Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Trojaner:Backdoor.Win32.SdBot.nci von Kaspersky gefunden. (https://www.trojaner-board.de/100883-trojaner-backdoor-win32-sdbot-nci-kaspersky-gefunden.html)

Maurice 29.06.2011 17:34

Trojaner:Backdoor.Win32.SdBot.nci von Kaspersky gefunden.
 
Guten Abend,
ich habe mir einen Trojaner wie der Thread Name schon sagt eingefangen. Habe aber keine große Ahnung von so etwas und wollte mal fragen ob ihr mir helfen könntet. Ein Freund hat mir gesagt das ich mal das alles durchlaufen lassen soll und es dann hier Posten soll.
http://www.trojaner-board.de/69886-a...-beachten.html

OTL.txt

OTL logfile created on: 29.06.2011 17:19:28 - Run 1
OTL by OldTimer - Version 3.2.24.2 Folder = C:\Users\Maurice\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

3,25 Gb Total Physical Memory | 2,13 Gb Available Physical Memory | 65,63% Memory free
17,90 Gb Paging File | 16,11 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): c:\pagefile.sys 15000 50000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 1376,16 Gb Total Space | 1289,53 Gb Free Space | 93,70% Space Free | Partition Type: NTFS
Drive D: | 20,00 Gb Total Space | 11,89 Gb Free Space | 59,43% Space Free | Partition Type: NTFS

Computer Name: MAURICE-PC | User Name: Maurice | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011.06.29 13:42:42 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Maurice\Desktop\OTL.exe
PRC - [2011.04.01 05:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) -- C:\Programme\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
PRC - [2011.03.22 23:56:40 | 000,687,448 | ---- | M] () -- C:\Programme\Common Files\logishrd\LQCVFX\COCIManager.exe
PRC - [2011.03.01 23:14:08 | 000,190,808 | ---- | M] (Logitech Inc.) -- C:\Programme\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2011.03.01 23:13:44 | 000,203,096 | ---- | M] () -- C:\Programme\Logitech\LWS\Webcam Software\CameraHelperShell.exe
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011.01.27 18:57:48 | 000,585,728 | ---- | M] () -- C:\Programme\HTC\HTC Sync 3.0\htcUPCTLoader.exe
PRC - [2011.01.13 04:01:28 | 006,129,496 | ---- | M] (Logitech Inc.) -- C:\Programme\Logitech\Vid HD\Vid.exe
PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.11.20 14:17:41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2010.11.13 00:40:17 | 000,274,608 | ---- | M] (RealNetworks, Inc.) -- C:\Programme\Real\RealPlayer\Update\realsched.exe
PRC - [2010.09.16 14:06:22 | 000,080,896 | ---- | M] () -- C:\Programme\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2010.05.07 12:39:36 | 000,344,736 | ---- | M] (Kaspersky Lab ZAO) -- C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
PRC - [2010.04.07 04:12:38 | 000,372,736 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2010.04.07 04:12:04 | 000,172,032 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2009.08.18 11:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009.08.18 11:29:22 | 000,183,152 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009.06.03 21:59:02 | 000,103,720 | ---- | M] (CyberLink) -- C:\Programme\CyberLink\Power2Go\CLMLSvc.exe
PRC - [2009.05.19 12:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009.02.26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2009.02.03 15:53:00 | 001,155,072 | ---- | M] (MAGIX AG) -- C:\Programme\Common Files\MAGIX Services\Database\bin\FABS.exe
PRC - [2007.07.24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- c:\Programme\Common Files\Protexis\License Service\PsiService_2.exe


========== Modules (SafeList) ==========

MOD - [2011.06.29 13:42:42 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Maurice\Desktop\OTL.exe
MOD - [2010.11.20 13:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011.04.01 05:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Programme\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2010.09.16 14:06:22 | 000,080,896 | ---- | M] () [Auto | Running] -- C:\Programme\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2010.05.07 12:39:36 | 000,344,736 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe -- (AVP)
SRV - [2010.04.07 04:12:04 | 000,172,032 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2009.12.16 19:26:00 | 003,453,712 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.02.03 15:53:00 | 001,155,072 | ---- | M] (MAGIX AG) [Unknown | Running] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2008.08.07 11:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2007.07.24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)


========== Driver Services (SafeList) ==========

DRV - [2011.04.01 05:11:10 | 004,333,280 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 200(UVC)
DRV - [2011.04.01 05:09:48 | 000,291,424 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS)
DRV - [2010.11.25 07:59:16 | 000,603,240 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTL8192su.sys -- (RTL8192su)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.07.27 08:12:26 | 000,114,784 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvpopflt.sys -- (lvpopflt)
DRV - [2010.06.23 10:24:56 | 000,023,040 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\htcnprot.sys -- (htcnprot)
DRV - [2010.05.07 18:43:30 | 000,025,824 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2010.05.07 12:28:06 | 000,475,224 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\System32\drivers\klif.sys -- (KLIF)
DRV - [2010.05.07 00:19:06 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\kl2.sys -- (kl2)
DRV - [2010.05.07 00:19:02 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\kl1.sys -- (kl1)
DRV - [2010.04.22 19:07:34 | 000,022,104 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\klim6.sys -- (KLIM6)
DRV - [2010.04.12 17:05:01 | 000,271,360 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2010.04.12 17:04:56 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2010.04.07 04:43:20 | 005,430,272 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2010.04.07 03:23:10 | 000,157,184 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2010.03.09 12:21:26 | 000,107,024 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2009.12.22 02:26:36 | 000,030,392 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\usbfilter.sys -- (usbfilter)
DRV - [2009.11.02 20:27:16 | 000,019,984 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009.10.26 08:54:24 | 000,025,088 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009.07.07 23:48:14 | 000,011,832 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\amdide.sys -- (amdide)
DRV - [2009.05.05 11:00:28 | 000,014,392 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://medion.msn.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Elf 1 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2856415&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.mtb-news.de/news/2011/05/27/sonntag-29-mai-action-heroes-20h-live-bei-mtb-news-de/"
FF - prefs.js..extensions.enabledItems: {4176DFF4-4698-11DE-BEEB-45DA55D89593}:0.8.12
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: KavAntiBanner@Kaspersky.ru:11.0.0.232
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.0.232
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5.8
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: piclens@cooliris.com:1.12.2.44172
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.11.13 00:41:10 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.06.22 00:36:29 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.06.16 14:40:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.06.22 00:36:29 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.06.16 14:40:45 | 000,000,000 | ---D | M]

[2010.03.20 13:23:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maurice\AppData\Roaming\mozilla\Extensions
[2011.06.22 06:46:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maurice\AppData\Roaming\mozilla\Firefox\Profiles\3ctj3o27.default\extensions
[2011.01.04 19:14:06 | 000,000,000 | ---D | M] (Speed Dial) -- C:\Users\Maurice\AppData\Roaming\mozilla\Firefox\Profiles\3ctj3o27.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010.05.25 16:30:31 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Maurice\AppData\Roaming\mozilla\Firefox\Profiles\3ctj3o27.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.06.22 06:46:00 | 000,000,000 | ---D | M] (Cooliris) -- C:\Users\Maurice\AppData\Roaming\mozilla\Firefox\Profiles\3ctj3o27.default\extensions\piclens@cooliris.com
[2011.06.10 22:22:25 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.03.20 13:22:34 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Programme\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.06.10 22:22:25 | 000,000,000 | ---D | M] (Skype extension) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010.06.13 14:10:30 | 000,000,000 | ---D | M] (Kaspersky Anti-Banner) -- C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru
[2010.06.13 14:10:30 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
File not found (No name found) --
() (No name found) -- C:\USERS\MAURICE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CTJ3O27.DEFAULT\EXTENSIONS\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.XPI
() (No name found) -- C:\USERS\MAURICE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CTJ3O27.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011.06.22 00:36:28 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.05.06 13:03:27 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.05.06 13:03:27 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.05.06 13:03:27 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.05.06 13:03:27 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.05.06 13:03:27 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.05.06 13:03:27 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml

O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programme\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID-Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [EA Core] File not found
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files\Logitech\Vid HD\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [msnmsgr] File not found
O4 - HKCU..\Run: [Pando Media Booster] File not found
O4 - Startup: C:\Users\Maurice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Maurice\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - File not found
O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - File not found
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll) - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\mzvkbd3.dll (Kaspersky Lab ZAO)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll) - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\kloehk.dll (Kaspersky Lab ZAO)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011.06.29 13:42:39 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Users\Maurice\Desktop\OTL.exe
[2011.06.20 13:23:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC Sync
[2011.06.15 23:01:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7.5
[2011.06.12 23:39:03 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ7.5
[2011.06.10 22:22:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype Extras
[2011.06.10 22:21:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011.06.10 22:21:55 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2011.06.09 13:40:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.06.09 13:38:28 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.06.09 13:38:27 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2 C:\Users\Maurice\Documents\*.tmp files -> C:\Users\Maurice\Documents\*.tmp -> ]
[1 C:\Users\Maurice\Desktop\*.tmp files -> C:\Users\Maurice\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011.06.29 17:16:48 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2011.06.29 17:16:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.06.29 17:16:42 | 2615,910,400 | -HS- | M] () -- C:\hiberfil.sys
[2011.06.29 13:42:42 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Maurice\Desktop\OTL.exe
[2011.06.29 13:41:22 | 000,009,888 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.06.29 13:41:22 | 000,009,888 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.06.29 13:29:36 | 000,000,000 | ---- | M] () -- C:\Users\Maurice\defogger_reenable
[2011.06.29 13:28:44 | 000,050,477 | ---- | M] () -- C:\Users\Maurice\Desktop\Defogger.exe
[2011.06.24 09:54:01 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.06.24 09:54:01 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.06.24 09:54:01 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.06.24 09:54:01 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.06.20 13:23:53 | 000,001,044 | ---- | M] () -- C:\Users\Public\Desktop\HTC Sync.lnk
[2011.06.12 14:34:21 | 000,007,609 | ---- | M] () -- C:\Users\Maurice\AppData\Local\Resmon.ResmonCfg
[2011.06.08 19:25:18 | 133,804,746 | ---- | M] () -- C:\Users\Maurice\Backup files 1.zip
[2011.06.04 17:48:00 | 002,766,970 | ---- | M] () -- C:\Users\Maurice\Desktop\IMAG0067.jpg
[2011.06.02 07:55:31 | 000,381,328 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2 C:\Users\Maurice\Documents\*.tmp files -> C:\Users\Maurice\Documents\*.tmp -> ]
[1 C:\Users\Maurice\Desktop\*.tmp files -> C:\Users\Maurice\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.06.29 13:29:36 | 000,000,000 | ---- | C] () -- C:\Users\Maurice\defogger_reenable
[2011.06.29 13:28:43 | 000,050,477 | ---- | C] () -- C:\Users\Maurice\Desktop\Defogger.exe
[2011.06.20 13:23:53 | 000,001,044 | ---- | C] () -- C:\Users\Public\Desktop\HTC Sync.lnk
[2011.06.12 14:34:21 | 000,007,609 | ---- | C] () -- C:\Users\Maurice\AppData\Local\Resmon.ResmonCfg
[2011.06.08 19:25:16 | 133,804,746 | ---- | C] () -- C:\Users\Maurice\Backup files 1.zip
[2011.06.05 22:59:01 | 002,766,970 | ---- | C] () -- C:\Users\Maurice\Desktop\IMAG0067.jpg
[2011.04.01 05:07:02 | 010,877,272 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll
[2011.04.01 05:07:02 | 000,102,744 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe
[2011.04.01 05:06:56 | 000,331,608 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll
[2011.04.01 04:56:00 | 000,027,872 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2011.03.22 23:58:22 | 000,014,168 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll
[2011.03.21 13:22:06 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2011.03.04 08:26:18 | 000,000,000 | ---- | C] () -- C:\Users\Maurice\AppData\Roaming\wklnhst.dat
[2010.06.13 13:20:18 | 000,115,369 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2010.06.13 13:20:18 | 000,097,859 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2010.05.07 18:43:30 | 000,025,824 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2010.04.21 19:50:22 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010.04.21 19:50:21 | 000,138,056 | ---- | C] () -- C:\Users\Maurice\AppData\Roaming\PnkBstrK.sys



GMER.txt

GMER 1.0.15.15640 - hxxp://www.gmer.net
Rootkit scan 2011-06-29 18:11:18
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\000000af WDC_WD15 rev.80.0
Running: 6b19q4v7.exe; Driver: C:\Users\Maurice\AppData\Local\Temp\pfliifob.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0x90E34992]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcConnectPort [0x90E363FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcCreatePort [0x90E36674]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcSendWaitReceivePort [0x90E368E6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwClose [0x90E352AA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwConnectPort [0x90E35A52]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateEvent [0x90E35E4E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateFile [0x90E354C8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateMutant [0x90E35D34]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0x90E34582]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreatePort [0x90E35C08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSection [0x90E3472A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSemaphore [0x90E35F6E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThread [0x90E34F32]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThreadEx [0x90E35030]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateWaitablePort [0x90E35C9E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDebugActiveProcess [0x90E37596]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDuplicateObject [0x90E38716]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwFsControlFile [0x90E35694]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwLoadDriver [0x90E37688]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwMapViewOfSection [0x90E37D62]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenEvent [0x90E35EE4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenFile [0x90E35336]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenMutant [0x90E35DC4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenProcess [0x90E34BDC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSection [0x90E37AFC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSemaphore [0x90E36004]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenThread [0x90E34AD0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueryDirectoryObject [0x90E36B30]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQuerySection [0x90E3809C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueueApcThread [0x90E3798E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyPort [0x90E36368]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0x90E3622E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0x90E37330]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwResumeThread [0x90E385B8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSecureConnectPort [0x90E3579C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetContextThread [0x90E3514C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetInformationToken [0x90E36BD2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSecurityObject [0x90E37790]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSystemInformation [0x90E381EC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendProcess [0x90E382DE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendThread [0x90E38418]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSystemDebugControl [0x90E374BA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateProcess [0x90E34D7C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateThread [0x90E34CD2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0x90E37F40]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0x90E34E68]

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwSaveKey + 13C1 83252339 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8328BD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10D7 83292DCC 4 Bytes [92, 49, E3, 90] {XCHG EDX, EAX; DEC ECX; JECXZ 0xffffffffffffff94}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10FF 83292DF4 8 Bytes [FA, 63, E3, 90, 74, 66, E3, ...] {CLI ; ARPL BX, SP; NOP ; JZ 0x6c; JECXZ 0xffffffffffffff98}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1143 83292E38 4 Bytes [E6, 68, E3, 90] {OUT 0x68, AL; JECXZ 0xffffffffffffff94}
.text ntkrnlpa.exe!KeRemoveQueueEx + 116F 83292E64 4 Bytes [AA, 52, E3, 90] {STOSB ; PUSH EDX; JECXZ 0xffffffffffffff94}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1193 83292E88 4 Bytes [52, 5A, E3, 90] {PUSH EDX; POP EDX; JECXZ 0xffffffffffffff94}
.text ...
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x93E3C000, 0x2F786C, 0xE8000020]
.text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0x9EC00300, 0x1B7E, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Real\RealPlayer\Update\realsched.exe[3320] kernel32.dll!SetUnhandledExceptionFilter 75F53D01 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind ???j?l??tunnel?ox????i???????????????????5??????s????7??????{152c3281-3409-11df-abf3-806e6f6e6963}???????????e???????e??Microsoft????i????N??i???7??????????? ???i???????????????????????????????????????????V??00????N??i?????????D?????i???????????i????D??i??? ???????i???????????????????????2?????????????????????i?????7???n????N??i???7???????????????????,??????????S???????????????????????USB\DevClass_00&SubC lass_00&Prot_00?USB\DevClass_00&SubClass_00?USB\DevClass_00?USB\COMPOSITE????????i??? ???????i???????????i???????????????????????????????????i??????????s.??????????????????????\??\USB#VID_09DA&PID_8090#5&27e4fbe1&0&3#{a5dcbf10-6530-11d2-901f-00c04fb951ed}?????? ???????i??????????????????????????????????? ???????i?????i???????1??L????????? ??????idg?????i???i???i??(?????????????????ad???????j??????p????????????????t??????????? ???????i?????i?????i????????&??????????????>?????i????????????usbstor.inf:Generic.NTx86:USBSTOR_BULK:6.1.7601.17577:usb\class_08&subclass_06&prot_50?? ????usb\class_08&subclass_06&prot_5
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Route ???j?????????????????????????????k??????????????t???????????????????????????????or??????????20??????????????????????@%systemroot%\system32\drivers\Rdp RefMp.sys,-100????????????????????????????????????????Extended Base????k?l?????????l???m??????????????????? ?????????????????????????????????????g????? ???e????????????????????????V????????g???????????????????s?????????????6??.1??????????????t???????????????t????p???????????????????n??????????????t??? ????????????????????????????????t????????????????????????k?k?1??system32\DRIVERS\pacer.sys???????????????????????????????????????????????????????????? ????P??????????????????????????????e???-???????C??{533c5b84-ec70-11d2-9505-00c04f79deaf}\0010?????????????????Microsoft????????????????????????????e???????????k?k?1???j????????????????V?????????????STORAGE\VolumeSnapshot??=C? ???r?????????????{00000000-0000-0000-0000-000000000000}?B-H???????5???{???????????y???k??????#{???i?i?k?????? ????????????????????????j???k???k??{71a27cdd-812a-11d0-bec7-08002be2092f}\0006?ff?????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Export ????????????????????????????????????????????????11?}?1??????????????????????????????????????????11???????????????????? ??????????????????????????????????????????????????????????????????????????????????????f???????????????f??????????.NTx86??????Microsoft???? ???????f???????????????????????????????f??????????? ???1??|???\?l??????H?????????????????????????????? ??????? ??????? ????????????.??x???X?h??????D???????????????????????????????????? ??????? ???????$??????.???????7??? ?????????????????????1????????????????????00000407?????????????????????????????????????????????????????????????????????????????????????-??????D3??Root\*6TO4MP\0048???????????????????????acpi\authenticamd_-_x86??????????????n??????????????????Net???????D?????????????????????????????????????????????? ???????????????????f?1????????????????????? ?????????????????????1????????????&????????????????????/??? ?????????????????????1????????????????????? ???????????????????f?1????????????????????? ?????????????????????1????????????????????? ?????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Bind ???j?k??\SystemRoot\system32\drivers\kbdhid.sys?????system32\DRIVERS\kl2.sys?????~???????????????j???????????????????????????????????????????????j???? ?????????????????????????????? ??????g?????????????e??un??un???????e??????t???@%systemroot%\system32\wkssvc.dll,-1005?????@%systemroot%\system32\wkssvc.dll,-1007?????????????????e????????????????????????5???~????????????R??j??????????system32\DRIVERS\lirsgt.sys?????????????????????????????????????s???????? j???? ??????B???l?l?i???????U??????????\SystemRoot\system32\drivers\mouclass.sys?????Z??j?????????n?????????f???A???e???????????n??11??????????????????????? B????????????????????????????????????????????????&????????????e??????????????B??j??????????storprop.dll,AtaPropPageProvider?????j?j??????????????????? ??????e??????el???????????????e???????j???.???????i?k????FSFilter Virtualization?????@%SystemRoot%\system32\drivers\ndis.sys,-200?????????????????j???????????n?k?n?n?j????$??j???4???????-???????????z??????????p????????????e???????????z?z?o??????????????????11?
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Route ???jSv???j???j??????????????? ???????i???????????i?1????????????????????? h????????????????????j????? ???????i?????j???????1????????????????????? ?i???i???i???i???i???i???i???j???j???j???j????? ???????j???????????i?1????????????????????? ???????5???????k?????j????? ???????i?????j???????1????????????????????? ???????j???????????i?1?????????????????????????h???????????5?????????????????????????j????? ???????i?????j???????1????????????????????? ???????j???????????i?1?????????????????????????i???6??????7&21d63dca&0?7?????????????j??????8??j????????h?????mshdc.inf_x86_neutral_f64b9c35a3a5be81?? ?????j?j?j?j?j?j?j????<??j????????h??????????&???????j???????h????b??j?????????n?????????????????????????????????????????????????????f???????????????t ???j???e??????????????????????????????e???????????????????????????nettun.inf?00}??@%systemroot%\system32\DRIVERS\RDPCDD.sys,-100???????????????????????????e?e?t?t?p???????????????????????????????????????6?.17??????????????????????????????t????????/??????s&?????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Export ????????Net?1}????????????????????m???????t?????????????????????*6to4mp? "???????????????t????,???????????????????????J??????k???????k???????k??? ?????????????????????????????????e??????`??????k???c??? ???????|???????????d?:??????????&?&????????????????????B??MSAFD NetBIOS [\Device\NetBT_Tcpip6_{EAC33483-A66E-42B8-BBC8-6CB8E9332F06}] SEQPACKET 83?r??MSAFD NetBIOS [\Device\NetBT_Tcpip6_{AD020F3B-705C-4737-A286-FAFB870E77B5}] DATAGRAM 71??A???????????-????????m??????????????????????????????????B??????????????Microsoft???????????????????????????????????????l??????????????????????????????????????????? ????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{50214A6A-01E5-4833-B41A-91509DABDD49}] DATAGRAM 88???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ?????????????????????AC???????????????????0???????e?? ?@
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Bind ???f?????????????7????????m??5???f??*6to4mp?????????or???j?j?????g?gMi??msisadrv?0???????????????????5??{8ECC055D-047F-11D1-A537-0000F8753ED1}?_10???f??Net??3???????j????N??????????????????????i??????????????????04??PCI\VEN_197B&DEV_2380&REV_00?PCI\VEN_197B&DEV_2380?PCI\VEN_197B &CC_0C0010?PCI\VEN_197B&CC_0C00?PCI\VEN_197B?PCI\CC_0C0010?PCI\CC_0C00????????g?gMi???????????R?????sPC???????????3?g?3???????????e?e?e?e?e?e?e?e?e?f? f??Microsoft???????????.NT??????????f???????6???f???e??tunnel?CCA????|??i???????3???f?fr ??TDI??????????????4???4??????el???????k??????????????????HD???f?f?f?f?????????????k????N??h????????D?????.NT??????????????????????????j?j?????g?ys??? ?????????s?????sol???????????t?????s%\?????????????????s????????????? ??????? ???????4???f???????e??????????????????????????????????LegacyDriver?????????????f???j?j?f???????f??LegacyDriver?8???????????%???????????????6?????????? ?????g???????????????????????????????????????????????f?f?i?i?f?i?:???/?l6???PCI\VEN_1022&DEV_1204&SUBSYS_00000000&REV_00?PCI\VE
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Route ???j?j????????????R??j????????h???????0??p???n?????eta??PnP Filter???????????j??????p?????????????????????b??j?????????n????????????????????????@%SystemRoot%\system32\drivers\fltmgr.sys,-10000????Extended Base???System32\drivers\hwpolicy.sys????j???j???j?????k?l??1.2.0.125????????q?????????????????????????j?j????????????????????????T??j????????h?????Sys tem32\Drivers\ksecdd.sys???????:??j????????h??????????j???0??e2???????6???????y??????p???Service??k???????j???????????j??????????????????????????????? ?????????????????8??j????????h??????????????????d???????????????????????????5???F??????d6???? ??5??????p?????????????????????????b??j?????????n????.NT?ms??oem3.inf?????j??????????????????????????g???system32\DRIVERS\nwifi.sys??????????????????? ????v??????????????????????? ???f???\?????\To??????????%SystemRoot%\system32\srvsvc.dll??????L??p??????k??????????????g????text????System32\Drivers\ksecpkg.sys?????????????5??s??? ????????????t????????j??????p????????????d?????????V2A???????j????????????????????????????m??k?
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Export ???j?j????????????????????????T??j????????h?????System32\Drivers\ksecdd.sys???????:??j????????h??????????j???0??e2???????6???????y??????p???Service??k ???????j???????????j????????????????????????????????????????????????8??j????????h??????????????????d???????????????????????????5???F??????d6???? ??5??????p?????????????????????????b??j?????????n????.NT?ms??oem3.inf?????j??????????????????????????g???system32\DRIVERS\nwifi.sys??????????????????? ????v??????????????????????? ???f???\?????\To??????????%SystemRoot%\system32\srvsvc.dll??????L??p??????k??????????????g????text????System32\Drivers\ksecpkg.sys?????????????5??s??? ????????????t????????j??????p????????????d?????????V2A???????j????????????????????????????m??k??????????????????????????HIDClass?????????????????????? ??????????????p???Cryptography?????????j???????e????^??j?????????e?????j??????????tunnel???????j???j???????????????????j?????j?n?????????????????????? Maurice??????????h??@%SystemRoot%\system32\drivers\fileinfo.sys,-100?????????j???-??e5????X????????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Bind ???j?n??????????????????????Maurice??????????h??@%SystemRoot%\system32\drivers\fileinfo.sys,-100?????????j???-??e5????X??????????e???s?z?s???????j???0???2???????l??????p???????z.????P??j????????h?????@%SystemRoot%\system32\drivers\nsiproxy.sys,-2???????????????????????n??%m??%m??????????????RPCSS?????????8????????????e?????????j????<??j????????h?????tunnel?ce????p???l???k???????????h?h?n?p?k? ??????g???????????????????????k??????????Extended Base???????C0??????r???????????????Controls the underlying video driver stacks to provide fully-featured display capabilities.?????Keyboard Class???????????k???????????????????????????j??????????????????system32\drivers\nsiproxy.sys??????????????????????????????????????g?????????????????e? ???????????????????????????????????????Z??j?????????e????input.inf????f?h?j???g??\SystemRoot\system32\drivers\HDAudBus.sys???????????????system32\DRIV ERS\kl1.sys???????j?z??????????????????????????????????{0??????????????t???192.168.178.1????????????u?u?u?????|?9?|????????t???????p????l?
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Route ???j?z??????????????????????????????????{0??????????????t???192.168.178.1????????????u?u?u?????|?9?|????????t???????p????l?x?}?}?}???????????m???p???? ???????????????????????????j?j?j?j?j?j?j?????????????g?????????????s??*PNP09FF????sh???????k???????????????????h?????????????????????????????????????? @%SystemRoot%\system32\drivers\mountmgr.sys,-101????????????????????system32\drivers\ndis.sys????????????l??????????system32\drivers\MSPCLOCK.sys???s???Typ??????????????????n???????????????m?m??? ??????????????????s??????????????????t????j????????????????4??j?????????????????j???????l?m???m?m?????????????+???+??NDIS Wrapper????\SystemRoot\system32\drivers\luafv.sys??????????????????????????????????????????????Microsoft????k?k????????????base????????????????t???t?? ?????????????t????????????????????????f?f?j?j?j?j?j???j?j????????t0??????????????????????????????????????@%SystemRoot%\system32\drivers\fvevol.sys,-100????????2??j????????h??????????????????????????????j???f?????????j?k??\SystemRoot\system32\drivers\kbdhid
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Export ???j???????l?m???m?m?????????????+???+??NDIS Wrapper????\SystemRoot\system32\drivers\luafv.sys??????????????????????????????????????????????Microsoft????k?k????????????base????????????????t???t?? ?????????????t????????????????????????f?f?j?j?j?j?j???j?j????????t0??????????????????????????????????????@%SystemRoot%\system32\drivers\fvevol.sys,-100????????2??j????????h??????????????????????????????j???f?????????j?k??\SystemRoot\system32\drivers\kbdhid.sys?????system32\DRIVERS\kl2.sys?????~??? ????????????j???????????????????????????????????????????????j?????????????????????????????????? ??????g?????????????e??un??un???????e??????t???@%systemroot%\system32\wkssvc.dll,-1005?????@%systemroot%\system32\wkssvc.dll,-1007?????????????????e????????????????????????5???~????????????R??j??????????system32\DRIVERS\lirsgt.sys?????????????????????????????????????s???????? j???? ??????B???l?l?i???????U??????????\SystemRoot\system32\drivers\mouclass.sys?????Z??j?????????n?????????f???A???e???????????n??11??????????????????????? B?

---- EOF - GMER 1.0.15 ----



ETRAS.txt
OTL Extras logfile created on: 29.06.2011 17:19:28 - Run 1
OTL by OldTimer - Version 3.2.24.2 Folder = C:\Users\Maurice\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

3,25 Gb Total Physical Memory | 2,13 Gb Available Physical Memory | 65,63% Memory free
17,90 Gb Paging File | 16,11 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): c:\pagefile.sys 15000 50000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 1376,16 Gb Total Space | 1289,53 Gb Free Space | 93,70% Space Free | Partition Type: NTFS
Drive D: | 20,00 Gb Total Space | 11,89 Gb Free Space | 59,43% Space Free | Partition Type: NTFS

Computer Name: MAURICE-PC | User Name: Maurice | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MIF5BA~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{806422F8-8E0A-494A-A369-0F34F1B89160}" = CorelDRAW Essentials 4 - Extra Content
"_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4
"{07B62101-7EBD-434A-94B1-B38063BE5516}" = CorelDRAW Essentials 4 - PHOTO-PAINT
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID-Anmelde-Assistent
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{0A169C69-5012-DAD1-B26D-6AD81A3242A9}" = Catalyst Control Center Localization All
"{0ED4216F-3540-4D6B-8199-1C8DDEA3924B}" = CorelDRAW Essentials 4 - Lang DE
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19AC095C-3520-4999-AA15-93B6D0248A50}" = CorelDRAW Essentials 4 - Content
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 18
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{34A9406E-1994-4C20-AC72-04CFA2B24545}" = CorelDRAW Essentials 4 - Lang EN
"{34B164BB-87C0-0E98-4B4B-867962CBB5EB}" = CCC Help Italian
"{3576C335-958D-4D60-A812-F68F9A2796AF}" = CorelDRAW Essentials 4 - Lang IT
"{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D8FA9E6-DE47-98B1-B292-D5BD9D1AC5F4}" = Catalyst Control Center Graphics Previews Vista
"{3E6F0CAD-EE38-42A5-9EEA-AE17A55BF2D4}" = Firebird SQL Server - MAGIX Edition
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4D07BB5D-7903-53B0-4EE0-F23FB43A3034}" = Catalyst Control Center Graphics Full New
"{4D66F66A-D5FA-15A2-F6E5-5589BD7E29AA}" = Catalyst Control Center InstallProxy
"{5107CFE6-65DB-C1BE-A97B-68C22747AD4F}" = CCC Help English
"{518FBF0D-3BA6-BF84-C949-D301EEA09F08}" = ccc-core-static
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{5500BB35-1C21-4328-9F16-F894B860FADE}" = CorelDRAW Essentials 4 - Lang NL
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A53AF94-FB62-528E-93D7-47D927FCBA89}" = Catalyst Control Center InstallProxy
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{70AA9B4F-64F7-4B0D-ADD8-05802D61AF72}" = Windows Live Toolbar
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5
"{76E852ED-1B06-4BC8-9D6A-625DB95FB7E5}" = CorelDRAW Essentials 4 - IPM - No VBA
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{7F276611-40A1-71AF-79B2-F896525FA898}" = CCC Help Danish
"{80186A32-8C10-9A90-409B-F83ED7823EA5}" = Catalyst Control Center Graphics Light
"{806422F8-8E0A-494A-A369-0F34F1B89160}" = CorelDRAW Essentials 4 - Extra Content
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie
"{853E9CDB-711A-533C-E73F-1D87DCCAF5B6}" = Catalyst Control Center Graphics Full Existing
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8730DBBF-3817-FC91-3C5D-A42F535A0C75}" = Catalyst Control Center Core Implementation
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9043B9A0-9505-405B-8202-E7167A38A89C}" = CorelDRAW Essentials 4
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{923E3957-F939-453A-BD55-41CFB8D7F211}" = HTC Sync
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{963911A3-E0E3-1D9B-CCF1-04607B415F9D}" = CCC Help Dutch
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{987B04C4-B5AC-4AD6-A7E9-8D681085B850}" = AMD USB Filter Driver
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B4A90F5-B7F6-742C-C761-526AD050B601}" = CCC Help French
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{9DB2B2B1-464C-F7ED-2032-B80A1F2EEA69}" = CCC Help Japanese
"{9E422606-5F50-5D98-D89F-74AF10167A25}" = CCC Help Norwegian
"{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker
"{ABD8B955-1C69-4AF3-949B-13CD587C175F}" = CorelDRAW Essentials 4 - Lang BR
"{AC76BA86-7AD7-1031-7B44-A94000000001}" = Adobe Reader 9.4.5 - Deutsch
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ADF60A14-CFC4-7174-D088-E1CFE6663EF3}" = ATI Catalyst Install Manager
"{AEDBD563-24BB-4EE3-8366-A654DAC2D988}" = Mirror's Edge™
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B9FA9F15-A1F3-4DB1-AD49-0B9351843FAA}" = CorelDRAW Essentials 4 - Draw
"{BA9319FE-BCEF-4C99-8039-F464648D046E}" = CorelDRAW Essentials 4 - Lang FR
"{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}" = Microsoft SQL Server 2005 Compact Edition [DEU]
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4 - ICA
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C3B58DC8-B030-0AE4-87C2-7721A4A485FA}" = CCC Help German
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C682F3F0-00A6-4379-B083-4F3273624D7B}" = CorelDRAW Essentials 4 - Lang ES
"{C897FCB3-2F8B-4185-8035-79E2AF3A92A4}" = iTunes
"{C8A6E0DE-B25F-D008-C10F-81DB91224A41}" = ccc-utility
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E3D04529-6EDB-11D8-A372-0050BAE317E1}" = CyberLink PowerDVD Copy
"{E4D15328-8C89-484B-B9AA-F5BE9EA6D01C}" = NVIDIA PhysX v8.10.17
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E8E25861-3B27-E2FE-877A-4E19B848EA31}" = CCC Help Spanish
"{E9D9AD46-011D-EC6D-180B-8A0C6835B778}" = CCC Help Swedish
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E2B312-D7FD-4349-A9B6-E90B36DB1BD0}" = Paint.NET v3.5.5
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F16841F6-5F0F-4DBE-B318-63CEB916F21D}" = CorelDRAW Essentials 4 - Filters
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FE6B2A1F-FFA0-9BD0-6C8E-BCA7AEDCFC5E}" = CCC Help Finnish
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 3.5
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.35.324
"Guild Wars" = GUILD WARS
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"Logitech Vid" = Logitech Vid HD
"MEDION Fotos auf CD & DVD SE Nord D" = MEDION Fotos auf CD & DVD SE Nord
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox 5.0 (x86 de)" = Mozilla Firefox 5.0 (x86 de)
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 12.0" = RealPlayer
"T4EPlayer" = T4E Player
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"TmNationsForever_is1" = TmNationsForever
"Uninstall_is1" = Uninstall 1.0.0.1
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CreepSmash.com" = CreepSmash.com

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 27.06.2011 15:00:23 | Computer Name = Maurice-PC | Source = Application Hang | ID = 1002
Description = Programm explorer.exe, Version 6.1.7601.17567 kann nicht mehr unter
Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf
in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
zu suchen. Prozess-ID: 1848 Startzeit: 01cc34fc4b128bf7 Endzeit: 10 Anwendungspfad:
C:\Windows\explorer.exe Berichts-ID: ad73e5c8-a0ef-11e0-bb31-bfc2bd3153aa

Error - 27.06.2011 15:03:27 | Computer Name = Maurice-PC | Source = Application Hang | ID = 1002
Description = Programm ICQ.exe, Version 7.5.0.5242 kann nicht mehr unter Windows
ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: f24 Startzeit:
01cc34cab5d68d2b Endzeit: 575 Anwendungspfad: C:\Program Files\ICQ7.5\ICQ.exe Berichts-ID:
f50dcdad-a0ef-11e0-bb31-bfc2bd3153aa

Error - 28.06.2011 05:17:17 | Computer Name = Maurice-PC | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 28.06.2011 07:22:08 | Computer Name = Maurice-PC | Source = VSS | ID = 13
Description =

Error - 28.06.2011 07:22:08 | Computer Name = Maurice-PC | Source = VSS | ID = 8193
Description =

Error - 28.06.2011 07:22:08 | Computer Name = Maurice-PC | Source = VSS | ID = 13
Description =

Error - 28.06.2011 07:22:08 | Computer Name = Maurice-PC | Source = VSS | ID = 8193
Description =

Error - 28.06.2011 17:15:25 | Computer Name = Maurice-PC | Source = Windows Backup | ID = 4103
Description =

Error - 28.06.2011 23:08:48 | Computer Name = Maurice-PC | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 29.06.2011 07:28:01 | Computer Name = Maurice-PC | Source = Application Hang | ID = 1002
Description = Programm HiJackThis204.exe, Version 2.0.0.4 kann nicht mehr unter
Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in
der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
zu suchen. Prozess-ID: bf4 Startzeit: 01cc364f473dda99 Endzeit: 3 Anwendungspfad: C:\Users\Maurice\Pictures\Downloads\HiJackThis204.exe

Berichts-ID:
b822eeb2-a242-11e0-9358-fd7fffc8dfa7

[ OSession Events ]
Error - 15.12.2010 18:04:34 | Computer Name = Maurice-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8
seconds with 0 seconds of active time. This session ended with a crash.

Error - 16.02.2011 12:58:32 | Computer Name = Maurice-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.

Error - 27.02.2011 11:34:23 | Computer Name = Maurice-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.

Error - 01.03.2011 16:52:09 | Computer Name = Maurice-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3
seconds with 0 seconds of active time. This session ended with a crash.

Error - 16.03.2011 17:06:37 | Computer Name = Maurice-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 9
seconds with 0 seconds of active time. This session ended with a crash.

Error - 19.04.2011 05:06:30 | Computer Name = Maurice-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 4
seconds with 0 seconds of active time. This session ended with a crash.

Error - 19.04.2011 05:06:37 | Computer Name = Maurice-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

Error - 21.04.2011 06:18:38 | Computer Name = Maurice-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 4
seconds with 0 seconds of active time. This session ended with a crash.

Error - 01.05.2011 08:28:25 | Computer Name = Maurice-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 7 seconds with 0 seconds of active time. This session ended with a crash.

Error - 26.05.2011 17:35:36 | Computer Name = Maurice-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 10
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 29.06.2011 11:19:09 | Computer Name = Maurice-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet
wurde: %%-2140993535

Error - 29.06.2011 11:19:19 | Computer Name = Maurice-PC | Source = PNRPSvc | ID = 102
Description =

Error - 29.06.2011 11:19:19 | Computer Name = Maurice-PC | Source = PNRPSvc | ID = 102
Description =

Error - 29.06.2011 11:19:19 | Computer Name = Maurice-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler
beendet: %%-2140993535

Error - 29.06.2011 11:19:19 | Computer Name = Maurice-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet
wurde: %%-2140993535

Error - 29.06.2011 11:19:19 | Computer Name = Maurice-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler
beendet: %%-2140993535

Error - 29.06.2011 11:19:19 | Computer Name = Maurice-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet
wurde: %%-2140993535

Error - 29.06.2011 11:19:58 | Computer Name = Maurice-PC | Source = PNRPSvc | ID = 102
Description =

Error - 29.06.2011 11:19:58 | Computer Name = Maurice-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet
wurde: %%-2140993535

Error - 29.06.2011 11:19:58 | Computer Name = Maurice-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler
beendet: %%-2140993535


< End of report >



Ich hoffe ihr könnt mir irgendwie helfen ^^
lg

cosinus 29.06.2011 22:24

Hallo und :hallo:

Bitte routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!


Danach OTL-Custom:


CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Maurice 30.06.2011 16:21

Otl.txt

OTL Logfile:
Code:

OTL logfile created on: 30.06.2011 17:05:24 - Run 1
OTL by OldTimer - Version 3.2.24.2    Folder = C:\Users\Maurice\Pictures\Downloads
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 2,05 Gb Available Physical Memory | 62,99% Memory free
17,90 Gb Paging File | 16,59 Gb Available in Paging File | 92,71% Paging File free
Paging file location(s): c:\pagefile.sys 15000 50000 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 1376,16 Gb Total Space | 1288,79 Gb Free Space | 93,65% Space Free | Partition Type: NTFS
Drive D: | 20,00 Gb Total Space | 11,89 Gb Free Space | 59,43% Space Free | Partition Type: NTFS
 
Computer Name: MAURICE-PC | User Name: Maurice | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.06.30 17:02:32 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Maurice\Pictures\Downloads\OTL.exe
PRC - [2011.06.30 16:40:14 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- c:\Programme\Real\RealPlayer\Update\realsched.exe
PRC - [2011.05.29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011.04.01 05:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) -- C:\Programme\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.11.20 14:17:41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2010.09.16 14:06:22 | 000,080,896 | ---- | M] () -- C:\Programme\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2010.05.07 12:39:36 | 000,344,736 | ---- | M] (Kaspersky Lab ZAO) -- C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
PRC - [2010.04.07 04:12:38 | 000,372,736 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2010.04.07 04:12:04 | 000,172,032 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2009.08.18 11:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009.08.18 11:29:22 | 000,183,152 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009.06.03 21:59:02 | 000,103,720 | ---- | M] (CyberLink) -- C:\Programme\CyberLink\Power2Go\CLMLSvc.exe
PRC - [2009.05.19 12:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009.02.03 15:53:00 | 001,155,072 | ---- | M] (MAGIX AG) -- C:\Programme\Common Files\MAGIX Services\Database\bin\FABS.exe
PRC - [2007.07.24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- c:\Programme\Common Files\Protexis\License Service\PsiService_2.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2011.06.30 17:02:32 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Maurice\Pictures\Downloads\OTL.exe
MOD - [2010.11.20 13:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.05.29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.04.01 05:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Programme\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2010.09.16 14:06:22 | 000,080,896 | ---- | M] () [Auto | Running] -- C:\Programme\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2010.05.07 12:39:36 | 000,344,736 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stop_Pending] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe -- (AVP)
SRV - [2010.04.07 04:12:04 | 000,172,032 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2009.12.16 19:26:00 | 003,453,712 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.02.03 15:53:00 | 001,155,072 | ---- | M] (MAGIX AG) [Unknown | Running] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2008.08.07 11:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2007.07.24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.05.29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011.04.01 05:11:10 | 004,333,280 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 200(UVC)
DRV - [2011.04.01 05:09:48 | 000,291,424 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS)
DRV - [2010.11.25 07:59:16 | 000,603,240 | ---- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTL8192su.sys -- (RTL8192su)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.07.27 08:12:26 | 000,114,784 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvpopflt.sys -- (lvpopflt)
DRV - [2010.06.23 10:24:56 | 000,023,040 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\htcnprot.sys -- (htcnprot)
DRV - [2010.05.07 18:43:30 | 000,025,824 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2010.05.07 12:28:06 | 000,475,224 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\System32\drivers\klif.sys -- (KLIF)
DRV - [2010.05.07 00:19:06 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\kl2.sys -- (kl2)
DRV - [2010.05.07 00:19:02 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\kl1.sys -- (kl1)
DRV - [2010.04.22 19:07:34 | 000,022,104 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\klim6.sys -- (KLIM6)
DRV - [2010.04.12 17:05:01 | 000,271,360 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2010.04.12 17:04:56 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2010.04.07 04:43:20 | 005,430,272 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2010.04.07 03:23:10 | 000,157,184 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2010.03.09 12:21:26 | 000,107,024 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2009.12.22 02:26:36 | 000,030,392 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\usbfilter.sys -- (usbfilter)
DRV - [2009.11.02 20:27:16 | 000,019,984 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009.10.26 08:54:24 | 000,025,088 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009.07.07 23:48:14 | 000,011,832 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\amdide.sys -- (amdide)
DRV - [2009.05.05 11:00:28 | 000,014,392 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://medion.msn.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Elf 1 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2856415&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.mtb-news.de/news/2011/05/27/sonntag-29-mai-action-heroes-20h-live-bei-mtb-news-de/"
FF - prefs.js..extensions.enabledItems: {4176DFF4-4698-11DE-BEEB-45DA55D89593}:0.8.12
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: KavAntiBanner@Kaspersky.ru:11.0.0.232
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.0.232
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5.8
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: piclens@cooliris.com:1.12.2.44172
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.06.30 16:40:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.06.30 16:40:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.06.30 16:41:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.06.30 16:40:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.06.30 16:41:43 | 000,000,000 | ---D | M]
 
[2010.03.20 13:23:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maurice\AppData\Roaming\mozilla\Extensions
[2011.06.22 06:46:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maurice\AppData\Roaming\mozilla\Firefox\Profiles\3ctj3o27.default\extensions
[2011.01.04 19:14:06 | 000,000,000 | ---D | M] (Speed Dial) -- C:\Users\Maurice\AppData\Roaming\mozilla\Firefox\Profiles\3ctj3o27.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010.05.25 16:30:31 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Maurice\AppData\Roaming\mozilla\Firefox\Profiles\3ctj3o27.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.06.22 06:46:00 | 000,000,000 | ---D | M] (Cooliris) -- C:\Users\Maurice\AppData\Roaming\mozilla\Firefox\Profiles\3ctj3o27.default\extensions\piclens@cooliris.com
[2011.06.10 22:22:25 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.03.20 13:22:34 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Programme\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.06.10 22:22:25 | 000,000,000 | ---D | M] (Skype extension) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010.06.13 14:10:30 | 000,000,000 | ---D | M] (Kaspersky Anti-Banner) -- C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru
[2010.06.13 14:10:30 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
File not found (No name found) --
() (No name found) -- C:\USERS\MAURICE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CTJ3O27.DEFAULT\EXTENSIONS\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.XPI
() (No name found) -- C:\USERS\MAURICE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CTJ3O27.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011.06.22 00:36:28 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.05.06 13:03:27 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.05.06 13:03:27 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.05.06 13:03:27 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.05.06 13:03:27 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.05.06 13:03:27 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.05.06 13:03:27 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programme\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID-Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [EA Core]  File not found
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files\Logitech\Vid HD\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [msnmsgr]  File not found
O4 - HKCU..\Run: [Pando Media Booster]  File not found
O4 - Startup: C:\Users\Maurice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Maurice\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} -  File not found
O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} -  File not found
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll) - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\mzvkbd3.dll (Kaspersky Lab ZAO)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll) - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\kloehk.dll (Kaspersky Lab ZAO)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpReg: Skype - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig - State: "startup" - 2
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: BsScanner - Service
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: BsScanner - Service
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)

 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.06.30 16:45:23 | 000,000,000 | ---D | C] -- C:\Users\Maurice\Desktop\Praktikum
[2011.06.30 16:41:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2011.06.30 12:11:21 | 000,000,000 | ---D | C] -- C:\Users\Maurice\AppData\Roaming\Malwarebytes
[2011.06.30 12:11:04 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.06.30 12:11:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.06.30 12:11:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.06.30 12:11:00 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.06.30 12:11:00 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.06.29 18:35:37 | 000,000,000 | ---D | C] -- C:\Users\Maurice\Desktop\Defogger
[2011.06.29 12:57:51 | 001,401,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2011.06.29 12:57:50 | 001,549,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2011.06.29 12:57:50 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2011.06.29 12:57:49 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2011.06.29 12:57:49 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2011.06.29 12:57:49 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2011.06.20 13:23:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC Sync
[2011.06.16 07:41:22 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.06.16 07:41:21 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011.06.16 07:41:21 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011.06.16 07:41:21 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011.06.15 23:01:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7.5
[2011.06.12 23:39:03 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ7.5
[2011.06.10 22:22:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype Extras
[2011.06.10 22:21:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011.06.10 22:21:55 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2011.06.09 13:40:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.06.09 13:38:28 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.06.09 13:38:27 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2 C:\Users\Maurice\Documents\*.tmp files -> C:\Users\Maurice\Documents\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.06.30 16:42:41 | 000,009,888 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.06.30 16:42:40 | 000,009,888 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.06.30 16:40:47 | 000,198,848 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll
[2011.06.30 16:40:24 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2011.06.30 16:40:24 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2011.06.30 16:40:16 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2011.06.30 16:34:48 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2011.06.30 16:34:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.06.30 16:34:41 | 2615,910,400 | -HS- | M] () -- C:\hiberfil.sys
[2011.06.29 18:54:48 | 000,381,328 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.06.29 13:29:36 | 000,000,000 | ---- | M] () -- C:\Users\Maurice\defogger_reenable
[2011.06.24 09:54:01 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.06.24 09:54:01 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.06.24 09:54:01 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.06.24 09:54:01 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.06.20 13:23:53 | 000,001,044 | ---- | M] () -- C:\Users\Public\Desktop\HTC Sync.lnk
[2011.06.19 21:01:38 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.06.12 14:34:21 | 000,007,609 | ---- | M] () -- C:\Users\Maurice\AppData\Local\Resmon.ResmonCfg
[2011.06.08 19:25:18 | 133,804,746 | ---- | M] () -- C:\Users\Maurice\Backup files 1.zip
[2 C:\Users\Maurice\Documents\*.tmp files -> C:\Users\Maurice\Documents\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.06.29 13:29:36 | 000,000,000 | ---- | C] () -- C:\Users\Maurice\defogger_reenable
[2011.06.20 13:23:53 | 000,001,044 | ---- | C] () -- C:\Users\Public\Desktop\HTC Sync.lnk
[2011.06.12 14:34:21 | 000,007,609 | ---- | C] () -- C:\Users\Maurice\AppData\Local\Resmon.ResmonCfg
[2011.06.08 19:25:16 | 133,804,746 | ---- | C] () -- C:\Users\Maurice\Backup files 1.zip
[2011.04.01 05:07:02 | 010,877,272 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll
[2011.04.01 05:07:02 | 000,102,744 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe
[2011.04.01 05:06:56 | 000,331,608 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll
[2011.04.01 04:56:00 | 000,027,872 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2011.03.22 23:58:22 | 000,014,168 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll
[2011.03.21 13:22:06 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2011.03.04 08:26:18 | 000,000,000 | ---- | C] () -- C:\Users\Maurice\AppData\Roaming\wklnhst.dat
[2010.06.13 13:20:18 | 000,115,369 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2010.06.13 13:20:18 | 000,097,859 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2010.05.07 18:43:30 | 000,025,824 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2010.04.21 19:50:22 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010.04.21 19:50:21 | 000,138,056 | ---- | C] () -- C:\Users\Maurice\AppData\Roaming\PnkBstrK.sys
[2010.04.21 19:49:51 | 000,215,016 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2010.04.21 19:49:48 | 002,427,248 | ---- | C] () -- C:\Windows\System32\pbsvc_heroes.exe
[2010.04.21 19:49:48 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2010.04.12 17:05:01 | 000,271,360 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2010.04.12 17:04:56 | 000,018,048 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2010.04.09 03:45:42 | 000,000,952 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2010.04.02 18:09:08 | 000,002,023 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2010.03.22 21:46:14 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.03.17 17:06:30 | 000,202,234 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2010.02.03 15:03:15 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2010.01.26 17:35:17 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.01.26 17:04:43 | 000,000,021 | ---- | C] () -- C:\Windows\System32\drivers\VERSION.DAT
[2009.09.09 19:01:40 | 000,027,675 | ---- | C] () -- C:\Windows\System32\drivers\klopp.dat
[2009.08.03 16:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.DLL
[2009.08.03 16:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009.07.14 10:47:43 | 000,653,928 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 10:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 10:47:43 | 000,129,800 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 10:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 06:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 06:33:53 | 000,381,328 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 04:05:48 | 000,615,810 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 04:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 04:05:48 | 000,106,190 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 04:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 04:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 04:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 02:55:09 | 000,587,776 | ---- | C] () -- C:\Windows\System32\hpotscl1.dll
[2009.07.14 01:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009.02.18 20:55:20 | 000,294,912 | ---- | C] () -- C:\Windows\System32\ATIODE.exe
[2009.02.03 23:52:02 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ATIODCLI.exe
[2008.10.07 10:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008.10.07 10:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
 
========== LOP Check ==========
 
[2011.04.02 10:28:05 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.04.13 21:44:46 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\HTC
[2011.04.13 21:44:48 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2011.06.30 15:20:05 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\ICQ
[2010.05.21 13:46:53 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Leadertech
[2011.02.15 21:30:21 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Simfy
[2011.03.04 08:26:21 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Template
[2011.05.30 19:45:48 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\TS3Client
[2011.02.02 19:51:47 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Ubisoft
[2011.05.28 22:37:20 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.05.21 14:59:19 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Adobe
[2010.06.13 10:12:42 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Apple Computer
[2010.03.20 12:27:38 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\ATI
[2010.04.09 03:45:43 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Corel
[2011.04.02 10:28:05 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.04.13 21:44:46 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\HTC
[2011.04.13 21:44:48 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2011.06.30 15:20:05 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\ICQ
[2010.03.20 12:26:58 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Identities
[2010.05.21 13:46:53 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Leadertech
[2010.03.20 12:30:38 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Macromedia
[2011.06.30 12:11:21 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Malwarebytes
[2009.07.14 10:56:41 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Media Center Programs
[2011.04.18 00:01:09 | 000,000,000 | --SD | M] -- C:\Users\Maurice\AppData\Roaming\Microsoft
[2010.03.20 13:23:12 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Mozilla
[2011.06.27 15:04:04 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Real
[2010.03.26 17:28:41 | 000,000,000 | RH-D | M] -- C:\Users\Maurice\AppData\Roaming\SecuROM
[2011.02.15 21:30:21 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Simfy
[2011.06.27 22:00:23 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Skype
[2011.06.27 16:09:56 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\skypePM
[2010.03.21 17:43:44 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Sun
[2011.03.04 08:26:21 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Template
[2011.05.30 19:45:48 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\TS3Client
[2011.02.02 19:51:47 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\Ubisoft
[2010.07.23 18:32:45 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\vlc
[2010.03.20 19:32:03 | 000,000,000 | ---D | M] -- C:\Users\Maurice\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2011.04.13 21:52:04 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Maurice\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2011.04.18 00:01:09 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Maurice\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2011.06.20 22:38:24 | 000,425,984 | ---- | M] () -- C:\Users\Maurice\AppData\Roaming\Mozilla\Firefox\Profiles\3ctj3o27.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
[2011.06.20 22:38:24 | 000,546,304 | ---- | M] () -- C:\Users\Maurice\AppData\Roaming\Mozilla\Firefox\Profiles\3ctj3o27.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
[2011.06.27 15:04:08 | 000,310,400 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Maurice\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\8.00\rnupgagent.exe
[2011.06.27 18:06:59 | 026,472,592 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Maurice\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\8.00\stub_data\RealPlayer_de.exe
[2011.06.27 18:05:19 | 000,676,624 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Maurice\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\8.00\stub_exe\RealPlayer_de.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
 
< MD5 for: AHCIX86S.SYS  >
[2007.11.14 19:44:42 | 000,129,552 | ---- | M] (Promise Technology, Inc.) MD5=58CB1FA96B24DFE2196548E959B1996B -- C:\ATI\Win7_Vista\8_723\Packages\Drivers\SBDrv\SB6xx\RAID\LH\ahcix86s.sys
[2009.10.26 19:41:10 | 000,189,496 | ---- | M] (Advanced Micro Devices, Inc) MD5=6C27F0A964EA98F457CAAB9A47030538 -- C:\ATI\Win7_Vista\8_723\Packages\Drivers\SBDrv\SB6xx\RAID\W7\ahcix86s.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\drivers\iaStorV.sys
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys
[2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
[2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\drivers\nvstor.sys
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys
[2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.05.07 00:19:02 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\drivers\kl1.sys
[2010.05.07 00:19:06 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\drivers\kl2.sys
[2010.05.07 12:28:06 | 000,475,224 | ---- | M] (Kaspersky Lab) Unable to obtain MD5 -- C:\Windows\system32\drivers\klif.sys
[2010.04.22 19:07:34 | 000,022,104 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\drivers\klim6.sys
[2009.11.02 20:27:16 | 000,019,984 | ---- | M] (Kaspersky Lab) Unable to obtain MD5 -- C:\Windows\system32\drivers\klmouflt.sys
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2010.04.07 04:13:10 | 000,446,464 | ---- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 -- C:\Windows\system32\ATIDEMGX.dll
[2010.05.07 12:37:58 | 000,228,024 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\klogon.dll

< End of report >

--- --- ---


So und jetzt?

cosinus 30.06.2011 16:24

Vollscan malwarebytes übersehen?

Maurice 30.06.2011 16:35

Nein, den habe ich auch gemacht.
Sry, überlesen das ich die Berichte auch posten muss.

Maurice 30.06.2011 16:38

Quickscan:

PHP-Code:

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Datenbank Version: 6985

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

30.06.2011 16:07:34
mbam-log-2011-06-30 (16-07-34).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 157108
Laufzeit: 6 Minute(n), 45 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden) 



Vollscan:

PHP-Code:

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Datenbank Version: 6985

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

30.06.2011 15:36:23
mbam-log-2011-06-30 (15-36-23).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 407519
Laufzeit: 3 Stunde(n), 23 Minute(n), 9 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden) 


cosinus 30.06.2011 19:25

Hast du auch noch das Log von Kaspersky mit diesem Fund?

Maurice 01.07.2011 13:01

Weiß nicht genau, was mich aber verwirrt ist das bei Erkannte Bedrohungen einmal bei Virenfrei und bei unter Quarantäne dieser Trojaner steht.
Kann man bei den Ergebnissen die ich gepostet habe irgendwas sehen, ob da jetzt was ist oder war?

cosinus 01.07.2011 13:04

Bevor ich das OTL-Log näher betrachte würde ich gern das Log von Kaspersky sehen

Maurice 01.07.2011 13:41

Ich werde mal gucken.

Maurice 01.07.2011 13:43

Ich gucke mal nach.

Maurice 01.07.2011 15:09

Welchen brauchst du denn? Ich hab das Programm seit dem ersten Fund oft durchlaufen lassen...

cosinus 01.07.2011 15:13

POste alle relevanten Funde. Wenn möglich auch einfach alle Logs zusammen in eine Textdatei kopiert, die gezippt hier per Anhang oder via File-Upload.net - Ihr kostenloser File Hoster!

Maurice 02.07.2011 11:03

Code:

30.06.2011 16:51:34        Kaspersky Internet Security        Schutz-Center        Gefunden: Backdoor.Win32.SdBot.nci                        K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\scsaver.exe        [/PHP]       
29.06.2011 03:27:49        Kaspersky Internet Security        Schutz-Center        Gefunden: HEUR:Trojan-Downloader.Script.Generic                        C:\Dokumente und Einstellungen\...\Lokale Einstellungen\Mozilla\Firefox\Profiles\3ctj3o27.default\Cache\7\93\1658Ad01/3ctj3o27               
28.06.2011 00:38:55        Kaspersky Internet Security        Schutz-Center        Gefunden: HEUR:Exploit.Script.Generic                        j:\...-pc\backup set 2011-06-07 200051\backup files 2011-06-08 190004\backup files 1.zip/C\Users\...\AppData\Local\Mozilla\Firefox\Profiles\3ctj3o27.default\Cache\C\68\3AFE4d01


Meintest du so etwas?

cosinus 03.07.2011 13:05

Warum postest du das so unübersichtlich? :balla:
Nicht in PHP-Tags posten! Wenn dann in Code- oder Quote-Tags!
Du brauchst auch nicht jeden Fund in separate Tags stecken!
Am besten alle Logs bzw. alle relevanten Infos in eine Textdatei kopieren und diese hier gezippt hochladen!

Maurice 03.07.2011 18:00

Zitat:

30.06.2011 16:51:34 Kaspersky Internet Security Schutz-Center Gefunden: Backdoor.Win32.SdBot.nci K:RECYCLERS-1-5-21-1482476501-1644491937-682003330-1013scsaver.exe

Das ist der einzigste der noch drauf ist. Sonst findet Kaspersky nichts mehr.
Was sollte denn noch relevant sein? Das ist der einzigste Fund.

cosinus 03.07.2011 18:30

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Elf 1 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2856415&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
[2010.05.25 16:30:31 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Maurice\AppData\Roaming\mozilla\Firefox\Profiles\3ctj3o27.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.06.10 22:22:25 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.03.20 13:22:34 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Programme\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
O4 - HKCU..\Run: [msnmsgr]  File not found
O4 - HKCU..\Run: [Pando Media Booster]  File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
:Files
K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013
:Commands
[purity]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Maurice 03.07.2011 18:41

Zitat:

========== OTL ==========
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "Elf 1 Customized Web Search" removed from browser.search.defaultthis.engineName
Prefs.js: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2856415&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl
Prefs.js: true removed from browser.search.useDBForOrder
C:\Users\Maurice\AppData\Roaming\mozilla\Firefox\Profiles\3ctj3o27.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}\chrome folder moved successfully.
C:\Users\Maurice\AppData\Roaming\mozilla\Firefox\Profiles\3ctj3o27.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\META-INF folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\defaults\preferences folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\defaults folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\chrome folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\skin folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\locale\en folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\locale\de folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\locale folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\content folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\skin folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\locale\en folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\locale\de folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\locale folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\content folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\components folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru folder moved successfully.
C:\Programme\Mozilla Firefox\extensions folder moved successfully.
Folder C:\Programme\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\msnmsgr not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Pando Media Booster not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
========== FILES ==========
File\Folder K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013 not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.24.2 log created on 07032011_193835
OKay, was kommt als nächstes?

cosinus 03.07.2011 18:47

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - also beide Haken setzen, auf Start scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

http://www.trojaner-board.de/attachm...rnen-start.png


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

Maurice 03.07.2011 18:59

Zitat:

2011/07/03 19:57:08.0753 1808 TDSS rootkit removing tool 2.5.8.0 Jun 28 2011 19:12:16
2011/07/03 19:57:09.0065 1808 ================================================================================
2011/07/03 19:57:09.0065 1808 SystemInfo:
2011/07/03 19:57:09.0065 1808
2011/07/03 19:57:09.0065 1808 OS Version: 6.1.7601 ServicePack: 1.0
2011/07/03 19:57:09.0065 1808 Product type: Workstation
2011/07/03 19:57:09.0065 1808 ComputerName: MAURICE-PC
2011/07/03 19:57:09.0065 1808 UserName: Maurice
2011/07/03 19:57:09.0065 1808 Windows directory: C:\Windows
2011/07/03 19:57:09.0065 1808 System windows directory: C:\Windows
2011/07/03 19:57:09.0065 1808 Processor architecture: Intel x86
2011/07/03 19:57:09.0065 1808 Number of processors: 4
2011/07/03 19:57:09.0065 1808 Page size: 0x1000
2011/07/03 19:57:09.0065 1808 Boot type: Normal boot
2011/07/03 19:57:09.0065 1808 ================================================================================
2011/07/03 19:57:12.0466 1808 Initialize success
2011/07/03 19:57:17.0614 3576 ================================================================================
2011/07/03 19:57:17.0614 3576 Scan started
2011/07/03 19:57:17.0614 3576 Mode: Manual;
2011/07/03 19:57:17.0614 3576 ================================================================================
2011/07/03 19:57:20.0468 3576 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
2011/07/03 19:57:20.0531 3576 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
2011/07/03 19:57:20.0562 3576 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
2011/07/03 19:57:20.0671 3576 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/07/03 19:57:20.0874 3576 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2011/07/03 19:57:20.0968 3576 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2011/07/03 19:57:21.0077 3576 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
2011/07/03 19:57:21.0139 3576 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
2011/07/03 19:57:21.0280 3576 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2011/07/03 19:57:21.0404 3576 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
2011/07/03 19:57:21.0482 3576 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
2011/07/03 19:57:21.0545 3576 amdide (211fce336502911ec03fc15a91344c98) C:\Windows\system32\DRIVERS\amdide.sys
2011/07/03 19:57:21.0607 3576 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2011/07/03 19:57:21.0794 3576 amdkmdag (c22bdfcbed2596692096f85a9bf54358) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/07/03 19:57:22.0060 3576 amdkmdap (cc6a16ce23dbc94a59f8e821558d5754) C:\Windows\system32\DRIVERS\atikmpag.sys
2011/07/03 19:57:22.0122 3576 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2011/07/03 19:57:22.0153 3576 amdsata (6f64c768a9a48fab7c6d6cee1b30f97f) C:\Windows\system32\DRIVERS\amdsata.sys
2011/07/03 19:57:22.0184 3576 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/07/03 19:57:22.0262 3576 amdxata (e27866684780606bcce640a57937d88a) C:\Windows\system32\DRIVERS\amdxata.sys
2011/07/03 19:57:22.0340 3576 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
2011/07/03 19:57:22.0418 3576 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2011/07/03 19:57:22.0496 3576 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2011/07/03 19:57:22.0559 3576 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/07/03 19:57:22.0637 3576 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
2011/07/03 19:57:22.0699 3576 AtiHdmiService (c822c615b2f693ef4e5b355432976a81) C:\Windows\system32\drivers\AtiHdmi.sys
2011/07/03 19:57:22.0777 3576 AtiPcie (b73c832088dd54b55e04ff6f9646ad8c) C:\Windows\system32\DRIVERS\AtiPcie.sys
2011/07/03 19:57:22.0855 3576 atksgt (6e996cf8459a2594e0e9609d0e34d41f) C:\Windows\system32\DRIVERS\atksgt.sys
2011/07/03 19:57:22.0964 3576 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2011/07/03 19:57:23.0089 3576 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/07/03 19:57:23.0152 3576 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2011/07/03 19:57:23.0214 3576 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/07/03 19:57:23.0354 3576 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
2011/07/03 19:57:23.0448 3576 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/07/03 19:57:23.0526 3576 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/07/03 19:57:23.0651 3576 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2011/07/03 19:57:23.0760 3576 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/07/03 19:57:23.0854 3576 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/07/03 19:57:23.0916 3576 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/07/03 19:57:23.0978 3576 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/07/03 19:57:24.0056 3576 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2011/07/03 19:57:24.0197 3576 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys
2011/07/03 19:57:24.0290 3576 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2011/07/03 19:57:24.0337 3576 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2011/07/03 19:57:24.0415 3576 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/07/03 19:57:24.0493 3576 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
2011/07/03 19:57:24.0571 3576 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2011/07/03 19:57:24.0649 3576 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2011/07/03 19:57:24.0712 3576 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
2011/07/03 19:57:24.0805 3576 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/07/03 19:57:24.0930 3576 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
2011/07/03 19:57:25.0024 3576 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2011/07/03 19:57:25.0102 3576 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2011/07/03 19:57:25.0180 3576 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2011/07/03 19:57:25.0304 3576 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
2011/07/03 19:57:25.0648 3576 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2011/07/03 19:57:25.0897 3576 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2011/07/03 19:57:26.0038 3576 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
2011/07/03 19:57:26.0162 3576 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2011/07/03 19:57:26.0256 3576 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2011/07/03 19:57:26.0334 3576 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2011/07/03 19:57:26.0412 3576 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2011/07/03 19:57:26.0474 3576 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2011/07/03 19:57:26.0537 3576 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/07/03 19:57:26.0615 3576 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2011/07/03 19:57:26.0677 3576 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2011/07/03 19:57:26.0740 3576 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2011/07/03 19:57:26.0802 3576 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
2011/07/03 19:57:26.0864 3576 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/07/03 19:57:27.0005 3576 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/07/03 19:57:27.0083 3576 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2011/07/03 19:57:27.0192 3576 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
2011/07/03 19:57:27.0332 3576 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
2011/07/03 19:57:27.0348 3576 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/07/03 19:57:27.0410 3576 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2011/07/03 19:57:27.0504 3576 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2011/07/03 19:57:27.0582 3576 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\drivers\hidusb.sys
2011/07/03 19:57:27.0644 3576 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
2011/07/03 19:57:27.0738 3576 HTCAND32 (950cc1e6ae3a6cd23e0945cde089b02c) C:\Windows\system32\Drivers\ANDROIDUSB.sys
2011/07/03 19:57:27.0832 3576 htcnprot (339adefad60353f960e3ca67ce468c24) C:\Windows\system32\DRIVERS\htcnprot.sys
2011/07/03 19:57:27.0894 3576 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
2011/07/03 19:57:27.0956 3576 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
2011/07/03 19:57:28.0019 3576 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
2011/07/03 19:57:28.0112 3576 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
2011/07/03 19:57:28.0222 3576 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2011/07/03 19:57:28.0378 3576 IntcAzAudAddService (97fa95e4f486f37d60ad3744d86f3d7e) C:\Windows\system32\drivers\RTKVHDA.sys
2011/07/03 19:57:28.0627 3576 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
2011/07/03 19:57:28.0690 3576 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2011/07/03 19:57:28.0752 3576 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/07/03 19:57:28.0814 3576 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
2011/07/03 19:57:28.0970 3576 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2011/07/03 19:57:29.0017 3576 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2011/07/03 19:57:29.0080 3576 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
2011/07/03 19:57:29.0142 3576 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
2011/07/03 19:57:29.0360 3576 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
2011/07/03 19:57:29.0470 3576 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
2011/07/03 19:57:29.0579 3576 kl1 (47f4320cff5bd3de472bb300a32a879e) C:\Windows\system32\DRIVERS\kl1.sys
2011/07/03 19:57:29.0657 3576 kl2 (0e29fe31bd4c72412ad99253e71b25c1) C:\Windows\system32\DRIVERS\kl2.sys
2011/07/03 19:57:29.0860 3576 KLIF (0fa77171e66d1f6887b02e9f9afe3523) C:\Windows\system32\DRIVERS\klif.sys
2011/07/03 19:57:29.0938 3576 KLIM6 (cf88b4985d957eee45c9939092e87c92) C:\Windows\system32\DRIVERS\klim6.sys
2011/07/03 19:57:30.0016 3576 klmouflt (3de1771c135328420315e21dde229bba) C:\Windows\system32\DRIVERS\klmouflt.sys
2011/07/03 19:57:30.0094 3576 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys
2011/07/03 19:57:30.0156 3576 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
2011/07/03 19:57:30.0296 3576 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
2011/07/03 19:57:30.0374 3576 Lbd (336abe8721cbc3110f1c6426da633417) C:\Windows\system32\DRIVERS\Lbd.sys
2011/07/03 19:57:30.0515 3576 lirsgt (975b6cf65f44e95883f3855bae8cecaf) C:\Windows\system32\DRIVERS\lirsgt.sys
2011/07/03 19:57:30.0842 3576 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/07/03 19:57:30.0983 3576 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/07/03 19:57:31.0061 3576 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/07/03 19:57:31.0139 3576 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/07/03 19:57:31.0201 3576 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/07/03 19:57:31.0295 3576 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2011/07/03 19:57:31.0404 3576 lvpopflt (cbf0bf6af73a704211bbb52efacaa8a0) C:\Windows\system32\DRIVERS\lvpopflt.sys
2011/07/03 19:57:31.0513 3576 LVPr2Mon (8be71d7edb8c7494913722059f760dd0) C:\Windows\system32\Drivers\LVPr2Mon.sys
2011/07/03 19:57:31.0638 3576 LVRS (b6e1ccd6572984adcae68439afd07011) C:\Windows\system32\DRIVERS\lvrs.sys
2011/07/03 19:57:31.0825 3576 LVUVC (6c42815dd57e397f0cd988304b5eb4b3) C:\Windows\system32\DRIVERS\lvuvc.sys
2011/07/03 19:57:32.0106 3576 MBAMProtector (3d2c13377763eeac0ca6fb46f57217ed) C:\Windows\system32\drivers\mbam.sys
2011/07/03 19:57:32.0200 3576 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2011/07/03 19:57:32.0262 3576 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/07/03 19:57:32.0324 3576 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2011/07/03 19:57:32.0402 3576 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2011/07/03 19:57:32.0434 3576 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys
2011/07/03 19:57:32.0527 3576 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2011/07/03 19:57:32.0574 3576 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
2011/07/03 19:57:32.0636 3576 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
2011/07/03 19:57:32.0746 3576 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2011/07/03 19:57:32.0808 3576 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
2011/07/03 19:57:32.0870 3576 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/07/03 19:57:32.0933 3576 mrxsmb10 (a70c828a93cce4c11617f6249f4d87fc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/07/03 19:57:33.0011 3576 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/07/03 19:57:33.0073 3576 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
2011/07/03 19:57:33.0136 3576 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
2011/07/03 19:57:33.0229 3576 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2011/07/03 19:57:33.0307 3576 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2011/07/03 19:57:33.0354 3576 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
2011/07/03 19:57:33.0432 3576 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2011/07/03 19:57:33.0510 3576 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/07/03 19:57:33.0557 3576 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2011/07/03 19:57:33.0635 3576 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2011/07/03 19:57:33.0744 3576 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
2011/07/03 19:57:33.0760 3576 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2011/07/03 19:57:33.0838 3576 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/07/03 19:57:33.0916 3576 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2011/07/03 19:57:33.0978 3576 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2011/07/03 19:57:34.0072 3576 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
2011/07/03 19:57:34.0103 3576 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/07/03 19:57:34.0150 3576 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/07/03 19:57:34.0212 3576 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/07/03 19:57:34.0306 3576 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/07/03 19:57:34.0352 3576 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
2011/07/03 19:57:34.0399 3576 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2011/07/03 19:57:34.0477 3576 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
2011/07/03 19:57:34.0555 3576 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/07/03 19:57:34.0649 3576 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2011/07/03 19:57:34.0711 3576 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2011/07/03 19:57:34.0805 3576 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
2011/07/03 19:57:34.0992 3576 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2011/07/03 19:57:35.0070 3576 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
2011/07/03 19:57:35.0179 3576 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
2011/07/03 19:57:35.0351 3576 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
2011/07/03 19:57:35.0460 3576 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
2011/07/03 19:57:35.0554 3576 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2011/07/03 19:57:35.0632 3576 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
2011/07/03 19:57:35.0694 3576 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2011/07/03 19:57:35.0788 3576 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
2011/07/03 19:57:35.0819 3576 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
2011/07/03 19:57:35.0990 3576 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/07/03 19:57:36.0084 3576 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2011/07/03 19:57:36.0178 3576 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2011/07/03 19:57:36.0380 3576 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2011/07/03 19:57:36.0443 3576 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2011/07/03 19:57:36.0599 3576 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2011/07/03 19:57:36.0724 3576 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2011/07/03 19:57:36.0958 3576 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/07/03 19:57:37.0082 3576 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2011/07/03 19:57:37.0145 3576 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2011/07/03 19:57:37.0192 3576 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/07/03 19:57:37.0223 3576 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/07/03 19:57:37.0316 3576 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/07/03 19:57:37.0410 3576 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2011/07/03 19:57:37.0441 3576 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
2011/07/03 19:57:37.0504 3576 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/07/03 19:57:37.0566 3576 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/07/03 19:57:37.0628 3576 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
2011/07/03 19:57:37.0675 3576 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2011/07/03 19:57:37.0753 3576 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
2011/07/03 19:57:37.0831 3576 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
2011/07/03 19:57:37.0909 3576 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2011/07/03 19:57:37.0987 3576 RTL8167 (e099d23ee1bbce0cf5745f811f3b1882) C:\Windows\system32\DRIVERS\Rt86win7.sys
2011/07/03 19:57:38.0065 3576 RTL8192su (9ce8deffaffccbf473015d76ae8ee514) C:\Windows\system32\DRIVERS\RTL8192su.sys
2011/07/03 19:57:38.0174 3576 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
2011/07/03 19:57:38.0284 3576 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
2011/07/03 19:57:38.0377 3576 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/07/03 19:57:38.0455 3576 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2011/07/03 19:57:38.0518 3576 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2011/07/03 19:57:38.0596 3576 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2011/07/03 19:57:38.0689 3576 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
2011/07/03 19:57:38.0783 3576 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
2011/07/03 19:57:38.0908 3576 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
2011/07/03 19:57:39.0001 3576 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/07/03 19:57:39.0110 3576 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
2011/07/03 19:57:39.0220 3576 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/07/03 19:57:39.0360 3576 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/07/03 19:57:39.0469 3576 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2011/07/03 19:57:39.0578 3576 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2011/07/03 19:57:39.0672 3576 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
2011/07/03 19:57:39.0734 3576 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
2011/07/03 19:57:39.0812 3576 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
2011/07/03 19:57:39.0875 3576 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2011/07/03 19:57:39.0968 3576 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
2011/07/03 19:57:40.0171 3576 Tcpip (24326784df8f3d5f5bbb9f878ce33c14) C:\Windows\system32\drivers\tcpip.sys
2011/07/03 19:57:40.0312 3576 TCPIP6 (24326784df8f3d5f5bbb9f878ce33c14) C:\Windows\system32\DRIVERS\tcpip.sys
2011/07/03 19:57:40.0343 3576 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
2011/07/03 19:57:40.0421 3576 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
2011/07/03 19:57:40.0483 3576 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
2011/07/03 19:57:40.0546 3576 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
2011/07/03 19:57:40.0608 3576 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
2011/07/03 19:57:40.0702 3576 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/07/03 19:57:40.0811 3576 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
2011/07/03 19:57:40.0873 3576 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
2011/07/03 19:57:40.0936 3576 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2011/07/03 19:57:41.0123 3576 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
2011/07/03 19:57:41.0450 3576 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
2011/07/03 19:57:41.0528 3576 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
2011/07/03 19:57:41.0606 3576 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2011/07/03 19:57:41.0700 3576 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\Windows\system32\Drivers\usbaapl.sys
2011/07/03 19:57:41.0794 3576 usbaudio (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys
2011/07/03 19:57:41.0856 3576 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/07/03 19:57:41.0934 3576 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
2011/07/03 19:57:42.0028 3576 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
2011/07/03 19:57:42.0106 3576 usbfilter (e5b14557793164db879ee56f5b59c3e2) C:\Windows\system32\DRIVERS\usbfilter.sys
2011/07/03 19:57:42.0184 3576 usbhub (9d22aad9ac6a07c691a1113e5f860868) C:\Windows\system32\drivers\usbhub.sys
2011/07/03 19:57:42.0277 3576 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
2011/07/03 19:57:42.0355 3576 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2011/07/03 19:57:42.0418 3576 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
2011/07/03 19:57:42.0480 3576 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/07/03 19:57:42.0496 3576 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/07/03 19:57:42.0574 3576 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
2011/07/03 19:57:42.0667 3576 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/07/03 19:57:42.0714 3576 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2011/07/03 19:57:42.0792 3576 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
2011/07/03 19:57:42.0870 3576 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
2011/07/03 19:57:42.0948 3576 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2011/07/03 19:57:43.0010 3576 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
2011/07/03 19:57:43.0073 3576 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
2011/07/03 19:57:43.0166 3576 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2011/07/03 19:57:43.0291 3576 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
2011/07/03 19:57:43.0432 3576 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/07/03 19:57:43.0556 3576 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys
2011/07/03 19:57:43.0619 3576 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys
2011/07/03 19:57:43.0697 3576 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\Windows\system32\DRIVERS\vwifimp.sys
2011/07/03 19:57:43.0728 3576 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2011/07/03 19:57:43.0790 3576 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/03 19:57:43.0884 3576 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/03 19:57:43.0915 3576 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2011/07/03 19:57:43.0978 3576 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/07/03 19:57:44.0071 3576 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/07/03 19:57:44.0134 3576 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2011/07/03 19:57:44.0227 3576 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
2011/07/03 19:57:44.0305 3576 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/07/03 19:57:44.0399 3576 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
2011/07/03 19:57:44.0461 3576 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/07/03 19:57:44.0555 3576 MBR (0x1B8) (4624822e540ec83cd0819525c65846ba) \Device\Harddisk0\DR0
2011/07/03 19:57:44.0602 3576 Boot (0x1200) (0adcd0eb588d44bd4c70cae75e35b383) \Device\Harddisk0\DR0\Partition0
2011/07/03 19:57:44.0633 3576 Boot (0x1200) (878bbda660f8b2d3971c9bff9ee7c850) \Device\Harddisk0\DR0\Partition1
2011/07/03 19:57:44.0648 3576 Boot (0x1200) (e3d44a51b61605b1fb6375050a87cc54) \Device\Harddisk0\DR0\Partition2
2011/07/03 19:57:44.0648 3576 ================================================================================
2011/07/03 19:57:44.0648 3576 Scan finished
2011/07/03 19:57:44.0648 3576 ================================================================================
2011/07/03 19:57:44.0664 3476 Detected object count: 0
2011/07/03 19:57:44.0664 3476 Actual detected object count: 0
Das wäre gemacht. Und was kommt jetzt?

cosinus 03.07.2011 20:20

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Maurice 03.07.2011 21:18

Combofix Logfile:
Code:

ComboFix 11-07-02.03 - Maurice 03.07.2011  22:05:24.1.4 - x86
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3326.2009 [GMT 2:00]
ausgeführt von:: c:\users\Maurice\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
AV: Lavasoft Ad-Watch Live! Virenschutz *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Maurice\AppData\Local\Microsoft\Windows\Temporary Internet Files\PMH3729.tmp
c:\windows\IsUn0407.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-06-03 bis 2011-07-03  ))))))))))))))))))))))))))))))
.
.
2011-07-03 20:12 . 2011-07-03 20:13        --------        d-----w-        c:\users\Maurice\AppData\Local\temp
2011-07-03 20:12 . 2011-07-03 20:12        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-07-03 17:38 . 2011-07-03 17:38        --------        d-----w-        C:\_OTL
2011-07-02 21:33 . 2011-07-02 21:33        --------        d-----w-        c:\users\Maurice\AppData\Roaming\ArchiCrypt
2011-07-02 21:31 . 2011-07-02 21:31        --------        d-----w-        c:\program files\ArchiCrypt
2011-07-02 14:38 . 2011-06-07 15:55        7074640        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{17612D2A-9584-483A-B491-0F5AD850AD3D}\mpengine.dll
2011-07-02 00:38 . 2011-07-01 18:22        16432        ----a-w-        c:\windows\system32\lsdelete.exe
2011-07-01 19:16 . 2011-07-01 19:16        --------        d-----w-        c:\programdata\EA Logs
2011-07-01 18:22 . 2011-07-01 18:22        101720        ----a-w-        c:\windows\system32\drivers\SBREDrv.sys
2011-07-01 18:18 . 2011-04-29 10:12        64512        ----a-w-        c:\windows\system32\drivers\Lbd.sys
2011-07-01 18:18 . 2011-07-01 18:18        --------        d-----w-        c:\programdata\Lavasoft
2011-07-01 18:18 . 2011-07-01 18:18        --------        d-----w-        c:\program files\Lavasoft
2011-07-01 17:46 . 2011-07-02 09:49        --------        d-----w-        c:\programdata\Spybot - Search & Destroy
2011-07-01 17:46 . 2011-07-01 17:46        --------        d-----w-        c:\program files\Spybot - Search & Destroy
2011-07-01 17:30 . 2006-06-19 11:01        69632        ----a-w-        c:\windows\system32\ztvcabinet.dll
2011-06-30 14:41 . 2011-06-30 14:41        --------        d-----w-        c:\program files\Common Files\xing shared
2011-06-30 10:11 . 2011-06-30 10:11        --------        d-----w-        c:\users\Maurice\AppData\Roaming\Malwarebytes
2011-06-30 10:11 . 2011-06-30 10:11        --------        d-----w-        c:\programdata\Malwarebytes
2011-06-30 10:11 . 2011-05-29 07:11        39984        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-30 10:11 . 2011-06-30 10:11        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2011-06-30 10:11 . 2011-05-29 07:11        22712        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-06-29 10:58 . 2011-05-24 10:44        293376        ----a-w-        c:\windows\system32\umpnpmgr.dll
2011-06-29 10:57 . 2011-05-04 04:32        1401344        ----a-w-        c:\windows\system32\mssrch.dll
2011-06-29 10:57 . 2011-05-04 04:34        1549312        ----a-w-        c:\windows\system32\tquery.dll
2011-06-29 10:57 . 2011-05-04 04:32        337408        ----a-w-        c:\windows\system32\mssph.dll
2011-06-29 10:57 . 2011-05-04 04:28        427520        ----a-w-        c:\windows\system32\SearchIndexer.exe
2011-06-29 10:57 . 2011-05-04 04:28        164352        ----a-w-        c:\windows\system32\SearchProtocolHost.exe
2011-06-29 10:57 . 2011-05-04 04:32        666624        ----a-w-        c:\windows\system32\mssvp.dll
2011-06-29 10:57 . 2011-05-04 04:32        197120        ----a-w-        c:\windows\system32\mssphtb.dll
2011-06-29 10:57 . 2011-05-04 04:32        59392        ----a-w-        c:\windows\system32\msscntrs.dll
2011-06-29 10:57 . 2011-05-04 04:28        86528        ----a-w-        c:\windows\system32\SearchFilterHost.exe
2011-06-21 22:36 . 2011-06-21 22:36        2106216        ----a-w-        c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-06-21 22:36 . 2011-06-21 22:36        1998168        ----a-w-        c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-06-16 05:41 . 2011-04-25 15:29        141104        ----a-w-        c:\program files\Internet Explorer\sqmapi.dll
2011-06-16 05:41 . 2011-04-22 23:25        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2011-06-16 05:41 . 2011-04-22 23:35        1797632        ----a-w-        c:\windows\system32\jscript9.dll
2011-06-16 05:04 . 2011-04-29 02:46        311808        ----a-w-        c:\windows\system32\drivers\srv.sys
2011-06-16 05:04 . 2011-04-29 02:46        310272        ----a-w-        c:\windows\system32\drivers\srv2.sys
2011-06-16 05:04 . 2011-04-29 02:46        114688        ----a-w-        c:\windows\system32\drivers\srvnet.sys
2011-06-16 05:04 . 2011-04-25 04:31        1290624        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2011-06-16 05:04 . 2011-04-25 02:18        338944        ----a-w-        c:\windows\system32\drivers\afd.sys
2011-06-16 05:04 . 2011-02-25 05:34        571904        ----a-w-        c:\windows\system32\oleaut32.dll
2011-06-16 05:04 . 2011-05-03 04:30        741376        ----a-w-        c:\windows\system32\inetcomm.dll
2011-06-16 05:04 . 2011-04-27 02:17        223744        ----a-w-        c:\windows\system32\drivers\mrxsmb10.sys
2011-06-16 05:04 . 2011-04-27 02:17        96768        ----a-w-        c:\windows\system32\drivers\mrxsmb20.sys
2011-06-16 05:04 . 2011-04-27 02:17        123904        ----a-w-        c:\windows\system32\drivers\mrxsmb.sys
2011-06-12 21:39 . 2011-06-29 19:38        --------        d-----w-        c:\program files\ICQ7.5
2011-06-10 20:22 . 2011-06-27 13:59        --------        d-----w-        c:\programdata\Skype Extras
2011-06-10 20:21 . 2011-06-10 20:21        --------        d-----w-        c:\program files\Common Files\Skype
2011-06-09 11:38 . 2011-06-09 11:38        --------        d-----w-        c:\program files\iPod
2011-06-09 11:38 . 2011-06-09 11:40        --------        d-----w-        c:\program files\iTunes
2011-06-07 10:35 . 2011-06-07 10:35        103864        ----a-w-        c:\program files\Mozilla Firefox\plugins\nppdf32.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-30 14:40 . 2010-01-18 06:30        348160        ----a-w-        c:\windows\system32\msvcr71.dll
2011-06-30 14:40 . 2010-01-18 06:30        499712        ----a-w-        c:\windows\system32\msvcp71.dll
2011-06-19 19:01 . 2011-05-14 10:18        404640        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-24 17:14 . 2010-01-26 14:37        222080        ------w-        c:\windows\system32\MpSigStub.exe
2011-05-18 20:47 . 2010-04-09 01:45        952        --sha-w-        c:\programdata\KGyGaAvL.sys
2011-04-22 19:14 . 2011-05-25 10:13        27008        ----a-w-        c:\windows\system32\drivers\Diskdump.sys
2011-04-17 22:01 . 2011-04-17 22:01        53248        ----a-r-        c:\users\Maurice\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-04-15 11:18 . 2011-04-15 11:18        159080        ----a-w-        c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10138.bin
2011-04-10 15:48 . 2011-04-10 15:48        86528        ----a-w-        c:\windows\system32\iesysprep.dll
2011-04-10 15:48 . 2011-04-10 15:48        76800        ----a-w-        c:\windows\system32\SetIEInstalledDate.exe
2011-04-10 15:48 . 2011-04-10 15:48        63488        ----a-w-        c:\windows\system32\tdc.ocx
2011-04-10 15:48 . 2011-04-10 15:48        48640        ----a-w-        c:\windows\system32\mshtmler.dll
2011-04-10 15:48 . 2011-04-10 15:48        367104        ----a-w-        c:\windows\system32\html.iec
2011-04-10 15:48 . 2011-04-10 15:48        161792        ----a-w-        c:\windows\system32\msls31.dll
2011-04-10 15:48 . 2011-04-10 15:48        1126912        ----a-w-        c:\windows\system32\wininet.dll
2011-04-10 15:48 . 2011-04-10 15:48        110592        ----a-w-        c:\windows\system32\IEAdvpack.dll
2011-04-10 15:48 . 2011-04-10 15:48        74752        ----a-w-        c:\windows\system32\iesetup.dll
2011-04-10 15:48 . 2011-04-10 15:48        420864        ----a-w-        c:\windows\system32\vbscript.dll
2011-04-10 15:48 . 2011-04-10 15:48        35840        ----a-w-        c:\windows\system32\imgutil.dll
2011-04-10 15:48 . 2011-04-10 15:48        23552        ----a-w-        c:\windows\system32\licmgr10.dll
2011-04-10 15:48 . 2011-04-10 15:48        152064        ----a-w-        c:\windows\system32\wextract.exe
2011-04-10 15:48 . 2011-04-10 15:48        150528        ----a-w-        c:\windows\system32\iexpress.exe
2011-04-10 15:48 . 2011-04-10 15:48        142848        ----a-w-        c:\windows\system32\ieUnatt.exe
2011-04-10 15:48 . 2011-04-10 15:48        1427456        ----a-w-        c:\windows\system32\inetcpl.cpl
2011-04-10 15:48 . 2011-04-10 15:48        11776        ----a-w-        c:\windows\system32\mshta.exe
2011-04-10 15:48 . 2011-04-10 15:48        101888        ----a-w-        c:\windows\system32\admparse.dll
2011-04-09 06:02 . 2011-05-11 20:21        3967872        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02 . 2011-05-11 20:21        3912576        ----a-w-        c:\windows\system32\ntoskrnl.exe
2011-04-09 05:56 . 2011-05-17 09:49        123904        ----a-w-        c:\windows\system32\poqexec.exe
2011-04-06 14:20 . 2011-04-06 14:20        91424        ----a-w-        c:\windows\system32\dnssd.dll
2011-04-06 14:20 . 2011-04-06 14:20        107808        ----a-w-        c:\windows\system32\dns-sd.exe
2011-06-21 22:36 . 2011-05-06 11:03        142296        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"Logitech Vid"="c:\program files\Logitech\Vid HD\Vid.exe" [2011-01-13 6129496]
"ICQ"="c:\program files\ICQ7.5\ICQ.exe" [2011-06-29 124216]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2009-06-03 103720]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-12-03 8120864]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-05-07 344736]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-06 102400]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-03-01 190808]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-07 421160]
"HTC Sync Loader"="c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-01-27 585728]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-06-30 273544]
.
c:\users\Maurice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-5-21 110592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~2\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~2\kloehk.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-05-26 19:50        15147400        ----a-r-        c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-05-06 132184]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-06-28 2151640]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-23 23040]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2011-04-29 15232]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-12-16 3453712]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-04-29 64512]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-22 22104]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-04-07 172032]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-02-03 1155072]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-04-01 428640]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-04-07 5430272]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-04-07 157184]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-05-29 22712]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-03-21 362600]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-11-25 603240]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 30392]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 47069977
*Deregistered* - 47069977
.
Inhalt des "geplante Tasks" Ordners
.
2011-07-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-04-29 11:19]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = about:blank
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube to Mp3 Converter - c:\users\Maurice\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Maurice\AppData\Roaming\Mozilla\Firefox\Profiles\3ctj3o27.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.mtb-news.de/news/2011/05/27/sonntag-29-mai-action-heroes-20h-live-bei-mtb-news-de/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
SafeBoot-BsScanner
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3481837660-1793344714-466227997-1000\Software\SecuROM\License information*]
"datasecu"=hex:77,d8,cc,77,c8,e6,93,70,7e,41,91,29,70,47,aa,f2,02,f2,55,1f,89,
  be,41,26,56,65,03,53,44,67,2a,d5,d9,a6,e7,b9,d6,29,4d,82,6b,a5,3d,4c,3e,e2,\
"rkeysecu"=hex:84,c4,10,36,15,35,8e,89,f4,53,45,70,5e,f4,05,88
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2011-07-03  22:14:51
ComboFix-quarantined-files.txt  2011-07-03 20:14
.
Vor Suchlauf: 8 Verzeichnis(se), 1.391.912.804.352 Bytes frei
Nach Suchlauf: 13 Verzeichnis(se), 1.394.795.802.624 Bytes frei
.
- - End Of File - - F1C143A3219D4950E2E9A0509AD6AF6A

--- --- ---


Kommt jetzt noch was oder war es der letzte Schritt? :D

cosinus 04.07.2011 08:30

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

Maurice 04.07.2011 13:12

GMER

GMER Logfile:
Code:

GMER 1.0.15.15640 - hxxp://www.gmer.net
Rootkit scan 2011-07-04 13:24:15
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\000000b2 WDC_WD15 rev.80.0
Running: oiq886te.exe; Driver: C:\Users\Maurice\AppData\Local\Temp\pfliifob.sys


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwAdjustPrivilegesToken [0x8C980992]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwAlpcConnectPort [0x8C9823FA]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwAlpcCreatePort [0x8C982674]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwAlpcSendWaitReceivePort [0x8C9828E6]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwClose [0x8C9812AA]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwConnectPort [0x8C981A52]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwCreateEvent [0x8C981E4E]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwCreateFile [0x8C9814C8]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwCreateMutant [0x8C981D34]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwCreateNamedPipeFile [0x8C980582]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwCreatePort [0x8C981C08]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwCreateSection [0x8C98072A]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwCreateSemaphore [0x8C981F6E]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwCreateThread [0x8C980F32]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwCreateThreadEx [0x8C981030]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwCreateWaitablePort [0x8C981C9E]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwDebugActiveProcess [0x8C983596]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwDuplicateObject [0x8C984716]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwFsControlFile [0x8C981694]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwLoadDriver [0x8C983688]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwMapViewOfSection [0x8C983D62]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwOpenEvent [0x8C981EE4]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwOpenFile [0x8C981336]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwOpenMutant [0x8C981DC4]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwOpenProcess [0x8C980BDC]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwOpenSection [0x8C983AFC]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwOpenSemaphore [0x8C982004]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwOpenThread [0x8C980AD0]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwQueryDirectoryObject [0x8C982B30]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwQuerySection [0x8C98409C]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwQueueApcThread [0x8C98398E]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwReplyPort [0x8C982368]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwReplyWaitReceivePort [0x8C98222E]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwRequestWaitReplyPort [0x8C983330]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwResumeThread [0x8C9845B8]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwSecureConnectPort [0x8C98179C]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwSetContextThread [0x8C98114C]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwSetInformationToken [0x8C982BD2]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwSetSecurityObject [0x8C983790]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwSetSystemInformation [0x8C9841EC]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwSuspendProcess [0x8C9842DE]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwSuspendThread [0x8C984418]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwSystemDebugControl [0x8C9834BA]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwTerminateProcess [0x8C980D7C]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwTerminateThread [0x8C980CD2]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwUnmapViewOfSection [0x8C983F40]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab)                  ZwWriteVirtualMemory [0x8C980E68]

---- Kernel code sections - GMER 1.0.15 ----

.text          ntkrnlpa.exe!ZwSaveKey + 13C1                                                                        83249339 1 Byte  [06]
.text          ntkrnlpa.exe!KiDispatchInterrupt + 5A2                                                                83282D52 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text          ntkrnlpa.exe!KeRemoveQueueEx + 10D7                                                                  83289DCC 4 Bytes  [92, 09, 98, 8C]
.text          ntkrnlpa.exe!KeRemoveQueueEx + 10FF                                                                  83289DF4 8 Bytes  [FA, 23, 98, 8C, 74, 26, 98, ...]
.text          ntkrnlpa.exe!KeRemoveQueueEx + 1143                                                                  83289E38 4 Bytes  [E6, 28, 98, 8C]
.text          ntkrnlpa.exe!KeRemoveQueueEx + 116F                                                                  83289E64 4 Bytes  [AA, 12, 98, 8C]
.text          ntkrnlpa.exe!KeRemoveQueueEx + 1193                                                                  83289E88 4 Bytes  [52, 1A, 98, 8C]
.text          ...                                                                                                 
.text          C:\Windows\system32\DRIVERS\atikmdag.sys                                                              section is writeable [0x9262A000, 0x2F786C, 0xE8000020]
.text          C:\Windows\system32\DRIVERS\lirsgt.sys                                                                section is writeable [0xA28BB300, 0x1B7E, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text          C:\Program Files\Real\RealPlayer\Update\realsched.exe[3092] kernel32.dll!SetUnhandledExceptionFilter  77483D01 5 Bytes  [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\tdx \Device\Tcp                                                                              kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume4                                                                fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume5                                                                fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device          \Driver\ACPI_HAL \Device\000000a7                                                                    halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice  \Driver\volmgr \Device\HarddiskVolume6                                                                fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume7                                                                fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\tdx \Device\Udp                                                                              kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
AttachedDevice  \Driver\tdx \Device\RawIp                                                                            kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind                                      ???j?l??tunnel?ox????i???????????????????5??????s????7??????{152c3281-3409-11df-abf3-806e6f6e6963}????????:??????D?gB9??Microsoft????i????N??i???7??????????? ???i???????????????????????????????????????????V??00????N??i?????????D?????i???????????i????D??i??? ???????i???????????????????????2?????????????????????i?????7???n????N??i???7???????????????????,??????????S???????????????????????USB\DevClass_00&SubClass_00&Prot_00?USB\DevClass_00&SubClass_00?USB\DevClass_00?USB\COMPOSITE????????i??? ???????i???????????i???????????????????????????????????i??????????s.??????????????????????\??\USB#VID_09DA&PID_8090#5&27e4fbe1&0&3#{a5dcbf10-6530-11d2-901f-00c04fb951ed}?????? ???????i??????????????????????????????????? ???????i?????i???????1??L????????? ??????idg?????i???i???i??(?????????????????ad???????????7?g?????????????????t??????????? ???????i?????i?????i????????&??????????????>?????i????????????usbstor.inf:Generic.NTx86:USBSTOR_BULK:6.1.7601.17577:usb\class_08&subclass_06&prot_50??????usb\class_08&subclass_06&prot_5
Reg            HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Route                                    ???j????????????????????????????????????????????t???????????????????????????????or??????????20??????????????????????@%systemroot%\system32\drivers\RdpRefMp.sys,-100????????????????????????????????????????SCSI Miniport????k?l?????????l???m??????????????????? ????????????????????????????$?????????p???? ???e????????????????????????V????????g????LegacyDriver?????????????????6??.1??????????????t????????????????????p???????????????????n??????????????t???????????????????????????????????t????????????????????????k?k?1??system32\DRIVERS\pacer.sys????????????????????????????????????????????????????????????????P??????????????????????????????e???-???????C??{533c5b84-ec70-11d2-9505-00c04f79deaf}\0010?????????????????Microsoft????????????????????????????e???????????k?k?1???j????????????????V?????????????STORAGE\VolumeSnapshot??=C????r?????????????{00000000-0000-0000-0000-000000000000}?B-H????X??????????????????y???k??????#{???i?i?k?????? ????????????????????????j???k???k??{71a27cdd-812a-11d0-bec7-08002be2092f}\0006?ff?????
Reg            HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Export                                    ????????????????????????????????????????????????11?}?1????$??????.???????7??????????????????????11???????????????????? ??????????????????????????????????????????????????????????????????????????????????????f???????????????f??????????.NTx86??????Microsoft???? ???????f???????????????????????????????f??????????? ???1??|???\?l??????H?????????????????????????????? ??????? ??????? ????????????.??x???X?h??????D???????????????????????????????????? ??????? ?????Root\*6TO4MP\0044???? ?????????????????????1????????????????????00000407?????????????????????????????????????????????????????????????????????????????????????-??????D3??Root\*6TO4MP\0048???????????????????????acpi\authenticamd_-_x86??????????????n??????????????????Net???????D?????????????????????????????????????????????? ???????????????????f?1????????????????????? ?????????????????????1????????????&????????????????????/??? ?????????????????????1????????????????????? ???????????????????f?1????????????????????? ?????????????????????1????????????????????? ?????????
Reg            HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Bind                                ???j?k??\SystemRoot\system32\drivers\kbdhid.sys?????system32\DRIVERS\kl2.sys?????~???????????????j???????????????????????????????????????????????j?????????????????????????????????? ??????g?????????????e??un??un???????e??????t???@%systemroot%\system32\wkssvc.dll,-1005?????@%systemroot%\system32\wkssvc.dll,-1007?????????????????e????????????????????????5???~????????????R??j??????????system32\DRIVERS\lirsgt.sys?????????????????????????????????????s????????j???e?f?~???????l?l?i???????U??????????\SystemRoot\system32\drivers\mouclass.sys?????Z??j?????????n??????:??????S?g_1???????????n??11???????????????????????B??????????????????????????????????????????????Pointer Class?????????????????B??j??????????storprop.dll,AtaPropPageProvider?????j?j?????????????????????????e??????el???????????????e???????j???.???????i?k????FSFilter Virtualization?????@%SystemRoot%\system32\drivers\ndis.sys,-201?????????????????j???????????n?k?n?n?j????$??j???4???????-???????????z??????????p????????????e???????????z?z?o??????????????????11?
Reg            HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Route                                ???jSv???j???j??????????????? ???????i???????????i?1????????????????????? h????????????????????j????? ???????i?????j???????1????????????????????? ?i???i???i???i???i???i???i???j???j???j???j????? ???????j???????????i?1????????????????????? ???????5???????k?????j????? ???????i?????j???????1????????????????????? ???????j???????????i?1?????????????????????????h???????????5?????????????????????????j????? ???????i?????j???????1????????????????????? ???????j???????????i?1?????????????????????????i???6??????7&21d63dca&0?7?????????????j??????8??j????????h?????mshdc.inf_x86_neutral_f64b9c35a3a5be81???????j?j?j?j?j?j?j????<??j????????h??????????&???????j???????h????b??j?????????n?????????????????????????????????????????f???????????????????????????t???j???e??????????????????????????????e???????????????????????????nettun.inf?00}??@%systemroot%\system32\DRIVERS\RDPCDD.sys,-100???????????????????????????e?g?n???j???????????????????????????????????????6?.17??????????????????????????????t?????X??????1???t?????????????????????
Reg            HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Export                              ????????Net?1}????????????????????m???????t?????????????????????*6to4mp? "???????????????t????,??????????????????????????????k???????k???????k??? ?????????????????????????????????e??????`??????k???c??? ???????|???????????d?:??????????%?&????????????????????B??MSAFD NetBIOS [\Device\NetBT_Tcpip6_{1EA6CF0A-FBE0-4912-993F-2E0D29FF0724}] SEQPACKET 3??r??MSAFD NetBIOS [\Device\NetBT_Tcpip6_{12F85669-41C3-43A6-9BD1-2D408BCE84F9}] DATAGRAM 70??A???????????-????????m??????????????????????????????????B??????????????Microsoft???????????????????????????????????????l???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{0460A44E-BF9B-4390-B541-6C61E6B57A13}] DATAGRAM 91?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????AC???????????????????0???????e?? ?@
Reg            HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Bind                                          ???f?????????????:???????????????f??*6to4mp??D??????or???j?j?????g?gMi??RasPppoe??????N?????????????????{8ECC055D-047F-11D1-A537-0000F8753ED1}?_10???f???s?s?s???????j????N??????????????????????i??????????????????04??PCI\VEN_197B&DEV_2380&REV_00?PCI\VEN_197B&DEV_2380?PCI\VEN_197B&CC_0C0010?PCI\VEN_197B&CC_0C00?PCI\VEN_197B?PCI\CC_0C0010?PCI\CC_0C00????????g?gMi???????????R?????sPC???f?f?f?f?f?f?f???????????e?e?e?e?e?e?e?e?e?f?f??Microsoft???????????.NT??????????f???????6???f???e??tunnel?CCA????|??i???????3???f?fr ??TDI??????????????4???4??????el???????k??????????????????HD???????f???v??se???????k????N??h????????D?????.NT??????????????????????????j?j?????g?ys????????????s?????sol???????????t?????s%\?????????????????s????????????? ??????? ???????4???f???????e??????????????????????????????????LegacyDriver?????????????f???j?j?f???????f??KSecDD?060???????????%??????????LegacyDriver?????f???????g???????????????????????????????????????????????f?f?i?i?f?i?:???/?l6???PCI\VEN_1022&DEV_1204&SUBSYS_00000000&REV_00?PCI\VE
Reg            HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Route                                        ???j?j????????????R??j????????h???????0??p???n?????eta??PnP Filter?????????????????g??????????????????????b??j?????????n????????????????????????@%SystemRoot%\system32\drivers\fltmgr.sys,-10000????????????????p???System32\drivers\hwpolicy.sys????j???j???j?????k?l??1.2.0.125????????q????T??j????????h????????j?j????????????????????????f????????????e????System32\Drivers\ksecdd.sys???????:??j????????h??????????j???0??e2???????????n??????????p???Fs_Rec?00????????j???????????j????????????????????????????????????????????????8??j????????h??????????????????d???????????????????????????5???F??????d6???? ??5??????p?????????????????????????b??j?????????n????.NT?ms??oem3.inf?????j??????????????????????????g???system32\DRIVERS\nwifi.sys???????????????????????v??????????????????????? ???f???\?????\To??????????%SystemRoot%\System32\srvsvc.dll??????L??p??????k???????????????t???text????System32\Drivers\ksecpkg.sys?????????????5??s????????????????????????j??????p????????????d?????????V2A???????j????????????????????????????m??k?
Reg            HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Export                                        ???j?j????????????????????????f????????????e????System32\Drivers\ksecdd.sys???????:??j????????h??????????j???0??e2???????????n??????????p???Fs_Rec?00????????j???????????j????????????????????????????????????????????????8??j????????h??????????????????d???????????????????????????5???F??????d6???? ??5??????p?????????????????????????b??j?????????n????.NT?ms??oem3.inf?????j??????????????????????????g???system32\DRIVERS\nwifi.sys???????????????????????v??????????????????????? ???f???\?????\To??????????%SystemRoot%\System32\srvsvc.dll??????L??p??????k???????????????t???text????System32\Drivers\ksecpkg.sys?????????????5??s????????????????????????j??????p????????????d?????????V2A???????j????????????????????????????m??k??????????????????????????HIDClass????????????????????????????????????p???Cryptography?????????j???????e????<??j????????h??????j??????????tunnel???????j???j???????????????????j?????j?n??????????????????????Maurice??????????h??@%SystemRoot%\system32\drivers\fileinfo.sys,-100?????????j???-??e5????X????????
Reg            HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Bind                                    ???j?n??????????????????????Maurice??????????h??@%SystemRoot%\system32\drivers\fileinfo.sys,-100?????????j???-??e5????X??????????e???s?z?s???????j???0???2?????? ??????g????????z.????P??j????????h?????@%SystemRoot%\system32\drivers\nsiproxy.sys,-2???????????????????????n??%m??%m??????????????RPCSS?????????8????????????e?????????j????<??j????????h??????????????????p???l???k??????????PNP_TDI??????????g???????????????????????k??????????Extended Base???????C0??????r???????????????Controls the underlying video driver stacks to provide fully-featured display capabilities.?????Keyboard Class???????????k???????????????????????????j??????????????????system32\drivers\nsiproxy.sys??????????????????????????????????????g?????????????????e???????j???9????????????????????????????Z??j?????????e????input.inf????f?h?j?g?t??\SystemRoot\system32\drivers\HDAudBus.sys??????j????system32\DRIVERS\kl1.sys?????????????????????????????????????s??rpcss???????????????????t???7616269602?8?<?????j?????u?u?u?????|?9?|????????t???????p????l?
Reg            HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Route                                    ???j????system32\DRIVERS\kl1.sys?????????????????????????????????????s??rpcss???????????????????t???7616269602?8?<?????j?????u?u?u?????|?9?|????????t???????p????l?x?}?}?}???????????m???p??????????????????????????????????????????t??????????????g?????????????s??*PNP09FF????sh???????k???????????????????h??????????????????????????????????????@%SystemRoot%\system32\drivers\mountmgr.sys,-101?????j?j?j?j?j?j?j??system32\drivers\ndis.sys????????????l??????????system32\drivers\MSPCLOCK.sys???s???Typ??????????????????n???????????????m?m?????????????????????s??????????????????t????j????????????????4??j?????????????????????????l?m???m?m?????????????+???+??NDIS Wrapper????\SystemRoot\system32\drivers\luafv.sys??????????????????????????????????????????????Microsoft????k?k????????????base????????????????t???t???????????????t????????????????????????f?f?j?j?j?j?j??????????????{0??????????????????????????????????????@%SystemRoot%\system32\drivers\fvevol.sys,-100????????2??j????????h??????????????????????????????.?????????????
Reg            HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Export                                  ???j?????u?u?u?????|?9?|????????t???????p????l?x?}?}?}???????????m???p??????????????????????????????????????????t??????????????g?????????????s??*PNP09FF????sh???????k???????????????????h??????????????????????????????????????@%SystemRoot%\system32\drivers\mountmgr.sys,-101?????j?j?j?j?j?j?j??system32\drivers\ndis.sys????????????l??????????system32\drivers\MSPCLOCK.sys???s???Typ??????????????????n???????????????m?m?????????????????????s??????????????????t????j????????????????4??j?????????????????????????l?m???m?m?????????????+???+??NDIS Wrapper????\SystemRoot\system32\drivers\luafv.sys??????????????????????????????????????????????Microsoft????k?k????????????base????????????????t???t???????????????t????????????????????????f?f?j?j?j?j?j??????????????{0??????????????????????????????????????@%SystemRoot%\system32\drivers\fvevol.sys,-100????????2??j????????h??????????????????????????????.?????????????j?k??\SystemRoot\system32\drivers\kbdhid.sys?????system32\DRIVERS\kl2.sys?????~???????????????j?????????????????????

---- EOF - GMER 1.0.15 ----

--- --- ---



OSAM

OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 13:37:37 on 04.07.2011

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 32-bit
Default Browser: Mozilla Corporation Firefox 5.0

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[AppInit DLLs]
-----( HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows )-----
"AppInit_DLLs" - "Kaspersky Lab ZAO" - C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll
"AppInit_DLLs" - "Kaspersky Lab ZAO" - C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll

[Boot Execute]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Session Manager )-----
"BootExecute" - ? - C:\Windows\system32\lsdelete.exe  (File found, but it contains no detailed information)

[Common]
-----( %SystemRoot%\Tasks )-----
"Ad-Aware Update (Weekly).job" - "Lavasoft Limited                                                      " - C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"PhysX.cpl" - "NVIDIA Corporation" - C:\Windows\system32\PhysX.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Pando" - "Pando Networks" - C:\Program Files\Pando Networks\Media Booster\PMB.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys  (File found, but it contains no detailed information)
"catchme" (catchme) - ? - C:\Users\Maurice\AppData\Local\Temp\catchme.sys  (File not found)
"EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys  (File not found)
"Lavasoft helper driver" (Lavasoft Kernexplorer) - ? - C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys  (File found, but it contains no detailed information)
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys  (File found, but it contains no detailed information)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"Profos" (Profos) - ? - C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\profos.sys  (File not found)

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
{872A9397-E0D6-4e28-B64D-52B8D0A7EA35} "DisplayCplExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamaxx.dll
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office12\ONFILTER.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - c:\program files\real\realplayer\rpshell.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{52B87208-9CCF-42C9-B88E-069281105805} "Trojan Remover Shell Extension" - ? -  (File not found | COM-object registry key not found)
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"eBay - Der weltweite Online-Marktplatz" - ? - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4  (HTTP value)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "&Windows Live Toolbar" - "Microsoft Corporation" - C:\Program Files\Windows Live\Toolbar\wltcore.dll
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{4248FE82-7FCB-46AC-B270-339F08212110} "&Virtuelle Tastatur" - "Kaspersky Lab ZAO" - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
"eBay - Der weltweite Online-Marktplatz" - ? - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4  (HTTP value)
"ICQ7.5" - "ICQ, LLC." - C:\Program Files\ICQ7.5\ICQ.exe
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "In Blog veröffentlichen" - "Microsoft Corporation" - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
{CCF151D8-D089-449F-A5A4-D9909053F20F} "Li&nks untersuchen" - "Kaspersky Lab ZAO" - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "&Windows Live Toolbar" - "Microsoft Corporation" - C:\Program Files\Windows Live\Toolbar\wltcore.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{E33CF602-D945-461A-83F0-819F76A199F8} "FilterBHO Class" - "Kaspersky Lab ZAO" - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} "IEVkbdBHO Class" - "Kaspersky Lab ZAO" - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{3049C3E9-B461-4BC5-8870-4C09146192CA} "RealPlayer Download and Record Plugin for Internet Explorer" - "RealPlayer" - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} "Search Helper" - "Microsoft Corporation" - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID-Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} "Windows Live Toolbar Helper" - "Microsoft Corporation" - C:\Program Files\Windows Live\Toolbar\wltcore.dll

[LSA Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )-----
"Security Packages" - "Microsoft Corporation" - C:\Windows\system32\livessp.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\Users\Maurice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"Adobe Gamma Loader.lnk" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"ICQ" - "ICQ, LLC." - "C:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4
"Logitech Vid" - "Logitech Inc." - "C:\Program Files\Logitech\Vid HD\Vid.exe" -bootmode
"SpybotSD TeaTimer" - "Safer Networking Limited" - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"AppleSyncNotifier" - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
"AVP" - "Kaspersky Lab ZAO" - "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
"CLMLServer" - "CyberLink" - "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
"HTC Sync Loader" - ? - "C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"LWS" - "Logitech Inc." - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"TkBellExe" - "RealNetworks, Inc." - "C:\Program Files\Real\RealPlayer\update\realsched.exe"  -osboot

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\Windows\system32\mdimon.dll
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"FABS - Helping agent for MAGIX media database" (Fabs) - "MAGIX AG" - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
"Internet Pass-Through Service" (PassThru Service) - ? - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"Kaspersky Anti-Virus Service" (AVP) - "Kaspersky Lab ZAO" - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
"Lavasoft Ad-Aware Service" (Lavasoft Ad-Aware Service) - "Lavasoft Limited" - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"nProtect GameGuard Service" (npggsvc) - "INCA Internet Co., Ltd." - C:\Windows\system32\GameMon.des
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"PnkBstrA" (PnkBstrA) - ? - C:\Windows\system32\PnkBstrA.exe  (File found, but it contains no detailed information)
"Protexis Licensing V2" (PSI_SVC_2) - "Protexis Inc." - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
"SBSD Security Center Service" (SBSDWSCService) - "Safer Networking Ltd." - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
"SeaPort" (SeaPort) - "Microsoft Corporation" - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
"WindowsLive Local NSP" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
"WindowsLive NSP" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru[/QUOTE]


MBR

Zitat:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: Service Pack 1 (build 7601), 32-bit
Base Board Manufacturer: MEDIONPC
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: MEDIONPC
System Product Name: MS-7646
Logical Drives Mask: 0x000000fc

Kernel Drivers (total 161):
0x83245000 \SystemRoot\system32\ntkrnlpa.exe
0x8320E000 \SystemRoot\system32\halmacpi.dll
0x80BC5000 \SystemRoot\system32\kdcom.dll
0x8C20A000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll
0x8C215000 \SystemRoot\system32\PSHED.dll
0x8C226000 \SystemRoot\system32\BOOTVID.dll
0x8C22E000 \SystemRoot\system32\CLFS.SYS
0x8C270000 \SystemRoot\system32\CI.dll
0x8C31B000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8C38C000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8C39A000 \SystemRoot\system32\drivers\ACPI.sys
0x8C3E2000 \SystemRoot\system32\drivers\WMILIB.SYS
0x8C3EB000 \SystemRoot\system32\drivers\msisadrv.sys
0x8C41F000 \SystemRoot\system32\drivers\pci.sys
0x8C449000 \SystemRoot\system32\drivers\vdrvroot.sys
0x8C454000 \SystemRoot\System32\drivers\partmgr.sys
0x8C465000 \SystemRoot\system32\drivers\volmgr.sys
0x8C475000 \SystemRoot\System32\drivers\volmgrx.sys
0x8C4C0000 \SystemRoot\system32\DRIVERS\amdide.sys
0x8C4C7000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x8C4D5000 \SystemRoot\System32\drivers\mountmgr.sys
0x8C4EB000 \SystemRoot\system32\drivers\atapi.sys
0x8C4F4000 \SystemRoot\system32\drivers\ataport.SYS
0x8C517000 \SystemRoot\system32\DRIVERS\amdsata.sys
0x8C528000 \SystemRoot\system32\DRIVERS\storport.sys
0x8C570000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x8C579000 \SystemRoot\system32\drivers\fltmgr.sys
0x8C5AD000 \SystemRoot\system32\drivers\fileinfo.sys
0x8C5BE000 \SystemRoot\system32\DRIVERS\Lbd.sys
0x8C60C000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8C73B000 \SystemRoot\System32\Drivers\msrpc.sys
0x8C766000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8C779000 \SystemRoot\System32\Drivers\cng.sys
0x8C7D6000 \SystemRoot\System32\drivers\pcw.sys
0x8C7E4000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8C830000 \SystemRoot\system32\drivers\ndis.sys
0x8C8E7000 \SystemRoot\system32\drivers\NETIO.SYS
0x8C925000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8CA0F000 \SystemRoot\System32\drivers\tcpip.sys
0x8CB59000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8CB8A000 \SystemRoot\system32\drivers\volsnap.sys
0x8CBC9000 \SystemRoot\System32\Drivers\spldr.sys
0x8CBD1000 \SystemRoot\System32\drivers\rdyboost.sys
0x8C94A000 \SystemRoot\System32\Drivers\mup.sys
0x8CC31000 \SystemRoot\system32\DRIVERS\kl1.sys
0x8D153000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8D15B000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x8D18D000 \SystemRoot\system32\DRIVERS\disk.sys
0x8D19E000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8D1C3000 \SystemRoot\system32\DRIVERS\AtiPcie.sys
0x8CC11000 \SystemRoot\system32\drivers\cdrom.sys
0x8C95A000 \SystemRoot\system32\DRIVERS\klif.sys
0x8D1F3000 \SystemRoot\System32\Drivers\Null.SYS
0x8CA00000 \SystemRoot\System32\Drivers\Beep.SYS
0x8C9DA000 \SystemRoot\System32\drivers\vga.sys
0x8C800000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8C821000 \SystemRoot\System32\drivers\watchdog.sys
0x8CA07000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8C9E6000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8C9EE000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8C7ED000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8C5CD000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8C5DB000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8C600000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x92A2C000 \SystemRoot\system32\drivers\afd.sys
0x92A86000 \SystemRoot\System32\DRIVERS\netbt.sys
0x92AB8000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x92ABF000 \SystemRoot\system32\DRIVERS\pacer.sys
0x92ADE000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x92AEF000 \SystemRoot\system32\DRIVERS\klim6.sys
0x92AF7000 \SystemRoot\system32\DRIVERS\netbios.sys
0x92B05000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x92B18000 \SystemRoot\system32\drivers\termdd.sys
0x92B29000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x92B6A000 \SystemRoot\system32\drivers\nsiproxy.sys
0x92B74000 \SystemRoot\system32\drivers\mssmbios.sys
0x92B7E000 \SystemRoot\System32\drivers\discache.sys
0x92B8A000 \SystemRoot\System32\Drivers\dfsc.sys
0x92BA2000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x92BB0000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x92BD1000 \SystemRoot\system32\DRIVERS\amdppm.sys
0x92A00000 \SystemRoot\system32\DRIVERS\atikmpag.sys
0x9300C000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x93601000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x936B8000 \SystemRoot\System32\drivers\dxgmms1.sys
0x936F1000 \SystemRoot\system32\drivers\HDAudBus.sys
0x93710000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x9376A000 \SystemRoot\system32\drivers\1394ohci.sys
0x93797000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x9379D000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x937A7000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x937F2000 \SystemRoot\system32\DRIVERS\usbfilter.sys
0x93588000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x93597000 \SystemRoot\system32\drivers\CompositeBus.sys
0x935A4000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x935B6000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x935CE000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x935D9000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x92BE2000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8C400000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x93A27000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x93A3E000 \SystemRoot\system32\drivers\kbdclass.sys
0x93A4B000 \SystemRoot\system32\drivers\mouclass.sys
0x93A58000 \SystemRoot\system32\drivers\swenum.sys
0x93A5A000 \SystemRoot\system32\drivers\ks.sys
0x93A8E000 \SystemRoot\system32\drivers\umbus.sys
0x93A9C000 \SystemRoot\system32\drivers\usbhub.sys
0x93AE0000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x93AF1000 \SystemRoot\system32\drivers\AtiHdmi.sys
0x93B0F000 \SystemRoot\system32\drivers\portcls.sys
0x93B3E000 \SystemRoot\system32\drivers\drmk.sys
0x94238000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x9450C000 \SystemRoot\system32\DRIVERS\RTL8192su.sys
0x945B5000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x945BF000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x945D6000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x945D8000 \SystemRoot\System32\Drivers\crashdmp.sys
0x945E5000 \SystemRoot\System32\Drivers\dump_diskdump.sys
0x945EF000 \SystemRoot\System32\Drivers\dump_amdsata.sys
0x94200000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x99A80000 \SystemRoot\System32\win32k.sys
0x94211000 \SystemRoot\System32\drivers\Dxapi.sys
0x9421B000 \SystemRoot\system32\DRIVERS\monitor.sys
0x93B57000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x94226000 \SystemRoot\system32\drivers\hidusb.sys
0x93B6E000 \SystemRoot\system32\drivers\HIDCLASS.SYS
0x94231000 \SystemRoot\system32\drivers\HIDPARSE.SYS
0x9D61E000 \SystemRoot\system32\DRIVERS\lvuvc.sys
0x9DA3F000 \SystemRoot\system32\drivers\usbaudio.sys
0x9DA53000 \SystemRoot\system32\DRIVERS\lvrs.sys
0x9DA99000 \SystemRoot\system32\drivers\kbdhid.sys
0x9DAA5000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x9DAB0000 \SystemRoot\system32\DRIVERS\klmouflt.sys
0x99CE0000 \SystemRoot\System32\TSDDD.dll
0x99D10000 \SystemRoot\System32\cdd.dll
0x9DAB9000 \SystemRoot\system32\drivers\luafv.sys
0x9DAD4000 \SystemRoot\system32\drivers\WudfPf.sys
0x9DAEE000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9DAFE000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x9DB44000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9DB54000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9DB67000 \SystemRoot\system32\DRIVERS\vwifimp.sys
0x9DB70000 \SystemRoot\system32\drivers\HTTP.sys
0x9D600000 \SystemRoot\system32\DRIVERS\bowser.sys
0x93B81000 \SystemRoot\System32\drivers\mpsdrv.sys
0x93B93000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x93BB6000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x93A00000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9D619000 \SystemRoot\system32\DRIVERS\lirsgt.sys
0xA382B000 \SystemRoot\system32\drivers\peauth.sys
0xA38C2000 \SystemRoot\System32\Drivers\secdrv.SYS
0xA38CC000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xA38ED000 \SystemRoot\System32\drivers\tcpipreg.sys
0xA38FA000 \SystemRoot\System32\DRIVERS\srv2.sys
0xA394A000 \SystemRoot\System32\DRIVERS\srv.sys
0xA399C000 \SystemRoot\System32\drivers\ipnat.sys
0xA39C2000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0xA39E3000 \??\C:\Windows\system32\drivers\mbam.sys
0x76EC0000 \Windows\System32\ntdll.dll
0x475B0000 \Windows\System32\smss.exe
0x77100000 \Windows\System32\apisetschema.dll

Processes (total 67):
0 System Idle Process
4 System
352 C:\Windows\System32\smss.exe
496 csrss.exe
580 C:\Windows\System32\wininit.exe
592 csrss.exe
632 C:\Windows\System32\services.exe
652 C:\Windows\System32\lsass.exe
660 C:\Windows\System32\lsm.exe
744 C:\Windows\System32\winlogon.exe
816 C:\Windows\System32\svchost.exe
892 C:\Windows\System32\svchost.exe
956 C:\Windows\System32\atiesrxx.exe
1016 C:\Windows\System32\svchost.exe
1056 C:\Windows\System32\svchost.exe
1088 C:\Windows\System32\svchost.exe
1128 C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
1272 C:\Windows\System32\svchost.exe
1348 C:\Windows\System32\atieclxx.exe
1572 C:\Windows\System32\dwm.exe
1604 C:\Windows\explorer.exe
1788 C:\Windows\System32\spoolsv.exe
1800 C:\Windows\System32\taskhost.exe
1848 C:\Windows\System32\svchost.exe
1936 C:\Windows\System32\svchost.exe
1992 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
300 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
716 C:\Program Files\Bonjour\mDNSResponder.exe
908 C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
1320 C:\Windows\System32\svchost.exe
1600 C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
116 C:\Windows\System32\PnkBstrA.exe
2076 C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
2100 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2152 C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
2192 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
2208 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
2308 C:\Windows\System32\svchost.exe
2400 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
2444 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
2564 C:\Program Files\iTunes\iTunesHelper.exe
2584 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
2596 C:\Program Files\Real\RealPlayer\Update\realsched.exe
2808 C:\Program Files\Windows Sidebar\sidebar.exe
2860 C:\Program Files\ICQ7.5\ICQ.exe
2900 C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
3236 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
4032 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
3344 C:\Program Files\Mozilla Firefox\firefox.exe
2476 C:\Program Files\Mozilla Firefox\plugin-container.exe
4072 C:\Program Files\iPod\bin\iPodService.exe
2892 C:\Windows\System32\alg.exe
1764 C:\Windows\System32\SearchIndexer.exe
4140 C:\Windows\System32\taskhost.exe
4236 C:\Program Files\Windows Media Player\wmpnetwk.exe
4276 WUDFHost.exe
5652 C:\Windows\System32\svchost.exe
4216 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
3204 C:\Windows\System32\svchost.exe
2728 C:\Windows\System32\svchost.exe
4356 <unknown>
5840 <unknown>
3728 C:\Windows\explorer.exe
1400 C:\Windows\System32\audiodg.exe
3272 C:\Users\Maurice\Desktop\MBRCheck.exe
5212 C:\Windows\System32\conhost.exe
5464 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000158`10c00000 (NTFS)

PhysicalDrive0 Model Number: WDCWD15EARS-00Z5B1, Rev: 80.00A80

Size Device Name MBR Status
--------------------------------------------
1397 GB \\.\PhysicalDrive0

Warum lagt mein Rechner jetzt nach den durchläufen von den drei Programmen?
Das hat er vorher nicht..-.-
Und ich habe die drei Logs so gepostet, weil das in einem Quote Fenster zu unübersichtlich wäre. Nehme ich mal an.

cosinus 04.07.2011 14:00

Zitat:

Size Device Name MBR Status
--------------------------------------------
1397 GB \\.\PhysicalDrive0
Log von mbrcheck ist unvollständig!

Zitat:

Warum lagt mein Rechner jetzt nach den durchläufen von den drei Programmen?
Könnte an GMER liegen. Windows schon neu gestartet?

Maurice 04.07.2011 14:57

Ja, habe ihn schon neu gestartet.
Als der Pc automtisch neu gestartet hat nachdem der MBRCheck durchgelaufen ist, ist er nicht richtig hochgefahren also hat Windows nicht gestartet...bei deiner Anweisung steht ja auch das das nur ein paar Sekunden dauern soll. Was es aber nicht tat.
lg

cosinus 04.07.2011 15:38

Zitat:

Als der Pc automtisch neu gestartet hat nachdem der MBRCheck durchgelaufen ist, ist er nicht richtig hochgefahren also hat Windows nicht gestartet...
Äh, nach mbrcheck startet Windows jetzt nicht mehr? :confused:
Hast du nur das Log gemacht oder irgendwelche Fixaktionen?

Maurice 04.07.2011 17:48

Eigentlich nur das Log so wie beschrieben.

Eine Frage an der Seite, würde der Trojaner auf eine externe Festplatte übergehen wenn ich eine anschließe? Dann würde ich wenn wir zu keinem Ergebniss kommen sollten meinen Rechner formatieren, aber wie das geht wüsste ich jetzt auch nicht 100% -.-.

cosinus 04.07.2011 19:40

Du willst jetzt so kurz vorm Abschluss doch alles plätten und neumachen? :confused:

Maurice 04.07.2011 20:13

Nein, will ich nicht^^ das war nur eine Frage. Ich kann ja nicht wissen das das bald fertig ist ;) habe ja keine Ahnung ;)
Also kommen wir zum eigentlich Thema zurück. Wie geht es denn jetzt weiter? Ich bin froh wenn ich das Teil wieder los bin oO

cosinus 04.07.2011 20:41

Edit. hast du mbrcheck per Rechtsklick als Admin ausgeführt? Wenn nicht würde das erklären warum zum Schluss keine brauchbare Ausgabe da steht.

Maurice 04.07.2011 21:29

Ich werde es einfach nochmal machen.

Maurice 04.07.2011 22:54

Windows startet immer noch nicht..

Wenn ich jetzt eine externe Festplatte anschließe, könnte es dann passieren das der Trojaner dann auch auf die Festplatte über geht?

cosinus 04.07.2011 23:00

Häh?? :confused:
Wie kannst du mbrcheck "wieder probieren" wenn Windows "immer noch nicht" startet!
Haben wir aneinander vorbei geredet?! Erst hieß der Rechner wäre nur langsam nach den drei Tools, dann irgendwie Windows startet nicht (oder doch?) - kannst du bitte mal klare Angaben machen?

Maurice 04.07.2011 23:36

Also, der Rechner ist nach dem die drei Tools durchgelaufen sind langsamer geworden. Das ist eine Sache.

Wenn ich jetzt den MBRChecker starte läuft er durch und dann startet er automatisch den Rechner neu. Er startet zwar neu, aber nur bis zu dem Punkt wo Windows normalerweise startet was es nicht tut. Wenn ich den Rechner dann aus mache und wieder an mache fährt er wieder normal hoch.

cosinus 05.07.2011 07:27

Wir sollten den MBR manuell fixen. Sichere für den Fall der Fälle alle wichtigen Daten.

Hast Du noch andere Betriebssysteme außer Win7 (32-Bit) installiert?
Wenn nicht: Schau mal hier => RescueDisc-Win7-32-Bit

Lad das iso runter, brenn es zB mit ImgBurn per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten)

Falls Du eine normale Win7-Installations-DVD (32-Bit) hast, brauchst Du das o.g. Image nicht sondern kannst einfach von der dieser DVD booten.

Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen. Erstell danach wieder neue Logs mit MBRCheck und wenn es geht GMER.

Maurice 05.07.2011 11:41

Also kann ich eine extern Festplatte ohne Bedenken an meinen Rechner anschließen?
Ich habe beide Win7 Dvd's also 32 und 64.

cosinus 05.07.2011 14:00

Zitat:

Also kann ich eine extern Festplatte ohne Bedenken an meinen Rechner anschließen?
Deaktivier vorher die automatische Wiedergabe komplett => Einstellungen für automatische Wiedergabe ändern

Zitat:

Ich habe beide Win7 Dvd's also 32 und 64.
Für deinen MBR-Fix brauchst du eine normale Installations-DVD 32-Bit.

Maurice 05.07.2011 17:58

Mir ist gerade eingefallen das ich ein Backup mit meiner externen Festplatte ausgeführt habe also eine Sicherung von der internen Platte mit Windows etc. könnte man nicht im Prinzip auch einfach eine Wiederherstellung der Dateien machen, damit der Trojaner nicht mehr da ist?

Maurice 05.07.2011 19:50

Ich muss mir erst DVD s kaufen...

cosinus 06.07.2011 11:04

Zitat:

Ich muss mir erst DVD s kaufen...
Und welchen Sinn macht die Aussage von dir vorher? => Ich habe beide Win7 Dvd's also 32 und 64. :stirn: :dummguck:

Nimm für den MBR-Fix die von mir verlinkte ISO-Datei.

Maurice 06.07.2011 11:13

Weil ich angenommen habe das das mit einer von beiden geht ;)

cosinus 06.07.2011 12:31

Äh, du hast aber geschrieben du hast beide bei dir und jetzt nicht? Sry kann ich nicht folgen... :balla:

Maurice 06.07.2011 20:11

Als ich eben booten wollte, habe ich ausversehen das System auf die Werkseinstellungen zurückgesetzt. Also alle Dateien gelöscht auser die die schon vorher auf dem Rechner drauf waren. Eben eine Suche mit Kaspersky durchgeführt und Kaspersky hat keinen Trojaner gefunden.
Anfangs war es eher ungewollt aber als ich immer weiter gegangen bin habe ich mir gedacht, was solls wird schon bzw. kann nicht weiter schaden.
Soll ich jetzt noch irgendwelche Untersuchungen mit Programmen zur Sicherheit durchführen oder ist die Sache jetzt gegessen?

Und ich möchte mich bei Ihnen recht herzlich für Ihre Hilfe bedanken und dafür das Sie mich unterstützt haben.

Mit freundlichen Grüßen Maurice :)

cosinus 06.07.2011 20:35

Wenn es auf Werkseinstellungen zurückgesetzt ist, sollte wieder alles ok sein.
Melde dich einfach nochmal hier falls es doch noch die gleichen Probleme gibt.

Maurice 07.07.2011 01:27

Zitat:

06.07.2011 20:20:17 Gefunden legales Programm, das von einem Angreifer benutzt werden kann, um den Computer oder die Benutzerdaten zu beschädigen HiddenObject.Multi.Generic C:\Users\All Users\Kaspersky Lab\AVP11\SysWHist\amlogs\76 Mittel
Das hat Kaspersky nochmal angezeigt, könnte das bedrohlich sein. Und weißt du was ich dagegen machen könnte? ;)

cosinus 07.07.2011 09:08

Zitat:

C:\Users\All Users\Kaspersky Lab\AVP11\SysWHist\amlogs\76 Mittel
Nicht jede Pupmeldung muss man ernst nehmen. Kaspersky bemängelt da was in seinem eigenen Ordne :balla: außerdem hast du ja eh recovert.

Maurice 07.07.2011 09:10

Okay danke ;)


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:09 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131