutoRun File - [2008.10.11 18:03:48 | 000,000,054 | R--- | M] () - E:\Autorun.inf -- [ UDF ]
O32 - AutoRun File - [2011.10.06 16:01:16 | 000,000,044 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{6447ef70-6442-11e1-8801-bcaec58adf4a}\Shell - "" = AutoRun
O33 - MountPoints2\{6447ef70-6442-11e1-8801-bcaec58adf4a}\Shell\AutoRun\command - "" = G:\Setup.exe -- [2011.10.06 16:01:18 | 000,355,920 | R--- | M] (Valve Corporation)
O33 - MountPoints2\{a662fb88-643e-11e1-8643-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{a662fb88-643e-11e1-8643-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Autorun.exe -- [2008.11.15 10:52:50 | 000,161,088 | R--- | M] (Take-Two Interactive Software, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
 
MsConfig:64bit - StartUpReg: ICQ - hkey= - key= - C:\Program Files (x86)\ICQ7.7\ICQ.exe (ICQ, LLC.)
MsConfig:64bit - StartUpReg: ManyCam - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: Skype - hkey= - key= - C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig:64bit - StartUpReg: SplitCam - hkey= - key= - C:\Program Files (x86)\SplitCam\SplitCam.exe (SplitCam Co.)
MsConfig:64bit - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig:64bit - StartUpReg: WebcamMaxAutoRun - hkey= - key= -  File not found
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - ff_vfw.dll File not found
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: VIDC.XVID - xvidvfw.dll File not found
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.03.14 21:17:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.03.14 20:10:51 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Malwarebytes
[2012.03.14 20:10:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.03.14 20:10:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.03.14 20:10:46 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.03.14 20:10:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.03.14 03:11:05 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx
[2012.03.14 03:01:14 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\exes
[2012.03.14 03:01:05 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\source
[2012.03.14 02:37:10 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\Skyrim
[2012.03.14 02:37:10 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\My Games
[2012.03.14 02:29:05 | 000,000,000 | ---D | C] -- C:\The Elder Scrolls V- Skyrim
[2012.03.14 02:16:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\The Elder Scrolls V- Skyrim
[2012.03.14 02:02:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2012.03.13 21:37:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2012.03.13 21:33:30 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2012.03.13 21:32:31 | 000,068,928 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2012.03.13 21:32:31 | 000,061,248 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2012.03.13 21:23:12 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2012.03.13 20:59:28 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Driver Cleaner Pro
[2012.03.13 20:59:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Cleaner Pro
[2012.03.13 20:59:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Driver Cleaner Pro
[2012.03.13 11:16:44 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\tiger-k
[2012.03.13 11:16:43 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\Moyea
[2012.03.13 11:16:43 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Moyea
[2012.03.13 11:14:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Moyea
[2012.03.13 11:14:19 | 000,606,208 | ---- | C] (hxxp://www.xvid.org) -- C:\Windows\SysWow64\xvidcore.dll
[2012.03.13 11:14:19 | 000,139,264 | ---- | C] (hxxp://www.xvid.org) -- C:\Windows\SysWow64\xvid.ax
[2012.03.13 11:14:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Moyea
[2012.03.13 06:50:48 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\Originals
[2012.03.13 06:12:50 | 000,000,000 | ---D | C] -- C:\Users\Robin\.thumbnails
[2012.03.13 06:11:14 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\gegl-0.0
[2012.03.13 06:11:14 | 000,000,000 | ---D | C] -- C:\Users\Robin\.gimp-2.6
[2012.03.13 06:09:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP
[2012.03.13 06:09:39 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2012.03.11 22:39:29 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\Neuer Ordner (2)
[2012.03.10 03:21:14 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\Originale vehicle datei!
[2012.03.08 18:10:55 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012.03.08 02:40:10 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\ManyCam
[2012.03.07 23:51:31 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\NVIDIA
[2012.03.07 23:30:00 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\Neuer Ordner
[2012.03.07 17:46:20 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Skype
[2012.03.07 17:46:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012.03.07 17:46:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012.03.07 17:46:04 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2012.03.07 17:46:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2012.03.07 15:28:22 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SplitCam
[2012.03.07 15:28:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SplitCam
[2012.03.07 15:06:34 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\APN
[2012.03.07 15:06:28 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\WebcamMax
[2012.03.07 15:06:28 | 000,000,000 | ---D | C] -- C:\ProgramData\WebcamMax
[2012.03.07 15:01:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7.1.0.0
[2012.03.07 14:09:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Web Solution Mart
[2012.03.07 06:48:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Tools
[2012.03.07 06:42:33 | 000,230,952 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\PCTSD64.sys
[2012.03.07 06:42:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
[2012.03.07 06:41:58 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2012.03.07 06:41:57 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\TestApp
[2012.03.07 06:41:57 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2012.03.07 05:59:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2012.03.07 05:59:35 | 000,055,384 | ---- | C] (Sunbelt Software) -- C:\Windows\SysNative\drivers\SBREDrv.sys
[2012.03.07 05:55:31 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\Sunbelt Software
[2012.03.07 05:53:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2012.03.07 05:09:23 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\gtk-2.0
[2012.03.07 05:05:51 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\.purple
[2012.03.07 05:04:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pidgin
[2012.03.07 02:53:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2012.03.07 02:53:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012.03.07 02:52:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2012.03.07 01:55:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012.03.07 01:55:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012.03.07 01:55:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012.03.06 03:03:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2012.03.05 17:46:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012.03.05 17:46:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2012.03.05 12:53:22 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\SlimBrowser
[2012.03.05 12:53:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlashPeak SlimBrowser
[2012.03.05 12:53:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SlimBrowser
[2012.03.05 10:18:13 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2012.03.05 10:17:52 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders
[2012.03.04 13:12:31 | 000,116,224 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\fms.dll
[2012.03.04 13:11:36 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysWow64\fms.dll
[2012.03.02 23:24:25 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\ICQ
[2012.03.02 20:45:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7.7
[2012.03.02 20:44:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ICQ6Toolbar
[2012.03.02 20:44:47 | 000,000,000 | ---D | C] -- C:\ProgramData\ICQ
[2012.03.02 20:40:22 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\ICQ
[2012.03.02 20:40:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ICQ7.7
[2012.03.02 12:42:27 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\Electronic Arts
[2012.03.02 12:25:21 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\TechSmith
[2012.03.02 12:25:16 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\Camtasia Studio
[2012.03.02 12:24:42 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\QuickTime
[2012.03.02 12:24:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Camtasia Studio 7
[2012.03.02 12:24:40 | 000,000,000 | ---D | C] -- C:\ProgramData\TechSmith
[2012.03.02 12:24:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012.03.02 12:24:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\TechSmith Shared
[2012.03.02 12:24:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TechSmith
[2012.03.02 12:15:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft WSE
[2012.03.02 12:10:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Electronic Arts
[2012.03.02 12:05:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2012.03.02 12:04:51 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2012.03.02 12:04:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite
[2012.03.02 12:04:24 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\DAEMON Tools Lite
[2012.03.02 12:04:22 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2012.03.02 11:54:30 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\WinRAR
[2012.03.02 11:54:30 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012.03.02 11:54:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012.03.02 11:54:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR
[2012.03.02 10:36:09 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\Rockstar Games
[2012.03.02 10:33:36 | 000,000,000 | -HSD | C] -- C:\ProgramData\SecuROM
[2012.03.02 10:29:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.03.02 10:29:46 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.03.02 10:26:00 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\Rockstar Games
[2012.03.02 10:25:17 | 000,000,000 | RH-D | C] -- C:\Users\Robin\AppData\Roaming\SecuROM
[2012.03.02 10:24:38 | 000,178,800 | ---- | C] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt_x64.dll
[2012.03.02 10:22:05 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\Games for Windows - LIVE Demos
[2012.03.02 10:18:19 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\xlive
[2012.03.02 10:18:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2012.03.02 10:18:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
[2012.03.02 09:50:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
[2012.03.02 09:50:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Rockstar Games
[2012.03.02 09:50:52 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2012.03.02 09:46:48 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Mozilla
[2012.03.02 09:46:48 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\Mozilla
[2012.03.02 09:46:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012.03.02 09:45:51 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\PhotoScape
[2012.03.02 09:45:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
[2012.03.02 09:45:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PhotoScape
[2012.03.02 09:44:47 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2012.03.02 09:44:47 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\IrfanView
[2012.03.02 09:44:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IrfanView
[2012.03.02 09:35:40 | 000,337,240 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012.03.02 09:35:40 | 000,024,408 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012.03.02 09:35:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012.03.02 09:35:38 | 000,819,032 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012.03.02 09:35:38 | 000,059,224 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012.03.02 09:35:38 | 000,053,080 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012.03.02 09:35:37 | 000,069,976 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012.03.02 09:35:22 | 000,201,352 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012.03.02 09:35:22 | 000,041,184 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.03.02 09:29:15 | 000,258,520 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012.03.02 09:28:59 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2012.03.02 09:28:41 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012.03.02 09:28:41 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012.03.02 09:27:55 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\Google
[2012.03.02 09:27:54 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2012.03.02 09:27:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2012.03.02 09:27:25 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2012.03.02 09:21:28 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Macromedia
[2012.03.02 09:21:28 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Adobe
[2012.03.02 09:21:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2012.03.02 09:21:23 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2012.03.02 09:15:32 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\Diagnostics
[2012.03.02 09:14:01 | 000,000,000 | R--D | C] -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.03.02 09:14:01 | 000,000,000 | R--D | C] -- C:\Users\Robin\Searches
[2012.03.02 09:14:01 | 000,000,000 | R--D | C] -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.03.02 09:13:51 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Identities
[2012.03.02 09:13:49 | 000,000,000 | R--D | C] -- C:\Users\Robin\Contacts
[2012.03.02 09:13:47 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\VirtualStore
[2012.03.02 09:13:36 | 000,000,000 | --SD | C] -- C:\Users\Robin\AppData\Roaming\Microsoft
[2012.03.02 09:13:36 | 000,000,000 | R--D | C] -- C:\Users\Robin\Videos
[2012.03.02 09:13:36 | 000,000,000 | R--D | C] -- C:\Users\Robin\Saved Games
[2012.03.02 09:13:36 | 000,000,000 | R--D | C] -- C:\Users\Robin\Pictures
[2012.03.02 09:13:36 | 000,000,000 | R--D | C] -- C:\Users\Robin\Music
[2012.03.02 09:13:36 | 000,000,000 | R--D | C] -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.03.02 09:13:36 | 000,000,000 | R--D | C] -- C:\Users\Robin\Links
[2012.03.02 09:13:36 | 000,000,000 | R--D | C] -- C:\Users\Robin\Favorites
[2012.03.02 09:13:36 | 000,000,000 | R--D | C] -- C:\Users\Robin\Downloads
[2012.03.02 09:13:36 | 000,000,000 | R--D | C] -- C:\Users\Robin\Documents
[2012.03.02 09:13:36 | 000,000,000 | R--D | C] -- C:\Users\Robin\Desktop
[2012.03.02 09:13:36 | 000,000,000 | R--D | C] -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\Vorlagen
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\AppData\Local\Verlauf
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\AppData\Local\Temporary Internet Files
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\Startmenü
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\SendTo
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\Recent
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\Netzwerkumgebung
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\Lokale Einstellungen
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\Documents\Eigene Videos
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\Documents\Eigene Musik
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\Eigene Dateien
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\Documents\Eigene Bilder
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\Druckumgebung
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\Cookies
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\AppData\Local\Anwendungsdaten
[2012.03.02 09:13:36 | 000,000,000 | -HSD | C] -- C:\Users\Robin\Anwendungsdaten
[2012.03.02 09:13:36 | 000,000,000 | -H-D | C] -- C:\Users\Robin\AppData
[2012.03.02 09:13:36 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\Temp
[2012.03.02 09:13:36 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\Microsoft
[2012.03.02 09:13:36 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Media Center Programs
[2012.03.02 09:13:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2012.03.02 09:13:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2012.03.02 09:13:29 | 000,000,000 | -HSD | C] -- C:\Recovery
[2012.03.02 09:13:29 | 000,000,000 | -HSD | C] -- C:\Programme
[2012.03.02 09:13:29 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2012.03.02 09:13:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2012.03.02 09:13:29 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2012.03.02 09:13:29 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2012.03.02 09:13:29 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2012.03.02 09:13:29 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2012.03.02 09:13:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2012.03.02 09:13:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2012.03.02 09:09:36 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012.03.02 09:07:09 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2012.03.02 09:06:50 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012.03.02 09:05:58 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.03.14 23:01:32 | 000,014,608 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.14 23:01:32 | 000,014,608 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.14 22:58:47 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.03.14 22:58:47 | 000,653,928 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.03.14 22:58:47 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.03.14 22:58:47 | 000,129,800 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.03.14 22:58:47 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.03.14 22:53:58 | 000,274,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.03.14 22:53:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.03.14 22:53:31 | 3220,574,208 | -HS- | M] () -- C:\hiberfil.sys
[2012.03.14 20:10:47 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.14 05:29:06 | 000,007,168 | ---- | M] () -- C:\Users\Robin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.03.13 20:59:28 | 000,001,975 | ---- | M] () -- C:\Users\Robin\Desktop\Driver Cleaner Pro.lnk
[2012.03.13 12:00:27 | 000,002,088 | ---- | M] () -- C:\Users\Robin\.recently-used.xbel
[2012.03.13 11:14:20 | 000,001,195 | ---- | M] () -- C:\Users\Public\Desktop\Moyea Video4Web Converter.lnk
[2012.03.13 10:53:26 | 000,000,168 | ---- | M] () -- C:\Users\Robin\defogger_reenable
[2012.03.13 10:52:35 | 000,050,477 | ---- | M] () -- C:\Users\Robin\Desktop\Defogger.exe
[2012.03.13 06:40:45 | 000,018,302 | ---- | M] () -- C:\Users\Robin\Documents\4523523.jpg
[2012.03.13 06:09:56 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2012.03.11 22:36:50 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.03.10 03:19:54 | 000,067,793 | ---- | M] () -- C:\Users\Robin\Desktop\dashcam.zip
[2012.03.09 03:30:58 | 000,044,255 | ---- | M] () -- C:\Users\Robin\Documents\11.jpg
[2012.03.08 23:14:08 | 000,047,393 | ---- | M] () -- C:\Users\Robin\Documents\DSC0125.jpg
[2012.03.08 22:29:53 | 005,953,248 | ---- | M] () -- C:\Users\Robin\Documents\DSC01041.JPG
[2012.03.08 20:09:46 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012.03.08 18:10:56 | 000,002,274 | ---- | M] () -- C:\Users\Robin\Desktop\Google Chrome.lnk
[2012.03.08 02:52:05 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.03.08 02:52:04 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2012.03.07 19:28:09 | 000,606,189 | ---- | M] () -- C:\Users\Robin\Documents\001.jpg
[2012.03.07 18:28:44 | 000,052,484 | ---- | M] () -- C:\Users\Robin\Documents\hajaajaiOFHJPFHIUIASFHUIWFHIOWERFHJIOWG.jpg
[2012.03.07 18:02:47 | 000,003,588 | ---- | M] () -- C:\Users\Robin\Documents\stad_-m_oedchen-alb1m21p.jpg
[2012.03.07 15:28:22 | 000,001,007 | ---- | M] () -- C:\Users\Robin\Desktop\SplitCam.lnk
[2012.03.07 06:43:10 | 001,744,890 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012.03.07 06:00:06 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2012.03.07 06:00:06 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2012.03.07 05:59:34 | 000,055,384 | ---- | M] (Sunbelt Software) -- C:\Windows\SysNative\drivers\SBREDrv.sys
[2012.03.07 01:55:03 | 000,001,258 | ---- | M] () -- C:\Users\Robin\Desktop\Spybot - Search & Destroy.lnk
[2012.03.07 01:15:19 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.03.07 01:15:14 | 000,201,352 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012.03.07 01:15:03 | 000,258,520 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012.03.07 01:04:06 | 000,819,032 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012.03.07 01:04:04 | 000,337,240 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012.03.07 01:02:20 | 000,053,080 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012.03.07 01:01:57 | 000,059,224 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012.03.07 01:01:52 | 000,069,976 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012.03.07 01:01:32 | 000,024,408 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012.03.05 12:53:18 | 000,001,021 | ---- | M] () -- C:\Users\Public\Desktop\FlashPeak SlimBrowser.lnk
[2012.03.02 12:58:36 | 000,005,385 | ---- | M] () -- C:\Users\Robin\Desktop\Sims3_Pets_bended.rar
[2012.03.02 12:39:11 | 000,002,264 | ---- | M] () -- C:\Users\Public\Desktop\Die Sims™ 3 Einfach tierisch.lnk
[2012.03.02 12:24:42 | 000,001,168 | ---- | M] () -- C:\Users\Public\Desktop\Camtasia Studio 7.lnk
[2012.03.02 12:15:32 | 000,002,086 | ---- | M] () -- C:\Users\Public\Desktop\Die*Sims™*3.lnk
[2012.03.02 12:05:30 | 000,001,950 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012.03.02 12:04:51 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2012.03.02 10:29:48 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.03.02 10:24:38 | 000,178,800 | ---- | M] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt_x64.dll
[2012.03.02 10:22:07 | 000,002,196 | ---- | M] () -- C:\Users\Public\Desktop\Grand Theft Auto IV.lnk
[2012.03.02 09:46:44 | 000,001,130 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.03.02 09:45:48 | 000,001,031 | ---- | M] () -- C:\Users\Robin\Desktop\PhotoScape.lnk
[2012.03.02 09:44:48 | 000,001,890 | ---- | M] () -- C:\Users\Robin\Desktop\IrfanView Thumbnails.lnk
[2012.03.02 09:44:48 | 000,000,998 | ---- | M] () -- C:\Users\Robin\Desktop\IrfanView.lnk
[2012.03.02 09:35:40 | 000,001,841 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012.03.02 09:10:10 | 000,052,953 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2012.03.02 09:10:10 | 000,052,953 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2012.03.01 01:02:00 | 000,068,928 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2012.03.01 01:02:00 | 000,061,248 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2012.03.01 01:02:00 | 000,011,770 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb
[2012.02.29 21:59:29 | 002,515,790 | ---- | M] () -- C:\Windows\SysNative\nvcoproc.bin
[2012.02.29 13:26:56 | 000,416,064 | ---- | M] () -- C:\Windows\SysWow64\nvStreaming.exe
[2012.02.24 10:36:50 | 000,230,952 | ---- | M] (PC Tools) -- C:\Windows\SysNative\drivers\PCTSD64.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.03.14 20:10:47 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.14 03:01:05 | 000,041,472 | ---- | C] () -- C:\Users\Robin\Desktop\skyrim4gb.exe
[2012.03.14 03:01:05 | 000,014,336 | ---- | C] () -- C:\Users\Robin\Desktop\skyrim4gb_helper.dll
[2012.03.13 21:33:49 | 002,515,790 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin
[2012.03.13 20:59:28 | 000,001,975 | ---- | C] () -- C:\Users\Robin\Desktop\Driver Cleaner Pro.lnk
[2012.03.13 12:00:27 | 000,002,088 | ---- | C] () -- C:\Users\Robin\.recently-used.xbel
[2012.03.13 11:14:20 | 000,001,195 | ---- | C] () -- C:\Users\Public\Desktop\Moyea Video4Web Converter.lnk
[2012.03.13 10:53:25 | 000,000,168 | ---- | C] () -- C:\Users\Robin\defogger_reenable
[2012.03.13 10:52:25 | 000,050,477 | ---- | C] () -- C:\Users\Robin\Desktop\Defogger.exe
[2012.03.13 06:40:45 | 000,018,302 | ---- | C] () -- C:\Users\Robin\Documents\4523523.jpg
[2012.03.13 06:09:56 | 000,000,910 | ---- | C] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2012.03.12 20:38:40 | 008,822,912 | ---- | C] () -- C:\Users\Robin\Desktop\Stefanie Heinzmann - Diggin' In The Dirt.mp3
[2012.03.11 22:36:50 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.03.10 03:19:53 | 000,067,793 | ---- | C] () -- C:\Users\Robin\Desktop\dashcam.zip
[2012.03.09 03:30:57 | 000,044,255 | ---- | C] () -- C:\Users\Robin\Documents\11.jpg
[2012.03.08 23:14:07 | 000,047,393 | ---- | C] () -- C:\Users\Robin\Documents\DSC0125.jpg
[2012.03.08 22:27:44 | 005,953,248 | ---- | C] () -- C:\Users\Robin\Documents\DSC01041.JPG
[2012.03.08 18:10:56 | 000,002,274 | ---- | C] () -- C:\Users\Robin\Desktop\Google Chrome.lnk
[2012.03.08 02:52:04 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.03.08 02:52:04 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2012.03.07 19:27:59 | 000,606,189 | ---- | C] () -- C:\Users\Robin\Documents\001.jpg
[2012.03.07 18:28:42 | 000,052,484 | ---- | C] () -- C:\Users\Robin\Documents\hajaajaiOFHJPFHIUIASFHUIWFHIOWERFHJIOWG.jpg
[2012.03.07 18:02:46 | 000,003,588 | ---- | C] () -- C:\Users\Robin\Documents\stad_-m_oedchen-alb1m21p.jpg
[2012.03.07 15:28:22 | 000,001,007 | ---- | C] () -- C:\Users\Robin\Desktop\SplitCam.lnk
[2012.03.07 15:28:18 | 000,810,496 | ---- | C] () -- C:\Windows\SysNative\xvidcore.dll
[2012.03.07 15:28:18 | 000,183,808 | ---- | C] () -- C:\Windows\SysNative\xvidvfw.dll
[2012.03.07 15:28:18 | 000,080,896 | ---- | C] () -- C:\Windows\SysNative\ff_vfw.dll
[2012.03.07 15:28:12 | 000,389,120 | ---- | C] () -- C:\Windows\SysWow64\actskn43.ocx
[2012.03.07 15:28:12 | 000,389,120 | ---- | C] () -- C:\Windows\SysNative\actskn43.ocx
[2012.03.07 06:42:36 | 001,744,890 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012.03.07 06:00:06 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2012.03.07 06:00:06 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2012.03.07 01:55:03 | 000,001,258 | ---- | C] () -- C:\Users\Robin\Desktop\Spybot - Search & Destroy.lnk
[2012.03.05 12:53:18 | 000,001,021 | ---- | C] () -- C:\Users\Public\Desktop\FlashPeak SlimBrowser.lnk
[2012.03.04 13:14:07 | 000,347,904 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd
[2012.03.04 13:11:00 | 000,010,429 | ---- | C] () -- C:\Windows\SysNative\ScavengeSpace.xml
[2012.03.04 13:10:35 | 000,105,559 | ---- | C] () -- C:\Windows\SysWow64\RacRules.xml
[2012.03.04 13:10:35 | 000,105,559 | ---- | C] () -- C:\Windows\SysNative\RacRules.xml
[2012.03.04 13:09:51 | 000,001,041 | ---- | C] () -- C:\Windows\SysWow64\tcpbidi.xml
[2012.03.02 13:48:17 | 000,007,168 | ---- | C] () -- C:\Users\Robin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.03.02 12:58:35 | 000,005,385 | ---- | C] () -- C:\Users\Robin\Desktop\Sims3_Pets_bended.rar
[2012.03.02 12:39:11 | 000,002,264 | ---- | C] () -- C:\Users\Public\Desktop\Die Sims™ 3 Einfach tierisch.lnk
[2012.03.02 12:24:42 | 000,001,168 | ---- | C] () -- C:\Users\Public\Desktop\Camtasia Studio 7.lnk
[2012.03.02 12:15:32 | 000,002,086 | ---- | C] () -- C:\Users\Public\Desktop\Die*Sims™*3.lnk
[2012.03.02 12:05:30 | 000,001,950 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012.03.02 10:29:48 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.03.02 10:22:07 | 000,002,196 | ---- | C] () -- C:\Users\Public\Desktop\Grand Theft Auto IV.lnk
[2012.03.02 10:17:51 | 000,001,338 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live ID.lnk
[2012.03.02 09:46:44 | 000,001,142 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.03.02 09:46:44 | 000,001,130 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.03.02 09:45:48 | 000,001,031 | ---- | C] () -- C:\Users\Robin\Desktop\PhotoScape.lnk
[2012.03.02 09:44:48 | 000,001,890 | ---- | C] () -- C:\Users\Robin\Desktop\IrfanView Thumbnails.lnk
[2012.03.02 09:44:48 | 000,000,998 | ---- | C] () -- C:\Users\Robin\Desktop\IrfanView.lnk
[2012.03.02 09:35:40 | 000,001,841 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012.03.02 09:29:15 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2012.03.02 09:14:06 | 000,001,405 | ---- | C] () -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012.03.02 09:14:02 | 000,001,439 | ---- | C] () -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.03.02 09:10:01 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012.03.02 09:10:00 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012.03.02 09:06:50 | 3220,574,208 | -HS- | C] () -- C:\hiberfil.sys
[2012.02.29 13:26:56 | 000,416,064 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011.09.28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
 
========== LOP Check ==========
 
[2012.03.07 05:09:34 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\.purple
[2012.03.14 02:00:57 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\DAEMON Tools Lite
[2012.03.07 05:09:27 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\gtk-2.0
[2012.03.14 00:07:11 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\ICQ
[2012.03.02 09:44:47 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\IrfanView
[2012.03.08 02:40:35 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\ManyCam
[2012.03.13 11:16:43 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Moyea
[2012.03.12 00:04:58 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\PhotoScape
[2012.03.09 04:46:22 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\SlimBrowser
[2012.03.07 06:41:57 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\TestApp
[2012.03.13 11:17:15 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\tiger-k
[2012.03.07 15:06:28 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\WebcamMax
[2009.07.14 06:08:49 | 000,009,954 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.03.07 05:09:34 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\.purple
[2012.03.02 09:21:28 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Adobe
[2012.03.14 02:00:57 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\DAEMON Tools Lite
[2012.03.07 05:09:27 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\gtk-2.0
[2012.03.14 00:07:11 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\ICQ
[2012.03.02 09:13:51 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Identities
[2012.03.02 09:44:47 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\IrfanView
[2012.03.02 09:21:28 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Macromedia
[2012.03.14 20:10:51 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Malwarebytes
[2012.03.08 02:40:35 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\ManyCam
[2009.07.14 19:18:18 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Media Center Programs
[2012.03.07 15:30:23 | 000,000,000 | --SD | M] -- C:\Users\Robin\AppData\Roaming\Microsoft
[2012.03.13 11:16:43 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Moyea
[2012.03.02 09:46:52 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Mozilla
[2012.03.07 23:51:31 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\NVIDIA
[2012.03.12 00:04:58 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\PhotoScape
[2012.03.02 10:25:17 | 000,000,000 | RH-D | M] -- C:\Users\Robin\AppData\Roaming\SecuROM
[2012.03.14 00:07:15 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Skype
[2012.03.09 04:46:22 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\SlimBrowser
[2012.03.07 06:41:57 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\TestApp
[2012.03.13 11:17:15 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\tiger-k
[2012.03.07 15:06:28 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\WebcamMax
[2012.03.02 11:56:21 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2012.03.02 12:15:42 | 000,010,134 | R--- | M] () -- C:\Users\Robin\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
 
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
 
 
< MD5 for: AGP440.SYS  >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 07:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 07:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.01.13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84

< End of report >


Was mich grade etwas beunruhigt ist das hier:


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)


Was soll das? Ist das ein Spionage Programm oder sowas??

EDIT: hab von dem fraunhofer institut noch nie was von gehört.

Mfg Roxii

RoXii 14.03.2012 23:35

Sorry für den Doppel Post!

cosinus 15.03.2012 04:24

Zitat:

EDIT: hab von dem fraunhofer institut noch nie was von gehört.
Offensichtlich hast du auch noch nie was von Google gehört :wtf:

RoXii 16.03.2012 00:29

hey ja aber was ist das nun genau?
und ist mein pc sonst sauber?

mfg roxii


hab über das institut nur gehört das es forschung in elektronik betreibt oder sowas... :balla:

cosinus 16.03.2012 16:41

Hör auf dir darüber Sorgen zu machen!
Ich sach dir schon was weg kann und was nicht mit Hilfe von Fix-Scripten

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 10 2C 97 5B 4D F8 CC 01  [binary data]
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\..\SearchScopes\{31736BAB-7BFB-43A9-BA0D-82651305DB62}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=MYC-ST&o=102869&src=crm&q={searchTerms}&locale=&apn_ptnrs=5J&apn_dtid=YYYYYYYYDE&apn_uid=95fa6c67-9d21-4d3c-b6dd-5e5349787c5e&apn_sauid=B9EEA00D-CC31-4D80-807C-06826F78973D
IE - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http://de.ask.com/?l=dis&o=102869&gct=hp"
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.3&q="
[2012.03.02 20:44:48 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Robin\AppData\Roaming\mozilla\Firefox\Profiles\sz5n2qep.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.01.03 16:27:44 | 000,002,333 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\searchplugins\askcom.xml
[2012.03.02 21:24:48 | 000,000,950 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\searchplugins\icqplugin-1.xml
[2011.03.30 14:14:34 | 000,001,042 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\searchplugins\icqplugin.xml
O3 - HKU\S-1-5-21-3752288333-708083476-1710006870-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-3752288333-708083476-1710006870-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.11.15 10:52:50 | 000,161,088 | R--- | M] (Take-Two Interactive Software, Inc.) - E:\Autorun.exe -- [ UDF ]
O32 - AutoRun File - [2008.10.11 18:03:48 | 000,000,054 | R--- | M] () - E:\Autorun.inf -- [ UDF ]
O32 - AutoRun File - [2011.10.06 16:01:16 | 000,000,044 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{6447ef70-6442-11e1-8801-bcaec58adf4a}\Shell - "" = AutoRun
O33 - MountPoints2\{6447ef70-6442-11e1-8801-bcaec58adf4a}\Shell\AutoRun\command - "" = G:\Setup.exe -- [2011.10.06 16:01:18 | 000,355,920 | R--- | M] (Valve Corporation)
O33 - MountPoints2\{a662fb88-643e-11e1-8643-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{a662fb88-643e-11e1-8643-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Autorun.exe -- [2008.11.15 10:52:50 | 000,161,088 | R--- | M] (Take-Two Interactive Software, Inc.)
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

RoXii 17.03.2012 10:43

hi hab den otl log angehängt.

cosinus 17.03.2012 15:05

Lies bitte meine Anleitungen richtig. Das war KEIN Fix-Log

RoXii 17.03.2012 16:30

hi

ich habe grade OTL.exe geöffnet und er hat mir ein neues log gegeben, ich poste es hier.


Code:

All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully!
HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Internet Explorer\SearchScopes\{31736BAB-7BFB-43A9-BA0D-82651305DB62}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31736BAB-7BFB-43A9-BA0D-82651305DB62}\ not found.
Registry key HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Folder C:\Users\Robin\AppData\Roaming\mozilla\Firefox\Profiles\sz5n2qep.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\ not found.
File C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\searchplugins\askcom.xml not found.
File C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\searchplugins\icqplugin-1.xml not found.
File C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\searchplugins\icqplugin.xml not found.
Registry value HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
File move failed. E:\Autorun.exe scheduled to be moved on reboot.
File move failed. E:\Autorun.inf scheduled to be moved on reboot.
File move failed. G:\autorun.inf scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6447ef70-6442-11e1-8801-bcaec58adf4a}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6447ef70-6442-11e1-8801-bcaec58adf4a}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6447ef70-6442-11e1-8801-bcaec58adf4a}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6447ef70-6442-11e1-8801-bcaec58adf4a}\ not found.
File move failed. G:\Setup.exe scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a662fb88-643e-11e1-8643-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a662fb88-643e-11e1-8643-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a662fb88-643e-11e1-8643-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a662fb88-643e-11e1-8643-806e6f6e6963}\ not found.
File move failed. E:\Autorun.exe scheduled to be moved on reboot.
ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully.
ADS C:\ProgramData\TEMP:430C6D84 deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: Robin
->Temp folder emptied: 279888 bytes
->Temporary Internet Files folder emptied: 3804050 bytes
->Java cache emptied: 3695964 bytes
->Google Chrome cache emptied: 89830686 bytes
->Flash cache emptied: 1636 bytes
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 531320 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36028605 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 128,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.37.1 log created on 03172012_102736

Files\Folders moved on Reboot...
File move failed. E:\Autorun.exe scheduled to be moved on reboot.
File move failed. E:\Autorun.inf scheduled to be moved on reboot.
File move failed. G:\autorun.inf scheduled to be moved on reboot.
File move failed. G:\Setup.exe scheduled to be moved on reboot.
File move failed. C:\Users\Robin\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.
C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0 moved successfully.
C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1 moved successfully.
C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2 moved successfully.
C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3 moved successfully.
C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Cache\index moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
File\Folder C:\Windows\temp\TMP00000338ADDEF9BC8219C7E2 not found!

Registry entries deleted on Reboot...



Mfg Roxii

RoXii 17.03.2012 20:12

Sorry für doppel post
aber ich hab es nochmal gemacht,
ich hoffe das es jetzt richtig ist der logg


Code:

All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully!
HKU\S-1-5-21-3752288333-708083476-1710006870-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\ not found.
HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Internet Explorer\SearchScopes\{31736BAB-7BFB-43A9-BA0D-82651305DB62}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31736BAB-7BFB-43A9-BA0D-82651305DB62}\ not found.
Registry key HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Folder C:\Users\Robin\AppData\Roaming\mozilla\Firefox\Profiles\sz5n2qep.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\ not found.
File C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\searchplugins\askcom.xml not found.
File C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\searchplugins\icqplugin-1.xml not found.
File C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\sz5n2qep.default\searchplugins\icqplugin.xml not found.
Registry value HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin not found.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin not found.
Registry value HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
File move failed. E:\Autorun.exe scheduled to be moved on reboot.
File move failed. E:\Autorun.inf scheduled to be moved on reboot.
File move failed. G:\autorun.inf scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6447ef70-6442-11e1-8801-bcaec58adf4a}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6447ef70-6442-11e1-8801-bcaec58adf4a}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6447ef70-6442-11e1-8801-bcaec58adf4a}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6447ef70-6442-11e1-8801-bcaec58adf4a}\ not found.
File move failed. G:\Setup.exe scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a662fb88-643e-11e1-8643-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a662fb88-643e-11e1-8643-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a662fb88-643e-11e1-8643-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a662fb88-643e-11e1-8643-806e6f6e6963}\ not found.
File move failed. E:\Autorun.exe scheduled to be moved on reboot.
Unable to delete ADS C:\ProgramData\TEMP:DFC5A2B2 .
Unable to delete ADS C:\ProgramData\TEMP:430C6D84 .
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: Robin
->Temp folder emptied: 1638806 bytes
->Temporary Internet Files folder emptied: 1314333 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 10002309 bytes
->Flash cache emptied: 470 bytes
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 12,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.37.1 log created on 03172012_200809

Files\Folders moved on Reboot...
File move failed. E:\Autorun.exe scheduled to be moved on reboot.
File move failed. E:\Autorun.inf scheduled to be moved on reboot.
File\Folder G:\autorun.inf not found!
File\Folder G:\Setup.exe not found!
File\Folder C:\Users\Robin\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...


cosinus 19.03.2012 15:29

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

RoXii 19.03.2012 16:47

Code:

16:03:01.0247 1424        TDSS rootkit removing tool 2.7.20.0 Mar  9 2012 17:10:43
16:03:01.0547 1424        ============================================================
16:03:01.0547 1424        Current date / time: 2012/03/19 16:03:01.0547
16:03:01.0547 1424        SystemInfo:
16:03:01.0547 1424       
16:03:01.0547 1424        OS Version: 6.1.7601 ServicePack: 1.0
16:03:01.0547 1424        Product type: Workstation
16:03:01.0547 1424        ComputerName: ROBIN-PC
16:03:01.0548 1424        UserName: Robin
16:03:01.0548 1424        Windows directory: C:\Windows
16:03:01.0548 1424        System windows directory: C:\Windows
16:03:01.0548 1424        Running under WOW64
16:03:01.0548 1424        Processor architecture: Intel x64
16:03:01.0548 1424        Number of processors: 4
16:03:01.0548 1424        Page size: 0x1000
16:03:01.0548 1424        Boot type: Normal boot
16:03:01.0548 1424        ============================================================
16:03:02.0786 1424        Drive \Device\Harddisk0\DR0 - Size: 0x53D67B6000 (335.35 Gb), SectorSize: 0x200, Cylinders: 0xAB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:03:02.0825 1424        \Device\Harddisk0\DR0:
16:03:02.0853 1424        MBR used
16:03:02.0853 1424        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1800800, BlocksNum 0x32000
16:03:02.0853 1424        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1832800, BlocksNum 0x1B19A800
16:03:02.0853 1424        \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1C9CD000, BlocksNum 0xD4E6000
16:03:02.0938 1424        Initialize success
16:03:02.0938 1424        ============================================================
16:04:09.0584 2804        ============================================================
16:04:09.0584 2804        Scan started
16:04:09.0584 2804        Mode: Manual; SigCheck; TDLFS;
16:04:09.0584 2804        ============================================================
16:04:09.0818 2804        1394ohci        (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
16:04:09.0928 2804        1394ohci - ok
16:04:10.0021 2804        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
16:04:10.0037 2804        ACPI - ok
16:04:10.0115 2804        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
16:04:10.0208 2804        AcpiPmi - ok
16:04:10.0333 2804        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
16:04:10.0380 2804        adp94xx - ok
16:04:10.0411 2804        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
16:04:10.0427 2804        adpahci - ok
16:04:10.0442 2804        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
16:04:10.0458 2804        adpu320 - ok
16:04:10.0583 2804        AFD            (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
16:04:10.0630 2804        AFD - ok
16:04:10.0692 2804        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
16:04:10.0708 2804        agp440 - ok
16:04:10.0754 2804        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
16:04:10.0786 2804        aliide - ok
16:04:10.0801 2804        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
16:04:10.0801 2804        amdide - ok
16:04:10.0895 2804        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
16:04:10.0973 2804        AmdK8 - ok
16:04:11.0051 2804        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
16:04:11.0098 2804        AmdPPM - ok
16:04:11.0160 2804        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
16:04:11.0176 2804        amdsata - ok
16:04:11.0222 2804        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
16:04:11.0254 2804        amdsbs - ok
16:04:11.0316 2804        amdxata        (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
16:04:11.0347 2804        amdxata - ok
16:04:11.0394 2804        AppID          (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
16:04:11.0581 2804        AppID - ok
16:04:11.0675 2804        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
16:04:11.0690 2804        arc - ok
16:04:11.0753 2804        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
16:04:11.0784 2804        arcsas - ok
16:04:11.0815 2804        aswFsBlk        (b9da213b5271db5fce962d827e6d620d) C:\Windows\system32\drivers\aswFsBlk.sys
16:04:11.0862 2804        aswFsBlk - ok
16:04:11.0940 2804        aswMonFlt      (21c9835d0e5ad2ff0f16134bcb32cc71) C:\Windows\system32\drivers\aswMonFlt.sys
16:04:11.0956 2804        aswMonFlt - ok
16:04:11.0987 2804        aswRdr          (1b96a5867abd4fa6135d8298fcccf9c6) C:\Windows\System32\Drivers\aswrdr2.sys
16:04:11.0987 2804        aswRdr - ok
16:04:12.0034 2804        aswSnx          (6e98bb288696777a3a8a07a52b0eaee9) C:\Windows\system32\drivers\aswSnx.sys
16:04:12.0049 2804        aswSnx - ok
16:04:12.0065 2804        aswSP          (d9fb49f16e4eb02efecae8cbfe4bcb4c) C:\Windows\system32\drivers\aswSP.sys
16:04:12.0080 2804        aswSP - ok
16:04:12.0112 2804        aswTdi          (7352bb9a564b94bbd7c9cbf165f55006) C:\Windows\system32\drivers\aswTdi.sys
16:04:12.0112 2804        aswTdi - ok
16:04:12.0143 2804        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
16:04:12.0299 2804        AsyncMac - ok
16:04:12.0330 2804        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
16:04:12.0330 2804        atapi - ok
16:04:12.0392 2804        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
16:04:12.0470 2804        b06bdrv - ok
16:04:12.0548 2804        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
16:04:12.0611 2804        b57nd60a - ok
16:04:12.0704 2804        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
16:04:12.0782 2804        Beep - ok
16:04:12.0860 2804        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
16:04:12.0907 2804        blbdrive - ok
16:04:13.0001 2804        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
16:04:13.0079 2804        bowser - ok
16:04:13.0141 2804        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
16:04:13.0235 2804        BrFiltLo - ok
16:04:13.0266 2804        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
16:04:13.0266 2804        BrFiltUp - ok
16:04:13.0297 2804        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
16:04:13.0328 2804        Brserid - ok
16:04:13.0344 2804        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
16:04:13.0360 2804        BrSerWdm - ok
16:04:13.0406 2804        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
16:04:13.0453 2804        BrUsbMdm - ok
16:04:13.0516 2804        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
16:04:13.0547 2804        BrUsbSer - ok
16:04:13.0594 2804        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
16:04:13.0640 2804        BTHMODEM - ok
16:04:13.0734 2804        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
16:04:13.0828 2804        cdfs - ok
16:04:13.0937 2804        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
16:04:13.0999 2804        cdrom - ok
16:04:14.0108 2804        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
16:04:14.0155 2804        circlass - ok
16:04:14.0202 2804        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
16:04:14.0249 2804        CLFS - ok
16:04:14.0342 2804        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
16:04:14.0389 2804        CmBatt - ok
16:04:14.0436 2804        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
16:04:14.0452 2804        cmdide - ok
16:04:14.0545 2804        CNG            (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
16:04:14.0576 2804        CNG - ok
16:04:14.0608 2804        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
16:04:14.0623 2804        Compbatt - ok
16:04:14.0732 2804        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
16:04:14.0795 2804        CompositeBus - ok
16:04:14.0888 2804        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
16:04:14.0920 2804        crcdisk - ok
16:04:15.0044 2804        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
16:04:15.0091 2804        DfsC - ok
16:04:15.0185 2804        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
16:04:15.0247 2804        discache - ok
16:04:15.0341 2804        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
16:04:15.0372 2804        Disk - ok
16:04:15.0466 2804        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
16:04:15.0497 2804        drmkaud - ok
16:04:15.0544 2804        dtsoftbus01    (46571ed73ae84469dca53081d33cf3c8) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
16:04:15.0544 2804        dtsoftbus01 - ok
16:04:15.0606 2804        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
16:04:15.0637 2804        DXGKrnl - ok
16:04:15.0762 2804        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
16:04:15.0871 2804        ebdrv - ok
16:04:15.0980 2804        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
16:04:16.0012 2804        elxstor - ok
16:04:16.0027 2804        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
16:04:16.0058 2804        ErrDev - ok
16:04:16.0090 2804        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
16:04:16.0121 2804        exfat - ok
16:04:16.0152 2804        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
16:04:16.0214 2804        fastfat - ok
16:04:16.0308 2804        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
16:04:16.0339 2804        fdc - ok
16:04:16.0386 2804        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
16:04:16.0402 2804        FileInfo - ok
16:04:16.0433 2804        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
16:04:16.0511 2804        Filetrace - ok
16:04:16.0620 2804        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
16:04:16.0651 2804        flpydisk - ok
16:04:16.0729 2804        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
16:04:16.0760 2804        FltMgr - ok
16:04:16.0854 2804        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
16:04:16.0885 2804        FsDepends - ok
16:04:16.0901 2804        Fs_Rec          (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
16:04:16.0901 2804        Fs_Rec - ok
16:04:16.0948 2804        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
16:04:16.0979 2804        fvevol - ok
16:04:17.0010 2804        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
16:04:17.0010 2804        gagp30kx - ok
16:04:17.0026 2804        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
16:04:17.0057 2804        hcw85cir - ok
16:04:17.0135 2804        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
16:04:17.0197 2804        HdAudAddService - ok
16:04:17.0291 2804        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
16:04:17.0338 2804        HDAudBus - ok
16:04:17.0400 2804        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
16:04:17.0447 2804        HidBatt - ok
16:04:17.0462 2804        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
16:04:17.0494 2804        HidBth - ok
16:04:17.0525 2804        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
16:04:17.0572 2804        HidIr - ok
16:04:17.0618 2804        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys
16:04:17.0650 2804        HidUsb - ok
16:04:17.0696 2804        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
16:04:17.0712 2804        HpSAMD - ok
16:04:17.0759 2804        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
16:04:17.0852 2804        HTTP - ok
16:04:17.0930 2804        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
16:04:17.0946 2804        hwpolicy - ok
16:04:18.0008 2804        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
16:04:18.0040 2804        i8042prt - ok
16:04:18.0102 2804        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
16:04:18.0149 2804        iaStorV - ok
16:04:18.0211 2804        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
16:04:18.0242 2804        iirsp - ok
16:04:18.0274 2804        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
16:04:18.0274 2804        intelide - ok
16:04:18.0352 2804        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
16:04:18.0383 2804        intelppm - ok
16:04:18.0430 2804        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:04:18.0492 2804        IpFilterDriver - ok
16:04:18.0586 2804        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
16:04:18.0632 2804        IPMIDRV - ok
16:04:18.0726 2804        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
16:04:18.0788 2804        IPNAT - ok
16:04:18.0820 2804        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
16:04:18.0866 2804        IRENUM - ok
16:04:18.0882 2804        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
16:04:18.0898 2804        isapnp - ok
16:04:18.0991 2804        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
16:04:19.0038 2804        iScsiPrt - ok
16:04:19.0085 2804        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
16:04:19.0116 2804        kbdclass - ok
16:04:19.0147 2804        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
16:04:19.0163 2804        kbdhid - ok
16:04:19.0194 2804        KSecDD          (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
16:04:19.0210 2804        KSecDD - ok
16:04:19.0241 2804        KSecPkg        (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
16:04:19.0241 2804        KSecPkg - ok
16:04:19.0272 2804        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
16:04:19.0303 2804        ksthunk - ok
16:04:19.0397 2804        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
16:04:19.0444 2804        lltdio - ok
16:04:19.0522 2804        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
16:04:19.0553 2804        LSI_FC - ok
16:04:19.0584 2804        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
16:04:19.0615 2804        LSI_SAS - ok
16:04:19.0631 2804        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
16:04:19.0646 2804        LSI_SAS2 - ok
16:04:19.0693 2804        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
16:04:19.0724 2804        LSI_SCSI - ok
16:04:19.0756 2804        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
16:04:19.0802 2804        luafv - ok
16:04:19.0912 2804        LVRS64          (0c85b2b6fb74b36a251792d45e0ef860) C:\Windows\system32\DRIVERS\lvrs64.sys
16:04:19.0958 2804        LVRS64 - ok
16:04:20.0099 2804        LVUVC64        (ff3a488924b0032b1a9ca6948c1fa9e8) C:\Windows\system32\DRIVERS\lvuvc64.sys
16:04:20.0255 2804        LVUVC64 - ok
16:04:20.0364 2804        ManyCam        (d33e2b74cf8b3a652bf0a9fbd068e87a) C:\Windows\system32\DRIVERS\ManyCam_x64.sys
16:04:20.0395 2804        ManyCam - ok
16:04:20.0442 2804        MBAMProtector  (79da94b35371b9e7104460c7693dcb2c) C:\Windows\system32\drivers\mbam.sys
16:04:20.0473 2804        MBAMProtector - ok
16:04:20.0504 2804        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
16:04:20.0504 2804        megasas - ok
16:04:20.0536 2804        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
16:04:20.0536 2804        MegaSR - ok
16:04:20.0567 2804        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
16:04:20.0614 2804        Modem - ok
16:04:20.0707 2804        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
16:04:20.0754 2804        monitor - ok
16:04:20.0801 2804        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys
16:04:20.0832 2804        mouclass - ok
16:04:20.0863 2804        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
16:04:20.0894 2804        mouhid - ok
16:04:20.0926 2804        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
16:04:20.0957 2804        mountmgr - ok
16:04:21.0019 2804        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
16:04:21.0066 2804        mpio - ok
16:04:21.0144 2804        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
16:04:21.0222 2804        mpsdrv - ok
16:04:21.0284 2804        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
16:04:21.0331 2804        MRxDAV - ok
16:04:21.0425 2804        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
16:04:21.0487 2804        mrxsmb - ok
16:04:21.0534 2804        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:04:21.0596 2804        mrxsmb10 - ok
16:04:21.0674 2804        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:04:21.0706 2804        mrxsmb20 - ok
16:04:21.0737 2804        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
16:04:21.0752 2804        msahci - ok
16:04:21.0815 2804        msdsm          (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
16:04:21.0846 2804        msdsm - ok
16:04:21.0877 2804        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
16:04:21.0908 2804        Msfs - ok
16:04:21.0924 2804        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
16:04:21.0955 2804        mshidkmdf - ok
16:04:22.0018 2804        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
16:04:22.0049 2804        msisadrv - ok
16:04:22.0111 2804        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
16:04:22.0189 2804        MSKSSRV - ok
16:04:22.0252 2804        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
16:04:22.0298 2804        MSPCLOCK - ok
16:04:22.0298 2804        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
16:04:22.0376 2804        MSPQM - ok
16:04:22.0486 2804        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
16:04:22.0517 2804        MsRPC - ok
16:04:22.0532 2804        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
16:04:22.0548 2804        mssmbios - ok
16:04:22.0564 2804        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
16:04:22.0626 2804        MSTEE - ok
16:04:22.0688 2804        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
16:04:22.0751 2804        MTConfig - ok
16:04:22.0844 2804        MTsensor        (19b006b181e3875fd254f7b67acf1e7c) C:\Windows\system32\DRIVERS\ASACPI.sys
16:04:22.0860 2804        MTsensor - ok
16:04:22.0907 2804        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
16:04:22.0922 2804        Mup - ok
16:04:23.0000 2804        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
16:04:23.0078 2804        NativeWifiP - ok
16:04:23.0188 2804        NDIS            (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
16:04:23.0234 2804        NDIS - ok
16:04:23.0266 2804        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
16:04:23.0312 2804        NdisCap - ok
16:04:23.0390 2804        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
16:04:23.0453 2804        NdisTapi - ok
16:04:23.0562 2804        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
16:04:23.0640 2804        Ndisuio - ok
16:04:23.0734 2804        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
16:04:23.0796 2804        NdisWan - ok
16:04:23.0858 2804        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
16:04:23.0936 2804        NDProxy - ok
16:04:24.0046 2804        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
16:04:24.0092 2804        NetBIOS - ok
16:04:24.0186 2804        NetBT          (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
16:04:24.0248 2804        NetBT - ok
16:04:24.0342 2804        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
16:04:24.0373 2804        nfrd960 - ok
16:04:24.0389 2804        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
16:04:24.0436 2804        Npfs - ok
16:04:24.0514 2804        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
16:04:24.0576 2804        nsiproxy - ok
16:04:24.0638 2804        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
16:04:24.0716 2804        Ntfs - ok
16:04:24.0763 2804        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
16:04:24.0826 2804        Null - ok
16:04:24.0919 2804        nusb3xhc        (f6d625ff7b56bb6ea063f0d3a5bbc996) C:\Windows\system32\DRIVERS\nusb3xhc.sys
16:04:24.0935 2804        nusb3xhc - ok
16:04:25.0013 2804        NVHDA          (8d4aac74b571fc356560e5b308955e93) C:\Windows\system32\drivers\nvhda64v.sys
16:04:25.0044 2804        NVHDA - ok
16:04:25.0340 2804        nvlddmkm        (0eb204639119370f5f8f2871fbf4e14b) C:\Windows\system32\DRIVERS\nvlddmkm.sys
16:04:25.0465 2804        nvlddmkm - ok
16:04:25.0574 2804        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
16:04:25.0606 2804        nvraid - ok
16:04:25.0637 2804        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
16:04:25.0652 2804        nvstor - ok
16:04:25.0762 2804        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
16:04:25.0808 2804        ohci1394 - ok
16:04:25.0840 2804        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
16:04:25.0855 2804        Parport - ok
16:04:25.0871 2804        partmgr        (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
16:04:25.0886 2804        partmgr - ok
16:04:25.0933 2804        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
16:04:25.0933 2804        pci - ok
16:04:25.0964 2804        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
16:04:25.0964 2804        pciide - ok
16:04:25.0996 2804        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
16:04:26.0011 2804        pcmcia - ok
16:04:26.0027 2804        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
16:04:26.0042 2804        pcw - ok
16:04:26.0058 2804        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
16:04:26.0120 2804        PEAUTH - ok
16:04:26.0198 2804        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
16:04:26.0261 2804        PptpMiniport - ok
16:04:26.0308 2804        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
16:04:26.0354 2804        Processor - ok
16:04:26.0448 2804        Psched          (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
16:04:26.0526 2804        Psched - ok
16:04:26.0651 2804        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
16:04:26.0713 2804        ql2300 - ok
16:04:26.0713 2804        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
16:04:26.0729 2804        ql40xx - ok
16:04:26.0729 2804        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
16:04:26.0760 2804        QWAVEdrv - ok
16:04:26.0776 2804        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
16:04:26.0791 2804        RasAcd - ok
16:04:26.0869 2804        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
16:04:26.0916 2804        RasAgileVpn - ok
16:04:26.0947 2804        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
16:04:27.0010 2804        Rasl2tp - ok
16:04:27.0134 2804        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
16:04:27.0212 2804        RasPppoe - ok
16:04:27.0306 2804        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
16:04:27.0384 2804        RasSstp - ok
16:04:27.0446 2804        rdbss          (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
16:04:27.0556 2804        rdbss - ok
16:04:27.0602 2804        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
16:04:27.0649 2804        rdpbus - ok
16:04:27.0680 2804        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
16:04:27.0743 2804        RDPCDD - ok
16:04:27.0821 2804        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
16:04:27.0899 2804        RDPENCDD - ok
16:04:27.0946 2804        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
16:04:27.0977 2804        RDPREFMP - ok
16:04:28.0024 2804        RDPWD          (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys
16:04:28.0070 2804        RDPWD - ok
16:04:28.0133 2804        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
16:04:28.0164 2804        rdyboost - ok
16:04:28.0273 2804        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
16:04:28.0336 2804        rspndr - ok
16:04:28.0445 2804        RTL8167        (ee082e06a82ff630351d1e0ebbd3d8d0) C:\Windows\system32\DRIVERS\Rt64win7.sys
16:04:28.0460 2804        RTL8167 - ok
16:04:28.0492 2804        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
16:04:28.0507 2804        sbp2port - ok
16:04:28.0585 2804        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
16:04:28.0632 2804        scfilter - ok
16:04:28.0694 2804        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
16:04:28.0757 2804        secdrv - ok
16:04:28.0850 2804        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
16:04:28.0882 2804        Serenum - ok
16:04:28.0897 2804        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
16:04:28.0928 2804        Serial - ok
16:04:29.0006 2804        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
16:04:29.0084 2804        sermouse - ok
16:04:29.0131 2804        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
16:04:29.0178 2804        sffdisk - ok
16:04:29.0194 2804        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
16:04:29.0209 2804        sffp_mmc - ok
16:04:29.0256 2804        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
16:04:29.0303 2804        sffp_sd - ok
16:04:29.0318 2804        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
16:04:29.0365 2804        sfloppy - ok
16:04:29.0459 2804        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
16:04:29.0490 2804        SiSRaid2 - ok
16:04:29.0490 2804        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
16:04:29.0506 2804        SiSRaid4 - ok
16:04:29.0615 2804        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
16:04:29.0677 2804        Smb - ok
16:04:29.0740 2804        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
16:04:29.0755 2804        spldr - ok
16:04:29.0802 2804        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
16:04:29.0880 2804        srv - ok
16:04:29.0989 2804        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
16:04:30.0036 2804        srv2 - ok
16:04:30.0098 2804        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
16:04:30.0130 2804        srvnet - ok
16:04:30.0208 2804        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
16:04:30.0239 2804        stexstor - ok
16:04:30.0286 2804        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
16:04:30.0317 2804        swenum - ok
16:04:30.0410 2804        Tcpip          (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
16:04:30.0488 2804        Tcpip - ok
16:04:30.0582 2804        TCPIP6          (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
16:04:30.0613 2804        TCPIP6 - ok
16:04:30.0660 2804        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
16:04:30.0723 2804        tcpipreg - ok
16:04:30.0785 2804        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
16:04:30.0816 2804        TDPIPE - ok
16:04:30.0863 2804        TDTCP          (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
16:04:30.0910 2804        TDTCP - ok
16:04:30.0972 2804        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
16:04:31.0019 2804        tdx - ok
16:04:31.0050 2804        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
16:04:31.0066 2804        TermDD - ok
16:04:31.0113 2804        tssecsrv        (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
16:04:31.0175 2804        tssecsrv - ok
16:04:31.0269 2804        TsUsbFlt        (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
16:04:31.0315 2804        TsUsbFlt - ok
16:04:31.0393 2804        tunnel          (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
16:04:31.0456 2804        tunnel - ok
16:04:31.0487 2804        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
16:04:31.0518 2804        uagp35 - ok
16:04:31.0549 2804        udfs            (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
16:04:31.0596 2804        udfs - ok
16:04:31.0643 2804        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
16:04:31.0659 2804        uliagpkx - ok
16:04:31.0799 2804        umbus          (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
16:04:31.0830 2804        umbus - ok
16:04:31.0846 2804        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
16:04:31.0877 2804        UmPass - ok
16:04:31.0986 2804        usbaudio        (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
16:04:32.0033 2804        usbaudio - ok
16:04:32.0049 2804        usbccgp        (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
16:04:32.0095 2804        usbccgp - ok
16:04:32.0205 2804        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
16:04:32.0251 2804        usbcir - ok
16:04:32.0283 2804        usbehci        (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
16:04:32.0314 2804        usbehci - ok
16:04:32.0361 2804        usbhub          (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
16:04:32.0407 2804        usbhub - ok
16:04:32.0454 2804        usbohci        (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\DRIVERS\usbohci.sys
16:04:32.0501 2804        usbohci - ok
16:04:32.0579 2804        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
16:04:32.0626 2804        usbprint - ok
16:04:32.0657 2804        USBSTOR        (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:04:32.0673 2804        USBSTOR - ok
16:04:32.0719 2804        usbuhci        (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
16:04:32.0766 2804        usbuhci - ok
16:04:32.0829 2804        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
16:04:32.0860 2804        vdrvroot - ok
16:04:32.0922 2804        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
16:04:32.0953 2804        vga - ok
16:04:32.0985 2804        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
16:04:33.0047 2804        VgaSave - ok
16:04:33.0063 2804        vhdmp          (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
16:04:33.0078 2804        vhdmp - ok
16:04:33.0094 2804        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
16:04:33.0109 2804        viaide - ok
16:04:33.0125 2804        volmgr          (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
16:04:33.0125 2804        volmgr - ok
16:04:33.0156 2804        volmgrx        (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
16:04:33.0172 2804        volmgrx - ok
16:04:33.0187 2804        volsnap        (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
16:04:33.0219 2804        volsnap - ok
16:04:33.0312 2804        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
16:04:33.0343 2804        vsmraid - ok
16:04:33.0359 2804        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
16:04:33.0390 2804        vwifibus - ok
16:04:33.0437 2804        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
16:04:33.0468 2804        WacomPen - ok
16:04:33.0531 2804        WANARP          (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
16:04:33.0577 2804        WANARP - ok
16:04:33.0593 2804        Wanarpv6        (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
16:04:33.0609 2804        Wanarpv6 - ok
16:04:33.0671 2804        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
16:04:33.0702 2804        Wd - ok
16:04:33.0718 2804        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
16:04:33.0749 2804        Wdf01000 - ok
16:04:33.0796 2804        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
16:04:33.0827 2804        WfpLwf - ok
16:04:33.0843 2804        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
16:04:33.0843 2804        WIMMount - ok
16:04:33.0967 2804        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
16:04:33.0999 2804        WmiAcpi - ok
16:04:34.0030 2804        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
16:04:34.0061 2804        ws2ifsl - ok
16:04:34.0108 2804        WudfPf          (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
16:04:34.0123 2804        WudfPf - ok
16:04:34.0155 2804        WUDFRd          (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
16:04:34.0217 2804        WUDFRd - ok
16:04:34.0233 2804        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
16:04:34.0389 2804        \Device\Harddisk0\DR0 - ok
16:04:34.0389 2804        Boot (0x1200)  (7b05a0c8d90e988eb4136b3e23d9e93e) \Device\Harddisk0\DR0\Partition0
16:04:34.0404 2804        \Device\Harddisk0\DR0\Partition0 - ok
16:04:34.0435 2804        Boot (0x1200)  (b554268e4eca51bf36d05f9f16170c41) \Device\Harddisk0\DR0\Partition1
16:04:34.0435 2804        \Device\Harddisk0\DR0\Partition1 - ok
16:04:34.0467 2804        Boot (0x1200)  (2ccdf725c11161936deb7a8a74877aba) \Device\Harddisk0\DR0\Partition2
16:04:34.0467 2804        \Device\Harddisk0\DR0\Partition2 - ok
16:04:34.0467 2804        ============================================================
16:04:34.0467 2804        Scan finished
16:04:34.0467 2804        ============================================================
16:04:34.0498 2004        Detected object count: 0
16:04:34.0498 2004        Actual detected object count: 0


cosinus 19.03.2012 17:02

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

RoXii 19.03.2012 18:25

hi habe den scan gemacht
und keine maus oder tastatur verwendet.

Code:

ComboFix 12-03-18.04 - Robin 19.03.2012  18:10:06.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4095.2895 [GMT 1:00]
ausgeführt von:: c:\users\Robin\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-02-19 bis 2012-03-19  ))))))))))))))))))))))))))))))
.
.
2012-03-19 17:13 . 2012-03-19 17:13        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-03-19 16:12 . 2012-03-19 16:13        --------        d-----w-        c:\program files\Core Temp
2012-03-17 09:31 . 2012-03-17 09:31        --------        d-----w-        c:\program files (x86)\7-Zip
2012-03-17 09:27 . 2012-03-17 09:27        --------        d-----w-        C:\_OTL
2012-03-16 09:44 . 2012-02-20 00:05        8643640        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{93CA4E39-1C82-4176-B393-38F33324CD83}\mpengine.dll
2012-03-15 02:47 . 2012-03-15 02:47        --------        d-----w-        c:\program files (x86)\Common Files\logishrd
2012-03-15 02:47 . 2012-03-15 02:47        --------        d-----w-        c:\program files\Common Files\logishrd
2012-03-14 20:17 . 2012-03-14 20:17        --------        d-----w-        c:\program files (x86)\ESET
2012-03-14 20:16 . 2011-11-19 15:20        5559152        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-03-14 20:16 . 2011-11-19 14:50        3968368        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2012-03-14 20:16 . 2011-11-19 14:50        3913584        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2012-03-14 19:10 . 2012-03-14 19:10        --------        d-----w-        c:\programdata\Malwarebytes
2012-03-14 19:10 . 2012-03-14 19:10        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-03-14 19:10 . 2011-12-10 14:24        23152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-03-14 19:08 . 2012-02-03 04:34        3145728        ----a-w-        c:\windows\system32\win32k.sys
2012-03-14 19:08 . 2012-02-10 06:36        1544192        ----a-w-        c:\windows\system32\DWrite.dll
2012-03-14 19:08 . 2012-02-10 05:38        1077248        ----a-w-        c:\windows\SysWow64\DWrite.dll
2012-03-14 19:07 . 2012-02-17 06:38        1031680        ----a-w-        c:\windows\system32\rdpcore.dll
2012-03-14 19:07 . 2012-02-17 05:34        826880        ----a-w-        c:\windows\SysWow64\rdpcore.dll
2012-03-14 19:07 . 2012-02-17 04:58        210944        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-03-14 19:07 . 2012-02-17 04:57        23552        ----a-w-        c:\windows\system32\drivers\tdtcp.sys
2012-03-14 19:07 . 2012-01-25 06:38        77312        ----a-w-        c:\windows\system32\rdpwsx.dll
2012-03-14 19:07 . 2012-01-25 06:38        149504        ----a-w-        c:\windows\system32\rdpcorekmts.dll
2012-03-14 19:07 . 2012-01-25 06:33        9216        ----a-w-        c:\windows\system32\rdrmemptylst.exe
2012-03-14 02:14 . 2010-06-02 03:55        77656        ----a-w-        c:\windows\system32\XAPOFX1_5.dll
2012-03-14 02:14 . 2010-06-02 03:55        74072        ----a-w-        c:\windows\SysWow64\XAPOFX1_5.dll
2012-03-14 02:14 . 2010-06-02 03:55        527192        ----a-w-        c:\windows\SysWow64\XAudio2_7.dll
2012-03-14 02:14 . 2010-06-02 03:55        518488        ----a-w-        c:\windows\system32\XAudio2_7.dll
2012-03-14 02:14 . 2010-06-02 03:55        239960        ----a-w-        c:\windows\SysWow64\xactengine3_7.dll
2012-03-14 02:14 . 2010-06-02 03:55        176984        ----a-w-        c:\windows\system32\xactengine3_7.dll
2012-03-14 02:14 . 2010-05-26 10:41        2526056        ----a-w-        c:\windows\system32\D3DCompiler_43.dll
2012-03-14 02:14 . 2010-05-26 10:41        2106216        ----a-w-        c:\windows\SysWow64\D3DCompiler_43.dll
2012-03-14 01:42 . 2012-03-14 01:42        22360        ----a-w-        c:\windows\SysWow64\X3DAudio1_7.dll
2012-03-14 01:29 . 2012-03-14 01:36        --------        d-----w-        C:\The Elder Scrolls V- Skyrim
2012-03-14 01:16 . 2012-03-14 01:27        --------        d-----w-        c:\program files (x86)\The Elder Scrolls V- Skyrim
2012-03-14 01:02 . 2012-03-14 01:03        --------        d-----w-        c:\program files (x86)\Common Files\Steam
2012-03-13 20:34 . 2012-03-15 11:05        --------        d-----w-        c:\users\UpdatusUser
2012-03-13 20:33 . 2012-02-29 21:00        3089728        ----a-w-        c:\windows\system32\nvsvc64.dll
2012-03-13 20:33 . 2012-02-29 21:00        6074176        ----a-w-        c:\windows\system32\nvcpl.dll
2012-03-13 20:33 . 2012-02-29 20:59        889664        ----a-w-        c:\windows\system32\nvvsvc.exe
2012-03-13 20:33 . 2012-02-29 20:59        63296        ----a-w-        c:\windows\system32\nvshext.dll
2012-03-13 20:33 . 2012-02-29 20:59        2561856        ----a-w-        c:\windows\system32\nvsvcr.dll
2012-03-13 20:33 . 2012-02-29 20:59        118080        ----a-w-        c:\windows\system32\nvmctray.dll
2012-03-13 20:33 . 2012-02-29 20:59        2515790        ----a-w-        c:\windows\system32\nvcoproc.bin
2012-03-13 20:33 . 2012-03-13 20:33        --------        d-----w-        c:\programdata\NVIDIA Corporation
2012-03-13 20:23 . 2012-03-13 20:33        --------        d-----w-        C:\NVIDIA
2012-03-13 19:59 . 2012-03-13 20:18        --------        d-----w-        c:\program files (x86)\Driver Cleaner Pro
2012-03-13 10:14 . 2012-01-09 12:43        606208        ----a-w-        c:\windows\SysWow64\xvidcore.dll
2012-03-13 10:14 . 2012-01-09 12:43        139264        ----a-w-        c:\windows\SysWow64\xvid.ax
2012-03-13 10:14 . 2006-07-17 23:00        348160        ----a-w-        c:\windows\SysWow64\msvcr71.dll
2012-03-13 10:14 . 2004-04-05 09:31        499712        ----a-w-        c:\windows\SysWow64\msvcp71.dll
2012-03-13 10:14 . 2012-03-13 10:14        --------        d-----w-        c:\program files (x86)\Moyea
2012-03-13 05:09 . 2012-03-13 05:09        --------        d-----w-        c:\program files\GIMP-2.0
2012-03-08 13:49 . 2012-03-08 13:49        --------        d-----w-        c:\windows\SysWow64\wbem\en-US
2012-03-08 13:49 . 2012-03-08 13:49        --------        d-----w-        c:\windows\system32\wbem\en-US
2012-03-07 16:46 . 2012-03-07 16:46        --------        d-----w-        c:\program files (x86)\Common Files\Skype
2012-03-07 16:46 . 2012-03-07 16:46        --------        d-----r-        c:\program files (x86)\Skype
2012-03-07 16:46 . 2012-03-07 16:46        --------        d-----w-        c:\programdata\Skype
2012-03-07 14:28 . 2012-01-03 07:03        810496        ----a-w-        c:\windows\system32\xvidcore.dll
2012-03-07 14:28 . 2012-01-03 07:03        80896        ----a-w-        c:\windows\system32\ff_vfw.dll
2012-03-07 14:28 . 2012-01-03 07:03        183808        ----a-w-        c:\windows\system32\xvidvfw.dll
2012-03-07 14:28 . 2012-01-03 07:03        389120        ----a-w-        c:\windows\SysWow64\actskn43.ocx
2012-03-07 14:28 . 2012-01-03 07:03        389120        ----a-w-        c:\windows\system32\actskn43.ocx
2012-03-07 14:28 . 2012-03-07 14:28        --------        d-----w-        c:\program files (x86)\SplitCam
2012-03-07 14:06 . 2012-03-07 14:20        --------        d-----w-        c:\programdata\WebcamMax
2012-03-07 14:01 . 2012-03-07 19:20        --------        d-----w-        c:\program files (x86)\7.1.0.0
2012-03-07 13:09 . 2004-03-08 23:00        152848        ----a-w-        c:\windows\SysWow64\COMDLG32.OCX
2012-03-07 13:09 . 2004-03-08 22:00        132880        ----a-w-        c:\windows\SysWow64\MSINET.OCX
2012-03-07 13:09 . 2004-03-08 22:00        1081616        ----a-w-        c:\windows\SysWow64\MSCOMCTL.OCX
2012-03-07 13:09 . 2012-03-07 13:09        --------        d-----w-        c:\program files (x86)\Common Files\Web Solution Mart
2012-03-07 05:48 . 2012-03-07 12:17        --------        d-----w-        c:\program files (x86)\PC Tools
2012-03-07 05:42 . 2012-03-07 12:17        --------        d-----w-        c:\program files (x86)\Common Files\PC Tools
2012-03-07 05:42 . 2012-02-24 09:36        230952        ----a-w-        c:\windows\system32\drivers\PCTSD64.sys
2012-03-07 05:41 . 2012-03-07 06:03        --------        d-----w-        c:\programdata\PC Tools
2012-03-07 04:59 . 2012-03-07 05:40        --------        dc----w-        c:\windows\system32\DRVSTORE
2012-03-07 04:59 . 2012-03-07 04:59        55384        ----a-w-        c:\windows\system32\drivers\SBREDrv.sys
2012-03-07 04:53 . 2012-03-07 04:59        --------        d-----w-        c:\programdata\Lavasoft
2012-03-07 04:04 . 2012-03-08 17:10        --------        d-----w-        c:\program files (x86)\Pidgin
2012-03-07 01:53 . 2012-03-07 01:53        --------        d-----w-        c:\program files (x86)\Common Files\Java
2012-03-07 01:52 . 2012-03-07 01:52        472808        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-03-07 01:52 . 2012-03-07 01:52        --------        d-----w-        c:\program files (x86)\Java
2012-03-07 00:55 . 2012-03-19 17:00        --------        d-----w-        c:\programdata\Spybot - Search & Destroy
2012-03-07 00:55 . 2012-03-07 00:55        --------        d-----w-        c:\program files (x86)\Spybot - Search & Destroy
2012-03-06 02:03 . 2012-03-06 02:03        --------        d-----w-        c:\program files (x86)\Microsoft.NET
2012-03-05 16:46 . 2012-03-05 16:46        --------        d-----w-        c:\program files (x86)\Microsoft Silverlight
2012-03-05 11:53 . 2012-03-05 11:53        --------        d-----w-        c:\program files (x86)\SlimBrowser
2012-03-05 09:18 . 2012-03-05 09:18        --------        d-----w-        c:\windows\system32\SPReview
2012-03-05 09:17 . 2012-03-05 09:17        --------        d-----w-        c:\windows\system32\EventProviders
2012-03-04 12:13 . 2010-11-20 13:33        951680        ----a-w-        c:\windows\system32\drivers\ndis.sys
2012-03-04 12:12 . 2010-11-20 13:34        71552        ----a-w-        c:\windows\system32\drivers\volmgr.sys
2012-03-04 12:11 . 2010-11-20 13:33        155008        ----a-w-        c:\windows\system32\drivers\mpio.sys
2012-03-04 12:10 . 2010-11-20 13:27        36352        ----a-w-        c:\windows\system32\wdiasqmmodule.dll
2012-03-04 12:09 . 2010-11-20 12:21        189952        ----a-w-        c:\windows\SysWow64\wdscore.dll
2012-03-04 12:09 . 2010-11-20 13:26        399872        ----a-w-        c:\windows\system32\dpx.dll
2012-03-04 12:09 . 2010-11-20 12:21        189952        ----a-w-        c:\windows\SysWow64\sqmapi.dll
2012-03-04 12:09 . 2010-11-20 12:21        363008        ----a-w-        c:\windows\SysWow64\wbemcomn.dll
2012-03-04 12:09 . 2010-11-20 12:21        189952        ----a-w-        c:\program files (x86)\Windows Portable Devices\sqmapi.dll
2012-03-04 12:09 . 2010-11-20 12:19        606208        ----a-w-        c:\windows\SysWow64\wbem\fastprox.dll
2012-03-04 12:07 . 2010-11-20 13:27        529408        ----a-w-        c:\windows\system32\wbemcomn.dll
2012-03-04 12:07 . 2010-11-20 13:27        244736        ----a-w-        c:\program files\Windows Portable Devices\sqmapi.dll
2012-03-04 12:07 . 2010-11-20 13:27        244736        ----a-w-        c:\windows\system32\sqmapi.dll
2012-03-04 09:44 . 2011-02-19 12:05        1139200        ----a-w-        c:\windows\system32\FntCache.dll
2012-03-04 09:44 . 2011-02-19 12:04        902656        ----a-w-        c:\windows\system32\d2d1.dll
2012-03-04 09:44 . 2011-02-19 06:30        739840        ----a-w-        c:\windows\SysWow64\d2d1.dll
2012-03-03 12:44 . 2011-03-25 03:29        343040        ----a-w-        c:\windows\system32\drivers\usbhub.sys
2012-03-03 12:44 . 2011-03-25 03:29        98816        ----a-w-        c:\windows\system32\drivers\usbccgp.sys
2012-03-03 12:44 . 2011-03-25 03:29        325120        ----a-w-        c:\windows\system32\drivers\usbport.sys
2012-03-03 12:44 . 2011-03-25 03:29        52736        ----a-w-        c:\windows\system32\drivers\usbehci.sys
2012-03-03 12:44 . 2011-03-25 03:29        25600        ----a-w-        c:\windows\system32\drivers\usbohci.sys
2012-03-03 12:44 . 2011-03-25 03:29        30720        ----a-w-        c:\windows\system32\drivers\usbuhci.sys
2012-03-03 02:28 . 2010-02-23 08:16        294912        ----a-w-        c:\windows\system32\browserchoice.exe
2012-03-03 02:14 . 2010-12-23 10:42        961024        ----a-w-        c:\windows\system32\CPFilters.dll
2012-03-03 02:13 . 2011-10-26 05:21        43520        ----a-w-        c:\windows\system32\csrsrv.dll
2012-03-03 02:12 . 2011-04-22 22:15        27520        ----a-w-        c:\windows\system32\drivers\Diskdump.sys
2012-03-03 02:11 . 2011-05-24 11:42        404480        ----a-w-        c:\windows\system32\umpnpmgr.dll
2012-03-03 02:08 . 2011-11-19 14:58        77312        ----a-w-        c:\windows\system32\packager.dll
2012-03-03 02:08 . 2011-11-19 14:01        67072        ----a-w-        c:\windows\SysWow64\packager.dll
2012-03-02 19:44 . 2012-03-02 19:44        --------        d-----w-        c:\program files (x86)\ICQ6Toolbar
2012-03-02 19:44 . 2012-03-02 19:44        --------        d-----w-        c:\programdata\ICQ
2012-03-02 19:40 . 2012-03-02 19:45        --------        d-----w-        c:\program files (x86)\ICQ7.7
2012-03-02 11:24 . 2012-03-02 11:24        --------        d-----w-        c:\windows\SysWow64\QuickTime
2012-03-02 11:24 . 2012-03-02 11:25        --------        d-----w-        c:\programdata\TechSmith
2012-03-02 11:24 . 2012-03-02 11:24        --------        d-----w-        c:\program files (x86)\QuickTime
2012-03-02 11:24 . 2012-03-02 11:24        --------        d-----w-        c:\program files (x86)\Common Files\TechSmith Shared
2012-03-02 11:24 . 2012-03-02 11:24        --------        d-----w-        c:\program files (x86)\TechSmith
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-05 09:24 . 2009-07-14 02:36        175616        ----a-w-        c:\windows\system32\msclmd.dll
2012-03-05 09:24 . 2009-07-14 02:36        152576        ----a-w-        c:\windows\SysWow64\msclmd.dll
2012-03-02 09:34 . 2009-08-18 11:49        564632        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2012-03-02 09:34 . 2009-08-18 10:24        18328        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-01-18 05:44 . 2012-01-18 05:44        540960        ----a-w-        c:\windows\SysWow64\LVUI2RC.dll
2012-01-18 05:44 . 2012-01-18 05:44        545056        ----a-w-        c:\windows\SysWow64\LVUI2.dll
2012-01-18 05:44 . 2012-01-18 05:44        561440        ----a-w-        c:\windows\system32\LVUIRC64.dll
2012-01-18 05:44 . 2012-01-18 05:44        4865568        ----a-w-        c:\windows\system32\drivers\lvuvc64.sys
2012-01-18 05:44 . 2012-01-18 05:44        769312        ----a-w-        c:\windows\system32\LVUI64.dll
2012-01-18 05:44 . 2012-01-18 05:44        351136        ----a-w-        c:\windows\system32\drivers\lvrs64.sys
2012-01-18 05:44 . 2012-01-18 05:44        307488        ----a-w-        c:\windows\SysWow64\lvcodec2.dll
2012-01-18 05:44 . 2012-01-18 05:44        263456        ----a-w-        c:\windows\system32\lvco13311044.dll
2012-01-18 05:44 . 2012-01-18 05:44        176416        ----a-w-        c:\windows\system32\lvcod64.dll
2012-01-18 05:44 . 2012-01-18 05:44        336408        ----a-w-        c:\windows\SysWow64\DevManagerCore.dll
2012-01-18 05:44 . 2012-01-18 05:44        336408        ----a-w-        c:\windows\system32\DevManagerCore.dll
2012-01-18 05:44 . 2012-01-18 05:44        10920984        ----a-w-        c:\windows\SysWow64\LogiDPP.dll
2012-01-18 05:44 . 2012-01-18 05:44        10920984        ----a-w-        c:\windows\system32\LogiDPP.dll
2012-01-18 05:44 . 2012-01-18 05:44        104472        ----a-w-        c:\windows\SysWow64\LogiDPPApp.exe
2012-01-18 05:44 . 2012-01-18 05:44        104472        ----a-w-        c:\windows\system32\LogiDPPApp.exe
2012-01-18 05:23 . 2012-01-18 05:23        38958        ----a-w-        c:\windows\system32\Repository.reg
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A02B5E09-122E-4A2D-B996-D997485B8C9E}]
2012-02-28 17:11        269312        ----a-w-        c:\users\Robin\AppData\LocalLow\Flagfox\IE\Flagfox.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-02-13 3481408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R3 ALSysIO;ALSysIO;c:\users\Robin\AppData\Local\Temp\ALSysIO64.sys [x]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]
R3 LVUVC64;Logitech HD Webcam C510(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam_x64.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 FlagfoxUpdater;Flagfox Updater;c:\users\Robin\AppData\LocalLow\Flagfox\IE\FlagfoxUpdater.exe [2012-02-28 18432]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-01 2348352]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-29 382272]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-07 00:15        135408        ----a-w-        c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page =
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files (x86)\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\SecuROM\License information*]
"datasecu"=hex:51,61,cc,75,07,db,89,fd,0d,69,f4,14,17,19,52,52,53,0f,28,8b,42,
  f1,19,f0,55,93,ef,fc,00,12,82,5a,9b,a0,f8,17,65,11,d3,50,5d,2b,1a,32,1e,35,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-03-19  18:17:33 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-03-19 17:17
.
Vor Suchlauf: 9 Verzeichnis(se), 112.393.822.208 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 112.277.676.032 Bytes frei
.
- - End Of File - - E9A397C92D285160F2E951C24B5FF8B8


cosinus 19.03.2012 18:33

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

RoXii 19.03.2012 18:56

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-03-19 18:44:12
-----------------------------
18:44:12.585    OS Version: Windows x64 6.1.7601 Service Pack 1
18:44:12.585    Number of processors: 4 586 0x403
18:44:12.586    ComputerName: ROBIN-PC  UserName: Robin
18:44:12.978    Initialize success
18:44:13.011    AVAST engine defs: 12031900
18:44:33.465    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
18:44:33.466    Disk 0 Vendor: ST3360320AS 3.AAM Size: 343399MB BusType: 3
18:44:33.488    Disk 0 MBR read successfully
18:44:33.490    Disk 0 MBR scan
18:44:33.491    Disk 0 Windows 7 default MBR code
18:44:33.501    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        12288 MB offset 2048
18:44:33.512    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 25167872
18:44:33.517    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      222005 MB offset 25372672
18:44:33.538    Disk 0 Partition 4 00    07    HPFS/NTFS NTFS      109004 MB offset 480038912
18:44:33.561    Disk 0 scanning C:\Windows\system32\drivers
18:44:37.887    Service scanning
18:44:47.467    Modules scanning
18:44:47.467    Disk 0 trace - called modules:
18:44:47.482    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
18:44:47.485    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004a5c060]
18:44:47.487    3 CLASSPNP.SYS[fffff8800199343f] -> nt!IofCallDriver -> [0xfffffa80043f4520]
18:44:47.497    5 ACPI.sys[fffff88000e357a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0xfffffa80043f9680]
18:44:47.824    AVAST engine scan C:\Windows
18:44:49.170    AVAST engine scan C:\Windows\system32
18:46:16.114    AVAST engine scan C:\Windows\system32\drivers
18:46:21.170    AVAST engine scan C:\Users\Robin
18:47:08.024    File: C:\Users\Robin\Desktop\skyrim4gb.exe  **INFECTED** Win32:Ransom [Trj]
18:47:13.038    AVAST engine scan C:\ProgramData
18:47:23.363    Scan finished successfully
18:55:07.094    Disk 0 MBR has been saved successfully to "C:\Users\Robin\Desktop\MBR.dat"
18:55:07.097    The log file has been saved successfully to "C:\Users\Robin\Desktop\aswMBR.txt"


diese skyrim4gb.exe habe ich gedownloaded damit skyrim die 4gb ram ausnutzen kann, vom entwickler macht es sonst nur 2 gb ram

cosinus 19.03.2012 19:00

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

RoXii 19.03.2012 20:24

Code:

Malwarebytes Anti-Malware (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.19.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Robin :: ROBIN-PC [Administrator]

Schutz: Deaktiviert

19.03.2012 19:12:12
mbam-log-2012-03-19 (19-12-12).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 335081
Laufzeit: 32 Minute(n), 39 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)



Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 03/19/2012 at 08:21 PM

Application Version : 5.0.1146

Core Rules Database Version : 8350
Trace Rules Database Version: 6162

Scan type      : Complete Scan
Total Scan Time : 00:33:53

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 475
Memory threats detected  : 0
Registry items scanned    : 67553
Registry threats detected : 0
File items scanned        : 52433
File threats detected    : 6

Adware.Tracking Cookie
       
        stats.computecmedia.de [ C:\USERS\ROBIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\ROBIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\ROBIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
       

Trojan.Agent/Gen-InstallIQ
        C:\USERS\ROBIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\CACHE\F_00089F
        C:\USERS\ROBIN\DOWNLOADS\CORETEMP_1236.EXE
        C:\Windows\Prefetch\CORETEMP_1236.EXE-3190DE95.pf


cosinus 20.03.2012 16:07

Kann alle weg. Nur Cookies und wenn überhaupt nur Überreste wenn es denn überhaupt Schädlinge sind und keine Fehlalarme.
Rechner soweit wieder ok?

RoXii 20.03.2012 20:37

hey danke cosinus :)

ich glaube der rechner läuft jetzt wieder schneller.
Vielen Dank

Super Arbeit:)

cosinus 21.03.2012 14:59

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

RoXii 21.03.2012 19:35

danke
hab alles geupdatet und passwörter geändert.
duuu bist ein held.


:-)

mfg Roxii


Alle Zeitangaben in WEZ +1. Es ist jetzt 20:59 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131