Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Browser und pc sehr langsam. Yontoo Layers Runtime 1.10.01 gefunden (https://www.trojaner-board.de/125373-browser-pc-sehr-langsam-yontoo-layers-runtime-1-10-01-gefunden.html)

perry85 08.10.2012 18:21

Browser und pc sehr langsam. Yontoo Layers Runtime 1.10.01 gefunden
 
Hallo,
wie schon im titel erwähnt ist mein pc bzw. das arbeiten mit dem browser sehr langsam und fehlerhaft, es scheint so als ob mein pc irgend was im hintergund macht. Oft wird auch angezeigt dass es ein nicht antwortendes skript gibt. des weiteren habe ich in meiner software liste ein programm entdeckt (Yontoo layers runtime 1.10.01) was ich nicht zuordnen kann, wo rauf ich dann bei google gesucht habe und auf den trojaner board gestoßen bin.
Habe dann malwarebytes durchlaufen lassen, und die anderen programme wie in den regeln beschieben.



Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.10.03.08

Windows XP Service Pack 3 x86 FAT32
Internet Explorer 8.0.6001.18702
MR :: ACER-5J0JDWIJ8Z [Administrator]

Schutz: Aktiviert

03.10.2012 21:49:52
mbam-log-2012-10-04 (01-52-31).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|G:\|H:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 423662
Laufzeit: 3 Stunde(n), 56 Minute(n), 58 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Dokumente und Einstellungen\MR\Eigene Dateien\Downloads\SoftonicDownloader_fuer_artistic-font-collection.exe (PUP.OfferBundler.ST) -> Keine Aktion durchgeführt.

(Ende)

OTL logfile created on: 08.10.2012 17:35:22 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\MR\Eigene Dateien\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

495,48 Mb Total Physical Memory | 178,41 Mb Available Physical Memory | 36,01% Memory free
1,62 Gb Paging File | 1,31 Gb Available in Paging File | 81,20% Paging File free
Paging file location(s): C:\pagefile.sys 744 1488 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 18,16 Gb Total Space | 1,37 Gb Free Space | 7,56% Space Free | Partition Type: FAT32
Drive D: | 9,76 Gb Total Space | 9,63 Gb Free Space | 98,71% Space Free | Partition Type: FAT32
Drive F: | 931,51 Gb Total Space | 649,55 Gb Free Space | 69,73% Space Free | Partition Type: NTFS

Computer Name: ACER-5J0JDWIJ8Z | User Name: MR | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.10.08 17:32:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\MR\Eigene Dateien\Downloads\OTL.exe
PRC - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.07 17:04:44 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.07.20 19:35:02 | 000,040,960 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizerHelper.exe
PRC - [2012.07.15 23:14:00 | 000,138,096 | ---- | M] (Facebook Inc.) -- C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Facebook\Update\FacebookUpdate.exe
PRC - [2011.12.22 19:11:22 | 000,818,952 | ---- | M] (ABBYY) -- C:\Programme\ABBYY FineReader 11\NetworkLicenseServer.exe
PRC - [2011.04.22 14:21:10 | 000,092,592 | ---- | M] (TomTom) -- C:\Programme\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2010.05.04 12:07:22 | 000,503,080 | ---- | M] (Nero AG) -- C:\Programme\Nero\Update\NASvc.exe
PRC - [2008.04.14 03:22:46 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2012.07.20 19:35:02 | 000,040,960 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizerHelper.exe
MOD - [2012.07.04 19:23:50 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll
MOD - [2012.07.04 19:20:20 | 001,712,128 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\359fd69eb60e9844ffd497e92345178c\Microsoft.VisualBasic.ni.dll
MOD - [2012.07.04 19:16:44 | 012,433,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll
MOD - [2012.07.04 19:16:16 | 001,592,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll
MOD - [2012.07.04 19:12:20 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
MOD - [2012.07.04 19:10:48 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2011.01.26 07:38:58 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.ServiceProcess.resources.dll
MOD - [2009.02.27 16:41:26 | 000,311,296 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\pdfshell.DEU


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Programme\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012.09.20 22:23:34 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.09.07 00:31:28 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.20 19:35:02 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizerHelper.exe -- (SearchAnonymizer)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011.12.22 19:11:22 | 000,818,952 | ---- | M] (ABBYY) [Auto | Running] -- C:\Programme\ABBYY FineReader 11\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Professional.11.0)
SRV - [2011.04.22 14:21:10 | 000,092,592 | ---- | M] (TomTom) [Auto | Running] -- C:\Programme\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2010.05.04 12:07:22 | 000,503,080 | ---- | M] (Nero AG) [Auto | Running] -- C:\Programme\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2006.11.06 14:21:10 | 000,210,432 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2003.07.28 13:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2006.11.04 06:45:48 | 000,178,913 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\V0260Vid.sys -- (V0260VID)
DRV - [2006.10.10 08:54:34 | 000,138,240 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcd.sys -- (Nokia USB Phone Parent)
DRV - [2006.10.10 08:54:32 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcj.sys -- (Nokia USB Port)
DRV - [2006.10.10 08:54:32 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcm.sys -- (Nokia USB Modem)
DRV - [2006.10.10 08:54:32 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdc.sys -- (Nokia USB Generic)
DRV - [2006.10.05 17:07:28 | 000,072,608 | ---- | M] (PACE Anti-Piracy, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\TPkd.sys -- (TPkd)
DRV - [2006.08.02 22:09:00 | 000,674,560 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w70n51.sys -- (w70n51)
DRV - [2003.06.23 10:35:48 | 000,092,840 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2003.06.23 10:35:40 | 001,170,464 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2003.06.23 10:35:16 | 000,046,976 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\R8139n51.sys -- (rtl8139)
DRV - [2003.06.23 10:35:14 | 000,035,913 | ---- | M] (SMC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA)
DRV - [2003.06.23 10:35:02 | 000,033,335 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wa301a.sys -- ({E2B953A6-195A-44F9-9BA3-3D5F4E32BB55})
DRV - [2003.06.20 19:51:16 | 000,740,044 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM)
DRV - [2003.02.21 11:20:14 | 000,065,076 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2002.11.20 14:52:14 | 000,033,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gv3.sys -- (gv3)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E62696E672E636F6D2F7365617263683F713D7B7365617263685465726D737D267372633D49452D536561726368426F7826464F524D3D4945385352 43&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&k=0
IE - HKCU\..\SearchScopes\{106E777E-C0C8-49B4-8409-5694E52FF2E1}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{11DA52D7-5B49-4C13-8F9E-4D8C40B84698}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{24B87460-205C-42B3-9598-683BFAFF6727}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{768963F2-ACE9-4A69-959F-B35479C58E7A}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{85F8B379-DE8F-4B16-A4AF-A820F54A8FF9}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{CD0A6457-AE13-4247-898F-94939EF8465D}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: {6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}:1.4.14
FF - prefs.js..extensions.enabledAddons: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.4.8.2
FF - prefs.js..extensions.enabledAddons: mintrayr@tn123.ath.cx:1.1.1
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.91
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: KavAntiBanner@Kaspersky.ru:11.0.0.232
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.0.232
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.9.3
FF - prefs.js..extensions.enabledItems: {6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}:1.4.14
FF - prefs.js..extensions.enabledItems: {de1b245c-de57-11da-ba2d-0050c2490048}:1.0.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: F:\Programme\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programme\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.09.07 00:30:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012.09.07 00:30:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2010.11.08 13:42:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\firejump@firejump.net [2012.07.20 19:35:26 | 000,000,000 | ---D | M]

[2010.11.08 13:18:10 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Extensions
[2010.11.08 13:43:48 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.06.26 19:21:40 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Extensions\home2@tomtom.com
[2010.11.08 13:18:10 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions
[2011.03.16 18:43:08 | 000,000,000 | ---D | M] (Fire.fm) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\{6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}
[2012.07.20 19:35:26 | 000,000,000 | ---D | M] (FireJump) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\firejump@firejump.net
[2012.10.06 12:21:46 | 000,000,000 | ---D | M] (MinimizeToTray revived (MinTrayR)) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\mintrayr@tn123.ath.cx
[2011.12.27 14:12:58 | 000,000,000 | ---D | M] (Yontoo Layers) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com
[2012.09.27 17:28:14 | 000,340,018 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
[2012.10.04 02:05:36 | 000,741,958 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.07.20 19:36:06 | 000,001,122 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin.xml
[2012.07.20 19:36:06 | 000,001,105 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin-1.xml
[2012.07.20 19:36:06 | 000,001,105 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin-2.xml
[2012.07.20 19:36:06 | 000,001,105 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin-3.xml
[2012.07.20 19:36:06 | 000,001,872 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\{AEE21247-EEFF-4752-82CD-CB25D64316A9}.xml
[2012.07.20 19:36:06 | 000,002,079 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\{29429F6F-EEFE-4EC9-97A1-AD0117DC8386}.xml
[2012.07.20 19:36:06 | 000,002,190 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\{C6850F3F-BED9-4BAD-A409-FF2D6BABAF74}.xml
[2012.09.07 00:30:20 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.09.07 00:31:36 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2012.06.28 17:42:00 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\mozilla firefox\plugins\npwachk.dll
[2010.11.08 13:38:36 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll
[2012.08.28 23:53:36 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
[2012.08.28 23:53:36 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.08.28 23:53:36 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.08.28 23:53:36 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012.08.28 23:53:36 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.08.28 23:53:36 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml

O1 HOSTS File: ([2003.04.02 12:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Programme\Yontoo Layers Runtime\YontooIEClient.dll (Yontoo LLC)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programme\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Bonus.SSR.FR11] C:\Programme\ABBYY FineReader 11\Bonus.ScreenshotReader.exe (ABBYY.)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [Ocs_SM] C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizer.exe (OCS)
O4 - HKCU..\Run: [Facebook Update] C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Easy-WebPrint - Drucken - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint - Vorschau - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Programme\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Programme\ICQ7.6\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289218268510 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F16A39D5-0872-4126-9C9D-D7630F36E7DD}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.09.15 06:12:14 | 000,000,080 | -H-- | M] () - F:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012.10.03 19:49:28 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Malwarebytes
[2012.10.03 19:48:40 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.10.03 19:48:38 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2012.10.03 19:48:37 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.10.03 19:48:37 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2012.10.02 23:49:19 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Microsoft Office Live Add-in
[2012.09.21 15:43:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Microsoft Office
[2012.09.21 15:41:49 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\DESIGNER
[2012.09.21 15:40:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2012.09.21 15:40:34 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft.NET
[2012.09.21 15:40:34 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Office
[2012.09.19 19:41:14 | 000,000,000 | ---D | C] -- C:\MappedFiles
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012.10.08 17:29:34 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\defogger_reenable
[2012.10.08 17:22:02 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.10.08 17:09:38 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.10.08 12:51:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.10.08 12:51:18 | 519,622,656 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.05 23:19:12 | 000,001,194 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1582333133-1907411925-173008773-1005Core1cd62cec2a47ee0.job
[2012.10.05 07:52:10 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012.10.03 19:48:42 | 000,000,664 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.03 17:16:42 | 000,142,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.09.21 15:47:00 | 000,000,400 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2012.09.19 19:53:16 | 000,000,000 | ---- | M] () -- C:\WINDOWS\pcvcdvw.INI
[2012.09.19 19:53:14 | 000,000,062 | ---- | M] () -- C:\WINDOWS\pcvcdbr.INI
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012.10.08 17:29:32 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\MR\defogger_reenable
[2012.10.03 19:48:41 | 000,000,664 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.21 15:46:59 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012.09.19 19:53:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\pcvcdvw.INI
[2012.09.19 19:53:12 | 000,000,062 | ---- | C] () -- C:\WINDOWS\pcvcdbr.INI
[2012.07.20 19:59:32 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
[2012.07.20 19:35:14 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\sqlite36_engine.dll
[2011.12.27 16:19:51 | 000,017,408 | ---- | C] () -- C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\WebpageIcons.db
[2011.12.15 23:42:23 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\$_hpcst$.hpc
[2011.07.22 22:33:54 | 000,000,924 | ---- | C] () -- C:\WINDOWS\posteriza.INI
[2010.12.16 21:35:34 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.12.15 18:50:28 | 000,019,160 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010.11.18 20:43:29 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS66.DLL
[2010.11.08 13:53:26 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2010.11.08 13:29:07 | 000,146,432 | ---- | C] () -- C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.11.08 13:18:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010.05.21 15:05:54 | 003,099,648 | ---- | C] () -- C:\Programme\openofficeorg32.msi
[2010.05.21 15:04:24 | 000,460,088 | ---- | C] () -- C:\Programme\setup.exe
[2010.05.21 15:02:28 | 145,988,142 | ---- | C] () -- C:\Programme\openofficeorg1.cab
[2010.05.21 14:07:44 | 000,000,290 | ---- | C] () -- C:\Programme\setup.ini

========== ZeroAccess Check ==========

[2011.01.26 07:34:52 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll -- [2008.04.14 03:22:26 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll -- [2009.02.09 11:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll -- [2008.04.14 03:22:32 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2010.11.08 13:51:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ICQ
[2010.11.08 14:34:16 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2010.11.08 14:35:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2010.11.08 15:50:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010.11.16 17:10:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Downloaded Installations
[2010.11.16 17:37:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Suite
[2011.06.26 19:23:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TomTom
[2011.11.12 01:38:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer
[2012.07.19 22:29:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PACE Anti-Piracy
[2003.06.23 19:08:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\InterTrust
[2010.11.08 13:43:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Thunderbird
[2010.11.08 13:51:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\ICQ
[2010.11.08 14:36:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\TuneUp Software
[2010.11.12 17:47:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OpenOffice.org
[2010.11.16 17:33:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\PC Suite
[2010.11.16 17:37:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Nokia
[2011.01.26 07:58:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Canon
[2011.06.26 19:21:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\TomTom
[2012.07.19 22:29:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\PACE Anti-Piracy
[2012.07.20 19:34:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\DesktopIconForAmazon
[2012.07.20 19:35:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS
[2012.07.20 19:36:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Opera
[2012.09.04 02:18:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OpenCandy

========== Purity Check ==========



< End of report >

OTL Extras logfile created on: 08.10.2012 17:35:22 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\MR\Eigene Dateien\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

495,48 Mb Total Physical Memory | 178,41 Mb Available Physical Memory | 36,01% Memory free
1,62 Gb Paging File | 1,31 Gb Available in Paging File | 81,20% Paging File free
Paging file location(s): C:\pagefile.sys 744 1488 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 18,16 Gb Total Space | 1,37 Gb Free Space | 7,56% Space Free | Partition Type: FAT32
Drive D: | 9,76 Gb Total Space | 9,63 Gb Free Space | 98,71% Space Free | Partition Type: FAT32
Drive F: | 931,51 Gb Total Space | 649,55 Gb Free Space | 69,73% Space Free | Partition Type: NTFS

Computer Name: ACER-5J0JDWIJ8Z | User Name: MR | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Digital Photo Professional] -- F:\Programme\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "C:\Programme\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Programme\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Programme\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1723:TCP" = 1723:TCP:*:Enabled:@xpsp2res.dll,-22015
"1701:UDP" = 1701:UDP:*:Enabled:@xpsp2res.dll,-22016
"500:UDP" = 500:UDP:*:Enabled:@xpsp2res.dll,-22017
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1723:TCP" = 1723:TCP:*:Enabled:@xpsp2res.dll,-22015
"1701:UDP" = 1701:UDP:*:Enabled:@xpsp2res.dll,-22016
"500:UDP" = 500:UDP:*:Enabled:@xpsp2res.dll,-22017
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Programme\Windows Live\Messenger\wlcsdk.exe" = C:\Programme\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Programme\Windows Live\Messenger\msnmsgr.exe" = C:\Programme\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
"C:\Programme\ICQ7.6\ICQ.exe" = C:\Programme\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6 -- (ICQ, LLC.)
"C:\Programme\Microsoft ActiveSync\rapimgr.exe" = C:\Programme\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager -- (Microsoft Corporation)
"C:\Programme\Microsoft ActiveSync\wcescomm.exe" = C:\Programme\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager -- (Microsoft Corporation)
"C:\Programme\Microsoft ActiveSync\WCESMgr.exe" = C:\Programme\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Programme\Messenger\msmsgs.exe" = C:\Programme\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation)
"C:\Programme\Windows Live\Messenger\wlcsdk.exe" = C:\Programme\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Programme\Windows Live\Messenger\msnmsgr.exe" = C:\Programme\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
"C:\Programme\Skype\Plugin Manager\skypePM.exe" = C:\Programme\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
"C:\Programme\ICQ7.6\ICQ.exe" = C:\Programme\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6 -- (ICQ, LLC.)
"C:\Programme\Microsoft ActiveSync\rapimgr.exe" = C:\Programme\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager -- (Microsoft Corporation)
"C:\Programme\Microsoft ActiveSync\wcescomm.exe" = C:\Programme\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager -- (Microsoft Corporation)
"C:\Programme\Microsoft ActiveSync\WCESMgr.exe" = C:\Programme\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application -- (Microsoft Corporation)
"C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Facebook\Video\Skype\FacebookVideoCalling.exe" = C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin -- (Skype Limited)
"C:\Programme\Mozilla Firefox\plugin-container.exe" = C:\Programme\Mozilla Firefox\plugin-container.exe:*:Enabled:Plugin Container for Firefox -- (Mozilla Corporation)
"C:\Programme\Java\JRE6\BIN\javaw.exe" = C:\Programme\Java\JRE6\BIN\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Programme\Skype\Phone\Skype.exe" = C:\Programme\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02091327-B124-4216-9D71-58C0E24F5392}" = Nokia PC Suite
"{04F3BF74-9E34-4D3E-93C3-D3D1F24199C8}" = PC Connectivity Solution
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216020F0}" = Java(TM) 6 Update 20
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 22
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3BFFC6B8-4EC0-4240-858C-998FD4077983}" = Nokia Connectivity Cable Driver
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68E6762C-20CA-41B2-8720-1B178B2C6AED}" = DxO FilmPack 2.0
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7644E42D-B096-457F-8B5B-901238FC81AE}" = ICQ7.6
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}" = Nero BurnLite 10
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Runtime 1.10.01
"{8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38}" = Microsoft .NET Framework 2.0 Language Pack - DEU
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Extreme Graphics Driver
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}" = Nero BurnLite 10
"{AC76BA86-7AD7-1031-7B44-A95000000001}" = Adobe Reader 9.5.2 - Deutsch
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C438B7C4-B4F8-49C5-A4DF-FF6F1F242778}" = NTI CD & DVD-Maker
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call
"{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1" = FireJump
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1100000-0011-0000-0001-074957833700}" = ABBYY FineReader 11
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"0852D05415AB9A4F1EF451E342267F76C776ED2F" = Windows Driver Package - Nokia Modem (11/03/2006 6.82.0.1)
"4CFD94C379217A02D5EA067615FF789CD731BCDB" = Windows Driver Package - Nokia (WUDFRd) WPD (11/03/2006 6.82.26.2)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Agere Systems Soft Modem" = Agere Systems AC'97 Modem
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"CANONBJ_Deinstall_CNMCP66.DLL" = Canon PIXMA iP2000
"Creative VF0260" = Creative Live! Cam Vista IM Driver (1.01.03.1104)
"DPP" = Canon Utilities Digital Photo Professional 3.8
"Easy-WebPrint" = Easy-WebPrint
"EOS Utility" = Canon Utilities EOS Utility
"ie8" = Windows Internet Explorer 8
"Indeo® Software" = Indeo® Software
"InstallShield_{C438B7C4-B4F8-49C5-A4DF-FF6F1F242778}" = NTI CD & DVD-Maker 6 Gold
"JDownloader" = JDownloader
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.0.1400
"Microsoft .NET Framework 2.0 Language Pack - DEU" = Microsoft .NET Framework 2.0 Language Pack - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox 15.0.1 (x86 de)" = Mozilla Firefox 15.0.1 (x86 de)
"Mozilla Thunderbird 15.0.1 (x86 de)" = Mozilla Thunderbird 15.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"PhotoStitch" = Canon Utilities PhotoStitch
"Picture Style Editor" = Canon Utilities Picture Style Editor
"SearchAnonymizer" = SearchAnonymizer
"TomTom HOME" = TomTom HOME 2.8.2.2264
"TravelMate 290" = TravelMate 290
"VLC media player" = VLC media player 1.1.4
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Erkennungs-Plug-in

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 11.09.2012 13:39:39 | Computer Name = ACER-5J0JDWIJ8Z | Source = Google Update | ID = 20
Description =

Error - 17.09.2012 09:23:06 | Computer Name = ACER-5J0JDWIJ8Z | Source = Google Update | ID = 20
Description =

Error - 17.09.2012 09:30:47 | Computer Name = ACER-5J0JDWIJ8Z | Source = Google Update | ID = 20
Description =

Error - 21.09.2012 09:32:12 | Computer Name = ACER-5J0JDWIJ8Z | Source = MsiInstaller | ID = 10005
Description = Product: Adobe After Effects 7.0 -- You must install Adobe After Effects
7.0 using Setup.exe.

Error - 24.09.2012 16:21:10 | Computer Name = ACER-5J0JDWIJ8Z | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung winamp.exe, Version 5.6.3.3235, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.

Error - 25.09.2012 12:56:50 | Computer Name = ACER-5J0JDWIJ8Z | Source = Google Update | ID = 20
Description =

Error - 25.09.2012 17:38:48 | Computer Name = ACER-5J0JDWIJ8Z | Source = Google Update | ID = 20
Description =

Error - 04.10.2012 18:29:04 | Computer Name = ACER-5J0JDWIJ8Z | Source = Google Update | ID = 20
Description =

Error - 04.10.2012 21:29:04 | Computer Name = ACER-5J0JDWIJ8Z | Source = Google Update | ID = 20
Description =

Error - 05.10.2012 00:29:02 | Computer Name = ACER-5J0JDWIJ8Z | Source = Google Update | ID = 20
Description =

[ System Events ]
Error - 06.10.2012 06:19:49 | Computer Name = ACER-5J0JDWIJ8Z | Source = Dhcp | ID = 1002
Description = Die IP-Adresslease 192.168.2.2 für die Netzwerkkarte mit der Netzwerkadresse
00023FBA476D wurde durch den DHCP-Server 192.168.2.1 abgelehnt (der DHCP-Server
hat eine DHCPNACK-Meldung gesendet).

Error - 06.10.2012 06:20:07 | Computer Name = ACER-5J0JDWIJ8Z | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Dienst "Bonjour"" wurde aufgrund folgenden Fehlers nicht
gestartet: %%3

Error - 06.10.2012 22:27:22 | Computer Name = ACER-5J0JDWIJ8Z | Source = Dhcp | ID = 1002
Description = Die IP-Adresslease 192.168.2.2 für die Netzwerkkarte mit der Netzwerkadresse
00023FBA476D wurde durch den DHCP-Server 192.168.2.1 abgelehnt (der DHCP-Server
hat eine DHCPNACK-Meldung gesendet).

Error - 06.10.2012 22:27:40 | Computer Name = ACER-5J0JDWIJ8Z | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Dienst "Bonjour"" wurde aufgrund folgenden Fehlers nicht
gestartet: %%3

Error - 07.10.2012 09:41:07 | Computer Name = ACER-5J0JDWIJ8Z | Source = Dhcp | ID = 1002
Description = Die IP-Adresslease 192.168.2.2 für die Netzwerkkarte mit der Netzwerkadresse
00023FBA476D wurde durch den DHCP-Server 192.168.2.1 abgelehnt (der DHCP-Server
hat eine DHCPNACK-Meldung gesendet).

Error - 07.10.2012 09:41:25 | Computer Name = ACER-5J0JDWIJ8Z | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Dienst "Bonjour"" wurde aufgrund folgenden Fehlers nicht
gestartet: %%3

Error - 07.10.2012 17:44:00 | Computer Name = ACER-5J0JDWIJ8Z | Source = Dhcp | ID = 1002
Description = Die IP-Adresslease 192.168.2.2 für die Netzwerkkarte mit der Netzwerkadresse
00023FBA476D wurde durch den DHCP-Server 192.168.2.1 abgelehnt (der DHCP-Server
hat eine DHCPNACK-Meldung gesendet).

Error - 07.10.2012 17:44:18 | Computer Name = ACER-5J0JDWIJ8Z | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Dienst "Bonjour"" wurde aufgrund folgenden Fehlers nicht
gestartet: %%3

Error - 08.10.2012 06:51:22 | Computer Name = ACER-5J0JDWIJ8Z | Source = Dhcp | ID = 1002
Description = Die IP-Adresslease 192.168.2.2 für die Netzwerkkarte mit der Netzwerkadresse
00023FBA476D wurde durch den DHCP-Server 192.168.2.1 abgelehnt (der DHCP-Server
hat eine DHCPNACK-Meldung gesendet).

Error - 08.10.2012 06:51:39 | Computer Name = ACER-5J0JDWIJ8Z | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Dienst "Bonjour"" wurde aufgrund folgenden Fehlers nicht
gestartet: %%3

[ TuneUp Events ]
Error - 01.12.2011 17:55:55 | Computer Name = ACER-5J0JDWIJ8Z | Source = TuneUp.UtilitiesSvc | ID = 300
Description =


< End of report >


GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-10-08 18:06:20
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 IC25N030ATMR04-0 rev.MOAOAD0A
Running: tvnerng5.exe; Driver: C:\DOKUME~1\MR\LOKALE~1\Temp\pgxyrfoc.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

cosinus 08.10.2012 20:13

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

perry85 08.10.2012 20:38

Also wenn ist das schon lange her, ich hatte schon mal vor ein paar jahren ein problem in dem berech. hab aber Malwarebytes erst jetzt neu installiert.

und sonst stehen da nur solche sachen im Reiter Logdateien.



2012/10/03 19:50:34 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Starting protection
2012/10/03 19:50:35 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Protection started successfully
2012/10/03 19:50:35 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Starting IP protection
2012/10/03 19:50:57 +0200 ACER-5J0JDWIJ8Z MR MESSAGE IP Protection started successfully
2012/10/03 19:51:37 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Starting database refresh
2012/10/03 19:51:37 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Stopping IP protection
2012/10/03 19:51:38 +0200 ACER-5J0JDWIJ8Z MR MESSAGE IP Protection stopped successfully
2012/10/03 19:51:53 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Database refreshed successfully
2012/10/03 19:51:53 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Starting IP protection
2012/10/03 19:52:08 +0200 ACER-5J0JDWIJ8Z MR MESSAGE IP Protection started successfully
2012/10/03 20:05:52 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Executing scheduled update: Daily
2012/10/03 20:05:58 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Database already up-to-date

2012/10/04 11:13:10 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Starting protection
2012/10/04 11:13:10 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Protection started successfully
2012/10/04 11:13:10 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Starting IP protection
2012/10/04 11:14:52 +0200 ACER-5J0JDWIJ8Z MR MESSAGE IP Protection started successfully
2012/10/04 11:23:33 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Executing scheduled update: Daily
2012/10/04 11:23:53 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Scheduled update executed successfully: database updated from version v2012.10.03.08 to version v2012.10.04.04
2012/10/04 11:23:53 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Starting database refresh
2012/10/04 11:23:53 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Stopping IP protection
2012/10/04 11:23:54 +0200 ACER-5J0JDWIJ8Z MR MESSAGE IP Protection stopped successfully
2012/10/04 11:24:37 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Database refreshed successfully
2012/10/04 11:24:37 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Starting IP protection
2012/10/04 11:24:50 +0200 ACER-5J0JDWIJ8Z MR MESSAGE IP Protection started successfully
2012/10/04 21:16:33 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Starting protection
2012/10/04 21:16:33 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Protection started successfully
2012/10/04 21:16:33 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Starting IP protection
2012/10/04 21:18:13 +0200 ACER-5J0JDWIJ8Z MR MESSAGE IP Protection started successfully

2012/10/05 07:12:49 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Executing scheduled update: Daily
2012/10/05 07:12:50 +0200 ACER-5J0JDWIJ8Z MR ERROR Scheduled update failed: Host not found failed with error code 0

2012/10/06 12:20:17 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Executing scheduled update: Daily
2012/10/06 12:20:42 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Scheduled update executed successfully: database updated from version v2012.10.04.04 to version v2012.10.06.02

2012/10/07 15:44:59 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Executing scheduled update: Daily
2012/10/07 15:46:44 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Scheduled update executed successfully: database updated from version v2012.10.06.02 to version v2012.10.07.03

2012/10/08 12:53:57 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Executing scheduled update: Daily
2012/10/08 12:55:29 +0200 ACER-5J0JDWIJ8Z MR MESSAGE Scheduled update executed successfully: database updated from version v2012.10.07.03 to version v2012.10.08.03

cosinus 09.10.2012 11:07

Bitte routinemäßig einen neuen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

perry85 10.10.2012 20:36

Code:

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=7bb54b6c4620184f94d8263b7646c0ac
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-10-10 12:17:38
# local_time=2012-10-10 02:17:38 (+0100, Westeuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=8192 67108863 100 0 2300 2300 0 0
# scanned=13251
# found=0
# cleaned=0
# scan_time=888
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=7bb54b6c4620184f94d8263b7646c0ac
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-10-10 02:33:33
# local_time=2012-10-10 04:33:33 (+0100, Westeuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=8192 67108863 100 0 3737 3737 0 0
# scanned=247953
# found=6
# cleaned=0
# scan_time=7608
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll        a variant of Win32/Adware.Yontoo.B application (unable to clean)        00000000000000000000000000000000        I
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll        a variant of Win32/Adware.Yontoo.B application (unable to clean)        00000000000000000000000000000000        I
C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Temp\YontooSetup-Silent.exe        Win32/Adware.Yontoo application (unable to clean)        00000000000000000000000000000000        I
C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Temp\YontooIEClient.dll        a variant of Win32/Adware.Yontoo.A application (unable to clean)        00000000000000000000000000000000        I
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com\content\overlay.js        Win32/Adware.Yontoo application (unable to clean)        00000000000000000000000000000000        I
C:\Programme\Yontoo Layers Runtime\YontooIEClient.dll        a variant of Win32/Adware.Yontoo.A application (unable to clean)        00000000000000000000000000000000        I
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=7bb54b6c4620184f94d8263b7646c0ac
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-10-10 11:29:44
# local_time=2012-10-10 01:29:44 (+0100, Westeuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=8192 67108863 100 0 31472 31472 0 0
# scanned=247844
# found=8
# cleaned=0
# scan_time=12069
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll        a variant of Win32/Adware.Yontoo.B application (unable to clean)        00000000000000000000000000000000        I
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll        a variant of Win32/Adware.Yontoo.B application (unable to clean)        00000000000000000000000000000000        I
C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Temp\YontooSetup-Silent.exe        Win32/Adware.Yontoo application (unable to clean)        00000000000000000000000000000000        I
C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Temp\YontooLayers.crx        Win32/Adware.Yontoo.C application (unable to clean)        00000000000000000000000000000000        I
C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Temp\YontooFFClient.xpi        Win32/Adware.Yontoo application (unable to clean)        00000000000000000000000000000000        I
C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Temp\YontooIEClient.dll        a variant of Win32/Adware.Yontoo.A application (unable to clean)        00000000000000000000000000000000        I
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com\content\overlay.js        Win32/Adware.Yontoo application (unable to clean)        00000000000000000000000000000000        I
C:\Programme\Yontoo Layers Runtime\YontooIEClient.dll        a variant of Win32/Adware.Yontoo.A application (unable to clean)        00000000000000000000000000000000        I

Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.10.09.09

Windows XP Service Pack 3 x86 FAT32
Internet Explorer 8.0.6001.18702
MR :: ACER-5J0JDWIJ8Z [Administrator]

Schutz: Deaktiviert

09.10.2012 19:09:35
mbam-log-2012-10-09 (19-09-35).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|G:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 422721
Laufzeit: 3 Stunde(n), 24 Minute(n), 57 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Dokumente und Einstellungen\MR\Eigene Dateien\Downloads\SoftonicDownloader_fuer_artistic-font-collection.exe (PUP.OfferBundler.ST) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


cosinus 11.10.2012 13:03

Code:

C:\Dokumente und Einstellungen\MR\Eigene Dateien\Downloads\SoftonicDownloader_fuer_artistic-font-collection.exe
Vermüllte Software von Softonic scheint gerade stark in Mode zu sein! :stirn:

Finger weg von Softonic!! :pfui:

Softonic ist eine Toolbar- und Adwareschleuder! Finger weg! Software lädt man sich mit oberster Priorität direkt vom Hersteller und nicht von solchen Toolbarklitschen wie Softonic! Im Notfall würde natürlich chip.de gehen


adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.

Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Rx].txt. (x=fortlaufende Nummer)

perry85 11.10.2012 19:52

Code:

  # AdwCleaner v2.004 - Datei am 11/10/2012 um 20:47:40 erstellt
# Aktualisiert am 06/10/2012 von Xplode
# Betriebssystem : Microsoft Windows XP Service Pack 3 (32 bits)
# Benutzer : MR - ACER-5J0JDWIJ8Z
# Bootmodus : Normal
# Ausgeführt unter : C:\Dokumente und Einstellungen\MR\Eigene Dateien\Downloads\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gefunden : C:\DOKUME~1\MR\LOKALE~1\Temp\AskSearch
Ordner Gefunden : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer
Ordner Gefunden : C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OpenCandy
Ordner Gefunden : C:\Programme\Yontoo Layers Runtime

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pm_launcher
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pm_launcher.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pm_printmanager
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pm_printmanager.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.tbtoolband
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.tbtoolband.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.useroptions
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\toolband.useroptions.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gefunden : HKLM\Software\Tarma Installer
Schlüssel Gefunden : HKU\S-1-5-21-1582333133-1907411925-173008773-1005\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Die Registrierungsdatenbank ist sauber.

*************************

AdwCleaner[R1].txt - [5061 octets] - [11/10/2012 20:47:40]

########## EOF - C:\AdwCleaner[R1].txt - [5121 octets] ##########


cosinus 12.10.2012 10:21

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Sx].txt. (x=fortlaufende Nummer)

perry85 12.10.2012 12:08

hi, hab gesehen das in meinem browser unter add ons Yontoo Layers auch ist. es ist deaktiviert. soll ich es entfernen?


Code:

# AdwCleaner v2.004 - Datei am 12/10/2012 um 12:54:49 erstellt
# Aktualisiert am 06/10/2012 von Xplode
# Betriebssystem : Microsoft Windows XP Service Pack 3 (32 bits)
# Benutzer : MR - ACER-5J0JDWIJ8Z
# Bootmodus : Normal
# Ausgeführt unter : C:\Dokumente und Einstellungen\MR\Eigene Dateien\Downloads\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\DOKUME~1\MR\LOKALE~1\Temp\AskSearch
Ordner Gelöscht : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer
Ordner Gelöscht : C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OpenCandy
Ordner Gelöscht : C:\Programme\Yontoo Layers Runtime

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.pm_launcher
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.pm_launcher.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.pm_printmanager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.pm_printmanager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.tbtoolband
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.tbtoolband.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.useroptions
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\toolband.useroptions.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gelöscht : HKLM\Software\Tarma Installer
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Die Registrierungsdatenbank ist sauber.

*************************

AdwCleaner[R1].txt - [5190 octets] - [11/10/2012 20:47:40]
AdwCleaner[S1].txt - [4962 octets] - [12/10/2012 12:54:49]

########## EOF - C:\AdwCleaner[S1].txt - [5022 octets] ##########


cosinus 12.10.2012 14:35

Hätte da mal zwei Fragen bevor es weiter geht (wir sind noch nicht fertig!)

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

perry85 12.10.2012 15:20

Also ich weis nicht genau was du mit normalem modus meinst? Aber z.b. in der task leiste ist oft nicht das was ich ein gestellt hab.

Im startmenü ist eigentlich alles da denke ich, keine leeren ordner.

weis nicht obs noch interessant ist aber es stürzt jetzt auf ein mal immer ein quick time plug in ab im browser. und es kommen noch immer meldungen das „skript konnte nicht beendet werden“ und „nicht antwortendes skript“

cosinus 12.10.2012 17:47

Es gibt einen normalen Windows-Start und den abgsicherten Modus mit verschiedenen Optionen. Offensichtlich läuft bei dir der normale Modus ohne Probleme.

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


perry85 13.10.2012 00:38

OTL Logfile:
Code:

OTL logfile created on: 13.10.2012 01:10:25 - Run 2
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Dokumente und Einstellungen\MR\Eigene Dateien\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
495,48 Mb Total Physical Memory | 199,87 Mb Available Physical Memory | 40,34% Memory free
1,13 Gb Paging File | 0,82 Gb Available in Paging File | 72,22% Paging File free
Paging file location(s): C:\pagefile.sys 744 1488 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 18,16 Gb Total Space | 1,13 Gb Free Space | 6,24% Space Free | Partition Type: FAT32
Drive D: | 9,76 Gb Total Space | 9,63 Gb Free Space | 98,71% Space Free | Partition Type: FAT32
Drive F: | 931,51 Gb Total Space | 650,57 Gb Free Space | 69,84% Space Free | Partition Type: NTFS
Drive G: | 298,09 Gb Total Space | 17,23 Gb Free Space | 5,78% Space Free | Partition Type: NTFS
 
Computer Name: ACER-5J0JDWIJ8Z | User Name: MR | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.10.13 01:06:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\MR\Eigene Dateien\Downloads\OTL(1).exe
PRC - [2012.10.12 19:47:50 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.07.20 19:35:02 | 000,040,960 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizerHelper.exe
PRC - [2012.07.15 23:14:00 | 000,138,096 | ---- | M] (Facebook Inc.) -- C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Facebook\Update\FacebookUpdate.exe
PRC - [2011.12.22 19:11:22 | 000,818,952 | ---- | M] (ABBYY) -- C:\Programme\ABBYY FineReader 11\NetworkLicenseServer.exe
PRC - [2011.04.22 14:21:10 | 000,092,592 | ---- | M] (TomTom) -- C:\Programme\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2010.05.04 12:07:22 | 000,503,080 | ---- | M] (Nero AG) -- C:\Programme\Nero\Update\NASvc.exe
PRC - [2008.04.14 03:22:46 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.10.12 19:47:48 | 002,294,240 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll
MOD - [2012.07.20 19:35:02 | 000,040,960 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizerHelper.exe
MOD - [2012.07.04 19:23:50 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll
MOD - [2012.07.04 19:20:20 | 001,712,128 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\359fd69eb60e9844ffd497e92345178c\Microsoft.VisualBasic.ni.dll
MOD - [2012.07.04 19:16:44 | 012,433,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll
MOD - [2012.07.04 19:16:16 | 001,592,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll
MOD - [2012.07.04 19:12:20 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
MOD - [2012.07.04 19:10:48 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2011.01.26 07:38:58 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.ServiceProcess.resources.dll
MOD - [2009.02.27 16:41:26 | 000,311,296 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\pdfshell.DEU
 
 
========== Services (SafeList) ==========
 
SRV - File not found [Auto | Stopped] -- C:\Programme\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012.10.12 19:47:48 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.10.09 20:23:10 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.07.20 19:35:02 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizerHelper.exe -- (SearchAnonymizer)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011.12.22 19:11:22 | 000,818,952 | ---- | M] (ABBYY) [Auto | Running] -- C:\Programme\ABBYY FineReader 11\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Professional.11.0)
SRV - [2011.04.22 14:21:10 | 000,092,592 | ---- | M] (TomTom) [Auto | Running] -- C:\Programme\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2010.05.04 12:07:22 | 000,503,080 | ---- | M] (Nero AG) [Auto | Running] -- C:\Programme\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2006.11.06 14:21:10 | 000,210,432 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2003.07.28 13:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - [2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2006.11.04 06:45:48 | 000,178,913 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\V0260Vid.sys -- (V0260VID)
DRV - [2006.10.10 08:54:34 | 000,138,240 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcd.sys -- (Nokia USB Phone Parent)
DRV - [2006.10.10 08:54:32 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcj.sys -- (Nokia USB Port)
DRV - [2006.10.10 08:54:32 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcm.sys -- (Nokia USB Modem)
DRV - [2006.10.10 08:54:32 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdc.sys -- (Nokia USB Generic)
DRV - [2006.10.05 17:07:28 | 000,072,608 | ---- | M] (PACE Anti-Piracy, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\TPkd.sys -- (TPkd)
DRV - [2006.08.02 22:09:00 | 000,674,560 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w70n51.sys -- (w70n51)
DRV - [2003.06.23 10:35:48 | 000,092,840 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2003.06.23 10:35:40 | 001,170,464 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2003.06.23 10:35:16 | 000,046,976 | ---- | M] (Realtek Semiconductor Corporation      ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\R8139n51.sys -- (rtl8139)
DRV - [2003.06.23 10:35:14 | 000,035,913 | ---- | M] (SMC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA)
DRV - [2003.06.23 10:35:02 | 000,033,335 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wa301a.sys -- ({E2B953A6-195A-44F9-9BA3-3D5F4E32BB55})
DRV - [2003.06.20 19:51:16 | 000,740,044 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM)
DRV - [2003.02.21 11:20:14 | 000,065,076 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2002.11.20 14:52:14 | 000,033,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gv3.sys -- (gv3)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope =
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes\{106E777E-C0C8-49B4-8409-5694E52FF2E1}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes\{11DA52D7-5B49-4C13-8F9E-4D8C40B84698}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes\{24B87460-205C-42B3-9598-683BFAFF6727}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes\{768963F2-ACE9-4A69-959F-B35479C58E7A}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes\{85F8B379-DE8F-4B16-A4AF-A820F54A8FF9}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes\{CD0A6457-AE13-4247-898F-94939EF8465D}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: mintrayr@tn123.ath.cx:1.1.1
FF - prefs.js..extensions.enabledAddons: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.4.8.3
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.91
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: KavAntiBanner@Kaspersky.ru:11.0.0.232
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.0.232
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.9.3
FF - prefs.js..extensions.enabledItems: {6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}:1.4.14
FF - prefs.js..extensions.enabledItems: {de1b245c-de57-11da-ba2d-0050c2490048}:1.0.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: F:\Programme\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programme\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.10.12 19:46:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012.10.12 19:46:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2010.11.08 13:42:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\firejump@firejump.net [2012.07.20 19:35:26 | 000,000,000 | ---D | M]
 
[2010.11.08 13:18:10 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Extensions
[2010.11.08 13:43:48 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.06.26 19:21:40 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Extensions\home2@tomtom.com
[2010.11.08 13:18:10 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions
[2012.07.20 19:35:26 | 000,000,000 | ---D | M] (FireJump) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\firejump@firejump.net
[2012.10.06 12:21:46 | 000,000,000 | ---D | M] (MinimizeToTray revived (MinTrayR)) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\mintrayr@tn123.ath.cx
[2011.12.27 14:12:58 | 000,000,000 | ---D | M] (Yontoo Layers) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com
[2012.10.10 01:11:22 | 000,340,256 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
[2012.10.11 01:17:24 | 000,088,614 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\extension@ciuvo.com.xpi
[2012.10.04 02:05:36 | 000,741,958 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.07.20 19:36:06 | 000,001,122 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin.xml
[2012.07.20 19:36:06 | 000,001,105 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin-1.xml
[2012.07.20 19:36:06 | 000,001,105 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin-2.xml
[2012.07.20 19:36:06 | 000,001,105 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin-3.xml
[2012.07.20 19:36:06 | 000,001,872 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\{AEE21247-EEFF-4752-82CD-CB25D64316A9}.xml
[2012.07.20 19:36:06 | 000,002,079 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\{29429F6F-EEFE-4EC9-97A1-AD0117DC8386}.xml
[2012.07.20 19:36:06 | 000,002,190 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\{C6850F3F-BED9-4BAD-A409-FF2D6BABAF74}.xml
[2012.10.12 19:46:52 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.10.12 19:47:50 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2012.06.28 17:42:00 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\mozilla firefox\plugins\npwachk.dll
[2010.11.08 13:38:36 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll
[2012.08.28 23:53:36 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
[2012.08.28 23:53:36 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.08.28 23:53:36 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.08.28 23:53:36 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012.08.28 23:53:36 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.08.28 23:53:36 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
 
O1 HOSTS File: ([2003.04.02 12:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programme\Canon\Easy-WebPrint\Toolband.dll ()
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Bonus.SSR.FR11] C:\Programme\ABBYY FineReader 11\Bonus.ScreenshotReader.exe (ABBYY.)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [Ocs_SM] C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizer.exe (OCS)
O4 - HKU\.DEFAULT..\Run: [PcSync] C:\Programme\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
O4 - HKU\S-1-5-18..\Run: [PcSync] C:\Programme\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
O4 - HKU\S-1-5-21-1582333133-1907411925-173008773-1005..\Run: [Facebook Update] C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Easy-WebPrint - Drucken - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint - Vorschau - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Programme\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Programme\ICQ7.6\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289218268510 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.09.15 06:12:14 | 000,000,080 | -H-- | M] () - F:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: 6to4 -  File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
MsConfig - StartUpReg: PCSuiteTrayApplication - hkey= - key= - C:\Programme\Nokia\Nokia PC Suite 6\LaunchApplication.exe (Nokia)
MsConfig - StartUpReg: TomTomHOME.exe - hkey= - key= - C:\Programme\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2
 
SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Sicherheitsupdate für Windows XP (KB923789)
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\INF\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
 
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Ligos Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll (Ligos Corporation)
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll (Ligos Corporation)
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Ligos Corporation)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.12 19:46:49 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2012.10.10 01:24:41 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2012.10.03 19:49:28 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Malwarebytes
[2012.10.03 19:48:40 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.10.03 19:48:38 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2012.10.03 19:48:37 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.10.03 19:48:37 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2012.10.02 23:49:19 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Microsoft Office Live Add-in
[2012.09.21 15:43:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Microsoft Office
[2012.09.21 15:41:49 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\DESIGNER
[2012.09.21 15:40:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2012.09.21 15:40:34 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft.NET
[2012.09.21 15:40:34 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Office
[2012.09.19 19:41:14 | 000,000,000 | ---D | C] -- C:\MappedFiles
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.13 00:22:04 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.10.12 23:19:08 | 000,001,194 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1582333133-1907411925-173008773-1005Core1cd62cec2a47ee0.job
[2012.10.12 12:58:12 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.10.12 12:58:10 | 519,622,656 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.08 17:29:34 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\defogger_reenable
[2012.10.08 17:09:38 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.10.05 07:52:10 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012.10.03 19:48:42 | 000,000,664 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.03 17:16:42 | 000,142,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.09.21 15:47:00 | 000,000,400 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2012.09.19 19:53:16 | 000,000,000 | ---- | M] () -- C:\WINDOWS\pcvcdvw.INI
[2012.09.19 19:53:14 | 000,000,062 | ---- | M] () -- C:\WINDOWS\pcvcdbr.INI
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.10.08 17:29:32 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\MR\defogger_reenable
[2012.10.03 19:48:41 | 000,000,664 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.21 15:46:59 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012.09.19 19:53:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\pcvcdvw.INI
[2012.09.19 19:53:12 | 000,000,062 | ---- | C] () -- C:\WINDOWS\pcvcdbr.INI
[2012.07.20 19:59:32 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
[2012.07.20 19:35:14 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\sqlite36_engine.dll
[2011.12.27 16:19:51 | 000,017,408 | ---- | C] () -- C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\WebpageIcons.db
[2011.12.15 23:42:23 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\$_hpcst$.hpc
[2011.07.22 22:33:54 | 000,000,924 | ---- | C] () -- C:\WINDOWS\posteriza.INI
[2010.12.16 21:35:34 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.12.15 18:50:28 | 000,019,160 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010.11.18 20:43:29 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS66.DLL
[2010.11.08 13:53:26 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2010.11.08 13:29:07 | 000,146,432 | ---- | C] () -- C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.11.08 13:18:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010.05.21 15:05:54 | 003,099,648 | ---- | C] () -- C:\Programme\openofficeorg32.msi
[2010.05.21 15:04:24 | 000,460,088 | ---- | C] () -- C:\Programme\setup.exe
[2010.05.21 15:02:28 | 145,988,142 | ---- | C] () -- C:\Programme\openofficeorg1.cab
[2010.05.21 14:07:44 | 000,000,290 | ---- | C] () -- C:\Programme\setup.ini
 
========== ZeroAccess Check ==========
 
[2011.01.26 07:34:52 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll -- [2008.04.14 03:22:26 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll -- [2009.02.09 11:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll -- [2008.04.14 03:22:32 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2003.06.23 19:08:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Default User\Anwendungsdaten\InterTrust
[2010.11.08 13:51:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ICQ
[2010.11.08 14:34:16 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2010.11.08 14:35:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2010.11.08 15:50:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010.11.16 17:10:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Downloaded Installations
[2010.11.16 17:37:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Suite
[2011.06.26 19:23:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TomTom
[2012.07.19 22:29:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PACE Anti-Piracy
[2011.02.21 01:44:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\TuneUp Software
[2003.06.23 19:08:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\InterTrust
[2010.11.08 13:43:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Thunderbird
[2010.11.08 13:51:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\ICQ
[2010.11.08 14:36:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\TuneUp Software
[2010.11.12 17:47:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OpenOffice.org
[2010.11.16 17:33:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\PC Suite
[2010.11.16 17:37:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Nokia
[2011.01.26 07:58:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Canon
[2011.06.26 19:21:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\TomTom
[2012.07.19 22:29:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\PACE Anti-Piracy
[2012.07.20 19:34:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\DesktopIconForAmazon
[2012.07.20 19:35:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS
[2012.07.20 19:36:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Opera
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2003.06.23 18:49:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Identities
[2003.06.23 19:08:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\InterTrust
[2003.06.23 18:31:52 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Microsoft
[2010.11.08 13:18:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla
[2010.11.08 13:26:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Winamp
[2010.11.08 13:33:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Sun
[2010.11.08 13:43:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Thunderbird
[2010.11.08 13:51:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\ICQ
[2010.11.08 13:53:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Skype
[2010.11.08 14:36:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\TuneUp Software
[2010.11.08 15:52:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Apple Computer
[2010.11.08 21:47:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\WinRAR
[2010.11.08 21:54:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Adobe
[2010.11.08 21:55:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Macromedia
[2010.11.08 22:22:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\vlc
[2010.11.12 17:47:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OpenOffice.org
[2010.11.16 17:33:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\PC Suite
[2010.11.16 17:37:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Nokia
[2010.12.16 21:35:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\skypePM
[2011.01.26 07:58:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Canon
[2011.01.26 08:14:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\ZoomBrowser EX
[2011.02.05 02:59:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\dvdcss
[2011.03.05 20:12:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Nero
[2011.06.26 19:21:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\TomTom
[2012.07.19 22:29:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\PACE Anti-Piracy
[2012.07.20 19:34:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\DesktopIconForAmazon
[2012.07.20 19:35:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS
[2012.07.20 19:36:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Opera
[2012.07.21 15:00:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\ABBYY
[2012.10.03 19:49:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Malwarebytes
 
< %APPDATA%\*.exe /s >
[2012.07.20 19:34:56 | 000,753,664 | ---- | M] (Microsoft) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\DesktopIconForAmazon\IconForAmazon.exe
[2012.04.24 23:06:44 | 000,158,000 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\FlashGot.exe
[2012.07.20 19:35:02 | 000,106,496 | ---- | M] (OCS) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizer.exe
[2012.07.20 19:35:02 | 000,040,960 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizerHelper.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2010.11.08 14:06:32 | 022,286,026 | ---- | M] () .cab file -- C:\I386\sp2.cab:AGP440.sys
[2010.11.08 20:38:16 | 023,898,261 | ---- | M] () .cab file -- C:\I386\sp3.cab:AGP440.sys
[2010.11.08 14:06:32 | 022,286,026 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2010.11.08 20:38:16 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
 
< MD5 for: ATAPI.SYS  >
[2003.04.02 12:00:00 | 010,180,476 | ---- | M] () .cab file -- C:\I386\sp1.cab:atapi.sys
[2010.11.08 14:06:32 | 022,286,026 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
[2010.11.08 20:38:16 | 023,898,261 | ---- | M] () .cab file -- C:\I386\sp3.cab:atapi.sys
[2010.11.08 14:06:32 | 022,286,026 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2010.11.08 20:38:16 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2003.04.02 12:00:00 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
 
< MD5 for: EVENTLOG.DLL  >
[2008.04.14 03:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 03:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll
 
< MD5 for: NETLOGON.DLL  >
[2008.04.14 03:22:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 03:22:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll
[2009.02.06 19:46:10 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ED4BBAD725A21632FB205452749FC8F5 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 19:46:10 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ED4BBAD725A21632FB205452749FC8F5 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
 
< MD5 for: SCECLI.DLL  >
[2008.04.14 03:22:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 03:22:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll
 
< MD5 for: USER32.DLL  >
[2005.03.02 19:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
[2008.04.14 03:22:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008.04.14 03:22:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.04.14 03:23:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 03:23:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Programme\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.04.14 03:23:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 03:23:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2003.04.02 12:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2003.04.02 12:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2003.06.23 18:31:14 | 000,401,408 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
[2003.06.23 18:31:14 | 000,606,208 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2003.06.23 18:31:14 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
 
<          >
[1980.01.01 00:00:00 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2003.06.23 18:40:17 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2011.10.04 23:58:37 | 000,000,276 | ---- | C] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2012.03.30 13:26:26 | 000,000,884 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012.07.15 23:14:03 | 000,001,194 | ---- | C] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1582333133-1907411925-173008773-1005Core1cd62cec2a47ee0.job

< End of report >

--- --- ---

cosinus 13.10.2012 16:06

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Hinweis: Falls Du Deinen Benutzernamen unkenntlich gemacht hast, musst Du das Ausgesternte in Deinen richtigen Benutzernamen wieder verwandeln, sonst funktioniert das Script nicht!!

Code:

:OTL
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes\{106E777E-C0C8-49B4-8409-5694E52FF2E1}: "URL" = http://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes\{11DA52D7-5B49-4C13-8F9E-4D8C40B84698}: "URL" = http://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes\{24B87460-205C-42B3-9598-683BFAFF6727}: "URL" = http://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes\{768963F2-ACE9-4A69-959F-B35479C58E7A}: "URL" = http://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes\{85F8B379-DE8F-4B16-A4AF-A820F54A8FF9}: "URL" = http://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
IE - HKU\S-1-5-21-1582333133-1907411925-173008773-1005\..\SearchScopes\{CD0A6457-AE13-4247-898F-94939EF8465D}: "URL" = http://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=1df234ca-ec5d-4f56-85c2-40532d0c06e6&pid=fotofreeware&mode=bounce&k=0
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q="
[2011.12.27 14:12:58 | 000,000,000 | ---D | M] (Yontoo Layers) -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com
[2012.07.20 19:36:06 | 000,001,122 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin.xml
[2012.07.20 19:36:06 | 000,001,105 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin-1.xml
[2012.07.20 19:36:06 | 000,001,105 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin-2.xml
[2012.07.20 19:36:06 | 000,001,105 | ---- | M] () -- C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin-3.xml
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.09.15 06:12:14 | 000,000,080 | -H-- | M] () - F:\autorun.inf -- [ NTFS ]
:Files
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com
C:\Programme\Yontoo Layers Runtime
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

perry85 14.10.2012 14:56

Code:

All processes killed
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-1582333133-1907411925-173008773-1005\Software\Microsoft\Internet Explorer\SearchScopes\{106E777E-C0C8-49B4-8409-5694E52FF2E1}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{106E777E-C0C8-49B4-8409-5694E52FF2E1}\ not found.
Registry key HKEY_USERS\S-1-5-21-1582333133-1907411925-173008773-1005\Software\Microsoft\Internet Explorer\SearchScopes\{11DA52D7-5B49-4C13-8F9E-4D8C40B84698}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11DA52D7-5B49-4C13-8F9E-4D8C40B84698}\ not found.
Registry key HKEY_USERS\S-1-5-21-1582333133-1907411925-173008773-1005\Software\Microsoft\Internet Explorer\SearchScopes\{24B87460-205C-42B3-9598-683BFAFF6727}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B87460-205C-42B3-9598-683BFAFF6727}\ not found.
Registry key HKEY_USERS\S-1-5-21-1582333133-1907411925-173008773-1005\Software\Microsoft\Internet Explorer\SearchScopes\{768963F2-ACE9-4A69-959F-B35479C58E7A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{768963F2-ACE9-4A69-959F-B35479C58E7A}\ not found.
Registry key HKEY_USERS\S-1-5-21-1582333133-1907411925-173008773-1005\Software\Microsoft\Internet Explorer\SearchScopes\{85F8B379-DE8F-4B16-A4AF-A820F54A8FF9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85F8B379-DE8F-4B16-A4AF-A820F54A8FF9}\ not found.
Registry key HKEY_USERS\S-1-5-21-1582333133-1907411925-173008773-1005\Software\Microsoft\Internet Explorer\SearchScopes\{CD0A6457-AE13-4247-898F-94939EF8465D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CD0A6457-AE13-4247-898F-94939EF8465D}\ not found.
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q=" removed from keyword.URL
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com\skin folder moved successfully.
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com\locale\en-US folder moved successfully.
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com\locale folder moved successfully.
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com\defaults\preferences folder moved successfully.
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com\defaults folder moved successfully.
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com\content folder moved successfully.
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com folder moved successfully.
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin.xml moved successfully.
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin-1.xml moved successfully.
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin-2.xml moved successfully.
C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\searchplugins\icqplugin-3.xml moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
F:\autorun.inf moved successfully.
========== FILES ==========
File\Folder C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer not found.
File\Folder C:\Dokumente und Einstellungen\MR\Anwendungsdaten\Mozilla\Firefox\Profiles\9dzd0iu8.default\extensions\plugin@yontoo.com not found.
File\Folder C:\Programme\Yontoo Layers Runtime not found.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Auflösungscache wurde geleert.
C:\Dokumente und Einstellungen\MR\Eigene Dateien\Downloads\cmd.bat deleted successfully.
C:\Dokumente und Einstellungen\MR\Eigene Dateien\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
 
User: All Users
 
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49554 bytes
 
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 68772 bytes
 
User: MR
->Temp folder emptied: 759279236 bytes
->Temporary Internet Files folder emptied: 10953733 bytes
->Java cache emptied: 4485041 bytes
->FireFox cache emptied: 301370334 bytes
->Flash cache emptied: 191123 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 39097 bytes
%systemroot%\System32 .tmp files removed: 2951 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5617118 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 1.032,00 mb
 
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.69.0 log created on 10142012_154421

Files\Folders moved on Reboot...
C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Temp\WCESLog.log moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


cosinus 14.10.2012 19:25

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

perry85 14.10.2012 23:24

Code:

  00:06:34.0070 0996  TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
00:06:36.0183 0996  ============================================================
00:06:36.0183 0996  Current date / time: 2012/10/15 00:06:36.0183
00:06:36.0183 0996  SystemInfo:
00:06:36.0183 0996 
00:06:36.0183 0996  OS Version: 5.1.2600 ServicePack: 3.0
00:06:36.0183 0996  Product type: Workstation
00:06:36.0183 0996  ComputerName: ACER-5J0JDWIJ8Z
00:06:36.0183 0996  UserName: MR
00:06:36.0183 0996  Windows directory: C:\WINDOWS
00:06:36.0183 0996  System windows directory: C:\WINDOWS
00:06:36.0183 0996  Processor architecture: Intel x86
00:06:36.0183 0996  Number of processors: 1
00:06:36.0183 0996  Page size: 0x1000
00:06:36.0183 0996  Boot type: Normal boot
00:06:36.0183 0996  ============================================================
00:07:33.0916 0996  Drive \Device\Harddisk0\DR0 - Size: 0x6FC7C8000 (27.95 Gb), SectorSize: 0x200, Cylinders: 0xE40, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
00:07:36.0460 0996  Drive \Device\Harddisk1\DR8 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
00:07:36.0470 0996  ============================================================
00:07:36.0470 0996  \Device\Harddisk0\DR0:
00:07:39.0324 0996  MBR partitions:
00:07:39.0324 0996  \Device\Harddisk0\DR0\Partition1: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x2457405
00:07:39.0324 0996  \Device\Harddisk0\DR0\Partition2: MBR, Type 0xC, StartLBA 0x2457444, BlocksNum 0x1388B3B
00:07:39.0324 0996  \Device\Harddisk1\DR8:
00:07:39.0344 0996  MBR partitions:
00:07:39.0344 0996  \Device\Harddisk1\DR8\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2542D682
00:07:39.0344 0996  ============================================================
00:07:40.0866 0996  C: <-> \Device\Harddisk0\DR0\Partition1
00:07:41.0567 0996  D: <-> \Device\Harddisk0\DR0\Partition2
00:07:41.0627 0996  G: <-> \Device\Harddisk1\DR8\Partition1
00:07:41.0627 0996  ============================================================
00:07:41.0627 0996  Initialize success
00:07:41.0627 0996  ============================================================
00:12:26.0797 0436  ============================================================
00:12:26.0797 0436  Scan started
00:12:26.0797 0436  Mode: Manual; SigCheck; TDLFS;
00:12:26.0797 0436  ============================================================
00:12:29.0491 0436  ================ Scan system memory ========================
00:12:29.0521 0436  System memory - ok
00:12:29.0531 0436  ================ Scan services =============================
00:12:32.0826 0436  [ 8912B38E7906BDE9999E4BBDC4E65BDC ] ABBYY.Licensing.FineReader.Professional.11.0 C:\Programme\ABBYY FineReader 11\NetworkLicenseServer.exe
00:12:38.0104 0436  ABBYY.Licensing.FineReader.Professional.11.0 - ok
00:12:38.0675 0436  Abiosdsk - ok
00:12:38.0685 0436  abp480n5 - ok
00:12:40.0277 0436  [ AC407F1A62C3A300B4F2B5A9F1D55B2C ] ACPI            C:\WINDOWS\system32\DRIVERS\ACPI.sys
00:12:53.0125 0436  ACPI - ok
00:12:53.0195 0436  [ 9E1CA3160DAFB159CA14F83B1E317F75 ] ACPIEC          C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
00:12:53.0756 0436  ACPIEC - ok
00:12:56.0430 0436  [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
00:12:56.0610 0436  AdobeFlashPlayerUpdateSvc - ok
00:12:56.0640 0436  adpu160m - ok
00:12:56.0951 0436  [ 8BED39E3C35D6A489438B8141717A557 ] aec            C:\WINDOWS\system32\drivers\aec.sys
00:12:57.0241 0436  aec - ok
00:12:57.0822 0436  [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD            C:\WINDOWS\System32\drivers\afd.sys
00:12:57.0952 0436  AFD - ok
00:13:00.0206 0436  [ 3E60F847C0C57EEDB7C0639710512CCC ] AgereSoftModem  C:\WINDOWS\system32\DRIVERS\AGRSM.sys
00:13:00.0816 0436  AgereSoftModem - ok
00:13:00.0836 0436  Aha154x - ok
00:13:00.0856 0436  aic78u2 - ok
00:13:00.0876 0436  aic78xx - ok
00:13:03.0070 0436  [ EA8D01E733FDA92147DE62AA04D154A6 ] ALCXWDM        C:\WINDOWS\system32\drivers\ALCXWDM.SYS
00:13:03.0841 0436  ALCXWDM - ok
00:13:04.0492 0436  [ 738D80CC01D7BC7584BE917B7F544394 ] Alerter        C:\WINDOWS\system32\alrsvc.dll
00:13:04.0842 0436  Alerter - ok
00:13:05.0143 0436  [ 190CD73D4984F94D823F9444980513E5 ] ALG            C:\WINDOWS\System32\alg.exe
00:13:05.0443 0436  ALG - ok
00:13:05.0453 0436  AliIde - ok
00:13:05.0473 0436  amsint - ok
00:13:06.0134 0436  [ 42C42796BD1A01D37CD9ED05D9694D2A ] ApfiltrService  C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
00:13:06.0314 0436  ApfiltrService - ok
00:13:06.0615 0436  AppMgmt - ok
00:13:07.0166 0436  [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394        C:\WINDOWS\system32\DRIVERS\arp1394.sys
00:13:07.0436 0436  Arp1394 - ok
00:13:07.0446 0436  asc - ok
00:13:07.0466 0436  asc3350p - ok
00:13:07.0476 0436  asc3550 - ok
00:13:08.0117 0436  [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state    C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
00:13:08.0207 0436  aspnet_state - ok
00:13:08.0327 0436  [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac        C:\WINDOWS\system32\DRIVERS\asyncmac.sys
00:13:08.0527 0436  AsyncMac - ok
00:13:08.0988 0436  [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi          C:\WINDOWS\system32\DRIVERS\atapi.sys
00:13:09.0269 0436  atapi - ok
00:13:09.0309 0436  Atdisk - ok
00:13:09.0569 0436  [ 9916C1225104BA14794209CFA8012159 ] Atmarpc        C:\WINDOWS\system32\DRIVERS\atmarpc.sys
00:13:09.0819 0436  Atmarpc - ok
00:13:10.0170 0436  [ 58ED0D5452DF7BE732193E7999C6B9A4 ] AudioSrv        C:\WINDOWS\System32\audiosrv.dll
00:13:10.0370 0436  AudioSrv - ok
00:13:10.0400 0436  [ D9F724AA26C010A217C97606B160ED68 ] audstub        C:\WINDOWS\system32\DRIVERS\audstub.sys
00:13:10.0641 0436  audstub - ok
00:13:10.0681 0436  [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep            C:\WINDOWS\system32\drivers\Beep.sys
00:13:10.0951 0436  Beep - ok
00:13:12.0123 0436  [ D6F603772A789BB3228F310D650B8BD1 ] BITS            C:\WINDOWS\system32\qmgr.dll
00:13:12.0393 0436  BITS - ok
00:13:12.0443 0436  Bonjour Service - ok
00:13:12.0533 0436  [ B71549F23736ADF83A571061C47777FD ] Browser        C:\WINDOWS\System32\browser.dll
00:13:12.0593 0436  Browser - ok
00:13:12.0623 0436  [ B5557A53074076E43ED70D5C0653FBF6 ] BTWUSB          C:\WINDOWS\system32\Drivers\btwusb.sys
00:13:12.0653 0436  BTWUSB ( UnsignedFile.Multi.Generic ) - warning
00:13:12.0653 0436  BTWUSB - detected UnsignedFile.Multi.Generic (1)
00:13:12.0693 0436  [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k        C:\WINDOWS\system32\drivers\cbidf2k.sys
00:13:12.0924 0436  cbidf2k - ok
00:13:12.0984 0436  [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE        C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
00:13:13.0174 0436  CCDECODE - ok
00:13:13.0194 0436  cd20xrnt - ok
00:13:13.0254 0436  [ C1B486A7658353D33A10CC15211A873B ] Cdaudio        C:\WINDOWS\system32\drivers\Cdaudio.sys
00:13:13.0485 0436  Cdaudio - ok
00:13:13.0565 0436  [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs            C:\WINDOWS\system32\drivers\Cdfs.sys
00:13:13.0705 0436  Cdfs - ok
00:13:13.0755 0436  [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom          C:\WINDOWS\system32\DRIVERS\cdrom.sys
00:13:13.0945 0436  Cdrom - ok
00:13:13.0955 0436  Changer - ok
00:13:14.0065 0436  [ 28E3040D1F1CA2008CD6B29DFEBC9A5E ] CiSvc          C:\WINDOWS\system32\cisvc.exe
00:13:14.0236 0436  CiSvc - ok
00:13:14.0346 0436  [ 778A30ED3C134EB7E406AFC407E9997D ] ClipSrv        C:\WINDOWS\system32\clipsrv.exe
00:13:14.0526 0436  ClipSrv - ok
00:13:14.0576 0436  [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
00:13:14.0596 0436  clr_optimization_v2.0.50727_32 - ok
00:13:14.0626 0436  [ 0F6C187D38D98F8DF904589A5F94D411 ] CmBatt          C:\WINDOWS\system32\DRIVERS\CmBatt.sys
00:13:14.0797 0436  CmBatt - ok
00:13:14.0827 0436  CmdIde - ok
00:13:14.0857 0436  [ 6E4C9F21F0FAE8940661144F41B13203 ] Compbatt        C:\WINDOWS\system32\DRIVERS\compbatt.sys
00:13:15.0027 0436  Compbatt - ok
00:13:15.0077 0436  COMSysApp - ok
00:13:15.0097 0436  Cpqarray - ok
00:13:15.0207 0436  [ 611F824E5C703A5A899F84C5F1699E4D ] CryptSvc        C:\WINDOWS\System32\cryptsvc.dll
00:13:15.0377 0436  CryptSvc - ok
00:13:15.0387 0436  dac2w2k - ok
00:13:15.0407 0436  dac960nt - ok
00:13:15.0488 0436  [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] DcomLaunch      C:\WINDOWS\system32\rpcss.dll
00:13:15.0568 0436  DcomLaunch - ok
00:13:15.0648 0436  [ C29A1C9B75BA38FA37F8C44405DEC360 ] Dhcp            C:\WINDOWS\System32\dhcpcsvc.dll
00:13:15.0878 0436  Dhcp - ok
00:13:15.0938 0436  [ 044452051F3E02E7963599FC8F4F3E25 ] Disk            C:\WINDOWS\system32\DRIVERS\disk.sys
00:13:16.0128 0436  Disk - ok
00:13:16.0249 0436  [ 96A48BDA68BF734AAE79F910AB884A34 ] DKbFltr        C:\WINDOWS\system32\Drivers\DKbFltr.sys
00:13:16.0269 0436  DKbFltr ( UnsignedFile.Multi.Generic ) - warning
00:13:16.0269 0436  DKbFltr - detected UnsignedFile.Multi.Generic (1)
00:13:16.0309 0436  dmadmin - ok
00:13:16.0389 0436  [ 0DCFC8395A99FECBB1EF771CEC7FE4EA ] dmboot          C:\WINDOWS\system32\drivers\dmboot.sys
00:13:16.0649 0436  dmboot - ok
00:13:16.0749 0436  [ 53720AB12B48719D00E327DA470A619A ] dmio            C:\WINDOWS\system32\drivers\dmio.sys
00:13:16.0930 0436  dmio - ok
00:13:17.0040 0436  [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload          C:\WINDOWS\system32\drivers\dmload.sys
00:13:17.0270 0436  dmload - ok
00:13:17.0360 0436  [ 25C83FFBBA13B554EB6D59A9B2E2EE78 ] dmserver        C:\WINDOWS\System32\dmserver.dll
00:13:17.0520 0436  dmserver - ok
00:13:17.0570 0436  [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic          C:\WINDOWS\system32\drivers\DMusic.sys
00:13:17.0751 0436  DMusic - ok
00:13:17.0841 0436  [ 407F3227AC618FD1CA54B335B083DE07 ] Dnscache        C:\WINDOWS\System32\dnsrslvr.dll
00:13:17.0911 0436  Dnscache - ok
00:13:17.0981 0436  [ 676E36C4FF5BCEA1900F44182B9723E6 ] Dot3svc        C:\WINDOWS\System32\dot3svc.dll
00:13:18.0181 0436  Dot3svc - ok
00:13:18.0191 0436  dpti2o - ok
00:13:18.0221 0436  [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud        C:\WINDOWS\system32\drivers\drmkaud.sys
00:13:18.0412 0436  drmkaud - ok
00:13:18.0502 0436  [ 4E4F2FDDAB0A0736D7671134DCCE91FB ] EapHost        C:\WINDOWS\System32\eapsvc.dll
00:13:18.0672 0436  EapHost - ok
00:13:18.0752 0436  [ 877C18558D70587AA7823A1A308AC96B ] ERSvc          C:\WINDOWS\System32\ersvc.dll
00:13:18.0932 0436  ERSvc - ok
00:13:19.0063 0436  [ A3EDBE9053889FB24AB22492472B39DC ] Eventlog        C:\WINDOWS\system32\services.exe
00:13:19.0103 0436  Eventlog - ok
00:13:19.0173 0436  [ AF4F6B5739D18CA7972AB53E091CBC74 ] EventSystem    C:\WINDOWS\System32\es.dll
00:13:19.0233 0436  EventSystem - ok
00:13:19.0273 0436  [ 38D332A6D56AF32635675F132548343E ] Fastfat        C:\WINDOWS\system32\drivers\Fastfat.sys
00:13:19.0453 0436  Fastfat - ok
00:13:19.0553 0436  [ 2DB7D303C36DDD055215052F118E8E75 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
00:13:19.0603 0436  FastUserSwitchingCompatibility - ok
00:13:19.0704 0436  [ 08B8B302AF0D1B3B8543429BBAC8F21F ] Fax            C:\WINDOWS\system32\fxssvc.exe
00:13:19.0894 0436  Fax - ok
00:13:19.0914 0436  [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc            C:\WINDOWS\system32\drivers\Fdc.sys
00:13:20.0104 0436  Fdc - ok
00:13:20.0124 0436  [ B0678A548587C5F1967B0D70BACAD6C1 ] Fips            C:\WINDOWS\system32\drivers\Fips.sys
00:13:20.0294 0436  Fips - ok
00:13:20.0304 0436  [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk        C:\WINDOWS\system32\drivers\Flpydisk.sys
00:13:20.0475 0436  Flpydisk - ok
00:13:20.0505 0436  [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr          C:\WINDOWS\system32\drivers\fltmgr.sys
00:13:20.0685 0436  FltMgr - ok
00:13:20.0855 0436  [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
00:13:20.0875 0436  FontCache3.0.0.0 - ok
00:13:20.0895 0436  [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec          C:\WINDOWS\system32\drivers\Fs_Rec.sys
00:13:21.0106 0436  Fs_Rec - ok
00:13:21.0146 0436  [ 8F1955CE42E1484714B542F341647778 ] Ftdisk          C:\WINDOWS\system32\DRIVERS\ftdisk.sys
00:13:21.0376 0436  Ftdisk - ok
00:13:21.0436 0436  [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM    C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
00:13:21.0456 0436  GEARAspiWDM - ok
00:13:21.0476 0436  [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc            C:\WINDOWS\system32\DRIVERS\msgpc.sys
00:13:21.0646 0436  Gpc - ok
00:13:21.0787 0436  [ F0A0041644A2E026044C6EEEC42B7241 ] gv3            C:\WINDOWS\system32\DRIVERS\gv3.sys
00:13:21.0817 0436  gv3 - ok
00:13:21.0907 0436  [ CB66BF85BF599BEFD6C6A57C2E20357F ] helpsvc        C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
00:13:22.0117 0436  helpsvc - ok
00:13:22.0167 0436  [ B35DA85E60C0103F2E4104532DA2F12B ] HidServ        C:\WINDOWS\System32\hidserv.dll
00:13:22.0347 0436  HidServ - ok
00:13:22.0458 0436  [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb          C:\WINDOWS\system32\DRIVERS\hidusb.sys
00:13:22.0648 0436  HidUsb - ok
00:13:22.0938 0436  [ ED29F14101523A6E0E808107405D452C ] hkmsvc          C:\WINDOWS\System32\kmsvc.dll
00:13:23.0169 0436  hkmsvc - ok
00:13:23.0189 0436  hpn - ok
00:13:23.0259 0436  [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP            C:\WINDOWS\system32\Drivers\HTTP.sys
00:13:23.0319 0436  HTTP - ok
00:13:23.0389 0436  [ 9E4ADB854CEBCFB81A4B36718FEECD16 ] HTTPFilter      C:\WINDOWS\System32\w3ssl.dll
00:13:23.0559 0436  HTTPFilter - ok
00:13:23.0569 0436  i2omgmt - ok
00:13:23.0589 0436  i2omp - ok
00:13:23.0619 0436  [ E283B97CFBEB86C1D86BAED5F7846A92 ] i8042prt        C:\WINDOWS\system32\DRIVERS\i8042prt.sys
00:13:23.0789 0436  i8042prt - ok
00:13:23.0829 0436  [ 759A944AA02F686EC069E6FF5B5636D8 ] ialm            C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
00:13:24.0040 0436  ialm - ok
00:13:24.0130 0436  [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc          C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
00:13:24.0190 0436  idsvc - ok
00:13:24.0220 0436  [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi          C:\WINDOWS\system32\DRIVERS\imapi.sys
00:13:24.0400 0436  Imapi - ok
00:13:24.0561 0436  [ D4B413AA210C21E46AEDD2BA5B68D38E ] ImapiService    C:\WINDOWS\System32\imapi.exe
00:13:24.0731 0436  ImapiService - ok
00:13:24.0831 0436  ini910u - ok
00:13:24.0861 0436  [ 69C4E3C9E67A1F103B94E14FDD5F3213 ] IntelIde        C:\WINDOWS\system32\DRIVERS\intelide.sys
00:13:25.0051 0436  IntelIde - ok
00:13:25.0181 0436  [ 4C7D2750158ED6E7AD642D97BFFAE351 ] intelppm        C:\WINDOWS\system32\DRIVERS\intelppm.sys
00:13:25.0342 0436  intelppm - ok
00:13:25.0452 0436  [ 3BB22519A194418D5FEC05D800A19AD0 ] ip6fw          C:\WINDOWS\system32\drivers\ip6fw.sys
00:13:25.0612 0436  ip6fw - ok
00:13:25.0722 0436  [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver  C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
00:13:25.0983 0436  IpFilterDriver - ok
00:13:26.0053 0436  [ B87AB476DCF76E72010632B5550955F5 ] IpInIp          C:\WINDOWS\system32\DRIVERS\ipinip.sys
00:13:26.0223 0436  IpInIp - ok
00:13:26.0293 0436  [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat          C:\WINDOWS\system32\DRIVERS\ipnat.sys
00:13:26.0463 0436  IpNat - ok
00:13:26.0483 0436  [ 23C74D75E36E7158768DD63D92789A91 ] IPSec          C:\WINDOWS\system32\DRIVERS\ipsec.sys
00:13:26.0664 0436  IPSec - ok
00:13:26.0714 0436  [ ACA5E7B54409F9CB5EED97ED0C81120E ] irda            C:\WINDOWS\system32\DRIVERS\irda.sys
00:13:26.0894 0436  irda - ok
00:13:26.0934 0436  [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM          C:\WINDOWS\system32\DRIVERS\irenum.sys
00:13:27.0094 0436  IRENUM - ok
00:13:27.0174 0436  [ 2EFE1DB1EC58A26B0C14BFDA122E246F ] Irmon          C:\WINDOWS\System32\irmon.dll
00:13:27.0345 0436  Irmon - ok
00:13:27.0435 0436  [ 6DFB88F64135C525433E87648BDA30DE ] isapnp          C:\WINDOWS\system32\DRIVERS\isapnp.sys
00:13:27.0595 0436  isapnp - ok
00:13:27.0765 0436  [ 9AE07549A0D691A103FAF8946554BDB7 ] JavaQuickStarterService C:\Programme\Java\jre6\bin\jqs.exe
00:13:27.0795 0436  JavaQuickStarterService - ok
00:13:27.0845 0436  [ 1704D8C4C8807B889E43C649B478A452 ] Kbdclass        C:\WINDOWS\system32\DRIVERS\kbdclass.sys
00:13:28.0026 0436  Kbdclass - ok
00:13:28.0176 0436  [ B6D6C117D771C98130497265F26D1882 ] kbdhid          C:\WINDOWS\system32\DRIVERS\kbdhid.sys
00:13:28.0326 0436  kbdhid - ok
00:13:28.0436 0436  [ 692BCF44383D056AED41B045A323D378 ] kmixer          C:\WINDOWS\system32\drivers\kmixer.sys
00:13:28.0606 0436  kmixer - ok
00:13:28.0636 0436  [ B467646C54CC746128904E1654C750C1 ] KSecDD          C:\WINDOWS\system32\drivers\KSecDD.sys
00:13:28.0686 0436  KSecDD - ok
00:13:28.0737 0436  [ 2BBDCB79900990F0716DFCB714E72DE7 ] lanmanserver    C:\WINDOWS\System32\srvsvc.dll
00:13:28.0807 0436  lanmanserver - ok
00:13:28.0907 0436  [ 1869B14B06B44B44AF70548E1EA3303F ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
00:13:28.0967 0436  lanmanworkstation - ok
00:13:28.0977 0436  lbrtfdc - ok
00:13:29.0037 0436  [ 636714B7D43C8D0C80449123FD266920 ] LmHosts        C:\WINDOWS\System32\lmhsvc.dll
00:13:29.0217 0436  LmHosts - ok
00:13:29.0337 0436  [ 65E794E86468B61F2BC79ABC48BC4433 ] MBAMProtector  C:\WINDOWS\system32\drivers\mbam.sys
00:13:30.0549 0436  MBAMProtector - ok
00:13:30.0629 0436  [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler  C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
00:13:30.0669 0436  MBAMScheduler - ok
00:13:30.0729 0436  [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService    C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
00:13:30.0779 0436  MBAMService - ok
00:13:30.0820 0436  [ B7550A7107281D170CE85524B1488C98 ] Messenger      C:\WINDOWS\System32\msgsvc.dll
00:13:30.0990 0436  Messenger - ok
00:13:31.0020 0436  [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd          C:\WINDOWS\system32\drivers\mnmdd.sys
00:13:31.0260 0436  mnmdd - ok
00:13:31.0340 0436  [ C2F1D365FD96791B037EE504868065D3 ] mnmsrvc        C:\WINDOWS\System32\mnmsrvc.exe
00:13:31.0491 0436  mnmsrvc - ok
00:13:31.0511 0436  [ 6FB74EBD4EC57A6F1781DE3852CC3362 ] Modem          C:\WINDOWS\system32\drivers\Modem.sys
00:13:31.0671 0436  Modem - ok
00:13:31.0691 0436  [ B24CE8005DEAB254C0251E15CB71D802 ] Mouclass        C:\WINDOWS\system32\DRIVERS\mouclass.sys
00:13:31.0851 0436  Mouclass - ok
00:13:31.0891 0436  [ 66A6F73C74E1791464160A7065CE711A ] mouhid          C:\WINDOWS\system32\DRIVERS\mouhid.sys
00:13:32.0111 0436  mouhid - ok
00:13:32.0232 0436  [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr        C:\WINDOWS\system32\drivers\MountMgr.sys
00:13:32.0382 0436  MountMgr - ok
00:13:32.0482 0436  [ 4D7F2682D29B92A6251B17957AA0B985 ] MozillaMaintenance C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe
00:13:32.0502 0436  MozillaMaintenance - ok
00:13:32.0512 0436  mraid35x - ok
00:13:32.0572 0436  [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV          C:\WINDOWS\system32\DRIVERS\mrxdav.sys
00:13:32.0752 0436  MRxDAV - ok
00:13:32.0842 0436  [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb          C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
00:13:32.0933 0436  MRxSmb - ok
00:13:32.0973 0436  [ 35A031AF38C55F92D28AA03EE9F12CC9 ] MSDTC          C:\WINDOWS\System32\msdtc.exe
00:13:33.0133 0436  MSDTC - ok
00:13:33.0213 0436  [ C941EA2454BA8350021D774DAF0F1027 ] Msfs            C:\WINDOWS\system32\drivers\Msfs.sys
00:13:33.0403 0436  Msfs - ok
00:13:33.0584 0436  MSIServer - ok
00:13:33.0614 0436  [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV        C:\WINDOWS\system32\drivers\MSKSSRV.sys
00:13:33.0774 0436  MSKSSRV - ok
00:13:33.0794 0436  [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK        C:\WINDOWS\system32\drivers\MSPCLOCK.sys
00:13:33.0934 0436  MSPCLOCK - ok
00:13:34.0034 0436  [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM          C:\WINDOWS\system32\drivers\MSPQM.sys
00:13:34.0214 0436  MSPQM - ok
00:13:34.0244 0436  [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios        C:\WINDOWS\system32\DRIVERS\mssmbios.sys
00:13:34.0415 0436  mssmbios - ok
00:13:34.0555 0436  [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE          C:\WINDOWS\system32\drivers\MSTEE.sys
00:13:34.0725 0436  MSTEE - ok
00:13:34.0815 0436  [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup            C:\WINDOWS\system32\drivers\Mup.sys
00:13:34.0865 0436  Mup - ok
00:13:34.0895 0436  [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC        C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
00:13:35.0086 0436  NABTSFEC - ok
00:13:35.0196 0436  [ 46BB15AE2AC7D025D6D2567B876817BD ] napagent        C:\WINDOWS\System32\qagentrt.dll
00:13:35.0376 0436  napagent - ok
00:13:35.0526 0436  [ 9D1CCE440552500DED3A62F9D779CDB4 ] NAUpdate        C:\Programme\Nero\Update\NASvc.exe
00:13:35.0566 0436  NAUpdate - ok
00:13:35.0606 0436  [ 1DF7F42665C94B825322FAE71721130D ] NDIS            C:\WINDOWS\system32\drivers\NDIS.sys
00:13:35.0797 0436  NDIS - ok
00:13:35.0837 0436  [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP          C:\WINDOWS\system32\DRIVERS\NdisIP.sys
00:13:35.0997 0436  NdisIP - ok
00:13:36.0107 0436  [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi        C:\WINDOWS\system32\DRIVERS\ndistapi.sys
00:13:36.0147 0436  NdisTapi - ok
00:13:36.0207 0436  [ F927A4434C5028758A842943EF1A3849 ] Ndisuio        C:\WINDOWS\system32\DRIVERS\ndisuio.sys
00:13:36.0368 0436  Ndisuio - ok
00:13:36.0398 0436  [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan        C:\WINDOWS\system32\DRIVERS\ndiswan.sys
00:13:36.0558 0436  NdisWan - ok
00:13:36.0588 0436  [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy        C:\WINDOWS\system32\drivers\NDProxy.sys
00:13:36.0608 0436  NDProxy - ok
00:13:36.0638 0436  [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS        C:\WINDOWS\system32\DRIVERS\netbios.sys
00:13:36.0828 0436  NetBIOS - ok
00:13:36.0918 0436  [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT          C:\WINDOWS\system32\DRIVERS\netbt.sys
00:13:37.0089 0436  NetBT - ok
00:13:37.0239 0436  [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDE          C:\WINDOWS\system32\netdde.exe
00:13:37.0399 0436  NetDDE - ok
00:13:37.0409 0436  [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDEdsdm      C:\WINDOWS\system32\netdde.exe
00:13:37.0559 0436  NetDDEdsdm - ok
00:13:37.0609 0436  [ AFB8261B56CBA0D86AEB6DF682AF9785 ] Netlogon        C:\WINDOWS\System32\lsass.exe
00:13:37.0770 0436  Netlogon - ok
00:13:37.0950 0436  [ E6D88F1F6745BF00B57E7855A2AB696C ] Netman          C:\WINDOWS\System32\netman.dll
00:13:38.0120 0436  Netman - ok
00:13:38.0310 0436  [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
00:13:38.0330 0436  NetTcpPortSharing - ok
00:13:38.0380 0436  [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394        C:\WINDOWS\system32\DRIVERS\nic1394.sys
00:13:38.0571 0436  NIC1394 - ok
00:13:38.0661 0436  [ F1B67B6B0751AE0E6E964B02821206A3 ] Nla            C:\WINDOWS\System32\mswsock.dll
00:13:38.0711 0436  Nla - ok
00:13:38.0791 0436  [ 1926B4EEF80F4A0C8CC8FCBB6B4A7461 ] Nokia USB Generic C:\WINDOWS\system32\drivers\nmwcdc.sys
00:13:38.0921 0436  Nokia USB Generic - ok
00:13:38.0961 0436  [ DF4211B6CA609FF11F43261E04AC92F1 ] Nokia USB Modem C:\WINDOWS\system32\drivers\nmwcdcm.sys
00:13:39.0031 0436  Nokia USB Modem - ok
00:13:39.0071 0436  [ DDFE78EEB4AFCF91EDC52B8F7C7DAD15 ] Nokia USB Phone Parent C:\WINDOWS\system32\drivers\nmwcd.sys
00:13:39.0152 0436  Nokia USB Phone Parent - ok
00:13:39.0182 0436  [ DF4211B6CA609FF11F43261E04AC92F1 ] Nokia USB Port  C:\WINDOWS\system32\drivers\nmwcdcj.sys
00:13:39.0222 0436  Nokia USB Port - ok
00:13:39.0252 0436  [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs            C:\WINDOWS\system32\drivers\Npfs.sys
00:13:39.0392 0436  Npfs - ok
00:13:39.0552 0436  [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs            C:\WINDOWS\system32\drivers\Ntfs.sys
00:13:39.0752 0436  Ntfs - ok
00:13:39.0782 0436  [ 15A72D5B8F0B6A718207F14BD5EBB8FF ] NTIDrvr        C:\WINDOWS\system32\DRIVERS\NTIDrvr.sys
00:13:39.0802 0436  NTIDrvr ( UnsignedFile.Multi.Generic ) - warning
00:13:39.0802 0436  NTIDrvr - detected UnsignedFile.Multi.Generic (1)
00:13:39.0822 0436  [ AFB8261B56CBA0D86AEB6DF682AF9785 ] NtLmSsp        C:\WINDOWS\System32\lsass.exe
00:13:39.0973 0436  NtLmSsp - ok
00:13:40.0203 0436  [ 56AF4064996FA5BAC9C449B1514B4770 ] NtmsSvc        C:\WINDOWS\system32\ntmssvc.dll
00:13:40.0393 0436  NtmsSvc - ok
00:13:40.0423 0436  [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null            C:\WINDOWS\system32\drivers\Null.sys
00:13:40.0654 0436  Null - ok
00:13:40.0684 0436  [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt        C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
00:13:40.0914 0436  NwlnkFlt - ok
00:13:40.0944 0436  [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd        C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
00:13:41.0194 0436  NwlnkFwd - ok
00:13:41.0305 0436  [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394        C:\WINDOWS\system32\DRIVERS\ohci1394.sys
00:13:41.0465 0436  ohci1394 - ok
00:13:41.0655 0436  [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose            C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE
00:13:41.0675 0436  ose - ok
00:13:41.0705 0436  [ F84785660305B9B903FB3BCA8BA29837 ] Parport        C:\WINDOWS\system32\DRIVERS\parport.sys
00:13:41.0895 0436  Parport - ok
00:13:41.0946 0436  [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr        C:\WINDOWS\system32\drivers\PartMgr.sys
00:13:42.0106 0436  PartMgr - ok
00:13:42.0156 0436  [ C2BF987829099A3EAA2CA6A0A90ECB4F ] ParVdm          C:\WINDOWS\system32\drivers\ParVdm.sys
00:13:42.0416 0436  ParVdm - ok
00:13:42.0436 0436  [ 387E8DEDC343AA2D1EFBC30580273ACD ] PCI            C:\WINDOWS\system32\DRIVERS\pci.sys
00:13:42.0586 0436  PCI - ok
00:13:42.0596 0436  PCIDump - ok
00:13:42.0617 0436  [ 59BA86D9A61CBCF4DF8E598C331F5B82 ] PCIIde          C:\WINDOWS\system32\DRIVERS\pciide.sys
00:13:42.0827 0436  PCIIde - ok
00:13:42.0877 0436  [ A2A966B77D61847D61A3051DF87C8C97 ] Pcmcia          C:\WINDOWS\system32\DRIVERS\pcmcia.sys
00:13:43.0037 0436  Pcmcia - ok
00:13:43.0057 0436  PDCOMP - ok
00:13:43.0067 0436  PDFRAME - ok
00:13:43.0077 0436  PDRELI - ok
00:13:43.0097 0436  PDRFRAME - ok
00:13:43.0117 0436  perc2 - ok
00:13:43.0127 0436  perc2hib - ok
00:13:43.0207 0436  [ A3EDBE9053889FB24AB22492472B39DC ] PlugPlay        C:\WINDOWS\system32\services.exe
00:13:43.0227 0436  PlugPlay - ok
00:13:43.0247 0436  [ AFB8261B56CBA0D86AEB6DF682AF9785 ] PolicyAgent    C:\WINDOWS\System32\lsass.exe
00:13:43.0398 0436  PolicyAgent - ok
00:13:43.0418 0436  [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport    C:\WINDOWS\system32\DRIVERS\raspptp.sys
00:13:43.0588 0436  PptpMiniport - ok
00:13:43.0628 0436  [ 2CB55427C58679F49AD600FCCBA76360 ] Processor      C:\WINDOWS\system32\DRIVERS\processr.sys
00:13:43.0788 0436  Processor - ok
00:13:43.0808 0436  [ AFB8261B56CBA0D86AEB6DF682AF9785 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
00:13:43.0958 0436  ProtectedStorage - ok
00:13:43.0978 0436  [ 09298EC810B07E5D582CB3A3F9255424 ] PSched          C:\WINDOWS\system32\DRIVERS\psched.sys
00:13:44.0149 0436  PSched - ok
00:13:44.0179 0436  [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink        C:\WINDOWS\system32\DRIVERS\ptilink.sys
00:13:44.0419 0436  Ptilink - ok
00:13:44.0469 0436  [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20        C:\WINDOWS\system32\Drivers\PxHelp20.sys
00:13:44.0489 0436  PxHelp20 - ok
00:13:44.0509 0436  ql1080 - ok
00:13:44.0519 0436  Ql10wnt - ok
00:13:44.0549 0436  ql12160 - ok
00:13:44.0559 0436  ql1240 - ok
00:13:44.0569 0436  ql1280 - ok
00:13:44.0599 0436  [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd          C:\WINDOWS\system32\DRIVERS\rasacd.sys
00:13:44.0810 0436  RasAcd - ok
00:13:44.0870 0436  [ F5BA6CACCDB66C8F048E867563203246 ] RasAuto        C:\WINDOWS\System32\rasauto.dll
00:13:45.0030 0436  RasAuto - ok
00:13:45.0060 0436  [ 0207D26DDF796A193CCD9F83047BB5FC ] Rasirda        C:\WINDOWS\system32\DRIVERS\rasirda.sys
00:13:45.0150 0436  Rasirda - ok
00:13:45.0170 0436  [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp        C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
00:13:45.0320 0436  Rasl2tp - ok
00:13:45.0370 0436  [ F9A7B66EA345726EDB5862A46B1ECCD5 ] RasMan          C:\WINDOWS\System32\rasmans.dll
00:13:45.0551 0436  RasMan - ok
00:13:45.0581 0436  [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe        C:\WINDOWS\system32\DRIVERS\raspppoe.sys
00:13:45.0741 0436  RasPppoe - ok
00:13:45.0771 0436  [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti          C:\WINDOWS\system32\DRIVERS\raspti.sys
00:13:46.0011 0436  Raspti - ok
00:13:46.0051 0436  [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss          C:\WINDOWS\system32\DRIVERS\rdbss.sys
00:13:46.0222 0436  Rdbss - ok
00:13:46.0242 0436  [ 4912D5B403614CE99C28420F75353332 ] RDPCDD          C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
00:13:46.0442 0436  RDPCDD - ok
00:13:46.0512 0436  [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD          C:\WINDOWS\system32\drivers\RDPWD.sys
00:13:46.0552 0436  RDPWD - ok
00:13:46.0612 0436  [ 263AF18AF0F3DB99F574C95F284CCEC9 ] RDSessMgr      C:\WINDOWS\system32\sessmgr.exe
00:13:46.0772 0436  RDSessMgr - ok
00:13:46.0803 0436  [ ED761D453856F795A7FE056E42C36365 ] redbook        C:\WINDOWS\system32\DRIVERS\redbook.sys
00:13:46.0973 0436  redbook - ok
00:13:47.0103 0436  [ 0E97EC96D6942CEEC2D188CC2EB69A01 ] RemoteAccess    C:\WINDOWS\System32\mprdim.dll
00:13:47.0283 0436  RemoteAccess - ok
00:13:47.0333 0436  [ 2A02E21867497DF20B8FC95631395169 ] RpcLocator      C:\WINDOWS\System32\locator.exe
00:13:47.0514 0436  RpcLocator - ok
00:13:47.0584 0436  [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] RpcSs          C:\WINDOWS\system32\rpcss.dll
00:13:47.0654 0436  RpcSs - ok
00:13:47.0734 0436  [ 4BDD71B4B521521499DFD14735C4F398 ] RSVP            C:\WINDOWS\System32\rsvp.exe
00:13:48.0004 0436  RSVP - ok
00:13:48.0094 0436  [ 2EF9C0DC26B30B2318B1FC3FAA1F0AE7 ] rtl8139        C:\WINDOWS\system32\DRIVERS\R8139n51.SYS
00:13:48.0134 0436  rtl8139 - ok
00:13:48.0154 0436  [ AFB8261B56CBA0D86AEB6DF682AF9785 ] SamSs          C:\WINDOWS\system32\lsass.exe
00:13:48.0335 0436  SamSs - ok
00:13:48.0385 0436  [ DCEC079FAD95D36C8DD5CB6D779DFE32 ] SCardSvr        C:\WINDOWS\System32\SCardSvr.exe
00:13:48.0585 0436  SCardSvr - ok
00:13:48.0645 0436  [ A050194A44D7FA8D7186ED2F4E8367AE ] Schedule        C:\WINDOWS\system32\schedsvc.dll
00:13:48.0805 0436  Schedule - ok
00:13:48.0966 0436  [ 0F4A80438E7286A0E623582F5F2395BD ] SearchAnonymizer C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizerHelper.exe
00:13:48.0986 0436  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - warning
00:13:48.0986 0436  SearchAnonymizer - detected UnsignedFile.Multi.Generic (1)
00:13:49.0036 0436  [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv          C:\WINDOWS\system32\DRIVERS\secdrv.sys
00:13:49.0196 0436  Secdrv - ok
00:13:49.0256 0436  [ BEE4CFD1D48C23B44CF4B974B0B79B2B ] seclogon        C:\WINDOWS\System32\seclogon.dll
00:13:49.0426 0436  seclogon - ok
00:13:49.0486 0436  [ 2AAC9B6ED9EDDFFB721D6452E34D67E3 ] SENS            C:\WINDOWS\system32\sens.dll
00:13:49.0647 0436  SENS - ok
00:13:49.0677 0436  [ CF24EB4F0412C82BCD1F4F35A025E31D ] Serial          C:\WINDOWS\system32\drivers\Serial.sys
00:13:49.0857 0436  Serial - ok
00:13:49.0987 0436  [ AAC24421FC74D612A7169C4D4A61B48C ] ServiceLayer    C:\Programme\PC Connectivity Solution\ServiceLayer.exe
00:13:50.0017 0436  ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
00:13:50.0017 0436  ServiceLayer - detected UnsignedFile.Multi.Generic (1)
00:13:50.0057 0436  [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy        C:\WINDOWS\system32\drivers\Sfloppy.sys
00:13:50.0237 0436  Sfloppy - ok
00:13:50.0288 0436  [ CAD058D5F8B889A87CA3EB3CF624DCEF ] SharedAccess    C:\WINDOWS\System32\ipnathlp.dll
00:13:50.0498 0436  SharedAccess - ok
00:13:50.0568 0436  [ 2DB7D303C36DDD055215052F118E8E75 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
00:13:50.0598 0436  ShellHWDetection - ok
00:13:50.0618 0436  Simbad - ok
00:13:50.0778 0436  [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate    C:\Programme\Skype\Updater\Updater.exe
00:13:50.0798 0436  SkypeUpdate - ok
00:13:50.0848 0436  [ 707647A1AA0EDB6CBEF61B0C75C28ED3 ] SMCIRDA        C:\WINDOWS\system32\DRIVERS\smcirda.sys
00:13:50.0898 0436  SMCIRDA - ok
00:13:50.0928 0436  Sparrow - ok
00:13:50.0979 0436  [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter        C:\WINDOWS\system32\drivers\splitter.sys
00:13:51.0159 0436  splitter - ok
00:13:51.0209 0436  [ 60784F891563FB1B767F70117FC2428F ] Spooler        C:\WINDOWS\system32\spoolsv.exe
00:13:51.0269 0436  Spooler - ok
00:13:51.0299 0436  [ 50FA898F8C032796D3B1B9951BB5A90F ] sr              C:\WINDOWS\system32\DRIVERS\sr.sys
00:13:51.0439 0436  sr - ok
00:13:51.0499 0436  [ FE77A85495065F3AD59C5C65B6C54182 ] srservice      C:\WINDOWS\System32\srsvc.dll
00:13:51.0650 0436  srservice - ok
00:13:51.0700 0436  [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv            C:\WINDOWS\system32\DRIVERS\srv.sys
00:13:51.0790 0436  Srv - ok
00:13:51.0880 0436  [ 4DF5B05DFAEC29E13E1ED6F6EE12C500 ] SSDPSRV        C:\WINDOWS\System32\ssdpsrv.dll
00:13:52.0060 0436  SSDPSRV - ok
00:13:52.0150 0436  [ BC2C5985611C5356B24AEB370953DED9 ] stisvc          C:\WINDOWS\system32\wiaservc.dll
00:13:52.0411 0436  stisvc - ok
00:13:52.0431 0436  [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum          C:\WINDOWS\system32\DRIVERS\swenum.sys
00:13:52.0601 0436  swenum - ok
00:13:52.0631 0436  [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi          C:\WINDOWS\system32\drivers\swmidi.sys
00:13:52.0801 0436  swmidi - ok
00:13:52.0851 0436  SwPrv - ok
00:13:52.0871 0436  symc810 - ok
00:13:52.0891 0436  symc8xx - ok
00:13:52.0911 0436  sym_hi - ok
00:13:52.0921 0436  sym_u3 - ok
00:13:52.0951 0436  [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio        C:\WINDOWS\system32\drivers\sysaudio.sys
00:13:53.0122 0436  sysaudio - ok
00:13:53.0182 0436  [ 2903FFFA2523926D6219428040DCE6B9 ] SysmonLog      C:\WINDOWS\system32\smlogsvc.exe
00:13:53.0342 0436  SysmonLog - ok
00:13:53.0452 0436  [ 05903CAC4B98908D55EA5774775B382E ] TapiSrv        C:\WINDOWS\System32\tapisrv.dll
00:13:53.0612 0436  TapiSrv - ok
00:13:53.0672 0436  [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip          C:\WINDOWS\system32\DRIVERS\tcpip.sys
00:13:53.0732 0436  Tcpip - ok
00:13:53.0783 0436  [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE          C:\WINDOWS\system32\drivers\TDPIPE.sys
00:13:53.0933 0436  TDPIPE - ok
00:13:53.0953 0436  [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP          C:\WINDOWS\system32\drivers\TDTCP.sys
00:13:54.0113 0436  TDTCP - ok
00:13:54.0143 0436  [ 88155247177638048422893737429D9E ] TermDD          C:\WINDOWS\system32\DRIVERS\termdd.sys
00:13:54.0293 0436  TermDD - ok
00:13:54.0393 0436  [ B7DE02C863D8F5A005A7BF375375A6A4 ] TermService    C:\WINDOWS\System32\termsrv.dll
00:13:54.0564 0436  TermService - ok
00:13:54.0654 0436  [ 2DB7D303C36DDD055215052F118E8E75 ] Themes          C:\WINDOWS\System32\shsvcs.dll
00:13:54.0674 0436  Themes - ok
00:13:54.0774 0436  [ EFEF22B9577E5051057FDE1AE381B50C ] TomTomHOMEService C:\Programme\TomTom HOME 2\TomTomHOMEService.exe
00:13:54.0794 0436  TomTomHOMEService - ok
00:13:54.0824 0436  TosIde - ok
00:13:54.0904 0436  [ 15FB67EB022A74B30E278D19B03DA3B4 ] TPkd            C:\WINDOWS\system32\drivers\TPkd.sys
00:13:54.0924 0436  TPkd ( UnsignedFile.Multi.Generic ) - warning
00:13:54.0924 0436  TPkd - detected UnsignedFile.Multi.Generic (1)
00:13:54.0994 0436  [ 626504572B175867F30F3215C04B3E2F ] TrkWks          C:\WINDOWS\system32\trkwks.dll
00:13:55.0195 0436  TrkWks - ok
00:13:55.0245 0436  [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs            C:\WINDOWS\system32\drivers\Udfs.sys
00:13:55.0445 0436  Udfs - ok
00:13:55.0455 0436  ultra - ok
00:13:55.0525 0436  [ AB0A7CA90D9E3D6A193905DC1715DED0 ] UMWdf          C:\WINDOWS\System32\wdfmgr.exe
00:13:55.0565 0436  UMWdf - ok
00:13:55.0615 0436  [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update          C:\WINDOWS\system32\DRIVERS\update.sys
00:13:55.0815 0436  Update - ok
00:13:55.0876 0436  [ 1DFD8975D8C89214B98D9387C1125B49 ] upnphost        C:\WINDOWS\System32\upnphost.dll
00:13:56.0046 0436  upnphost - ok
00:13:56.0116 0436  [ 9B11E6118958E63E1FEF129466E2BDA7 ] UPS            C:\WINDOWS\System32\ups.exe
00:13:56.0276 0436  UPS - ok
00:13:56.0346 0436  [ E919708DB44ED8543A7C017953148330 ] usbaudio        C:\WINDOWS\system32\drivers\usbaudio.sys
00:13:56.0516 0436  usbaudio - ok
00:13:56.0547 0436  [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp        C:\WINDOWS\system32\DRIVERS\usbccgp.sys
00:13:56.0717 0436  usbccgp - ok
00:13:56.0737 0436  [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci        C:\WINDOWS\system32\DRIVERS\usbehci.sys
00:13:56.0897 0436  usbehci - ok
00:13:56.0927 0436  [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub          C:\WINDOWS\system32\DRIVERS\usbhub.sys
00:13:57.0097 0436  usbhub - ok
00:13:57.0127 0436  [ A717C8721046828520C9EDF31288FC00 ] usbprint        C:\WINDOWS\system32\DRIVERS\usbprint.sys
00:13:57.0288 0436  usbprint - ok
00:13:57.0338 0436  [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan        C:\WINDOWS\system32\DRIVERS\usbscan.sys
00:13:57.0498 0436  usbscan - ok
00:13:57.0518 0436  [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR        C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
00:13:57.0668 0436  USBSTOR - ok
00:13:57.0698 0436  [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci        C:\WINDOWS\system32\DRIVERS\usbuhci.sys
00:13:57.0858 0436  usbuhci - ok
00:13:57.0909 0436  [ C90055BD2BB41443462EA715E0876B8D ] V0260VID        C:\WINDOWS\system32\DRIVERS\V0260Vid.sys
00:13:57.0969 0436  V0260VID - ok
00:13:57.0999 0436  [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave        C:\WINDOWS\System32\drivers\vga.sys
00:13:58.0179 0436  VgaSave - ok
00:13:58.0189 0436  ViaIde - ok
00:13:58.0219 0436  [ A5A712F4E880874A477AF790B5186E1D ] VolSnap        C:\WINDOWS\system32\drivers\VolSnap.sys
00:13:58.0379 0436  VolSnap - ok
00:13:58.0479 0436  [ 68F106273BE29E7B7EF8266977268E78 ] VSS            C:\WINDOWS\System32\vssvc.exe
00:13:58.0650 0436  VSS - ok
00:13:58.0740 0436  [ 7B353059E665F8B7AD2BBEAEF597CF45 ] W32Time        C:\WINDOWS\System32\w32time.dll
00:13:58.0910 0436  W32Time - ok
00:13:59.0000 0436  [ 677AD85E3058C821F5A73CDF7E5B5478 ] w70n51          C:\WINDOWS\system32\DRIVERS\w70n51.sys
00:13:59.0120 0436  w70n51 - ok
00:13:59.0150 0436  [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp          C:\WINDOWS\system32\DRIVERS\wanarp.sys
00:13:59.0331 0436  Wanarp - ok
00:13:59.0341 0436  WDICA - ok
00:13:59.0401 0436  [ 6768ACF64B18196494413695F0C3A00F ] wdmaud          C:\WINDOWS\system32\drivers\wdmaud.sys
00:13:59.0561 0436  wdmaud - ok
00:13:59.0641 0436  [ 81727C9873E3905A2FFC1EBD07265002 ] WebClient      C:\WINDOWS\System32\webclnt.dll
00:13:59.0781 0436  WebClient - ok
00:13:59.0871 0436  [ 6F3F3973D97714CC5F906A19FE883729 ] winmgmt        C:\WINDOWS\system32\wbem\WMIsvc.dll
00:14:00.0042 0436  winmgmt - ok
00:14:00.0132 0436  [ 140EF97B64F560FD78643CAE2CDAD838 ] WmdmPmSN        C:\WINDOWS\system32\mspmsnsv.dll
00:14:00.0172 0436  WmdmPmSN - ok
00:14:00.0222 0436  [ 93908111BA57A6E60EC2FA2DE202105C ] WmiApSrv        C:\WINDOWS\System32\wbem\wmiapsrv.exe
00:14:00.0402 0436  WmiApSrv - ok
00:14:00.0482 0436  [ 300B3E84FAF1A5C1F791C159BA28035D ] wscsvc          C:\WINDOWS\system32\wscsvc.dll
00:14:00.0652 0436  wscsvc - ok
00:14:00.0713 0436  [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC        C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
00:14:00.0893 0436  WSTCODEC - ok
00:14:00.0983 0436  [ 7B4FE05202AA6BF9F4DFD0E6A0D8A085 ] wuauserv        C:\WINDOWS\system32\wuauserv.dll
00:14:01.0153 0436  wuauserv - ok
00:14:01.0243 0436  [ C4F109C005F6725162D2D12CA751E4A7 ] WZCSVC          C:\WINDOWS\System32\wzcsvc.dll
00:14:01.0434 0436  WZCSVC - ok
00:14:01.0504 0436  [ 0ADA34871A2E1CD2CAAFED1237A47750 ] xmlprov        C:\WINDOWS\System32\xmlprov.dll
00:14:01.0694 0436  xmlprov - ok
00:14:01.0764 0436  [ 4FF040FE3099D578131CF62E3B822E0D ] {6080A529-897E-4629-A488-ABA0C29B635E} C:\WINDOWS\system32\drivers\ialmsbw.sys
00:14:01.0804 0436  {6080A529-897E-4629-A488-ABA0C29B635E} - ok
00:14:01.0844 0436  [ 9623FE5A34823EF8BE6BA55CB52222E8 ] {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} C:\WINDOWS\system32\drivers\ialmkchw.sys
00:14:01.0884 0436  {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
00:14:01.0914 0436  [ 4ACDBB1E48986863B34E696B479F7455 ] {E2B953A6-195A-44F9-9BA3-3D5F4E32BB55} C:\WINDOWS\system32\drivers\wA301a.sys
00:14:01.0954 0436  {E2B953A6-195A-44F9-9BA3-3D5F4E32BB55} - ok
00:14:01.0964 0436  ================ Scan global ===============================
00:14:02.0085 0436  [ 2C60091CA5F67C3032EAB3B30390C27F ] C:\WINDOWS\system32\basesrv.dll
00:14:02.0175 0436  [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll
00:14:02.0235 0436  [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll
00:14:02.0285 0436  [ A3EDBE9053889FB24AB22492472B39DC ] C:\WINDOWS\system32\services.exe
00:14:02.0285 0436  [Global] - ok
00:14:02.0285 0436  ================ Scan MBR ==================================
00:14:02.0305 0436  [ 671B81004FDD1588FA9ED1331C9CECA9 ] \Device\Harddisk0\DR0
00:14:02.0555 0436  \Device\Harddisk0\DR0 ( TDSS File System ) - warning
00:14:02.0555 0436  \Device\Harddisk0\DR0 - detected TDSS File System (1)
00:14:02.0585 0436  [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR8
00:14:02.0796 0436  \Device\Harddisk1\DR8 - ok
00:14:02.0806 0436  ================ Scan VBR ==================================
00:14:02.0836 0436  [ D942CD8972B5F073792F4DE61D328D4B ] \Device\Harddisk0\DR0\Partition1
00:14:02.0836 0436  \Device\Harddisk0\DR0\Partition1 - ok
00:14:02.0866 0436  [ 64DCC1CB2D04F7BE2626705D075BED62 ] \Device\Harddisk0\DR0\Partition2
00:14:02.0866 0436  \Device\Harddisk0\DR0\Partition2 - ok
00:14:02.0886 0436  [ B140085EEC6B2377E4D2B3B56FE57AC5 ] \Device\Harddisk1\DR8\Partition1
00:14:02.0896 0436  \Device\Harddisk1\DR8\Partition1 - ok
00:14:02.0896 0436  ============================================================
00:14:02.0896 0436  Scan finished
00:14:02.0896 0436  ============================================================
00:14:03.0016 3428  Detected object count: 7
00:14:03.0016 3428  Actual detected object count: 7
00:22:37.0776 3428  BTWUSB ( UnsignedFile.Multi.Generic ) - skipped by user
00:22:37.0776 3428  BTWUSB ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:22:37.0786 3428  DKbFltr ( UnsignedFile.Multi.Generic ) - skipped by user
00:22:37.0786 3428  DKbFltr ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:22:37.0786 3428  NTIDrvr ( UnsignedFile.Multi.Generic ) - skipped by user
00:22:37.0786 3428  NTIDrvr ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:22:37.0786 3428  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - skipped by user
00:22:37.0786 3428  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:22:37.0786 3428  ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
00:22:37.0786 3428  ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:22:37.0786 3428  TPkd ( UnsignedFile.Multi.Generic ) - skipped by user
00:22:37.0786 3428  TPkd ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:22:37.0796 3428  \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
00:22:37.0796 3428  \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip


cosinus 15.10.2012 13:52

Code:

\Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
Diesen Eintrag bitte mit dem TDSS-Killer fixen. Aber bitte nur diesen Eintrag!

Um das zu tun musst du den TDSS-Killer neu starten und einen neuen Scan machen. Wenn du danach die Ergebnisse siehst, stellst du bitte diesen Eintrag auf CURE bzw. DELETE (je nachdem was dir angeboten wird, alle anderen bitte auf SKIP lassen! ) und klickst dann unten rechts auf continue

Starte Windows danach neu und mach wieder ein komplett neues Log mit dem TDSS-Killer. Wie immer wieder in CODE-Tags posten.

perry85 15.10.2012 18:22

den TDSS-Killer wieder so einstellen wie beim ersten scan, oder einfach so lassen wie es ist und scanen?

cosinus 15.10.2012 19:02

So wie beim ersten mal bitte auch wieder einstellen

perry85 15.10.2012 19:59

Code:


20:52:21.0163 2572  TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
20:52:24.0117 2572  ============================================================
20:52:24.0117 2572  Current date / time: 2012/10/15 20:52:24.0117
20:52:24.0117 2572  SystemInfo:
20:52:24.0117 2572 
20:52:24.0117 2572  OS Version: 5.1.2600 ServicePack: 3.0
20:52:24.0117 2572  Product type: Workstation
20:52:24.0117 2572  ComputerName: ACER-5J0JDWIJ8Z
20:52:24.0117 2572  UserName: MR
20:52:24.0117 2572  Windows directory: C:\WINDOWS
20:52:24.0117 2572  System windows directory: C:\WINDOWS
20:52:24.0117 2572  Processor architecture: Intel x86
20:52:24.0117 2572  Number of processors: 1
20:52:24.0117 2572  Page size: 0x1000
20:52:24.0117 2572  Boot type: Normal boot
20:52:24.0117 2572  ============================================================
20:52:25.0750 2572  Drive \Device\Harddisk0\DR0 - Size: 0x6FC7C8000 (27.95 Gb), SectorSize: 0x200, Cylinders: 0xE40, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
20:52:25.0770 2572  Drive \Device\Harddisk1\DR4 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
20:52:25.0790 2572  Drive \Device\Harddisk2\DR6 - Size: 0xE8E0DB5800 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
20:52:28.0934 2572  ============================================================
20:52:28.0934 2572  \Device\Harddisk0\DR0:
20:52:28.0934 2572  MBR partitions:
20:52:28.0934 2572  \Device\Harddisk0\DR0\Partition1: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x2457405
20:52:28.0934 2572  \Device\Harddisk0\DR0\Partition2: MBR, Type 0xC, StartLBA 0x2457444, BlocksNum 0x1388B3B
20:52:28.0934 2572  \Device\Harddisk1\DR4:
20:52:28.0944 2572  MBR partitions:
20:52:28.0944 2572  \Device\Harddisk1\DR4\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2542D682
20:52:28.0944 2572  \Device\Harddisk2\DR6:
20:52:28.0954 2572  MBR partitions:
20:52:28.0954 2572  \Device\Harddisk2\DR6\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x74705800
20:52:28.0954 2572  ============================================================
20:52:28.0954 2572  C: <-> \Device\Harddisk0\DR0\Partition1
20:52:28.0974 2572  D: <-> \Device\Harddisk0\DR0\Partition2
20:52:29.0115 2572  F: <-> \Device\Harddisk2\DR6\Partition1
20:52:29.0185 2572  G: <-> \Device\Harddisk1\DR4\Partition1
20:52:29.0185 2572  ============================================================
20:52:29.0185 2572  Initialize success
20:52:29.0185 2572  ============================================================
20:52:51.0056 3156  ============================================================
20:52:51.0056 3156  Scan started
20:52:51.0056 3156  Mode: Manual; SigCheck; TDLFS;
20:52:51.0056 3156  ============================================================
20:52:52.0308 3156  ================ Scan system memory ========================
20:52:52.0308 3156  System memory - ok
20:52:52.0308 3156  ================ Scan services =============================
20:52:52.0839 3156  [ 8912B38E7906BDE9999E4BBDC4E65BDC ] ABBYY.Licensing.FineReader.Professional.11.0 C:\Programme\ABBYY FineReader 11\NetworkLicenseServer.exe
20:52:53.0650 3156  ABBYY.Licensing.FineReader.Professional.11.0 - ok
20:52:53.0710 3156  Abiosdsk - ok
20:52:53.0730 3156  abp480n5 - ok
20:52:53.0790 3156  [ AC407F1A62C3A300B4F2B5A9F1D55B2C ] ACPI            C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:52:56.0013 3156  ACPI - ok
20:52:56.0113 3156  [ 9E1CA3160DAFB159CA14F83B1E317F75 ] ACPIEC          C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
20:52:56.0314 3156  ACPIEC - ok
20:52:56.0594 3156  [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
20:52:56.0634 3156  AdobeFlashPlayerUpdateSvc - ok
20:52:56.0654 3156  adpu160m - ok
20:52:56.0704 3156  [ 8BED39E3C35D6A489438B8141717A557 ] aec            C:\WINDOWS\system32\drivers\aec.sys
20:52:56.0945 3156  aec - ok
20:52:57.0025 3156  [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD            C:\WINDOWS\System32\drivers\afd.sys
20:52:57.0095 3156  AFD - ok
20:52:57.0165 3156  [ 3E60F847C0C57EEDB7C0639710512CCC ] AgereSoftModem  C:\WINDOWS\system32\DRIVERS\AGRSM.sys
20:52:57.0325 3156  AgereSoftModem - ok
20:52:57.0335 3156  Aha154x - ok
20:52:57.0355 3156  aic78u2 - ok
20:52:57.0365 3156  aic78xx - ok
20:52:57.0445 3156  [ EA8D01E733FDA92147DE62AA04D154A6 ] ALCXWDM        C:\WINDOWS\system32\drivers\ALCXWDM.SYS
20:52:57.0615 3156  ALCXWDM - ok
20:52:57.0756 3156  [ 738D80CC01D7BC7584BE917B7F544394 ] Alerter        C:\WINDOWS\system32\alrsvc.dll
20:52:57.0986 3156  Alerter - ok
20:52:58.0026 3156  [ 190CD73D4984F94D823F9444980513E5 ] ALG            C:\WINDOWS\System32\alg.exe
20:52:58.0226 3156  ALG - ok
20:52:58.0236 3156  AliIde - ok
20:52:58.0256 3156  amsint - ok
20:52:58.0337 3156  [ 42C42796BD1A01D37CD9ED05D9694D2A ] ApfiltrService  C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
20:52:58.0387 3156  ApfiltrService - ok
20:52:58.0447 3156  AppMgmt - ok
20:52:58.0497 3156  [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394        C:\WINDOWS\system32\DRIVERS\arp1394.sys
20:52:58.0697 3156  Arp1394 - ok
20:52:58.0707 3156  asc - ok
20:52:58.0727 3156  asc3350p - ok
20:52:58.0737 3156  asc3550 - ok
20:52:58.0877 3156  [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state    C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
20:52:58.0897 3156  aspnet_state - ok
20:52:58.0927 3156  [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac        C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:52:59.0108 3156  AsyncMac - ok
20:52:59.0208 3156  [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi          C:\WINDOWS\system32\DRIVERS\atapi.sys
20:52:59.0398 3156  atapi - ok
20:52:59.0418 3156  Atdisk - ok
20:52:59.0518 3156  [ 9916C1225104BA14794209CFA8012159 ] Atmarpc        C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:52:59.0678 3156  Atmarpc - ok
20:52:59.0819 3156  [ 58ED0D5452DF7BE732193E7999C6B9A4 ] AudioSrv        C:\WINDOWS\System32\audiosrv.dll
20:53:00.0009 3156  AudioSrv - ok
20:53:00.0109 3156  [ D9F724AA26C010A217C97606B160ED68 ] audstub        C:\WINDOWS\system32\DRIVERS\audstub.sys
20:53:00.0319 3156  audstub - ok
20:53:00.0400 3156  [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep            C:\WINDOWS\system32\drivers\Beep.sys
20:53:00.0660 3156  Beep - ok
20:53:00.0750 3156  [ D6F603772A789BB3228F310D650B8BD1 ] BITS            C:\WINDOWS\system32\qmgr.dll
20:53:00.0950 3156  BITS - ok
20:53:01.0000 3156  Bonjour Service - ok
20:53:01.0060 3156  [ B71549F23736ADF83A571061C47777FD ] Browser        C:\WINDOWS\System32\browser.dll
20:53:01.0121 3156  Browser - ok
20:53:01.0151 3156  [ B5557A53074076E43ED70D5C0653FBF6 ] BTWUSB          C:\WINDOWS\system32\Drivers\btwusb.sys
20:53:01.0181 3156  BTWUSB ( UnsignedFile.Multi.Generic ) - warning
20:53:01.0181 3156  BTWUSB - detected UnsignedFile.Multi.Generic (1)
20:53:01.0221 3156  [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k        C:\WINDOWS\system32\drivers\cbidf2k.sys
20:53:01.0501 3156  cbidf2k - ok
20:53:01.0571 3156  [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE        C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
20:53:01.0741 3156  CCDECODE - ok
20:53:01.0761 3156  cd20xrnt - ok
20:53:01.0781 3156  [ C1B486A7658353D33A10CC15211A873B ] Cdaudio        C:\WINDOWS\system32\drivers\Cdaudio.sys
20:53:02.0022 3156  Cdaudio - ok
20:53:02.0102 3156  [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs            C:\WINDOWS\system32\drivers\Cdfs.sys
20:53:02.0262 3156  Cdfs - ok
20:53:02.0292 3156  [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom          C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:53:02.0482 3156  Cdrom - ok
20:53:02.0503 3156  Changer - ok
20:53:02.0623 3156  [ 28E3040D1F1CA2008CD6B29DFEBC9A5E ] CiSvc          C:\WINDOWS\system32\cisvc.exe
20:53:02.0793 3156  CiSvc - ok
20:53:02.0903 3156  [ 778A30ED3C134EB7E406AFC407E9997D ] ClipSrv        C:\WINDOWS\system32\clipsrv.exe
20:53:03.0083 3156  ClipSrv - ok
20:53:03.0234 3156  [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:53:03.0254 3156  clr_optimization_v2.0.50727_32 - ok
20:53:03.0284 3156  [ 0F6C187D38D98F8DF904589A5F94D411 ] CmBatt          C:\WINDOWS\system32\DRIVERS\CmBatt.sys
20:53:03.0444 3156  CmBatt - ok
20:53:03.0454 3156  CmdIde - ok
20:53:03.0484 3156  [ 6E4C9F21F0FAE8940661144F41B13203 ] Compbatt        C:\WINDOWS\system32\DRIVERS\compbatt.sys
20:53:03.0654 3156  Compbatt - ok
20:53:03.0704 3156  COMSysApp - ok
20:53:03.0734 3156  Cpqarray - ok
20:53:03.0824 3156  [ 611F824E5C703A5A899F84C5F1699E4D ] CryptSvc        C:\WINDOWS\System32\cryptsvc.dll
20:53:04.0015 3156  CryptSvc - ok
20:53:04.0025 3156  dac2w2k - ok
20:53:04.0045 3156  dac960nt - ok
20:53:04.0125 3156  [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] DcomLaunch      C:\WINDOWS\system32\rpcss.dll
20:53:04.0225 3156  DcomLaunch - ok
20:53:04.0285 3156  [ C29A1C9B75BA38FA37F8C44405DEC360 ] Dhcp            C:\WINDOWS\System32\dhcpcsvc.dll
20:53:04.0505 3156  Dhcp - ok
20:53:04.0596 3156  [ 044452051F3E02E7963599FC8F4F3E25 ] Disk            C:\WINDOWS\system32\DRIVERS\disk.sys
20:53:04.0776 3156  Disk - ok
20:53:04.0896 3156  [ 96A48BDA68BF734AAE79F910AB884A34 ] DKbFltr        C:\WINDOWS\system32\Drivers\DKbFltr.sys
20:53:04.0926 3156  DKbFltr ( UnsignedFile.Multi.Generic ) - warning
20:53:04.0926 3156  DKbFltr - detected UnsignedFile.Multi.Generic (1)
20:53:04.0966 3156  dmadmin - ok
20:53:05.0036 3156  [ 0DCFC8395A99FECBB1EF771CEC7FE4EA ] dmboot          C:\WINDOWS\system32\drivers\dmboot.sys
20:53:05.0297 3156  dmboot - ok
20:53:05.0407 3156  [ 53720AB12B48719D00E327DA470A619A ] dmio            C:\WINDOWS\system32\drivers\dmio.sys
20:53:05.0587 3156  dmio - ok
20:53:05.0697 3156  [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload          C:\WINDOWS\system32\drivers\dmload.sys
20:53:05.0927 3156  dmload - ok
20:53:06.0028 3156  [ 25C83FFBBA13B554EB6D59A9B2E2EE78 ] dmserver        C:\WINDOWS\System32\dmserver.dll
20:53:06.0188 3156  dmserver - ok
20:53:06.0328 3156  [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic          C:\WINDOWS\system32\drivers\DMusic.sys
20:53:06.0518 3156  DMusic - ok
20:53:06.0598 3156  [ 407F3227AC618FD1CA54B335B083DE07 ] Dnscache        C:\WINDOWS\System32\dnsrslvr.dll
20:53:06.0659 3156  Dnscache - ok
20:53:06.0739 3156  [ 676E36C4FF5BCEA1900F44182B9723E6 ] Dot3svc        C:\WINDOWS\System32\dot3svc.dll
20:53:06.0909 3156  Dot3svc - ok
20:53:06.0929 3156  dpti2o - ok
20:53:06.0989 3156  [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud        C:\WINDOWS\system32\drivers\drmkaud.sys
20:53:07.0179 3156  drmkaud - ok
20:53:07.0229 3156  [ 4E4F2FDDAB0A0736D7671134DCCE91FB ] EapHost        C:\WINDOWS\System32\eapsvc.dll
20:53:07.0390 3156  EapHost - ok
20:53:07.0520 3156  [ 877C18558D70587AA7823A1A308AC96B ] ERSvc          C:\WINDOWS\System32\ersvc.dll
20:53:07.0690 3156  ERSvc - ok
20:53:07.0820 3156  [ A3EDBE9053889FB24AB22492472B39DC ] Eventlog        C:\WINDOWS\system32\services.exe
20:53:07.0850 3156  Eventlog - ok
20:53:07.0920 3156  [ AF4F6B5739D18CA7972AB53E091CBC74 ] EventSystem    C:\WINDOWS\System32\es.dll
20:53:07.0980 3156  EventSystem - ok
20:53:08.0030 3156  [ 38D332A6D56AF32635675F132548343E ] Fastfat        C:\WINDOWS\system32\drivers\Fastfat.sys
20:53:08.0251 3156  Fastfat - ok
20:53:08.0321 3156  [ 2DB7D303C36DDD055215052F118E8E75 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
20:53:08.0381 3156  FastUserSwitchingCompatibility - ok
20:53:08.0471 3156  [ 08B8B302AF0D1B3B8543429BBAC8F21F ] Fax            C:\WINDOWS\system32\fxssvc.exe
20:53:08.0661 3156  Fax - ok
20:53:08.0812 3156  [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc            C:\WINDOWS\system32\drivers\Fdc.sys
20:53:09.0032 3156  Fdc - ok
20:53:09.0122 3156  [ B0678A548587C5F1967B0D70BACAD6C1 ] Fips            C:\WINDOWS\system32\drivers\Fips.sys
20:53:09.0292 3156  Fips - ok
20:53:09.0443 3156  [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk        C:\WINDOWS\system32\drivers\Flpydisk.sys
20:53:09.0633 3156  Flpydisk - ok
20:53:10.0324 3156  [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr          C:\WINDOWS\system32\drivers\fltmgr.sys
20:53:10.0624 3156  FltMgr - ok
20:53:11.0546 3156  [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
20:53:11.0716 3156  FontCache3.0.0.0 - ok
20:53:11.0756 3156  [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec          C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:53:12.0046 3156  Fs_Rec - ok
20:53:12.0307 3156  [ 8F1955CE42E1484714B542F341647778 ] Ftdisk          C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:53:12.0527 3156  Ftdisk - ok
20:53:12.0587 3156  [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM    C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
20:53:12.0597 3156  GEARAspiWDM - ok
20:53:12.0627 3156  [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc            C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:53:12.0797 3156  Gpc - ok
20:53:12.0918 3156  [ F0A0041644A2E026044C6EEEC42B7241 ] gv3            C:\WINDOWS\system32\DRIVERS\gv3.sys
20:53:12.0948 3156  gv3 - ok
20:53:13.0048 3156  [ CB66BF85BF599BEFD6C6A57C2E20357F ] helpsvc        C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
20:53:13.0218 3156  helpsvc - ok
20:53:13.0288 3156  [ B35DA85E60C0103F2E4104532DA2F12B ] HidServ        C:\WINDOWS\System32\hidserv.dll
20:53:13.0468 3156  HidServ - ok
20:53:13.0598 3156  [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb          C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:53:13.0769 3156  HidUsb - ok
20:53:13.0899 3156  [ ED29F14101523A6E0E808107405D452C ] hkmsvc          C:\WINDOWS\System32\kmsvc.dll
20:53:14.0059 3156  hkmsvc - ok
20:53:14.0069 3156  hpn - ok
20:53:14.0199 3156  [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP            C:\WINDOWS\system32\Drivers\HTTP.sys
20:53:14.0249 3156  HTTP - ok
20:53:14.0340 3156  [ 9E4ADB854CEBCFB81A4B36718FEECD16 ] HTTPFilter      C:\WINDOWS\System32\w3ssl.dll
20:53:14.0510 3156  HTTPFilter - ok
20:53:14.0520 3156  i2omgmt - ok
20:53:14.0530 3156  i2omp - ok
20:53:14.0570 3156  [ E283B97CFBEB86C1D86BAED5F7846A92 ] i8042prt        C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:53:14.0750 3156  i8042prt - ok
20:53:14.0780 3156  [ 759A944AA02F686EC069E6FF5B5636D8 ] ialm            C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
20:53:14.0960 3156  ialm - ok
20:53:15.0041 3156  [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc          C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
20:53:15.0111 3156  idsvc - ok
20:53:15.0141 3156  [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi          C:\WINDOWS\system32\DRIVERS\imapi.sys
20:53:15.0301 3156  Imapi - ok
20:53:15.0411 3156  [ D4B413AA210C21E46AEDD2BA5B68D38E ] ImapiService    C:\WINDOWS\System32\imapi.exe
20:53:15.0621 3156  ImapiService - ok
20:53:15.0641 3156  ini910u - ok
20:53:15.0681 3156  [ 69C4E3C9E67A1F103B94E14FDD5F3213 ] IntelIde        C:\WINDOWS\system32\DRIVERS\intelide.sys
20:53:15.0842 3156  IntelIde - ok
20:53:15.0882 3156  [ 4C7D2750158ED6E7AD642D97BFFAE351 ] intelppm        C:\WINDOWS\system32\DRIVERS\intelppm.sys
20:53:16.0052 3156  intelppm - ok
20:53:16.0092 3156  [ 3BB22519A194418D5FEC05D800A19AD0 ] ip6fw          C:\WINDOWS\system32\drivers\ip6fw.sys
20:53:16.0262 3156  ip6fw - ok
20:53:16.0392 3156  [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver  C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:53:16.0623 3156  IpFilterDriver - ok
20:53:16.0673 3156  [ B87AB476DCF76E72010632B5550955F5 ] IpInIp          C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:53:16.0833 3156  IpInIp - ok
20:53:16.0883 3156  [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat          C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:53:17.0053 3156  IpNat - ok
20:53:17.0073 3156  [ 23C74D75E36E7158768DD63D92789A91 ] IPSec          C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:53:17.0254 3156  IPSec - ok
20:53:17.0314 3156  [ ACA5E7B54409F9CB5EED97ED0C81120E ] irda            C:\WINDOWS\system32\DRIVERS\irda.sys
20:53:17.0474 3156  irda - ok
20:53:17.0594 3156  [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM          C:\WINDOWS\system32\DRIVERS\irenum.sys
20:53:17.0754 3156  IRENUM - ok
20:53:17.0885 3156  [ 2EFE1DB1EC58A26B0C14BFDA122E246F ] Irmon          C:\WINDOWS\System32\irmon.dll
20:53:18.0095 3156  Irmon - ok
20:53:18.0185 3156  [ 6DFB88F64135C525433E87648BDA30DE ] isapnp          C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:53:18.0375 3156  isapnp - ok
20:53:18.0596 3156  [ 9AE07549A0D691A103FAF8946554BDB7 ] JavaQuickStarterService C:\Programme\Java\jre6\bin\jqs.exe
20:53:18.0626 3156  JavaQuickStarterService - ok
20:53:18.0646 3156  [ 1704D8C4C8807B889E43C649B478A452 ] Kbdclass        C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:53:18.0836 3156  Kbdclass - ok
20:53:18.0866 3156  [ B6D6C117D771C98130497265F26D1882 ] kbdhid          C:\WINDOWS\system32\DRIVERS\kbdhid.sys
20:53:19.0056 3156  kbdhid - ok
20:53:19.0086 3156  [ 692BCF44383D056AED41B045A323D378 ] kmixer          C:\WINDOWS\system32\drivers\kmixer.sys
20:53:19.0247 3156  kmixer - ok
20:53:19.0287 3156  [ B467646C54CC746128904E1654C750C1 ] KSecDD          C:\WINDOWS\system32\drivers\KSecDD.sys
20:53:19.0337 3156  KSecDD - ok
20:53:19.0367 3156  [ 2BBDCB79900990F0716DFCB714E72DE7 ] lanmanserver    C:\WINDOWS\System32\srvsvc.dll
20:53:19.0437 3156  lanmanserver - ok
20:53:19.0527 3156  [ 1869B14B06B44B44AF70548E1EA3303F ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
20:53:19.0587 3156  lanmanworkstation - ok
20:53:19.0607 3156  lbrtfdc - ok
20:53:19.0657 3156  [ 636714B7D43C8D0C80449123FD266920 ] LmHosts        C:\WINDOWS\System32\lmhsvc.dll
20:53:19.0837 3156  LmHosts - ok
20:53:19.0878 3156  [ 65E794E86468B61F2BC79ABC48BC4433 ] MBAMProtector  C:\WINDOWS\system32\drivers\mbam.sys
20:53:20.0128 3156  MBAMProtector - ok
20:53:20.0198 3156  [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler  C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
20:53:20.0238 3156  MBAMScheduler - ok
20:53:20.0298 3156  [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService    C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
20:53:20.0348 3156  MBAMService - ok
20:53:20.0398 3156  [ B7550A7107281D170CE85524B1488C98 ] Messenger      C:\WINDOWS\System32\msgsvc.dll
20:53:20.0609 3156  Messenger - ok
20:53:20.0679 3156  [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd          C:\WINDOWS\system32\drivers\mnmdd.sys
20:53:20.0909 3156  mnmdd - ok
20:53:20.0989 3156  [ C2F1D365FD96791B037EE504868065D3 ] mnmsrvc        C:\WINDOWS\System32\mnmsrvc.exe
20:53:21.0129 3156  mnmsrvc - ok
20:53:21.0149 3156  [ 6FB74EBD4EC57A6F1781DE3852CC3362 ] Modem          C:\WINDOWS\system32\drivers\Modem.sys
20:53:21.0310 3156  Modem - ok
20:53:21.0330 3156  [ B24CE8005DEAB254C0251E15CB71D802 ] Mouclass        C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:53:21.0490 3156  Mouclass - ok
20:53:21.0590 3156  [ 66A6F73C74E1791464160A7065CE711A ] mouhid          C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:53:21.0820 3156  mouhid - ok
20:53:21.0880 3156  [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr        C:\WINDOWS\system32\drivers\MountMgr.sys
20:53:22.0041 3156  MountMgr - ok
20:53:22.0111 3156  [ 4D7F2682D29B92A6251B17957AA0B985 ] MozillaMaintenance C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe
20:53:22.0141 3156  MozillaMaintenance - ok
20:53:22.0151 3156  mraid35x - ok
20:53:22.0211 3156  [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV          C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:53:22.0381 3156  MRxDAV - ok
20:53:22.0531 3156  [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb          C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:53:22.0631 3156  MRxSmb - ok
20:53:22.0682 3156  [ 35A031AF38C55F92D28AA03EE9F12CC9 ] MSDTC          C:\WINDOWS\System32\msdtc.exe
20:53:22.0902 3156  MSDTC - ok
20:53:22.0972 3156  [ C941EA2454BA8350021D774DAF0F1027 ] Msfs            C:\WINDOWS\system32\drivers\Msfs.sys
20:53:23.0132 3156  Msfs - ok
20:53:23.0252 3156  MSIServer - ok
20:53:23.0282 3156  [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV        C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:53:23.0443 3156  MSKSSRV - ok
20:53:23.0453 3156  [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK        C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:53:23.0603 3156  MSPCLOCK - ok
20:53:23.0663 3156  [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM          C:\WINDOWS\system32\drivers\MSPQM.sys
20:53:23.0833 3156  MSPQM - ok
20:53:23.0853 3156  [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios        C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:53:24.0023 3156  mssmbios - ok
20:53:24.0124 3156  [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE          C:\WINDOWS\system32\drivers\MSTEE.sys
20:53:24.0304 3156  MSTEE - ok
20:53:24.0344 3156  [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup            C:\WINDOWS\system32\drivers\Mup.sys
20:53:24.0374 3156  Mup - ok
20:53:24.0404 3156  [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC        C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
20:53:24.0574 3156  NABTSFEC - ok
20:53:24.0765 3156  [ 46BB15AE2AC7D025D6D2567B876817BD ] napagent        C:\WINDOWS\System32\qagentrt.dll
20:53:24.0945 3156  napagent - ok
20:53:25.0175 3156  [ 9D1CCE440552500DED3A62F9D779CDB4 ] NAUpdate        C:\Programme\Nero\Update\NASvc.exe
20:53:25.0215 3156  NAUpdate - ok
20:53:25.0245 3156  [ 1DF7F42665C94B825322FAE71721130D ] NDIS            C:\WINDOWS\system32\drivers\NDIS.sys
20:53:25.0405 3156  NDIS - ok
20:53:25.0436 3156  [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP          C:\WINDOWS\system32\DRIVERS\NdisIP.sys
20:53:25.0606 3156  NdisIP - ok
20:53:25.0626 3156  [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi        C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:53:25.0676 3156  NdisTapi - ok
20:53:25.0716 3156  [ F927A4434C5028758A842943EF1A3849 ] Ndisuio        C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:53:25.0876 3156  Ndisuio - ok
20:53:25.0966 3156  [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan        C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:53:26.0126 3156  NdisWan - ok
20:53:26.0157 3156  [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy        C:\WINDOWS\system32\drivers\NDProxy.sys
20:53:26.0177 3156  NDProxy - ok
20:53:26.0207 3156  [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS        C:\WINDOWS\system32\DRIVERS\netbios.sys
20:53:26.0377 3156  NetBIOS - ok
20:53:26.0477 3156  [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT          C:\WINDOWS\system32\DRIVERS\netbt.sys
20:53:26.0637 3156  NetBT - ok
20:53:26.0797 3156  [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDE          C:\WINDOWS\system32\netdde.exe
20:53:26.0938 3156  NetDDE - ok
20:53:26.0948 3156  [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDEdsdm      C:\WINDOWS\system32\netdde.exe
20:53:27.0108 3156  NetDDEdsdm - ok
20:53:27.0148 3156  [ AFB8261B56CBA0D86AEB6DF682AF9785 ] Netlogon        C:\WINDOWS\System32\lsass.exe
20:53:27.0308 3156  Netlogon - ok
20:53:27.0378 3156  [ E6D88F1F6745BF00B57E7855A2AB696C ] Netman          C:\WINDOWS\System32\netman.dll
20:53:27.0559 3156  Netman - ok
20:53:27.0759 3156  [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:53:27.0789 3156  NetTcpPortSharing - ok
20:53:27.0829 3156  [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394        C:\WINDOWS\system32\DRIVERS\nic1394.sys
20:53:28.0009 3156  NIC1394 - ok
20:53:28.0099 3156  [ F1B67B6B0751AE0E6E964B02821206A3 ] Nla            C:\WINDOWS\System32\mswsock.dll
20:53:28.0139 3156  Nla - ok
20:53:28.0179 3156  [ 1926B4EEF80F4A0C8CC8FCBB6B4A7461 ] Nokia USB Generic C:\WINDOWS\system32\drivers\nmwcdc.sys
20:53:28.0300 3156  Nokia USB Generic - ok
20:53:28.0320 3156  [ DF4211B6CA609FF11F43261E04AC92F1 ] Nokia USB Modem C:\WINDOWS\system32\drivers\nmwcdcm.sys
20:53:28.0370 3156  Nokia USB Modem - ok
20:53:28.0410 3156  [ DDFE78EEB4AFCF91EDC52B8F7C7DAD15 ] Nokia USB Phone Parent C:\WINDOWS\system32\drivers\nmwcd.sys
20:53:28.0450 3156  Nokia USB Phone Parent - ok
20:53:28.0480 3156  [ DF4211B6CA609FF11F43261E04AC92F1 ] Nokia USB Port  C:\WINDOWS\system32\drivers\nmwcdcj.sys
20:53:28.0510 3156  Nokia USB Port - ok
20:53:28.0530 3156  [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs            C:\WINDOWS\system32\drivers\Npfs.sys
20:53:28.0720 3156  Npfs - ok
20:53:28.0790 3156  [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs            C:\WINDOWS\system32\drivers\Ntfs.sys
20:53:28.0991 3156  Ntfs - ok
20:53:29.0021 3156  [ 15A72D5B8F0B6A718207F14BD5EBB8FF ] NTIDrvr        C:\WINDOWS\system32\DRIVERS\NTIDrvr.sys
20:53:29.0041 3156  NTIDrvr ( UnsignedFile.Multi.Generic ) - warning
20:53:29.0041 3156  NTIDrvr - detected UnsignedFile.Multi.Generic (1)
20:53:29.0061 3156  [ AFB8261B56CBA0D86AEB6DF682AF9785 ] NtLmSsp        C:\WINDOWS\System32\lsass.exe
20:53:29.0201 3156  NtLmSsp - ok
20:53:29.0351 3156  [ 56AF4064996FA5BAC9C449B1514B4770 ] NtmsSvc        C:\WINDOWS\system32\ntmssvc.dll
20:53:29.0551 3156  NtmsSvc - ok
20:53:29.0662 3156  [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null            C:\WINDOWS\system32\drivers\Null.sys
20:53:29.0912 3156  Null - ok
20:53:30.0042 3156  [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt        C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:53:30.0323 3156  NwlnkFlt - ok
20:53:30.0543 3156  [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd        C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:53:30.0793 3156  NwlnkFwd - ok
20:53:30.0943 3156  [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394        C:\WINDOWS\system32\DRIVERS\ohci1394.sys
20:53:31.0114 3156  ohci1394 - ok
20:53:31.0294 3156  [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose            C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE
20:53:31.0314 3156  ose - ok
20:53:31.0344 3156  [ F84785660305B9B903FB3BCA8BA29837 ] Parport        C:\WINDOWS\system32\DRIVERS\parport.sys
20:53:31.0554 3156  Parport - ok
20:53:31.0654 3156  [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr        C:\WINDOWS\system32\drivers\PartMgr.sys
20:53:31.0815 3156  PartMgr - ok
20:53:31.0855 3156  [ C2BF987829099A3EAA2CA6A0A90ECB4F ] ParVdm          C:\WINDOWS\system32\drivers\ParVdm.sys
20:53:32.0095 3156  ParVdm - ok
20:53:32.0115 3156  [ 387E8DEDC343AA2D1EFBC30580273ACD ] PCI            C:\WINDOWS\system32\DRIVERS\pci.sys
20:53:32.0295 3156  PCI - ok
20:53:32.0305 3156  PCIDump - ok
20:53:32.0325 3156  [ 59BA86D9A61CBCF4DF8E598C331F5B82 ] PCIIde          C:\WINDOWS\system32\DRIVERS\pciide.sys
20:53:32.0556 3156  PCIIde - ok
20:53:32.0666 3156  [ A2A966B77D61847D61A3051DF87C8C97 ] Pcmcia          C:\WINDOWS\system32\DRIVERS\pcmcia.sys
20:53:32.0826 3156  Pcmcia - ok
20:53:32.0836 3156  PDCOMP - ok
20:53:32.0856 3156  PDFRAME - ok
20:53:32.0866 3156  PDRELI - ok
20:53:32.0876 3156  PDRFRAME - ok
20:53:32.0896 3156  perc2 - ok
20:53:32.0906 3156  perc2hib - ok
20:53:32.0996 3156  [ A3EDBE9053889FB24AB22492472B39DC ] PlugPlay        C:\WINDOWS\system32\services.exe
20:53:33.0016 3156  PlugPlay - ok
20:53:33.0036 3156  [ AFB8261B56CBA0D86AEB6DF682AF9785 ] PolicyAgent    C:\WINDOWS\System32\lsass.exe
20:53:33.0187 3156  PolicyAgent - ok
20:53:33.0257 3156  [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport    C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:53:33.0427 3156  PptpMiniport - ok
20:53:33.0457 3156  [ 2CB55427C58679F49AD600FCCBA76360 ] Processor      C:\WINDOWS\system32\DRIVERS\processr.sys
20:53:33.0627 3156  Processor - ok
20:53:33.0637 3156  [ AFB8261B56CBA0D86AEB6DF682AF9785 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
20:53:33.0788 3156  ProtectedStorage - ok
20:53:33.0808 3156  [ 09298EC810B07E5D582CB3A3F9255424 ] PSched          C:\WINDOWS\system32\DRIVERS\psched.sys
20:53:33.0988 3156  PSched - ok
20:53:34.0018 3156  [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink        C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:53:34.0268 3156  Ptilink - ok
20:53:34.0378 3156  [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20        C:\WINDOWS\system32\Drivers\PxHelp20.sys
20:53:34.0398 3156  PxHelp20 - ok
20:53:34.0408 3156  ql1080 - ok
20:53:34.0428 3156  Ql10wnt - ok
20:53:34.0438 3156  ql12160 - ok
20:53:34.0458 3156  ql1240 - ok
20:53:34.0468 3156  ql1280 - ok
20:53:34.0509 3156  [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd          C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:53:34.0739 3156  RasAcd - ok
20:53:34.0879 3156  [ F5BA6CACCDB66C8F048E867563203246 ] RasAuto        C:\WINDOWS\System32\rasauto.dll
20:53:35.0059 3156  RasAuto - ok
20:53:35.0159 3156  [ 0207D26DDF796A193CCD9F83047BB5FC ] Rasirda        C:\WINDOWS\system32\DRIVERS\rasirda.sys
20:53:35.0250 3156  Rasirda - ok
20:53:35.0260 3156  [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp        C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:53:35.0440 3156  Rasl2tp - ok
20:53:35.0550 3156  [ F9A7B66EA345726EDB5862A46B1ECCD5 ] RasMan          C:\WINDOWS\System32\rasmans.dll
20:53:35.0730 3156  RasMan - ok
20:53:35.0850 3156  [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe        C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:53:36.0011 3156  RasPppoe - ok
20:53:36.0041 3156  [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti          C:\WINDOWS\system32\DRIVERS\raspti.sys
20:53:36.0291 3156  Raspti - ok
20:53:36.0361 3156  [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss          C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:53:36.0521 3156  Rdbss - ok
20:53:36.0642 3156  [ 4912D5B403614CE99C28420F75353332 ] RDPCDD          C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:53:36.0822 3156  RDPCDD - ok
20:53:36.0982 3156  [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD          C:\WINDOWS\system32\drivers\RDPWD.sys
20:53:37.0012 3156  RDPWD - ok
20:53:37.0072 3156  [ 263AF18AF0F3DB99F574C95F284CCEC9 ] RDSessMgr      C:\WINDOWS\system32\sessmgr.exe
20:53:37.0252 3156  RDSessMgr - ok
20:53:37.0353 3156  [ ED761D453856F795A7FE056E42C36365 ] redbook        C:\WINDOWS\system32\DRIVERS\redbook.sys
20:53:37.0553 3156  redbook - ok
20:53:37.0743 3156  [ 0E97EC96D6942CEEC2D188CC2EB69A01 ] RemoteAccess    C:\WINDOWS\System32\mprdim.dll
20:53:37.0913 3156  RemoteAccess - ok
20:53:37.0974 3156  [ 2A02E21867497DF20B8FC95631395169 ] RpcLocator      C:\WINDOWS\System32\locator.exe
20:53:38.0144 3156  RpcLocator - ok
20:53:38.0284 3156  [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] RpcSs          C:\WINDOWS\system32\rpcss.dll
20:53:38.0364 3156  RpcSs - ok
20:53:38.0424 3156  [ 4BDD71B4B521521499DFD14735C4F398 ] RSVP            C:\WINDOWS\System32\rsvp.exe
20:53:38.0655 3156  RSVP - ok
20:53:38.0745 3156  [ 2EF9C0DC26B30B2318B1FC3FAA1F0AE7 ] rtl8139        C:\WINDOWS\system32\DRIVERS\R8139n51.SYS
20:53:38.0785 3156  rtl8139 - ok
20:53:38.0805 3156  [ AFB8261B56CBA0D86AEB6DF682AF9785 ] SamSs          C:\WINDOWS\system32\lsass.exe
20:53:38.0995 3156  SamSs - ok
20:53:39.0065 3156  [ DCEC079FAD95D36C8DD5CB6D779DFE32 ] SCardSvr        C:\WINDOWS\System32\SCardSvr.exe
20:53:39.0225 3156  SCardSvr - ok
20:53:39.0376 3156  [ A050194A44D7FA8D7186ED2F4E8367AE ] Schedule        C:\WINDOWS\system32\schedsvc.dll
20:53:39.0546 3156  Schedule - ok
20:53:39.0756 3156  [ 0F4A80438E7286A0E623582F5F2395BD ] SearchAnonymizer C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizerHelper.exe
20:53:39.0776 3156  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - warning
20:53:39.0776 3156  SearchAnonymizer - detected UnsignedFile.Multi.Generic (1)
20:53:39.0826 3156  [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv          C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:53:40.0006 3156  Secdrv - ok
20:53:40.0167 3156  [ BEE4CFD1D48C23B44CF4B974B0B79B2B ] seclogon        C:\WINDOWS\System32\seclogon.dll
20:53:40.0407 3156  seclogon - ok
20:53:40.0487 3156  [ 2AAC9B6ED9EDDFFB721D6452E34D67E3 ] SENS            C:\WINDOWS\system32\sens.dll
20:53:40.0647 3156  SENS - ok
20:53:40.0768 3156  [ CF24EB4F0412C82BCD1F4F35A025E31D ] Serial          C:\WINDOWS\system32\drivers\Serial.sys
20:53:40.0918 3156  Serial - ok
20:53:41.0038 3156  [ AAC24421FC74D612A7169C4D4A61B48C ] ServiceLayer    C:\Programme\PC Connectivity Solution\ServiceLayer.exe
20:53:41.0068 3156  ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
20:53:41.0068 3156  ServiceLayer - detected UnsignedFile.Multi.Generic (1)
20:53:41.0128 3156  [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy        C:\WINDOWS\system32\drivers\Sfloppy.sys
20:53:41.0328 3156  Sfloppy - ok
20:53:41.0459 3156  [ CAD058D5F8B889A87CA3EB3CF624DCEF ] SharedAccess    C:\WINDOWS\System32\ipnathlp.dll
20:53:41.0689 3156  SharedAccess - ok
20:53:41.0769 3156  [ 2DB7D303C36DDD055215052F118E8E75 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
20:53:41.0799 3156  ShellHWDetection - ok
20:53:41.0819 3156  Simbad - ok
20:53:41.0969 3156  [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate    C:\Programme\Skype\Updater\Updater.exe
20:53:41.0999 3156  SkypeUpdate - ok
20:53:42.0049 3156  [ 707647A1AA0EDB6CBEF61B0C75C28ED3 ] SMCIRDA        C:\WINDOWS\system32\DRIVERS\smcirda.sys
20:53:42.0099 3156  SMCIRDA - ok
20:53:42.0130 3156  Sparrow - ok
20:53:42.0180 3156  [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter        C:\WINDOWS\system32\drivers\splitter.sys
20:53:42.0420 3156  splitter - ok
20:53:42.0450 3156  [ 60784F891563FB1B767F70117FC2428F ] Spooler        C:\WINDOWS\system32\spoolsv.exe
20:53:42.0500 3156  Spooler - ok
20:53:42.0530 3156  [ 50FA898F8C032796D3B1B9951BB5A90F ] sr              C:\WINDOWS\system32\DRIVERS\sr.sys
20:53:42.0670 3156  sr - ok
20:53:42.0730 3156  [ FE77A85495065F3AD59C5C65B6C54182 ] srservice      C:\WINDOWS\System32\srsvc.dll
20:53:42.0891 3156  srservice - ok
20:53:42.0931 3156  [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv            C:\WINDOWS\system32\DRIVERS\srv.sys
20:53:43.0021 3156  Srv - ok
20:53:43.0101 3156  [ 4DF5B05DFAEC29E13E1ED6F6EE12C500 ] SSDPSRV        C:\WINDOWS\System32\ssdpsrv.dll
20:53:43.0271 3156  SSDPSRV - ok
20:53:43.0351 3156  [ BC2C5985611C5356B24AEB370953DED9 ] stisvc          C:\WINDOWS\system32\wiaservc.dll
20:53:43.0582 3156  stisvc - ok
20:53:43.0612 3156  [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum          C:\WINDOWS\system32\DRIVERS\swenum.sys
20:53:43.0772 3156  swenum - ok
20:53:43.0802 3156  [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi          C:\WINDOWS\system32\drivers\swmidi.sys
20:53:43.0972 3156  swmidi - ok
20:53:44.0032 3156  SwPrv - ok
20:53:44.0062 3156  symc810 - ok
20:53:44.0072 3156  symc8xx - ok
20:53:44.0092 3156  sym_hi - ok
20:53:44.0112 3156  sym_u3 - ok
20:53:44.0142 3156  [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio        C:\WINDOWS\system32\drivers\sysaudio.sys
20:53:44.0313 3156  sysaudio - ok
20:53:44.0443 3156  [ 2903FFFA2523926D6219428040DCE6B9 ] SysmonLog      C:\WINDOWS\system32\smlogsvc.exe
20:53:44.0613 3156  SysmonLog - ok
20:53:44.0763 3156  [ 05903CAC4B98908D55EA5774775B382E ] TapiSrv        C:\WINDOWS\System32\tapisrv.dll
20:53:44.0944 3156  TapiSrv - ok
20:53:45.0054 3156  [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip          C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:53:45.0124 3156  Tcpip - ok
20:53:45.0154 3156  [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE          C:\WINDOWS\system32\drivers\TDPIPE.sys
20:53:45.0304 3156  TDPIPE - ok
20:53:45.0324 3156  [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP          C:\WINDOWS\system32\drivers\TDTCP.sys
20:53:45.0494 3156  TDTCP - ok
20:53:45.0524 3156  [ 88155247177638048422893737429D9E ] TermDD          C:\WINDOWS\system32\DRIVERS\termdd.sys
20:53:45.0665 3156  TermDD - ok
20:53:45.0755 3156  [ B7DE02C863D8F5A005A7BF375375A6A4 ] TermService    C:\WINDOWS\System32\termsrv.dll
20:53:45.0925 3156  TermService - ok
20:53:46.0055 3156  [ 2DB7D303C36DDD055215052F118E8E75 ] Themes          C:\WINDOWS\System32\shsvcs.dll
20:53:46.0075 3156  Themes - ok
20:53:46.0175 3156  [ EFEF22B9577E5051057FDE1AE381B50C ] TomTomHOMEService C:\Programme\TomTom HOME 2\TomTomHOMEService.exe
20:53:46.0195 3156  TomTomHOMEService - ok
20:53:46.0205 3156  TosIde - ok
20:53:46.0275 3156  [ 15FB67EB022A74B30E278D19B03DA3B4 ] TPkd            C:\WINDOWS\system32\drivers\TPkd.sys
20:53:46.0295 3156  TPkd ( UnsignedFile.Multi.Generic ) - warning
20:53:46.0295 3156  TPkd - detected UnsignedFile.Multi.Generic (1)
20:53:46.0366 3156  [ 626504572B175867F30F3215C04B3E2F ] TrkWks          C:\WINDOWS\system32\trkwks.dll
20:53:46.0576 3156  TrkWks - ok
20:53:46.0636 3156  [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs            C:\WINDOWS\system32\drivers\Udfs.sys
20:53:46.0786 3156  Udfs - ok
20:53:46.0806 3156  ultra - ok
20:53:46.0946 3156  [ AB0A7CA90D9E3D6A193905DC1715DED0 ] UMWdf          C:\WINDOWS\System32\wdfmgr.exe
20:53:46.0986 3156  UMWdf - ok
20:53:47.0037 3156  [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update          C:\WINDOWS\system32\DRIVERS\update.sys
20:53:47.0227 3156  Update - ok
20:53:47.0337 3156  [ 1DFD8975D8C89214B98D9387C1125B49 ] upnphost        C:\WINDOWS\System32\upnphost.dll
20:53:47.0537 3156  upnphost - ok
20:53:47.0647 3156  [ 9B11E6118958E63E1FEF129466E2BDA7 ] UPS            C:\WINDOWS\System32\ups.exe
20:53:47.0808 3156  UPS - ok
20:53:47.0948 3156  [ E919708DB44ED8543A7C017953148330 ] usbaudio        C:\WINDOWS\system32\drivers\usbaudio.sys
20:53:48.0118 3156  usbaudio - ok
20:53:48.0148 3156  [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp        C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:53:48.0308 3156  usbccgp - ok
20:53:48.0338 3156  [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci        C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:53:48.0489 3156  usbehci - ok
20:53:48.0529 3156  [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub          C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:53:48.0689 3156  usbhub - ok
20:53:48.0729 3156  [ A717C8721046828520C9EDF31288FC00 ] usbprint        C:\WINDOWS\system32\DRIVERS\usbprint.sys
20:53:48.0889 3156  usbprint - ok
20:53:48.0939 3156  [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan        C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:53:49.0110 3156  usbscan - ok
20:53:49.0130 3156  [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR        C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:53:49.0270 3156  USBSTOR - ok
20:53:49.0300 3156  [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci        C:\WINDOWS\system32\DRIVERS\usbuhci.sys
20:53:49.0460 3156  usbuhci - ok
20:53:49.0520 3156  [ C90055BD2BB41443462EA715E0876B8D ] V0260VID        C:\WINDOWS\system32\DRIVERS\V0260Vid.sys
20:53:49.0570 3156  V0260VID - ok
20:53:49.0610 3156  [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave        C:\WINDOWS\System32\drivers\vga.sys
20:53:49.0770 3156  VgaSave - ok
20:53:49.0781 3156  ViaIde - ok
20:53:49.0811 3156  [ A5A712F4E880874A477AF790B5186E1D ] VolSnap        C:\WINDOWS\system32\drivers\VolSnap.sys
20:53:49.0951 3156  VolSnap - ok
20:53:50.0031 3156  [ 68F106273BE29E7B7EF8266977268E78 ] VSS            C:\WINDOWS\System32\vssvc.exe
20:53:50.0191 3156  VSS - ok
20:53:50.0271 3156  [ 7B353059E665F8B7AD2BBEAEF597CF45 ] W32Time        C:\WINDOWS\System32\w32time.dll
20:53:50.0451 3156  W32Time - ok
20:53:50.0542 3156  [ 677AD85E3058C821F5A73CDF7E5B5478 ] w70n51          C:\WINDOWS\system32\DRIVERS\w70n51.sys
20:53:50.0672 3156  w70n51 - ok
20:53:50.0702 3156  [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp          C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:53:50.0872 3156  Wanarp - ok
20:53:50.0892 3156  WDICA - ok
20:53:50.0942 3156  [ 6768ACF64B18196494413695F0C3A00F ] wdmaud          C:\WINDOWS\system32\drivers\wdmaud.sys
20:53:51.0112 3156  wdmaud - ok
20:53:51.0183 3156  [ 81727C9873E3905A2FFC1EBD07265002 ] WebClient      C:\WINDOWS\System32\webclnt.dll
20:53:51.0333 3156  WebClient - ok
20:53:51.0413 3156  [ 6F3F3973D97714CC5F906A19FE883729 ] winmgmt        C:\WINDOWS\system32\wbem\WMIsvc.dll
20:53:51.0593 3156  winmgmt - ok
20:53:51.0693 3156  [ 140EF97B64F560FD78643CAE2CDAD838 ] WmdmPmSN        C:\WINDOWS\system32\mspmsnsv.dll
20:53:51.0733 3156  WmdmPmSN - ok
20:53:51.0773 3156  [ 93908111BA57A6E60EC2FA2DE202105C ] WmiApSrv        C:\WINDOWS\System32\wbem\wmiapsrv.exe
20:53:51.0944 3156  WmiApSrv - ok
20:53:51.0994 3156  [ 300B3E84FAF1A5C1F791C159BA28035D ] wscsvc          C:\WINDOWS\system32\wscsvc.dll
20:53:52.0154 3156  wscsvc - ok
20:53:52.0204 3156  [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC        C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
20:53:52.0374 3156  WSTCODEC - ok
20:53:52.0474 3156  [ 7B4FE05202AA6BF9F4DFD0E6A0D8A085 ] wuauserv        C:\WINDOWS\system32\wuauserv.dll
20:53:52.0645 3156  wuauserv - ok
20:53:52.0735 3156  [ C4F109C005F6725162D2D12CA751E4A7 ] WZCSVC          C:\WINDOWS\System32\wzcsvc.dll
20:53:52.0955 3156  WZCSVC - ok
20:53:53.0005 3156  [ 0ADA34871A2E1CD2CAAFED1237A47750 ] xmlprov        C:\WINDOWS\System32\xmlprov.dll
20:53:53.0185 3156  xmlprov - ok
20:53:53.0256 3156  [ 4FF040FE3099D578131CF62E3B822E0D ] {6080A529-897E-4629-A488-ABA0C29B635E} C:\WINDOWS\system32\drivers\ialmsbw.sys
20:53:53.0296 3156  {6080A529-897E-4629-A488-ABA0C29B635E} - ok
20:53:53.0306 3156  [ 9623FE5A34823EF8BE6BA55CB52222E8 ] {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} C:\WINDOWS\system32\drivers\ialmkchw.sys
20:53:53.0356 3156  {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
20:53:53.0376 3156  [ 4ACDBB1E48986863B34E696B479F7455 ] {E2B953A6-195A-44F9-9BA3-3D5F4E32BB55} C:\WINDOWS\system32\drivers\wA301a.sys
20:53:53.0416 3156  {E2B953A6-195A-44F9-9BA3-3D5F4E32BB55} - ok
20:53:53.0416 3156  ================ Scan global ===============================
20:53:53.0536 3156  [ 2C60091CA5F67C3032EAB3B30390C27F ] C:\WINDOWS\system32\basesrv.dll
20:53:53.0636 3156  [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll
20:53:53.0696 3156  [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll
20:53:53.0736 3156  [ A3EDBE9053889FB24AB22492472B39DC ] C:\WINDOWS\system32\services.exe
20:53:53.0746 3156  [Global] - ok
20:53:53.0746 3156  ================ Scan MBR ==================================
20:53:53.0766 3156  [ 671B81004FDD1588FA9ED1331C9CECA9 ] \Device\Harddisk0\DR0
20:53:54.0087 3156  \Device\Harddisk0\DR0 - ok
20:53:54.0117 3156  [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR4
20:53:54.0337 3156  \Device\Harddisk1\DR4 - ok
20:53:57.0472 3156  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk2\DR6
20:53:57.0962 3156  \Device\Harddisk2\DR6 - ok
20:53:57.0962 3156  ================ Scan VBR ==================================
20:53:58.0002 3156  [ 77B39F30F0D6B363DA6048B9D72F35B7 ] \Device\Harddisk0\DR0\Partition1
20:53:58.0002 3156  \Device\Harddisk0\DR0\Partition1 - ok
20:53:58.0042 3156  [ 64DCC1CB2D04F7BE2626705D075BED62 ] \Device\Harddisk0\DR0\Partition2
20:53:58.0042 3156  \Device\Harddisk0\DR0\Partition2 - ok
20:53:58.0062 3156  [ B140085EEC6B2377E4D2B3B56FE57AC5 ] \Device\Harddisk1\DR4\Partition1
20:53:58.0072 3156  \Device\Harddisk1\DR4\Partition1 - ok
20:53:58.0153 3156  [ EF25E569139DE39A6C0A5B9A20C4DEFB ] \Device\Harddisk2\DR6\Partition1
20:53:58.0163 3156  \Device\Harddisk2\DR6\Partition1 - ok
20:53:58.0173 3156  ============================================================
20:53:58.0173 3156  Scan finished
20:53:58.0173 3156  ============================================================
20:53:58.0313 0524  Detected object count: 6
20:53:58.0313 0524  Actual detected object count: 6
20:56:22.0841 0524  BTWUSB ( UnsignedFile.Multi.Generic ) - skipped by user
20:56:22.0841 0524  BTWUSB ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:56:22.0851 0524  DKbFltr ( UnsignedFile.Multi.Generic ) - skipped by user
20:56:22.0851 0524  DKbFltr ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:56:22.0851 0524  NTIDrvr ( UnsignedFile.Multi.Generic ) - skipped by user
20:56:22.0851 0524  NTIDrvr ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:56:22.0851 0524  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - skipped by user
20:56:22.0851 0524  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:56:22.0851 0524  ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
20:56:22.0851 0524  ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:56:22.0861 0524  TPkd ( UnsignedFile.Multi.Generic ) - skipped by user
20:56:22.0861 0524  TPkd ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 16.10.2012 11:34

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

perry85 16.10.2012 19:52

ist das normal das ComboFix über zwei stunden dauert, oder hat es sich aufgehängt?!

nach ein paar stunden tat sich dann gar nichts mehr.
Hab es dann noch mal versucht so wie beschieben, Maus und Tastatur nicht benutzt, aber das selbe.
hab es mal was beobachtet weil ich in der nähe war, der cursor hörte schon nach ca. 10 min auf zu blinken.
was kann ich tun, oder hab ich was falsch gemacht oder übersehen?!

cosinus 17.10.2012 13:50

Starte Windows neu, lösch die alte combofix.exe, lade CF neu runter und probier es bitte nochmal.

perry85 19.10.2012 10:11

ich bekomm es einfach nicht hin :stirn:

combofix kommt nur bis zum durchsuchen von Infizierungen auf dem PC.
egal ob ich den pc 1 stunde oder 8 stunden in ruhe lasse.

ist die combofix.exe noch wo anders zu löschen als auf dem desktop bzw. da wo hin ich sie runtergeladen hab? ich sehe immer nur das ComboFix-Piktogramm ohne exe!

hab ich an irgendwas nicht gedacht es auszuschalten?! Anti-Virus-, malwarebytes und Firewall ist aus.

cosinus 19.10.2012 11:06

Letzter Versuch bevor wir CF überspringen: Lade Combofix.exe nochmal neu runter, starte im abgesicherten Modus mit Netzwerktreibern und lass CF da nochmal werkeln

perry85 20.10.2012 18:22

wie mach ich denn das im abgesicherten Modus mit Netzwerktreibern starten?

cosinus 21.10.2012 12:30

Sowas hättest du in wenigen Sekunden selbst mit Google gefunden aber hier hast es:


Abgesicherter Modus zur Bereinigung
  • Windows mit F8-Taste beim Start in den abgesicherten Modus bringen.
  • Starte den Rechner in den abgesicherten Modus mit Netzwerktreibern:

    Windows im abgesicherten Modusstarten

perry85 22.10.2012 14:16

leider macht combofix da auch nicht mehr.

cosinus 22.10.2012 14:46

Dann lassen wir CF sein

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

perry85 22.10.2012 15:37

[code] GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-10-22 16:34:35
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 IC25N030ATMR04-0 rev.MOAOAD0A
Running: 0htc1k25.exe; Driver: C:\DOKUME~1\MR\LOKALE~1\Temp\pgxyrfoc.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\Fastfat \Fat                                                            fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout  15
Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota    10000
Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler                  yes
Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk                 
Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout  90
Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota    10000

---- EOF - GMER 1.0.15 ----

--- --- ---

Code:

OSAM Logfile:

       
Code:

       
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 16:59:48 on 22.10.2012

OS: Windows XP Home Edition Service Pack 3 (Build 2600)
Default Browser: Mozilla Corporation Firefox 16.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"AppleSoftwareUpdate.job" - "Apple Inc." - C:\Programme\Apple Software Update\SoftwareUpdate.exe
"FacebookUpdateTaskUserS-1-5-21-1582333133-1907411925-173008773-1005Core1cd62cec2a47ee0.job" - "Facebook Inc." - C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Facebook\Update\FacebookUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
"infocardcpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\infocardcpl.cpl
"JAVACPL.CPL" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\JAVACPL.CPL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"NokiaConnectionManager" - "Nokia" - C:\PROGRA~1\Nokia\NOKIAP~1\CONNEC~1.CPL
"QuickTime" - "Apple Inc." - C:\Programme\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys  (File not found)
"Dritek HotKey Keyboard Filter Driver" (DKbFltr) - "Dritek System Inc." - C:\WINDOWS\System32\Drivers\DKbFltr.sys
"i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys  (File not found)
"lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\WINDOWS\system32\drivers\mbam.sys
"PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys  (File not found)
"PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys  (File not found)
"PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys  (File not found)
"PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys  (File not found)
"PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys  (File not found)
"pgxyrfoc" (pgxyrfoc) - ? - C:\DOKUME~1\MR\LOKALE~1\Temp\pgxyrfoc.sys  (Hidden registry entry, rootkit activity | File not found)
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\WINDOWS\System32\Drivers\PxHelp20.sys
"TPkd" (TPkd) - "PACE Anti-Piracy, Inc." - C:\WINDOWS\system32\drivers\TPkd.sys
"Upper Class Filter Driver" (NTIDrvr) - "NewTech Infosystems, Inc." - C:\WINDOWS\System32\DRIVERS\NTIDrvr.sys
"WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys  (File not found)
"WIDCOMM USB Bluetooth Driver" (BTWUSB) - ? - C:\WINDOWS\System32\Drivers\btwusb.sys

[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{807553E5-5146-11D5-A672-00B0D022E945} "text/xml" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? -   (File not found | COM-object registry key not found)
{79E48320-C6B5-49F1-992B-571D53586885} "FineReader11.FRContextMenu.1" - "ABBYY." - C:\Programme\ABBYY FineReader 11\FRIntegration.dll
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -   (File not found | COM-object registry key not found)
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? -   (File not found | COM-object registry key not found)
{32683183-48a0-441b-a342-7c2a440a9478} "Media Band" - ? -   (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Programme\Microsoft Office\OFFICE11\msohev.dll
{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} "Nokia Phone Browser" - "Nokia" - C:\Programme\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? -   (File not found | COM-object registry key not found)
{e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Programme\WinRAR\rarext.dll

[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{32683183-48a0-441b-a342-7c2a440a9478} "{32683183-48a0-441b-a342-7c2a440a9478}" - ? -   (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBarLayout" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Programme\Java\jre1.6.0_20\bin\npjpi160_20.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_22.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_22.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_22.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"ICQ7.6" - "ICQ, LLC." - C:\Programme\ICQ7.6\ICQ.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Recherchieren" - "Microsoft Corporation" - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} "Easy-WebPrint" - ? - C:\Programme\Canon\Easy-WebPrint\Toolband.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jp2ssv.dll
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[Logon]
-----( %AllUsersProfile%\Startmenü\Programme\Autostart )-----
"Adobe Gamma Loader.lnk" - "Adobe Systems, Inc." - C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe  (Shortcut exists | File exists)
"DESKTOP.INI" - ? - C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\DESKTOP.INI
-----( %UserProfile%\Startmenü\Programme\Autostart )-----
"DESKTOP.INI" - ? - C:\Dokumente und Einstellungen\MR\Startmenü\Programme\Autostart\DESKTOP.INI
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Facebook Update" - "Facebook Inc." - "C:\Dokumente und Einstellungen\MR\Lokale Einstellungen\Anwendungsdaten\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Bonus.SSR.FR11" - "ABBYY." - "C:\Programme\ABBYY FineReader 11\Bonus.ScreenshotReader.exe" /autorun
"LaunchApp" - "Acer Inc." - Alaunch
"Ocs_SM" - "OCS" - C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizer.exe
"QuickTime Task" - "Apple Inc." - "C:\Programme\QuickTime\qttask.exe" -atboottime

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\WINDOWS\system32\mdimon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
"@C:\Programme\Nero\Update\NASvc.exe,-200" (NAUpdate) - "Nero AG" - C:\Programme\Nero\Update\NASvc.exe
"ABBYY FineReader 11 PE Licensing Service" (ABBYY.Licensing.FineReader.Professional.11.0) - "ABBYY" - C:\Programme\ABBYY FineReader 11\NetworkLicenseServer.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"Anwendungsverwaltung" (AppMgmt) - ? - C:\WINDOWS\System32\appmgmts.dll  (File not found)
"ASP.NET-Zustandsdienst" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
"Dienst "Bonjour"" (Bonjour Service) - ? - C:\Programme\Bonjour\mDNSResponder.exe  (File not found)
"Java Quick Starter" (JavaQuickStarterService) - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jqs.exe
"MBAMScheduler" (MBAMScheduler) - "Malwarebytes Corporation" - C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE
"PEVSystemStart" (PEVSystemStart) - ? - C:\ComboFix\pev.3XE  (File found, but it contains no detailed information)
"SearchAnonymizer" (SearchAnonymizer) - ? - C:\Dokumente und Einstellungen\MR\Anwendungsdaten\OCS\SM\SearchAnonymizerHelper.exe
"ServiceLayer" (ServiceLayer) - "Nokia." - C:\Programme\PC Connectivity Solution\ServiceLayer.exe
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Programme\Skype\Updater\Updater.exe
"TomTomHOMEService" (TomTomHOMEService) - "TomTom" - C:\Programme\TomTom HOME 2\TomTomHOMEService.exe
"Windows CardSpace" (idsvc) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
"Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe

[Winlogon]
-----( HKCU\Control Panel\IOProcs )-----
"MVB" - ? - mvfs32.dll  (File not found)
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions )-----
{c6dc5466-785a-11d2-84d0-00c04fb169f7} "Softwareinstallation" - ? - appmgmts.dll  (File not found)

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - ? - C:\Programme\Bonjour\mdnsNSP.dll  (File not found)

===[ Logfile end ]=========================================[ Logfile end ]===


--- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-22 17:06:26
-----------------------------
17:06:26.166    OS Version: Windows 5.1.2600 Service Pack 3
17:06:26.166    Number of processors: 1 586 0x905
17:06:26.166    ComputerName: ACER-5J0JDWIJ8Z  UserName: MR
17:06:27.077    Initialize success
17:10:57.977    AVAST engine defs: 12102200
17:11:20.910    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
17:11:20.910    Disk 0 Vendor: IC25N030ATMR04-0 MOAOAD0A Size: 28615MB BusType: 3
17:11:20.930    Disk 0 MBR read successfully
17:11:20.930    Disk 0 MBR scan
17:11:21.050    Disk 0 unknown MBR code
17:11:21.070    Disk 0 Partition 1 80 (A) 0C    FAT32 LBA MSWIN4.1    18606 MB offset 63
17:11:21.100    Disk 0 Partition 2 00    0C    FAT32 LBA MSWIN4.1    10001 MB offset 38106180
17:11:21.120    Disk 0 Partition 3 00    1E Hidd FAT16 LBA MSWIN4.1        7 MB offset 58589055
17:11:21.130    Disk 0 scanning sectors +58605120
17:11:21.330    Disk 0 scanning C:\WINDOWS\system32\drivers
17:11:33.879    Service scanning
17:12:04.052    Modules scanning
17:12:13.706    Disk 0 trace - called modules:
17:12:13.736    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
17:12:13.736    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x863929c0]
17:12:13.736    3 CLASSPNP.SYS[f75b8fd7] -> nt!IofCallDriver -> \Device\00000071[0x86393030]
17:12:13.746    5 ACPI.sys[f750e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x86372d98]
17:12:14.257    AVAST engine scan C:\WINDOWS
17:12:29.979    AVAST engine scan C:\WINDOWS\system32
17:15:14.265    AVAST engine scan C:\WINDOWS\system32\drivers
17:15:29.778    AVAST engine scan C:\Dokumente und Einstellungen\MR
17:18:07.785    AVAST engine scan C:\Dokumente und Einstellungen\All Users
17:18:20.593    Scan finished successfully
17:21:48.462    Disk 0 MBR has been saved successfully to "C:\Dokumente und Einstellungen\MR\Desktop\MBR.dat"
17:21:48.462    The log file has been saved successfully to "C:\Dokumente und Einstellungen\MR\Desktop\aswMBR.txt"


cosinus 29.10.2012 07:54

Code:

Disk 0 Partition 3 00    1E Hidd FAT16 LBA MSWIN4.1        7 MB offset 58589055
Diese versteckte Partition gefällt mir so noch garnicht.

Live-System PartedMagic / GParted
  1. Lade Dir ISO-Image von PartedMagic
  2. Brenn es per Imagebrennfunktion auf CD, geht zB mit ImgBurn unter Windows
  3. Boote von der gebrannten CD, im Bootmenü von Option 1 starten und warten bis der Linux-Desktop oben ist
  4. Du müsstest ein Symbol PartitionEditor auf dem Desktop finden, das doppelklicken
  5. Wenn das Tool die Partitionen aufgelistet hat, bitte einen Screenshot mit Hilfe der Taste DRUCK auf der Tastatur erstellen, diesen Screenshot hier posten (idR hast du einen Internetzugang mit PartedMagic, wenn nicht einfach den Screenshot auf einem Stick abspeichern und unter Windows hier posten)


Alle Zeitangaben in WEZ +1. Es ist jetzt 13:02 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131