Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   BKA Trojaner 1.15 (Windows Vista) (https://www.trojaner-board.de/124691-bka-trojaner-1-15-windows-vista.html)

boris1 25.09.2012 19:56

BKA Trojaner 1.15 (Windows Vista)
 
Hallo,

ich habe den Laptop eines Bekannten hier der mit dem BKA Trojaner infiziert ist. Es handelt sich lt. bka-trojaner.de um die Version 1.15.

Hier das Logfile von Malwarebytes:

Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.07.13

Windows Vista Service Pack 2 x86 FAT32 (Abgesichertenmodus)
Internet Explorer 8.0.6001.19328
xxx :: xxx-PC [Administrator]

Schutz: Deaktiviert

25.09.2012 19:40:29
mbam-log-2012-09-25 (20-50-23).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 386843
Laufzeit: 1 Stunde(n), 9 Minute(n), 35 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 1
C:\Users\xxx\AppData\Roaming\hellomoto (Trojan.Ransom.FGen) -> Keine Aktion durchgeführt.

Infizierte Dateien: 2
C:\Users\xxx\AppData\Roaming\hellomoto\TujP.dat (Trojan.Ransom.FGen) -> Keine Aktion durchgeführt.
C:\Users\xxx\AppData\Roaming\hellomoto\BukF.dat (Trojan.Ransom.FGen) -> Keine Aktion durchgeführt.

(Ende)



:dankeschoen:



edit, gerade gelesen das OTL hier gefragt ist, download läuft und logfile wird nachgeliefert.

Jetzt hab ich eventuell Mist gemacht. Ich bin bei Malewarebytes auf entfernen gegangen ( in der Annahme ich kann noch was in Quarantäne verschieben) und dann passierte nix mehr. Jetzt kann ich den Laptop normal starten, das BKA Fenster kommt nicht mehr. Dafür hab ich nun eine Eieruhr laufen und kann keine Programme starten.

cosinus 26.09.2012 09:38

Funktioniert noch der abgesicherte Modus mit Netzwerktreibern? Mit Internetverbindung?



Abgesicherter Modus zur Bereinigung
  • Windows mit F8-Taste beim Start in den abgesicherten Modus bringen.
  • Starte den Rechner in den abgesicherten Modus mit Netzwerktreibern:

    Windows im abgesicherten Modusstarten

boris1 26.09.2012 18:36

Ja, das klappt.
Habe Malwarebytes aktualisiert und lasse es noch einmal laufen.

Hier nochmal die aktuellen Logfiles:

Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.26.09

Windows Vista Service Pack 2 x86 FAT32 (Abgesichertenmodus/Netzwerkfähig)
Internet Explorer 8.0.6001.19328
matthes :: xxx-PC [Administrator]

Schutz: Deaktiviert

26.09.2012 19:35:37
mbam-log-2012-09-26 (20-47-00).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 388690
Laufzeit: 1 Stunde(n), 10 Minute(n), 13 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 4
C:\ACER\Preload\Autorun\APP\BioProtection_Upek\Install\doc\FingerprintTutorial.exe (Trojan.Spatet) -> Keine Aktion durchgeführt.
C:\ACER\Preload\Autorun\APP\BioProtection_Upek\Install\doc\SystemWizard.exe (Trojan.Spatet) -> Keine Aktion durchgeführt.
C:\Program Files\Acer\Acer Bio Protection\FingerprintTutorial.exe (Trojan.Spatet) -> Keine Aktion durchgeführt.
C:\Program Files\Acer\Acer Bio Protection\SystemWizard.exe (Trojan.Spatet) -> Keine Aktion durchgeführt.

(Ende)

Code:

OTL logfile created on: 26.09.2012 20:54:52 - Run 1
OTL by OldTimer - Version 3.2.68.0    Folder = C:\Users\xxx\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19328)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,99 Gb Total Physical Memory | 2,41 Gb Available Physical Memory | 80,46% Memory free
6,19 Gb Paging File | 5,82 Gb Available in Paging File | 94,11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 78,05 Gb Total Space | 31,46 Gb Free Space | 40,31% Space Free | Partition Type: NTFS
Drive D: | 106,50 Gb Total Space | 42,43 Gb Free Space | 39,85% Space Free | Partition Type: NTFS
Drive E: | 99,99 Gb Total Space | 72,43 Gb Free Space | 72,43% Space Free | Partition Type: NTFS
Drive G: | 7,52 Gb Total Space | 7,42 Gb Free Space | 98,72% Space Free | Partition Type: FAT32
 
Computer Name: xxx-PC | User Name: xxx | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\matthes\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
 
 
========== Services (SafeList) ==========
 
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (N360) -- C:\Program Files\Norton 360\Engine\6.3.0.14\ccSvcHst.exe (Symantec Corporation)
SRV - (TeamViewer7) -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (Polar Daemon) -- C:\Program Files\Polar\Daemon\polard.exe ()
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (lxea_device) -- C:\Windows\System32\lxeacoms.exe ( )
SRV - (lxeaCATSCustConnectService) -- C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxeaserv.exe ()
SRV - (ACDaemon) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (Fabs) -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (IGBASVC) -- C:\Program Files\Acer\Acer Bio Protection\BASVC.exe ()
SRV - (EvtEng) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV - (RegSrvc) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (IAANTMON) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (CLHNService) -- C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
 
 
========== Driver Services (SafeList) ==========
 
DRV - (SYMNDISV) -- C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS File not found
DRV - (SYMFW) -- C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (DKbFltr) -- system32\DRIVERS\DKbFltr.sys File not found
DRV - (cpuz132) -- C:\Users\xxx\AppData\Local\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120922.008\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120922.008\NAVENG.SYS (Symantec Corporation)
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (IDSVix86) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\IPSDefs\20120921.001\IDSvix86.sys (Symantec Corporation)
DRV - (BHDrvx86) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\BASHDefs\20120919.001\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SRTSP) -- C:\Windows\System32\drivers\N360\0603000.00E\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) -- C:\Windows\System32\drivers\N360\0603000.00E\srtspx.sys (Symantec Corporation)
DRV - (ccSet_N360) -- C:\Windows\System32\drivers\N360\0603000.00E\ccsetx86.sys (Symantec Corporation)
DRV - (SymEFA) -- C:\Windows\System32\drivers\N360\0603000.00E\symefa.sys (Symantec Corporation)
DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDIv) -- C:\Windows\System32\drivers\N360\0603000.00E\symtdiv.sys (Symantec Corporation)
DRV - (SymDS) -- C:\Windows\System32\drivers\N360\0603000.00E\symds.sys (Symantec Corporation)
DRV - (SymIRON) -- C:\Windows\System32\drivers\N360\0603000.00E\ironx86.sys (Symantec Corporation)
DRV - (L1E) -- C:\Windows\System32\drivers\L1E60x86.sys (Atheros Communications, Inc.)
DRV - (winusb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (hotcore3) -- C:\Windows\System32\drivers\hotcore3.sys (Paragon Software Group)
DRV - (NETw5v32) -- C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (AlfaFF) -- C:\Windows\System32\drivers\AlfaFF.sys (Alfa Corporation)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) -- C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl (Cyberlink Corp.)
DRV - (Uim_IM) -- C:\Windows\System32\drivers\Uim_IM.sys (Paragon Software Group)
DRV - (UimBus) -- C:\Windows\System32\drivers\UimBus.sys (Paragon Software Group)
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (WSDPrintDevice) -- C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (NTIPPKernel) -- C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys (Cyberlink Corp.)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (winbondcir) -- C:\Windows\System32\drivers\winbondcir.sys (Winbond Electronics Corporation)
DRV - (Afc) -- C:\Windows\System32\drivers\afc.sys (Arcsoft, Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=IEAUTOBR
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://isearch.avg.com/?cid={6376A146-BED6-45C9-A8A3-2130C08AD332}&mid=16301b71c18b47d09a43d16acde5e2c2-cec7e7c3b131d31bd22a47617a9612cba7920b81&lang=de&ds=tt014&pr=sa&d=2012-07-16 21:06:35&v=11.1.0.12&sap=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - No CLSID value found
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = hxxp://isearch.avg.com/search?cid={6376A146-BED6-45C9-A8A3-2130C08AD332}&mid=16301b71c18b47d09a43d16acde5e2c2-cec7e7c3b131d31bd22a47617a9612cba7920b81&lang=de&ds=tt014&pr=sa&d=2012-07-16 21:06:35&v=11.1.0.12&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = hxxp://int.search-results.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=360&chn=retail&geo=DE&ver=5
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=IEAUTOBR
IE - HKCU\..\SearchScopes\{DA0F6B44-AEEB-40C9-8514-D8063D84A2C1}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=DVS2&o=1586&src=crm&q={searchTerms}&locale=&apn_ptnrs=^AAA&apn_dtid=^YYYYYY^YY^DE&apn_uid=67ba21ef-ec03-4c49-86d9-720a894a458f&apn_sauid=B3132688-519A-47DD-8AEC-5953DFB835ED
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "search for firefox"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p="
FF - prefs.js..browser.search.order.1: "search for firefox"
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "search for firefox"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: addon@gutscheine-live.de:1.1
FF - prefs.js..extensions.enabledAddons: finder@meingutscheincode.de:3.0.3
FF - prefs.js..extensions.enabledAddons: ciuvo-extension@billiger.de:1.0.462
FF - prefs.js..extensions.enabledAddons: {b677fa16-ac2f-410c-8ea5-3bc98ed515d3}:1.2
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.1.5 - 1
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2012.7.5.2
FF - prefs.js..extensions.enabledItems: {b677fa16-ac2f-410c-8ea5-3bc98ed515d3}:1.2
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.11.2
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..keyword.URL: "hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
FF - prefs.js..network.proxy.type: 0
 
FF - user.js..keyword.URL: "hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
FF - user.js..browser.search.selectedEngine: "search for firefox"
FF - user.js..browser.search.order.1: "search for firefox"
FF - user.js..browser.search.defaultenginename: "search for firefox"
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@erdas.com/ERDAS Image Web Server ECW JPEG2000 Plugin,version=9.3: C:\Program Files\ERDAS\Image Web Server\Firefox Plug-in\NP_NCS6.dll (ERDAS)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\IPSFFPlgn\ [2012.05.04 11:17:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\coFFPlgn\ [2012.09.26 18:54:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.11 11:03:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.08.20 10:06:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.08.23 13:20:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.11 11:03:14 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.08.20 10:06:56 | 000,000,000 | ---D | M]
 
[2010.10.01 16:06:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\Extensions
[2010.10.01 16:06:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.09.13 10:30:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\Firefox\Profiles\38gpdnax.default\extensions
[2012.08.21 21:04:08 | 000,000,000 | ---D | M] (DVDVideoSoftTB) -- C:\Users\matthes\AppData\Roaming\mozilla\Firefox\Profiles\38gpdnax.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012.09.13 10:30:04 | 000,000,000 | ---D | M] (FoxLingo) -- C:\Users\matthes\AppData\Roaming\mozilla\Firefox\Profiles\38gpdnax.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2012.03.19 10:21:11 | 000,004,270 | ---- | M] () (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\extensions\addon@gutscheine-live.de.xpi
[2012.08.30 02:12:30 | 000,088,614 | ---- | M] () (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\extensions\extension@ciuvo.com.xpi
[2011.10.02 09:30:46 | 000,105,020 | ---- | M] () (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\extensions\finder@meingutscheincode.de.xpi
[2012.07.26 10:28:38 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011.08.02 17:39:53 | 000,002,399 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\searchplugins\askcom.xml
[2011.05.12 11:25:21 | 000,002,448 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\searchplugins\safesearch.xml
[2009.12.18 22:01:14 | 000,001,201 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\searchplugins\winamp-search.xml
[2012.06.18 12:42:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010.01.27 20:03:47 | 000,000,000 | ---D | M] (Adobe Reader) -- C:\Program Files\Mozilla Firefox\extensions\{b677fa16-ac2f-410c-8ea5-3bc98ed515d3}
[2011.05.25 22:24:53 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:creator="billiger.de Sparberater" em:homepageURL="hxxp://sparberater.billiger.de" em:iconURL="chrome://ciuvo/content/icons/billigerde/ciuvo_icon.png" em:id="ciuvo-extension@billiger.de" em:name="billiger.de Sparberater" em:optionsURL="" em:type="2" em:updateKey="MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDBHgpsx79ZmWK5YY6tA/iPgCxyzLL2SpWEBcJgQYa2qsiay+akqFqG0hr0TyGQOzkEnoRUkysljyzTHIUYXS3V7yorR7CN9+Vv/xC5RbSesfs8DOukKHWNQPrL57OvLzJIMrl86HLcKBiPZAQ4sAoITuYGnsr6CY3fZxYKTGNS/wIDAQAB" em:updateURL="hxxp://ciuvo.com/ciuvo/update?id=%ITEM_ID%&version=%ITEM_VERSION%&maxversion=%ITEM_MAXAPPVERSION%&status=%ITEM_STATUS%&app_id=%APP_ID%&app_version=%APP_VERSION%&os=%APP_OS%&locale=%APP_LOCALE%&tag=billigerde" em:version="1.0.462">) -- C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de
[2011.05.25 22:24:53 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de\chrome
[2012.09.26 18:54:10 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\COFFPLGN
[2012.05.04 11:17:19 | 000,000,000 | ---D | M] (Norton Vulnerability Protection) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\IPSFFPLGN
[2009.09.17 15:42:23 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012.09.11 11:03:14 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008.06.30 14:44:08 | 000,324,976 | ---- | M] (Symantec Corporation) -- C:\Program Files\mozilla firefox\components\coFFPlgn.dll
[2012.03.16 17:39:29 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.12.09 19:23:32 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012.06.15 00:46:57 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.07.16 21:06:28 | 000,003,750 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012.09.11 11:03:12 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.15 00:46:57 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.15 00:46:57 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.15 00:46:57 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.15 00:46:56 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Lexmark Symbolleiste) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Adobe Reader) - {147FEC3F-6DE9-437C-8FC1-6B8A20AA0A72} - C:\Users\matthes\AppData\Roaming\AdobeReader\IE\AdobeReader.dll (Adobe Systems, Incorporated)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\6.3.0.14\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\6.3.0.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (billiger.de Sparberater) - {92A6EE5B-5AE3-4159-9134-938BCA95B753} - C:\Program Files\billigerde\Internet Explorer\billigerde.dll (solute gmbh)
O2 - BHO: (Lexmark ) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Lexmark Symbolleiste) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.3.0.14\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Lexmark Symbolleiste) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Lexmark Symbolleiste) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.3.0.14\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [lxeamon.exe] C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe (Acer Incorporated)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SearchIndexer] C:\Users\matthes\AppData\Local\Microsoft\Windows\89\SearchIndexer.exe ()
O4 - Startup: C:\Users\matthes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe ()
O9 - Extra 'Tools' menuitem : Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe ()
O9 - Extra Button: Amazon (amazon.de) - {603D3CE5-33BC-4d51-A31E-613A2B826E21} - C:\Users\matthes\AppData\Roaming\IEButtons\toolbutton2.js ()
O9 - Extra Button: easy Shopping - {804420A5-7F05-4ee9-92F2-D2B644AD9102} - C:\Users\matthes\AppData\Roaming\IEButtons\toolbutton3.js ()
O9 - Extra Button: eBay (ebay.de) - {C376BD23-6DC3-4e10-9ED0-AB8C0444E45C} - C:\Users\matthes\AppData\Roaming\IEButtons\toolbutton1.js ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.5.1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{463FB10B-4FC8-44CD-824A-096C81AA3247}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AWinNotifyVitaKey MC3000: DllName - (C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll) - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll (Arachnoid Biometrics Identification Group Corp.)
O20 - Winlogon\Notify\spba: DllName - (C:\Program Files\Common Files\SPBA\homefus2.dll) - C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
O24 - Desktop WallPaper: C:\Users\matthes\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\matthes\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{fc6e75ed-8782-11df-84a4-00238b010b31}\Shell\AutoRun\command - "" = Menu.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.26 20:53:40 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\matthes\Desktop\OTL(1).exe
[2012.09.26 20:53:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\matthes\Desktop\OTL.exe
[2012.09.25 21:59:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.09.25 21:59:22 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.09.25 19:36:28 | 000,000,000 | ---D | C] -- C:\Users\matthes\AppData\Roaming\Malwarebytes
[2012.09.25 19:36:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.09.25 19:36:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.09.25 19:36:11 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.25 19:36:11 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.09.22 10:46:29 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.09.22 10:46:29 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.09.22 10:46:27 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.09.22 10:46:27 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012.09.22 10:46:27 | 000,630,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012.09.22 10:46:27 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2012.09.22 10:46:27 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2012.09.22 10:46:27 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2012.09.22 10:46:27 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2012.09.22 10:46:27 | 000,174,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2012.09.22 10:46:27 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.09.22 10:46:27 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.09.22 10:46:27 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2012.09.22 10:46:27 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2012.09.22 10:46:27 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2012.09.22 10:46:27 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2012.09.22 10:46:27 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2012.09.22 10:46:27 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2012.09.17 19:15:46 | 000,000,000 | ---D | C] -- C:\Users\matthes\Ordnerdeckblätter
[2012.09.17 18:44:38 | 000,000,000 | ---D | C] -- C:\Users\matthes\Desktop\Arleen Fotoalbum
[2012.09.11 14:27:34 | 000,000,000 | ---D | C] -- C:\Windows\System32\Samsung_USB_Drivers
[2010.03.07 11:45:51 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\matthes\AppData\Roaming\pcouffin.sys
[2004.07.09 05:08:36 | 000,472,576 | ---- | C] (Microsoft Corporation) -- C:\Program Files\dxsetup.exe
[2004.07.09 05:08:34 | 002,242,560 | ---- | C] (Microsoft Corporation) -- C:\Program Files\dsetup32.dll
[2004.07.09 04:03:10 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Program Files\DSETUP.dll
[10 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[10 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.26 20:53:42 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\matthes\Desktop\OTL(1).exe
[2012.09.26 20:53:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\matthes\Desktop\OTL.exe
[2012.09.26 20:49:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.26 19:02:59 | 000,004,096 | ---- | M] () -- C:\ProgramData\nvModes.001
[2012.09.26 19:02:39 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.09.26 19:02:22 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.26 19:02:21 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.25 21:59:22 | 000,000,773 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.09.25 21:50:00 | 000,000,422 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{52A60082-F11F-4DC0-815C-41B71B2E7AD3}.job
[2012.09.25 19:36:13 | 000,000,875 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.25 19:35:40 | 000,041,984 | ---- | M] () -- C:\Users\matthes\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.25 19:34:52 | 000,627,756 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.09.25 19:34:52 | 000,595,386 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.09.25 19:34:52 | 000,125,870 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.09.25 19:34:52 | 000,103,460 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.09.25 18:46:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.23 23:05:23 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.09.23 15:35:00 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.09.20 19:49:59 | 000,696,240 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.09.20 19:49:59 | 000,073,136 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.09.18 14:29:30 | 000,001,154 | ---- | M] () -- C:\Users\matthes\Desktop\OpenOffice.org 3.3 - Verknüpfung.lnk
[2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.08.30 01:06:05 | 000,000,032 | ---- | M] () -- C:\Windows\Menu.INI
[10 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[10 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.09.25 21:59:22 | 000,000,773 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.09.25 19:36:13 | 000,000,875 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.18 14:29:30 | 000,001,154 | ---- | C] () -- C:\Users\matthes\Desktop\OpenOffice.org 3.3 - Verknüpfung.lnk
[2012.08.22 21:58:24 | 000,022,079 | ---- | C] () -- C:\Users\matthes\EPlus Kündigung 2.odt
[2012.08.21 13:48:01 | 000,047,179 | ---- | C] () -- C:\Users\matthes\Urlaub Malle.odt
[2012.06.25 15:20:17 | 000,061,243 | ---- | C] () -- C:\Users\matthes\2012-06-22 01 12 37.jpg
[2012.01.09 22:36:41 | 000,323,584 | ---- | C] () -- C:\Windows\System32\lxeains.dll
[2012.01.09 22:36:41 | 000,262,144 | ---- | C] () -- C:\Windows\System32\lxeainsb.dll
[2012.01.09 22:36:40 | 000,294,912 | ---- | C] () -- C:\Windows\System32\lxeacui.dll
[2012.01.09 22:36:40 | 000,253,952 | ---- | C] () -- C:\Windows\System32\lxeacu.dll
[2012.01.09 22:36:40 | 000,110,592 | ---- | C] () -- C:\Windows\System32\lxeacuir.dll
[2012.01.09 22:36:40 | 000,086,016 | ---- | C] () -- C:\Windows\System32\lxeagcfg.dll
[2012.01.09 20:20:57 | 000,000,044 | -H-- | C] () -- C:\Windows\System32\lxearwrd.ini
[2012.01.09 20:20:41 | 000,364,544 | ---- | C] ( ) -- C:\Windows\System32\lxeainpa.dll
[2012.01.09 20:20:41 | 000,356,352 | ---- | C] ( ) -- C:\Windows\System32\LXEAhcp.dll
[2012.01.09 20:20:41 | 000,344,064 | ---- | C] ( ) -- C:\Windows\System32\lxeaiesc.dll
[2012.01.09 20:20:41 | 000,331,776 | ---- | C] () -- C:\Windows\System32\LXEAinst.dll
[2012.01.09 20:20:40 | 001,048,576 | ---- | C] ( ) -- C:\Windows\System32\lxeaserv.dll
[2012.01.09 20:20:40 | 000,847,872 | ---- | C] ( ) -- C:\Windows\System32\lxeausb1.dll
[2012.01.09 20:20:40 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxeapmui.dll
[2012.01.09 20:20:39 | 000,577,536 | ---- | C] ( ) -- C:\Windows\System32\lxealmpm.dll
[2012.01.09 20:20:39 | 000,114,688 | ---- | C] () -- C:\Windows\System32\lxeainsr.dll
[2012.01.09 20:20:39 | 000,057,344 | ---- | C] () -- C:\Windows\System32\lxeajswr.dll
[2012.01.09 20:20:38 | 000,688,128 | ---- | C] ( ) -- C:\Windows\System32\lxeahbn3.dll
[2012.01.09 20:20:38 | 000,324,264 | ---- | C] ( ) -- C:\Windows\System32\lxeaih.exe
[2012.01.09 20:20:38 | 000,208,896 | ---- | C] () -- C:\Windows\System32\lxeagrd.dll
[2012.01.09 20:20:38 | 000,090,112 | ---- | C] () -- C:\Windows\System32\lxeacub.dll
[2012.01.09 20:20:38 | 000,036,864 | ---- | C] () -- C:\Windows\System32\lxeacur.dll
[2012.01.09 20:20:37 | 000,802,816 | ---- | C] ( ) -- C:\Windows\System32\lxeacomc.dll
[2012.01.09 20:20:37 | 000,598,696 | ---- | C] ( ) -- C:\Windows\System32\lxeacoms.exe
[2012.01.09 20:20:37 | 000,373,416 | ---- | C] ( ) -- C:\Windows\System32\lxeacfg.exe
[2012.01.09 20:20:37 | 000,372,736 | ---- | C] ( ) -- C:\Windows\System32\lxeacomm.dll
[2011.11.29 11:34:28 | 000,000,000 | ---- | C] () -- C:\Users\matthes\AppData\Local\{977B9521-6D44-4719-ABEB-E5DFE92018C3}
[2011.07.31 16:08:52 | 000,000,055 | ---- | C] () -- C:\Windows\ClonyDrives.ini
[2011.07.31 16:06:38 | 000,000,340 | ---- | C] () -- C:\Windows\Clony2.ini
[2011.07.28 16:44:43 | 000,000,034 | ---- | C] () -- C:\Windows\cdplayer.ini
[2011.05.05 12:49:35 | 000,000,000 | ---- | C] () -- C:\Users\matthes\AppData\Local\{35FDC0F4-068D-4B3D-BD33-81A24E62D79E}
[2011.03.16 14:10:42 | 000,000,046 | ---- | C] () -- C:\ProgramData\.SimImages
[2011.01.24 20:08:48 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011.01.24 20:08:48 | 000,042,112 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2011.01.07 23:27:17 | 000,000,032 | ---- | C] () -- C:\Windows\Menu.INI
[2011.01.04 17:10:56 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2011.01.04 17:10:56 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2011.01.04 17:10:56 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2011.01.04 17:10:56 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2010.08.10 18:52:12 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010.03.07 11:45:51 | 000,087,608 | ---- | C] () -- C:\Users\matthes\AppData\Roaming\inst.exe
[2010.03.07 11:45:51 | 000,007,887 | ---- | C] () -- C:\Users\matthes\AppData\Roaming\pcouffin.cat
[2010.03.07 11:45:51 | 000,001,144 | ---- | C] () -- C:\Users\matthes\AppData\Roaming\pcouffin.inf
[2009.09.19 17:35:42 | 000,007,592 | ---- | C] () -- C:\Users\matthes\AppData\Local\d3d9caps.dat
[2008.12.25 21:39:02 | 000,041,984 | ---- | C] () -- C:\Users\matthes\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.12.25 08:45:38 | 000,004,096 | ---- | C] () -- C:\ProgramData\nvModes.001
[2008.12.25 08:27:04 | 000,068,105 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2004.07.22 11:51:34 | 003,432,656 | ---- | C] () -- C:\Program Files\ManagedDX.CAB
[2004.07.19 23:58:36 | 001,156,363 | ---- | C] () -- C:\Program Files\BDANT.cab
[2004.07.19 23:53:26 | 000,976,020 | ---- | C] () -- C:\Program Files\BDAXP.cab
[2004.07.09 15:17:16 | 013,265,040 | ---- | C] () -- C:\Program Files\dxnt.cab
[2004.07.09 10:13:48 | 015,493,481 | ---- | C] () -- C:\Program Files\DirectX.cab
[2004.07.09 10:13:46 | 000,703,080 | ---- | C] () -- C:\Program Files\BDA.cab
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >

Code:

OTL Extras logfile created on: 26.09.2012 20:54:52 - Run 1
OTL by OldTimer - Version 3.2.68.0    Folder = C:\Users\matthes\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19328)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,99 Gb Total Physical Memory | 2,41 Gb Available Physical Memory | 80,46% Memory free
6,19 Gb Paging File | 5,82 Gb Available in Paging File | 94,11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 78,05 Gb Total Space | 31,46 Gb Free Space | 40,31% Space Free | Partition Type: NTFS
Drive D: | 106,50 Gb Total Space | 42,43 Gb Free Space | 39,85% Space Free | Partition Type: NTFS
Drive E: | 99,99 Gb Total Space | 72,43 Gb Free Space | 72,43% Space Free | Partition Type: NTFS
Drive G: | 7,52 Gb Total Space | 7,42 Gb Free Space | 98,72% Space Free | Partition Type: FAT32
 
Computer Name: MATTHES-PC | User Name: matthes | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AntiVirusDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-1437981379-4010485698-1217947183-1000]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{037A1C7B-F629-4C92-8EC6-94CD3E800FCA}" = lport=445 | protocol=6 | dir=in | app=system |
"{4E4D09C7-551D-4E57-94D7-1A8D53FB5CB1}" = lport=137 | protocol=17 | dir=in | app=system |
"{5A14045D-14F0-495F-9121-AB0FBAC90D5B}" = rport=138 | protocol=17 | dir=out | app=system |
"{728C2F4B-1813-4D6E-80C6-7A4AC0D9A690}" = rport=137 | protocol=17 | dir=out | app=system |
"{7A3D5800-2A75-4A74-A3A8-8F2E2DB057F8}" = lport=138 | protocol=17 | dir=in | app=system |
"{8C8B6DFC-DC74-4DC5-AA03-23D2247635A6}" = lport=139 | protocol=6 | dir=in | app=system |
"{8E7B148D-FEC9-4AA2-9AA4-9363B6B00D95}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{D7C46CF9-39A0-4086-9A76-3FD050F43B7A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{DB79A1DD-6A73-4929-B37F-C81006570247}" = rport=445 | protocol=6 | dir=out | app=system |
"{DD49CB44-61CF-495A-A8FA-C15286F97299}" = rport=139 | protocol=6 | dir=out | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0985FB0F-B2F5-421A-BBE8-B431D50DB4B7}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
"{0B28F639-1B5F-4FE6-9E67-CA0C7A84E763}" = protocol=6 | dir=in | app=c:\windows\system32\lxeacoms.exe |
"{0DA38D6E-6AAF-4C91-9579-7B27B68ED5F9}" = protocol=6 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{13417092-6D48-44C8-AD5A-B3F4F62BBBB4}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version7\teamviewer_service.exe |
"{138A9CC8-F959-4021-BDED-CE172C7997B5}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
"{146B7FD1-33A7-4DDD-9918-F58D13CB06D7}" = protocol=17 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{1AA00725-A13C-4EEE-BC22-B586A94CD2F6}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\playmovie.exe |
"{270267C3-1FA7-4E64-986D-709D0F9DA88E}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version7\teamviewer.exe |
"{2F18F945-87DC-4E4B-85F3-E754745EF576}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\pmvservice.exe |
"{3179652A-6F14-473A-A39F-1221F8D7C2CD}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
"{3181C907-22CC-4C0D-9D49-1EA9F13C546D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{32726939-FBBD-4C56-A59D-500B223762B4}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe |
"{3EBCC6BE-F171-4DDA-AB2C-1C2066F58622}" = protocol=6 | dir=in | app=c:\windows\system32\muzapp.exe |
"{47C258A6-99EB-4ECD-AFB4-75D27AEFE409}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{48FEAC56-F606-4827-BB12-B3BE74E96492}" = protocol=17 | dir=in | app=c:\windows\system32\muzapp.exe |
"{4EBACC8C-A158-4F00-8B74-681982E8459F}" = protocol=6 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{6CB5E4B7-B839-4249-A2B2-E839C3A5BA9F}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe |
"{7D67D26C-5B33-4CB0-A8ED-FFAE8E85C379}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
"{8936421D-E889-46B7-BC85-798E75310000}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
"{9F9E36B6-DCC4-490C-8B1B-B1125B40C33E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{A767232F-AC31-4BB3-8C6D-B723C3A62C52}" = protocol=17 | dir=in | app=c:\windows\system32\lxeacoms.exe |
"{AA3FB272-8D2A-4659-96EE-F92D6CA58432}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version7\teamviewer_service.exe |
"{BFE975F9-6202-42D6-91F1-85AB3D3EEBB0}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
"{C0FBB0EB-DEC6-40FC-8C59-6E5864DD81E5}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
"{C644E89B-AAC2-46A0-BE4E-2F2ED8793724}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
"{CBF0F9DB-B155-4D9A-BB6A-2B75B9AE5EBB}" = protocol=17 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{DAF8073A-BC97-4D25-A500-65A6C0E3E13A}" = protocol=17 | dir=in | app=c:\windows\system32\muzapp.exe |
"{E4234823-B34F-4A5B-B784-B19B8D21FA75}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F5E669CA-548F-4A5E-B2A0-1502F2ACB386}" = protocol=6 | dir=in | app=c:\windows\system32\muzapp.exe |
"{F8AA535A-D084-4DC4-AA63-42BEA0564876}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version7\teamviewer.exe |
"{FD8E1353-A21A-42C8-BFD3-F20B6ED78B05}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{FE396E4B-2380-43B7-9646-F58B8975095E}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.6400
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Symbolleiste
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{18472E28-FCA0-421F-BDAC-AC65012E29F2}" = ArcSoft MediaImpression
"{1B4E3046-4982-4436-8B6F-2EE4F63326C9}" = Wendy
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5
"{288A240F-9E68-4A2E-8230-A495D6CC9AFB}" = Polar WebSync
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}" = Firebird SQL Server - MAGIX Edition
"{35C0A1E4-D02A-412C-841F-266DBB116ABB}" = Intel(R) PROSet/Wireless WiFi-Software
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{49CC1A6A-3A1A-4EE7-913F-8106B51B59D1}" = Paragon Partition Manager 8.5 Personal
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}" = OmniPage SE 2.0
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111692950}" = Mahjongg Artifacts
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{92A6EE5B-5AE3-4159-9134-938BCA95B753}" = billiger.de Sparberater
"{95140000-00AF-0407-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A1ABB265-926B-481C-8A51-8125566DFE82}" = Polar WebLink 2.4.13
"{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}" = Acer Crystal Eye Webcam 2.0.8
"{A9212616-FCA2-4173-BD99-5C741EB3A068}" = Ulead DVD PictureShow 2 SE Basic
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{BE8602AE-3E73-4820-8063-F833BCAD7C3C}" = Polar Daemon
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe  1.4.142.1
"{D2C5E510-BE6D-42CC-9F61-E4F939078474}" = Lexmark
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{ECCD28B2-8798-4D16-8126-625D728294A1}" = SPBA 5.8
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F8013DD1-574B-4921-A473-88A2F7A34D16}" = Paragon Drive Backup™ 8.5 Personal Edition
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Acer Acer Bio Protection 6.0.00.17" = Acer Bio Protection

AAU 6.0.00.17
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE
"AVIConverter" = AVIConverter 5.1.0
"CCleaner" = CCleaner
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Direct Card Updater" = Direct Card Updater
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"Exif-Viewer" = Exif-Viewer 2.50
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"Lexmark S300-S400 Series" = Lexmark S300-S400 Series
"MAGIX Foto Manager 9 D" = MAGIX Foto Manager 9
"MAGIX Online Druck Service D" = MAGIX Online Druck Service
"MAGIX Screenshare D" = MAGIX Screenshare
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.0.1400
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox 15.0.1 (x86 de)" = Mozilla Firefox 15.0.1 (x86 de)
"Mozilla Thunderbird 15.0.1 (x86 de)" = Mozilla Thunderbird 15.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"N360" = Norton 360
"NVIDIA Drivers" = NVIDIA Drivers
"Polipo" = Polipo 1.0.4.1
"Recuva" = Recuva
"SimilarImages" = SimilarImages
"sv.net" = sv.net
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamViewer 7" = TeamViewer 7
"Tor" = Tor 0.2.1.30
"Vidalia" = Vidalia 0.2.10
"Weather9 Service" = Weather9 Service
"Winamp" = Winamp
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Anwendungserkennung
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 25.09.2012 15:56:38 | Computer Name = matthes-PC | Source = EventSystem | ID = 4609
Description =
 
Error - 25.09.2012 15:57:54 | Computer Name = matthes-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 25.09.2012 16:10:22 | Computer Name = matthes-PC | Source = EventSystem | ID = 4609
Description =
 
Error - 25.09.2012 16:11:40 | Computer Name = matthes-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 25.09.2012 16:13:49 | Computer Name = matthes-PC | Source = EventSystem | ID = 4609
Description =
 
Error - 25.09.2012 16:15:02 | Computer Name = matthes-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 26.09.2012 13:33:41 | Computer Name = matthes-PC | Source = EventSystem | ID = 4609
Description =
 
Error - 26.09.2012 13:34:45 | Computer Name = matthes-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 26.09.2012 14:49:55 | Computer Name = matthes-PC | Source = EventSystem | ID = 4609
Description =
 
Error - 26.09.2012 14:51:05 | Computer Name = matthes-PC | Source = WinMgmt | ID = 10
Description =
 
[ Media Center Events ]
Error - 26.05.2010 06:10:22 | Computer Name = matthes-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed;
 Win32 GetLastError returned 0D  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 26.05.2010 06:15:22 | Computer Name = matthes-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed;
 Win32 GetLastError returned 0D  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 26.05.2010 06:20:22 | Computer Name = matthes-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed;
 Win32 GetLastError returned 0D  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 26.05.2010 06:25:22 | Computer Name = matthes-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed;
 Win32 GetLastError returned 0D  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 26.05.2010 06:30:25 | Computer Name = matthes-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed;
 Win32 GetLastError returned 0D  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 26.05.2010 06:35:22 | Computer Name = matthes-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed;
 Win32 GetLastError returned 0D  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 26.05.2010 06:40:22 | Computer Name = matthes-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed;
 Win32 GetLastError returned 0D  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 26.05.2010 06:45:22 | Computer Name = matthes-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed;
 Win32 GetLastError returned 0D  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 26.05.2010 06:50:22 | Computer Name = matthes-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed;
 Win32 GetLastError returned 0D  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 26.05.2010 06:55:22 | Computer Name = matthes-PC | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed;
 Win32 GetLastError returned 0D  Prozess: DefaultDomain Objektname: Media Center Guide

 
[ System Events ]
Error - 26.09.2012 13:35:36 | Computer Name = matthes-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 26.09.2012 14:49:48 | Computer Name = matthes-PC | Source = DCOM | ID = 10005
Description =
 
Error - 26.09.2012 14:49:55 | Computer Name = matthes-PC | Source = DCOM | ID = 10005
Description =
 
Error - 26.09.2012 14:49:56 | Computer Name = matthes-PC | Source = DCOM | ID = 10005
Description =
 
Error - 26.09.2012 14:49:58 | Computer Name = matthes-PC | Source = DCOM | ID = 10005
Description =
 
Error - 26.09.2012 14:49:59 | Computer Name = matthes-PC | Source = DCOM | ID = 10005
Description =
 
Error - 26.09.2012 14:50:00 | Computer Name = matthes-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description =
 
Error - 26.09.2012 14:51:05 | Computer Name = matthes-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 26.09.2012 14:51:05 | Computer Name = matthes-PC | Source = Service Control Manager | ID = 7026
Description =
 
Error - 26.09.2012 14:51:48 | Computer Name = matthes-PC | Source = Service Control Manager | ID = 7001
Description =
 
 
< End of report >

Ich habe das Log nach dem löschen vergessen:

Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.26.09

Windows Vista Service Pack 2 x86 FAT32 (Abgesichertenmodus/Netzwerkfähig)
Internet Explorer 8.0.6001.19328
matthes :: xxx-PC [Administrator]

Schutz: Deaktiviert

26.09.2012 19:35:37
mbam-log-2012-09-26 (19-35-37).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 388690
Laufzeit: 1 Stunde(n), 10 Minute(n), 13 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 4
C:\ACER\Preload\Autorun\APP\BioProtection_Upek\Install\doc\FingerprintTutorial.exe (Trojan.Spatet) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ACER\Preload\Autorun\APP\BioProtection_Upek\Install\doc\SystemWizard.exe (Trojan.Spatet) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\Acer\Acer Bio Protection\FingerprintTutorial.exe (Trojan.Spatet) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\Acer\Acer Bio Protection\SystemWizard.exe (Trojan.Spatet) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


cosinus 27.09.2012 15:14


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset



Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

boris1 27.09.2012 17:44

Vielen Dank schon einmal für deine Hilfe, hier das Log:

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=22879763992c6449bb3871da3b8ea07e
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-09-27 04:26:09
# local_time=2012-09-27 06:26:09 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=3589 16777214 100 74 2582261 99419556 0 0
# compatibility_mode=5892 16776574 100 100 88229074 186289788 0 0
# compatibility_mode=8192 67108863 100 0 521 521 0 0
# scanned=171105
# found=5
# cleaned=0
# scan_time=6109
C:\ProgramData\WinMaximizer\WinMaximizer\InstallCache\{B6796CC9-76A5-46C8-BF10-B057474FECA3}\WinMaximizer.msi        a variant of Win32/SlowPCfighter application (unable to clean)        00000000000000000000000000000000        I
C:\Users\All Users\WinMaximizer\WinMaximizer\InstallCache\{B6796CC9-76A5-46C8-BF10-B057474FECA3}\WinMaximizer.msi        a variant of Win32/SlowPCfighter application (unable to clean)        00000000000000000000000000000000        I
C:\Users\matthes\AppData\Local\Microsoft\Windows\89\SearchIndexer.exe        Win32/TrojanDownloader.Retacino.A trojan (unable to clean)        00000000000000000000000000000000        I
D:\xxx\Downloads\registrybooster(1).exe        Win32/RegistryBooster application (unable to clean)        00000000000000000000000000000000        I
D:\xxx\Downloads\registrybooster.exe        Win32/RegistryBooster application (unable to clean)        00000000000000000000000000000000        I


cosinus 27.09.2012 20:30

Code:

D:\xxx\Downloads\registrybooster.exe
Finger weg von Registry-Cleanern!!

Die Registry ist das Hirn des Systems. Funktioniert das Hirn nicht, funktioniert der Rest nicht mehr wirklich.
Wir lesen oft genug von Hilfesuchenden, dass deren System nach der Nutzung von Registry Cleanern nicht mehr startet.
  • Wie soll der Cleaner zu 100% wissen ob der Eintrag benötigt wird oder nicht ?
  • Es ist vollkommen egal ob ein paar verwaiste Registry Einträge am System sind oder nicht.
  • Auch die dauernd angepriesene Beschleunigung des Systems ist nur bedingt wahr. Du würdest es nicht merken.

Ein sogenanntes False Positive von einem Cleaner kann auch dein System unbootbar machen.
Zerstörst Du die Registry, zerstörst Du Windows.


adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.

Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Rx].txt. (x=fortlaufende Nummer)

boris1 27.09.2012 20:43

Vielen Dank, werde ich weiterleiten. Ist zum Glück nicht mein PC.

Hier das Log:

Code:

# AdwCleaner v2.003 - Datei am 09/27/2012 um 21:38:34 erstellt
# Aktualisiert am 23/09/2012 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : matthes - MATTHES-PC
# Bootmodus : Abgesicherter Modus mit Netzwerkunterstützung
# Ausgeführt unter : C:\Users\matthes\Desktop\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gefunden : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
Datei Gefunden : C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\searchplugins\Askcom.xml
Ordner Gefunden : C:\Program Files\Conduit
Ordner Gefunden : C:\Program Files\DVDVideoSoftTB
Ordner Gefunden : C:\Users\matthes\AppData\Local\Conduit
Ordner Gefunden : C:\Users\matthes\AppData\Local\ConduitEngine
Ordner Gefunden : C:\Users\matthes\AppData\LocalLow\Conduit
Ordner Gefunden : C:\Users\matthes\AppData\LocalLow\DVDVideoSoftTB
Ordner Gefunden : C:\Users\matthes\AppData\LocalLow\PriceGong
Ordner Gefunden : C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\CT2269050
Ordner Gefunden : C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
Ordner Gefunden : C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\Smartbar
Ordner Gefunden : C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\WinampToolbarData
Ordner Gefunden : C:\Users\matthes\AppData\Roaming\OpenCandy

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gefunden : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gefunden : HKCU\Software\IGearSettings
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : HKCU\Toolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gefunden : HKLM\Software\Conduit
Schlüssel Gefunden : HKLM\Software\DVDVideoSoftTB
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F3F48B0-F87F-4558-B924-0816D492D227}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F92E8F7-8B24-4FD3-92F4-6526415CA0C8}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar
Schlüssel Gefunden : HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.6001.19328

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://isearch.avg.com/?cid={6376A146-BED6-45C9-A8A3-2130C08AD332}&mid=16301b71c18b47d09a43d16acde5e2c2-cec7e7c3b131d31bd22a47617a9612cba7920b81&lang=de&ds=tt014&pr=sa&d=2012-07-16 21:06:35&v=11.1.0.12&sap=hp

-\\ Mozilla Firefox v15.0.1 (de)

Profilname : default
Datei : C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\prefs.js

Gefunden : user_pref("CT2269050.1000082.isPlayDisplay", "true");
Gefunden : user_pref("CT2269050.1000082.state", "{\"state\":\"stopped\",\"text\":\"Hotmix 108\",\"description\"[...]
Gefunden : user_pref("CT2269050.1000234.TWC_TMP_city", "ESCHBORN");
Gefunden : user_pref("CT2269050.1000234.TWC_TMP_country", "DE");
Gefunden : user_pref("CT2269050.1000234.TWC_locId", "GMXX0007");
Gefunden : user_pref("CT2269050.1000234.TWC_location", "Germany");
Gefunden : user_pref("CT2269050.1000234.TWC_region", "OT");
Gefunden : user_pref("CT2269050.1000234.TWC_temp_dis", "c");
Gefunden : user_pref("CT2269050.1000234.TWC_wind_dis", "kmh");
Gefunden : user_pref("CT2269050.1000234.weatherData", "{\"icon\":\"31.png\",\"temperature\":\"15°C\",\"temperat[...]
Gefunden : user_pref("CT2269050.CT2269050ads1", "%7B%22ads%22%3A%5B%7B%22aid%22%3A%2232557%22%2C%22title%22%3A%[...]
Gefunden : user_pref("CT2269050.CT2269050current_term", "hide");
Gefunden : user_pref("CT2269050.CT2269050sdate", "2");
Gefunden : user_pref("CT2269050.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Gefunden : user_pref("CT2269050.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[...]
Gefunden : user_pref("CT2269050.FirstTime", "true");
Gefunden : user_pref("CT2269050.FirstTimeFF3", "true");
Gefunden : user_pref("CT2269050.UserID", "UN46447353630535957");
Gefunden : user_pref("CT2269050.addressBarTakeOverEnabledInHidden", "true");
Gefunden : user_pref("CT2269050.autoDisableScopes", -1);
Gefunden : user_pref("CT2269050.defaultSearch", "FALSE");
Gefunden : user_pref("CT2269050.embeddedsData", "[{\"appId\":\"128834881989343895\",\"apiPermissions\":{\"cross[...]
Gefunden : user_pref("CT2269050.enableAlerts", "always");
Gefunden : user_pref("CT2269050.firstTimeDialogOpened", "true");
Gefunden : user_pref("CT2269050.fixPageNotFoundErrorInHidden", "true");
Gefunden : user_pref("CT2269050.fixUrls", true);
Gefunden : user_pref("CT2269050.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Gefunden : user_pref("CT2269050.isNewTabEnabled", true);
Gefunden : user_pref("CT2269050.isPerformedSmartBarTransition", "true");
Gefunden : user_pref("CT2269050.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Gefunden : user_pref("CT2269050.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"Impuestos de No Residentes\",\"E[...]
Gefunden : user_pref("CT2269050.openThankYouPage", "FALSE");
Gefunden : user_pref("CT2269050.openUninstallPage", "FALSE");
Gefunden : user_pref("CT2269050.search.searchAppId", "128834881989343895");
Gefunden : user_pref("CT2269050.search.searchCount", "1");
Gefunden : user_pref("CT2269050.searchInNewTabEnabledInHidden", "true");
Gefunden : user_pref("CT2269050.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"true\"}");
Gefunden : user_pref("CT2269050.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Gefunden : user_pref("CT2269050.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[...]
Gefunden : user_pref("CT2269050.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[...]
Gefunden : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[...]
Gefunden : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[...]
Gefunden : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[...]
Gefunden : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[...]
Gefunden : user_pref("CT2269050.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data[...]
Gefunden : user_pref("CT2269050.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1342426658664");
Gefunden : user_pref("CT2269050.serviceLayer_services_appTracking_lastUpdate", "1342426540466");
Gefunden : user_pref("CT2269050.serviceLayer_services_appsMetadata_lastUpdate", "1342894753378");
Gefunden : user_pref("CT2269050.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1342203786086");
Gefunden : user_pref("CT2269050.serviceLayer_services_login_10.10.2.10_lastUpdate", "1342426539450");
Gefunden : user_pref("CT2269050.serviceLayer_services_login_10.10.20.14_lastUpdate", "1342902033054");
Gefunden : user_pref("CT2269050.serviceLayer_services_optimizer_lastUpdate", "1342797961977");
Gefunden : user_pref("CT2269050.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1342203786170");
Gefunden : user_pref("CT2269050.serviceLayer_services_searchAPI_lastUpdate", "1342894753825");
Gefunden : user_pref("CT2269050.serviceLayer_services_serviceMap_lastUpdate", "1342894753201");
Gefunden : user_pref("CT2269050.serviceLayer_services_toolbarContextMenu_lastUpdate", "1342203786027");
Gefunden : user_pref("CT2269050.serviceLayer_services_toolbarSettings_lastUpdate", "1342902032961");
Gefunden : user_pref("CT2269050.serviceLayer_services_translation_lastUpdate", "1342894753362");
Gefunden : user_pref("CT2269050.settingsINI", true);
Gefunden : user_pref("CT2269050.shouldFirstTimeDialog", "FALSE");
Gefunden : user_pref("CT2269050.smartbar.CTID", "CT2269050");
Gefunden : user_pref("CT2269050.smartbar.Uninstall", "0");
Gefunden : user_pref("CT2269050.smartbar.isHidden", true);
Gefunden : user_pref("CT2269050.smartbar.toolbarName", "DVDVideoSoftTB ");
Gefunden : user_pref("CT2269050.startPage", "FALSE");
Gefunden : user_pref("CT2269050.toolbarBornServerTime", "29-5-2012");
Gefunden : user_pref("CT2269050.toolbarCurrentServerTime", "21-7-2012");
Gefunden : user_pref("CT2269050.toolbarDisabled", "true");
Gefunden : user_pref("browser.search.defaultengine", "Ask.com");
Gefunden : user_pref("extensions.engine@conduit.com.install-event-fired", true);
Gefunden : user_pref("extensions.foxlingo.addit.defaultAddons", "{ \"software\": {\"20\": {\"id\": \"20\",\"tit[...]
Gefunden : user_pref("winamp_toolbar.buttons.layout", "skins_btn_wa;plugins_btn_wa;shout_btn_wa;video_btn_wa;ai[...]
Gefunden : user_pref("winamp_toolbar.firsttime.showwindow", false);
Gefunden : user_pref("winamp_toolbar.install.lastTbVersion", "5.6.11.2");
Gefunden : user_pref("winamp_toolbar.metrics.activestampdate", "11");
Gefunden : user_pref("winamp_toolbar.metrics.activestampmonth", "3");
Gefunden : user_pref("winamp_toolbar.metrics.activestampyear", "2011");
Gefunden : user_pref("winamp_toolbar.metrics.originalDate", "18");
Gefunden : user_pref("winamp_toolbar.metrics.originalHours", "18");
Gefunden : user_pref("winamp_toolbar.metrics.originalMinutes", "1");
Gefunden : user_pref("winamp_toolbar.metrics.originalMonth", "12");
Gefunden : user_pref("winamp_toolbar.metrics.originalSeconds", "11");
Gefunden : user_pref("winamp_toolbar.metrics.originalYear", "2009");
Gefunden : user_pref("winamp_toolbar.search.populateoncomplete", false);
Gefunden : user_pref("winamp_toolbar.search.searchtype", "web");
Gefunden : user_pref("winamp_toolbar.search.source", "tb50ffwinamp");
Gefunden : user_pref("winamp_toolbar.strbundle.msg", "Winamp Toolbar");
Gefunden : user_pref("winamp_toolbar.upgrade.showwindow", false);
Gefunden : user_pref("winamp_toolbar.winamp.appversion", "1");
Gefunden : user_pref("winamp_toolbar.winamp.artist", "");
Gefunden : user_pref("winamp_toolbar.winamp.title", "-999999");
Gefunden : user_pref("winamp_toolbar.winamp.tracklength", "-999999");
Gefunden : user_pref("winamp_toolbar.winamp.tracktime", "-999999");
Gefunden : user_pref("winamp_toolbar.winamp.volume", "255");

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\matthes\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [14944 octets] - [27/09/2012 21:38:34]

########## EOF - C:\AdwCleaner[R1].txt - [15005 octets] ##########


cosinus 27.09.2012 21:05

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Sx].txt. (x=fortlaufende Nummer)

boris1 27.09.2012 21:25

Der Neustart war jetzt ohne abgesicherten Modus. Das Log hat sich geöffnet, allerdings war dann wieder nur die Eieruhr zu sehen.
Habe nochmals im abgesicherten Modus gestartet, das läuft. Ist das z.Zt jetzt normal so?

Hier das Log:

Code:

# AdwCleaner v2.003 - Datei am 09/27/2012 um 22:10:44 erstellt
# Aktualisiert am 23/09/2012 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : matthes - MATTHES-PC
# Bootmodus : Abgesicherter Modus mit Netzwerkunterstützung
# Ausgeführt unter : C:\Users\matthes\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
Datei Gelöscht : C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\searchplugins\Askcom.xml
Ordner Gelöscht : C:\Program Files\Conduit
Ordner Gelöscht : C:\Program Files\DVDVideoSoftTB
Ordner Gelöscht : C:\Users\matthes\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\matthes\AppData\Local\ConduitEngine
Ordner Gelöscht : C:\Users\matthes\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\matthes\AppData\LocalLow\DVDVideoSoftTB
Ordner Gelöscht : C:\Users\matthes\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\CT2269050
Ordner Gelöscht : C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
Ordner Gelöscht : C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\Smartbar
Ordner Gelöscht : C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\WinampToolbarData
Ordner Gelöscht : C:\Users\matthes\AppData\Roaming\OpenCandy

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\IGearSettings
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\DVDVideoSoftTB
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F3F48B0-F87F-4558-B924-0816D492D227}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F92E8F7-8B24-4FD3-92F4-6526415CA0C8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.6001.19328

Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://isearch.avg.com/?cid={6376A146-BED6-45C9-A8A3-2130C08AD332}&mid=16301b71c18b47d09a43d16acde5e2c2-cec7e7c3b131d31bd22a47617a9612cba7920b81&lang=de&ds=tt014&pr=sa&d=2012-07-16 21:06:35&v=11.1.0.12&sap=hp --> hxxp://www.google.com

-\\ Mozilla Firefox v15.0.1 (de)

Profilname : default
Datei : C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\prefs.js

C:\Users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\user.js ... Gelöscht !

Gelöscht : user_pref("CT2269050.1000082.isPlayDisplay", "true");
Gelöscht : user_pref("CT2269050.1000082.state", "{\"state\":\"stopped\",\"text\":\"Hotmix 108\",\"description\"[...]
Gelöscht : user_pref("CT2269050.1000234.TWC_TMP_city", "ESCHBORN");
Gelöscht : user_pref("CT2269050.1000234.TWC_TMP_country", "DE");
Gelöscht : user_pref("CT2269050.1000234.TWC_locId", "GMXX0007");
Gelöscht : user_pref("CT2269050.1000234.TWC_location", "Germany");
Gelöscht : user_pref("CT2269050.1000234.TWC_region", "OT");
Gelöscht : user_pref("CT2269050.1000234.TWC_temp_dis", "c");
Gelöscht : user_pref("CT2269050.1000234.TWC_wind_dis", "kmh");
Gelöscht : user_pref("CT2269050.1000234.weatherData", "{\"icon\":\"31.png\",\"temperature\":\"15°C\",\"temperat[...]
Gelöscht : user_pref("CT2269050.CT2269050ads1", "%7B%22ads%22%3A%5B%7B%22aid%22%3A%2232557%22%2C%22title%22%3A%[...]
Gelöscht : user_pref("CT2269050.CT2269050current_term", "hide");
Gelöscht : user_pref("CT2269050.CT2269050sdate", "2");
Gelöscht : user_pref("CT2269050.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Gelöscht : user_pref("CT2269050.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[...]
Gelöscht : user_pref("CT2269050.FirstTime", "true");
Gelöscht : user_pref("CT2269050.FirstTimeFF3", "true");
Gelöscht : user_pref("CT2269050.UserID", "UN46447353630535957");
Gelöscht : user_pref("CT2269050.addressBarTakeOverEnabledInHidden", "true");
Gelöscht : user_pref("CT2269050.autoDisableScopes", -1);
Gelöscht : user_pref("CT2269050.defaultSearch", "FALSE");
Gelöscht : user_pref("CT2269050.embeddedsData", "[{\"appId\":\"128834881989343895\",\"apiPermissions\":{\"cross[...]
Gelöscht : user_pref("CT2269050.enableAlerts", "always");
Gelöscht : user_pref("CT2269050.firstTimeDialogOpened", "true");
Gelöscht : user_pref("CT2269050.fixPageNotFoundErrorInHidden", "true");
Gelöscht : user_pref("CT2269050.fixUrls", true);
Gelöscht : user_pref("CT2269050.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Gelöscht : user_pref("CT2269050.isNewTabEnabled", true);
Gelöscht : user_pref("CT2269050.isPerformedSmartBarTransition", "true");
Gelöscht : user_pref("CT2269050.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Gelöscht : user_pref("CT2269050.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"Impuestos de No Residentes\",\"E[...]
Gelöscht : user_pref("CT2269050.openThankYouPage", "FALSE");
Gelöscht : user_pref("CT2269050.openUninstallPage", "FALSE");
Gelöscht : user_pref("CT2269050.search.searchAppId", "128834881989343895");
Gelöscht : user_pref("CT2269050.search.searchCount", "1");
Gelöscht : user_pref("CT2269050.searchInNewTabEnabledInHidden", "true");
Gelöscht : user_pref("CT2269050.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"true\"}");
Gelöscht : user_pref("CT2269050.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Gelöscht : user_pref("CT2269050.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[...]
Gelöscht : user_pref("CT2269050.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[...]
Gelöscht : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[...]
Gelöscht : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[...]
Gelöscht : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[...]
Gelöscht : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[...]
Gelöscht : user_pref("CT2269050.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data[...]
Gelöscht : user_pref("CT2269050.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1342426658664");
Gelöscht : user_pref("CT2269050.serviceLayer_services_appTracking_lastUpdate", "1342426540466");
Gelöscht : user_pref("CT2269050.serviceLayer_services_appsMetadata_lastUpdate", "1342894753378");
Gelöscht : user_pref("CT2269050.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1342203786086");
Gelöscht : user_pref("CT2269050.serviceLayer_services_login_10.10.2.10_lastUpdate", "1342426539450");
Gelöscht : user_pref("CT2269050.serviceLayer_services_login_10.10.20.14_lastUpdate", "1342902033054");
Gelöscht : user_pref("CT2269050.serviceLayer_services_optimizer_lastUpdate", "1342797961977");
Gelöscht : user_pref("CT2269050.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1342203786170");
Gelöscht : user_pref("CT2269050.serviceLayer_services_searchAPI_lastUpdate", "1342894753825");
Gelöscht : user_pref("CT2269050.serviceLayer_services_serviceMap_lastUpdate", "1342894753201");
Gelöscht : user_pref("CT2269050.serviceLayer_services_toolbarContextMenu_lastUpdate", "1342203786027");
Gelöscht : user_pref("CT2269050.serviceLayer_services_toolbarSettings_lastUpdate", "1342902032961");
Gelöscht : user_pref("CT2269050.serviceLayer_services_translation_lastUpdate", "1342894753362");
Gelöscht : user_pref("CT2269050.settingsINI", true);
Gelöscht : user_pref("CT2269050.shouldFirstTimeDialog", "FALSE");
Gelöscht : user_pref("CT2269050.smartbar.CTID", "CT2269050");
Gelöscht : user_pref("CT2269050.smartbar.Uninstall", "0");
Gelöscht : user_pref("CT2269050.smartbar.isHidden", true);
Gelöscht : user_pref("CT2269050.smartbar.toolbarName", "DVDVideoSoftTB ");
Gelöscht : user_pref("CT2269050.startPage", "FALSE");
Gelöscht : user_pref("CT2269050.toolbarBornServerTime", "29-5-2012");
Gelöscht : user_pref("CT2269050.toolbarCurrentServerTime", "21-7-2012");
Gelöscht : user_pref("CT2269050.toolbarDisabled", "true");
Gelöscht : user_pref("browser.search.defaultengine", "Ask.com");
Gelöscht : user_pref("extensions.engine@conduit.com.install-event-fired", true);
Gelöscht : user_pref("extensions.foxlingo.addit.defaultAddons", "{ \"software\": {\"20\": {\"id\": \"20\",\"tit[...]
Gelöscht : user_pref("winamp_toolbar.buttons.layout", "skins_btn_wa;plugins_btn_wa;shout_btn_wa;video_btn_wa;ai[...]
Gelöscht : user_pref("winamp_toolbar.firsttime.showwindow", false);
Gelöscht : user_pref("winamp_toolbar.install.lastTbVersion", "5.6.11.2");
Gelöscht : user_pref("winamp_toolbar.metrics.activestampdate", "11");
Gelöscht : user_pref("winamp_toolbar.metrics.activestampmonth", "3");
Gelöscht : user_pref("winamp_toolbar.metrics.activestampyear", "2011");
Gelöscht : user_pref("winamp_toolbar.metrics.originalDate", "18");
Gelöscht : user_pref("winamp_toolbar.metrics.originalHours", "18");
Gelöscht : user_pref("winamp_toolbar.metrics.originalMinutes", "1");
Gelöscht : user_pref("winamp_toolbar.metrics.originalMonth", "12");
Gelöscht : user_pref("winamp_toolbar.metrics.originalSeconds", "11");
Gelöscht : user_pref("winamp_toolbar.metrics.originalYear", "2009");
Gelöscht : user_pref("winamp_toolbar.search.populateoncomplete", false);
Gelöscht : user_pref("winamp_toolbar.search.searchtype", "web");
Gelöscht : user_pref("winamp_toolbar.search.source", "tb50ffwinamp");
Gelöscht : user_pref("winamp_toolbar.strbundle.msg", "Winamp Toolbar");
Gelöscht : user_pref("winamp_toolbar.upgrade.showwindow", false);
Gelöscht : user_pref("winamp_toolbar.winamp.appversion", "1");
Gelöscht : user_pref("winamp_toolbar.winamp.artist", "");
Gelöscht : user_pref("winamp_toolbar.winamp.title", "-999999");
Gelöscht : user_pref("winamp_toolbar.winamp.tracklength", "-999999");
Gelöscht : user_pref("winamp_toolbar.winamp.tracktime", "-999999");
Gelöscht : user_pref("winamp_toolbar.winamp.volume", "255");

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\matthes\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [15075 octets] - [27/09/2012 21:38:34]
AdwCleaner[S1].txt - [15096 octets] - [27/09/2012 22:10:44]

########## EOF - C:\AdwCleaner[S1].txt - [15157 octets] ##########


cosinus 28.09.2012 09:52

Hätte da mal zwei Fragen bevor es weiter geht (wir sind noch nicht fertig!)

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

boris1 28.09.2012 15:48

Nein, es geht noch nicht wieder. Wenn ich das Startmenü öffnen möchte bekomme ich die Eieruhr zu sehen und es passiert nichts weiter.
Programme auf dem Desktop lassen sich auch nicht öffnen. Im normalen Modus kann ich also das Startmenü nicht aufklappen.


Im abgesicherten Modus kann ich das Startmenü öffnen, leere Ordner kann ich dort nicht entdecken.

cosinus 28.09.2012 15:59

Mach bitte ein neues OTL-Log im abgesicherten Modus mit Netzwerktreibern. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


boris1 28.09.2012 18:13

Code:

OTL logfile created on: 28.09.2012 18:49:04 - Run 2
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\matthes\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19328)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,99 Gb Total Physical Memory | 2,55 Gb Available Physical Memory | 85,22% Memory free
6,18 Gb Paging File | 5,93 Gb Available in Paging File | 95,95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 78,05 Gb Total Space | 31,39 Gb Free Space | 40,22% Space Free | Partition Type: NTFS
Drive D: | 106,50 Gb Total Space | 42,43 Gb Free Space | 39,85% Space Free | Partition Type: NTFS
Drive E: | 99,99 Gb Total Space | 72,43 Gb Free Space | 72,43% Space Free | Partition Type: NTFS
 
Computer Name: MATTHES-PC | User Name: matthes | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\matthes\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
 
========== Services (SafeList) ==========
 
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (N360) -- C:\Program Files\Norton 360\Engine\6.3.0.14\ccSvcHst.exe (Symantec Corporation)
SRV - (TeamViewer7) -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (Polar Daemon) -- C:\Program Files\Polar\Daemon\polard.exe ()
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (lxea_device) -- C:\Windows\System32\lxeacoms.exe ( )
SRV - (lxeaCATSCustConnectService) -- C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxeaserv.exe ()
SRV - (ACDaemon) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (Fabs) -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (IGBASVC) -- C:\Program Files\Acer\Acer Bio Protection\BASVC.exe ()
SRV - (EvtEng) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV - (RegSrvc) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (IAANTMON) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (CLHNService) -- C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
 
 
========== Driver Services (SafeList) ==========
 
DRV - (SYMNDISV) -- C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS File not found
DRV - (SYMFW) -- C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (DKbFltr) -- system32\DRIVERS\DKbFltr.sys File not found
DRV - (cpuz132) -- C:\Users\matthes\AppData\Local\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120922.008\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120922.008\NAVENG.SYS (Symantec Corporation)
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (IDSVix86) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\IPSDefs\20120921.001\IDSvix86.sys (Symantec Corporation)
DRV - (BHDrvx86) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\BASHDefs\20120919.001\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SRTSP) -- C:\Windows\System32\drivers\N360\0603000.00E\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) -- C:\Windows\System32\drivers\N360\0603000.00E\srtspx.sys (Symantec Corporation)
DRV - (ccSet_N360) -- C:\Windows\System32\drivers\N360\0603000.00E\ccsetx86.sys (Symantec Corporation)
DRV - (SymEFA) -- C:\Windows\System32\drivers\N360\0603000.00E\symefa.sys (Symantec Corporation)
DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDIv) -- C:\Windows\System32\drivers\N360\0603000.00E\symtdiv.sys (Symantec Corporation)
DRV - (SymDS) -- C:\Windows\System32\drivers\N360\0603000.00E\symds.sys (Symantec Corporation)
DRV - (SymIRON) -- C:\Windows\System32\drivers\N360\0603000.00E\ironx86.sys (Symantec Corporation)
DRV - (L1E) -- C:\Windows\System32\drivers\L1E60x86.sys (Atheros Communications, Inc.)
DRV - (winusb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (hotcore3) -- C:\Windows\System32\drivers\hotcore3.sys (Paragon Software Group)
DRV - (NETw5v32) -- C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (AlfaFF) -- C:\Windows\System32\drivers\AlfaFF.sys (Alfa Corporation)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) -- C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl (Cyberlink Corp.)
DRV - (Uim_IM) -- C:\Windows\System32\drivers\Uim_IM.sys (Paragon Software Group)
DRV - (UimBus) -- C:\Windows\System32\drivers\UimBus.sys (Paragon Software Group)
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (WSDPrintDevice) -- C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (NTIPPKernel) -- C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys (Cyberlink Corp.)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (winbondcir) -- C:\Windows\System32\drivers\winbondcir.sys (Winbond Electronics Corporation)
DRV - (Afc) -- C:\Windows\System32\drivers\afc.sys (Arcsoft, Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data]
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://global.acer.com [binary data]
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - No CLSID value found
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = hxxp://int.search-results.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=360&chn=retail&geo=DE&ver=5
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\..\SearchScopes\{DA0F6B44-AEEB-40C9-8514-D8063D84A2C1}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=DVS2&o=1586&src=crm&q={searchTerms}&locale=&apn_ptnrs=^AAA&apn_dtid=^YYYYYY^YY^DE&apn_uid=67ba21ef-ec03-4c49-86d9-720a894a458f&apn_sauid=B3132688-519A-47DD-8AEC-5953DFB835ED
IE - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "search for firefox"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p="
FF - prefs.js..browser.search.order.1: "search for firefox"
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "search for firefox"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: addon@gutscheine-live.de:1.1
FF - prefs.js..extensions.enabledAddons: finder@meingutscheincode.de:3.0.3
FF - prefs.js..extensions.enabledAddons: ciuvo-extension@billiger.de:1.0.462
FF - prefs.js..extensions.enabledAddons: {b677fa16-ac2f-410c-8ea5-3bc98ed515d3}:1.2
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.1.5 - 1
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2012.7.5.2
FF - prefs.js..extensions.enabledItems: {b677fa16-ac2f-410c-8ea5-3bc98ed515d3}:1.2
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.11.2
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..keyword.URL: "hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@erdas.com/ERDAS Image Web Server ECW JPEG2000 Plugin,version=9.3: C:\Program Files\ERDAS\Image Web Server\Firefox Plug-in\NP_NCS6.dll (ERDAS)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\IPSFFPlgn\ [2012.05.04 11:17:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\coFFPlgn\ [2012.09.28 16:42:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.11 11:03:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.08.20 10:06:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.08.23 13:20:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.11 11:03:14 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.08.20 10:06:56 | 000,000,000 | ---D | M]
 
[2010.10.01 16:06:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\Extensions
[2010.10.01 16:06:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.09.27 22:10:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\Firefox\Profiles\38gpdnax.default\extensions
[2012.09.13 10:30:04 | 000,000,000 | ---D | M] (FoxLingo) -- C:\Users\matthes\AppData\Roaming\mozilla\Firefox\Profiles\38gpdnax.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2012.03.19 10:21:11 | 000,004,270 | ---- | M] () (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\extensions\addon@gutscheine-live.de.xpi
[2012.08.30 02:12:30 | 000,088,614 | ---- | M] () (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\extensions\extension@ciuvo.com.xpi
[2011.10.02 09:30:46 | 000,105,020 | ---- | M] () (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\extensions\finder@meingutscheincode.de.xpi
[2012.07.26 10:28:38 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011.05.12 11:25:21 | 000,002,448 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\searchplugins\safesearch.xml
[2009.12.18 22:01:14 | 000,001,201 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\searchplugins\winamp-search.xml
[2012.06.18 12:42:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010.01.27 20:03:47 | 000,000,000 | ---D | M] (Adobe Reader) -- C:\Program Files\Mozilla Firefox\extensions\{b677fa16-ac2f-410c-8ea5-3bc98ed515d3}
[2011.05.25 22:24:53 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:creator="billiger.de Sparberater" em:homepageURL="hxxp://sparberater.billiger.de" em:iconURL="chrome://ciuvo/content/icons/billigerde/ciuvo_icon.png" em:id="ciuvo-extension@billiger.de" em:name="billiger.de Sparberater" em:optionsURL="" em:type="2" em:updateKey="MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDBHgpsx79ZmWK5YY6tA/iPgCxyzLL2SpWEBcJgQYa2qsiay+akqFqG0hr0TyGQOzkEnoRUkysljyzTHIUYXS3V7yorR7CN9+Vv/xC5RbSesfs8DOukKHWNQPrL57OvLzJIMrl86HLcKBiPZAQ4sAoITuYGnsr6CY3fZxYKTGNS/wIDAQAB" em:updateURL="hxxp://ciuvo.com/ciuvo/update?id=%ITEM_ID%&amp;version=%ITEM_VERSION%&amp;maxversion=%ITEM_MAXAPPVERSION%&amp;status=%ITEM_STATUS%&amp;app_id=%APP_ID%&amp;app_version=%APP_VERSION%&amp;os=%APP_OS%&amp;locale=%APP_LOCALE%&amp;tag=billigerde" em:version="1.0.462">) -- C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de
[2011.05.25 22:24:53 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de\chrome
[2012.09.28 16:42:06 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\COFFPLGN
[2012.05.04 11:17:19 | 000,000,000 | ---D | M] (Norton Vulnerability Protection) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\IPSFFPLGN
[2009.09.17 15:42:23 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012.09.11 11:03:14 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008.06.30 14:44:08 | 000,324,976 | ---- | M] (Symantec Corporation) -- C:\Program Files\mozilla firefox\components\coFFPlgn.dll
[2012.03.16 17:39:29 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.12.09 19:23:32 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012.06.15 00:46:57 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.11 11:03:12 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.15 00:46:57 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.15 00:46:57 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.15 00:46:57 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.15 00:46:56 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Lexmark Symbolleiste) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Adobe Reader) - {147FEC3F-6DE9-437C-8FC1-6B8A20AA0A72} - C:\Users\matthes\AppData\Roaming\AdobeReader\IE\AdobeReader.dll (Adobe Systems, Incorporated)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\6.3.0.14\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\6.3.0.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (billiger.de Sparberater) - {92A6EE5B-5AE3-4159-9134-938BCA95B753} - C:\Program Files\billigerde\Internet Explorer\billigerde.dll (solute gmbh)
O2 - BHO: (Lexmark ) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Lexmark Symbolleiste) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.3.0.14\coieplg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\..\Toolbar\ShellBrowser: (Lexmark Symbolleiste) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\..\Toolbar\WebBrowser: (Lexmark Symbolleiste) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.3.0.14\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [lxeamon.exe] C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe (Acer Incorporated)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000..\Run: [SearchIndexer] C:\Users\matthes\AppData\Local\Microsoft\Windows\89\SearchIndexer.exe ()
O4 - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000..\RunOnce: [Report] C:\AdwCleaner[S1].txt ()
O4 - Startup: C:\Users\matthes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\Software\Policies\Microsoft\Internet Explorer\Recovery present
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe ()
O9 - Extra 'Tools' menuitem : Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe ()
O9 - Extra Button: Amazon (amazon.de) - {603D3CE5-33BC-4d51-A31E-613A2B826E21} - C:\Users\matthes\AppData\Roaming\IEButtons\toolbutton2.js ()
O9 - Extra Button: easy Shopping - {804420A5-7F05-4ee9-92F2-D2B644AD9102} - C:\Users\matthes\AppData\Roaming\IEButtons\toolbutton3.js ()
O9 - Extra Button: eBay (ebay.de) - {C376BD23-6DC3-4e10-9ED0-AB8C0444E45C} - C:\Users\matthes\AppData\Roaming\IEButtons\toolbutton1.js ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.5.1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{463FB10B-4FC8-44CD-824A-096C81AA3247}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AWinNotifyVitaKey MC3000: DllName - (C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll) - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll (Arachnoid Biometrics Identification Group Corp.)
O20 - Winlogon\Notify\spba: DllName - (C:\Program Files\Common Files\SPBA\homefus2.dll) - C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
O24 - Desktop WallPaper: C:\Users\matthes\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\matthes\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{fc6e75ed-8782-11df-84a4-00238b010b31}\Shell\AutoRun\command - "" = Menu.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpReg: ArcadeDeluxeAgent - hkey= - key= - C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
MsConfig - StartUpReg: CLMLServer - hkey= - key= - C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
MsConfig - StartUpReg: KiesHelper - hkey= - key= -  File not found
MsConfig - StartUpReg: KiesPDLR - hkey= - key= -  File not found
MsConfig - StartUpReg: KiesTrayAgent - hkey= - key= -  File not found
MsConfig - StartUpReg: OpwareSE2 - hkey= - key= - C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
MsConfig - StartUpReg: PlayMovie - hkey= - key= - C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig - StartUpReg: WinampAgent - hkey= - key= - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
MsConfig - StartUpReg: WMPNSCFG - hkey= - key= - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
MsConfig - StartUpReg: ZPdtWzdVitaKey MC3000 - hkey= - key= - C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe (Arachnoid Biometrics Identification Group Corp.)
MsConfig - State: "startup" - 0
MsConfig - State: "services" - 0
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.27 16:35:39 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.09.27 16:35:03 | 002,322,184 | ---- | C] (ESET) -- C:\Users\matthes\Desktop\esetsmartinstaller_enu.exe
[2012.09.26 20:53:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\matthes\Desktop\OTL.exe
[2012.09.25 21:59:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.09.25 21:59:22 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.09.25 19:36:28 | 000,000,000 | ---D | C] -- C:\Users\matthes\AppData\Roaming\Malwarebytes
[2012.09.25 19:36:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.09.25 19:36:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.09.25 19:36:11 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.25 19:36:11 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.09.17 19:15:46 | 000,000,000 | ---D | C] -- C:\Users\matthes\Ordnerdeckblätter
[2012.09.17 18:44:38 | 000,000,000 | ---D | C] -- C:\Users\matthes\Desktop\Arleen Fotoalbum
[2012.09.11 14:27:34 | 000,000,000 | ---D | C] -- C:\Windows\System32\Samsung_USB_Drivers
[2010.03.07 11:45:51 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\matthes\AppData\Roaming\pcouffin.sys
[2004.07.09 05:08:36 | 000,472,576 | ---- | C] (Microsoft Corporation) -- C:\Program Files\dxsetup.exe
[2004.07.09 05:08:34 | 002,242,560 | ---- | C] (Microsoft Corporation) -- C:\Program Files\dsetup32.dll
[2004.07.09 04:03:10 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Program Files\DSETUP.dll
[10 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[10 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.28 18:47:45 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\matthes\Desktop\OTL.exe
[2012.09.28 18:43:05 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.28 16:41:45 | 000,065,536 | ---- | M] () -- C:\ProgramData\nvModes.001
[2012.09.28 16:41:32 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.28 16:41:32 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.28 16:41:29 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.09.27 21:38:13 | 000,513,501 | ---- | M] () -- C:\Users\matthes\Desktop\adwcleaner.exe
[2012.09.27 16:35:19 | 002,322,184 | ---- | M] (ESET) -- C:\Users\matthes\Desktop\esetsmartinstaller_enu.exe
[2012.09.25 21:59:22 | 000,000,773 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.09.25 21:50:00 | 000,000,422 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{52A60082-F11F-4DC0-815C-41B71B2E7AD3}.job
[2012.09.25 19:36:13 | 000,000,875 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.25 19:35:40 | 000,041,984 | ---- | M] () -- C:\Users\matthes\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.25 19:34:52 | 000,627,756 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.09.25 19:34:52 | 000,595,386 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.09.25 19:34:52 | 000,125,870 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.09.25 19:34:52 | 000,103,460 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.09.25 18:46:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.23 23:05:23 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.09.23 15:35:00 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.09.18 14:29:30 | 000,001,154 | ---- | M] () -- C:\Users\matthes\Desktop\OpenOffice.org 3.3 - Verknüpfung.lnk
[2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.08.30 01:06:05 | 000,000,032 | ---- | M] () -- C:\Windows\Menu.INI
[10 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[10 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.09.27 21:37:50 | 000,513,501 | ---- | C] () -- C:\Users\matthes\Desktop\adwcleaner.exe
[2012.09.25 21:59:22 | 000,000,773 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.09.25 19:36:13 | 000,000,875 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.18 14:29:30 | 000,001,154 | ---- | C] () -- C:\Users\matthes\Desktop\OpenOffice.org 3.3 - Verknüpfung.lnk
[2012.08.22 21:58:24 | 000,022,079 | ---- | C] () -- C:\Users\matthes\EPlus Kündigung 2.odt
[2012.08.21 13:48:01 | 000,047,179 | ---- | C] () -- C:\Users\matthes\Urlaub Malle.odt
[2012.06.25 15:20:17 | 000,061,243 | ---- | C] () -- C:\Users\matthes\2012-06-22 01 12 37.jpg
[2012.01.09 22:36:41 | 000,323,584 | ---- | C] () -- C:\Windows\System32\lxeains.dll
[2012.01.09 22:36:41 | 000,262,144 | ---- | C] () -- C:\Windows\System32\lxeainsb.dll
[2012.01.09 22:36:40 | 000,294,912 | ---- | C] () -- C:\Windows\System32\lxeacui.dll
[2012.01.09 22:36:40 | 000,253,952 | ---- | C] () -- C:\Windows\System32\lxeacu.dll
[2012.01.09 22:36:40 | 000,110,592 | ---- | C] () -- C:\Windows\System32\lxeacuir.dll
[2012.01.09 22:36:40 | 000,086,016 | ---- | C] () -- C:\Windows\System32\lxeagcfg.dll
[2012.01.09 20:20:57 | 000,000,044 | -H-- | C] () -- C:\Windows\System32\lxearwrd.ini
[2012.01.09 20:20:41 | 000,364,544 | ---- | C] ( ) -- C:\Windows\System32\lxeainpa.dll
[2012.01.09 20:20:41 | 000,356,352 | ---- | C] ( ) -- C:\Windows\System32\LXEAhcp.dll
[2012.01.09 20:20:41 | 000,344,064 | ---- | C] ( ) -- C:\Windows\System32\lxeaiesc.dll
[2012.01.09 20:20:41 | 000,331,776 | ---- | C] () -- C:\Windows\System32\LXEAinst.dll
[2012.01.09 20:20:40 | 001,048,576 | ---- | C] ( ) -- C:\Windows\System32\lxeaserv.dll
[2012.01.09 20:20:40 | 000,847,872 | ---- | C] ( ) -- C:\Windows\System32\lxeausb1.dll
[2012.01.09 20:20:40 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxeapmui.dll
[2012.01.09 20:20:39 | 000,577,536 | ---- | C] ( ) -- C:\Windows\System32\lxealmpm.dll
[2012.01.09 20:20:39 | 000,114,688 | ---- | C] () -- C:\Windows\System32\lxeainsr.dll
[2012.01.09 20:20:39 | 000,057,344 | ---- | C] () -- C:\Windows\System32\lxeajswr.dll
[2012.01.09 20:20:38 | 000,688,128 | ---- | C] ( ) -- C:\Windows\System32\lxeahbn3.dll
[2012.01.09 20:20:38 | 000,324,264 | ---- | C] ( ) -- C:\Windows\System32\lxeaih.exe
[2012.01.09 20:20:38 | 000,208,896 | ---- | C] () -- C:\Windows\System32\lxeagrd.dll
[2012.01.09 20:20:38 | 000,090,112 | ---- | C] () -- C:\Windows\System32\lxeacub.dll
[2012.01.09 20:20:38 | 000,036,864 | ---- | C] () -- C:\Windows\System32\lxeacur.dll
[2012.01.09 20:20:37 | 000,802,816 | ---- | C] ( ) -- C:\Windows\System32\lxeacomc.dll
[2012.01.09 20:20:37 | 000,598,696 | ---- | C] ( ) -- C:\Windows\System32\lxeacoms.exe
[2012.01.09 20:20:37 | 000,373,416 | ---- | C] ( ) -- C:\Windows\System32\lxeacfg.exe
[2012.01.09 20:20:37 | 000,372,736 | ---- | C] ( ) -- C:\Windows\System32\lxeacomm.dll
[2011.11.29 11:34:28 | 000,000,000 | ---- | C] () -- C:\Users\matthes\AppData\Local\{977B9521-6D44-4719-ABEB-E5DFE92018C3}
[2011.07.31 16:08:52 | 000,000,055 | ---- | C] () -- C:\Windows\ClonyDrives.ini
[2011.07.31 16:06:38 | 000,000,340 | ---- | C] () -- C:\Windows\Clony2.ini
[2011.07.28 16:44:43 | 000,000,034 | ---- | C] () -- C:\Windows\cdplayer.ini
[2011.05.05 12:49:35 | 000,000,000 | ---- | C] () -- C:\Users\matthes\AppData\Local\{35FDC0F4-068D-4B3D-BD33-81A24E62D79E}
[2011.03.16 14:10:42 | 000,000,046 | ---- | C] () -- C:\ProgramData\.SimImages
[2011.01.24 20:08:48 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011.01.24 20:08:48 | 000,042,112 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2011.01.07 23:27:17 | 000,000,032 | ---- | C] () -- C:\Windows\Menu.INI
[2011.01.04 17:10:56 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2011.01.04 17:10:56 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2011.01.04 17:10:56 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2011.01.04 17:10:56 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2010.08.10 18:52:12 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010.03.07 11:45:51 | 000,087,608 | ---- | C] () -- C:\Users\matthes\AppData\Roaming\inst.exe
[2010.03.07 11:45:51 | 000,007,887 | ---- | C] () -- C:\Users\matthes\AppData\Roaming\pcouffin.cat
[2010.03.07 11:45:51 | 000,001,144 | ---- | C] () -- C:\Users\matthes\AppData\Roaming\pcouffin.inf
[2009.09.19 17:35:42 | 000,007,592 | ---- | C] () -- C:\Users\matthes\AppData\Local\d3d9caps.dat
[2008.12.25 21:39:02 | 000,041,984 | ---- | C] () -- C:\Users\matthes\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.12.25 08:45:38 | 000,065,536 | ---- | C] () -- C:\ProgramData\nvModes.001
[2008.12.25 08:27:04 | 000,068,105 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2004.07.22 11:51:34 | 003,432,656 | ---- | C] () -- C:\Program Files\ManagedDX.CAB
[2004.07.19 23:58:36 | 001,156,363 | ---- | C] () -- C:\Program Files\BDANT.cab
[2004.07.19 23:53:26 | 000,976,020 | ---- | C] () -- C:\Program Files\BDAXP.cab
[2004.07.09 15:17:16 | 013,265,040 | ---- | C] () -- C:\Program Files\dxnt.cab
[2004.07.09 10:13:48 | 015,493,481 | ---- | C] () -- C:\Program Files\DirectX.cab
[2004.07.09 10:13:46 | 000,703,080 | ---- | C] () -- C:\Program Files\BDA.cab
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2008.12.25 09:08:33 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Acer
[2008.07.30 04:10:28 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Acer GameZone Console
[2009.01.19 18:12:29 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Ashampoo
[2009.11.05 15:54:03 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\DirectCard Updater
[2012.07.14 17:50:03 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\DVDVideoSoft
[2012.02.26 15:46:23 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Exif Viewer
[2009.03.14 20:23:15 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Foxit
[2009.11.05 15:54:03 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\IEButtons
[2011.10.23 16:16:27 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\KeePassX
[2010.05.03 08:42:01 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\MAGIX
[2008.12.26 17:12:59 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\OpenOffice.org
[2011.07.20 17:11:43 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Samsung
[2010.03.30 22:28:24 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\ScanSoft
[2010.10.01 16:06:45 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Thunderbird
[2010.10.07 09:10:44 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Tific
[2012.07.16 21:04:08 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\TuneUp Software
[2010.01.27 20:13:37 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\uTorrent
[2012.07.14 17:46:08 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Vso
[2009.11.11 13:16:16 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\weather9
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2008.12.25 09:08:33 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Acer
[2008.07.30 04:10:28 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Acer GameZone Console
[2011.08.23 17:57:41 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Adobe
[2010.01.27 20:03:47 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\AdobeReader
[2011.07.24 18:20:02 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\ArcSoft
[2009.01.19 18:12:29 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Ashampoo
[2009.06.21 16:31:28 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\CyberLink
[2009.11.05 15:54:03 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\DirectCard Updater
[2012.07.14 17:50:03 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\DVDVideoSoft
[2012.02.26 15:46:23 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Exif Viewer
[2009.03.14 20:23:15 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Foxit
[2010.09.19 20:42:30 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Google
[2008.12.18 12:50:29 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Identities
[2009.11.05 15:54:03 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\IEButtons
[2010.04.09 18:35:25 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Intel
[2011.10.23 16:16:27 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\KeePassX
[2008.12.18 12:50:59 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Macromedia
[2010.05.03 08:42:01 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\MAGIX
[2012.09.25 19:36:28 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Malwarebytes
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Media Center Programs
[2011.08.23 17:57:41 | 000,000,000 | --SD | M] -- C:\Users\matthes\AppData\Roaming\Microsoft
[2008.12.22 17:07:03 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Mozilla
[2008.12.26 17:12:59 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\OpenOffice.org
[2011.07.20 17:11:43 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Samsung
[2010.03.30 22:28:24 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\ScanSoft
[2012.09.23 22:46:45 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Skype
[2009.12.16 17:42:56 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Symantec
[2010.10.01 16:06:45 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Thunderbird
[2010.10.07 09:10:44 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Tific
[2011.09.14 21:28:20 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Tor
[2012.07.16 21:04:08 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\TuneUp Software
[2010.01.27 20:13:37 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\uTorrent
[2011.09.14 21:28:14 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Vidalia
[2011.06.16 15:04:48 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\vlc
[2012.07.14 17:46:08 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Vso
[2009.11.11 13:16:16 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\weather9
[2012.09.25 22:00:47 | 000,000,000 | ---D | M] -- C:\Users\matthes\AppData\Roaming\Winamp
 
< %APPDATA%\*.exe /s >
[2012.07.14 17:46:08 | 000,087,608 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\inst.exe
[2009.11.02 15:45:32 | 000,641,536 | ---- | M] (DirectCard Updater (Info)) -- C:\Users\matthes\AppData\Roaming\DirectCard Updater\uninstall.exe
[2011.09.29 09:19:14 | 000,929,680 | ---- | M] (Samsung) -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Kies.exe
[2011.09.29 09:19:18 | 000,278,928 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesDriverInstaller.exe
[2011.09.16 04:58:14 | 000,285,696 | ---- | M] (Samsung) -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesLogger.exe
[2011.09.29 09:19:16 | 003,508,112 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesTrayAgent.exe
[2011.07.26 10:27:16 | 000,140,800 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\ConnectionManager.exe
[2011.09.16 04:56:02 | 000,283,648 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceDataService.exe
[2011.09.16 04:56:04 | 000,666,624 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceManager.exe
[2011.09.29 09:19:20 | 000,067,472 | ---- | M] (Samsung) -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\Kies_Tutorial.exe
[2011.09.16 04:55:38 | 000,106,408 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\AgentInstaller.exe
[2011.09.16 04:55:38 | 000,101,288 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\AgentUpdate.exe
[2011.09.29 09:19:24 | 000,131,984 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\BinaryLoaderMgr.exe
[2011.09.29 09:19:26 | 000,020,880 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\KiesPDLR.exe
[2011.09.29 09:19:28 | 004,662,392 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\MediaModules\MyFreeCodecPack.exe
[2011.09.16 04:54:38 | 024,111,736 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
[2011.09.29 09:19:30 | 000,364,432 | ---- | M] (ml) -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\Temp\Kies.Update.exe
[2011.11.08 12:11:58 | 000,392,080 | ---- | M] (ml) -- C:\Users\matthes\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
[2009.10.28 17:34:44 | 034,119,048 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\weather9\avira_antivir_personal408_de.exe
[2009.11.03 15:48:12 | 001,010,176 | ---- | M] (Setup-Service) -- C:\Users\matthes\AppData\Roaming\weather9\uninstall.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\drivers\atapi.sys
[2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2008.07.20 11:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\ACER\Preload\Autorun\DRV\Intel Robson RBSMDL2G\Winall\Driver\IaStor.sys
[2008.07.20 11:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008.07.20 18:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\Windows\System32\drivers\iaStor.sys
[2008.07.20 11:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_7b6e77f6\iaStor.sys
[2008.04.20 18:29:38 | 000,317,464 | ---- | M] (Intel Corporation) MD5=9F1220113A3A7F4F08042C699324D073 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_18bd4575\iaStor.sys
[2008.07.20 11:44:54 | 000,402,456 | ---- | M] (Intel Corporation) MD5=FC28E90F2204D8FD147FA9BFA8A51C01 -- C:\ACER\Preload\Autorun\DRV\Intel Robson RBSMDL2G\Winall\Driver64\IaStor.sys
[2008.07.20 11:44:54 | 000,402,456 | ---- | M] (Intel Corporation) MD5=FC28E90F2204D8FD147FA9BFA8A51C01 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.21 04:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 04:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows\System32\user32.dll
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
[2008.01.21 04:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 04:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.21 04:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 04:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008.01.21 05:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008.01.21 05:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008.01.21 05:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >
[2006.11.02 15:01:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2006.11.02 15:01:49 | 000,032,534 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.09.18 23:19:25 | 000,000,422 | -H-- | C] () -- C:\Windows\Tasks\User_Feed_Synchronization-{52A60082-F11F-4DC0-815C-41B71B2E7AD3}.job
[2010.08.31 20:36:30 | 000,001,096 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2010.08.31 20:36:31 | 000,001,100 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.08.18 16:57:08 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job

< End of report >


cosinus 28.09.2012 19:41

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Hinweis: Falls Du Deinen Benutzernamen unkenntlich gemacht hast, musst Du das Ausgesternte in Deinen richtigen Benutzernamen wieder verwandeln, sonst funktioniert das Script nicht!!

Code:

:OTL
FF - user.js - File not found
DRV - (SYMNDISV) -- C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS File not found
DRV - (SYMFW) -- C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
FF - prefs.js..browser.search.defaultenginename: "search for firefox"
FF - prefs.js..browser.search.order.1: "search for firefox"
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "search for firefox"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: addon@gutscheine-live.de:1.1
FF - prefs.js..extensions.enabledAddons: finder@meingutscheincode.de:3.0.3
FF - prefs.js..extensions.enabledAddons: ciuvo-extension@billiger.de:1.0.462
FF - prefs.js..keyword.URL: "http://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
[2012.03.19 10:21:11 | 000,004,270 | ---- | M] () (No name found) -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\extensions\addon@gutscheine-live.de.xpi
[2011.05.12 11:25:21 | 000,002,448 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\searchplugins\safesearch.xml
[2009.12.18 22:01:14 | 000,001,201 | ---- | M] () -- C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\searchplugins\winamp-search.xml
[2009.09.17 15:42:23 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011.05.25 22:24:53 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:creator="billiger.de Sparberater" em:homepageURL="http://sparberater.billiger.de" em:iconURL="chrome://ciuvo/content/icons/billigerde/ciuvo_icon.png" em:id="ciuvo-extension@billiger.de" em:name="billiger.de Sparberater" em:optionsURL="" em:type="2" em:updateKey="MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDBHgpsx79ZmWK5YY6tA/iPgCxyzLL2SpWEBcJgQYa2qsiay+akqFqG0hr0TyGQOzkEnoRUkysljyzTHIUYXS3V7yorR7CN9+Vv/xC5RbSesfs8DOukKHWNQPrL57OvLzJIMrl86HLcKBiPZAQ4sAoITuYGnsr6CY3fZxYKTGNS/wIDAQAB" em:updateURL="http://ciuvo.com/ciuvo/update?id=%ITEM_ID%&amp;version=%ITEM_VERSION%&amp;maxversion=%ITEM_MAXAPPVERSION%&amp;status=%ITEM_STATUS%&amp;app_id=%APP_ID%&amp;app_version=%APP_VERSION%&amp;os=%APP_OS%&amp;locale=%APP_LOCALE%&amp;tag=billigerde" em:version="1.0.462">) -- C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de
[2011.12.09 19:23:32 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
O2 - BHO: (billiger.de Sparberater) - {92A6EE5B-5AE3-4159-9134-938BCA95B753} - C:\Program Files\billigerde\Internet Explorer\billigerde.dll (solute gmbh)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Lexmark Symbolleiste) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-1437981379-4010485698-1217947183-1000\Software\Policies\Microsoft\Internet Explorer\Recovery present
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{fc6e75ed-8782-11df-84a4-00238b010b31}\Shell\AutoRun\command - "" = Menu.exe
:Files
C:\Users\matthes\AppData\Roaming\*.exe
C:\ProgramData\WinMaximizer
C:\Users\All Users\WinMaximizer
C:\Users\matthes\AppData\Local\Microsoft\Windows\89
D:\xxx\Downloads\registrybooster*
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

boris1 28.09.2012 20:08

Im normalen Modus bekomme ich jetzt einen schwarzen Bildschirm. Der Mauszeiger ist noch zu sehen, mehr passiert aber nicht mehr.
Abgesicherter Modus klappt.

cosinus 28.09.2012 20:26

Das LOg vom Fix fehlt -.-

boris1 28.09.2012 20:29

Von allein hat es sich nicht geöffnet. Jetzt habe ich otl noch einmal gestartet, da kam dieses Log:

Code:

All processes killed
========== OTL ==========
Service SYMNDISV stopped successfully!
Service SYMNDISV deleted successfully!
File  C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS File not found not found.
Service SYMFW stopped successfully!
Service SYMFW deleted successfully!
File  C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS File not found not found.
Service NwlnkFwd stopped successfully!
Service NwlnkFwd deleted successfully!
File  system32\DRIVERS\nwlnkfwd.sys File not found not found.
Service NwlnkFlt stopped successfully!
Service NwlnkFlt deleted successfully!
File  system32\DRIVERS\nwlnkflt.sys File not found not found.
Prefs.js: "search for firefox" removed from browser.search.defaultenginename
Prefs.js: "search for firefox" removed from browser.search.order.1
Prefs.js: "moz2-ytff-" removed from browser.search.param.yahoo-fr
Prefs.js: "moz2-ytff-" removed from browser.search.param.yahoo-fr-cjkt
Prefs.js: "search for firefox" removed from browser.search.selectedEngine
Prefs.js: true removed from browser.search.useDBForOrder
Prefs.js: addon@gutscheine-live.de:1.1 removed from extensions.enabledAddons
Prefs.js: finder@meingutscheincode.de:3.0.3 removed from extensions.enabledAddons
Prefs.js: ciuvo-extension@billiger.de:1.0.462 removed from extensions.enabledAddons
Prefs.js: "hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q=" removed from keyword.URL
C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\extensions\addon@gutscheine-live.de.xpi moved successfully.
C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\searchplugins\safesearch.xml moved successfully.
C:\Users\matthes\AppData\Roaming\mozilla\firefox\profiles\38gpdnax.default\searchplugins\winamp-search.xml moved successfully.
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\defaults\preferences folder moved successfully.
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\defaults folder moved successfully.
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\chrome folder moved successfully.
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de\chrome\locale\en-US folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de\chrome\locale\de-DE folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de\chrome\locale folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de\chrome\content\lib folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de\chrome\content\icons\billigerde folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de\chrome\content\icons folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de\chrome\content folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de\chrome folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\ciuvo-extension@billiger.de folder moved successfully.
C:\Program Files\Mozilla Firefox\plugins\npwachk.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92A6EE5B-5AE3-4159-9134-938BCA95B753}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92A6EE5B-5AE3-4159-9134-938BCA95B753}\ deleted successfully.
C:\Program Files\billigerde\Internet Explorer\billigerde.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{0BF43445-2F28-4351-9252-17FE6E806AA0} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0BF43445-2F28-4351-9252-17FE6E806AA0}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{1017A80C-6F09-4548-A84D-EDD6AC9525F0} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1017A80C-6F09-4548-A84D-EDD6AC9525F0}\ deleted successfully.
C:\Program Files\Lexmark Toolbar\toolband.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableCAD deleted successfully.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery\ not found.
Registry key HKEY_USERS\S-1-5-21-1437981379-4010485698-1217947183-1000\Software\Policies\Microsoft\Internet Explorer\Recovery\ deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fc6e75ed-8782-11df-84a4-00238b010b31}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc6e75ed-8782-11df-84a4-00238b010b31}\ not found.
File Menu.exe not found.
========== FILES ==========
C:\Users\matthes\AppData\Roaming\inst.exe moved successfully.
C:\ProgramData\WinMaximizer\WinMaximizer\LOGS folder moved successfully.
C:\ProgramData\WinMaximizer\WinMaximizer\InstallCache\{B6796CC9-76A5-46C8-BF10-B057474FECA3} folder moved successfully.
C:\ProgramData\WinMaximizer\WinMaximizer\InstallCache folder moved successfully.
C:\ProgramData\WinMaximizer\WinMaximizer\Backup folder moved successfully.
C:\ProgramData\WinMaximizer\WinMaximizer folder moved successfully.
C:\ProgramData\WinMaximizer folder moved successfully.
File\Folder C:\Users\All Users\WinMaximizer not found.
C:\Users\matthes\AppData\Local\Microsoft\Windows\89 folder moved successfully.
File\Folder D:\xxx\Downloads\registrybooster* not found.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\matthes\Desktop\cmd.bat deleted successfully.
C:\Users\matthes\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Gast
 
User: matthes
->Temp folder emptied: 1096635 bytes
->Temporary Internet Files folder emptied: 721973 bytes
->Java cache emptied: 16994011 bytes
->FireFox cache emptied: 45263032 bytes
->Flash cache emptied: 580 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 99370653 bytes
 
Total Files Cleaned = 156,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.69.0 log created on 09282012_205042

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


cosinus 28.09.2012 20:58

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

boris1 28.09.2012 21:19

Im normalen Modus bekomme ich nur die Eieruhr zu sehen

cosinus 28.09.2012 21:31

Dann mach es bitte im abgesicherten Modus mit Netzwerktreibern

boris1 29.09.2012 06:55

Code:

07:51:46.0075 0316  TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
07:51:48.0088 0316  ============================================================
07:51:48.0088 0316  Current date / time: 2012/09/29 07:51:48.0088
07:51:48.0088 0316  SystemInfo:
07:51:48.0088 0316 
07:51:48.0088 0316  OS Version: 6.0.6002 ServicePack: 2.0
07:51:48.0088 0316  Product type: Workstation
07:51:48.0088 0316  ComputerName: MATTHES-PC
07:51:48.0088 0316  UserName: matthes
07:51:48.0088 0316  Windows directory: C:\Windows
07:51:48.0088 0316  System windows directory: C:\Windows
07:51:48.0088 0316  Processor architecture: Intel x86
07:51:48.0088 0316  Number of processors: 2
07:51:48.0088 0316  Page size: 0x1000
07:51:48.0088 0316  Boot type: Safe boot with network
07:51:48.0088 0316  ============================================================
07:51:48.0540 0316  Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
07:51:48.0540 0316  ============================================================
07:51:48.0540 0316  \Device\Harddisk0\DR0:
07:51:48.0540 0316  MBR partitions:
07:51:48.0540 0316  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1400800, BlocksNum 0x9C18566
07:51:48.0571 0316  ============================================================
07:51:48.0634 0316  C: <-> \Device\Harddisk0\DR0\Partition1
07:51:48.0634 0316  ============================================================
07:51:48.0634 0316  Initialize success
07:51:48.0634 0316  ============================================================
07:52:26.0214 0944  ============================================================
07:52:26.0214 0944  Scan started
07:52:26.0214 0944  Mode: Manual; SigCheck; TDLFS;
07:52:26.0214 0944  ============================================================
07:52:26.0323 0944  ================ Scan system memory ========================
07:52:26.0323 0944  System memory - ok
07:52:26.0323 0944  ================ Scan services =============================
07:52:26.0589 0944  [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon        C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
07:52:26.0698 0944  ACDaemon - ok
07:52:26.0823 0944  [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI            C:\Windows\system32\drivers\acpi.sys
07:52:26.0854 0944  ACPI - ok
07:52:26.0901 0944  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
07:52:26.0916 0944  AdobeARMservice - ok
07:52:26.0994 0944  [ E12CFCF1DDBFC50948A75E6E38793225 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
07:52:27.0010 0944  AdobeFlashPlayerUpdateSvc - ok
07:52:27.0057 0944  [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
07:52:27.0088 0944  adp94xx - ok
07:52:27.0150 0944  [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci        C:\Windows\system32\drivers\adpahci.sys
07:52:27.0166 0944  adpahci - ok
07:52:27.0197 0944  [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
07:52:27.0213 0944  adpu160m - ok
07:52:27.0228 0944  [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
07:52:27.0244 0944  adpu320 - ok
07:52:27.0291 0944  [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
07:52:27.0431 0944  AeLookupSvc - ok
07:52:27.0478 0944  [ FE3EA6E9AFC1A78E6EDCA121E006AFB7 ] Afc            C:\Windows\system32\drivers\Afc.sys
07:52:27.0493 0944  Afc - ok
07:52:27.0540 0944  [ 3911B972B55FEA0478476B2E777B29FA ] AFD            C:\Windows\system32\drivers\afd.sys
07:52:27.0603 0944  AFD - ok
07:52:27.0649 0944  [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440          C:\Windows\system32\drivers\agp440.sys
07:52:27.0649 0944  agp440 - ok
07:52:27.0696 0944  [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
07:52:27.0712 0944  aic78xx - ok
07:52:27.0743 0944  [ 4490B8BDF38750458EB9B24835FDA8FE ] AlfaFF          C:\Windows\system32\Drivers\AlfaFF.sys
07:52:27.0759 0944  AlfaFF - ok
07:52:27.0790 0944  [ A1545B731579895D8CC44FC0481C1192 ] ALG            C:\Windows\System32\alg.exe
07:52:27.0961 0944  ALG - ok
07:52:27.0977 0944  [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide          C:\Windows\system32\drivers\aliide.sys
07:52:27.0977 0944  aliide - ok
07:52:27.0993 0944  [ C47344BC706E5F0B9DCE369516661578 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
07:52:28.0008 0944  amdagp - ok
07:52:28.0024 0944  [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide          C:\Windows\system32\drivers\amdide.sys
07:52:28.0039 0944  amdide - ok
07:52:28.0071 0944  [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7          C:\Windows\system32\drivers\amdk7.sys
07:52:28.0149 0944  AmdK7 - ok
07:52:28.0164 0944  [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
07:52:28.0195 0944  AmdK8 - ok
07:52:28.0227 0944  [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo        C:\Windows\System32\appinfo.dll
07:52:28.0289 0944  Appinfo - ok
07:52:28.0320 0944  [ 5D2888182FB46632511ACEE92FDAD522 ] arc            C:\Windows\system32\drivers\arc.sys
07:52:28.0320 0944  arc - ok
07:52:28.0351 0944  [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
07:52:28.0367 0944  arcsas - ok
07:52:28.0398 0944  [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
07:52:28.0429 0944  AsyncMac - ok
07:52:28.0461 0944  [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi          C:\Windows\system32\drivers\atapi.sys
07:52:28.0476 0944  atapi - ok
07:52:28.0523 0944  [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
07:52:28.0570 0944  AudioEndpointBuilder - ok
07:52:28.0570 0944  [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv        C:\Windows\System32\Audiosrv.dll
07:52:28.0601 0944  Audiosrv - ok
07:52:28.0632 0944  [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep            C:\Windows\system32\drivers\Beep.sys
07:52:28.0695 0944  Beep - ok
07:52:28.0757 0944  [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE            C:\Windows\System32\bfe.dll
07:52:28.0804 0944  BFE - ok
07:52:28.0991 0944  [ C364F02969E9A842321DD91BCFF749D4 ] BHDrvx86        C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\BASHDefs\20120919.001\BHDrvx86.sys
07:52:29.0053 0944  BHDrvx86 - ok
07:52:29.0147 0944  [ 93952506C6D67330367F7E7934B6A02F ] BITS            C:\Windows\System32\qmgr.dll
07:52:29.0209 0944  BITS - ok
07:52:29.0225 0944  [ D4DF28447741FD3D953526E33A617397 ] blbdrive        C:\Windows\system32\drivers\blbdrive.sys
07:52:29.0256 0944  blbdrive - ok
07:52:29.0287 0944  [ 35F376253F687BDE63976CCB3F2108CA ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
07:52:29.0334 0944  bowser - ok
07:52:29.0381 0944  [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
07:52:29.0412 0944  BrFiltLo - ok
07:52:29.0443 0944  [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
07:52:29.0506 0944  BrFiltUp - ok
07:52:29.0521 0944  [ B1564976D98E91FC764D5DC28A0297DA ] Bridge          C:\Windows\system32\DRIVERS\bridge.sys
07:52:29.0568 0944  Bridge - ok
07:52:29.0599 0944  [ B1564976D98E91FC764D5DC28A0297DA ] BridgeMP        C:\Windows\system32\DRIVERS\bridge.sys
07:52:29.0631 0944  BridgeMP - ok
07:52:29.0677 0944  [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser        C:\Windows\System32\browser.dll
07:52:29.0740 0944  Browser - ok
07:52:29.0771 0944  [ B304E75CFF293029EDDF094246747113 ] Brserid        C:\Windows\system32\drivers\brserid.sys
07:52:29.0943 0944  Brserid - ok
07:52:29.0989 0944  [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
07:52:30.0036 0944  BrSerWdm - ok
07:52:30.0067 0944  [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
07:52:30.0145 0944  BrUsbMdm - ok
07:52:30.0161 0944  [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
07:52:30.0208 0944  BrUsbSer - ok
07:52:30.0255 0944  [ 6D39C954799B63BA866910234CF7D726 ] BthEnum        C:\Windows\system32\DRIVERS\BthEnum.sys
07:52:30.0301 0944  BthEnum - ok
07:52:30.0333 0944  [ 9A966A8E86D1771911AE34A20D11BFF3 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
07:52:30.0379 0944  BTHMODEM - ok
07:52:30.0411 0944  [ 5904EFA25F829BF84EA6FB045134A1D8 ] BthPan          C:\Windows\system32\DRIVERS\bthpan.sys
07:52:30.0457 0944  BthPan - ok
07:52:30.0489 0944  [ 611FF3F2F095C8D4A6D4CFD9DCC09793 ] BTHPORT        C:\Windows\system32\Drivers\BTHport.sys
07:52:30.0551 0944  BTHPORT - ok
07:52:30.0567 0944  [ A4C8377FA4A994E07075107DBE2E3DCE ] BthServ        C:\Windows\System32\bthserv.dll
07:52:30.0613 0944  BthServ - ok
07:52:30.0660 0944  [ D330803EAB2A15CAEC7F011F1D4CB30E ] BTHUSB          C:\Windows\system32\Drivers\BTHUSB.sys
07:52:30.0691 0944  BTHUSB - ok
07:52:30.0723 0944  [ 3EA1A20DC0CA1AD23E7AA8C37A91BCD1 ] btwaudio        C:\Windows\system32\drivers\btwaudio.sys
07:52:30.0738 0944  btwaudio - ok
07:52:30.0769 0944  [ 195872E48A7FB01F8BC9B800F70F4054 ] btwavdt        C:\Windows\system32\drivers\btwavdt.sys
07:52:30.0769 0944  btwavdt - ok
07:52:30.0785 0944  [ 0724E7D6C9B6A289EDDDA33FA8176E80 ] btwrchid        C:\Windows\system32\DRIVERS\btwrchid.sys
07:52:30.0801 0944  btwrchid - ok
07:52:30.0894 0944  [ ACE85AF1C31F68BDFEE9333F6592917E ] ccSet_N360      C:\Windows\system32\drivers\N360\0603000.00E\ccSetx86.sys
07:52:30.0894 0944  ccSet_N360 - ok
07:52:30.0925 0944  [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
07:52:30.0988 0944  cdfs - ok
07:52:31.0035 0944  [ 6B4BFFB9BECD728097024276430DB314 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
07:52:31.0081 0944  cdrom - ok
07:52:31.0128 0944  [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc    C:\Windows\System32\certprop.dll
07:52:31.0175 0944  CertPropSvc - ok
07:52:31.0206 0944  [ E5D4133F37219DBCFE102BC61072589D ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
07:52:31.0253 0944  circlass - ok
07:52:31.0300 0944  [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS            C:\Windows\system32\CLFS.sys
07:52:31.0315 0944  CLFS - ok
07:52:31.0393 0944  [ 5CA9B1062C0C3E3AE19C23AD9D8A5048 ] CLHNService    C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
07:52:31.0440 0944  CLHNService ( UnsignedFile.Multi.Generic ) - warning
07:52:31.0440 0944  CLHNService - detected UnsignedFile.Multi.Generic (1)
07:52:31.0503 0944  [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
07:52:31.0518 0944  clr_optimization_v2.0.50727_32 - ok
07:52:31.0581 0944  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
07:52:31.0627 0944  clr_optimization_v4.0.30319_32 - ok
07:52:31.0659 0944  [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
07:52:31.0705 0944  CmBatt - ok
07:52:31.0721 0944  [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
07:52:31.0737 0944  cmdide - ok
07:52:31.0752 0944  [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
07:52:31.0752 0944  Compbatt - ok
07:52:31.0768 0944  COMSysApp - ok
07:52:31.0846 0944  cpuz132 - ok
07:52:31.0861 0944  [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
07:52:31.0877 0944  crcdisk - ok
07:52:31.0893 0944  [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe          C:\Windows\system32\drivers\crusoe.sys
07:52:31.0924 0944  Crusoe - ok
07:52:31.0971 0944  [ 75C6A297E364014840B48ECCD7525E30 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
07:52:32.0017 0944  CryptSvc - ok
07:52:32.0080 0944  [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch      C:\Windows\system32\rpcss.dll
07:52:32.0142 0944  DcomLaunch - ok
07:52:32.0173 0944  [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
07:52:32.0205 0944  DfsC - ok
07:52:32.0298 0944  [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR            C:\Windows\system32\DFSR.exe
07:52:32.0454 0944  DFSR - ok
07:52:32.0548 0944  [ 9028559C132146FB75EB7ACF384B086A ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
07:52:32.0610 0944  Dhcp - ok
07:52:32.0657 0944  [ 5D4AEFC3386920236A548271F8F1AF6A ] disk            C:\Windows\system32\drivers\disk.sys
07:52:32.0673 0944  disk - ok
07:52:32.0688 0944  DKbFltr - ok
07:52:32.0719 0944  [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache        C:\Windows\System32\dnsrslvr.dll
07:52:32.0766 0944  Dnscache - ok
07:52:32.0797 0944  [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc        C:\Windows\System32\dot3svc.dll
07:52:32.0844 0944  dot3svc - ok
07:52:32.0891 0944  [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS            C:\Windows\system32\dps.dll
07:52:32.0938 0944  DPS - ok
07:52:32.0969 0944  [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
07:52:33.0016 0944  drmkaud - ok
07:52:33.0063 0944  [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
07:52:33.0094 0944  DXGKrnl - ok
07:52:33.0125 0944  [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60          C:\Windows\system32\DRIVERS\E1G60I32.sys
07:52:33.0172 0944  E1G60 - ok
07:52:33.0219 0944  [ C0B95E40D85CD807D614E264248A45B9 ] EapHost        C:\Windows\System32\eapsvc.dll
07:52:33.0250 0944  EapHost - ok
07:52:33.0281 0944  [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache          C:\Windows\system32\drivers\ecache.sys
07:52:33.0297 0944  Ecache - ok
07:52:33.0359 0944  [ 85B8B4032A895A746D46A288A9B30DED ] eeCtrl          C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
07:52:33.0375 0944  eeCtrl - ok
07:52:33.0437 0944  [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
07:52:33.0515 0944  ehRecvr - ok
07:52:33.0531 0944  [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched        C:\Windows\ehome\ehsched.exe
07:52:33.0546 0944  ehSched - ok
07:52:33.0546 0944  [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart        C:\Windows\ehome\ehstart.dll
07:52:33.0593 0944  ehstart - ok
07:52:33.0655 0944  [ 23B62471681A124889978F6295B3F4C6 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
07:52:33.0671 0944  elxstor - ok
07:52:33.0718 0944  [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
07:52:33.0780 0944  EMDMgmt - ok
07:52:33.0827 0944  [ B5A8A04A6E5B4E86B95B1553AA918F5F ] EraserUtilRebootDrv C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
07:52:33.0843 0944  EraserUtilRebootDrv - ok
07:52:33.0858 0944  [ 3DB974F3935483555D7148663F726C61 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
07:52:33.0905 0944  ErrDev - ok
07:52:33.0967 0944  [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem    C:\Windows\system32\es.dll
07:52:34.0030 0944  EventSystem - ok
07:52:34.0123 0944  [ 54B6E150BFF4A47EB0D204119D262E46 ] EvtEng          C:\Program Files\Intel\WiFi\bin\EvtEng.exe
07:52:34.0170 0944  EvtEng ( UnsignedFile.Multi.Generic ) - warning
07:52:34.0170 0944  EvtEng - detected UnsignedFile.Multi.Generic (1)
07:52:34.0217 0944  [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat          C:\Windows\system32\drivers\exfat.sys
07:52:34.0248 0944  exfat - ok
07:52:34.0295 0944  Fabs - ok
07:52:34.0342 0944  [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
07:52:34.0373 0944  fastfat - ok
07:52:34.0420 0944  [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
07:52:34.0482 0944  fdc - ok
07:52:34.0513 0944  [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost        C:\Windows\system32\fdPHost.dll
07:52:34.0545 0944  fdPHost - ok
07:52:34.0560 0944  [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub        C:\Windows\system32\fdrespub.dll
07:52:34.0607 0944  FDResPub - ok
07:52:34.0654 0944  [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
07:52:34.0654 0944  FileInfo - ok
07:52:34.0685 0944  [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
07:52:34.0716 0944  Filetrace - ok
07:52:34.0825 0944  [ FFF1130F7C9FA01D093A1EDFC5CCE8FC ] FirebirdServerMAGIXInstance C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
07:52:35.0028 0944  FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - warning
07:52:35.0028 0944  FirebirdServerMAGIXInstance - detected UnsignedFile.Multi.Generic (1)
07:52:35.0044 0944  [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
07:52:35.0075 0944  flpydisk - ok
07:52:35.0106 0944  [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
07:52:35.0122 0944  FltMgr - ok
07:52:35.0169 0944  [ 8CE364388C8ECA59B14B539179276D44 ] FontCache      C:\Windows\system32\FntCache.dll
07:52:35.0262 0944  FontCache - ok
07:52:35.0325 0944  [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
07:52:35.0340 0944  FontCache3.0.0.0 - ok
07:52:35.0371 0944  [ 10398B515653442A5B89FDF6A1D06180 ] FsUsbExDisk    C:\Windows\system32\FsUsbExDisk.SYS
07:52:35.0387 0944  FsUsbExDisk - ok
07:52:35.0434 0944  [ 2A0D3EE7D2D42A3A812D3E6795A2382B ] FsUsbExService  C:\Windows\system32\FsUsbExService.Exe
07:52:35.0449 0944  FsUsbExService - ok
07:52:35.0465 0944  [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
07:52:35.0512 0944  Fs_Rec - ok
07:52:35.0543 0944  [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
07:52:35.0543 0944  gagp30kx - ok
07:52:35.0590 0944  [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc          C:\Windows\System32\gpsvc.dll
07:52:35.0637 0944  gpsvc - ok
07:52:35.0715 0944  [ F02A533F517EB38333CB12A9E8963773 ] gupdate        C:\Program Files\Google\Update\GoogleUpdate.exe
07:52:35.0730 0944  gupdate - ok
07:52:35.0746 0944  [ F02A533F517EB38333CB12A9E8963773 ] gupdatem        C:\Program Files\Google\Update\GoogleUpdate.exe
07:52:35.0761 0944  gupdatem - ok
07:52:35.0808 0944  [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
07:52:35.0855 0944  HdAudAddService - ok
07:52:35.0917 0944  [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
07:52:35.0995 0944  HDAudBus - ok
07:52:36.0042 0944  [ FCB3F4BE408F72C1BD81BCABA87FC22F ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
07:52:36.0073 0944  HidBth - ok
07:52:36.0089 0944  [ D8DF3722D5E961BAA1292AA2F12827E2 ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
07:52:36.0120 0944  HidIr - ok
07:52:36.0151 0944  [ 84067081F3318162797385E11A8F0582 ] hidserv        C:\Windows\system32\hidserv.dll
07:52:36.0183 0944  hidserv - ok
07:52:36.0229 0944  [ CCA4B519B17E23A00B826C55716809CC ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
07:52:36.0261 0944  HidUsb - ok
07:52:36.0307 0944  [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc          C:\Windows\system32\kmsvc.dll
07:52:36.0354 0944  hkmsvc - ok
07:52:36.0385 0944  [ D308726110A6011514DCDFC6E3FC21F2 ] hotcore3        C:\Windows\system32\DRIVERS\hotcore3.sys
07:52:36.0385 0944  hotcore3 - ok
07:52:36.0432 0944  [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
07:52:36.0448 0944  HpCISSs - ok
07:52:36.0510 0944  [ 46D67209550973257601A533E2AC5785 ] HSFHWAZL        C:\Windows\system32\DRIVERS\VSTAZL3.SYS
07:52:36.0573 0944  HSFHWAZL - ok
07:52:36.0619 0944  [ FADD7095163CB3CB4073793EBB50FE75 ] HSF_DPV        C:\Windows\system32\DRIVERS\HSX_DPV.sys
07:52:36.0744 0944  HSF_DPV - ok
07:52:36.0791 0944  [ 058783BEDD17615D1FECE09F77960436 ] HSXHWAZL        C:\Windows\system32\DRIVERS\HSXHWAZL.sys
07:52:36.0822 0944  HSXHWAZL - ok
07:52:36.0838 0944  [ F870AA3E254628EBEAFE754108D664DE ] HTTP            C:\Windows\system32\drivers\HTTP.sys
07:52:36.0916 0944  HTTP - ok
07:52:36.0947 0944  [ C6B032D69650985468160FC9937CF5B4 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
07:52:36.0947 0944  i2omp - ok
07:52:37.0009 0944  [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
07:52:37.0041 0944  i8042prt - ok
07:52:37.0103 0944  [ 3E42C4691AAD4B1E8D0466F9CBF05CBE ] IAANTMON        C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
07:52:37.0119 0944  IAANTMON - ok
07:52:37.0181 0944  [ 707C1692214B1C290271067197F075F6 ] iaStor          C:\Windows\system32\DRIVERS\iaStor.sys
07:52:37.0197 0944  iaStor - ok
07:52:37.0212 0944  [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
07:52:37.0228 0944  iaStorV - ok
07:52:37.0275 0944  [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc          C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
07:52:37.0321 0944  idsvc - ok
07:52:37.0415 0944  [ 404FB2AAF532BC7BBACC8880BE401C74 ] IDSVix86        C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\IPSDefs\20120921.001\IDSvix86.sys
07:52:37.0446 0944  IDSVix86 - ok
07:52:37.0618 0944  [ 33FFC1E1117C4BE00A07AEDD72AE68B1 ] IGBASVC        C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
07:52:37.0789 0944  IGBASVC ( UnsignedFile.Multi.Generic ) - warning
07:52:37.0789 0944  IGBASVC - detected UnsignedFile.Multi.Generic (1)
07:52:37.0821 0944  [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
07:52:37.0836 0944  iirsp - ok
07:52:37.0883 0944  [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT          C:\Windows\System32\ikeext.dll
07:52:37.0930 0944  IKEEXT - ok
07:52:37.0992 0944  [ 219CA9A36D6DE2EC04F958C907673436 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
07:52:38.0226 0944  IntcAzAudAddService - ok
07:52:38.0257 0944  [ 83AA759F3189E6370C30DE5DC5590718 ] intelide        C:\Windows\system32\drivers\intelide.sys
07:52:38.0273 0944  intelide - ok
07:52:38.0304 0944  [ 224191001E78C89DFA78924C3EA595FF ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
07:52:38.0351 0944  intelppm - ok
07:52:38.0382 0944  [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
07:52:38.0429 0944  IPBusEnum - ok
07:52:38.0476 0944  [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
07:52:38.0523 0944  IpFilterDriver - ok
07:52:38.0569 0944  [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
07:52:38.0616 0944  iphlpsvc - ok
07:52:38.0616 0944  IpInIp - ok
07:52:38.0647 0944  [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
07:52:38.0679 0944  IPMIDRV - ok
07:52:38.0679 0944  [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
07:52:38.0741 0944  IPNAT - ok
07:52:38.0757 0944  [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
07:52:38.0788 0944  IRENUM - ok
07:52:38.0819 0944  [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
07:52:38.0819 0944  isapnp - ok
07:52:38.0866 0944  [ 232FA340531D940AAC623B121A595034 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
07:52:38.0881 0944  iScsiPrt - ok
07:52:38.0897 0944  [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
07:52:38.0913 0944  iteatapi - ok
07:52:38.0928 0944  [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid        C:\Windows\system32\drivers\iteraid.sys
07:52:38.0944 0944  iteraid - ok
07:52:38.0959 0944  [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
07:52:38.0975 0944  kbdclass - ok
07:52:39.0053 0944  [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
07:52:39.0084 0944  kbdhid - ok
07:52:39.0100 0944  [ A3E186B4B935905B829219502557314E ] KeyIso          C:\Windows\system32\lsass.exe
07:52:39.0147 0944  KeyIso - ok
07:52:39.0193 0944  [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
07:52:39.0225 0944  KSecDD - ok
07:52:39.0256 0944  [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm          C:\Windows\system32\msdtckrm.dll
07:52:39.0287 0944  KtmRm - ok
07:52:39.0443 0944  [ 24ABDDEB766C8459F9D562EB083B6CB8 ] L1E            C:\Windows\system32\DRIVERS\L1E60x86.sys
07:52:39.0490 0944  L1E - ok
07:52:39.0521 0944  [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer    C:\Windows\system32\srvsvc.dll
07:52:39.0583 0944  LanmanServer - ok
07:52:39.0630 0944  [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
07:52:39.0661 0944  LanmanWorkstation - ok
07:52:39.0724 0944  [ 793FF718477345CD5D232C50BED1E452 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
07:52:39.0739 0944  LightScribeService ( UnsignedFile.Multi.Generic ) - warning
07:52:39.0739 0944  LightScribeService - detected UnsignedFile.Multi.Generic (1)
07:52:39.0771 0944  [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
07:52:39.0817 0944  lltdio - ok
07:52:39.0864 0944  [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
07:52:39.0895 0944  lltdsvc - ok
07:52:39.0911 0944  [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts        C:\Windows\System32\lmhsvc.dll
07:52:39.0973 0944  lmhosts - ok
07:52:39.0989 0944  [ C7E15E82879BF3235B559563D4185365 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
07:52:40.0005 0944  LSI_FC - ok
07:52:40.0036 0944  [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
07:52:40.0051 0944  LSI_SAS - ok
07:52:40.0067 0944  [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
07:52:40.0083 0944  LSI_SCSI - ok
07:52:40.0098 0944  [ 8F5C7426567798E62A3B3614965D62CC ] luafv          C:\Windows\system32\drivers\luafv.sys
07:52:40.0145 0944  luafv - ok
07:52:40.0223 0944  [ 2349335A8033FD9834D1C401EAE1C9BF ] lxeaCATSCustConnectService C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxeaserv.exe
07:52:40.0254 0944  lxeaCATSCustConnectService - ok
07:52:40.0270 0944  lxea_device - ok
07:52:40.0301 0944  [ 65E794E86468B61F2BC79ABC48BC4433 ] MBAMProtector  C:\Windows\system32\drivers\mbam.sys
07:52:40.0317 0944  MBAMProtector - ok
07:52:40.0395 0944  [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler  C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
07:52:40.0410 0944  MBAMScheduler - ok
07:52:40.0488 0944  [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
07:52:40.0535 0944  MBAMService - ok
07:52:40.0597 0944  [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
07:52:40.0597 0944  Mcx2Svc - ok
07:52:40.0629 0944  [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk        C:\Windows\system32\DRIVERS\mdmxsdk.sys
07:52:40.0660 0944  mdmxsdk - ok
07:52:40.0707 0944  [ 0001CE609D66632FA17B84705F658879 ] megasas        C:\Windows\system32\drivers\megasas.sys
07:52:40.0707 0944  megasas - ok
07:52:40.0738 0944  [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR          C:\Windows\system32\drivers\megasr.sys
07:52:40.0753 0944  MegaSR - ok
07:52:40.0816 0944  [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS          C:\Windows\system32\mmcss.dll
07:52:40.0847 0944  MMCSS - ok
07:52:40.0878 0944  [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem          C:\Windows\system32\drivers\modem.sys
07:52:40.0909 0944  Modem - ok
07:52:40.0909 0944  [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
07:52:40.0956 0944  monitor - ok
07:52:40.0987 0944  [ 5BF6A1326A335C5298477754A506D263 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
07:52:41.0003 0944  mouclass - ok
07:52:41.0003 0944  [ 93B8D4869E12CFBE663915502900876F ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
07:52:41.0050 0944  mouhid - ok
07:52:41.0081 0944  [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
07:52:41.0097 0944  MountMgr - ok
07:52:41.0128 0944  [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
07:52:41.0143 0944  MozillaMaintenance - ok
07:52:41.0175 0944  [ 511D011289755DD9F9A7579FB0B064E6 ] mpio            C:\Windows\system32\drivers\mpio.sys
07:52:41.0190 0944  mpio - ok
07:52:41.0190 0944  [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
07:52:41.0237 0944  mpsdrv - ok
07:52:41.0268 0944  [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc          C:\Windows\system32\mpssvc.dll
07:52:41.0299 0944  MpsSvc - ok
07:52:41.0346 0944  [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
07:52:41.0346 0944  Mraid35x - ok
07:52:41.0377 0944  [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
07:52:41.0424 0944  MRxDAV - ok
07:52:41.0440 0944  [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
07:52:41.0487 0944  mrxsmb - ok
07:52:41.0533 0944  [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
07:52:41.0565 0944  mrxsmb10 - ok
07:52:41.0596 0944  [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
07:52:41.0627 0944  mrxsmb20 - ok
07:52:41.0674 0944  [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci          C:\Windows\system32\drivers\msahci.sys
07:52:41.0689 0944  msahci - ok
07:52:41.0705 0944  [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
07:52:41.0721 0944  msdsm - ok
07:52:41.0752 0944  [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC          C:\Windows\System32\msdtc.exe
07:52:41.0783 0944  MSDTC - ok
07:52:41.0814 0944  [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
07:52:41.0845 0944  Msfs - ok
07:52:41.0877 0944  [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
07:52:41.0892 0944  msisadrv - ok
07:52:41.0923 0944  [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
07:52:41.0970 0944  MSiSCSI - ok
07:52:41.0970 0944  msiserver - ok
07:52:42.0001 0944  [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
07:52:42.0048 0944  MSKSSRV - ok
07:52:42.0064 0944  [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
07:52:42.0111 0944  MSPCLOCK - ok
07:52:42.0111 0944  [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
07:52:42.0157 0944  MSPQM - ok
07:52:42.0204 0944  [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
07:52:42.0220 0944  MsRPC - ok
07:52:42.0235 0944  [ E384487CB84BE41D09711C30CA79646C ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
07:52:42.0251 0944  mssmbios - ok
07:52:42.0251 0944  [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
07:52:42.0298 0944  MSTEE - ok
07:52:42.0329 0944  [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup            C:\Windows\system32\Drivers\mup.sys
07:52:42.0329 0944  Mup - ok
07:52:42.0391 0944  [ F2840DBFE9322F35557219AE82CC4597 ] N360            C:\Program Files\Norton 360\Engine\6.3.0.14\ccSvcHst.exe
07:52:42.0407 0944  N360 - ok
07:52:42.0438 0944  [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent        C:\Windows\system32\qagentRT.dll
07:52:42.0485 0944  napagent - ok
07:52:42.0516 0944  [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
07:52:42.0547 0944  NativeWifiP - ok
07:52:42.0641 0944  [ 8E4C77AD9BB279900C00F870CC0C674B ] NAVENG          C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120922.008\NAVENG.SYS
07:52:42.0657 0944  NAVENG - ok
07:52:42.0703 0944  [ 826F699B69E88A3920C70F344DD42D88 ] NAVEX15        C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120922.008\NAVEX15.SYS
07:52:42.0781 0944  NAVEX15 - ok
07:52:42.0859 0944  [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS            C:\Windows\system32\drivers\ndis.sys
07:52:42.0891 0944  NDIS - ok
07:52:42.0922 0944  [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
07:52:42.0953 0944  NdisTapi - ok
07:52:42.0969 0944  [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
07:52:43.0000 0944  Ndisuio - ok
07:52:43.0031 0944  [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
07:52:43.0062 0944  NdisWan - ok
07:52:43.0109 0944  [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
07:52:43.0156 0944  NDProxy - ok
07:52:43.0187 0944  [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
07:52:43.0203 0944  NetBIOS - ok
07:52:43.0234 0944  [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
07:52:43.0281 0944  netbt - ok
07:52:43.0312 0944  [ A3E186B4B935905B829219502557314E ] Netlogon        C:\Windows\system32\lsass.exe
07:52:43.0312 0944  Netlogon - ok
07:52:43.0359 0944  [ C8052711DAECC48B982434C5116CA401 ] Netman          C:\Windows\System32\netman.dll
07:52:43.0390 0944  Netman - ok
07:52:43.0421 0944  [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm        C:\Windows\System32\netprofm.dll
07:52:43.0452 0944  netprofm - ok
07:52:43.0483 0944  [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
07:52:43.0499 0944  NetTcpPortSharing - ok
07:52:43.0608 0944  [ 8DE67BD902095A13329FD82C85A1FA09 ] NETw5v32        C:\Windows\system32\DRIVERS\NETw5v32.sys
07:52:43.0827 0944  NETw5v32 - ok
07:52:43.0842 0944  [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
07:52:43.0858 0944  nfrd960 - ok
07:52:43.0889 0944  [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc          C:\Windows\System32\nlasvc.dll
07:52:43.0920 0944  NlaSvc - ok
07:52:43.0951 0944  [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
07:52:43.0967 0944  Npfs - ok
07:52:43.0983 0944  [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi            C:\Windows\system32\nsisvc.dll
07:52:44.0029 0944  nsi - ok
07:52:44.0061 0944  [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
07:52:44.0107 0944  nsiproxy - ok
07:52:44.0154 0944  [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
07:52:44.0217 0944  Ntfs - ok
07:52:44.0263 0944  [ 2757D2BA59AEE155209E24942AB127C9 ] NTIDrvr        C:\Windows\system32\DRIVERS\NTIDrvr.sys
07:52:44.0279 0944  NTIDrvr - ok
07:52:44.0357 0944  [ 547BFA3591C70674B0BFC99354AB78B3 ] NTIPPKernel    C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys
07:52:44.0373 0944  NTIPPKernel ( UnsignedFile.Multi.Generic ) - warning
07:52:44.0373 0944  NTIPPKernel - detected UnsignedFile.Multi.Generic (1)
07:52:44.0388 0944  [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi      C:\Windows\system32\drivers\ntrigdigi.sys
07:52:44.0451 0944  ntrigdigi - ok
07:52:44.0466 0944  [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null            C:\Windows\system32\drivers\Null.sys
07:52:44.0513 0944  Null - ok
07:52:44.0575 0944  [ 2C7AC27710E8D41C1EB7D1599187D237 ] NVHDA          C:\Windows\system32\drivers\nvhda32v.sys
07:52:44.0591 0944  NVHDA - ok
07:52:44.0763 0944  [ CB0D6F8F65B8766FF2AAAA78881FD9F8 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
07:52:45.0137 0944  nvlddmkm - ok
07:52:45.0168 0944  [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
07:52:45.0184 0944  nvraid - ok
07:52:45.0215 0944  [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
07:52:45.0231 0944  nvstor - ok
07:52:45.0246 0944  [ 15315BB51E9025FE41B482681C6E7BA2 ] nvsvc          C:\Windows\system32\nvvsvc.exe
07:52:45.0262 0944  nvsvc - ok
07:52:45.0293 0944  [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
07:52:45.0309 0944  nv_agp - ok
07:52:45.0324 0944  [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
07:52:45.0371 0944  ohci1394 - ok
07:52:45.0449 0944  [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc        C:\Windows\system32\p2psvc.dll
07:52:45.0511 0944  p2pimsvc - ok
07:52:45.0527 0944  [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc          C:\Windows\system32\p2psvc.dll
07:52:45.0558 0944  p2psvc - ok
07:52:45.0605 0944  [ 0FA9B5055484649D63C303FE404E5F4D ] Parport        C:\Windows\system32\drivers\parport.sys
07:52:45.0667 0944  Parport - ok
07:52:45.0730 0944  [ B9C2B89F08670E159F7181891E449CD9 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
07:52:45.0730 0944  partmgr - ok
07:52:45.0761 0944  [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm          C:\Windows\system32\drivers\parvdm.sys
07:52:45.0808 0944  Parvdm - ok
07:52:45.0839 0944  [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc          C:\Windows\System32\pcasvc.dll
07:52:45.0870 0944  PcaSvc - ok
07:52:45.0901 0944  [ 941DC1D19E7E8620F40BBC206981EFDB ] pci            C:\Windows\system32\drivers\pci.sys
07:52:45.0917 0944  pci - ok
07:52:45.0948 0944  [ FC175F5DDAB666D7F4D17449A547626F ] pciide          C:\Windows\system32\drivers\pciide.sys
07:52:45.0948 0944  pciide - ok
07:52:45.0979 0944  [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
07:52:45.0995 0944  pcmcia - ok
07:52:46.0011 0944  [ 5B6C11DE7E839C05248CED8825470FEF ] pcouffin        C:\Windows\system32\Drivers\pcouffin.sys
07:52:46.0073 0944  pcouffin - ok
07:52:46.0120 0944  [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
07:52:46.0213 0944  PEAUTH - ok
07:52:46.0260 0944  [ B1689DF169143F57053F795390C99DB3 ] pla            C:\Windows\system32\pla.dll
07:52:46.0338 0944  pla - ok
07:52:46.0401 0944  [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
07:52:46.0447 0944  PlugPlay - ok
07:52:46.0494 0944  [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
07:52:46.0557 0944  PNRPAutoReg - ok
07:52:46.0619 0944  [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc        C:\Windows\system32\p2psvc.dll
07:52:46.0650 0944  PNRPsvc - ok
07:52:46.0744 0944  [ 94CE8D68338E72B915468D10ECEF07BE ] Polar Daemon    C:\Program Files\Polar\Daemon\polard.exe
07:52:46.0759 0944  Polar Daemon ( UnsignedFile.Multi.Generic ) - warning
07:52:46.0759 0944  Polar Daemon - detected UnsignedFile.Multi.Generic (1)
07:52:46.0791 0944  [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
07:52:46.0853 0944  PolicyAgent - ok
07:52:46.0884 0944  [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
07:52:46.0931 0944  PptpMiniport - ok
07:52:46.0947 0944  [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor      C:\Windows\system32\drivers\processr.sys
07:52:46.0993 0944  Processor - ok
07:52:47.0009 0944  [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc        C:\Windows\system32\profsvc.dll
07:52:47.0040 0944  ProfSvc - ok
07:52:47.0056 0944  [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
07:52:47.0071 0944  ProtectedStorage - ok
07:52:47.0103 0944  [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
07:52:47.0118 0944  PSched - ok
07:52:47.0181 0944  [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
07:52:47.0243 0944  ql2300 - ok
07:52:47.0274 0944  [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
07:52:47.0274 0944  ql40xx - ok
07:52:47.0305 0944  [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE          C:\Windows\system32\qwave.dll
07:52:47.0352 0944  QWAVE - ok
07:52:47.0368 0944  [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
07:52:47.0415 0944  QWAVEdrv - ok
07:52:47.0461 0944  [ 70DBDAB246C18B78E2200D6401D038BE ] RapiMgr        C:\Windows\WindowsMobile\rapimgr.dll
07:52:47.0508 0944  RapiMgr - ok
07:52:47.0524 0944  [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
07:52:47.0555 0944  RasAcd - ok
07:52:47.0586 0944  [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto        C:\Windows\System32\rasauto.dll
07:52:47.0602 0944  RasAuto - ok
07:52:47.0633 0944  [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
07:52:47.0680 0944  Rasl2tp - ok
07:52:47.0711 0944  [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan          C:\Windows\System32\rasmans.dll
07:52:47.0773 0944  RasMan - ok
07:52:47.0789 0944  [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
07:52:47.0836 0944  RasPppoe - ok
07:52:47.0867 0944  [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
07:52:47.0883 0944  RasSstp - ok
07:52:47.0914 0944  [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
07:52:47.0961 0944  rdbss - ok
07:52:47.0992 0944  [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
07:52:48.0039 0944  RDPCDD - ok
07:52:48.0070 0944  [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr          C:\Windows\system32\drivers\rdpdr.sys
07:52:48.0101 0944  rdpdr - ok
07:52:48.0101 0944  [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
07:52:48.0132 0944  RDPENCDD - ok
07:52:48.0195 0944  [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
07:52:48.0226 0944  RDPWD - ok
07:52:48.0335 0944  [ 3FF45B7F17D5837216ABAE652CC61540 ] RegSrvc        C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
07:52:48.0366 0944  RegSrvc ( UnsignedFile.Multi.Generic ) - warning
07:52:48.0366 0944  RegSrvc - detected UnsignedFile.Multi.Generic (1)
07:52:48.0413 0944  [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess    C:\Windows\System32\mprdim.dll
07:52:48.0444 0944  RemoteAccess - ok
07:52:48.0475 0944  [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry  C:\Windows\system32\regsvc.dll
07:52:48.0522 0944  RemoteRegistry - ok
07:52:48.0569 0944  [ 6482707F9F4DA0ECBAB43B2E0398A101 ] RFCOMM          C:\Windows\system32\DRIVERS\rfcomm.sys
07:52:48.0600 0944  RFCOMM - ok
07:52:48.0663 0944  [ D1F1D0EE50F8C070A612796676971699 ] RichVideo      C:\Program Files\Cyberlink\Shared files\RichVideo.exe
07:52:48.0678 0944  RichVideo ( UnsignedFile.Multi.Generic ) - warning
07:52:48.0678 0944  RichVideo - detected UnsignedFile.Multi.Generic (1)
07:52:48.0694 0944  [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator      C:\Windows\system32\locator.exe
07:52:48.0725 0944  RpcLocator - ok
07:52:48.0756 0944  [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs          C:\Windows\system32\rpcss.dll
07:52:48.0787 0944  RpcSs - ok
07:52:48.0850 0944  [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
07:52:48.0881 0944  rspndr - ok
07:52:48.0897 0944  [ 7A4F79DF3793160B280CDE152B61FE33 ] RTSTOR          C:\Windows\system32\drivers\RTSTOR.SYS
07:52:48.0912 0944  RTSTOR - ok
07:52:48.0943 0944  [ A3E186B4B935905B829219502557314E ] SamSs          C:\Windows\system32\lsass.exe
07:52:48.0959 0944  SamSs - ok
07:52:48.0990 0944  [ 3CE8F073A557E172B330109436984E30 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
07:52:49.0006 0944  sbp2port - ok
07:52:49.0037 0944  [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
07:52:49.0084 0944  SCardSvr - ok
07:52:49.0131 0944  [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule        C:\Windows\system32\schedsvc.dll
07:52:49.0177 0944  Schedule - ok
07:52:49.0224 0944  [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc    C:\Windows\System32\certprop.dll
07:52:49.0240 0944  SCPolicySvc - ok
07:52:49.0271 0944  [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
07:52:49.0302 0944  SDRSVC - ok
07:52:49.0333 0944  [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
07:52:49.0396 0944  secdrv - ok
07:52:49.0427 0944  [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon        C:\Windows\system32\seclogon.dll
07:52:49.0474 0944  seclogon - ok
07:52:49.0505 0944  [ A9BBAB5759771E523F55563D6CBE140F ] SENS            C:\Windows\System32\sens.dll
07:52:49.0552 0944  SENS - ok
07:52:49.0583 0944  [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum        C:\Windows\system32\drivers\serenum.sys
07:52:49.0645 0944  Serenum - ok
07:52:49.0677 0944  [ C70D69A918B178D3C3B06339B40C2E1B ] Serial          C:\Windows\system32\drivers\serial.sys
07:52:49.0723 0944  Serial - ok
07:52:49.0739 0944  [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
07:52:49.0755 0944  sermouse - ok
07:52:49.0801 0944  [ D2193326F729B163125610DBF3E17D57 ] SessionEnv      C:\Windows\system32\sessenv.dll
07:52:49.0848 0944  SessionEnv - ok
07:52:49.0848 0944  [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
07:52:49.0895 0944  sffdisk - ok
07:52:49.0911 0944  [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
07:52:49.0942 0944  sffp_mmc - ok
07:52:49.0957 0944  [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
07:52:49.0989 0944  sffp_sd - ok
07:52:50.0004 0944  [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
07:52:50.0051 0944  sfloppy - ok
07:52:50.0082 0944  [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
07:52:50.0113 0944  SharedAccess - ok
07:52:50.0145 0944  [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
07:52:50.0191 0944  ShellHWDetection - ok
07:52:50.0223 0944  [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp          C:\Windows\system32\drivers\sisagp.sys
07:52:50.0238 0944  sisagp - ok
07:52:50.0269 0944  [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
07:52:50.0285 0944  SiSRaid2 - ok
07:52:50.0301 0944  [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
07:52:50.0316 0944  SiSRaid4 - ok
07:52:50.0363 0944  [ EA396139541706B4B433641D62EA53CE ] SkypeUpdate    C:\Program Files\Skype\Updater\Updater.exe
07:52:50.0363 0944  SkypeUpdate - ok
07:52:50.0472 0944  [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc          C:\Windows\system32\SLsvc.exe
07:52:50.0659 0944  slsvc - ok
07:52:50.0691 0944  [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify      C:\Windows\system32\SLUINotify.dll
07:52:50.0737 0944  SLUINotify - ok
07:52:50.0769 0944  [ 7B75299A4D201D6A6533603D6914AB04 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
07:52:50.0800 0944  Smb - ok
07:52:50.0815 0944  [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
07:52:50.0847 0944  SNMPTRAP - ok
07:52:50.0878 0944  [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr          C:\Windows\system32\drivers\spldr.sys
07:52:50.0893 0944  spldr - ok
07:52:50.0909 0944  [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler        C:\Windows\System32\spoolsv.exe
07:52:50.0956 0944  Spooler - ok
07:52:51.0034 0944  [ 7BB297CADA42903328E92425D9761DA6 ] SRTSP          C:\Windows\System32\Drivers\N360\0603000.00E\SRTSP.SYS
07:52:51.0049 0944  SRTSP - ok
07:52:51.0065 0944  [ 475FCF0F28D845BF1C8ABAC27F19003E ] SRTSPX          C:\Windows\system32\drivers\N360\0603000.00E\SRTSPX.SYS
07:52:51.0081 0944  SRTSPX - ok
07:52:51.0127 0944  [ 41987F9FC0E61ADF54F581E15029AD91 ] srv            C:\Windows\system32\DRIVERS\srv.sys
07:52:51.0174 0944  srv - ok
07:52:51.0205 0944  [ FF33AFF99564B1AA534F58868CBE41EF ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
07:52:51.0283 0944  srv2 - ok
07:52:51.0315 0944  [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
07:52:51.0330 0944  srvnet - ok
07:52:51.0361 0944  [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
07:52:51.0424 0944  SSDPSRV - ok
07:52:51.0455 0944  [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc        C:\Windows\system32\sstpsvc.dll
07:52:51.0502 0944  SstpSvc - ok
07:52:51.0549 0944  [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc          C:\Windows\System32\wiaservc.dll
07:52:51.0595 0944  stisvc - ok
07:52:51.0627 0944  [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
07:52:51.0642 0944  swenum - ok
07:52:51.0673 0944  [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv          C:\Windows\System32\swprv.dll
07:52:51.0720 0944  swprv - ok
07:52:51.0736 0944  [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
07:52:51.0751 0944  Symc8xx - ok
07:52:51.0783 0944  [ 690FA0E61B90084C4D9A721BD4F3D779 ] SymDS          C:\Windows\system32\drivers\N360\0603000.00E\SYMDS.SYS
07:52:51.0814 0944  SymDS - ok
07:52:51.0907 0944  [ 8F88EDB211B12537D2DC2A6D73D6067C ] SymEFA          C:\Windows\system32\drivers\N360\0603000.00E\SYMEFA.SYS
07:52:51.0954 0944  SymEFA - ok
07:52:52.0032 0944  [ 74E2521E96176A4449570E50BE91954D ] SymEvent        C:\Windows\system32\Drivers\SYMEVENT.SYS
07:52:52.0048 0944  SymEvent - ok
07:52:52.0079 0944  [ 2C356CCA706505CF63CBE39D532B9236 ] SymIRON        C:\Windows\system32\drivers\N360\0603000.00E\Ironx86.SYS
07:52:52.0095 0944  SymIRON - ok
07:52:52.0110 0944  [ 40C6E6417C8B7D7FCF82CFBE71525795 ] SYMTDIv        C:\Windows\System32\Drivers\N360\0603000.00E\SYMTDIV.SYS
07:52:52.0126 0944  SYMTDIv - ok
07:52:52.0157 0944  [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
07:52:52.0157 0944  Sym_hi - ok
07:52:52.0173 0944  [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
07:52:52.0188 0944  Sym_u3 - ok
07:52:52.0219 0944  [ 4C9BB4B3B9EAC26211484C30B914C6DC ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
07:52:52.0235 0944  SynTP - ok
07:52:52.0251 0944  [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain        C:\Windows\system32\sysmain.dll
07:52:52.0313 0944  SysMain - ok
07:52:52.0344 0944  [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
07:52:52.0375 0944  TabletInputService - ok
07:52:52.0407 0944  [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv        C:\Windows\System32\tapisrv.dll
07:52:52.0438 0944  TapiSrv - ok
07:52:52.0469 0944  [ CB05822CD9CC6C688168E113C603DBE7 ] TBS            C:\Windows\System32\tbssvc.dll
07:52:52.0485 0944  TBS - ok
07:52:52.0609 0944  [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
07:52:52.0656 0944  Tcpip - ok
07:52:52.0703 0944  [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
07:52:52.0734 0944  Tcpip6 - ok
07:52:52.0781 0944  [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
07:52:52.0843 0944  tcpipreg - ok
07:52:52.0859 0944  [ 72B9E77565DA5FA564581976E000D29B ] TcUsb          C:\Windows\system32\Drivers\tcusb.sys
07:52:52.0875 0944  TcUsb - ok
07:52:52.0906 0944  [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
07:52:52.0937 0944  TDPIPE - ok
07:52:52.0953 0944  [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
07:52:52.0984 0944  TDTCP - ok
07:52:53.0015 0944  [ 76B06EB8A01FC8624D699E7045303E54 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
07:52:53.0031 0944  tdx - ok
07:52:53.0140 0944  [ A4D2CE94B028EF1E437CF4AC3D8FF26C ] TeamViewer7    C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
07:52:53.0249 0944  TeamViewer7 - ok
07:52:53.0296 0944  [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
07:52:53.0311 0944  TermDD - ok
07:52:53.0343 0944  [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService    C:\Windows\System32\termsrv.dll
07:52:53.0389 0944  TermService - ok
07:52:53.0436 0944  [ C7230FBEE14437716701C15BE02C27B8 ] Themes          C:\Windows\system32\shsvcs.dll
07:52:53.0452 0944  Themes - ok
07:52:53.0467 0944  [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER    C:\Windows\system32\mmcss.dll
07:52:53.0499 0944  THREADORDER - ok
07:52:53.0530 0944  [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks          C:\Windows\System32\trkwks.dll
07:52:53.0592 0944  TrkWks - ok
07:52:53.0639 0944  [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
07:52:53.0670 0944  TrustedInstaller - ok
07:52:53.0686 0944  [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
07:52:53.0717 0944  tssecsrv - ok
07:52:53.0733 0944  [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
07:52:53.0748 0944  tunmp - ok
07:52:53.0779 0944  [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
07:52:53.0811 0944  tunnel - ok
07:52:53.0857 0944  [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35          C:\Windows\system32\drivers\uagp35.sys
07:52:53.0857 0944  uagp35 - ok
07:52:53.0889 0944  [ F763E070843EE2803DE1395002B42938 ] UBHelper        C:\Windows\system32\drivers\UBHelper.sys
07:52:53.0904 0944  UBHelper - ok
07:52:53.0935 0944  [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
07:52:53.0982 0944  udfs - ok
07:52:54.0013 0944  [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
07:52:54.0060 0944  UI0Detect - ok
07:52:54.0091 0944  [ 78B63388550028AED6C52F843ABF6000 ] UimBus          C:\Windows\system32\DRIVERS\UimBus.sys
07:52:54.0107 0944  UimBus - ok
07:52:54.0123 0944  [ 3412EFAF3CB0B6C21818A3C407714CA1 ] Uim_IM          C:\Windows\system32\Drivers\Uim_IM.sys
07:52:54.0138 0944  Uim_IM - ok
07:52:54.0138 0944  [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
07:52:54.0154 0944  uliagpkx - ok
07:52:54.0185 0944  [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci        C:\Windows\system32\drivers\uliahci.sys
07:52:54.0201 0944  uliahci - ok
07:52:54.0216 0944  [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata          C:\Windows\system32\drivers\ulsata.sys
07:52:54.0232 0944  UlSata - ok
07:52:54.0232 0944  [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
07:52:54.0247 0944  ulsata2 - ok
07:52:54.0263 0944  [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
07:52:54.0310 0944  umbus - ok
07:52:54.0357 0944  [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost        C:\Windows\System32\upnphost.dll
07:52:54.0403 0944  upnphost - ok
07:52:54.0435 0944  [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
07:52:54.0450 0944  usbccgp - ok
07:52:54.0481 0944  [ E9476E6C486E76BC4898074768FB7131 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
07:52:54.0544 0944  usbcir - ok
07:52:54.0591 0944  [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
07:52:54.0606 0944  usbehci - ok
07:52:54.0637 0944  [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
07:52:54.0653 0944  usbhub - ok
07:52:54.0669 0944  [ 38DBC7DD6CC5A72011F187425384388B ] usbohci        C:\Windows\system32\drivers\usbohci.sys
07:52:54.0747 0944  usbohci - ok
07:52:54.0778 0944  [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
07:52:54.0825 0944  usbprint - ok
07:52:54.0856 0944  [ A508C9BD8724980512136B039BBA65E9 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
07:52:54.0887 0944  usbscan - ok
07:52:54.0887 0944  [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
07:52:54.0934 0944  USBSTOR - ok
07:52:54.0965 0944  [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
07:52:55.0012 0944  usbuhci - ok
07:52:55.0043 0944  [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
07:52:55.0090 0944  usbvideo - ok
07:52:55.0105 0944  [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms          C:\Windows\System32\uxsms.dll
07:52:55.0152 0944  UxSms - ok
07:52:55.0199 0944  [ CD88D1B7776DC17A119049742EC07EB4 ] vds            C:\Windows\System32\vds.exe
07:52:55.0230 0944  vds - ok
07:52:55.0261 0944  [ 87B06E1F30B749A114F74622D013F8D4 ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
07:52:55.0308 0944  vga - ok
07:52:55.0339 0944  [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave        C:\Windows\System32\drivers\vga.sys
07:52:55.0371 0944  VgaSave - ok
07:52:55.0386 0944  [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp          C:\Windows\system32\drivers\viaagp.sys
07:52:55.0402 0944  viaagp - ok
07:52:55.0433 0944  [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7          C:\Windows\system32\drivers\viac7.sys
07:52:55.0449 0944  ViaC7 - ok
07:52:55.0480 0944  [ AADF5587A4063F52C2C3FED7887426FC ] viaide          C:\Windows\system32\drivers\viaide.sys
07:52:55.0495 0944  viaide - ok
07:52:55.0511 0944  [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
07:52:55.0527 0944  volmgr - ok
07:52:55.0558 0944  [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
07:52:55.0573 0944  volmgrx - ok
07:52:55.0605 0944  [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
07:52:55.0636 0944  volsnap - ok
07:52:55.0667 0944  [ 587253E09325E6BF226B299774B728A9 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
07:52:55.0667 0944  vsmraid - ok
07:52:55.0729 0944  [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS            C:\Windows\system32\vssvc.exe
07:52:55.0807 0944  VSS - ok
07:52:55.0823 0944  [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time        C:\Windows\system32\w32time.dll
07:52:55.0854 0944  W32Time - ok
07:52:55.0870 0944  [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
07:52:55.0917 0944  WacomPen - ok
07:52:55.0917 0944  [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
07:52:55.0963 0944  Wanarp - ok
07:52:55.0963 0944  [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
07:52:55.0979 0944  Wanarpv6 - ok
07:52:56.0026 0944  [ 779F9C90D3FE9C70B6FFD8EF035F3E83 ] WcesComm        C:\Windows\WindowsMobile\wcescomm.dll
07:52:56.0057 0944  WcesComm - ok
07:52:56.0073 0944  [ A3CD60FD826381B49F03832590E069AF ] wcncsvc        C:\Windows\System32\wcncsvc.dll
07:52:56.0119 0944  wcncsvc - ok
07:52:56.0151 0944  [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
07:52:56.0182 0944  WcsPlugInService - ok
07:52:56.0197 0944  [ 78FE9542363F297B18C027B2D7E7C07F ] Wd              C:\Windows\system32\drivers\wd.sys
07:52:56.0213 0944  Wd - ok
07:52:56.0260 0944  [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
07:52:56.0291 0944  Wdf01000 - ok
07:52:56.0291 0944  [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost  C:\Windows\system32\wdi.dll
07:52:56.0322 0944  WdiServiceHost - ok
07:52:56.0338 0944  [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost  C:\Windows\system32\wdi.dll
07:52:56.0353 0944  WdiSystemHost - ok
07:52:56.0400 0944  [ 04C37D8107320312FBAE09926103D5E2 ] WebClient      C:\Windows\System32\webclnt.dll
07:52:56.0447 0944  WebClient - ok
07:52:56.0478 0944  [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc          C:\Windows\system32\wecsvc.dll
07:52:56.0556 0944  Wecsvc - ok
07:52:56.0572 0944  [ 670FF720071ED741206D69BD995EA453 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
07:52:56.0603 0944  wercplsupport - ok
07:52:56.0619 0944  [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc          C:\Windows\System32\WerSvc.dll
07:52:56.0650 0944  WerSvc - ok
07:52:56.0665 0944  [ BB9CBAF6AC20452B245C324F1F50EE81 ] winachsf        C:\Windows\system32\DRIVERS\HSX_CNXT.sys
07:52:56.0712 0944  winachsf - ok
07:52:56.0759 0944  [ 3FA87D56769838AAC82FAFC3E78FC732 ] winbondcir      C:\Windows\system32\DRIVERS\winbondcir.sys
07:52:56.0806 0944  winbondcir - ok
07:52:56.0853 0944  [ 4575AA12561C5648483403541D0D7F2B ] WinDefend      C:\Program Files\Windows Defender\mpsvc.dll
07:52:56.0868 0944  WinDefend - ok
07:52:56.0884 0944  WinHttpAutoProxySvc - ok
07:52:56.0931 0944  [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
07:52:56.0962 0944  Winmgmt - ok
07:52:57.0009 0944  [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM          C:\Windows\system32\WsmSvc.dll
07:52:57.0118 0944  WinRM - ok
07:52:57.0165 0944  [ 676F4B665BDD8053EAA53AC1695B8074 ] winusb          C:\Windows\system32\DRIVERS\WinUSB.SYS
07:52:57.0180 0944  winusb - ok
07:52:57.0227 0944  [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc        C:\Windows\System32\wlansvc.dll
07:52:57.0274 0944  Wlansvc - ok
07:52:57.0321 0944  [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi        C:\Windows\system32\DRIVERS\wmiacpi.sys
07:52:57.0352 0944  WmiAcpi - ok
07:52:57.0399 0944  [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
07:52:57.0445 0944  wmiApSrv - ok
07:52:57.0508 0944  [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc  C:\Program Files\Windows Media Player\wmpnetwk.exe
07:52:57.0617 0944  WMPNetworkSvc - ok
07:52:57.0648 0944  [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
07:52:57.0695 0944  WPCSvc - ok
07:52:57.0726 0944  [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
07:52:57.0773 0944  WPDBusEnum - ok
07:52:57.0804 0944  [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
07:52:57.0835 0944  WpdUsb - ok
07:52:57.0945 0944  [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
07:52:57.0991 0944  WPFFontCache_v0400 - ok
07:52:58.0007 0944  [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
07:52:58.0085 0944  ws2ifsl - ok
07:52:58.0116 0944  [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc          C:\Windows\System32\wscsvc.dll
07:52:58.0132 0944  wscsvc - ok
07:52:58.0147 0944  [ 4422AC5ED8D4C2F0DB63E71D4C069DD7 ] WSDPrintDevice  C:\Windows\system32\DRIVERS\WSDPrint.sys
07:52:58.0179 0944  WSDPrintDevice - ok
07:52:58.0194 0944  WSearch - ok
07:52:58.0257 0944  [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv        C:\Windows\system32\wuaueng.dll
07:52:58.0350 0944  wuauserv - ok
07:52:58.0397 0944  [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
07:52:58.0444 0944  WUDFRd - ok
07:52:58.0459 0944  [ 575A4190D989F64732119E4114045A4F ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
07:52:58.0491 0944  wudfsvc - ok
07:52:58.0522 0944  [ DAB33CFA9DD24251AAA389FF36B64D4B ] XAudio          C:\Windows\system32\DRIVERS\xaudio.sys
07:52:58.0553 0944  XAudio - ok
07:52:58.0584 0944  [ CD5F291A1161F15896D1A4D63DAFF5DF ] XAudioService  C:\Windows\system32\DRIVERS\xaudio.exe
07:52:58.0631 0944  XAudioService - ok
07:52:58.0693 0944  [ 4D840C6AF3C020ED3A35EFBA9025CF4A ] {49DE1C67-83F8-4102-99E0-C16DCC7EEC796} C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl
07:52:58.0693 0944  {49DE1C67-83F8-4102-99E0-C16DCC7EEC796} - ok
07:52:58.0709 0944  ================ Scan global ===============================
07:52:58.0725 0944  [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
07:52:58.0756 0944  [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
07:52:58.0771 0944  [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
07:52:58.0818 0944  [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
07:52:58.0818 0944  [Global] - ok
07:52:58.0818 0944  ================ Scan MBR ==================================
07:52:58.0834 0944  [ BB9D3A6A13C5010348DA7C900BB6AF50 ] \Device\Harddisk0\DR0
07:52:59.0770 0944  \Device\Harddisk0\DR0 - ok
07:52:59.0770 0944  ================ Scan VBR ==================================
07:52:59.0770 0944  [ C78215C9610E1A165B5C79393A5C1655 ] \Device\Harddisk0\DR0\Partition1
07:52:59.0770 0944  \Device\Harddisk0\DR0\Partition1 - ok
07:52:59.0770 0944  ============================================================
07:52:59.0770 0944  Scan finished
07:52:59.0770 0944  ============================================================
07:52:59.0785 1224  Detected object count: 9
07:52:59.0785 1224  Actual detected object count: 9
07:53:35.0431 1224  CLHNService ( UnsignedFile.Multi.Generic ) - skipped by user
07:53:35.0431 1224  CLHNService ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:53:35.0431 1224  EvtEng ( UnsignedFile.Multi.Generic ) - skipped by user
07:53:35.0431 1224  EvtEng ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:53:35.0463 1224  FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - skipped by user
07:53:35.0463 1224  FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:53:35.0463 1224  IGBASVC ( UnsignedFile.Multi.Generic ) - skipped by user
07:53:35.0463 1224  IGBASVC ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:53:35.0463 1224  LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
07:53:35.0463 1224  LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:53:35.0463 1224  NTIPPKernel ( UnsignedFile.Multi.Generic ) - skipped by user
07:53:35.0463 1224  NTIPPKernel ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:53:35.0463 1224  Polar Daemon ( UnsignedFile.Multi.Generic ) - skipped by user
07:53:35.0463 1224  Polar Daemon ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:53:35.0478 1224  RegSrvc ( UnsignedFile.Multi.Generic ) - skipped by user
07:53:35.0478 1224  RegSrvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:53:35.0478 1224  RichVideo ( UnsignedFile.Multi.Generic ) - skipped by user
07:53:35.0478 1224  RichVideo ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 01.10.2012 09:52

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

boris1 01.10.2012 10:27

Konnte den PC nicht im normalen Modus starten, bekam nach dem hochfahren statt des Desktops einen schwarzen Bildschirm zu sehen.
Im abgesicherten Modus klappt es, hier die LOG Datei:

[code]
Combofix Logfile:
Code:

ComboFix 12-09-30.03 - matthes 01.10.2012  11:00:20.1.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3066.2577 [GMT 2:00]
ausgeführt von:: c:\users\matthes\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Acer\Acer Bio Protection\PwdFilter.dll
c:\programdata\Roaming
c:\programdata\SPL21D2.tmp
c:\programdata\SPL52A6.tmp
c:\programdata\SPL86C3.tmp
c:\programdata\SPLC0DC.tmp
c:\programdata\SPLCADC.tmp
c:\programdata\SPLCD26.tmp
c:\programdata\SPLD9CA.tmp
c:\programdata\SPLDAC4.tmp
c:\programdata\SPLDBFC.tmp
c:\programdata\SPLF8FE.tmp
c:\windows\IsUn0407.exe
c:\windows\system32\muzapp.exe
c:\windows\system32\System32\MASetupCleaner.exe
c:\windows\system32\System32\muzapp.exe
c:\windows\system32\wininit.dll
E:\install.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-09-01 bis 2012-10-01  ))))))))))))))))))))))))))))))
.
.
2012-09-28 18:50 . 2012-09-28 18:50        --------        d-----w-        C:\_OTL
2012-09-27 14:35 . 2012-09-27 14:35        --------        d-----w-        c:\program files\ESET
2012-09-25 19:59 . 2012-09-25 19:59        --------        d-----w-        c:\program files\CCleaner
2012-09-25 17:36 . 2012-09-25 17:36        --------        d-----w-        c:\users\matthes\AppData\Roaming\Malwarebytes
2012-09-25 17:36 . 2012-09-25 17:36        --------        d-----w-        c:\programdata\Malwarebytes
2012-09-25 17:36 . 2012-09-25 17:36        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2012-09-25 17:36 . 2012-09-07 15:04        22856        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-17 17:15 . 2012-09-20 14:44        --------        d-----w-        c:\users\matthes\Ordnerdeckblätter
2012-09-11 12:27 . 2012-09-12 12:53        --------        d-----w-        c:\windows\system32\Samsung_USB_Drivers
2012-09-11 09:03 . 2012-09-11 09:03        73696        ----a-w-        c:\program files\Mozilla Firefox\breakpadinjector.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-20 17:49 . 2012-05-11 13:11        696240        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-09-20 17:49 . 2011-06-09 12:43        73136        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-14 15:46 . 2010-03-07 09:45        47360        ----a-w-        c:\users\matthes\AppData\Roaming\pcouffin.sys
2012-07-06 02:17 . 2012-08-15 08:00        574112        ----a-w-        c:\windows\system32\drivers\N360\0603000.00E\srtsp.sys
2012-07-06 02:17 . 2012-08-15 08:00        32928        ----a-w-        c:\windows\system32\drivers\N360\0603000.00E\srtspx.sys
2012-07-04 14:02 . 2012-08-17 11:18        2047488        ----a-w-        c:\windows\system32\win32k.sys
2004-07-09 03:08 . 2004-07-09 03:08        472576        ----a-w-        c:\program files\dxsetup.exe
2004-07-09 03:08 . 2004-07-09 03:08        2242560        ----a-w-        c:\program files\dsetup32.dll
2004-07-09 02:03 . 2004-07-09 02:03        62976        ----a-w-        c:\program files\DSETUP.dll
2012-09-11 09:03 . 2011-04-11 15:27        266720        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
2008-06-30 12:44 . 2009-12-13 21:53        324976        ----a-w-        c:\program files\mozilla firefox\components\coFFPlgn.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{147FEC3F-6DE9-437C-8FC1-6B8A20AA0A72}]
2010-01-26 14:52        192512        ----a-w-        c:\users\matthes\AppData\Roaming\AdobeReader\IE\AdobeReader.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1049896]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-07 6139904]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-18 92704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-18 13543968]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
"lxeamon.exe"="c:\program files\Lexmark S300-S400 Series\lxeamon.exe" [2011-01-23 770728]
"EzPrint"="c:\program files\Lexmark S300-S400 Series\ezprint.exe" [2009-04-29 139944]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
.
c:\users\matthes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2008-10-28 10:38        3197952        ----a-w-        c:\program files\Acer\Acer Bio Protection\WinNotify.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\spba]
2008-03-25 14:24        567560        ----a-w-        c:\program files\Common Files\SPBA\homefus2.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages        REG_MULTI_SZ          scecli c:\program files\Acer\Acer Bio Protection\PwdFilter
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcadeDeluxeAgent]
2008-07-24 14:54        147456        ------w-        c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
2008-07-24 14:54        167936        ------w-        c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
2003-05-08 10:00        49152        ----a-w-        c:\program files\ScanSoft\OmniPageSE2.0\opwareSE2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
2008-07-18 15:04        167936        ------w-        c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 09:07        252296        ----a-w-        c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2011-12-09 17:22        74752        ----a-w-        c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:25        202240        ----a-w-        c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZPdtWzdVitaKey MC3000]
2008-10-28 10:38        3676160        ----a-w-        c:\program files\Acer\Acer Bio Protection\PdtWzd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1437981379-4010485698-1217947183-1000]
"EnableNotificationsRef"=dword:00000001
.
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs        REG_MULTI_SZ          BthServ
WindowsMobile        REG_MULTI_SZ          wcescomm rapimgr
LocalServiceRestricted        REG_MULTI_SZ          WcesComm RapiMgr
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-11 17:50]
.
2012-10-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 18:35]
.
2012-09-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 18:35]
.
2012-09-25 c:\windows\Tasks\User_Feed_Synchronization-{52A60082-F11F-4DC0-815C-41B71B2E7AD3}.job
- c:\windows\system32\msfeedssync.exe [2012-09-22 08:30]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{603D3CE5-33BC-4d51-A31E-613A2B826E21} - c:\users\matthes\AppData\Roaming\IEButtons\toolbutton2.js
IE: {{804420A5-7F05-4ee9-92F2-D2B644AD9102} - c:\users\matthes\AppData\Roaming\IEButtons\toolbutton3.js
IE: {{C376BD23-6DC3-4e10-9ED0-AB8C0444E45C} - c:\users\matthes\AppData\Roaming\IEButtons\toolbutton1.js
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\matthes\AppData\Roaming\Mozilla\Firefox\Profiles\38gpdnax.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{40c3cc16-7269-4b32-9531-17f2950fb06f} - (no file)
HKCU-Run-SearchIndexer - c:\users\matthes\AppData\Local\Microsoft\Windows\89\SearchIndexer.exe
MSConfigStartUp-KiesHelper - c:\program files\Samsung\Kies\KiesHelper.exe
MSConfigStartUp-KiesPDLR - c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
MSConfigStartUp-KiesTrayAgent - c:\program files\Samsung\Kies\KiesTrayAgent.exe
AddRemove-sv.net - e:\sozial~1.hls\svnet\UNWISE.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-10-01 11:21
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\6.3.0.14\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\6.3.0.14\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(1408)
c:\windows\system32\btncopy.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\helppane.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-10-01  11:23:46 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-10-01 09:23
.
Vor Suchlauf: 18 Verzeichnis(se), 33.673.388.032 Bytes frei
Nach Suchlauf: 24 Verzeichnis(se), 33.296.908.288 Bytes frei
.
- - End Of File - - E539618963764A787E48D3DF4FB3384F

--- --- ---

cosinus 01.10.2012 13:35

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

boris1 01.10.2012 16:41

Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-10-01 16:05:58
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST932032 rev.0303
Running: 7jr8d694.exe; Driver: C:\Users\matthes\AppData\Local\Temp\kxriifow.sys


---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                [74AD7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                [74B1B4E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]            [74ADBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]      [74ACF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                [74AD75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]              [74ACE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]  [74B073F5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]    [74ADDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]            [74ACFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]              [74ACFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]              [74AC71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]      [74B5CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]          [74AFC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]            [74ACD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                      [74AC6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                      [74AC687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1400] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]        [74AD2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                              Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                              hotcore3.sys (A part of Paragon System Utilities/Paragon Software Group)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                              hotcore3.sys (A part of Paragon System Utilities/Paragon Software Group)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                              hotcore3.sys (A part of Paragon System Utilities/Paragon Software Group)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume4                                                              hotcore3.sys (A part of Paragon System Utilities/Paragon Software Group)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume5                                                              hotcore3.sys (A part of Paragon System Utilities/Paragon Software Group)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269ddfef6                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269ddfef6@001ee29f991a            0x9B 0x60 0xDD 0xE0 ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269ddfef6@60a10a10ad8a            0x0D 0x03 0x14 0x27 ...
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\002269ddfef6 (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\002269ddfef6@001ee29f991a                0x9B 0x60 0xDD 0xE0 ...
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\002269ddfef6@60a10a10ad8a                0x0D 0x03 0x14 0x27 ...

---- EOF - GMER 1.0.15 ----


Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 16:23:02 on 01.10.2012

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 15.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"iproset.cpl" - "Intel(R) Corporation" - C:\Windows\system32\iproset.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"PROSet Tools" - "Intel(R) Corporation" - C:\Windows\System32\iPROSet.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"AlfaFF File System mini-filter" (AlfaFF) - "Alfa Corporation" - C:\Windows\System32\Drivers\AlfaFF.sys
"BHDrvx86" (BHDrvx86) - "Symantec Corporation" - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\BASHDefs\20120919.001\BHDrvx86.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"cpuz132" (cpuz132) - ? - C:\Users\matthes\AppData\Local\Temp\cpuz132\cpuz132_x32.sys  (File not found)
"Dritek Keyboard Filter Driver" (DKbFltr) - ? - C:\Windows\System32\DRIVERS\DKbFltr.sys  (File not found)
"EraserUtilRebootDrv" (EraserUtilRebootDrv) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
"hc3ServiceName" (hotcore3) - "Paragon Software Group" - C:\Windows\System32\DRIVERS\hotcore3.sys
"IDSVix86" (IDSVix86) - "Symantec Corporation" - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\IPSDefs\20120921.001\IDSvix86.sys
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"kxriifow" (kxriifow) - ? - C:\Users\matthes\AppData\Local\Temp\kxriifow.sys  (Hidden registry entry, rootkit activity | File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"NAVENG" (NAVENG) - "Symantec Corporation" - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120922.008\NAVENG.SYS
"NAVEX15" (NAVEX15) - "Symantec Corporation" - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120922.008\NAVEX15.SYS
"Norton 360 Settings Manager" (ccSet_N360) - "Symantec Corporation" - C:\Windows\system32\drivers\N360\0603000.00E\ccSetx86.sys
"NTIPPKernel" (NTIPPKernel) - "Cyberlink Corp." - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys
"PPdus ASPI Shell" (Afc) - "Arcsoft, Inc." - C:\Windows\System32\drivers\Afc.sys
"Symantec Data Store" (SymDS) - "Symantec Corporation" - C:\Windows\System32\drivers\N360\0603000.00E\SYMDS.SYS
"Symantec Eraser Control driver" (eeCtrl) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
"Symantec Extended File Attributes" (SymEFA) - "Symantec Corporation" - C:\Windows\System32\drivers\N360\0603000.00E\SYMEFA.SYS
"Symantec Iron Driver" (SymIRON) - "Symantec Corporation" - C:\Windows\system32\drivers\N360\0603000.00E\Ironx86.SYS
"Symantec Real Time Storage Protection" (SRTSP) - "Symantec Corporation" - C:\Windows\System32\Drivers\N360\0603000.00E\SRTSP.SYS
"Symantec Real Time Storage Protection (PEL)" (SRTSPX) - "Symantec Corporation" - C:\Windows\system32\drivers\N360\0603000.00E\SRTSPX.SYS
"Symantec Vista Network Dispatch Driver" (SYMTDIv) - "Symantec Corporation" - C:\Windows\System32\Drivers\N360\0603000.00E\SYMTDIV.SYS
"SymEvent" (SymEvent) - "Symantec Corporation" - C:\Windows\system32\Drivers\SYMEVENT.SYS
"UBHelper" (UBHelper) - "NewTech Infosystems Corporation" - C:\Windows\system32\drivers\UBHelper.sys
"Upper Class Filter Driver" (NTIDrvr) - "NewTech Infosystems, Inc." - C:\Windows\System32\DRIVERS\NTIDrvr.sys
"{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}" ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) - "Cyberlink Corp." - C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{8F9D8FBE-C5C1-4B65-986E-51235C9283E8} "FPLaunchCache" - "Arachnoid Biometrics Identification Group Corp." - C:\Program Files\Acer\Acer Bio Protection\FPLaunchCache.dll
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -  (File not found | COM-object registry key not found)
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -  (File not found | COM-object registry key not found)
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - ? -  (File not found | COM-object registry key not found)
{A40526DD-F152-4C1D-844C-CE668D29B77E} "Shell extension for NTP" - ? -  (File not found | COM-object registry key not found)
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
<binary data> "Norton Toolbar" - "Symantec Corporation" - C:\Program Files\Norton 360\Engine\6.3.0.14\coIEPlg.dll
<binary data> "{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 10.5.1" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 10.5.1" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
"Amazon (amazon.de)" - ? - C:\Users\matthes\AppData\Roaming\IEButtons\toolbutton2.js
"easy Shopping" - ? - C:\Users\matthes\AppData\Roaming\IEButtons\toolbutton3.js
"eBay (ebay.de)" - ? - C:\Users\matthes\AppData\Roaming\IEButtons\toolbutton1.js
"Quick-Launching Area" - ? - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} "Norton Toolbar" - "Symantec Corporation" - C:\Program Files\Norton 360\Engine\6.3.0.14\coIEPlg.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{147FEC3F-6DE9-437C-8FC1-6B8A20AA0A72} "Adobe Reader" - "Adobe Systems, Incorporated" - C:\Users\matthes\AppData\Roaming\AdobeReader\IE\AdobeReader.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
{D2C5E510-BE6D-42CC-9F61-E4F939078474} "Lexmark " - ? - C:\Program Files\Lexmark Printable Web\bho.dll
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} "Norton Identity Protection" - "Symantec Corporation" - C:\Program Files\Norton 360\Engine\6.3.0.14\coIEPlg.dll
{6D53EC84-6AAE-4787-AEEE-F4628F01010C} "Norton Vulnerability Protection" - "Symantec Corporation" - C:\Program Files\Norton 360\Engine\6.3.0.14\IPS\IPSBHO.DLL
{1017A80C-6F09-4548-A84D-EDD6AC9525F0} "{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" - ? -  (File not found | COM-object registry key not found)

[LSA Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )-----
"Notification packages" - ? - C:\Program Files\Acer\Acer Bio Protection\PwdFilter  (File not found)

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\matthes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"OpenOffice.org 3.3.lnk" - ? - C:\Program Files\OpenOffice.org 3\program\quickstart.exe  (Shortcut exists | File found, but it contains no detailed information | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Skype" - "Skype Technologies S.A." - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"EzPrint" - ? - "C:\Program Files\Lexmark S300-S400 Series\ezprint.exe"
"IAAnotif" - "Intel Corporation" - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
"lxeamon.exe" - ? - "C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe"
"PLFSetI" - ? - C:\Windows\PLFSetI.exe
"WarReg_PopUp" - "Acer Incorporated" - C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"ArcSoft Connect Daemon" (ACDaemon) - "ArcSoft Inc." - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
"CLHNService" (CLHNService) - ? - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
"FABS - Helping agent for MAGIX media database" (Fabs) - "MAGIX AG" - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
"FsUsbExService" (FsUsbExService) - "Teruten" - C:\Windows\system32\FsUsbExService.Exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"iGroupTec Service" (IGBASVC) - ? - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe  (File found, but it contains no detailed information)
"Intel(R) Matrix Storage Event Monitor" (IAANTMON) - "Intel Corporation" - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
"Intel® PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
"Intel® PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
"LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
"MBAMScheduler" (MBAMScheduler) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
"Norton 360" (N360) - "Symantec Corporation" - C:\Program Files\Norton 360\Engine\6.3.0.14\ccSvcHst.exe
"Polar Daemon" (Polar Daemon) - ? - C:\Program Files\Polar\Daemon\polard.exe  (File found, but it contains no detailed information)
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files\Skype\Updater\Updater.exe
"TeamViewer 7" (TeamViewer7) - "TeamViewer GmbH" - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe

[Winlogon]
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )-----
"AWinNotifyVitaKey MC3000" - "Arachnoid Biometrics Identification Group Corp." - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
"spba" - "UPEK Inc." - C:\Program Files\Common Files\SPBA\homefus2.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-01 16:26:01
-----------------------------
16:26:01.323    OS Version: Windows 6.0.6002 Service Pack 2
16:26:01.323    Number of processors: 2 586 0xF0D
16:26:01.323    ComputerName: MATTHES-PC  UserName: matthes
16:26:02.025    Initialize success
16:40:45.999    AVAST engine defs: 12100100
16:49:50.967    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
16:49:50.967    Disk 0 Vendor: ST932032 0303 Size: 305245MB BusType: 3
16:49:51.317    Disk 0 MBR read successfully
16:49:51.317    Disk 0 MBR scan
16:49:51.327    Disk 0 unknown MBR code
16:49:51.337    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        10240 MB offset 2048
16:49:51.397    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        79920 MB offset 20973568
16:49:51.407    Disk 0 Partition - 00    0F Extended LBA            211452 MB offset 184651110
16:49:51.517    Disk 0 Partition 3 00    12  Compaq diag NTFS        3630 MB offset 617705472
16:49:51.607    Disk 0 Partition - 00    05    Extended            109053 MB offset 184662015
16:49:51.617    Disk 0 Partition 4 00    07    HPFS/NTFS NTFS      109053 MB offset 184662016
16:49:51.627    Disk 0 Partition - 00    05    Extended            102393 MB offset 408013710
16:49:51.667    Disk 0 Partition 5 00    07    HPFS/NTFS NTFS      102393 MB offset 408002868
16:49:51.717    Disk 0 scanning sectors +625139712
16:49:51.927    Disk 0 scanning C:\Windows\system32\drivers
16:50:15.136    Service scanning
16:50:40.221    Modules scanning
16:50:45.993    Disk 0 trace - called modules:
16:50:46.008    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys
16:50:46.024    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x869e05b0]
16:50:46.024    3 CLASSPNP.SYS[8b1a68b3] -> nt!IofCallDriver -> [0x84ddf6b8]
16:50:46.040    5 acpi.sys[806986bc] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x84da0028]
16:50:46.554    AVAST engine scan C:\Windows
16:50:54.573    AVAST engine scan C:\Windows\system32
16:54:41.662    AVAST engine scan C:\Windows\system32\drivers
16:54:59.711    AVAST engine scan C:\Users\matthes
16:58:08.190    AVAST engine scan C:\ProgramData
17:00:02.538    Scan finished successfully
17:25:40.932    Disk 0 MBR has been saved successfully to "C:\Users\matthes\Desktop\MBR.dat"
17:25:40.932    The log file has been saved successfully to "C:\Users\matthes\Desktop\aswMBR.txt"


cosinus 02.10.2012 13:01

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.
Mach den Fix auch dann nicht, wenn du zB mit TrueCrypt oder anderen Verschlüsselungsprogrammen eine Vollverschlüsselung der Windowspartition bzw. gesamten Festplatte hast


Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!

Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

boris1 02.10.2012 15:43

Ich brauchte nur das Programm öffnen und direkt auf FIXMBR klicken? Oder hätte ich vorab noch einmal scannen müssen?

Im normalen Modus bekomme ich das Desktop wieder zu sehen, kann aber weder Programme noch Startmenü öffnen.

Hier Das neue Log:

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-02 16:13:04
-----------------------------
16:13:04.800    OS Version: Windows 6.0.6002 Service Pack 2
16:13:04.800    Number of processors: 2 586 0xF0D
16:13:04.800    ComputerName: MATTHES-PC  UserName: matthes
16:13:13.911    Initialize success
16:13:27.779    AVAST engine defs: 12100100
16:13:31.492    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
16:13:31.492    Disk 0 Vendor: ST932032 0303 Size: 305245MB BusType: 3
16:13:31.507    Disk 0 MBR read successfully
16:13:31.507    Disk 0 MBR scan
16:13:31.523    Disk 0 Windows VISTA default MBR code
16:13:31.523    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        10240 MB offset 2048
16:13:31.539    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        79920 MB offset 20973568
16:13:31.554    Disk 0 Partition - 00    0F Extended LBA            211452 MB offset 184651110
16:13:31.601    Disk 0 Partition 3 00    12  Compaq diag NTFS        3630 MB offset 617705472
16:13:31.648    Disk 0 Partition - 00    05    Extended            109053 MB offset 184662015
16:13:31.663    Disk 0 Partition 4 00    07    HPFS/NTFS NTFS      109053 MB offset 184662016
16:13:31.663    Disk 0 Partition - 00    05    Extended            102393 MB offset 408013710
16:13:31.695    Disk 0 Partition 5 00    07    HPFS/NTFS NTFS      102393 MB offset 408002868
16:13:31.710    Disk 0 scanning sectors +625139712
16:13:31.819    Disk 0 scanning C:\Windows\system32\drivers
16:13:45.407    Service scanning
16:14:12.036    Modules scanning
16:14:16.155    Disk 0 trace - called modules:
16:14:16.186    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys
16:14:16.201    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8695b440]
16:14:16.201    3 CLASSPNP.SYS[8b1a28b3] -> nt!IofCallDriver -> [0x860cd408]
16:14:16.217    5 acpi.sys[806916bc] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x84da0028]
16:14:16.779    AVAST engine scan C:\Windows
16:14:21.115    AVAST engine scan C:\Windows\system32
16:17:55.459    AVAST engine scan C:\Windows\system32\drivers
16:18:11.574    AVAST engine scan C:\Users\matthes
16:21:13.579    AVAST engine scan C:\ProgramData
16:22:53.856    Scan finished successfully
16:39:23.520    Disk 0 MBR has been saved successfully to "C:\Users\matthes\Desktop\MBR.dat"
16:39:23.536    The log file has been saved successfully to "C:\Users\matthes\Desktop\aswMBR.txt"


cosinus 02.10.2012 19:27

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

boris1 02.10.2012 19:41

Ich kann aber noch immer im normalen Modus nichts machen, kein Startmenü und keine Programme öffnen. Ist doch im Moment noch ok?

Der Scan läuft.

Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.10.02.07

Windows Vista Service Pack 2 x86 NTFS (Abgesichertenmodus/Netzwerkfähig)
Internet Explorer 8.0.6001.19328
matthes :: MATTHES-PC [Administrator]

Schutz: Deaktiviert

02.10.2012 20:39:23
mbam-log-2012-10-02 (20-39-23).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 382731
Laufzeit: 1 Stunde(n), 1 Minute(n), 19 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 10/03/2012 at 10:03 AM

Application Version : 5.5.1022

Core Rules Database Version : 9330
Trace Rules Database Version: 7142

Scan type      : Complete Scan
Total Scan Time : 01:54:36

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC Off - Administrator

Memory items scanned      : 381
Memory threats detected  : 0
Registry items scanned    : 34361
Registry threats detected : 0
File items scanned        : 165327
File threats detected    : 111

Adware.Tracking Cookie
        .atdmt.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjkyglc5kdp.stats.esomniture.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .autoscout24.112.2o7.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        tracking.mobile.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .dyntracker.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]


cosinus 05.10.2012 11:11

Wenn der normale Modus immer noch nicht geht, hilft evtl ein ältere Wiederherstellungspunkt.
Seit wann genau geht der normale Modus denn nicht mehr?

boris1 05.10.2012 11:29

Aufgefallen ist mir das hier nachdem ich den adwCleaner laufen lassen habe:
http://www.trojaner-board.de/124691-...tml#post925677

Es ist natürlich gut möglich das es schon ein paar Schritte früher war, das weiß ich nicht, da dann immer der abgesicherte Modus lief.

Ich weiß nicht ob es einen Systemwiederherstellungspunkt gibt. Ist es möglich das ich da im abgesicherten Modus nicht hineinkomme?

ich kann unter Systemwiederherstellung > System > Computerschutz nichts entdecken.

cosinus 05.10.2012 11:48

Also das findet jeder mit Google => Windows Vista - Wiederherstellungspunkt - Netzwerktotal.de

boris1 05.10.2012 12:42

Stimmt, da hatte ich gerade ein Brett vorm Kopf. Danke :)

Systemwiederherstellung durchgeführt. Scheint so wieder zu klappen, soll ich jetzt noch einmal scannen?

cosinus 05.10.2012 14:18

Ja bitte !

boris1 05.10.2012 18:01

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 10/05/2012 at 06:53 PM

Application Version : 5.5.1022

Core Rules Database Version : 9346
Trace Rules Database Version: 7158

Scan type      : Complete Scan
Total Scan Time : 02:47:34

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Administrator

Memory items scanned      : 835
Memory threats detected  : 0
Registry items scanned    : 38247
Registry threats detected : 0
File items scanned        : 166750
File threats detected    : 118

Adware.Tracking Cookie
        C:\Users\matthes\AppData\Roaming\Microsoft\Windows\Cookies\UHQBIL7P.txt [ /atdmt.com ]
        C:\Users\matthes\AppData\Roaming\Microsoft\Windows\Cookies\WY0PL4DU.txt [ /c.atdmt.com ]
        C:\USERS\MATTHES\Cookies\UHQBIL7P.txt [ Cookie:matthes@atdmt.com/ ]
        C:\USERS\MATTHES\Cookies\WY0PL4DU.txt [ Cookie:matthes@c.atdmt.com/ ]
        .atdmt.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjkyglc5kdp.stats.esomniture.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .autoscout24.112.2o7.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        tracking.mobile.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .dyntracker.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MATTHES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\38GPDNAX.DEFAULT\COOKIES.SQLITE ]

Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.10.05.04

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19298
matthes :: MATTHES-PC [Administrator]

Schutz: Deaktiviert

05.10.2012 14:08:04
mbam-log-2012-10-05 (14-08-04).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 387494
Laufzeit: 1 Stunde(n), 49 Minute(n), 21 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 05.10.2012 18:29

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

boris1 05.10.2012 18:32

Scheint soweit alles ok zu sein.

Vielen Dank dafür, war eine super Hilfe von dir !

cosinus 05.10.2012 18:34

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:14 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131