Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Infizierte Registrierungswerte Hijack.ControlPanelStyle (https://www.trojaner-board.de/118524-infizierte-registrierungswerte-hijack-controlpanelstyle.html)

mot2001 04.07.2012 15:22

Infizierte Registrierungswerte Hijack.ControlPanelStyle
 
Hallo zusammen,

alles fing damit an, dass auf meinem Computer folgender Virus vorhanden war: Exploit.java.cve-2012-1723.b. Der konnte entfernt werden. Dieser Virus hat sich dadurch bemerkbar gemacht, dass sich auf einmal ein Fenster geöffnet hat in dem zu lesen war, dass mein PC 20 Infektionen ausgesetz ist. Ich habe dieses Fenster sofort geschlossen und alle Programme beendet und den PC sofort runtergefahren. Dann habe ich eine Überprüfung mit der Kaspersky Rescue Disk 10 durchgeführt. Bei dieser Überprüfung wurde der oben genannte Virus gefunden und entfernt.
Nach Überprüfung mit Malwarbytes Anti-Malware wurde "Hijack.ControlPanelStyle" gefunden. Um sicher zu gehen, dass ich diesen komplett entfernt bekomme, habe ich alles, was hier im Board vorgeschlagen wird gemacht, s. Logfiles.

vielen Dank für eure Hilfe

hier die mbam log file

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.07.04.03

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Administrator :: THEO99 [Administrator]

Schutz: Aktiviert

04.07.2012 10:03:56
mbam-log-2012-07-04 (11-49-13).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 487005
Laufzeit: 1 Stunde(n), 42 Minute(n), 20 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Daten: 1 -> Keine Aktion durchgeführt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

cosinus 05.07.2012 15:18

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

mot2001 06.07.2012 09:29

Liebes Board-Team, leider sind nur noch die protection-Logs dort abgespeichert. Ich denke, die werden nicht weiterhelfen.

cosinus 06.07.2012 10:52

Führ bitte auch ESET aus, danach sehen wir weiter.

Hinweis: ESET zeigt durchaus öfter ein paar Fehlalarme. Deswegen soll auch von ESET immer nur erst das Log gepostet und nichts entfernt werden.

ESET Online Scanner

Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten! Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.
  • Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt so öffnen: per Rechtsklick => als Administrator ausführen
  • Dein Anti-Virus-Programm während des Scans deaktivieren.

    Button http://img695.imageshack.us/img695/1599/eset1l.jpg (<< klick) drücken.
    • Firefox-User:
      Bitte esetsmartinstaller_enu.exe downloaden.Das Firefox-Addon auf dem Desktop speichern und dann installieren.
    • IE-User:
      müssen das Installieren eines ActiveX Elements erlauben.
  • Setze den einen Haken bei Yes, i accept the Terms of Use.
  • Drücke den http://img707.imageshack.us/img707/687/starteg.jpg Button.
  • Warte bis die Komponenten herunter geladen wurden.
  • Setze einen Haken bei "Scan archives".
  • Gehe sicher das bei Remove Found Threats kein Hacken gesetzt ist.
  • http://img707.imageshack.us/img707/687/starteg.jpg drücken.
  • Die Signaturen werden herunter geladen.Der Scan beginnt automatisch.
Wenn der Scan beendet wurde
  • Klicke Finish.
  • Browser schließen.
Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und kopiere folgenden Text in das Ausführen Fenster.
Code:

"%PROGRAMFILES%\Eset\Eset Online Scanner\log.txt"
Hinweis: Falls du ein 64-Bit-Windows einsetzt, lautet der Pfad so:

Code:

"%PROGRAMFILES(X86)%\Eset\Eset Online Scanner\log.txt"
Poste nun den Inhalt der log.txt.

mot2001 06.07.2012 14:22

Liebes Board-Team,

ESET habe ich durchlaufen lassen, konnte aber nur mit der Offline-Version arbeiten, da die Online-Variante beim Starten des Setup abstuerzte.

cosinus 08.07.2012 18:27

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

mot2001 09.07.2012 10:11

Zitat:

Zitat von cosinus (Beitrag 859810)
Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

zu 1. Windows scheint auf dem ersten Blick normal zu laufen
zu 2. Es fehlen keinerlei Eintraege in den Programmeordnern.

cosinus 09.07.2012 12:46

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


mot2001 09.07.2012 13:59

Hallo liebes Board-Team,
hier die OTL-Text

Code:

OTL logfile created on: 09.07.2012 14:43:22 - Run 2
OTL by OldTimer - Version 3.2.53.1    Folder = C:\Profile\Administrator\Eigene Dateien\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,35 Gb Available Physical Memory | 67,73% Memory free
3,85 Gb Paging File | 3,19 Gb Available in Paging File | 83,03% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 232,88 Gb Total Space | 177,61 Gb Free Space | 76,27% Space Free | Partition Type: NTFS
 
Computer Name: THEO99 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Profile\Administrator\Eigene Dateien\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Programme\ESET\ESET Smart Security\ekrn.exe (ESET)
PRC - C:\Programme\ESET\ESET Smart Security\egui.exe (ESET)
PRC - C:\Programme\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Programme\Common\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
PRC - C:\Programme\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
PRC - C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Programme\Nero\Nero 7\InCD\InCD.exe (Nero AG)
PRC - C:\Programme\Common\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\SwissAcademic.Citavi.IEPicker\1.0.0.0__f59eabe05cc67589\SwissAcademic.Citavi.IEPicker.dll ()
MOD - C:\WINDOWS\assembly\GAC\Interop.SHDocVw\1.1.0.0__4b827ebe229d539f\Interop.SHDocVw.dll ()
MOD - C:\Programme\Common\Adobe\Acrobat\ActiveX\PDFShell.DEU ()
MOD - C:\Programme\McAfee\Common Framework\boost_thread-vc80-mt-1_32.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\WINDOWS\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3054.18653__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3054.18892__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3054.18608__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3054.18668__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3054.18882__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3054.18645__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3054.18630__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard\2.0.3054.18864__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3054.18924__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3054.18837__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3054.18782__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3054.18848__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3054.18932__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Dashboard\2.0.3054.18660__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3054.18855__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3054.18623__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3054.18846__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Runtime\2.0.3054.18659__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3054.18793__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3054.18871__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3054.18792__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3054.18885__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashboard\2.0.3054.18840__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3054.18683__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3054.18777__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3054.18632__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3054.18676__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3054.18814__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3054.18783__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3054.18690__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3054.18812__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3054.18827__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3054.18785__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3054.18791__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3005.17490__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3005.17473__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3005.17516__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3005.17562__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3005.17512__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3005.17563__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.3005.17468__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3005.17493__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3005.17540__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3005.17556__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.3005.17465__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3005.17466__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3005.17608__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3005.17518__90ba9c70f846762e\DEM.OS.I0602.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3005.17496__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3005.17491__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3005.17479__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Shared\2.0.3005.17531__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.3005.17510__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.OS\2.0.3005.17517__90ba9c70f846762e\DEM.OS.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics\2.0.3005.17519__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3005.17488__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3005.17530__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3005.17521__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3005.17536__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3005.17522__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3005.17541__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3005.17535__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3005.17535__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3005.17539__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3005.17506__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3005.17531__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3005.17521__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3005.17537__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3005.17514__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\APM.Foundation\2.0.3005.17511__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3005.17489__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3054.18949__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3054.18597__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.3054.18910__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3005.17484__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOCALIZATION.Foundation.Private\2.0.3005.17481__90ba9c70f846762e\LOCALIZATION.Foundation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3054.18907__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3005.17475__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3005.17511__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3054.18639__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3005.17513__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3054.18597__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3005.17514__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3005.17508__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3054.18617__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\ATIDEMOS\2.0.3054.18598__90ba9c70f846762e\ATIDEMOS.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3005.17499__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.3054.18909__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3005.17542__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\APM.Server\2.0.3054.18594__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Server\2.0.3054.18596__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\Programme\McAfee\Common Framework\ccme_base.dll ()
MOD - C:\Programme\McAfee\Common Framework\cryptocme2.dll ()
MOD - C:\WINDOWS\system32\pdfcmnnt.dll ()
MOD - C:\WINDOWS\system32\HPBHealr.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (mfevtp) -- C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (MBAMService) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (ekrn) -- C:\Programme\ESET\ESET Smart Security\ekrn.exe (ESET)
SRV - (McShield) -- C:\Programme\Common\McAfee\SystemCore\\mcshield.exe ()
SRV - (odserv) -- C:\Programme\Common\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (McAfeeFramework) -- C:\Programme\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (McTaskManager) -- C:\Programme\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
SRV - (InCDsrv) -- C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (NMIndexingService) -- C:\Programme\Common\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (ose) -- C:\Programme\Common\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (MDM) -- C:\Programme\Common\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (WDICA) --  File not found
DRV - (PDRFRAME) --  File not found
DRV - (PDRELI) --  File not found
DRV - (PDFRAME) --  File not found
DRV - (PDCOMP) --  File not found
DRV - (PCIDump) --  File not found
DRV - (mferkdk) -- C:\Programme\McAfee\VirusScan Enterprise\mferkdk.sys File not found
DRV - (mfeavfk01) --  File not found
DRV - (lbrtfdc) --  File not found
DRV - (i2omgmt) --  File not found
DRV - (GMSIPCI) -- D:\INSTALL\GMSIPCI.SYS File not found
DRV - (Changer) --  File not found
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdet) -- C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (MBAMProtector) -- C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (epfw) -- C:\WINDOWS\system32\drivers\epfw.sys (ESET)
DRV - (epfwtdi) -- C:\WINDOWS\system32\drivers\epfwtdi.sys (ESET)
DRV - (Epfwndis) -- C:\WINDOWS\system32\drivers\epfwndis.sys (ESET)
DRV - (eamon) -- C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - (ehdrv) -- C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)
DRV - (mfetdi2k) -- C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation                          )
DRV - (InCDfs) -- C:\WINDOWS\system32\drivers\InCDfs.sys (Nero AG)
DRV - (incdrm) -- C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (InCDPass) -- C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (InCDrec) -- C:\WINDOWS\System32\drivers\InCDrec.sys (Nero AG)
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (irsir) -- C:\WINDOWS\system32\drivers\irsir.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
 
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
 
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
 
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\..\SearchScopes,DefaultScope = {92FD8C98-6028-4617-BA31-64982853525E}
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=F718CA02-C933-4555-9489-2204C23BD233&apn_sauid=C5CF927F-FF85-4954-B1D8-B49AF863A92B
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\..\SearchScopes\{92FD8C98-6028-4617-BA31-64982853525E}: "URL" = hxxp://www.google.de/search?q={searchTerms}
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {8AA36F4F-6DC7-4c06-77AF-5035170634FE}:2011.01.25
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Programme\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc;version=0.8.6f: C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN Team)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}: C:\Profile\All Users\Anwendungsdaten\Swiss Academic Software\Citavi Picker\Firefox [2011.01.31 13:40:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Programme\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012.03.29 12:48:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Programme\Common\McAfee\SystemCore [2012.07.09 14:37:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.07.06 13:04:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012.04.25 11:12:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2012.04.13 13:40:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Programme\ESET\ESET Smart Security\Mozilla Thunderbird [2012.07.06 13:19:28 | 000,000,000 | ---D | M]
 
[2011.03.09 14:44:42 | 000,000,000 | ---D | M] (No name found) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Extensions
[2011.03.09 14:44:42 | 000,000,000 | ---D | M] (No name found) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.07.04 11:53:13 | 000,000,000 | ---D | M] (No name found) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\extensions
[2011.01.31 14:02:31 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.07.06 13:05:07 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.04.25 10:59:01 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAMME\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012.07.06 13:04:59 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2012.04.25 10:58:59 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll
[2012.07.06 13:04:50 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.07.06 13:04:50 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.07.06 13:04:50 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.06 13:04:50 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.06 13:04:50 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.06 13:04:50 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2004.08.04 13:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\Common\McAfee\SystemCore\ScriptSn.20120413102718.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-515967899-492894223-839522115-500\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-515967899-492894223-839522115-500\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Programme\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Programme\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Common\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Programme\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [egui] C:\Programme\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [InCD] C:\Programme\Nero\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [LanguageShortcut] C:\Programme\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Programme\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Common\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [SecurDisc] C:\Programme\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
O4 - HKLM..\Run: [ShStatEXE] C:\Programme\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\.DEFAULT..\RunOnce: [nlsf] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [nlsf] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [nlsf] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [nlsf] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = B5 00 00 00  [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-515967899-492894223-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Citavi Picker... - C:\Profile\All Users\Anwendungsdaten\Swiss Academic Software\Citavi Picker\Internet Explorer\ShowContextMenu.html ()
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O15 - HKU\S-1-5-21-515967899-492894223-839522115-500\..Trusted Domains: microsoft.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-515967899-492894223-839522115-500\..Trusted Domains: microsoft.com ([*.update] * in Trusted sites)
O15 - HKU\S-1-5-21-515967899-492894223-839522115-500\..Trusted Domains: microsoft.com ([*.windowsupdate] * in Trusted sites)
O15 - HKU\S-1-5-21-515967899-492894223-839522115-500\..Trusted Domains: windowsupdate.com ([]* in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1212150358734 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1340968528124 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} hxxp://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = user.hu-berlin.de
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7E608E10-CB07-4588-8B69-C9422848FAE7}: NameServer = 141.20.1.3,141.20.1.31
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.05.29 16:21:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: 6to4 -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
MsConfig - StartUpReg: ApnUpdater - hkey= - key= - C:\Programme\Ask.com\Updater\Updater.exe (Ask)
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: mfehidk - C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
SafeBootNet: mfehidk.sys - C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
SafeBootNet: mfevtp - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - Microsoft Outlook Express 6
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Sicherheitsupdate für Windows XP (KB923789)
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {881dd1c5-3dcf-431b-b061-f3f88e8be88a} -
ActiveX: {8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C314CE45-3392-3B73-B4E1-139CD41CA933} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
ActiveX: Microsoft Base Smart Card Crypto Provider Package -
 
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.09 10:18:35 | 000,000,000 | RH-D | C] -- C:\Profile\Administrator\Recent
[2012.07.06 13:20:46 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\ESET
[2012.07.06 13:20:46 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Anwendungsdaten\ESET
[2012.07.06 13:20:32 | 000,000,000 | ---D | C] -- C:\Profile\LocalService\Lokale Einstellungen\Anwendungsdaten\ESET
[2012.07.06 13:19:25 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Startmenü\Programme\ESET
[2012.07.06 13:19:24 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2012.07.06 13:19:24 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Anwendungsdaten\ESET
[2012.07.06 13:05:12 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Anwendungsdaten\Mozilla
[2012.07.06 13:05:10 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Maintenance Service
[2012.07.03 14:23:13 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\GHISLER
[2012.07.03 12:26:54 | 000,000,000 | ---D | C] -- C:\Programme\stinger
[2012.06.29 15:12:01 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Anwendungsdaten\Malwarebytes
[2012.06.29 15:11:52 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.06.29 15:11:35 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Anwendungsdaten\Malwarebytes
[2012.06.29 15:11:32 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.06.29 15:11:32 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2012.06.29 13:53:14 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Startmenü\Programme\Microsoft Silverlight
[2012.06.29 13:49:58 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Silverlight
[2012.06.29 13:49:43 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Dokumente\microsoft
[2012.06.29 13:49:35 | 000,000,000 | ---D | C] -- C:\Programme\Windows Live SkyDrive
[2012.06.29 13:48:27 | 000,000,000 | ---D | C] -- C:\Programme\Common\Windows Live
[2012.06.29 13:47:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\WindowsPowerShell
[2012.06.29 13:47:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\winrm
[2012.06.29 13:47:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2012.06.29 13:47:31 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$968930Uinstall_KB968930$
[2012.06.29 13:46:17 | 000,000,000 | ---D | C] -- C:\Programme\Windows Media Connect 2
[2012.06.29 13:44:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2012.06.29 13:44:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2012.06.29 13:28:34 | 000,000,000 | -HSD | C] -- C:\Profile\Administrator\PrivacIE
[2012.06.29 13:27:35 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Startmenü\Programme\Microsoft Office Live Add-in
[2012.06.29 13:27:34 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft
[2012.06.29 13:25:16 | 000,000,000 | R--D | C] -- C:\Profile\Administrator\Eigene Dateien\Eigene Musik
[2012.06.29 13:25:15 | 000,000,000 | R--D | C] -- C:\Profile\Administrator\Eigene Dateien\Eigene Bilder
[2012.06.29 13:25:14 | 000,000,000 | -HSD | C] -- C:\Profile\Administrator\IETldCache
[2012.06.29 13:21:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2012.06.29 13:18:40 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2012.06.29 11:05:46 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\AskToolbar
[2012.06.28 16:57:26 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.09 14:34:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.07.09 10:17:09 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.07.06 10:24:57 | 000,002,064 | ---- | M] () -- C:\Profile\Administrator\Desktop\alteLogs.zip
[2012.07.04 16:21:36 | 000,019,080 | ---- | M] () -- C:\Profile\Administrator\Desktop\Logfiles.7z
[2012.07.04 09:57:33 | 000,000,222 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012.07.04 09:55:40 | 000,027,506 | ---- | M] () -- C:\cc_20120704_095454.reg
[2012.07.04 09:53:07 | 000,000,654 | ---- | M] () -- C:\Profile\All Users\Desktop\CCleaner.lnk
[2012.07.03 12:27:12 | 000,475,704 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfehidk.sys
[2012.07.03 12:27:12 | 000,159,608 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\mfevtps.exe
[2012.07.03 12:27:12 | 000,087,656 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mferkdet.sys
[2012.06.29 15:11:52 | 000,000,756 | ---- | M] () -- C:\Profile\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.29 15:05:15 | 000,496,252 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2012.06.29 15:05:15 | 000,475,942 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.06.29 15:05:15 | 000,092,010 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2012.06.29 15:05:15 | 000,076,976 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.06.29 13:54:38 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012.06.29 13:46:31 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2012.06.29 13:46:31 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2012.06.29 13:44:49 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2012.06.29 13:28:10 | 000,000,274 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2012.06.14 08:14:27 | 000,726,296 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.07.06 10:24:57 | 000,002,064 | ---- | C] () -- C:\Profile\Administrator\Desktop\alteLogs.zip
[2012.07.04 16:21:36 | 000,019,080 | ---- | C] () -- C:\Profile\Administrator\Desktop\Logfiles.7z
[2012.07.04 09:55:02 | 000,027,506 | ---- | C] () -- C:\cc_20120704_095454.reg
[2012.06.29 15:11:52 | 000,000,756 | ---- | C] () -- C:\Profile\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.29 13:44:49 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2012.06.29 13:43:39 | 000,225,262 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msimain.sdb
[2012.04.27 11:13:47 | 000,079,360 | ---- | C] () -- C:\WINDOWS\MULTIKYB.DLL
[2012.04.27 11:13:47 | 000,064,584 | ---- | C] () -- C:\WINDOWS\MultiKey.ini
[2012.04.27 11:13:47 | 000,057,856 | ---- | C] () -- C:\WINDOWS\Multikey.exe
[2012.02.16 16:13:48 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011.01.20 13:45:57 | 000,000,032 | ---- | C] () -- C:\WINDOWS\Menu.INI
[2008.06.16 11:26:43 | 000,009,630 | RHS- | C] () -- C:\Profile\All Users\ntuser.pol
 
========== LOP Check ==========
 
[2012.07.06 13:20:46 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ESET
[2010.02.03 15:36:53 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\GHISLER
[2008.05.30 13:41:51 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ICAClient
[2008.07.07 15:12:37 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\OfficeUpdate12
[2011.01.31 13:44:26 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Swiss Academic Software
[2011.03.09 14:44:40 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Thunderbird
[2012.04.25 10:59:24 | 000,000,000 | ---D | M] -- C:\Profile\All Users\Anwendungsdaten\Ask
[2012.07.06 13:19:24 | 000,000,000 | ---D | M] -- C:\Profile\All Users\Anwendungsdaten\ESET
[2012.03.30 13:19:49 | 000,000,000 | ---D | M] -- C:\Profile\All Users\Anwendungsdaten\regid.1986-12.com.adobe
[2011.01.31 13:40:44 | 000,000,000 | ---D | M] -- C:\Profile\All Users\Anwendungsdaten\Swiss Academic Software
[2012.07.09 09:40:17 | 000,000,000 | ---D | M] -- C:\Profile\doehlerm\Anwendungsdaten\ESET
[2011.05.25 20:11:41 | 000,000,000 | ---D | M] -- C:\Profile\doehlerm\Anwendungsdaten\ICAClient
[2011.02.01 12:03:56 | 000,000,000 | ---D | M] -- C:\Profile\doehlerm\Anwendungsdaten\Swiss Academic Software
[2011.03.09 14:53:38 | 000,000,000 | ---D | M] -- C:\Profile\doehlerm\Anwendungsdaten\Thunderbird
[2008.06.16 11:49:30 | 000,000,000 | ---D | M] -- C:\Profile\hildebrh\Anwendungsdaten\CoSoSys
[2008.06.16 13:00:03 | 000,000,000 | ---D | M] -- C:\Profile\hildebrh\Anwendungsdaten\ICAClient
[2012.03.23 12:29:30 | 000,000,000 | ---D | M] -- C:\Profile\mda\Anwendungsdaten\Swiss Academic Software
[2012.04.13 13:40:46 | 000,000,000 | ---D | M] -- C:\Profile\mda\Anwendungsdaten\Thunderbird
[2011.03.31 10:25:04 | 000,000,000 | ---D | M] -- C:\Profile\rackteua\Anwendungsdaten\Swiss Academic Software
[2011.09.13 13:40:14 | 000,000,000 | ---D | M] -- C:\Profile\shkjbob\Anwendungsdaten\Swiss Academic Software
[2012.07.04 09:57:33 | 000,000,222 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2012.06.29 13:28:10 | 000,000,274 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.03.29 12:49:59 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Adobe
[2008.05.30 13:35:47 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Apple Computer
[2008.06.02 15:50:33 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ATI
[2012.07.06 13:20:46 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ESET
[2010.02.03 15:36:53 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\GHISLER
[2008.05.30 13:41:51 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ICAClient
[2008.05.30 12:19:58 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Identities
[2008.05.30 11:21:31 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\InstallShield
[2010.01.22 11:51:35 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Macromedia
[2012.06.29 15:12:01 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Malwarebytes
[2011.03.16 15:06:31 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\McAfee
[2012.06.29 13:49:41 | 000,000,000 | --SD | M] -- C:\Profile\Administrator\Anwendungsdaten\Microsoft
[2008.05.30 15:51:50 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Mozilla
[2008.07.07 15:12:37 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\OfficeUpdate12
[2008.05.30 14:31:53 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Sun
[2011.01.31 13:44:26 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Swiss Academic Software
[2008.05.30 16:22:56 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Talkback
[2011.03.09 14:44:40 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Thunderbird
 
< %APPDATA%\*.exe /s >
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2006.03.02 17:57:59 | 016,721,925 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.05.30 14:49:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.05.30 14:49:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
 
< MD5 for: ATAPI.SYS  >
[2006.03.02 17:57:59 | 016,721,925 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.05.30 14:49:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.05.30 14:49:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
 
< MD5 for: EVENTLOG.DLL  >
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll
[2004.08.04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
 
< MD5 for: NETLOGON.DLL  >
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll
[2004.08.04 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
 
< MD5 for: SCECLI.DLL  >
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll
[2004.08.04 13:00:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
 
< MD5 for: USER32.DLL  >
[2006.03.02 17:44:00 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe
[2004.08.04 13:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2004.08.04 13:00:00 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2004.08.04 13:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2004.08.04 13:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008.05.29 18:14:07 | 000,098,304 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2008.05.29 18:14:07 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2008.05.29 18:14:07 | 000,450,560 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
 
<          >

< End of report >


cosinus 09.07.2012 14:00

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

mot2001 09.07.2012 14:11

Zitat:

Zitat von cosinus (Beitrag 860252)
Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

ja, hier der Inhalt:
Code:

# AdwCleaner v1.701 - Logfile created 07/09/2012 at 15:07:35
# Updated 02/07/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Administrator - THEO99
# Running from : C:\Profile\Administrator\Eigene Dateien\Downloads\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Profile\All Users\Anwendungsdaten\Ask
Folder Found : C:\Programme\Ask.com
Folder Found : C:\WINDOWS\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
File Found : C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

***** [Registry] *****

Key Found : HKCU\Software\APN
Key Found : HKCU\Software\AskToolbar
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKLM\SOFTWARE\APN
Key Found : HKLM\SOFTWARE\AskToolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater
Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{38EE5CEE-4B62-11D3-854F-00A0C9C898E7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8D670533-270B-4549-B19B-414FB9C6EBDB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A3F2A195-0D11-463b-96BB-D2FF1B7490A1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ECD0ECC6-DCA4-4013-A915-12355AB70999}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

*************************

AdwCleaner[R1].txt - [3547 octets] - [09/07/2012 15:07:35]

########## EOF - C:\AdwCleaner[R1].txt - [3675 octets] ##########


cosinus 09.07.2012 14:15

  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

mot2001 09.07.2012 14:27

Zitat:

Zitat von cosinus (Beitrag 860277)
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

hier die S1:
Code:

# AdwCleaner v1.701 - Logfile created 07/09/2012 at 15:19:46
# Updated 02/07/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Administrator - THEO99
# Running from : C:\Profile\Administrator\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Profile\All Users\Anwendungsdaten\Ask
Folder Deleted : C:\Programme\Ask.com
Folder Deleted : C:\WINDOWS\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
File Deleted : C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

***** [Registry] *****

Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\AskToolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\APN
Key Deleted : HKLM\SOFTWARE\AskToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater
Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{38EE5CEE-4B62-11D3-854F-00A0C9C898E7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8D670533-270B-4549-B19B-414FB9C6EBDB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A3F2A195-0D11-463b-96BB-D2FF1B7490A1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ECD0ECC6-DCA4-4013-A915-12355AB70999}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

*************************

AdwCleaner[R1].txt - [3676 octets] - [09/07/2012 15:07:35]
AdwCleaner[S1].txt - [3662 octets] - [09/07/2012 15:19:46]

########## EOF - C:\AdwCleaner[S1].txt - [3790 octets] ##########


cosinus 09.07.2012 14:32

Kannst du bitte mal diese Vollzitate sein lassen?

mot2001 09.07.2012 15:20

sorry, ok!

cosinus 09.07.2012 15:22

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


mot2001 10.07.2012 08:44

ja, hab ich jetzt mit der neuesten OTL durchgefuehrt.

Code:

OTL logfile created on: 10.07.2012 09:30:06 - Run 3
OTL by OldTimer - Version 3.2.53.1    Folder = C:\Profile\Administrator\Eigene Dateien\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,45 Gb Available Physical Memory | 72,35% Memory free
3,85 Gb Paging File | 3,20 Gb Available in Paging File | 83,26% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 232,88 Gb Total Space | 177,58 Gb Free Space | 76,26% Space Free | Partition Type: NTFS
 
Computer Name: THEO99 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Profile\Administrator\Eigene Dateien\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programme\ESET\ESET Smart Security\ekrn.exe (ESET)
PRC - C:\Programme\ESET\ESET Smart Security\egui.exe (ESET)
PRC - C:\Programme\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Programme\Common\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
PRC - C:\Programme\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
PRC - C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Programme\Nero\Nero 7\InCD\InCD.exe (Nero AG)
PRC - C:\Programme\Common\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\Programme\McAfee\Common Framework\boost_thread-vc80-mt-1_32.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3054.18653__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3054.18892__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3054.18608__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3054.18668__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3054.18882__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3054.18645__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3054.18630__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard\2.0.3054.18864__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3054.18924__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3054.18837__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3054.18782__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3054.18848__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3054.18932__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Dashboard\2.0.3054.18660__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3054.18855__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3054.18623__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3054.18846__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Runtime\2.0.3054.18659__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3054.18793__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3054.18871__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3054.18792__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3054.18885__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashboard\2.0.3054.18840__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3054.18683__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3054.18777__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3054.18632__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3054.18676__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3054.18814__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3054.18783__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3054.18690__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3054.18812__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3054.18827__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3054.18785__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3054.18791__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3005.17490__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3005.17473__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3005.17516__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3005.17562__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3005.17512__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3005.17563__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.3005.17468__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3005.17493__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3005.17540__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3005.17556__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.3005.17465__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3005.17466__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3005.17608__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3005.17518__90ba9c70f846762e\DEM.OS.I0602.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3005.17496__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3005.17491__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3005.17479__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Shared\2.0.3005.17531__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.3005.17510__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.OS\2.0.3005.17517__90ba9c70f846762e\DEM.OS.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics\2.0.3005.17519__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3005.17488__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3005.17530__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3005.17521__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3005.17536__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3005.17522__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3005.17541__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3005.17535__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3005.17535__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3005.17539__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3005.17506__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3005.17531__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3005.17521__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3005.17537__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3005.17514__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\APM.Foundation\2.0.3005.17511__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3005.17489__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3054.18949__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3054.18597__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.3054.18910__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3005.17484__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOCALIZATION.Foundation.Private\2.0.3005.17481__90ba9c70f846762e\LOCALIZATION.Foundation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3054.18907__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3005.17475__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3005.17511__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3054.18639__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3005.17513__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3054.18597__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3005.17514__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3005.17508__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3054.18617__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\ATIDEMOS\2.0.3054.18598__90ba9c70f846762e\ATIDEMOS.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3005.17499__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.3054.18909__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3005.17542__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\APM.Server\2.0.3054.18594__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Server\2.0.3054.18596__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\Programme\McAfee\Common Framework\ccme_base.dll ()
MOD - C:\Programme\McAfee\Common Framework\cryptocme2.dll ()
MOD - C:\WINDOWS\system32\pdfcmnnt.dll ()
MOD - C:\WINDOWS\system32\HPBHealr.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (mfevtp) -- C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (MBAMService) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (ekrn) -- C:\Programme\ESET\ESET Smart Security\ekrn.exe (ESET)
SRV - (McShield) -- C:\Programme\Common\McAfee\SystemCore\\mcshield.exe ()
SRV - (odserv) -- C:\Programme\Common\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (McAfeeFramework) -- C:\Programme\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (McTaskManager) -- C:\Programme\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
SRV - (InCDsrv) -- C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (NMIndexingService) -- C:\Programme\Common\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (ose) -- C:\Programme\Common\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (MDM) -- C:\Programme\Common\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (WDICA) --  File not found
DRV - (PDRFRAME) --  File not found
DRV - (PDRELI) --  File not found
DRV - (PDFRAME) --  File not found
DRV - (PDCOMP) --  File not found
DRV - (PCIDump) --  File not found
DRV - (mferkdk) -- C:\Programme\McAfee\VirusScan Enterprise\mferkdk.sys File not found
DRV - (mfeavfk01) --  File not found
DRV - (lbrtfdc) --  File not found
DRV - (i2omgmt) --  File not found
DRV - (GMSIPCI) -- D:\INSTALL\GMSIPCI.SYS File not found
DRV - (Changer) --  File not found
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdet) -- C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (MBAMProtector) -- C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (epfw) -- C:\WINDOWS\system32\drivers\epfw.sys (ESET)
DRV - (epfwtdi) -- C:\WINDOWS\system32\drivers\epfwtdi.sys (ESET)
DRV - (Epfwndis) -- C:\WINDOWS\system32\drivers\epfwndis.sys (ESET)
DRV - (eamon) -- C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - (ehdrv) -- C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)
DRV - (mfetdi2k) -- C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation                          )
DRV - (InCDfs) -- C:\WINDOWS\system32\drivers\InCDfs.sys (Nero AG)
DRV - (incdrm) -- C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (InCDPass) -- C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (InCDrec) -- C:\WINDOWS\System32\drivers\InCDrec.sys (Nero AG)
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (irsir) -- C:\WINDOWS\system32\drivers\irsir.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
 
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
 
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
 
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\..\SearchScopes,DefaultScope = {92FD8C98-6028-4617-BA31-64982853525E}
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\..\SearchScopes\{92FD8C98-6028-4617-BA31-64982853525E}: "URL" = hxxp://www.google.de/search?q={searchTerms}
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {8AA36F4F-6DC7-4c06-77AF-5035170634FE}:2011.01.25
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Programme\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc;version=0.8.6f: C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN Team)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}: C:\Profile\All Users\Anwendungsdaten\Swiss Academic Software\Citavi Picker\Firefox [2011.01.31 13:40:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Programme\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012.03.29 12:48:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Programme\Common\McAfee\SystemCore [2012.07.10 09:16:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.07.06 13:04:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012.04.25 11:12:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2012.04.13 13:40:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Programme\ESET\ESET Smart Security\Mozilla Thunderbird [2012.07.06 13:19:28 | 000,000,000 | ---D | M]
 
[2011.03.09 14:44:42 | 000,000,000 | ---D | M] (No name found) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Extensions
[2011.03.09 14:44:42 | 000,000,000 | ---D | M] (No name found) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.07.04 11:53:13 | 000,000,000 | ---D | M] (No name found) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\extensions
[2011.01.31 14:02:31 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.07.06 13:05:07 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.04.25 10:59:01 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAMME\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012.07.06 13:04:59 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2012.04.25 10:58:59 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll
[2012.07.06 13:04:50 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.07.06 13:04:50 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.07.06 13:04:50 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.06 13:04:50 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.06 13:04:50 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.06 13:04:50 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2004.08.04 13:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\Common\McAfee\SystemCore\ScriptSn.20120413102718.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-515967899-492894223-839522115-500\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Programme\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Programme\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Common\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Programme\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [egui] C:\Programme\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [InCD] C:\Programme\Nero\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [LanguageShortcut] C:\Programme\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Programme\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Common\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [SecurDisc] C:\Programme\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
O4 - HKLM..\Run: [ShStatEXE] C:\Programme\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\.DEFAULT..\RunOnce: [nlsf] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [nlsf] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [nlsf] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [nlsf] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = B5 00 00 00  [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-515967899-492894223-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Citavi Picker... - C:\Profile\All Users\Anwendungsdaten\Swiss Academic Software\Citavi Picker\Internet Explorer\ShowContextMenu.html ()
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O15 - HKU\S-1-5-21-515967899-492894223-839522115-500\..Trusted Domains: microsoft.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-515967899-492894223-839522115-500\..Trusted Domains: microsoft.com ([*.update] * in Trusted sites)
O15 - HKU\S-1-5-21-515967899-492894223-839522115-500\..Trusted Domains: microsoft.com ([*.windowsupdate] * in Trusted sites)
O15 - HKU\S-1-5-21-515967899-492894223-839522115-500\..Trusted Domains: windowsupdate.com ([]* in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1212150358734 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1340968528124 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} hxxp://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = user.hu-berlin.de
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7E608E10-CB07-4588-8B69-C9422848FAE7}: NameServer = 141.20.1.3,141.20.1.31
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.05.29 16:21:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: 6to4 -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: mfehidk - C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
SafeBootNet: mfehidk.sys - C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
SafeBootNet: mfevtp - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - Microsoft Outlook Express 6
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Sicherheitsupdate für Windows XP (KB923789)
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {881dd1c5-3dcf-431b-b061-f3f88e8be88a} -
ActiveX: {8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C314CE45-3392-3B73-B4E1-139CD41CA933} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
ActiveX: Microsoft Base Smart Card Crypto Provider Package -
 
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.09 16:53:25 | 000,000,000 | RH-D | C] -- C:\Profile\Administrator\Recent
[2012.07.06 13:20:46 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\ESET
[2012.07.06 13:20:46 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Anwendungsdaten\ESET
[2012.07.06 13:20:32 | 000,000,000 | ---D | C] -- C:\Profile\LocalService\Lokale Einstellungen\Anwendungsdaten\ESET
[2012.07.06 13:19:25 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Startmenü\Programme\ESET
[2012.07.06 13:19:24 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2012.07.06 13:19:24 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Anwendungsdaten\ESET
[2012.07.06 13:05:12 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Anwendungsdaten\Mozilla
[2012.07.06 13:05:10 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Maintenance Service
[2012.07.03 14:23:13 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\GHISLER
[2012.07.03 12:26:54 | 000,000,000 | ---D | C] -- C:\Programme\stinger
[2012.06.29 15:12:01 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Anwendungsdaten\Malwarebytes
[2012.06.29 15:11:52 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.06.29 15:11:35 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Anwendungsdaten\Malwarebytes
[2012.06.29 15:11:32 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.06.29 15:11:32 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2012.06.29 13:53:14 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Startmenü\Programme\Microsoft Silverlight
[2012.06.29 13:49:58 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Silverlight
[2012.06.29 13:49:43 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Dokumente\microsoft
[2012.06.29 13:49:35 | 000,000,000 | ---D | C] -- C:\Programme\Windows Live SkyDrive
[2012.06.29 13:48:27 | 000,000,000 | ---D | C] -- C:\Programme\Common\Windows Live
[2012.06.29 13:47:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\WindowsPowerShell
[2012.06.29 13:47:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\winrm
[2012.06.29 13:47:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2012.06.29 13:47:31 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$968930Uinstall_KB968930$
[2012.06.29 13:46:17 | 000,000,000 | ---D | C] -- C:\Programme\Windows Media Connect 2
[2012.06.29 13:44:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2012.06.29 13:44:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2012.06.29 13:28:34 | 000,000,000 | -HSD | C] -- C:\Profile\Administrator\PrivacIE
[2012.06.29 13:27:35 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Startmenü\Programme\Microsoft Office Live Add-in
[2012.06.29 13:27:34 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft
[2012.06.29 13:25:16 | 000,000,000 | R--D | C] -- C:\Profile\Administrator\Eigene Dateien\Eigene Musik
[2012.06.29 13:25:15 | 000,000,000 | R--D | C] -- C:\Profile\Administrator\Eigene Dateien\Eigene Bilder
[2012.06.29 13:25:14 | 000,000,000 | -HSD | C] -- C:\Profile\Administrator\IETldCache
[2012.06.29 13:21:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2012.06.29 13:18:40 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2012.06.29 11:05:46 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\AskToolbar
[2012.06.28 16:57:26 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.10 09:13:00 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.07.09 15:07:22 | 000,618,655 | ---- | M] () -- C:\Profile\Administrator\Desktop\adwcleaner.exe
[2012.07.09 10:17:09 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.07.06 10:24:57 | 000,002,064 | ---- | M] () -- C:\Profile\Administrator\Desktop\alteLogs.zip
[2012.07.04 16:21:36 | 000,019,080 | ---- | M] () -- C:\Profile\Administrator\Desktop\Logfiles.7z
[2012.07.04 09:55:40 | 000,027,506 | ---- | M] () -- C:\cc_20120704_095454.reg
[2012.07.04 09:53:07 | 000,000,654 | ---- | M] () -- C:\Profile\All Users\Desktop\CCleaner.lnk
[2012.07.03 12:27:12 | 000,475,704 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfehidk.sys
[2012.07.03 12:27:12 | 000,159,608 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\mfevtps.exe
[2012.07.03 12:27:12 | 000,087,656 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mferkdet.sys
[2012.06.29 15:11:52 | 000,000,756 | ---- | M] () -- C:\Profile\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.29 15:05:15 | 000,496,252 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2012.06.29 15:05:15 | 000,475,942 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.06.29 15:05:15 | 000,092,010 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2012.06.29 15:05:15 | 000,076,976 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.06.29 13:54:38 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012.06.29 13:46:31 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2012.06.29 13:46:31 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2012.06.29 13:44:49 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2012.06.29 13:28:10 | 000,000,274 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2012.06.14 08:14:27 | 000,726,296 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.07.09 15:07:21 | 000,618,655 | ---- | C] () -- C:\Profile\Administrator\Desktop\adwcleaner.exe
[2012.07.06 10:24:57 | 000,002,064 | ---- | C] () -- C:\Profile\Administrator\Desktop\alteLogs.zip
[2012.07.04 16:21:36 | 000,019,080 | ---- | C] () -- C:\Profile\Administrator\Desktop\Logfiles.7z
[2012.07.04 09:55:02 | 000,027,506 | ---- | C] () -- C:\cc_20120704_095454.reg
[2012.06.29 15:11:52 | 000,000,756 | ---- | C] () -- C:\Profile\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.29 13:44:49 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2012.06.29 13:43:39 | 000,225,262 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msimain.sdb
[2012.04.27 11:13:47 | 000,079,360 | ---- | C] () -- C:\WINDOWS\MULTIKYB.DLL
[2012.04.27 11:13:47 | 000,064,584 | ---- | C] () -- C:\WINDOWS\MultiKey.ini
[2012.04.27 11:13:47 | 000,057,856 | ---- | C] () -- C:\WINDOWS\Multikey.exe
[2012.02.16 16:13:48 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011.01.20 13:45:57 | 000,000,032 | ---- | C] () -- C:\WINDOWS\Menu.INI
[2008.06.16 11:26:43 | 000,009,630 | RHS- | C] () -- C:\Profile\All Users\ntuser.pol
 
========== LOP Check ==========
 
[2012.07.06 13:20:46 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ESET
[2010.02.03 15:36:53 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\GHISLER
[2008.05.30 13:41:51 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ICAClient
[2008.07.07 15:12:37 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\OfficeUpdate12
[2011.01.31 13:44:26 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Swiss Academic Software
[2011.03.09 14:44:40 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Thunderbird
[2012.07.06 13:19:24 | 000,000,000 | ---D | M] -- C:\Profile\All Users\Anwendungsdaten\ESET
[2012.03.30 13:19:49 | 000,000,000 | ---D | M] -- C:\Profile\All Users\Anwendungsdaten\regid.1986-12.com.adobe
[2011.01.31 13:40:44 | 000,000,000 | ---D | M] -- C:\Profile\All Users\Anwendungsdaten\Swiss Academic Software
[2012.07.09 09:40:17 | 000,000,000 | ---D | M] -- C:\Profile\doehlerm\Anwendungsdaten\ESET
[2011.05.25 20:11:41 | 000,000,000 | ---D | M] -- C:\Profile\doehlerm\Anwendungsdaten\ICAClient
[2011.02.01 12:03:56 | 000,000,000 | ---D | M] -- C:\Profile\doehlerm\Anwendungsdaten\Swiss Academic Software
[2011.03.09 14:53:38 | 000,000,000 | ---D | M] -- C:\Profile\doehlerm\Anwendungsdaten\Thunderbird
[2008.06.16 11:49:30 | 000,000,000 | ---D | M] -- C:\Profile\hildebrh\Anwendungsdaten\CoSoSys
[2008.06.16 13:00:03 | 000,000,000 | ---D | M] -- C:\Profile\hildebrh\Anwendungsdaten\ICAClient
[2012.03.23 12:29:30 | 000,000,000 | ---D | M] -- C:\Profile\mda\Anwendungsdaten\Swiss Academic Software
[2012.04.13 13:40:46 | 000,000,000 | ---D | M] -- C:\Profile\mda\Anwendungsdaten\Thunderbird
[2011.03.31 10:25:04 | 000,000,000 | ---D | M] -- C:\Profile\rackteua\Anwendungsdaten\Swiss Academic Software
[2011.09.13 13:40:14 | 000,000,000 | ---D | M] -- C:\Profile\shkjbob\Anwendungsdaten\Swiss Academic Software
[2012.06.29 13:28:10 | 000,000,274 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.03.29 12:49:59 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Adobe
[2008.05.30 13:35:47 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Apple Computer
[2008.06.02 15:50:33 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ATI
[2012.07.06 13:20:46 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ESET
[2010.02.03 15:36:53 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\GHISLER
[2008.05.30 13:41:51 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ICAClient
[2008.05.30 12:19:58 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Identities
[2008.05.30 11:21:31 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\InstallShield
[2010.01.22 11:51:35 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Macromedia
[2012.06.29 15:12:01 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Malwarebytes
[2011.03.16 15:06:31 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\McAfee
[2012.06.29 13:49:41 | 000,000,000 | --SD | M] -- C:\Profile\Administrator\Anwendungsdaten\Microsoft
[2008.05.30 15:51:50 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Mozilla
[2008.07.07 15:12:37 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\OfficeUpdate12
[2008.05.30 14:31:53 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Sun
[2011.01.31 13:44:26 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Swiss Academic Software
[2008.05.30 16:22:56 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Talkback
[2011.03.09 14:44:40 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Thunderbird
 
< %APPDATA%\*.exe /s >
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2006.03.02 17:57:59 | 016,721,925 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.05.30 14:49:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.05.30 14:49:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
 
< MD5 for: ATAPI.SYS  >
[2006.03.02 17:57:59 | 016,721,925 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.05.30 14:49:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.05.30 14:49:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
 
< MD5 for: EVENTLOG.DLL  >
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll
[2004.08.04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
 
< MD5 for: NETLOGON.DLL  >
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll
[2004.08.04 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
 
< MD5 for: SCECLI.DLL  >
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll
[2004.08.04 13:00:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
 
< MD5 for: USER32.DLL  >
[2006.03.02 17:44:00 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe
[2004.08.04 13:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2004.08.04 13:00:00 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2004.08.04 13:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2004.08.04 13:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008.05.29 18:14:07 | 000,098,304 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2008.05.29 18:14:07 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2008.05.29 18:14:07 | 000,450,560 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< End of report >


cosinus 10.07.2012 13:08

Zitat:

PRC - C:\Programme\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\Programme\ESET\ESET Smart Security\ekrn.exe (ESET)
Das fällt mir ja jetzt erst auf :headbang:

Willst du dein System in die Knie zwingen? Zwei solcher Virenscanner installiert man niemals parallel! Deinstalliere einen der beiden!

Max. Malwarebytes kann man zu einem installierten Virenscanner benutzen, bei Malwarebytes würde ich aber die reine Free-Variante ohne Hintergrundschutz-Modul verwenden.
(die anderen Scanner die ich hier in der Bereinigung/Analyse verwende kommen den anderen auch nichts ins Gehege)

mot2001 10.07.2012 13:19

ESET und Malwarebytes hatte ich nur installiert, weil Sie mir hier im Board diese SW zur Herstellung der Logfiles vorgeschlagen hatten. Normalerweise habe ich nur McAfee installiert. Die anderen Tools deinstalliere ich nach Eurer Analyse sowieso wieder. McAfee hatte ich wie auch hier vorgeschlagen deaktiviert.

cosinus 10.07.2012 20:05

Na, nur weil wir hier mit dem ESET-OnlineScanner arbeiten ist das keine Pauschalaufforderung für jeden die normale Version von ESET einfach zu installiert :eek:

Zwei solcher Tools gehen eigentlich garnicht und deswegen sollst du jetzt ja auch einen der beiden umgehend deinstallieren, also ESET

mot2001 10.07.2012 20:40

ich finde, Du koenntest Deine Art, hier mit ganz normalen Menschen umzugehen, ein bisschen ueberpruefen. Weshalb ich ESET auf dem PC installiert habe und nicht die OnlineVersion, hatte ich auch hier gepostet. Lesen und Verstehen schuetzt vor falschen Behauptungen. Vielleicht solltest Du von Deinem hohen Ross ein bisschen runterkommen. Unsereins ist wirklich dankbar fuer Eure Arbeit, aber keiner aus Eurem wirklich nuetzlichen Forum muss uns zeigen, wie schlau er ist. Wir wissen es.

cosinus 10.07.2012 22:29

Sry aber jetzt vergreifst du dich im Ton!
Wir verweisen nicht aus Spaß auf die Online-Variante, wenn die nicht geht hättest du erst mal nachfragen können anstatt einfach ESET richtig zu installieren!

Du machst etwas falsch, ich erklär dir warum es falsch ist und dann bist du auch noch beleidigt! Mit deiner infantilen Einstellung kann und will ich dir nicht helfen

mot2001 11.07.2012 08:19

ein bisschen Freundlichkeit ist nicht zu viel verlangt und wenn das infantil ist, dann bin ich es. Vielleicht koenntest Du jemand anderen hier im Board vorschlagen, der die Arbeit mit mir fortsetzt?

cosinus 11.07.2012 10:07

Ich hab dir deutlich mitgeteilt, dass zwei Virenscanner wie McAfee und das ESET-Teil was du installiert hast, das System negativ beeinträchtigen. Mir ist das natürlich erst danach aufgefallen, dass du dann zwei Virenscanner im System hattest, aber erst wäre wirklich sinnvoller gewesen wenn du erst nachgfragt hättest was nun passieren soll da ja die Online-Variante nicht funktionierte

Auf meinen deutlichen Hinweis reagierst du mit patzigen Antworten, eigentlich bist du es der hier unfreundlich war!

Zitat:

ein bisschen Freundlichkeit ist nicht zu viel verlangt
genau, denk mal drüber nach!

mot2001 11.07.2012 10:28

ok, koennen wir jetzt noch auf ganz sachlicher Ebene weitermachen oder wird der Thread jetzt beendet? ESET habe ich jeden falls deinstalliert.

cosinus 11.07.2012 12:03

Warum fängst du hier überhaupt an mir Unfreundlichkeit vorzuwerfen?
Lag es am Smilie => :headbang:
Wenn ja, der war an mich selbst gerichtet weil ich es übersehen habe, dass du zwei Scanner installiert hast!
Ich hab mich höchstens ein wenig darüber gewundert, dass du einfach was installierst ohne Absprache, mir wäre ein Nachfragen, was passieren soll wenn der OnlineScanner nicht geht, lieber gewesen!

mot2001 11.07.2012 12:32

na gut, ich denke, vielleicht ein wenig ueberreagiert zu haben - Sorry, ich habe mich an diese Forensprache einfach noch nicht gewoehnt.

cosinus 11.07.2012 12:42

Hast du den "echten" ESET deinstalliert? Wenn ja, brauch ich wie o.g. ein neues OTL-Log

mot2001 11.07.2012 13:22

ja, ESET war schon komplett deinstalliert und danach hatte ich auch einen Neustart durchgefuehrt. McAfee hatte ich saemtliche Einstellungen deaktiviert. Danach die neueste OTL runtergeladen und bin dann wie beim letzten OTL Durchlauf vorgegangen

Hier also die neueste OTL log:

Code:

OTL logfile created on: 11.07.2012 14:06:14 - Run 4
OTL by OldTimer - Version 3.2.53.1    Folder = C:\Profile\Administrator\Eigene Dateien\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,46 Gb Available Physical Memory | 73,08% Memory free
3,85 Gb Paging File | 3,43 Gb Available in Paging File | 89,21% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 232,88 Gb Total Space | 177,61 Gb Free Space | 76,27% Space Free | Partition Type: NTFS
 
Computer Name: THEO99 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Profile\Administrator\Eigene Dateien\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Programme\Common\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\VirusScan Enterprise\mcconsol.exe (McAfee, Inc.)
PRC - C:\Programme\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
PRC - C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Programme\Nero\Nero 7\InCD\InCD.exe (Nero AG)
PRC - C:\Programme\Common\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\Programme\McAfee\Common Framework\boost_thread-vc80-mt-1_32.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3054.18653__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3054.18892__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3054.18608__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3054.18668__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3054.18882__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3054.18645__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3054.18630__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard\2.0.3054.18864__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3054.18924__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3054.18837__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3054.18782__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3054.18848__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3054.18932__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Dashboard\2.0.3054.18660__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3054.18855__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3054.18623__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3054.18846__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Runtime\2.0.3054.18659__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3054.18793__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3054.18871__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3054.18792__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3054.18885__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashboard\2.0.3054.18840__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3054.18683__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3054.18777__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3054.18632__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3054.18676__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3054.18814__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3054.18783__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3054.18690__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3054.18812__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3054.18827__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3054.18785__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3054.18791__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3005.17490__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3005.17473__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3005.17516__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3005.17562__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3005.17512__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3005.17563__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.3005.17468__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3005.17493__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3005.17540__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3005.17556__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.3005.17465__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3005.17466__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3005.17608__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3005.17518__90ba9c70f846762e\DEM.OS.I0602.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3005.17496__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3005.17491__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3005.17479__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Shared\2.0.3005.17531__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.3005.17510__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.OS\2.0.3005.17517__90ba9c70f846762e\DEM.OS.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics\2.0.3005.17519__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3005.17488__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3005.17530__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3005.17521__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3005.17536__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3005.17522__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3005.17541__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3005.17535__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3005.17535__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3005.17539__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3005.17506__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3005.17531__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3005.17521__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3005.17537__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3005.17514__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\APM.Foundation\2.0.3005.17511__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3005.17489__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3054.18949__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3054.18597__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.3054.18910__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3005.17484__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOCALIZATION.Foundation.Private\2.0.3005.17481__90ba9c70f846762e\LOCALIZATION.Foundation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3054.18907__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3005.17475__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3005.17511__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3054.18639__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3005.17513__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3054.18597__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3005.17514__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3005.17508__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3054.18617__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\ATIDEMOS\2.0.3054.18598__90ba9c70f846762e\ATIDEMOS.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3005.17499__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.3054.18909__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3005.17542__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\APM.Server\2.0.3054.18594__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Server\2.0.3054.18596__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\Programme\McAfee\Common Framework\ccme_base.dll ()
MOD - C:\Programme\McAfee\Common Framework\cryptocme2.dll ()
MOD - C:\WINDOWS\system32\pdfcmnnt.dll ()
MOD - C:\WINDOWS\system32\HPBHealr.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (mfevtp) -- C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McShield) -- C:\Programme\Common\McAfee\SystemCore\\mcshield.exe ()
SRV - (odserv) -- C:\Programme\Common\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (McAfeeFramework) -- C:\Programme\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (McTaskManager) -- C:\Programme\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
SRV - (InCDsrv) -- C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (NMIndexingService) -- C:\Programme\Common\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (ose) -- C:\Programme\Common\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (MDM) -- C:\Programme\Common\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (WDICA) --  File not found
DRV - (PDRFRAME) --  File not found
DRV - (PDRELI) --  File not found
DRV - (PDFRAME) --  File not found
DRV - (PDCOMP) --  File not found
DRV - (PCIDump) --  File not found
DRV - (mferkdk) -- C:\Programme\McAfee\VirusScan Enterprise\mferkdk.sys File not found
DRV - (mfeavfk01) --  File not found
DRV - (lbrtfdc) --  File not found
DRV - (i2omgmt) --  File not found
DRV - (GMSIPCI) -- D:\INSTALL\GMSIPCI.SYS File not found
DRV - (Changer) --  File not found
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdet) -- C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) -- C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation                          )
DRV - (InCDfs) -- C:\WINDOWS\system32\drivers\InCDfs.sys (Nero AG)
DRV - (incdrm) -- C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (InCDPass) -- C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (InCDrec) -- C:\WINDOWS\System32\drivers\InCDrec.sys (Nero AG)
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (irsir) -- C:\WINDOWS\system32\drivers\irsir.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
 
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
 
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
 
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\Software\Microsoft\Internet Explorer\SearchURL\g, = hxxp://www.google.com/search?hl=en&q=%s
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\..\SearchScopes,DefaultScope = {92FD8C98-6028-4617-BA31-64982853525E}
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\..\SearchScopes\{92FD8C98-6028-4617-BA31-64982853525E}: "URL" = hxxp://www.google.de/search?q={searchTerms}
IE - HKU\S-1-5-21-515967899-492894223-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {8AA36F4F-6DC7-4c06-77AF-5035170634FE}:2011.01.25
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Programme\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc;version=0.8.6f: C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN Team)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}: C:\Profile\All Users\Anwendungsdaten\Swiss Academic Software\Citavi Picker\Firefox [2011.01.31 13:40:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Programme\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012.03.29 12:48:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Programme\Common\McAfee\SystemCore [2012.07.11 11:51:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.07.06 13:04:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012.04.25 11:12:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2012.04.13 13:40:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
 
[2011.03.09 14:44:42 | 000,000,000 | ---D | M] (No name found) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Extensions
[2011.03.09 14:44:42 | 000,000,000 | ---D | M] (No name found) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.07.04 11:53:13 | 000,000,000 | ---D | M] (No name found) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\extensions
[2011.01.31 14:02:31 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.07.06 13:05:07 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.04.25 10:59:01 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAMME\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012.07.06 13:04:59 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2012.04.25 10:58:59 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll
[2012.07.06 13:04:50 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.07.06 13:04:50 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.07.06 13:04:50 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.06 13:04:50 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.06 13:04:50 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.06 13:04:50 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2004.08.04 13:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\Common\McAfee\SystemCore\ScriptSn.20120413102718.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-515967899-492894223-839522115-500\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Programme\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Programme\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Common\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Programme\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [InCD] C:\Programme\Nero\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [LanguageShortcut] C:\Programme\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Programme\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Common\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [SecurDisc] C:\Programme\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
O4 - HKLM..\Run: [ShStatEXE] C:\Programme\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\.DEFAULT..\RunOnce: [nlsf] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [nlsf] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [nlsf] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [nlsf] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-515967899-492894223-839522115-500..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10n_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = B5 00 00 00  [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-515967899-492894223-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Citavi Picker... - C:\Profile\All Users\Anwendungsdaten\Swiss Academic Software\Citavi Picker\Internet Explorer\ShowContextMenu.html ()
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O15 - HKU\S-1-5-21-515967899-492894223-839522115-500\..Trusted Domains: microsoft.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-515967899-492894223-839522115-500\..Trusted Domains: microsoft.com ([*.update] * in Trusted sites)
O15 - HKU\S-1-5-21-515967899-492894223-839522115-500\..Trusted Domains: microsoft.com ([*.windowsupdate] * in Trusted sites)
O15 - HKU\S-1-5-21-515967899-492894223-839522115-500\..Trusted Domains: windowsupdate.com ([]* in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1212150358734 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1340968528124 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} hxxp://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = user.hu-berlin.de
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7E608E10-CB07-4588-8B69-C9422848FAE7}: NameServer = 141.20.1.3,141.20.1.31
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.05.29 16:21:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: 6to4 -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: mfehidk - C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
SafeBootNet: mfehidk.sys - C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
SafeBootNet: mfevtp - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - Microsoft Outlook Express 6
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Sicherheitsupdate für Windows XP (KB923789)
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {881dd1c5-3dcf-431b-b061-f3f88e8be88a} -
ActiveX: {8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C314CE45-3392-3B73-B4E1-139CD41CA933} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
ActiveX: Microsoft Base Smart Card Crypto Provider Package -
 
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.11 11:48:38 | 000,000,000 | RH-D | C] -- C:\Profile\Administrator\Recent
[2012.07.06 13:20:46 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\ESET
[2012.07.06 13:20:46 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Anwendungsdaten\ESET
[2012.07.06 13:20:32 | 000,000,000 | ---D | C] -- C:\Profile\LocalService\Lokale Einstellungen\Anwendungsdaten\ESET
[2012.07.06 13:05:12 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Anwendungsdaten\Mozilla
[2012.07.06 13:05:10 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Maintenance Service
[2012.07.03 14:23:13 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\GHISLER
[2012.07.03 12:26:54 | 000,000,000 | ---D | C] -- C:\Programme\stinger
[2012.06.29 15:12:01 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Anwendungsdaten\Malwarebytes
[2012.06.29 15:11:35 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Anwendungsdaten\Malwarebytes
[2012.06.29 13:53:14 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Startmenü\Programme\Microsoft Silverlight
[2012.06.29 13:49:58 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Silverlight
[2012.06.29 13:49:43 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Dokumente\microsoft
[2012.06.29 13:49:35 | 000,000,000 | ---D | C] -- C:\Programme\Windows Live SkyDrive
[2012.06.29 13:48:27 | 000,000,000 | ---D | C] -- C:\Programme\Common\Windows Live
[2012.06.29 13:47:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\WindowsPowerShell
[2012.06.29 13:47:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\winrm
[2012.06.29 13:47:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2012.06.29 13:47:31 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$968930Uinstall_KB968930$
[2012.06.29 13:46:17 | 000,000,000 | ---D | C] -- C:\Programme\Windows Media Connect 2
[2012.06.29 13:44:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2012.06.29 13:44:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2012.06.29 13:28:34 | 000,000,000 | -HSD | C] -- C:\Profile\Administrator\PrivacIE
[2012.06.29 13:27:35 | 000,000,000 | ---D | C] -- C:\Profile\All Users\Startmenü\Programme\Microsoft Office Live Add-in
[2012.06.29 13:27:34 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft
[2012.06.29 13:25:16 | 000,000,000 | R--D | C] -- C:\Profile\Administrator\Eigene Dateien\Eigene Musik
[2012.06.29 13:25:15 | 000,000,000 | R--D | C] -- C:\Profile\Administrator\Eigene Dateien\Eigene Bilder
[2012.06.29 13:25:14 | 000,000,000 | -HSD | C] -- C:\Profile\Administrator\IETldCache
[2012.06.29 13:21:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2012.06.29 13:18:40 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2012.06.29 11:05:46 | 000,000,000 | ---D | C] -- C:\Profile\Administrator\Lokale Einstellungen\Anwendungsdaten\AskToolbar
[2012.06.28 16:57:26 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.11 11:49:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.07.11 11:29:24 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.07.09 15:07:22 | 000,618,655 | ---- | M] () -- C:\Profile\Administrator\Desktop\adwcleaner.exe
[2012.07.06 10:24:57 | 000,002,064 | ---- | M] () -- C:\Profile\Administrator\Desktop\alteLogs.zip
[2012.07.04 16:21:36 | 000,019,080 | ---- | M] () -- C:\Profile\Administrator\Desktop\Logfiles.7z
[2012.07.04 09:55:40 | 000,027,506 | ---- | M] () -- C:\cc_20120704_095454.reg
[2012.07.04 09:53:07 | 000,000,654 | ---- | M] () -- C:\Profile\All Users\Desktop\CCleaner.lnk
[2012.07.03 12:27:12 | 000,475,704 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfehidk.sys
[2012.07.03 12:27:12 | 000,159,608 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\mfevtps.exe
[2012.07.03 12:27:12 | 000,087,656 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mferkdet.sys
[2012.06.29 15:05:15 | 000,496,252 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2012.06.29 15:05:15 | 000,475,942 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.06.29 15:05:15 | 000,092,010 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2012.06.29 15:05:15 | 000,076,976 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.06.29 13:54:38 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012.06.29 13:46:31 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2012.06.29 13:46:31 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2012.06.29 13:44:49 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2012.06.29 13:28:10 | 000,000,274 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2012.06.14 08:14:27 | 000,726,296 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.07.09 15:07:21 | 000,618,655 | ---- | C] () -- C:\Profile\Administrator\Desktop\adwcleaner.exe
[2012.07.06 10:24:57 | 000,002,064 | ---- | C] () -- C:\Profile\Administrator\Desktop\alteLogs.zip
[2012.07.04 16:21:36 | 000,019,080 | ---- | C] () -- C:\Profile\Administrator\Desktop\Logfiles.7z
[2012.07.04 09:55:02 | 000,027,506 | ---- | C] () -- C:\cc_20120704_095454.reg
[2012.06.29 13:44:49 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2012.06.29 13:43:39 | 000,225,262 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msimain.sdb
[2012.04.27 11:13:47 | 000,079,360 | ---- | C] () -- C:\WINDOWS\MULTIKYB.DLL
[2012.04.27 11:13:47 | 000,064,584 | ---- | C] () -- C:\WINDOWS\MultiKey.ini
[2012.04.27 11:13:47 | 000,057,856 | ---- | C] () -- C:\WINDOWS\Multikey.exe
[2012.02.16 16:13:48 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011.01.20 13:45:57 | 000,000,032 | ---- | C] () -- C:\WINDOWS\Menu.INI
[2008.06.16 11:26:43 | 000,009,630 | RHS- | C] () -- C:\Profile\All Users\ntuser.pol
 
========== LOP Check ==========
 
[2012.07.06 13:20:46 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ESET
[2010.02.03 15:36:53 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\GHISLER
[2008.05.30 13:41:51 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ICAClient
[2008.07.07 15:12:37 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\OfficeUpdate12
[2011.01.31 13:44:26 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Swiss Academic Software
[2011.03.09 14:44:40 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Thunderbird
[2012.03.30 13:19:49 | 000,000,000 | ---D | M] -- C:\Profile\All Users\Anwendungsdaten\regid.1986-12.com.adobe
[2011.01.31 13:40:44 | 000,000,000 | ---D | M] -- C:\Profile\All Users\Anwendungsdaten\Swiss Academic Software
[2012.07.09 09:40:17 | 000,000,000 | ---D | M] -- C:\Profile\doehlerm\Anwendungsdaten\ESET
[2011.05.25 20:11:41 | 000,000,000 | ---D | M] -- C:\Profile\doehlerm\Anwendungsdaten\ICAClient
[2011.02.01 12:03:56 | 000,000,000 | ---D | M] -- C:\Profile\doehlerm\Anwendungsdaten\Swiss Academic Software
[2011.03.09 14:53:38 | 000,000,000 | ---D | M] -- C:\Profile\doehlerm\Anwendungsdaten\Thunderbird
[2008.06.16 11:49:30 | 000,000,000 | ---D | M] -- C:\Profile\hildebrh\Anwendungsdaten\CoSoSys
[2008.06.16 13:00:03 | 000,000,000 | ---D | M] -- C:\Profile\hildebrh\Anwendungsdaten\ICAClient
[2012.03.23 12:29:30 | 000,000,000 | ---D | M] -- C:\Profile\mda\Anwendungsdaten\Swiss Academic Software
[2012.04.13 13:40:46 | 000,000,000 | ---D | M] -- C:\Profile\mda\Anwendungsdaten\Thunderbird
[2011.03.31 10:25:04 | 000,000,000 | ---D | M] -- C:\Profile\rackteua\Anwendungsdaten\Swiss Academic Software
[2011.09.13 13:40:14 | 000,000,000 | ---D | M] -- C:\Profile\shkjbob\Anwendungsdaten\Swiss Academic Software
[2012.06.29 13:28:10 | 000,000,274 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.03.29 12:49:59 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Adobe
[2008.05.30 13:35:47 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Apple Computer
[2008.06.02 15:50:33 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ATI
[2012.07.06 13:20:46 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ESET
[2010.02.03 15:36:53 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\GHISLER
[2008.05.30 13:41:51 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\ICAClient
[2008.05.30 12:19:58 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Identities
[2008.05.30 11:21:31 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\InstallShield
[2010.01.22 11:51:35 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Macromedia
[2012.06.29 15:12:01 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Malwarebytes
[2011.03.16 15:06:31 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\McAfee
[2012.06.29 13:49:41 | 000,000,000 | --SD | M] -- C:\Profile\Administrator\Anwendungsdaten\Microsoft
[2008.05.30 15:51:50 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Mozilla
[2008.07.07 15:12:37 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\OfficeUpdate12
[2008.05.30 14:31:53 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Sun
[2011.01.31 13:44:26 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Swiss Academic Software
[2008.05.30 16:22:56 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Talkback
[2011.03.09 14:44:40 | 000,000,000 | ---D | M] -- C:\Profile\Administrator\Anwendungsdaten\Thunderbird
 
< %APPDATA%\*.exe /s >
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2006.03.02 17:57:59 | 016,721,925 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.05.30 14:49:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.05.30 14:49:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
 
< MD5 for: ATAPI.SYS  >
[2006.03.02 17:57:59 | 016,721,925 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.05.30 14:49:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.05.30 14:49:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
 
< MD5 for: EVENTLOG.DLL  >
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll
[2004.08.04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
 
< MD5 for: NETLOGON.DLL  >
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll
[2004.08.04 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
 
< MD5 for: SCECLI.DLL  >
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll
[2004.08.04 13:00:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
 
< MD5 for: USER32.DLL  >
[2006.03.02 17:44:00 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe
[2004.08.04 13:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2004.08.04 13:00:00 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2004.08.04 13:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2004.08.04 13:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008.05.29 18:14:07 | 000,098,304 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2008.05.29 18:14:07 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2008.05.29 18:14:07 | 000,450,560 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
 
<          >

< End of report >


cosinus 11.07.2012 14:16

Code:

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = user.hu-berlin.de
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7E608E10-CB07-4588-8B69-C9422848FAE7}: NameServer = 141.20.1.3,141.20.1.31

Rechner in der Uni? Humboldt Uni Berlin?
Fester Rechner, dein Rechner?

:confused:

mot2001 11.07.2012 14:19

Ja, das ist mein Rechner in der Uni. Gibt es da Probleme. Wir haben leider keine Virenspezialisten.

cosinus 11.07.2012 14:46

Was heißt "dein" Rechner, ist es dein eigener Rechner oder Eigentum der Uni und du arbeitest an diesem Rechner nur?

mot2001 11.07.2012 14:52

der Rechner ist Eigentum der Uni.

cosinus 11.07.2012 14:58

Sry genau das dachte ich mir.
Das verhält sich wie ein Büro-PC
Mag sein, das ihr in der Uni keinen Virenspezi habt, aber da dieser Rechner der Uni gehört muss es einen administrativ Verantwortlichen für diesen Rechner geben, der dir bei diesem Problem weiterhelfen muss

Ist mir sowieso unbegreiflich, dass jmd an festen Uni-Rechnern Adminrechte bekommt



Siehe => http://www.trojaner-board.de/108422-...-anfragen.html

Zitat:

3. Grundsätzlich bereinigen wir keine gewerblich genutzten Rechner. Dafür ist die IT Abteilung eurer Firma zuständig.

Bei Kleinunternehmen, welche keinen IT Support haben, machen wir da eine Ausnahme und helfen gerne ( kleine Spende hilft auch uns ).
Voraussetzung: Ihr teilt uns dies in eurer ersten Antwort mit.
Bedenkt jedoch, dass Logfiles viele heikle Informationen enthalten können ( Kundendaten, Bankdaten, etc ) sowie das Malware die Möglichkeit besitzt, diese auszuspähen und zu missbrauchen. Hier legen wir euch ein Formatieren und Neuaufsetzen nahe.

mot2001 11.07.2012 15:25

naja, die Uni ist zwar kein Gewerbe sondern Dienst an der Oeffentlichkeit, sie macht in jedem Falle kein Gewinn. Mehr kann ich dazu nicht sagen.

cosinus 11.07.2012 21:49

Naja ich würde hier schon eine Ausnahme machen, so ist das ja nicht, weil in unserem Strang ja nun wirklich nicht von Uni-Rechnern die Rede ist
Aber dennoch finde ich das schon etwas merkwürdig, bei einer Uni sollte man schon erwarten dürfen, dass es dort Admins gibt die sich auch für die Rechner im Uni-Netz verantwortlich fühlen! Und auch tatsächlich dafür zuständig sind und dann auch bei Problemen/Fragen verfügbar sind und handeln!


Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - user.js - File not found
[2011.01.31 14:02:31 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
O4 - HKLM..\Run: []  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-515967899-492894223-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.05.29 16:21:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

mot2001 12.07.2012 08:36

das habe ich jetzt auch unter Befolgung Deiner Hinweise gemacht.
Die Nutzernamen ersetze ich durch xxx:

All processes killed
========== OTL ==========
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: true removed from browser.search.useDBForOrder
C:\Profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults\preferences folder moved successfully.
C:\Profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults folder moved successfully.
C:\Profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome folder moved successfully.
C:\Profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} folder moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\HonorAutoRunSetting deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableStatusMessages deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\VerboseStatus deleted successfully.
Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun not found.
Registry value HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-515967899-492894223-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\AUTOEXEC.BAT moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 210481140 bytes
->Temporary Internet Files folder emptied: 6517016 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 63470995 bytes
->Flash cache emptied: 795 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: xxx
->Temp folder emptied: 599383239 bytes
->Temporary Internet Files folder emptied: 7044989 bytes
->Java cache emptied: 2419591 bytes
->FireFox cache emptied: 58214590 bytes
->Flash cache emptied: 11912 bytes

User: xxx
->Temp folder emptied: 4153384 bytes
->Temporary Internet Files folder emptied: 8502736 bytes
->FireFox cache emptied: 12271427 bytes

User: xxx
->Temp folder emptied: 91672715 bytes
->Temporary Internet Files folder emptied: 12744405 bytes
->Java cache emptied: 1522498 bytes
->FireFox cache emptied: 35311829 bytes
->Flash cache emptied: 1535537 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: xxx
->Temp folder emptied: 21719393 bytes
->Temporary Internet Files folder emptied: 3937255 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 46307141 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33237 bytes

User: xxx
->Temp folder emptied: 587497 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: xxx
->Temp folder emptied: 667325 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 44650233 bytes
->Flash cache emptied: 456 bytes

User: xxx
->Temp folder emptied: 962183 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 47600070 bytes
->Flash cache emptied: 456 bytes

User: xxx
->Temp folder emptied: 588347 bytes
->Temporary Internet Files folder emptied: 44668029 bytes
->Java cache emptied: 284967 bytes
->FireFox cache emptied: 2928589 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2134333 bytes
%systemroot%\System32 .tmp files removed: 2951 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 9375488 bytes
RecycleBin emptied: 1374624 bytes

Total Files Cleaned = 1.281,00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default User

User: xxx
->Flash cache emptied: 0 bytes

User: xxx

User: xxx
->Flash cache emptied: 0 bytes

User: LocalService

User: xxx

User: NetworkService

User: xxx

User: xxx
->Flash cache emptied: 0 bytes

User: xxx
->Flash cache emptied: 0 bytes

User: xxx

Total Flash Files Cleaned = 0,00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.53.1 log created on 07122012_092132

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

cosinus 12.07.2012 10:53

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

mot2001 12.07.2012 11:50

ok, hab ich unter Beachtung Deiner Hinweise ausgefuehrt:

Code:

12:43:00.0114 2388        TDSS rootkit removing tool 2.7.45.0 Jul  9 2012 12:46:35
12:43:00.0332 2388        ============================================================
12:43:00.0332 2388        Current date / time: 2012/07/12 12:43:00.0332
12:43:00.0332 2388        SystemInfo:
12:43:00.0332 2388       
12:43:00.0332 2388        OS Version: 5.1.2600 ServicePack: 3.0
12:43:00.0332 2388        Product type: Workstation
12:43:00.0332 2388        ComputerName: THEO99
12:43:00.0332 2388        UserName: Administrator
12:43:00.0332 2388        Windows directory: C:\WINDOWS
12:43:00.0332 2388        System windows directory: C:\WINDOWS
12:43:00.0332 2388        Processor architecture: Intel x86
12:43:00.0332 2388        Number of processors: 2
12:43:00.0332 2388        Page size: 0x1000
12:43:00.0332 2388        Boot type: Normal boot
12:43:00.0332 2388        ============================================================
12:43:01.0301 2388        Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
12:43:01.0317 2388        ============================================================
12:43:01.0317 2388        \Device\Harddisk0\DR0:
12:43:01.0317 2388        MBR partitions:
12:43:01.0317 2388        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1D1C0681
12:43:01.0317 2388        ============================================================
12:43:01.0332 2388        C: <-> \Device\Harddisk0\DR0\Partition0
12:43:01.0332 2388        ============================================================
12:43:01.0332 2388        Initialize success
12:43:01.0332 2388        ============================================================
12:44:16.0937 2932        ============================================================
12:44:16.0937 2932        Scan started
12:44:16.0937 2932        Mode: Manual; SigCheck; TDLFS;
12:44:16.0937 2932        ============================================================
12:44:18.0109 2932        Abiosdsk - ok
12:44:18.0109 2932        abp480n5 - ok
12:44:18.0156 2932        ACPI            (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
12:44:19.0078 2932        ACPI - ok
12:44:19.0109 2932        ACPIEC          (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\drivers\ACPIEC.sys
12:44:19.0234 2932        ACPIEC - ok
12:44:19.0234 2932        adpu160m - ok
12:44:19.0265 2932        aec            (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
12:44:19.0390 2932        aec - ok
12:44:19.0421 2932        AFD            (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
12:44:19.0484 2932        AFD - ok
12:44:19.0484 2932        Aha154x - ok
12:44:19.0500 2932        aic78u2 - ok
12:44:19.0500 2932        aic78xx - ok
12:44:19.0531 2932        Alerter        (738d80cc01d7bc7584be917b7f544394) C:\WINDOWS\system32\alrsvc.dll
12:44:19.0656 2932        Alerter - ok
12:44:19.0687 2932        ALG            (190cd73d4984f94d823f9444980513e5) C:\WINDOWS\System32\alg.exe
12:44:19.0750 2932        ALG - ok
12:44:19.0765 2932        AliIde - ok
12:44:19.0796 2932        AmdK8          (58be3c2f1aa041ea56f7305a6463035c) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
12:44:19.0812 2932        AmdK8 ( UnsignedFile.Multi.Generic ) - warning
12:44:19.0812 2932        AmdK8 - detected UnsignedFile.Multi.Generic (1)
12:44:19.0812 2932        amsint - ok
12:44:19.0843 2932        AppMgmt        (d45960be52c3c610d361977057f98c54) C:\WINDOWS\System32\appmgmts.dll
12:44:19.0921 2932        AppMgmt - ok
12:44:19.0921 2932        asc - ok
12:44:19.0921 2932        asc3350p - ok
12:44:19.0937 2932        asc3550 - ok
12:44:20.0203 2932        aspnet_state    (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
12:44:20.0234 2932        aspnet_state - ok
12:44:20.0250 2932        AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
12:44:20.0375 2932        AsyncMac - ok
12:44:20.0390 2932        atapi          (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
12:44:20.0531 2932        atapi - ok
12:44:20.0531 2932        Atdisk - ok
12:44:20.0625 2932        Ati HotKey Poller (5ceda44447a28db469de28afc0950650) C:\WINDOWS\system32\Ati2evxx.exe
12:44:20.0640 2932        Ati HotKey Poller ( UnsignedFile.Multi.Generic ) - warning
12:44:20.0640 2932        Ati HotKey Poller - detected UnsignedFile.Multi.Generic (1)
12:44:20.0718 2932        ATI Smart      (737371583e0173f963d74435be3e96d2) C:\WINDOWS\system32\ati2sgag.exe
12:44:20.0765 2932        ATI Smart ( UnsignedFile.Multi.Generic ) - warning
12:44:20.0765 2932        ATI Smart - detected UnsignedFile.Multi.Generic (1)
12:44:20.0984 2932        ati2mtag        (b63516824da0d8b9ad136e6e044a795f) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
12:44:21.0156 2932        ati2mtag ( UnsignedFile.Multi.Generic ) - warning
12:44:21.0156 2932        ati2mtag - detected UnsignedFile.Multi.Generic (1)
12:44:22.0265 2932        Atmarpc        (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
12:44:22.0390 2932        Atmarpc - ok
12:44:22.0437 2932        AudioSrv        (58ed0d5452df7be732193e7999c6b9a4) C:\WINDOWS\System32\audiosrv.dll
12:44:22.0578 2932        AudioSrv - ok
12:44:22.0609 2932        audstub        (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
12:44:22.0734 2932        audstub - ok
12:44:22.0749 2932        Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
12:44:22.0890 2932        Beep - ok
12:44:22.0921 2932        BITS            (d6f603772a789bb3228f310d650b8bd1) C:\WINDOWS\system32\qmgr.dll
12:44:23.0062 2932        BITS - ok
12:44:23.0077 2932        Browser        (b42057f06bbb98b31876c0b3f2b54e33) C:\WINDOWS\System32\browser.dll
12:44:23.0249 2932        Browser - ok
12:44:23.0281 2932        cbidf2k        (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
12:44:23.0406 2932        cbidf2k - ok
12:44:23.0421 2932        cd20xrnt - ok
12:44:23.0421 2932        Cdaudio        (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
12:44:23.0562 2932        Cdaudio - ok
12:44:23.0577 2932        Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
12:44:23.0718 2932        Cdfs - ok
12:44:23.0734 2932        Cdrom          (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
12:44:23.0890 2932        Cdrom - ok
12:44:23.0890 2932        Changer - ok
12:44:23.0906 2932        CiSvc          (28e3040d1f1ca2008cd6b29dfebc9a5e) C:\WINDOWS\system32\cisvc.exe
12:44:24.0062 2932        CiSvc - ok
12:44:24.0077 2932        ClipSrv        (778a30ed3c134eb7e406afc407e9997d) C:\WINDOWS\system32\clipsrv.exe
12:44:24.0202 2932        ClipSrv - ok
12:44:24.0484 2932        clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:44:24.0515 2932        clr_optimization_v2.0.50727_32 - ok
12:44:24.0702 2932        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:44:24.0718 2932        clr_optimization_v4.0.30319_32 - ok
12:44:24.0718 2932        CmdIde - ok
12:44:24.0734 2932        COMSysApp - ok
12:44:24.0734 2932        Cpqarray - ok
12:44:24.0796 2932        CryptSvc        (611f824e5c703a5a899f84c5f1699e4d) C:\WINDOWS\System32\cryptsvc.dll
12:44:24.0937 2932        CryptSvc - ok
12:44:24.0937 2932        dac2w2k - ok
12:44:24.0952 2932        dac960nt - ok
12:44:24.0999 2932        DcomLaunch      (3127afbf2c1ed0ab14a1bbb7aaecb85b) C:\WINDOWS\system32\rpcss.dll
12:44:25.0046 2932        DcomLaunch - ok
12:44:25.0077 2932        Dhcp            (c29a1c9b75ba38fa37f8c44405dec360) C:\WINDOWS\System32\dhcpcsvc.dll
12:44:25.0218 2932        Dhcp - ok
12:44:25.0249 2932        Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
12:44:25.0405 2932        Disk - ok
12:44:25.0421 2932        dmadmin - ok
12:44:25.0484 2932        dmboot          (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
12:44:25.0640 2932        dmboot - ok
12:44:25.0655 2932        dmio            (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
12:44:25.0796 2932        dmio - ok
12:44:25.0812 2932        dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
12:44:25.0937 2932        dmload - ok
12:44:25.0968 2932        dmserver        (25c83ffbba13b554eb6d59a9b2e2ee78) C:\WINDOWS\System32\dmserver.dll
12:44:26.0109 2932        dmserver - ok
12:44:26.0140 2932        DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
12:44:26.0280 2932        DMusic - ok
12:44:26.0327 2932        Dnscache        (407f3227ac618fd1ca54b335b083de07) C:\WINDOWS\System32\dnsrslvr.dll
12:44:26.0405 2932        Dnscache - ok
12:44:26.0437 2932        Dot3svc        (676e36c4ff5bcea1900f44182b9723e6) C:\WINDOWS\System32\dot3svc.dll
12:44:26.0577 2932        Dot3svc - ok
12:44:26.0765 2932        Dot4            (3e4b043f8bc6be1d4820cc6c9c500306) C:\WINDOWS\system32\DRIVERS\Dot4.sys
12:44:26.0968 2932        Dot4 - ok
12:44:26.0999 2932        Dot4Print      (77ce63a8a34ae23d9fe4c7896d1debe7) C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys
12:44:27.0140 2932        Dot4Print - ok
12:44:27.0140 2932        dpti2o - ok
12:44:27.0155 2932        drmkaud        (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
12:44:27.0296 2932        drmkaud - ok
12:44:27.0327 2932        EapHost        (4e4f2fddab0a0736d7671134dcce91fb) C:\WINDOWS\System32\eapsvc.dll
12:44:27.0452 2932        EapHost - ok
12:44:27.0483 2932        ERSvc          (877c18558d70587aa7823a1a308ac96b) C:\WINDOWS\System32\ersvc.dll
12:44:27.0624 2932        ERSvc - ok
12:44:27.0655 2932        Eventlog        (a3edbe9053889fb24ab22492472b39dc) C:\WINDOWS\system32\services.exe
12:44:27.0687 2932        Eventlog - ok
12:44:27.0718 2932        EventSystem    (af4f6b5739d18ca7972ab53e091cbc74) C:\WINDOWS\system32\es.dll
12:44:27.0765 2932        EventSystem - ok
12:44:27.0796 2932        Fastfat        (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
12:44:27.0921 2932        Fastfat - ok
12:44:27.0952 2932        FastUserSwitchingCompatibility (2db7d303c36ddd055215052f118e8e75) C:\WINDOWS\System32\shsvcs.dll
12:44:27.0999 2932        FastUserSwitchingCompatibility - ok
12:44:28.0015 2932        Fdc            (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
12:44:28.0140 2932        Fdc - ok
12:44:28.0155 2932        Fips            (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
12:44:28.0312 2932        Fips - ok
12:44:28.0343 2932        Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
12:44:28.0468 2932        Flpydisk - ok
12:44:28.0499 2932        FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
12:44:28.0640 2932        FltMgr - ok
12:44:28.0765 2932        FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
12:44:28.0780 2932        FontCache3.0.0.0 - ok
12:44:28.0812 2932        Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
12:44:28.0937 2932        Fs_Rec - ok
12:44:28.0952 2932        Ftdisk          (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
12:44:29.0077 2932        Ftdisk - ok
12:44:29.0077 2932        GMSIPCI - ok
12:44:29.0108 2932        Gpc            (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
12:44:29.0265 2932        Gpc - ok
12:44:29.0296 2932        HDAudBus        (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
12:44:29.0437 2932        HDAudBus - ok
12:44:29.0483 2932        helpsvc        (cb66bf85bf599befd6c6a57c2e20357f) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
12:44:29.0624 2932        helpsvc - ok
12:44:29.0655 2932        HidServ        (b35da85e60c0103f2e4104532da2f12b) C:\WINDOWS\System32\hidserv.dll
12:44:29.0796 2932        HidServ - ok
12:44:29.0796 2932        HidUsb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
12:44:29.0936 2932        HidUsb - ok
12:44:29.0968 2932        hkmsvc          (ed29f14101523a6e0e808107405d452c) C:\WINDOWS\System32\kmsvc.dll
12:44:30.0093 2932        hkmsvc - ok
12:44:30.0108 2932        hpn - ok
12:44:30.0140 2932        HTTP            (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
12:44:30.0186 2932        HTTP - ok
12:44:30.0218 2932        HTTPFilter      (9e4adb854cebcfb81a4b36718feecd16) C:\WINDOWS\System32\w3ssl.dll
12:44:30.0343 2932        HTTPFilter - ok
12:44:30.0343 2932        i2omgmt - ok
12:44:30.0343 2932        i2omp - ok
12:44:30.0374 2932        i8042prt        (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
12:44:30.0530 2932        i8042prt - ok
12:44:30.0640 2932        idsvc          (c01ac32dc5c03076cfb852cb5da5229c) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
12:44:30.0702 2932        idsvc - ok
12:44:30.0702 2932        Imapi          (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
12:44:30.0843 2932        Imapi - ok
12:44:30.0874 2932        ImapiService    (d4b413aa210c21e46aedd2ba5b68d38e) C:\WINDOWS\system32\imapi.exe
12:44:30.0999 2932        ImapiService - ok
12:44:31.0046 2932        InCDfs          (7bfc3eda22190c0fe8c2ca19e5379da5) C:\WINDOWS\system32\drivers\InCDFs.sys
12:44:31.0061 2932        InCDfs - ok
12:44:31.0093 2932        InCDPass        (fc4dbf18a4eb0d2fe3171471a3d0f9a8) C:\WINDOWS\system32\drivers\InCDPass.sys
12:44:31.0108 2932        InCDPass - ok
12:44:31.0124 2932        InCDrec        (f8e7c551def07fdc12ca5cc7ae5d975b) C:\WINDOWS\system32\drivers\InCDrec.sys
12:44:31.0124 2932        InCDrec - ok
12:44:31.0155 2932        incdrm          (31a5a3809249a326eb0ef58d563a9654) C:\WINDOWS\system32\drivers\InCDRm.sys
12:44:31.0155 2932        incdrm - ok
12:44:31.0327 2932        InCDsrv        (c773d093d5c18765e71c7992aee051a2) C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe
12:44:31.0405 2932        InCDsrv - ok
12:44:32.0483 2932        ini910u - ok
12:44:32.0780 2932        IntcAzAudAddService (613a2b00da1d4a80de1ec8cfb52c0d89) C:\WINDOWS\system32\drivers\RtkHDAud.sys
12:44:32.0983 2932        IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - warning
12:44:32.0983 2932        IntcAzAudAddService - detected UnsignedFile.Multi.Generic (1)
12:44:34.0092 2932        IntelIde - ok
12:44:34.0124 2932        Ip6Fw          (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
12:44:34.0264 2932        Ip6Fw - ok
12:44:34.0280 2932        IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
12:44:34.0421 2932        IpFilterDriver - ok
12:44:34.0452 2932        IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
12:44:34.0592 2932        IpInIp - ok
12:44:34.0608 2932        IpNat          (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
12:44:34.0733 2932        IpNat - ok
12:44:34.0764 2932        IPSec          (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
12:44:34.0905 2932        IPSec - ok
12:44:34.0921 2932        irda            (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys
12:44:34.0967 2932        irda - ok
12:44:34.0983 2932        IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
12:44:35.0061 2932        IRENUM - ok
12:44:35.0077 2932        Irmon          (2efe1db1ec58a26b0c14bfda122e246f) C:\WINDOWS\System32\irmon.dll
12:44:35.0139 2932        Irmon - ok
12:44:35.0186 2932        irsir          (0501f0b9ab08425f8c0eacbdcc04aa32) C:\WINDOWS\system32\DRIVERS\irsir.sys
12:44:35.0249 2932        irsir - ok
12:44:35.0264 2932        isapnp          (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
12:44:35.0389 2932        isapnp - ok
12:44:35.0546 2932        JavaQuickStarterService (0a5709543986843d37a92290b7838340) C:\Programme\Java\jre6\bin\jqs.exe
12:44:35.0577 2932        JavaQuickStarterService - ok
12:44:35.0592 2932        Kbdclass        (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
12:44:35.0733 2932        Kbdclass - ok
12:44:35.0764 2932        kmixer          (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
12:44:35.0905 2932        kmixer - ok
12:44:35.0936 2932        KSecDD          (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
12:44:35.0983 2932        KSecDD - ok
12:44:36.0014 2932        lanmanserver    (2bbdcb79900990f0716dfcb714e72de7) C:\WINDOWS\System32\srvsvc.dll
12:44:36.0061 2932        lanmanserver - ok
12:44:36.0108 2932        lanmanworkstation (1869b14b06b44b44af70548e1ea3303f) C:\WINDOWS\System32\wkssvc.dll
12:44:36.0155 2932        lanmanworkstation - ok
12:44:36.0155 2932        lbrtfdc - ok
12:44:36.0186 2932        LmHosts        (636714b7d43c8d0c80449123fd266920) C:\WINDOWS\System32\lmhsvc.dll
12:44:36.0342 2932        LmHosts - ok
12:44:36.0467 2932        McAfeeFramework (062d80f13d762f7bc2f38430d60f5048) C:\Programme\McAfee\Common Framework\FrameworkService.exe
12:44:36.0483 2932        McAfeeFramework - ok
12:44:36.0577 2932        McShield        (c7a9f5343373f389de64c625c5f93d96) C:\Programme\Common\McAfee\SystemCore\\mcshield.exe
12:44:36.0608 2932        McShield - ok
12:44:36.0670 2932        McTaskManager  (b15bb3aef59158b4e1dda5328c842713) C:\Programme\McAfee\VirusScan Enterprise\vstskmgr.exe
12:44:36.0686 2932        McTaskManager - ok
12:44:36.0764 2932        MDM            (11f714f85530a2bd134074dc30e99fca) C:\Programme\Common\Microsoft Shared\VS7DEBUG\MDM.EXE
12:44:36.0795 2932        MDM - ok
12:44:36.0827 2932        Messenger      (b7550a7107281d170ce85524b1488c98) C:\WINDOWS\System32\msgsvc.dll
12:44:36.0967 2932        Messenger - ok
12:44:36.0999 2932        mfeapfk        (fca77f9c5d9f19992ae02538181236a6) C:\WINDOWS\system32\drivers\mfeapfk.sys
12:44:37.0014 2932        mfeapfk - ok
12:44:37.0045 2932        mfeavfk        (ed6c0825f98bcfa05ee10db9d9ca8391) C:\WINDOWS\system32\drivers\mfeavfk.sys
12:44:37.0061 2932        mfeavfk - ok
12:44:37.0061 2932        mfeavfk01 - ok
12:44:37.0077 2932        mfebopk        (4957d3b3f35f583a2b11eacb651bff9f) C:\WINDOWS\system32\drivers\mfebopk.sys
12:44:37.0092 2932        mfebopk - ok
12:44:37.0139 2932        mfehidk        (37800fbb68d88e3c3e49bb9c97233e87) C:\WINDOWS\system32\drivers\mfehidk.sys
12:44:37.0170 2932        mfehidk - ok
12:44:37.0186 2932        mferkdet        (47c91e229b129047f0138011ddf9f92f) C:\WINDOWS\system32\drivers\mferkdet.sys
12:44:37.0202 2932        mferkdet - ok
12:44:37.0249 2932        mferkdk - ok
12:44:37.0280 2932        mfetdi2k        (09aaf8e41a1e965fea21700ce69c408c) C:\WINDOWS\system32\drivers\mfetdi2k.sys
12:44:37.0295 2932        mfetdi2k - ok
12:44:37.0311 2932        mfevtp          (9f09caa8dc12fc1626f82a5c212f6f9c) C:\WINDOWS\system32\mfevtps.exe
12:44:37.0327 2932        mfevtp - ok
12:44:37.0358 2932        Modem          (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
12:44:37.0514 2932        Modem - ok
12:44:37.0530 2932        Mouclass        (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
12:44:37.0670 2932        Mouclass - ok
12:44:37.0702 2932        mouhid          (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
12:44:37.0858 2932        mouhid - ok
12:44:37.0858 2932        MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
12:44:38.0014 2932        MountMgr - ok
12:44:38.0045 2932        MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe
12:44:38.0092 2932        MozillaMaintenance - ok
12:44:38.0092 2932        mraid35x - ok
12:44:38.0108 2932        MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
12:44:38.0264 2932        MRxDAV - ok
12:44:38.0327 2932        MRxSmb          (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
12:44:38.0389 2932        MRxSmb - ok
12:44:38.0420 2932        MSDTC          (35a031af38c55f92d28aa03ee9f12cc9) C:\WINDOWS\system32\msdtc.exe
12:44:38.0577 2932        MSDTC - ok
12:44:38.0592 2932        Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
12:44:38.0717 2932        Msfs - ok
12:44:38.0717 2932        MSIServer - ok
12:44:38.0748 2932        MSKSSRV        (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
12:44:38.0889 2932        MSKSSRV - ok
12:44:38.0905 2932        MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
12:44:39.0030 2932        MSPCLOCK - ok
12:44:39.0045 2932        MSPQM          (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
12:44:39.0186 2932        MSPQM - ok
12:44:39.0217 2932        mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
12:44:39.0342 2932        mssmbios - ok
12:44:39.0389 2932        Mup            (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
12:44:39.0420 2932        Mup - ok
12:44:39.0452 2932        napagent        (46bb15ae2ac7d025d6d2567b876817bd) C:\WINDOWS\System32\qagentrt.dll
12:44:39.0577 2932        napagent - ok
12:44:39.0686 2932        NBService      (6d8fcdd5bb3b676ef58fa234073492c6) C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
12:44:39.0717 2932        NBService - ok
12:44:39.0748 2932        NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
12:44:39.0889 2932        NDIS - ok
12:44:39.0905 2932        NdisTapi        (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
12:44:39.0967 2932        NdisTapi - ok
12:44:39.0983 2932        Ndisuio        (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
12:44:40.0108 2932        Ndisuio - ok
12:44:40.0123 2932        NdisWan        (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
12:44:40.0280 2932        NdisWan - ok
12:44:40.0311 2932        NDProxy        (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
12:44:40.0373 2932        NDProxy - ok
12:44:40.0389 2932        NetBIOS        (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
12:44:40.0498 2932        NetBIOS - ok
12:44:40.0514 2932        NetBT          (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
12:44:40.0655 2932        NetBT - ok
12:44:40.0686 2932        NetDDE          (8ace4251bffd09ce75679fe940e996cc) C:\WINDOWS\system32\netdde.exe
12:44:40.0842 2932        NetDDE - ok
12:44:40.0842 2932        NetDDEdsdm      (8ace4251bffd09ce75679fe940e996cc) C:\WINDOWS\system32\netdde.exe
12:44:40.0967 2932        NetDDEdsdm - ok
12:44:40.0983 2932        Netlogon        (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
12:44:41.0108 2932        Netlogon - ok
12:44:41.0139 2932        Netman          (e6d88f1f6745bf00b57e7855a2ab696c) C:\WINDOWS\System32\netman.dll
12:44:41.0264 2932        Netman - ok
12:44:41.0405 2932        NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:44:41.0420 2932        NetTcpPortSharing - ok
12:44:41.0467 2932        Nla            (f1b67b6b0751ae0e6e964b02821206a3) C:\WINDOWS\System32\mswsock.dll
12:44:41.0498 2932        Nla - ok
12:44:41.0655 2932        NMIndexingService (e584d6668e6a3923ff32e026a5ed2a03) C:\Programme\Common\Ahead\Lib\NMIndexingService.exe
12:44:41.0670 2932        NMIndexingService - ok
12:44:41.0701 2932        Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
12:44:41.0795 2932        Npfs - ok
12:44:41.0858 2932        Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
12:44:42.0045 2932        Ntfs - ok
12:44:42.0061 2932        NtLmSsp        (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
12:44:42.0170 2932        NtLmSsp - ok
12:44:42.0233 2932        NtmsSvc        (56af4064996fa5bac9c449b1514b4770) C:\WINDOWS\system32\ntmssvc.dll
12:44:42.0358 2932        NtmsSvc - ok
12:44:42.0389 2932        Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
12:44:42.0514 2932        Null - ok
12:44:42.0545 2932        NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
12:44:42.0670 2932        NwlnkFlt - ok
12:44:42.0670 2932        NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
12:44:42.0795 2932        NwlnkFwd - ok
12:44:42.0967 2932        odserv          (785f487a64950f3cb8e9f16253ba3b7b) C:\Programme\Common\Microsoft Shared\OFFICE12\ODSERV.EXE
12:44:42.0998 2932        odserv - ok
12:44:43.0045 2932        ose            (5a432a042dae460abe7199b758e8606c) C:\Programme\Common\Microsoft Shared\Source Engine\OSE.EXE
12:44:43.0217 2932        ose - ok
12:44:43.0248 2932        Parport        (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\DRIVERS\parport.sys
12:44:43.0404 2932        Parport - ok
12:44:43.0436 2932        PartMgr        (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
12:44:43.0545 2932        PartMgr - ok
12:44:43.0592 2932        ParVdm          (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
12:44:43.0701 2932        ParVdm - ok
12:44:43.0764 2932        PCI            (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
12:44:43.0889 2932        PCI - ok
12:44:43.0889 2932        PCIDump - ok
12:44:43.0920 2932        PCIIde          (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
12:44:44.0045 2932        PCIIde - ok
12:44:44.0076 2932        Pcmcia          (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\drivers\Pcmcia.sys
12:44:44.0186 2932        Pcmcia - ok
12:44:44.0186 2932        PDCOMP - ok
12:44:44.0201 2932        PDFRAME - ok
12:44:44.0201 2932        PDRELI - ok
12:44:44.0217 2932        PDRFRAME - ok
12:44:44.0217 2932        perc2 - ok
12:44:44.0217 2932        perc2hib - ok
12:44:44.0264 2932        PlugPlay        (a3edbe9053889fb24ab22492472b39dc) C:\WINDOWS\system32\services.exe
12:44:44.0311 2932        PlugPlay - ok
12:44:44.0326 2932        PolicyAgent    (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
12:44:44.0451 2932        PolicyAgent - ok
12:44:44.0483 2932        PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
12:44:44.0608 2932        PptpMiniport - ok
12:44:44.0623 2932        Processor      (2cb55427c58679f49ad600fccba76360) C:\WINDOWS\system32\DRIVERS\processr.sys
12:44:44.0764 2932        Processor - ok
12:44:44.0764 2932        ProtectedStorage (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
12:44:44.0889 2932        ProtectedStorage - ok
12:44:44.0904 2932        PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
12:44:45.0029 2932        PSched - ok
12:44:45.0061 2932        Ptilink        (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
12:44:45.0170 2932        Ptilink - ok
12:44:45.0170 2932        ql1080 - ok
12:44:45.0186 2932        Ql10wnt - ok
12:44:45.0186 2932        ql12160 - ok
12:44:45.0186 2932        ql1240 - ok
12:44:45.0201 2932        ql1280 - ok
12:44:45.0201 2932        RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
12:44:45.0357 2932        RasAcd - ok
12:44:45.0373 2932        RasAuto        (f5ba6caccdb66c8f048e867563203246) C:\WINDOWS\System32\rasauto.dll
12:44:45.0482 2932        RasAuto - ok
12:44:45.0514 2932        Rasirda        (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
12:44:45.0561 2932        Rasirda - ok
12:44:45.0576 2932        Rasl2tp        (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
12:44:45.0717 2932        Rasl2tp - ok
12:44:45.0764 2932        RasMan          (f9a7b66ea345726edb5862a46b1eccd5) C:\WINDOWS\System32\rasmans.dll
12:44:45.0873 2932        RasMan - ok
12:44:45.0889 2932        RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
12:44:46.0014 2932        RasPppoe - ok
12:44:46.0029 2932        Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
12:44:46.0170 2932        Raspti - ok
12:44:46.0201 2932        Rdbss          (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
12:44:46.0326 2932        Rdbss - ok
12:44:46.0326 2932        RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
12:44:46.0451 2932        RDPCDD - ok
12:44:46.0482 2932        rdpdr          (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
12:44:46.0592 2932        rdpdr - ok
12:44:46.0639 2932        RDPWD          (6589db6e5969f8eee594cf71171c5028) C:\WINDOWS\system32\drivers\RDPWD.sys
12:44:46.0701 2932        RDPWD - ok
12:44:46.0732 2932        RDSessMgr      (263af18af0f3db99f574c95f284ccec9) C:\WINDOWS\system32\sessmgr.exe
12:44:46.0857 2932        RDSessMgr - ok
12:44:46.0889 2932        redbook        (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
12:44:47.0045 2932        redbook - ok
12:44:47.0076 2932        RemoteAccess    (0e97ec96d6942ceec2d188cc2eb69a01) C:\WINDOWS\System32\mprdim.dll
12:44:47.0185 2932        RemoteAccess - ok
12:44:47.0232 2932        RemoteRegistry  (e4cd1f3d84e1c2ca0b8cf7501e201593) C:\WINDOWS\system32\regsvc.dll
12:44:47.0357 2932        RemoteRegistry - ok
12:44:47.0498 2932        RichVideo      (bd517c7fb119997effbe39d5e4b37b05) C:\Programme\CyberLink\Shared Files\RichVideo.exe
12:44:47.0498 2932        RichVideo ( UnsignedFile.Multi.Generic ) - warning
12:44:47.0498 2932        RichVideo - detected UnsignedFile.Multi.Generic (1)
12:44:47.0529 2932        RpcLocator      (2a02e21867497df20b8fc95631395169) C:\WINDOWS\system32\locator.exe
12:44:47.0654 2932        RpcLocator - ok
12:44:47.0701 2932        RpcSs          (3127afbf2c1ed0ab14a1bbb7aaecb85b) C:\WINDOWS\system32\rpcss.dll
12:44:47.0732 2932        RpcSs - ok
12:44:47.0764 2932        RSVP            (4bdd71b4b521521499dfd14735c4f398) C:\WINDOWS\system32\rsvp.exe
12:44:47.0873 2932        RSVP - ok
12:44:47.0920 2932        RTLE8023xp      (36ada62330c31ad314e4a26b815fc485) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
12:44:47.0951 2932        RTLE8023xp - ok
12:44:47.0982 2932        SamSs          (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
12:44:48.0107 2932        SamSs - ok
12:44:48.0123 2932        SCardSvr        (dcec079fad95d36c8dd5cb6d779dfe32) C:\WINDOWS\System32\SCardSvr.exe
12:44:48.0279 2932        SCardSvr - ok
12:44:48.0310 2932        Schedule        (a050194a44d7fa8d7186ed2f4e8367ae) C:\WINDOWS\system32\schedsvc.dll
12:44:48.0451 2932        Schedule - ok
12:44:48.0482 2932        Secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
12:44:48.0529 2932        Secdrv - ok
12:44:48.0545 2932        seclogon        (bee4cfd1d48c23b44cf4b974b0b79b2b) C:\WINDOWS\System32\seclogon.dll
12:44:48.0670 2932        seclogon - ok
12:44:48.0701 2932        SENS            (2aac9b6ed9eddffb721d6452e34d67e3) C:\WINDOWS\system32\sens.dll
12:44:48.0842 2932        SENS - ok
12:44:48.0857 2932        serenum        (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
12:44:48.0982 2932        serenum - ok
12:44:48.0998 2932        Serial          (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\DRIVERS\serial.sys
12:44:49.0123 2932        Serial - ok
12:44:49.0154 2932        Sfloppy        (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
12:44:49.0279 2932        Sfloppy - ok
12:44:49.0326 2932        SharedAccess    (cad058d5f8b889a87ca3eb3cf624dcef) C:\WINDOWS\System32\ipnathlp.dll
12:44:49.0467 2932        SharedAccess - ok
12:44:49.0498 2932        ShellHWDetection (2db7d303c36ddd055215052f118e8e75) C:\WINDOWS\System32\shsvcs.dll
12:44:49.0529 2932        ShellHWDetection - ok
12:44:49.0529 2932        Simbad - ok
12:44:49.0545 2932        Sparrow - ok
12:44:49.0560 2932        splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
12:44:49.0685 2932        splitter - ok
12:44:49.0717 2932        Spooler        (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
12:44:49.0748 2932        Spooler - ok
12:44:49.0763 2932        sr              (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
12:44:49.0826 2932        sr - ok
12:44:49.0857 2932        srservice      (fe77a85495065f3ad59c5c65b6c54182) C:\WINDOWS\system32\srsvc.dll
12:44:49.0920 2932        srservice - ok
12:44:49.0951 2932        Srv            (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
12:44:50.0013 2932        Srv - ok
12:44:50.0029 2932        SSDPSRV        (4df5b05dfaec29e13e1ed6f6ee12c500) C:\WINDOWS\System32\ssdpsrv.dll
12:44:50.0092 2932        SSDPSRV - ok
12:44:50.0123 2932        stisvc          (bc2c5985611c5356b24aeb370953ded9) C:\WINDOWS\system32\wiaservc.dll
12:44:50.0248 2932        stisvc - ok
12:44:50.0263 2932        swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
12:44:50.0420 2932        swenum - ok
12:44:50.0435 2932        swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
12:44:50.0545 2932        swmidi - ok
12:44:50.0545 2932        SwPrv - ok
12:44:50.0560 2932        symc810 - ok
12:44:50.0560 2932        symc8xx - ok
12:44:50.0560 2932        sym_hi - ok
12:44:50.0576 2932        sym_u3 - ok
12:44:50.0592 2932        sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
12:44:50.0732 2932        sysaudio - ok
12:44:50.0748 2932        SysmonLog      (2903fffa2523926d6219428040dce6b9) C:\WINDOWS\system32\smlogsvc.exe
12:44:50.0857 2932        SysmonLog - ok
12:44:50.0888 2932        TapiSrv        (05903cac4b98908d55ea5774775b382e) C:\WINDOWS\System32\tapisrv.dll
12:44:51.0013 2932        TapiSrv - ok
12:44:51.0060 2932        Tcpip          (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
12:44:51.0107 2932        Tcpip - ok
12:44:51.0123 2932        TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
12:44:51.0279 2932        TDPIPE - ok
12:44:51.0295 2932        TDTCP          (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
12:44:51.0435 2932        TDTCP - ok
12:44:51.0451 2932        TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
12:44:51.0576 2932        TermDD - ok
12:44:51.0623 2932        TermService    (b7de02c863d8f5a005a7bf375375a6a4) C:\WINDOWS\System32\termsrv.dll
12:44:51.0748 2932        TermService - ok
12:44:51.0795 2932        Themes          (2db7d303c36ddd055215052f118e8e75) C:\WINDOWS\System32\shsvcs.dll
12:44:51.0810 2932        Themes - ok
12:44:51.0826 2932        TlntSvr        (03681a1ce77f51586903869a5ab1deab) C:\WINDOWS\system32\tlntsvr.exe
12:44:51.0904 2932        TlntSvr - ok
12:44:51.0904 2932        TosIde - ok
12:44:51.0935 2932        TrkWks          (626504572b175867f30f3215c04b3e2f) C:\WINDOWS\system32\trkwks.dll
12:44:52.0060 2932        TrkWks - ok
12:44:52.0091 2932        Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
12:44:52.0216 2932        Udfs - ok
12:44:52.0232 2932        ultra - ok
12:44:52.0279 2932        Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
12:44:52.0420 2932        Update - ok
12:44:52.0451 2932        upnphost        (1dfd8975d8c89214b98d9387c1125b49) C:\WINDOWS\System32\upnphost.dll
12:44:52.0513 2932        upnphost - ok
12:44:52.0529 2932        UPS            (9b11e6118958e63e1fef129466e2bda7) C:\WINDOWS\System32\ups.exe
12:44:52.0623 2932        UPS - ok
12:44:52.0654 2932        usbccgp        (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
12:44:52.0763 2932        usbccgp - ok
12:44:52.0779 2932        usbehci        (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
12:44:52.0888 2932        usbehci - ok
12:44:52.0920 2932        usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
12:44:53.0045 2932        usbhub - ok
12:44:53.0060 2932        usbohci        (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
12:44:53.0185 2932        usbohci - ok
12:44:53.0216 2932        usbprint        (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
12:44:53.0326 2932        usbprint - ok
12:44:53.0357 2932        usbscan        (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
12:44:53.0466 2932        usbscan - ok
12:44:53.0498 2932        usbstor        (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
12:44:53.0607 2932        usbstor - ok
12:44:53.0623 2932        VgaSave        (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
12:44:53.0763 2932        VgaSave - ok
12:44:53.0763 2932        ViaIde - ok
12:44:53.0794 2932        VolSnap        (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
12:44:53.0919 2932        VolSnap - ok
12:44:53.0966 2932        VSS            (68f106273be29e7b7ef8266977268e78) C:\WINDOWS\System32\vssvc.exe
12:44:54.0029 2932        VSS - ok
12:44:54.0060 2932        W32Time        (7b353059e665f8b7ad2bbeaef597cf45) C:\WINDOWS\system32\w32time.dll
12:44:54.0169 2932        W32Time - ok
12:44:54.0185 2932        Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
12:44:54.0326 2932        Wanarp - ok
12:44:54.0326 2932        WDICA - ok
12:44:54.0341 2932        wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
12:44:54.0451 2932        wdmaud - ok
12:44:54.0482 2932        WebClient      (81727c9873e3905a2ffc1ebd07265002) C:\WINDOWS\System32\webclnt.dll
12:44:54.0607 2932        WebClient - ok
12:44:54.0716 2932        winmgmt        (6f3f3973d97714cc5f906a19fe883729) C:\WINDOWS\system32\wbem\WMIsvc.dll
12:44:54.0857 2932        winmgmt - ok
12:44:54.0935 2932        WinRM          (f10075c2ec96d2eb118012e78ece2fc2) C:\WINDOWS\system32\WsmSvc.dll
12:44:55.0029 2932        WinRM - ok
12:44:55.0060 2932        WmdmPmSN        (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll
12:44:55.0107 2932        WmdmPmSN - ok
12:44:55.0169 2932        Wmi            (ffa4d901d46d07a5bab2d8307fbb51a6) C:\WINDOWS\System32\advapi32.dll
12:44:55.0216 2932        Wmi - ok
12:44:55.0326 2932        WmiApSrv        (93908111ba57a6e60ec2fa2de202105c) C:\WINDOWS\system32\wbem\wmiapsrv.exe
12:44:55.0466 2932        WmiApSrv - ok
12:44:55.0607 2932        WMPNetworkSvc  (bf05650bb7df5e9ebdd25974e22403bb) C:\Programme\Windows Media Player\WMPNetwk.exe
12:44:55.0669 2932        WMPNetworkSvc - ok
12:44:55.0997 2932        WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
12:44:56.0029 2932        WPFFontCache_v0400 - ok
12:44:56.0763 2932        wscsvc          (300b3e84faf1a5c1f791c159ba28035d) C:\WINDOWS\system32\wscsvc.dll
12:44:56.0872 2932        wscsvc - ok
12:44:56.0888 2932        wuauserv        (7b4fe05202aa6bf9f4dfd0e6a0d8a085) C:\WINDOWS\system32\wuauserv.dll
12:44:57.0044 2932        wuauserv - ok
12:44:57.0169 2932        WudfPf          (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
12:44:57.0216 2932        WudfPf - ok
12:44:57.0263 2932        WudfRd          (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
12:44:57.0279 2932        WudfRd - ok
12:44:57.0294 2932        WudfSvc        (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
12:44:57.0326 2932        WudfSvc - ok
12:44:57.0372 2932        WZCSVC          (c4f109c005f6725162d2d12ca751e4a7) C:\WINDOWS\System32\wzcsvc.dll
12:44:57.0497 2932        WZCSVC - ok
12:44:57.0529 2932        xmlprov        (0ada34871a2e1cd2caafed1237a47750) C:\WINDOWS\System32\xmlprov.dll
12:44:57.0669 2932        xmlprov - ok
12:44:57.0685 2932        MBR (0x1B8)    (72b8ce41af0de751c946802b3ed844b4) \Device\Harddisk0\DR0
12:44:58.0122 2932        \Device\Harddisk0\DR0 - ok
12:44:58.0122 2932        Boot (0x1200)  (0d1cf8d85f4616114d6c44e72b6bb271) \Device\Harddisk0\DR0\Partition0
12:44:58.0138 2932        \Device\Harddisk0\DR0\Partition0 - ok
12:44:58.0138 2932        ============================================================
12:44:58.0138 2932        Scan finished
12:44:58.0138 2932        ============================================================
12:44:58.0247 1456        Detected object count: 6
12:44:58.0247 1456        Actual detected object count: 6


cosinus 12.07.2012 14:41

Log ist unvollständig! Die untere Zusammenfassung fehlt

mot2001 12.07.2012 14:50

hm, jetzt:

Code:

12:43:00.0114 2388        TDSS rootkit removing tool 2.7.45.0 Jul  9 2012 12:46:35
12:43:00.0332 2388        ============================================================
12:43:00.0332 2388        Current date / time: 2012/07/12 12:43:00.0332
12:43:00.0332 2388        SystemInfo:
12:43:00.0332 2388       
12:43:00.0332 2388        OS Version: 5.1.2600 ServicePack: 3.0
12:43:00.0332 2388        Product type: Workstation
12:43:00.0332 2388        ComputerName: THEO99
12:43:00.0332 2388        UserName: Administrator
12:43:00.0332 2388        Windows directory: C:\WINDOWS
12:43:00.0332 2388        System windows directory: C:\WINDOWS
12:43:00.0332 2388        Processor architecture: Intel x86
12:43:00.0332 2388        Number of processors: 2
12:43:00.0332 2388        Page size: 0x1000
12:43:00.0332 2388        Boot type: Normal boot
12:43:00.0332 2388        ============================================================
12:43:01.0301 2388        Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
12:43:01.0317 2388        ============================================================
12:43:01.0317 2388        \Device\Harddisk0\DR0:
12:43:01.0317 2388        MBR partitions:
12:43:01.0317 2388        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1D1C0681
12:43:01.0317 2388        ============================================================
12:43:01.0332 2388        C: <-> \Device\Harddisk0\DR0\Partition0
12:43:01.0332 2388        ============================================================
12:43:01.0332 2388        Initialize success
12:43:01.0332 2388        ============================================================
12:44:16.0937 2932        ============================================================
12:44:16.0937 2932        Scan started
12:44:16.0937 2932        Mode: Manual; SigCheck; TDLFS;
12:44:16.0937 2932        ============================================================
12:44:18.0109 2932        Abiosdsk - ok
12:44:18.0109 2932        abp480n5 - ok
12:44:18.0156 2932        ACPI            (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
12:44:19.0078 2932        ACPI - ok
12:44:19.0109 2932        ACPIEC          (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\drivers\ACPIEC.sys
12:44:19.0234 2932        ACPIEC - ok
12:44:19.0234 2932        adpu160m - ok
12:44:19.0265 2932        aec            (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
12:44:19.0390 2932        aec - ok
12:44:19.0421 2932        AFD            (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
12:44:19.0484 2932        AFD - ok
12:44:19.0484 2932        Aha154x - ok
12:44:19.0500 2932        aic78u2 - ok
12:44:19.0500 2932        aic78xx - ok
12:44:19.0531 2932        Alerter        (738d80cc01d7bc7584be917b7f544394) C:\WINDOWS\system32\alrsvc.dll
12:44:19.0656 2932        Alerter - ok
12:44:19.0687 2932        ALG            (190cd73d4984f94d823f9444980513e5) C:\WINDOWS\System32\alg.exe
12:44:19.0750 2932        ALG - ok
12:44:19.0765 2932        AliIde - ok
12:44:19.0796 2932        AmdK8          (58be3c2f1aa041ea56f7305a6463035c) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
12:44:19.0812 2932        AmdK8 ( UnsignedFile.Multi.Generic ) - warning
12:44:19.0812 2932        AmdK8 - detected UnsignedFile.Multi.Generic (1)
12:44:19.0812 2932        amsint - ok
12:44:19.0843 2932        AppMgmt        (d45960be52c3c610d361977057f98c54) C:\WINDOWS\System32\appmgmts.dll
12:44:19.0921 2932        AppMgmt - ok
12:44:19.0921 2932        asc - ok
12:44:19.0921 2932        asc3350p - ok
12:44:19.0937 2932        asc3550 - ok
12:44:20.0203 2932        aspnet_state    (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
12:44:20.0234 2932        aspnet_state - ok
12:44:20.0250 2932        AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
12:44:20.0375 2932        AsyncMac - ok
12:44:20.0390 2932        atapi          (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
12:44:20.0531 2932        atapi - ok
12:44:20.0531 2932        Atdisk - ok
12:44:20.0625 2932        Ati HotKey Poller (5ceda44447a28db469de28afc0950650) C:\WINDOWS\system32\Ati2evxx.exe
12:44:20.0640 2932        Ati HotKey Poller ( UnsignedFile.Multi.Generic ) - warning
12:44:20.0640 2932        Ati HotKey Poller - detected UnsignedFile.Multi.Generic (1)
12:44:20.0718 2932        ATI Smart      (737371583e0173f963d74435be3e96d2) C:\WINDOWS\system32\ati2sgag.exe
12:44:20.0765 2932        ATI Smart ( UnsignedFile.Multi.Generic ) - warning
12:44:20.0765 2932        ATI Smart - detected UnsignedFile.Multi.Generic (1)
12:44:20.0984 2932        ati2mtag        (b63516824da0d8b9ad136e6e044a795f) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
12:44:21.0156 2932        ati2mtag ( UnsignedFile.Multi.Generic ) - warning
12:44:21.0156 2932        ati2mtag - detected UnsignedFile.Multi.Generic (1)
12:44:22.0265 2932        Atmarpc        (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
12:44:22.0390 2932        Atmarpc - ok
12:44:22.0437 2932        AudioSrv        (58ed0d5452df7be732193e7999c6b9a4) C:\WINDOWS\System32\audiosrv.dll
12:44:22.0578 2932        AudioSrv - ok
12:44:22.0609 2932        audstub        (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
12:44:22.0734 2932        audstub - ok
12:44:22.0749 2932        Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
12:44:22.0890 2932        Beep - ok
12:44:22.0921 2932        BITS            (d6f603772a789bb3228f310d650b8bd1) C:\WINDOWS\system32\qmgr.dll
12:44:23.0062 2932        BITS - ok
12:44:23.0077 2932        Browser        (b42057f06bbb98b31876c0b3f2b54e33) C:\WINDOWS\System32\browser.dll
12:44:23.0249 2932        Browser - ok
12:44:23.0281 2932        cbidf2k        (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
12:44:23.0406 2932        cbidf2k - ok
12:44:23.0421 2932        cd20xrnt - ok
12:44:23.0421 2932        Cdaudio        (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
12:44:23.0562 2932        Cdaudio - ok
12:44:23.0577 2932        Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
12:44:23.0718 2932        Cdfs - ok
12:44:23.0734 2932        Cdrom          (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
12:44:23.0890 2932        Cdrom - ok
12:44:23.0890 2932        Changer - ok
12:44:23.0906 2932        CiSvc          (28e3040d1f1ca2008cd6b29dfebc9a5e) C:\WINDOWS\system32\cisvc.exe
12:44:24.0062 2932        CiSvc - ok
12:44:24.0077 2932        ClipSrv        (778a30ed3c134eb7e406afc407e9997d) C:\WINDOWS\system32\clipsrv.exe
12:44:24.0202 2932        ClipSrv - ok
12:44:24.0484 2932        clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:44:24.0515 2932        clr_optimization_v2.0.50727_32 - ok
12:44:24.0702 2932        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:44:24.0718 2932        clr_optimization_v4.0.30319_32 - ok
12:44:24.0718 2932        CmdIde - ok
12:44:24.0734 2932        COMSysApp - ok
12:44:24.0734 2932        Cpqarray - ok
12:44:24.0796 2932        CryptSvc        (611f824e5c703a5a899f84c5f1699e4d) C:\WINDOWS\System32\cryptsvc.dll
12:44:24.0937 2932        CryptSvc - ok
12:44:24.0937 2932        dac2w2k - ok
12:44:24.0952 2932        dac960nt - ok
12:44:24.0999 2932        DcomLaunch      (3127afbf2c1ed0ab14a1bbb7aaecb85b) C:\WINDOWS\system32\rpcss.dll
12:44:25.0046 2932        DcomLaunch - ok
12:44:25.0077 2932        Dhcp            (c29a1c9b75ba38fa37f8c44405dec360) C:\WINDOWS\System32\dhcpcsvc.dll
12:44:25.0218 2932        Dhcp - ok
12:44:25.0249 2932        Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
12:44:25.0405 2932        Disk - ok
12:44:25.0421 2932        dmadmin - ok
12:44:25.0484 2932        dmboot          (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
12:44:25.0640 2932        dmboot - ok
12:44:25.0655 2932        dmio            (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
12:44:25.0796 2932        dmio - ok
12:44:25.0812 2932        dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
12:44:25.0937 2932        dmload - ok
12:44:25.0968 2932        dmserver        (25c83ffbba13b554eb6d59a9b2e2ee78) C:\WINDOWS\System32\dmserver.dll
12:44:26.0109 2932        dmserver - ok
12:44:26.0140 2932        DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
12:44:26.0280 2932        DMusic - ok
12:44:26.0327 2932        Dnscache        (407f3227ac618fd1ca54b335b083de07) C:\WINDOWS\System32\dnsrslvr.dll
12:44:26.0405 2932        Dnscache - ok
12:44:26.0437 2932        Dot3svc        (676e36c4ff5bcea1900f44182b9723e6) C:\WINDOWS\System32\dot3svc.dll
12:44:26.0577 2932        Dot3svc - ok
12:44:26.0765 2932        Dot4            (3e4b043f8bc6be1d4820cc6c9c500306) C:\WINDOWS\system32\DRIVERS\Dot4.sys
12:44:26.0968 2932        Dot4 - ok
12:44:26.0999 2932        Dot4Print      (77ce63a8a34ae23d9fe4c7896d1debe7) C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys
12:44:27.0140 2932        Dot4Print - ok
12:44:27.0140 2932        dpti2o - ok
12:44:27.0155 2932        drmkaud        (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
12:44:27.0296 2932        drmkaud - ok
12:44:27.0327 2932        EapHost        (4e4f2fddab0a0736d7671134dcce91fb) C:\WINDOWS\System32\eapsvc.dll
12:44:27.0452 2932        EapHost - ok
12:44:27.0483 2932        ERSvc          (877c18558d70587aa7823a1a308ac96b) C:\WINDOWS\System32\ersvc.dll
12:44:27.0624 2932        ERSvc - ok
12:44:27.0655 2932        Eventlog        (a3edbe9053889fb24ab22492472b39dc) C:\WINDOWS\system32\services.exe
12:44:27.0687 2932        Eventlog - ok
12:44:27.0718 2932        EventSystem    (af4f6b5739d18ca7972ab53e091cbc74) C:\WINDOWS\system32\es.dll
12:44:27.0765 2932        EventSystem - ok
12:44:27.0796 2932        Fastfat        (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
12:44:27.0921 2932        Fastfat - ok
12:44:27.0952 2932        FastUserSwitchingCompatibility (2db7d303c36ddd055215052f118e8e75) C:\WINDOWS\System32\shsvcs.dll
12:44:27.0999 2932        FastUserSwitchingCompatibility - ok
12:44:28.0015 2932        Fdc            (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
12:44:28.0140 2932        Fdc - ok
12:44:28.0155 2932        Fips            (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
12:44:28.0312 2932        Fips - ok
12:44:28.0343 2932        Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
12:44:28.0468 2932        Flpydisk - ok
12:44:28.0499 2932        FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
12:44:28.0640 2932        FltMgr - ok
12:44:28.0765 2932        FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
12:44:28.0780 2932        FontCache3.0.0.0 - ok
12:44:28.0812 2932        Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
12:44:28.0937 2932        Fs_Rec - ok
12:44:28.0952 2932        Ftdisk          (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
12:44:29.0077 2932        Ftdisk - ok
12:44:29.0077 2932        GMSIPCI - ok
12:44:29.0108 2932        Gpc            (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
12:44:29.0265 2932        Gpc - ok
12:44:29.0296 2932        HDAudBus        (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
12:44:29.0437 2932        HDAudBus - ok
12:44:29.0483 2932        helpsvc        (cb66bf85bf599befd6c6a57c2e20357f) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
12:44:29.0624 2932        helpsvc - ok
12:44:29.0655 2932        HidServ        (b35da85e60c0103f2e4104532da2f12b) C:\WINDOWS\System32\hidserv.dll
12:44:29.0796 2932        HidServ - ok
12:44:29.0796 2932        HidUsb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
12:44:29.0936 2932        HidUsb - ok
12:44:29.0968 2932        hkmsvc          (ed29f14101523a6e0e808107405d452c) C:\WINDOWS\System32\kmsvc.dll
12:44:30.0093 2932        hkmsvc - ok
12:44:30.0108 2932        hpn - ok
12:44:30.0140 2932        HTTP            (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
12:44:30.0186 2932        HTTP - ok
12:44:30.0218 2932        HTTPFilter      (9e4adb854cebcfb81a4b36718feecd16) C:\WINDOWS\System32\w3ssl.dll
12:44:30.0343 2932        HTTPFilter - ok
12:44:30.0343 2932        i2omgmt - ok
12:44:30.0343 2932        i2omp - ok
12:44:30.0374 2932        i8042prt        (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
12:44:30.0530 2932        i8042prt - ok
12:44:30.0640 2932        idsvc          (c01ac32dc5c03076cfb852cb5da5229c) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
12:44:30.0702 2932        idsvc - ok
12:44:30.0702 2932        Imapi          (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
12:44:30.0843 2932        Imapi - ok
12:44:30.0874 2932        ImapiService    (d4b413aa210c21e46aedd2ba5b68d38e) C:\WINDOWS\system32\imapi.exe
12:44:30.0999 2932        ImapiService - ok
12:44:31.0046 2932        InCDfs          (7bfc3eda22190c0fe8c2ca19e5379da5) C:\WINDOWS\system32\drivers\InCDFs.sys
12:44:31.0061 2932        InCDfs - ok
12:44:31.0093 2932        InCDPass        (fc4dbf18a4eb0d2fe3171471a3d0f9a8) C:\WINDOWS\system32\drivers\InCDPass.sys
12:44:31.0108 2932        InCDPass - ok
12:44:31.0124 2932        InCDrec        (f8e7c551def07fdc12ca5cc7ae5d975b) C:\WINDOWS\system32\drivers\InCDrec.sys
12:44:31.0124 2932        InCDrec - ok
12:44:31.0155 2932        incdrm          (31a5a3809249a326eb0ef58d563a9654) C:\WINDOWS\system32\drivers\InCDRm.sys
12:44:31.0155 2932        incdrm - ok
12:44:31.0327 2932        InCDsrv        (c773d093d5c18765e71c7992aee051a2) C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe
12:44:31.0405 2932        InCDsrv - ok
12:44:32.0483 2932        ini910u - ok
12:44:32.0780 2932        IntcAzAudAddService (613a2b00da1d4a80de1ec8cfb52c0d89) C:\WINDOWS\system32\drivers\RtkHDAud.sys
12:44:32.0983 2932        IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - warning
12:44:32.0983 2932        IntcAzAudAddService - detected UnsignedFile.Multi.Generic (1)
12:44:34.0092 2932        IntelIde - ok
12:44:34.0124 2932        Ip6Fw          (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
12:44:34.0264 2932        Ip6Fw - ok
12:44:34.0280 2932        IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
12:44:34.0421 2932        IpFilterDriver - ok
12:44:34.0452 2932        IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
12:44:34.0592 2932        IpInIp - ok
12:44:34.0608 2932        IpNat          (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
12:44:34.0733 2932        IpNat - ok
12:44:34.0764 2932        IPSec          (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
12:44:34.0905 2932        IPSec - ok
12:44:34.0921 2932        irda            (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys
12:44:34.0967 2932        irda - ok
12:44:34.0983 2932        IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
12:44:35.0061 2932        IRENUM - ok
12:44:35.0077 2932        Irmon          (2efe1db1ec58a26b0c14bfda122e246f) C:\WINDOWS\System32\irmon.dll
12:44:35.0139 2932        Irmon - ok
12:44:35.0186 2932        irsir          (0501f0b9ab08425f8c0eacbdcc04aa32) C:\WINDOWS\system32\DRIVERS\irsir.sys
12:44:35.0249 2932        irsir - ok
12:44:35.0264 2932        isapnp          (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
12:44:35.0389 2932        isapnp - ok
12:44:35.0546 2932        JavaQuickStarterService (0a5709543986843d37a92290b7838340) C:\Programme\Java\jre6\bin\jqs.exe
12:44:35.0577 2932        JavaQuickStarterService - ok
12:44:35.0592 2932        Kbdclass        (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
12:44:35.0733 2932        Kbdclass - ok
12:44:35.0764 2932        kmixer          (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
12:44:35.0905 2932        kmixer - ok
12:44:35.0936 2932        KSecDD          (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
12:44:35.0983 2932        KSecDD - ok
12:44:36.0014 2932        lanmanserver    (2bbdcb79900990f0716dfcb714e72de7) C:\WINDOWS\System32\srvsvc.dll
12:44:36.0061 2932        lanmanserver - ok
12:44:36.0108 2932        lanmanworkstation (1869b14b06b44b44af70548e1ea3303f) C:\WINDOWS\System32\wkssvc.dll
12:44:36.0155 2932        lanmanworkstation - ok
12:44:36.0155 2932        lbrtfdc - ok
12:44:36.0186 2932        LmHosts        (636714b7d43c8d0c80449123fd266920) C:\WINDOWS\System32\lmhsvc.dll
12:44:36.0342 2932        LmHosts - ok
12:44:36.0467 2932        McAfeeFramework (062d80f13d762f7bc2f38430d60f5048) C:\Programme\McAfee\Common Framework\FrameworkService.exe
12:44:36.0483 2932        McAfeeFramework - ok
12:44:36.0577 2932        McShield        (c7a9f5343373f389de64c625c5f93d96) C:\Programme\Common\McAfee\SystemCore\\mcshield.exe
12:44:36.0608 2932        McShield - ok
12:44:36.0670 2932        McTaskManager  (b15bb3aef59158b4e1dda5328c842713) C:\Programme\McAfee\VirusScan Enterprise\vstskmgr.exe
12:44:36.0686 2932        McTaskManager - ok
12:44:36.0764 2932        MDM            (11f714f85530a2bd134074dc30e99fca) C:\Programme\Common\Microsoft Shared\VS7DEBUG\MDM.EXE
12:44:36.0795 2932        MDM - ok
12:44:36.0827 2932        Messenger      (b7550a7107281d170ce85524b1488c98) C:\WINDOWS\System32\msgsvc.dll
12:44:36.0967 2932        Messenger - ok
12:44:36.0999 2932        mfeapfk        (fca77f9c5d9f19992ae02538181236a6) C:\WINDOWS\system32\drivers\mfeapfk.sys
12:44:37.0014 2932        mfeapfk - ok
12:44:37.0045 2932        mfeavfk        (ed6c0825f98bcfa05ee10db9d9ca8391) C:\WINDOWS\system32\drivers\mfeavfk.sys
12:44:37.0061 2932        mfeavfk - ok
12:44:37.0061 2932        mfeavfk01 - ok
12:44:37.0077 2932        mfebopk        (4957d3b3f35f583a2b11eacb651bff9f) C:\WINDOWS\system32\drivers\mfebopk.sys
12:44:37.0092 2932        mfebopk - ok
12:44:37.0139 2932        mfehidk        (37800fbb68d88e3c3e49bb9c97233e87) C:\WINDOWS\system32\drivers\mfehidk.sys
12:44:37.0170 2932        mfehidk - ok
12:44:37.0186 2932        mferkdet        (47c91e229b129047f0138011ddf9f92f) C:\WINDOWS\system32\drivers\mferkdet.sys
12:44:37.0202 2932        mferkdet - ok
12:44:37.0249 2932        mferkdk - ok
12:44:37.0280 2932        mfetdi2k        (09aaf8e41a1e965fea21700ce69c408c) C:\WINDOWS\system32\drivers\mfetdi2k.sys
12:44:37.0295 2932        mfetdi2k - ok
12:44:37.0311 2932        mfevtp          (9f09caa8dc12fc1626f82a5c212f6f9c) C:\WINDOWS\system32\mfevtps.exe
12:44:37.0327 2932        mfevtp - ok
12:44:37.0358 2932        Modem          (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
12:44:37.0514 2932        Modem - ok
12:44:37.0530 2932        Mouclass        (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
12:44:37.0670 2932        Mouclass - ok
12:44:37.0702 2932        mouhid          (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
12:44:37.0858 2932        mouhid - ok
12:44:37.0858 2932        MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
12:44:38.0014 2932        MountMgr - ok
12:44:38.0045 2932        MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe
12:44:38.0092 2932        MozillaMaintenance - ok
12:44:38.0092 2932        mraid35x - ok
12:44:38.0108 2932        MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
12:44:38.0264 2932        MRxDAV - ok
12:44:38.0327 2932        MRxSmb          (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
12:44:38.0389 2932        MRxSmb - ok
12:44:38.0420 2932        MSDTC          (35a031af38c55f92d28aa03ee9f12cc9) C:\WINDOWS\system32\msdtc.exe
12:44:38.0577 2932        MSDTC - ok
12:44:38.0592 2932        Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
12:44:38.0717 2932        Msfs - ok
12:44:38.0717 2932        MSIServer - ok
12:44:38.0748 2932        MSKSSRV        (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
12:44:38.0889 2932        MSKSSRV - ok
12:44:38.0905 2932        MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
12:44:39.0030 2932        MSPCLOCK - ok
12:44:39.0045 2932        MSPQM          (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
12:44:39.0186 2932        MSPQM - ok
12:44:39.0217 2932        mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
12:44:39.0342 2932        mssmbios - ok
12:44:39.0389 2932        Mup            (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
12:44:39.0420 2932        Mup - ok
12:44:39.0452 2932        napagent        (46bb15ae2ac7d025d6d2567b876817bd) C:\WINDOWS\System32\qagentrt.dll
12:44:39.0577 2932        napagent - ok
12:44:39.0686 2932        NBService      (6d8fcdd5bb3b676ef58fa234073492c6) C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
12:44:39.0717 2932        NBService - ok
12:44:39.0748 2932        NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
12:44:39.0889 2932        NDIS - ok
12:44:39.0905 2932        NdisTapi        (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
12:44:39.0967 2932        NdisTapi - ok
12:44:39.0983 2932        Ndisuio        (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
12:44:40.0108 2932        Ndisuio - ok
12:44:40.0123 2932        NdisWan        (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
12:44:40.0280 2932        NdisWan - ok
12:44:40.0311 2932        NDProxy        (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
12:44:40.0373 2932        NDProxy - ok
12:44:40.0389 2932        NetBIOS        (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
12:44:40.0498 2932        NetBIOS - ok
12:44:40.0514 2932        NetBT          (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
12:44:40.0655 2932        NetBT - ok
12:44:40.0686 2932        NetDDE          (8ace4251bffd09ce75679fe940e996cc) C:\WINDOWS\system32\netdde.exe
12:44:40.0842 2932        NetDDE - ok
12:44:40.0842 2932        NetDDEdsdm      (8ace4251bffd09ce75679fe940e996cc) C:\WINDOWS\system32\netdde.exe
12:44:40.0967 2932        NetDDEdsdm - ok
12:44:40.0983 2932        Netlogon        (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
12:44:41.0108 2932        Netlogon - ok
12:44:41.0139 2932        Netman          (e6d88f1f6745bf00b57e7855a2ab696c) C:\WINDOWS\System32\netman.dll
12:44:41.0264 2932        Netman - ok
12:44:41.0405 2932        NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:44:41.0420 2932        NetTcpPortSharing - ok
12:44:41.0467 2932        Nla            (f1b67b6b0751ae0e6e964b02821206a3) C:\WINDOWS\System32\mswsock.dll
12:44:41.0498 2932        Nla - ok
12:44:41.0655 2932        NMIndexingService (e584d6668e6a3923ff32e026a5ed2a03) C:\Programme\Common\Ahead\Lib\NMIndexingService.exe
12:44:41.0670 2932        NMIndexingService - ok
12:44:41.0701 2932        Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
12:44:41.0795 2932        Npfs - ok
12:44:41.0858 2932        Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
12:44:42.0045 2932        Ntfs - ok
12:44:42.0061 2932        NtLmSsp        (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
12:44:42.0170 2932        NtLmSsp - ok
12:44:42.0233 2932        NtmsSvc        (56af4064996fa5bac9c449b1514b4770) C:\WINDOWS\system32\ntmssvc.dll
12:44:42.0358 2932        NtmsSvc - ok
12:44:42.0389 2932        Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
12:44:42.0514 2932        Null - ok
12:44:42.0545 2932        NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
12:44:42.0670 2932        NwlnkFlt - ok
12:44:42.0670 2932        NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
12:44:42.0795 2932        NwlnkFwd - ok
12:44:42.0967 2932        odserv          (785f487a64950f3cb8e9f16253ba3b7b) C:\Programme\Common\Microsoft Shared\OFFICE12\ODSERV.EXE
12:44:42.0998 2932        odserv - ok
12:44:43.0045 2932        ose            (5a432a042dae460abe7199b758e8606c) C:\Programme\Common\Microsoft Shared\Source Engine\OSE.EXE
12:44:43.0217 2932        ose - ok
12:44:43.0248 2932        Parport        (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\DRIVERS\parport.sys
12:44:43.0404 2932        Parport - ok
12:44:43.0436 2932        PartMgr        (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
12:44:43.0545 2932        PartMgr - ok
12:44:43.0592 2932        ParVdm          (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
12:44:43.0701 2932        ParVdm - ok
12:44:43.0764 2932        PCI            (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
12:44:43.0889 2932        PCI - ok
12:44:43.0889 2932        PCIDump - ok
12:44:43.0920 2932        PCIIde          (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
12:44:44.0045 2932        PCIIde - ok
12:44:44.0076 2932        Pcmcia          (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\drivers\Pcmcia.sys
12:44:44.0186 2932        Pcmcia - ok
12:44:44.0186 2932        PDCOMP - ok
12:44:44.0201 2932        PDFRAME - ok
12:44:44.0201 2932        PDRELI - ok
12:44:44.0217 2932        PDRFRAME - ok
12:44:44.0217 2932        perc2 - ok
12:44:44.0217 2932        perc2hib - ok
12:44:44.0264 2932        PlugPlay        (a3edbe9053889fb24ab22492472b39dc) C:\WINDOWS\system32\services.exe
12:44:44.0311 2932        PlugPlay - ok
12:44:44.0326 2932        PolicyAgent    (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
12:44:44.0451 2932        PolicyAgent - ok
12:44:44.0483 2932        PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
12:44:44.0608 2932        PptpMiniport - ok
12:44:44.0623 2932        Processor      (2cb55427c58679f49ad600fccba76360) C:\WINDOWS\system32\DRIVERS\processr.sys
12:44:44.0764 2932        Processor - ok
12:44:44.0764 2932        ProtectedStorage (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
12:44:44.0889 2932        ProtectedStorage - ok
12:44:44.0904 2932        PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
12:44:45.0029 2932        PSched - ok
12:44:45.0061 2932        Ptilink        (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
12:44:45.0170 2932        Ptilink - ok
12:44:45.0170 2932        ql1080 - ok
12:44:45.0186 2932        Ql10wnt - ok
12:44:45.0186 2932        ql12160 - ok
12:44:45.0186 2932        ql1240 - ok
12:44:45.0201 2932        ql1280 - ok
12:44:45.0201 2932        RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
12:44:45.0357 2932        RasAcd - ok
12:44:45.0373 2932        RasAuto        (f5ba6caccdb66c8f048e867563203246) C:\WINDOWS\System32\rasauto.dll
12:44:45.0482 2932        RasAuto - ok
12:44:45.0514 2932        Rasirda        (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
12:44:45.0561 2932        Rasirda - ok
12:44:45.0576 2932        Rasl2tp        (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
12:44:45.0717 2932        Rasl2tp - ok
12:44:45.0764 2932        RasMan          (f9a7b66ea345726edb5862a46b1eccd5) C:\WINDOWS\System32\rasmans.dll
12:44:45.0873 2932        RasMan - ok
12:44:45.0889 2932        RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
12:44:46.0014 2932        RasPppoe - ok
12:44:46.0029 2932        Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
12:44:46.0170 2932        Raspti - ok
12:44:46.0201 2932        Rdbss          (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
12:44:46.0326 2932        Rdbss - ok
12:44:46.0326 2932        RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
12:44:46.0451 2932        RDPCDD - ok
12:44:46.0482 2932        rdpdr          (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
12:44:46.0592 2932        rdpdr - ok
12:44:46.0639 2932        RDPWD          (6589db6e5969f8eee594cf71171c5028) C:\WINDOWS\system32\drivers\RDPWD.sys
12:44:46.0701 2932        RDPWD - ok
12:44:46.0732 2932        RDSessMgr      (263af18af0f3db99f574c95f284ccec9) C:\WINDOWS\system32\sessmgr.exe
12:44:46.0857 2932        RDSessMgr - ok
12:44:46.0889 2932        redbook        (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
12:44:47.0045 2932        redbook - ok
12:44:47.0076 2932        RemoteAccess    (0e97ec96d6942ceec2d188cc2eb69a01) C:\WINDOWS\System32\mprdim.dll
12:44:47.0185 2932        RemoteAccess - ok
12:44:47.0232 2932        RemoteRegistry  (e4cd1f3d84e1c2ca0b8cf7501e201593) C:\WINDOWS\system32\regsvc.dll
12:44:47.0357 2932        RemoteRegistry - ok
12:44:47.0498 2932        RichVideo      (bd517c7fb119997effbe39d5e4b37b05) C:\Programme\CyberLink\Shared Files\RichVideo.exe
12:44:47.0498 2932        RichVideo ( UnsignedFile.Multi.Generic ) - warning
12:44:47.0498 2932        RichVideo - detected UnsignedFile.Multi.Generic (1)
12:44:47.0529 2932        RpcLocator      (2a02e21867497df20b8fc95631395169) C:\WINDOWS\system32\locator.exe
12:44:47.0654 2932        RpcLocator - ok
12:44:47.0701 2932        RpcSs          (3127afbf2c1ed0ab14a1bbb7aaecb85b) C:\WINDOWS\system32\rpcss.dll
12:44:47.0732 2932        RpcSs - ok
12:44:47.0764 2932        RSVP            (4bdd71b4b521521499dfd14735c4f398) C:\WINDOWS\system32\rsvp.exe
12:44:47.0873 2932        RSVP - ok
12:44:47.0920 2932        RTLE8023xp      (36ada62330c31ad314e4a26b815fc485) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
12:44:47.0951 2932        RTLE8023xp - ok
12:44:47.0982 2932        SamSs          (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
12:44:48.0107 2932        SamSs - ok
12:44:48.0123 2932        SCardSvr        (dcec079fad95d36c8dd5cb6d779dfe32) C:\WINDOWS\System32\SCardSvr.exe
12:44:48.0279 2932        SCardSvr - ok
12:44:48.0310 2932        Schedule        (a050194a44d7fa8d7186ed2f4e8367ae) C:\WINDOWS\system32\schedsvc.dll
12:44:48.0451 2932        Schedule - ok
12:44:48.0482 2932        Secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
12:44:48.0529 2932        Secdrv - ok
12:44:48.0545 2932        seclogon        (bee4cfd1d48c23b44cf4b974b0b79b2b) C:\WINDOWS\System32\seclogon.dll
12:44:48.0670 2932        seclogon - ok
12:44:48.0701 2932        SENS            (2aac9b6ed9eddffb721d6452e34d67e3) C:\WINDOWS\system32\sens.dll
12:44:48.0842 2932        SENS - ok
12:44:48.0857 2932        serenum        (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
12:44:48.0982 2932        serenum - ok
12:44:48.0998 2932        Serial          (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\DRIVERS\serial.sys
12:44:49.0123 2932        Serial - ok
12:44:49.0154 2932        Sfloppy        (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
12:44:49.0279 2932        Sfloppy - ok
12:44:49.0326 2932        SharedAccess    (cad058d5f8b889a87ca3eb3cf624dcef) C:\WINDOWS\System32\ipnathlp.dll
12:44:49.0467 2932        SharedAccess - ok
12:44:49.0498 2932        ShellHWDetection (2db7d303c36ddd055215052f118e8e75) C:\WINDOWS\System32\shsvcs.dll
12:44:49.0529 2932        ShellHWDetection - ok
12:44:49.0529 2932        Simbad - ok
12:44:49.0545 2932        Sparrow - ok
12:44:49.0560 2932        splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
12:44:49.0685 2932        splitter - ok
12:44:49.0717 2932        Spooler        (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
12:44:49.0748 2932        Spooler - ok
12:44:49.0763 2932        sr              (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
12:44:49.0826 2932        sr - ok
12:44:49.0857 2932        srservice      (fe77a85495065f3ad59c5c65b6c54182) C:\WINDOWS\system32\srsvc.dll
12:44:49.0920 2932        srservice - ok
12:44:49.0951 2932        Srv            (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
12:44:50.0013 2932        Srv - ok
12:44:50.0029 2932        SSDPSRV        (4df5b05dfaec29e13e1ed6f6ee12c500) C:\WINDOWS\System32\ssdpsrv.dll
12:44:50.0092 2932        SSDPSRV - ok
12:44:50.0123 2932        stisvc          (bc2c5985611c5356b24aeb370953ded9) C:\WINDOWS\system32\wiaservc.dll
12:44:50.0248 2932        stisvc - ok
12:44:50.0263 2932        swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
12:44:50.0420 2932        swenum - ok
12:44:50.0435 2932        swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
12:44:50.0545 2932        swmidi - ok
12:44:50.0545 2932        SwPrv - ok
12:44:50.0560 2932        symc810 - ok
12:44:50.0560 2932        symc8xx - ok
12:44:50.0560 2932        sym_hi - ok
12:44:50.0576 2932        sym_u3 - ok
12:44:50.0592 2932        sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
12:44:50.0732 2932        sysaudio - ok
12:44:50.0748 2932        SysmonLog      (2903fffa2523926d6219428040dce6b9) C:\WINDOWS\system32\smlogsvc.exe
12:44:50.0857 2932        SysmonLog - ok
12:44:50.0888 2932        TapiSrv        (05903cac4b98908d55ea5774775b382e) C:\WINDOWS\System32\tapisrv.dll
12:44:51.0013 2932        TapiSrv - ok
12:44:51.0060 2932        Tcpip          (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
12:44:51.0107 2932        Tcpip - ok
12:44:51.0123 2932        TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
12:44:51.0279 2932        TDPIPE - ok
12:44:51.0295 2932        TDTCP          (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
12:44:51.0435 2932        TDTCP - ok
12:44:51.0451 2932        TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
12:44:51.0576 2932        TermDD - ok
12:44:51.0623 2932        TermService    (b7de02c863d8f5a005a7bf375375a6a4) C:\WINDOWS\System32\termsrv.dll
12:44:51.0748 2932        TermService - ok
12:44:51.0795 2932        Themes          (2db7d303c36ddd055215052f118e8e75) C:\WINDOWS\System32\shsvcs.dll
12:44:51.0810 2932        Themes - ok
12:44:51.0826 2932        TlntSvr        (03681a1ce77f51586903869a5ab1deab) C:\WINDOWS\system32\tlntsvr.exe
12:44:51.0904 2932        TlntSvr - ok
12:44:51.0904 2932        TosIde - ok
12:44:51.0935 2932        TrkWks          (626504572b175867f30f3215c04b3e2f) C:\WINDOWS\system32\trkwks.dll
12:44:52.0060 2932        TrkWks - ok
12:44:52.0091 2932        Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
12:44:52.0216 2932        Udfs - ok
12:44:52.0232 2932        ultra - ok
12:44:52.0279 2932        Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
12:44:52.0420 2932        Update - ok
12:44:52.0451 2932        upnphost        (1dfd8975d8c89214b98d9387c1125b49) C:\WINDOWS\System32\upnphost.dll
12:44:52.0513 2932        upnphost - ok
12:44:52.0529 2932        UPS            (9b11e6118958e63e1fef129466e2bda7) C:\WINDOWS\System32\ups.exe
12:44:52.0623 2932        UPS - ok
12:44:52.0654 2932        usbccgp        (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
12:44:52.0763 2932        usbccgp - ok
12:44:52.0779 2932        usbehci        (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
12:44:52.0888 2932        usbehci - ok
12:44:52.0920 2932        usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
12:44:53.0045 2932        usbhub - ok
12:44:53.0060 2932        usbohci        (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
12:44:53.0185 2932        usbohci - ok
12:44:53.0216 2932        usbprint        (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
12:44:53.0326 2932        usbprint - ok
12:44:53.0357 2932        usbscan        (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
12:44:53.0466 2932        usbscan - ok
12:44:53.0498 2932        usbstor        (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
12:44:53.0607 2932        usbstor - ok
12:44:53.0623 2932        VgaSave        (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
12:44:53.0763 2932        VgaSave - ok
12:44:53.0763 2932        ViaIde - ok
12:44:53.0794 2932        VolSnap        (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
12:44:53.0919 2932        VolSnap - ok
12:44:53.0966 2932        VSS            (68f106273be29e7b7ef8266977268e78) C:\WINDOWS\System32\vssvc.exe
12:44:54.0029 2932        VSS - ok
12:44:54.0060 2932        W32Time        (7b353059e665f8b7ad2bbeaef597cf45) C:\WINDOWS\system32\w32time.dll
12:44:54.0169 2932        W32Time - ok
12:44:54.0185 2932        Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
12:44:54.0326 2932        Wanarp - ok
12:44:54.0326 2932        WDICA - ok
12:44:54.0341 2932        wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
12:44:54.0451 2932        wdmaud - ok
12:44:54.0482 2932        WebClient      (81727c9873e3905a2ffc1ebd07265002) C:\WINDOWS\System32\webclnt.dll
12:44:54.0607 2932        WebClient - ok
12:44:54.0716 2932        winmgmt        (6f3f3973d97714cc5f906a19fe883729) C:\WINDOWS\system32\wbem\WMIsvc.dll
12:44:54.0857 2932        winmgmt - ok
12:44:54.0935 2932        WinRM          (f10075c2ec96d2eb118012e78ece2fc2) C:\WINDOWS\system32\WsmSvc.dll
12:44:55.0029 2932        WinRM - ok
12:44:55.0060 2932        WmdmPmSN        (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll
12:44:55.0107 2932        WmdmPmSN - ok
12:44:55.0169 2932        Wmi            (ffa4d901d46d07a5bab2d8307fbb51a6) C:\WINDOWS\System32\advapi32.dll
12:44:55.0216 2932        Wmi - ok
12:44:55.0326 2932        WmiApSrv        (93908111ba57a6e60ec2fa2de202105c) C:\WINDOWS\system32\wbem\wmiapsrv.exe
12:44:55.0466 2932        WmiApSrv - ok
12:44:55.0607 2932        WMPNetworkSvc  (bf05650bb7df5e9ebdd25974e22403bb) C:\Programme\Windows Media Player\WMPNetwk.exe
12:44:55.0669 2932        WMPNetworkSvc - ok
12:44:55.0997 2932        WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
12:44:56.0029 2932        WPFFontCache_v0400 - ok
12:44:56.0763 2932        wscsvc          (300b3e84faf1a5c1f791c159ba28035d) C:\WINDOWS\system32\wscsvc.dll
12:44:56.0872 2932        wscsvc - ok
12:44:56.0888 2932        wuauserv        (7b4fe05202aa6bf9f4dfd0e6a0d8a085) C:\WINDOWS\system32\wuauserv.dll
12:44:57.0044 2932        wuauserv - ok
12:44:57.0169 2932        WudfPf          (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
12:44:57.0216 2932        WudfPf - ok
12:44:57.0263 2932        WudfRd          (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
12:44:57.0279 2932        WudfRd - ok
12:44:57.0294 2932        WudfSvc        (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
12:44:57.0326 2932        WudfSvc - ok
12:44:57.0372 2932        WZCSVC          (c4f109c005f6725162d2d12ca751e4a7) C:\WINDOWS\System32\wzcsvc.dll
12:44:57.0497 2932        WZCSVC - ok
12:44:57.0529 2932        xmlprov        (0ada34871a2e1cd2caafed1237a47750) C:\WINDOWS\System32\xmlprov.dll
12:44:57.0669 2932        xmlprov - ok
12:44:57.0685 2932        MBR (0x1B8)    (72b8ce41af0de751c946802b3ed844b4) \Device\Harddisk0\DR0
12:44:58.0122 2932        \Device\Harddisk0\DR0 - ok
12:44:58.0122 2932        Boot (0x1200)  (0d1cf8d85f4616114d6c44e72b6bb271) \Device\Harddisk0\DR0\Partition0
12:44:58.0138 2932        \Device\Harddisk0\DR0\Partition0 - ok
12:44:58.0138 2932        ============================================================
12:44:58.0138 2932        Scan finished
12:44:58.0138 2932        ============================================================
12:44:58.0247 1456        Detected object count: 6
12:44:58.0247 1456        Actual detected object count: 6
15:45:47.0689 1456        AmdK8 ( UnsignedFile.Multi.Generic ) - skipped by user
15:45:47.0689 1456        AmdK8 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:45:47.0689 1456        Ati HotKey Poller ( UnsignedFile.Multi.Generic ) - skipped by user
15:45:47.0689 1456        Ati HotKey Poller ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:45:47.0689 1456        ATI Smart ( UnsignedFile.Multi.Generic ) - skipped by user
15:45:47.0689 1456        ATI Smart ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:45:47.0689 1456        ati2mtag ( UnsignedFile.Multi.Generic ) - skipped by user
15:45:47.0689 1456        ati2mtag ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:45:47.0704 1456        IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - skipped by user
15:45:47.0704 1456        IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:45:47.0704 1456        RichVideo ( UnsignedFile.Multi.Generic ) - skipped by user
15:45:47.0704 1456        RichVideo ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 12.07.2012 15:18

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

mot2001 12.07.2012 15:42

hab ich gemacht unter Beachtung Deiner Hinweise, wobei vor dem Durchlauf die MS WiderherstellungsConsole runtergeladen und installiert wurde:

Code:

ComboFix 12-07-12.02 - Administrator 12.07.2012  16:32:14.1.2 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.49.1031.18.2047.1537 [GMT 2:00]
ausgeführt von:: c:\profile\Administrator\Eigene Dateien\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\profile\Administrator\WINDOWS
c:\profile\hildebrh\Lokale Einstellungen\Anwendungsdaten\assembly\tmp
c:\windows\IsUn0407.exe
c:\windows\unin0407.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-06-12 bis 2012-07-12  ))))))))))))))))))))))))))))))
.
.
2012-07-12 07:21 . 2012-07-12 07:21        --------        d-----w-        C:\_OTL
2012-07-12 07:14 . 2012-07-12 07:14        70344        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-12 07:14 . 2012-07-12 07:14        426184        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-07-09 07:38 . 2012-07-09 07:38        --------        d-sh--w-        c:\profile\doehlerm\IETldCache
2012-07-06 11:20 . 2012-07-06 11:20        --------        d-----w-        c:\profile\Administrator\Lokale Einstellungen\Anwendungsdaten\ESET
2012-07-06 11:20 . 2012-07-06 11:20        --------        d-----w-        c:\profile\Administrator\Anwendungsdaten\ESET
2012-07-06 11:20 . 2012-07-06 11:20        --------        d-----w-        c:\profile\LocalService\Lokale Einstellungen\Anwendungsdaten\ESET
2012-07-06 11:05 . 2012-07-06 11:05        --------        d-----w-        c:\programme\Mozilla Maintenance Service
2012-07-06 11:04 . 2012-07-06 11:04        157608        ----a-w-        c:\programme\Mozilla Firefox\maintenanceservice_installer.exe
2012-07-06 11:04 . 2012-07-06 11:04        113120        ----a-w-        c:\programme\Mozilla Firefox\maintenanceservice.exe
2012-07-06 11:04 . 2012-07-06 11:04        421200        ----a-w-        c:\programme\Mozilla Firefox\msvcp100.dll
2012-07-06 11:04 . 2012-07-06 11:04        770384        ----a-w-        c:\programme\Mozilla Firefox\msvcr100.dll
2012-07-04 07:55 . 2012-07-04 07:55        27506        ----a-w-        C:\cc_20120704_095454.reg
2012-07-03 12:23 . 2012-07-03 12:23        --------        d-----w-        c:\profile\Administrator\Lokale Einstellungen\Anwendungsdaten\GHISLER
2012-07-03 10:26 . 2012-07-03 10:27        --------        d-----w-        c:\programme\stinger
2012-06-29 13:12 . 2012-06-29 13:12        --------        d-----w-        c:\profile\Administrator\Anwendungsdaten\Malwarebytes
2012-06-29 13:11 . 2012-06-29 13:11        --------        d-----w-        c:\profile\All Users\Anwendungsdaten\Malwarebytes
2012-06-29 11:49 . 2012-06-29 12:08        --------        d-----w-        c:\programme\Microsoft Silverlight
2012-06-29 11:49 . 2012-06-29 11:49        --------        d-----w-        c:\programme\Windows Live SkyDrive
2012-06-29 11:48 . 2012-06-29 11:48        --------        d-----w-        c:\programme\Common\Windows Live
2012-06-29 11:47 . 2012-06-29 11:47        --------        d-----w-        c:\windows\system32\winrm
2012-06-29 11:47 . 2012-06-29 11:47        --------        d-----w-        c:\windows\system32\GroupPolicy
2012-06-29 11:47 . 2012-06-29 11:47        --------        dc-h--w-        c:\windows\$968930Uinstall_KB968930$
2012-06-29 11:46 . 2012-06-29 11:46        --------        d-----w-        c:\programme\Windows Media Connect 2
2012-06-29 11:44 . 2012-06-29 11:45        --------        d-----w-        c:\windows\system32\drivers\UMDF
2012-06-29 11:44 . 2012-06-29 11:44        --------        d-----w-        c:\windows\system32\LogFiles
2012-06-29 11:28 . 2012-06-29 11:28        --------        d-sh--w-        c:\profile\Administrator\PrivacIE
2012-06-29 11:27 . 2012-06-29 11:49        --------        d-----w-        c:\programme\Microsoft
2012-06-29 11:25 . 2012-06-29 11:25        --------        d-sh--w-        c:\profile\Administrator\IETldCache
2012-06-29 11:22 . 2012-05-11 14:40        521728        -c----w-        c:\windows\system32\dllcache\jsdbgui.dll
2012-06-29 11:21 . 2011-08-16 10:45        6144        -c----w-        c:\windows\system32\dllcache\iecompat.dll
2012-06-29 11:20 . 2012-05-11 14:40        12800        -c----w-        c:\windows\system32\dllcache\xpshims.dll
2012-06-29 11:20 . 2012-05-11 14:40        247808        -c----w-        c:\windows\system32\dllcache\ieproxy.dll
2012-06-29 11:20 . 2012-05-11 14:40        743424        -c----w-        c:\windows\system32\dllcache\iedvtool.dll
2012-06-29 11:18 . 2012-06-29 11:20        --------        dc-h--w-        c:\windows\ie8
2012-06-29 09:05 . 2012-06-29 11:31        --------        d-----w-        c:\profile\Administrator\Lokale Einstellungen\Anwendungsdaten\AskToolbar
2012-06-29 09:05 . 2001-08-18 01:22        12288        -c--a-w-        c:\windows\system32\dllcache\mouhid.sys
2012-06-29 09:05 . 2001-08-18 01:22        12288        ----a-w-        c:\windows\system32\drivers\mouhid.sys
2012-06-28 14:57 . 2012-06-28 16:24        --------        d---a-w-        C:\Kaspersky Rescue Disk 10.0
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-03 10:27 . 2011-03-16 13:02        87656        ----a-w-        c:\windows\system32\drivers\mferkdet.sys
2012-07-03 10:27 . 2011-03-16 13:02        475704        ----a-w-        c:\windows\system32\drivers\mfehidk.sys
2012-07-03 10:27 . 2011-03-16 13:02        159608        ----a-w-        c:\windows\system32\mfevtps.exe
2012-06-13 13:55 . 2006-03-02 15:44        1866240        ----a-w-        c:\windows\system32\win32k.sys
2012-06-05 15:49 . 2008-05-30 12:34        1372672        ------w-        c:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2004-08-04 11:00        1172480        ----a-w-        c:\windows\system32\msxml3.dll
2012-06-04 15:35 . 2009-08-06 18:23        222448        ----a-w-        c:\windows\system32\muweb.dll
2012-06-04 04:32 . 2004-08-04 11:00        152576        ----a-w-        c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2008-05-30 12:26        18456        ----a-w-        c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2008-05-30 12:26        15896        ----a-w-        c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2008-05-29 14:19        329240        ----a-w-        c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2008-05-29 14:19        210968        ----a-w-        c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2008-05-29 14:19        219160        ----a-w-        c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2008-05-30 12:26        45080        ----a-w-        c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2008-05-30 12:26        15896        ----a-w-        c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2008-05-29 14:19        53784        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2008-05-29 14:19        35864        ----a-w-        c:\windows\system32\wups.dll
2012-06-02 13:19 . 2004-08-04 11:00        97304        ----a-w-        c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2008-05-30 12:26        23576        ----a-w-        c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2008-05-29 14:19        577048        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2008-05-29 14:19        1933848        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-02 13:18 . 2010-01-22 09:47        275696        ----a-w-        c:\windows\system32\mucltui.dll
2012-06-02 13:18 . 2010-01-22 09:47        18160        ----a-w-        c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2004-08-04 11:00        604160        ----a-w-        c:\windows\system32\crypt32.dll
2012-05-16 15:07 . 2006-03-02 15:45        916992        ----a-w-        c:\windows\system32\wininet.dll
2012-05-11 14:40 . 2004-08-04 11:00        43520        ------w-        c:\windows\system32\licmgr10.dll
2012-05-11 14:40 . 2004-08-04 11:00        1469440        ------w-        c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2004-08-04 11:00        385024        ------w-        c:\windows\system32\html.iec
2012-05-05 03:14 . 2006-03-02 15:43        2150912        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-05-05 03:14 . 2004-08-03 23:50        2029056        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2008-05-29 14:18        139656        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-04-25 08:58 . 2008-05-30 13:52        73728        ----a-w-        c:\windows\system32\javacpl.cpl
2012-04-25 08:58 . 2011-01-31 11:42        472808        ----a-w-        c:\windows\system32\deployJava1.dll
2012-07-06 11:04 . 2012-03-29 10:45        85472        ----a-w-        c:\programme\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-11-06 16855552]
"SkyTel"="SkyTel.EXE" [2007-10-11 1826816]
"RemoteControl"="c:\programme\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\programme\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"NeroFilterCheck"="c:\programme\Common\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\programme\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\programme\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"StartCCC"="c:\programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"QuickTime Task"="c:\programme\QuickTime\qttask.exe" [2008-03-28 413696]
"Adobe Reader Speed Launcher"="c:\programme\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\programme\Common\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"McAfeeUpdaterUI"="c:\programme\McAfee\Common Framework\udaterui.exe" [2011-01-12 161088]
"ShStatEXE"="c:\programme\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2011-01-12 215360]
"Adobe Acrobat Speed Launcher"="c:\programme\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2010-10-25 36760]
"Acrobat Assistant 8.0"="c:\programme\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2010-10-25 821144]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\McAfee\\Common Framework\\FrameworkService.exe"=
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [16.03.2011 15:02 89528]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [16.03.2011 15:02 159608]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [16.03.2011 15:02 87656]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\programme\Mozilla Maintenance Service\maintenanceservice.exe [06.07.2012 13:05 113120]
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 24367411
*Deregistered* - 24367411
*Deregistered* - mfeavfk01
.
Inhalt des "geplante Tasks" Ordners
.
2008-05-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-04-11 15:57]
.
2012-06-29 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-22 20:18]
.
.
------- Zusätzlicher Suchlauf -------
.
IE: &Citavi Picker... - file://c:\profile\All Users\Anwendungsdaten\Swiss Academic Software\Citavi Picker\Internet Explorer\ShowContextMenu.html
IE: An vorhandene PDF-Datei anfügen - c:\programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - c:\programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: microsoft.com
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: windowsupdate.com
TCP: Interfaces\{7E608E10-CB07-4588-8B69-C9422848FAE7}: NameServer = 141.20.1.3,141.20.1.31
FF - ProfilePath - c:\profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-Citrix-ICA-Client - c:\windows\ISUN0407.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-07-12 16:35
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-515967899-492894223-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,27,5f,38,b1,ca,84,33,41,a6,7c,74,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,27,5f,38,b1,ca,84,33,41,a6,7c,74,\
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]
"7040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(856)
c:\windows\system32\Ati2evxx.dll
.
Zeit der Fertigstellung: 2012-07-12  16:36:38
ComboFix-quarantined-files.txt  2012-07-12 14:36
.
Vor Suchlauf: 13 Verzeichnis(se), 191.490.367.488 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 191.707.545.600 Bytes frei
.
WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - 01BCEF55916A394CEFB64DD60925512B


cosinus 12.07.2012 18:12

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.

Code:

Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"=-

Dirlook::
c:\windows\$968930Uinstall_KB968930$

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

mot2001 13.07.2012 08:33

hab ich unter Beachtung Deiner Hinweise durchgefuehrt. Folgende Abweichungen sind dabei aufgetreten:
1. CoFi hat zu Beginn des Durchlaufs eine Programmaktualisierung durchgefuehrt.
2. Bei Stufe 4 ist folgendes Programm abgestuerzt: PEV.exe
3. Das Programm CoFi hat mich nicht nach einem Neustart gefragt, wie beim ersten Durchlauf. Es hat dann gleich die LogDatei erstellt:

Code:

ComboFix 12-07-13.01 - Administrator 13.07.2012  9:14.2.2 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.49.1031.18.2047.1596 [GMT 2:00]
ausgeführt von:: c:\profile\Administrator\Eigene Dateien\Downloads\ComboFix.exe
Benutzte Befehlsschalter :: c:\profile\Administrator\Desktop\CFScript.txt
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-06-13 bis 2012-07-13  ))))))))))))))))))))))))))))))
.
.
2012-07-12 07:21 . 2012-07-12 07:21        --------        d-----w-        C:\_OTL
2012-07-12 07:14 . 2012-07-12 07:14        70344        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-12 07:14 . 2012-07-12 07:14        426184        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-07-09 07:38 . 2012-07-09 07:38        --------        d-sh--w-        c:\profile\doehlerm\IETldCache
2012-07-06 11:20 . 2012-07-06 11:20        --------        d-----w-        c:\profile\Administrator\Lokale Einstellungen\Anwendungsdaten\ESET
2012-07-06 11:20 . 2012-07-06 11:20        --------        d-----w-        c:\profile\Administrator\Anwendungsdaten\ESET
2012-07-06 11:20 . 2012-07-06 11:20        --------        d-----w-        c:\profile\LocalService\Lokale Einstellungen\Anwendungsdaten\ESET
2012-07-06 11:05 . 2012-07-06 11:05        --------        d-----w-        c:\programme\Mozilla Maintenance Service
2012-07-06 11:04 . 2012-07-06 11:04        157608        ----a-w-        c:\programme\Mozilla Firefox\maintenanceservice_installer.exe
2012-07-06 11:04 . 2012-07-06 11:04        113120        ----a-w-        c:\programme\Mozilla Firefox\maintenanceservice.exe
2012-07-06 11:04 . 2012-07-06 11:04        421200        ----a-w-        c:\programme\Mozilla Firefox\msvcp100.dll
2012-07-06 11:04 . 2012-07-06 11:04        770384        ----a-w-        c:\programme\Mozilla Firefox\msvcr100.dll
2012-07-04 07:55 . 2012-07-04 07:55        27506        ----a-w-        C:\cc_20120704_095454.reg
2012-07-03 12:23 . 2012-07-03 12:23        --------        d-----w-        c:\profile\Administrator\Lokale Einstellungen\Anwendungsdaten\GHISLER
2012-07-03 10:26 . 2012-07-03 10:27        --------        d-----w-        c:\programme\stinger
2012-06-29 13:12 . 2012-06-29 13:12        --------        d-----w-        c:\profile\Administrator\Anwendungsdaten\Malwarebytes
2012-06-29 13:11 . 2012-06-29 13:11        --------        d-----w-        c:\profile\All Users\Anwendungsdaten\Malwarebytes
2012-06-29 11:49 . 2012-06-29 12:08        --------        d-----w-        c:\programme\Microsoft Silverlight
2012-06-29 11:49 . 2012-06-29 11:49        --------        d-----w-        c:\programme\Windows Live SkyDrive
2012-06-29 11:48 . 2012-06-29 11:48        --------        d-----w-        c:\programme\Common\Windows Live
2012-06-29 11:47 . 2012-06-29 11:47        --------        d-----w-        c:\windows\system32\winrm
2012-06-29 11:47 . 2012-06-29 11:47        --------        d-----w-        c:\windows\system32\GroupPolicy
2012-06-29 11:47 . 2012-06-29 11:47        --------        dc-h--w-        c:\windows\$968930Uinstall_KB968930$
2012-06-29 11:46 . 2012-06-29 11:46        --------        d-----w-        c:\programme\Windows Media Connect 2
2012-06-29 11:44 . 2012-06-29 11:45        --------        d-----w-        c:\windows\system32\drivers\UMDF
2012-06-29 11:44 . 2012-06-29 11:44        --------        d-----w-        c:\windows\system32\LogFiles
2012-06-29 11:28 . 2012-06-29 11:28        --------        d-sh--w-        c:\profile\Administrator\PrivacIE
2012-06-29 11:27 . 2012-06-29 11:49        --------        d-----w-        c:\programme\Microsoft
2012-06-29 11:25 . 2012-06-29 11:25        --------        d-sh--w-        c:\profile\Administrator\IETldCache
2012-06-29 11:22 . 2012-05-11 14:40        521728        -c----w-        c:\windows\system32\dllcache\jsdbgui.dll
2012-06-29 11:21 . 2011-08-16 10:45        6144        -c----w-        c:\windows\system32\dllcache\iecompat.dll
2012-06-29 11:20 . 2012-05-11 14:40        12800        -c----w-        c:\windows\system32\dllcache\xpshims.dll
2012-06-29 11:20 . 2012-05-11 14:40        247808        -c----w-        c:\windows\system32\dllcache\ieproxy.dll
2012-06-29 11:20 . 2012-05-11 14:40        743424        -c----w-        c:\windows\system32\dllcache\iedvtool.dll
2012-06-29 11:18 . 2012-06-29 11:20        --------        dc-h--w-        c:\windows\ie8
2012-06-29 09:05 . 2012-06-29 11:31        --------        d-----w-        c:\profile\Administrator\Lokale Einstellungen\Anwendungsdaten\AskToolbar
2012-06-29 09:05 . 2001-08-18 01:22        12288        -c--a-w-        c:\windows\system32\dllcache\mouhid.sys
2012-06-29 09:05 . 2001-08-18 01:22        12288        ----a-w-        c:\windows\system32\drivers\mouhid.sys
2012-06-28 14:57 . 2012-06-28 16:24        --------        d---a-w-        C:\Kaspersky Rescue Disk 10.0
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-03 10:27 . 2011-03-16 13:02        87656        ----a-w-        c:\windows\system32\drivers\mferkdet.sys
2012-07-03 10:27 . 2011-03-16 13:02        475704        ----a-w-        c:\windows\system32\drivers\mfehidk.sys
2012-07-03 10:27 . 2011-03-16 13:02        159608        ----a-w-        c:\windows\system32\mfevtps.exe
2012-06-13 13:55 . 2006-03-02 15:44        1866240        ----a-w-        c:\windows\system32\win32k.sys
2012-06-05 15:49 . 2008-05-30 12:34        1372672        ------w-        c:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2004-08-04 11:00        1172480        ----a-w-        c:\windows\system32\msxml3.dll
2012-06-04 15:35 . 2009-08-06 18:23        222448        ----a-w-        c:\windows\system32\muweb.dll
2012-06-04 04:32 . 2004-08-04 11:00        152576        ----a-w-        c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2008-05-30 12:26        18456        ----a-w-        c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2008-05-30 12:26        15896        ----a-w-        c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2008-05-29 14:19        329240        ----a-w-        c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2008-05-29 14:19        210968        ----a-w-        c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2008-05-29 14:19        219160        ----a-w-        c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2008-05-30 12:26        45080        ----a-w-        c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2008-05-30 12:26        15896        ----a-w-        c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2008-05-29 14:19        53784        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2008-05-29 14:19        35864        ----a-w-        c:\windows\system32\wups.dll
2012-06-02 13:19 . 2004-08-04 11:00        97304        ----a-w-        c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2008-05-30 12:26        23576        ----a-w-        c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2008-05-29 14:19        577048        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2008-05-29 14:19        1933848        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-02 13:18 . 2010-01-22 09:47        275696        ----a-w-        c:\windows\system32\mucltui.dll
2012-06-02 13:18 . 2010-01-22 09:47        18160        ----a-w-        c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2004-08-04 11:00        604160        ----a-w-        c:\windows\system32\crypt32.dll
2012-05-16 15:07 . 2006-03-02 15:45        916992        ----a-w-        c:\windows\system32\wininet.dll
2012-05-11 14:40 . 2004-08-04 11:00        43520        ------w-        c:\windows\system32\licmgr10.dll
2012-05-11 14:40 . 2004-08-04 11:00        1469440        ------w-        c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2004-08-04 11:00        385024        ------w-        c:\windows\system32\html.iec
2012-05-05 03:14 . 2006-03-02 15:43        2150912        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-05-05 03:14 . 2004-08-03 23:50        2029056        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2008-05-29 14:18        139656        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-04-25 08:58 . 2008-05-30 13:52        73728        ----a-w-        c:\windows\system32\javacpl.cpl
2012-04-25 08:58 . 2011-01-31 11:42        472808        ----a-w-        c:\windows\system32\deployJava1.dll
2012-07-06 11:04 . 2012-03-29 10:45        85472        ----a-w-        c:\programme\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((((((((((  Look  )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\$968930Uinstall_KB968930$ ----
.
2012-06-29 11:47 . 2009-06-25 07:59        225072        -c----w-        c:\windows\$968930Uinstall_KB968930$\spuninst\spuninst.exe
2012-06-29 11:47 . 2009-06-25 07:59        385328        -c----w-        c:\windows\$968930Uinstall_KB968930$\spuninst\updspapi.dll
2012-06-29 11:47 . 2012-06-29 11:48        74046        -c--a-w-        c:\windows\$968930Uinstall_KB968930$\spuninst\spuninst.inf
2012-06-29 11:47 . 2012-06-29 11:47        14029        -c--a-w-        c:\windows\$968930Uinstall_KB968930$\spuninst\spuninst.txt
2009-10-09 12:57 . 2009-10-09 12:57        20480        -c----w-        c:\windows\$968930Uinstall_KB968930$\PSCustomSetupUtil.exe
2009-10-09 12:56 . 2009-10-09 12:56        9216        -c----w-        c:\windows\$968930Uinstall_KB968930$\PSSetupNativeUtils.exe
.
.
(((((((((((((((((((((((((((((  SnapShot@2012-07-12_14.35.29  )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-13 07:01 . 2012-07-13 07:01        16384              c:\windows\Temp\Perflib_Perfdata_10c.dat
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-11-06 16855552]
"SkyTel"="SkyTel.EXE" [2007-10-11 1826816]
"RemoteControl"="c:\programme\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\programme\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"NeroFilterCheck"="c:\programme\Common\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\programme\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\programme\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"StartCCC"="c:\programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"QuickTime Task"="c:\programme\QuickTime\qttask.exe" [2008-03-28 413696]
"Adobe Reader Speed Launcher"="c:\programme\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\programme\Common\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"McAfeeUpdaterUI"="c:\programme\McAfee\Common Framework\udaterui.exe" [2011-01-12 161088]
"ShStatEXE"="c:\programme\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2011-01-12 215360]
"Adobe Acrobat Speed Launcher"="c:\programme\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2010-10-25 36760]
"Acrobat Assistant 8.0"="c:\programme\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2010-10-25 821144]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\McAfee\\Common Framework\\FrameworkService.exe"=
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [16.03.2011 15:02 89528]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [16.03.2011 15:02 159608]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [16.03.2011 15:02 87656]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\programme\Mozilla Maintenance Service\maintenanceservice.exe [06.07.2012 13:05 113120]
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
*Deregistered* - mfeavfk01
.
Inhalt des "geplante Tasks" Ordners
.
2008-05-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-04-11 15:57]
.
2012-06-29 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-22 20:18]
.
.
------- Zusätzlicher Suchlauf -------
.
IE: &Citavi Picker... - file://c:\profile\All Users\Anwendungsdaten\Swiss Academic Software\Citavi Picker\Internet Explorer\ShowContextMenu.html
IE: An vorhandene PDF-Datei anfügen - c:\programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - c:\programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: microsoft.com
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: windowsupdate.com
TCP: Interfaces\{7E608E10-CB07-4588-8B69-C9422848FAE7}: NameServer = 141.20.1.3,141.20.1.31
FF - ProfilePath - c:\profile\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\l3srtxij.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-07-13 09:19
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-515967899-492894223-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,27,5f,38,b1,ca,84,33,41,a6,7c,74,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,27,5f,38,b1,ca,84,33,41,a6,7c,74,\
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]
"7040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(824)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3924)
c:\programme\McAfee\Common Framework\McTrayLegacySupportPlugin.dll
c:\programme\McAfee\Common Framework\McTrayInterfaceLib.dll
c:\programme\McAfee\Common Framework\McAfeeWin32GUISupportDLL.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Zeit der Fertigstellung: 2012-07-13  09:20:34
ComboFix-quarantined-files.txt  2012-07-13 07:20
ComboFix2.txt  2012-07-12 14:36
.
Vor Suchlauf: 15 Verzeichnis(se), 191.669.006.336 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 191.659.802.624 Bytes frei
.
- - End Of File - - 6D441AFE1CAFAA7D83B2059C60F53011


cosinus 13.07.2012 19:32

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

mot2001 16.07.2012 11:57

Gmer:

Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-07-16 11:50:52
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 SAMSUNG_HD250HJ rev.FH100-06
Running: 3r2wg8tk.exe; Driver: C:\Profile\ADMINI~1\LOKALE~1\Temp\fxtdipog.sys


---- System - GMER 1.0.15 ----

Code            mfehidk.sys (McAfee Link Driver/McAfee, Inc.)                                                          ZwOpenProcess [0xB9EA8264]
Code            mfehidk.sys (McAfee Link Driver/McAfee, Inc.)                                                          ZwOpenThread [0xB9EA8278]
Code            \??\C:\Profile\ADMINI~1\LOKALE~1\Temp\catchme.sys                                                      pIofCallDriver
Code            mfehidk.sys (McAfee Link Driver/McAfee, Inc.)                                                          NtOpenProcess
Code            mfehidk.sys (McAfee Link Driver/McAfee, Inc.)                                                          NtOpenThread

---- Kernel code sections - GMER 1.0.15 ----

PAGE            ntkrnlpa.exe!NtOpenProcess                                                                              805CB456 5 Bytes  JMP B9EA8268 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!NtOpenThread                                                                              805CB6E2 5 Bytes  JMP B9EA827C mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text          C:\WINDOWS\system32\DRIVERS\ati2mtag.sys                                                                section is writeable [0xB78CC000, 0x18FFBC, 0xE8000020]
?              C:\WINDOWS\system32\Drivers\PROCEXP113.SYS                                                              Das System kann die angegebene Datei nicht finden. !
?              C:\Profile\ADMINI~1\LOKALE~1\Temp\catchme.sys                                                          Das System kann die angegebene Datei nicht finden. !

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\WINDOWS\system32\mfevtps.exe[656] @ C:\WINDOWS\system32\CRYPT32.dll [ADVAPI32.dll!RegQueryValueExW]  [00409380] C:\WINDOWS\system32\mfevtps.exe (McAfee Process Validation Service/McAfee, Inc.)
IAT            C:\WINDOWS\system32\mfevtps.exe[656] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA]      [004093E0] C:\WINDOWS\system32\mfevtps.exe (McAfee Process Validation Service/McAfee, Inc.)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                  mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                  InCDrec.SYS (InCD File System Recognizer/Nero AG)
AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                              mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                              mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                            mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs                                 
Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout                      15
Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota                        10000
Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler                                      yes
Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk                                     
Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout                      90
Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota                        10000

---- EOF - GMER 1.0.15 ----

Osam:

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 12:14:52 on 16.07.2012

OS: Windows XP Professional Service Pack 3 (Build 2600)
Default Browser: Mozilla Corporation Firefox 13.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"AppleSoftwareUpdate.job" - "Apple Inc." - C:\Programme\Apple Software Update\SoftwareUpdate.exe
"WGASetup.job" - "Microsoft Corporation" - C:\WINDOWS\system32\KB905474\wgasetup.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"ALSndMgr.cpl" - "Realtek Semiconductor Corp." - C:\WINDOWS\system32\ALSndMgr.cpl
"BDEADMIN.CPL" - ? - C:\WINDOWS\system32\BDEADMIN.CPL
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
"infocardcpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\infocardcpl.cpl
"javacpl.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\javacpl.cpl
"RTSndMgr.cpl" - "Realtek Semiconductor Corp." - C:\WINDOWS\system32\RTSndMgr.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL
"Nero BurnRights" - "Nero AG" - C:\Programme\Nero\Nero 7\Nero Toolkit\NeroBurnRights.cpl
"QuickTime" - "Apple Inc." - C:\Programme\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"AMD-Prozessortreiber" (AmdK8) - "Advanced Micro Devices" - C:\WINDOWS\System32\DRIVERS\AmdK8.sys
"ati2mtag" (ati2mtag) - "ATI Technologies Inc." - C:\WINDOWS\System32\DRIVERS\ati2mtag.sys
"catchme" (catchme) - ? - C:\Profile\ADMINI~1\LOKALE~1\Temp\catchme.sys  (File not found)
"Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys  (File not found)
"fxtdipog" (fxtdipog) - ? - C:\Profile\ADMINI~1\LOKALE~1\Temp\fxtdipog.sys  (Hidden registry entry, rootkit activity | File not found)
"GMSIPCI" (GMSIPCI) - ? - D:\INSTALL\GMSIPCI.SYS  (File not found)
"i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys  (File not found)
"InCD File System" (InCDfs) - "Nero AG" - C:\WINDOWS\System32\drivers\InCDFs.sys
"InCD Reader" (incdrm) - "Nero AG" - C:\WINDOWS\System32\drivers\InCDRm.sys
"InCDPass" (InCDPass) - "Nero AG" - C:\WINDOWS\System32\drivers\InCDPass.sys
"InCDrec" (InCDrec) - "Nero AG" - C:\WINDOWS\system32\drivers\InCDrec.sys
"lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys  (File not found)
"mbr" (mbr) - ? - C:\ComboFix\mbr.sys  (Hidden registry entry, rootkit activity | File not found)
"McAfee Inc." (mfeavfk01) - ? - C:\WINDOWS\system32\drivers\mfeavfk01.sys  (File not found)
"McAfee Inc. mfeapfk" (mfeapfk) - "McAfee, Inc." - C:\WINDOWS\System32\drivers\mfeapfk.sys
"McAfee Inc. mfeavfk" (mfeavfk) - "McAfee, Inc." - C:\WINDOWS\System32\drivers\mfeavfk.sys
"McAfee Inc. mfebopk" (mfebopk) - "McAfee, Inc." - C:\WINDOWS\System32\drivers\mfebopk.sys
"McAfee Inc. mfehidk" (mfehidk) - "McAfee, Inc." - C:\WINDOWS\System32\drivers\mfehidk.sys
"McAfee Inc. mferkdet" (mferkdet) - "McAfee, Inc." - C:\WINDOWS\System32\drivers\mferkdet.sys
"McAfee Inc. mfetdi2k" (mfetdi2k) - "McAfee, Inc." - C:\WINDOWS\System32\drivers\mfetdi2k.sys
"PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys  (File not found)
"PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys  (File not found)
"PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys  (File not found)
"PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys  (File not found)
"PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys  (File not found)
"Service for Realtek HD Audio (WDM)" (IntcAzAudAddService) - "Realtek Semiconductor Corp." - C:\WINDOWS\System32\drivers\RtkHDAud.sys
"VSCore mferkdk" (mferkdk) - ? - C:\Programme\McAfee\VirusScan Enterprise\mferkdk.sys  (File not found)
"WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys  (File not found)

[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Programme\Common\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\Common\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Programme\Common\Microsoft Shared\Help\hxds.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Programme\7-Zip\7-zip.dll
{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} "Acrobat Elements Context Menu" - "Adobe Systems Inc." - C:\Programme\Adobe\Acrobat 10.0\Acrobat Elements\ContextMenu.dll
{42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? -  (File not found | COM-object registry key not found)
{CAE3251E-9B15-4810-B268-852AD9792A59} "InCDShellExt Class" - "Nero AG" - C:\Programme\Nero\Nero 7\InCD\InCDshx.dll
{B3D9AEDE-B2C3-406d-A254-6BE07767B08B} "InCDUdfPerm Class" - "Nero AG" - C:\Programme\Nero\Nero 7\InCD\InCDUP.dll
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? -  (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Programme\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\Common\MICROS~1\OFFICE12\msoshext.dll
{00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\Common\MICROS~1\OFFICE12\msoshext.dll
{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2} "NeroCoverEdLiveIcons Class" - "Nero AG" - C:\Programme\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? -  (File not found | COM-object registry key not found)
{e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - ? - C:\Programme\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Web Folders" - "Microsoft Corporation" - C:\Programme\Common\Microsoft Shared\Web Folders\MSONSEXT.DLL

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "Adobe PDF" - "Adobe Systems Incorporated" - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBarLayout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} "Java Plug-in 1.6.0_06" - "Sun Microsystems, Inc." - C:\Programme\Java\jre1.6.0_06\bin\npjpi160_06.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} "MUWebControl Class" - "Microsoft Corporation" - C:\WINDOWS\system32\muweb.dll / hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1340968528124
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} "Office Genuine Advantage Validation Tool" - ? - C:\WINDOWS\system32\OGACheckControl.DLL / hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
{C7DB51B4-BCF7-4923-8874-7F1A0DC92277} "Office Update Installation Engine" - "Microsoft Corporation" - C:\WINDOWS\opuc.dll / hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{609D670F-B735-4da7-AC6D-F3BD358E325E} "Citavi Picker" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "Adobe PDF" - "Adobe Systems Incorporated" - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{AE7CD045-E861-484f-8273-0445EE161910} "Adobe PDF Conversion Toolbar Helper" - "Adobe Systems Incorporated" - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\ssv.dll
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} "scriptproxy" - "McAfee, Inc." - C:\Programme\Common\McAfee\SystemCore\ScriptSn.20120413102718.dll
{F4971EE7-DAA0-4053-9964-665D8EE6A077} "SmartSelect Class" - "Adobe Systems Incorporated" - C:\Programme\Common\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
{609D670F-B735-4da7-AC6D-F3BD358E325E} "SwissAcademic.Citavi.Picker.IEPicker" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Programme\Common\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[Logon]
-----( %AllUsersProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Profile\All Users\Startmenü\Programme\Autostart\desktop.ini
-----( %UserProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Profile\Administrator\Startmenü\Programme\Autostart\desktop.ini
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Acrobat Assistant 8.0" - "Adobe Systems Inc." - "C:\Programme\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
"Adobe Acrobat Speed Launcher" - "Adobe Systems Incorporated" - "C:\Programme\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Programme\Common\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Programme\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"InCD" - "Nero AG" - C:\Programme\Nero\Nero 7\InCD\InCD.exe
"LanguageShortcut" - ? - C:\Programme\CyberLink\PowerDVD\Language\Language.exe
"McAfeeUpdaterUI" - "McAfee, Inc." - "C:\Programme\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
"NeroFilterCheck" - "Nero AG" - C:\Programme\Common\Ahead\Lib\NeroCheck.exe
"QuickTime Task" - "Apple Inc." - "C:\Programme\QuickTime\qttask.exe" -atboottime
"RemoteControl" - "Cyberlink Corp." - C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
"RTHDCPL" - "Realtek Semiconductor Corp." - RTHDCPL.EXE
"SecurDisc" - "Nero AG" - C:\Programme\Nero\Nero 7\InCD\NBHGui.exe
"ShStatEXE" - "McAfee, Inc." - "C:\Programme\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
"SkyTel" - "Realtek Semiconductor Corp." - SkyTel.EXE
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"novaPDF Pro Desktop 5 Monitor" - "Softland" - C:\WINDOWS\system32\novamnp5.dll
"PDFCreator" - ? - C:\WINDOWS\system32\pdfcmnnt.dll  (File found, but it contains no detailed information)

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"ASP.NET-Zustandsdienst" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
"Ati HotKey Poller" (Ati HotKey Poller) - "ATI Technologies Inc." - C:\WINDOWS\system32\Ati2evxx.exe
"ATI Smart" (ATI Smart) - ? - C:\WINDOWS\system32\ati2sgag.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Programme\CyberLink\Shared Files\RichVideo.exe
"InCD Helper" (InCDsrv) - "Nero AG" - C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe
"Java Quick Starter" (JavaQuickStarterService) - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jqs.exe
"Machine Debug Manager" (MDM) - "Microsoft Corporation" - C:\Programme\Common\Microsoft Shared\VS7DEBUG\MDM.EXE
"McAfee Framework-Dienst" (McAfeeFramework) - "McAfee, Inc." - C:\Programme\McAfee\Common Framework\FrameworkService.exe
"McAfee McShield" (McShield) - "McAfee, Inc." - C:\Programme\Common\McAfee\SystemCore\mcshield.exe
"McAfee Task Manager" (McTaskManager) - "McAfee, Inc." - C:\Programme\McAfee\VirusScan Enterprise\vstskmgr.exe
"McAfee Validation Trust Protection Service" (mfevtp) - "McAfee, Inc." - C:\WINDOWS\system32\mfevtps.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Programme\Common\Microsoft Shared\OFFICE12\ODSERV.EXE
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe
"NBService" (NBService) - "Nero AG" - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
"NMIndexingService" (NMIndexingService) - "Nero AG" - C:\Programme\Common\Ahead\Lib\NMIndexingService.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Programme\Common\Microsoft Shared\Source Engine\OSE.EXE
"Windows CardSpace" (idsvc) - "Microsoft Corporation" - c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
"Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0) - "Microsoft Corporation" - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
"Windows Presentation Foundation Font Cache 4.0.0.0" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe

[Winlogon]
-----( HKCU\Control Panel\IOProcs )-----
"MVB" - ? - mvfs32.dll  (File not found)
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )-----
"AtiExtEvent" - "ATI Technologies Inc." - C:\WINDOWS\system32\Ati2evxx.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

aswMBR log:

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-16 12:21:22
-----------------------------
12:21:22.168    OS Version: Windows 5.1.2600 Service Pack 3
12:21:22.168    Number of processors: 2 586 0x6B02
12:21:22.168    ComputerName: THEO99  UserName:
12:21:22.746    Initialize success
12:24:23.954    AVAST engine defs: 12071600
12:26:33.848    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
12:26:33.848    Disk 0 Vendor: SAMSUNG_HD250HJ FH100-06 Size: 238475MB BusType: 3
12:26:33.895    Disk 0 MBR read successfully
12:26:33.895    Disk 0 MBR scan
12:26:33.926    Disk 0 Windows XP default MBR code
12:26:33.958    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      238464 MB offset 63
12:26:33.958    Disk 0 scanning sectors +488376000
12:26:34.067    Disk 0 scanning C:\WINDOWS\system32\drivers
12:27:19.709    Service scanning
12:27:23.099    Service GMSIPCI D:\INSTALL\GMSIPCI.SYS **LOCKED** 21
12:27:32.709    Modules scanning
12:28:26.304    Disk 0 trace - called modules:
12:28:26.335    ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
12:28:26.335    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89e5e1e0]
12:28:26.335    3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000069[0x89e49f18]
12:28:26.335    5 ACPI.sys[b9f7e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x89d84d98]
12:28:26.945    AVAST engine scan C:\WINDOWS
12:30:06.369    AVAST engine scan C:\WINDOWS\system32
12:43:47.093    AVAST engine scan C:\WINDOWS\system32\drivers
12:45:50.034    Disk 0 MBR has been saved successfully to "C:\Profile\Administrator\Desktop\MBR.dat"
12:45:50.034    The log file has been saved successfully to "C:\Profile\Administrator\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-16 12:21:22
-----------------------------
12:21:22.168    OS Version: Windows 5.1.2600 Service Pack 3
12:21:22.168    Number of processors: 2 586 0x6B02
12:21:22.168    ComputerName: THEO99  UserName:
12:21:22.746    Initialize success
12:24:23.954    AVAST engine defs: 12071600
12:26:33.848    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
12:26:33.848    Disk 0 Vendor: SAMSUNG_HD250HJ FH100-06 Size: 238475MB BusType: 3
12:26:33.895    Disk 0 MBR read successfully
12:26:33.895    Disk 0 MBR scan
12:26:33.926    Disk 0 Windows XP default MBR code
12:26:33.958    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      238464 MB offset 63
12:26:33.958    Disk 0 scanning sectors +488376000
12:26:34.067    Disk 0 scanning C:\WINDOWS\system32\drivers
12:27:19.709    Service scanning
12:27:23.099    Service GMSIPCI D:\INSTALL\GMSIPCI.SYS **LOCKED** 21
12:27:32.709    Modules scanning
12:28:26.304    Disk 0 trace - called modules:
12:28:26.335    ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
12:28:26.335    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89e5e1e0]
12:28:26.335    3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000069[0x89e49f18]
12:28:26.335    5 ACPI.sys[b9f7e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x89d84d98]
12:28:26.945    AVAST engine scan C:\WINDOWS
12:30:06.369    AVAST engine scan C:\WINDOWS\system32
12:43:47.093    AVAST engine scan C:\WINDOWS\system32\drivers
12:45:50.034    Disk 0 MBR has been saved successfully to "C:\Profile\Administrator\Desktop\MBR.dat"
12:45:50.034    The log file has been saved successfully to "C:\Profile\Administrator\Desktop\aswMBR.txt"
12:45:50.675    AVAST engine scan C:\Profile\Administrator
12:48:41.585    AVAST engine scan C:\Profile\All Users
12:49:36.462    Scan finished successfully
12:50:34.432    Disk 0 MBR has been saved successfully to "C:\Profile\Administrator\Desktop\MBR.dat"
12:50:34.432    The log file has been saved successfully to "C:\Profile\Administrator\Desktop\aswMBR.txt"


cosinus 16.07.2012 16:23

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

mot2001 17.07.2012 10:33

hier also das Logfile von SuperAntiSpyware:

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 07/17/2012 at 11:26 AM

Application Version : 5.5.1006

Core Rules Database Version : 8910
Trace Rules Database Version: 6722

Scan type      : Complete Scan
Total Scan Time : 00:59:41

Operating System Information
Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator

Memory items scanned      : 618
Memory threats detected  : 0
Registry items scanned    : 34472
Registry threats detected : 0
File items scanned        : 48823
File threats detected    : 136

Adware.Tracking Cookie
        C:\Profile\Administrator\Cookies\5TEU640F.txt [ /atdmt.com ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@www.zanox-affiliate[2].txt [ Cookie:shksrab@www.zanox-affiliate.de/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@axelspringer.122.2o7[1].txt [ Cookie:shksrab@axelspringer.122.2o7.net/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@tradedoubler[1].txt [ Cookie:shksrab@tradedoubler.com/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@de2.komtrack[2].txt [ Cookie:shksrab@de2.komtrack.com/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@advertising[2].txt [ Cookie:shksrab@advertising.com/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@track.webtrekk[2].txt [ Cookie:shksrab@track.webtrekk.net/523478367474333/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@bs.serving-sys[2].txt [ Cookie:shksrab@bs.serving-sys.com/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@adserver.konradin[2].txt [ Cookie:shksrab@adserver.konradin.de/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@doubleclick[2].txt [ Cookie:shksrab@doubleclick.net/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@komtrack[2].txt [ Cookie:shksrab@komtrack.com/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@track.webtrekk[1].txt [ Cookie:shksrab@track.webtrekk.de/511731243725473/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@adfarm1.adition[1].txt [ Cookie:shksrab@adfarm1.adition.com/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@revsci[1].txt [ Cookie:shksrab@revsci.net/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@tracknet.twyn[2].txt [ Cookie:shksrab@tracknet.twyn.com/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@adtech[1].txt [ Cookie:shksrab@adtech.de/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@serving-sys[1].txt [ Cookie:shksrab@serving-sys.com/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@tacoda[2].txt [ Cookie:shksrab@tacoda.net/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@mediaplex[1].txt [ Cookie:shksrab@mediaplex.com/ ]
        C:\PROFILE\SHKSRAB\Cookies\shksrab@specificclick[2].txt [ Cookie:shksrab@specificclick.net/ ]
        .imrworldwide.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\PROFILE\ADMINISTRATOR\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\L3SRTXIJ.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .mswmw7mobilemainprod.122.2o7.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\PROFILE\DOEHLERM\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ALDE08OS.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\PROFILE\HENRIK HILDEBRANDT\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\90MFRKFW.DEFAULT\COOKIES.TXT ]
        ad.yieldmanager.com [ C:\PROFILE\HENRIK HILDEBRANDT\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\90MFRKFW.DEFAULT\COOKIES.TXT ]
        ad.yieldmanager.com [ C:\PROFILE\HENRIK HILDEBRANDT\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\90MFRKFW.DEFAULT\COOKIES.TXT ]
        ad.yieldmanager.com [ C:\PROFILE\HENRIK HILDEBRANDT\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\90MFRKFW.DEFAULT\COOKIES.TXT ]
        ad.yieldmanager.com [ C:\PROFILE\HENRIK HILDEBRANDT\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\90MFRKFW.DEFAULT\COOKIES.TXT ]
        ad.yieldmanager.com [ C:\PROFILE\HENRIK HILDEBRANDT\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\90MFRKFW.DEFAULT\COOKIES.TXT ]
        .xiti.com [ C:\PROFILE\HILDEBRH\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ORAEWH4F.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\PROFILE\HILDEBRH\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ORAEWH4F.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\PROFILE\HILDEBRH\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ORAEWH4F.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\PROFILE\HILDEBRH\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ORAEWH4F.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\PROFILE\HILDEBRH\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ORAEWH4F.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\PROFILE\HILDEBRH\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ORAEWH4F.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\PROFILE\HILDEBRH\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ORAEWH4F.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\PROFILE\HILDEBRH\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\ORAEWH4F.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\PROFILE\MDA\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\PZN9IAGI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\PROFILE\MDA\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\PZN9IAGI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\PROFILE\MDA\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\PZN9IAGI.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\PROFILE\MDA\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\PZN9IAGI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\PROFILE\RACKTEUA\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\JO9PPSXT.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\PROFILE\RACKTEUA\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\JO9PPSXT.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\PROFILE\RACKTEUA\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\JO9PPSXT.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\PROFILE\RACKTEUA\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\JO9PPSXT.DEFAULT\COOKIES.SQLITE ]


und von vom Antimalwarebyte:

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.07.17.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Administrator :: THEO99 [Administrator]

17.07.2012 09:16:25
mbam-log-2012-07-17 (10-21-28).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 482514
Laufzeit: 1 Stunde(n), 3 Minute(n), 53 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Daten: 1 -> Keine Aktion durchgeführt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 17.07.2012 15:19

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

mot2001 17.07.2012 15:32

nun moechte ich mich bei Dir erst mal herzlich bedanken fuer Deine umfangreiche Arbeit!!!

Kannst Du mir noch etwas zu dem Fund 'infizierte Registrierungswerte' in amwb sagen?
Und noch eine Frage: Kann man eine Aussage treffen ueber die Herkunft der Virenfunde, also Ursprung bspw. Internet (MailClient, Webrowser) USB-LW?
Wir sind uns nicht klar, wie wir uns den Virus eingefangen hatten.

cosinus 18.07.2012 15:04

Code:

Infizierte Registrierungswerte: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|ForceClassicControlPanel (Hijack.ControlPanelStyle

Einfach mal nach ForceClassicControlPanel googlen, dann solltest du es selber schon sehen :pfeiff:

Wo genau die Schädlinge herkamen kann ich doch nicht sagen! Es gibt verschiedene Verbreitungswege und diese müssen alle von dir abgedichtet werden! :kloppen:

Halte Dich am besten grob an diese Regeln:
  1. Sei misstrauisch im Internet und v.a. bei unbekannten E-Mails, sei vorsichtig bei der Herausgabe persönlicher Daten!!
  2. Halte Windows und alle verwendeten Programme immer aktuell - unterstützen kann dich dabei Secunia PSI
  3. Führe regelmäßig Backups auf externe Medien durch
  4. Arbeite mit eingeschränkten Rechten
  5. Nutze sicherere Programme wie zB Opera oder Firefox zum Surfen statt den IE, zum Mailen Thunderbird statt Outlook Express - E-Mails nur als reinen text anzeigen lassen
  6. automatische Wiedergabe von allen Laufwerken komplett deaktivieren, denn das ist ein unnötiges Sicherheitsrisiko
  7. Bei der Installation von Software möglichst darauf achten, dass die Setups aus offiziellen Quellen stammen und du bei der Installation nach Möglichkeit die benutzerdefinierte Methode wählst - dann hast du die Möglichkeit etwaigen Schrott (wie Toolbars oder sowas wie RegistryBooster) abzuwählen, welcher sonst einfach mitinstalliert wird.
  8. Bösartige bzw. ungewollte Sites von vornherein blockieren lassen mit Hilfe der MVPS Hosts File => Blocking Unwanted Parasites with a Hosts File
  9. Finger weg von: TuneUp, Registry-Cleanern aller Art, Softonic sowie illegalen Cracks/Keygens oder anderen "Tools" um ein kommerzielles Programm ohne Lizenz nutzen zu können
  10. dubiose Seiten bzw. Kinofilm-Streaming-Portale ebenfalls sein lassen, erstens handelt man sich dort schnell Malware ein oder kann in Abofallen geraten und zweitens bewegen sich diese Seiten in einer rechtlichen Grauzone.


Alles noch genauer erklärt steht hier => Kompromittierung unvermeidbar?


Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

mot2001 18.07.2012 15:22

nochmals besten Dank fuer Deine umfangreich Unterstuetzung! An Deinen abschliessenden Hinweisen werden wir uns orientieren.


Alle Zeitangaben in WEZ +1. Es ist jetzt 03:15 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131