Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Stealer.exe - System jetzt in Ordnung? (https://www.trojaner-board.de/103745-stealer-exe-system-ordnung.html)

ErichZann 29.09.2011 17:21

Stealer.exe - System jetzt in Ordnung?
 
Hallo!

Ich habe folgendes Problem: Ich wollte mir neulich eine neue Version einer ICQ banner remover software runterladen, aber hab das wohl leider nicht von der offiziellen Seite gemacht, sondern einfach über google gesucht - schön blöd.

Bei der Ausführung (ich verwende Windows 7, 64 bit, als eingeschränkter User) wollte das mein Admin-Passwort haben, was nicht ungewöhnlich ist, wenn an Programmdateien etwas verändert werden muss. Ich habe es also eingeben, und sofort kam eine Fundmeldung von Avast. Die Details weiß ich leider nicht mehr, weil ich recht schnell auf "Löschen" gedrückt habe, aber es wurde irgendwas mit "Stealer.exe" angezeigt. Nach dem Löschen habe ich nichts auffälliges bemerkt.

Auch wenn ich weiß, dass das nicht unbedingt etwas bringen muss, habe ich sofort eine Systemwiederherstellung ausgeführt (nicht die letzte, sondern etwas älter, ca. 1 Woche). Danach habe ich dann Malewarebytes installiert, und einen vollständigen Scan durchgeführt, auch einen im abgesicherten Modus, und dann mit Avast nochmal einen vollständigen Scan, und einen Boot-Time-Scan. Bei all diesen Scans wurde weder in den Dateien, der Registrierung oder den laufenden Prozessen etwas entdeckt.

Kann ich dann davon ausgehen, dass alles ok ist? Oder sollte ich sonst noch etwas überprüfen? Ich weiß nicht, wie gut Avast wirklich die Ausführung von sowas verhindern kann, aber ich weiß auch nicht, ob man direkt neu installieren sollte, wenn man nichtmal einen Hinweis hat, dass der Virus je wirklich installiert wurde...


Grüße!

ErichZann 29.09.2011 18:55

Oh, ein kleines Update: Habe grad in Avast geguckt, da kann man den Log von dem Fund noch sehen (ist der einzige Eintrag bei Dateisystem-Schutz):

C:\Users\Benutzername\AppData\Local\Temp\Stealer.exe
Bedrohung: Win32:Inject-ZH [Drp]


Grüße und danke!

cosinus 29.09.2011 19:52

Bitte alle Logs von Malwarebytes posten auch wenn keine Funde dabei sind.

ErichZann 29.09.2011 20:39

Ok, hier sind zwei Logs von den Scans:


Zitat:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7783

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

23.09.2011 23:25:58
mbam-log-2011-09-23 (23-25-58).txt

Scan type: Full scan (C:\|)
Objects scanned: 524062
Time elapsed: 55 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Zitat:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7783

Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 9.0.8112.16421

24.09.2011 09:07:03
mbam-log-2011-09-24 (09-07-03).txt

Scan type: Quick scan
Objects scanned: 216635
Time elapsed: 1 minute(s), 44 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

cosinus 29.09.2011 20:50

Die Scans sind ja schon fast ne Woche her. Mach bitte ein Update der Signaturen von Malwarebytes, dann einen neues Vollscan.

ErichZann 29.09.2011 21:41

Naja, das war direkt nachdem das passiert ist, und danach war ich ein paar Tage nicht zuhause... in dem Sinne ist das eigentlich aktuell, aber gut, ich kann gleich nochmal einen neuen Schnellscan machen...

EDIT: So, hier mal ein neuer Schnellscan. Aber wie gesagt, ich würde die Scans oben schon als aktuell ansehen, war halt direkt nachdem es passiert war, mit den damals neusten Definitionen... Sonst könnte man ja immer sagen, dass man ein paar Wochen warten soll, bis es neue Definitionen gibt... oder seh ich das falsch?

Grüße!

Zitat:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7829

Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 9.0.8112.16421

29.09.2011 22:46:08
mbam-log-2011-09-29 (22-46-08).txt

Scan type: Quick scan
Objects scanned: 218130
Time elapsed: 1 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


EDIT2: Vollscan gibts morgen früh, so lange bin ich heute nicht mehr wach.

cosinus 29.09.2011 22:08

Wieso Quickscan? Ich wollte einen neuen Vollscan sehen.

ErichZann 30.09.2011 06:21

Guten morgen, hier kommt der Scan:

Zitat:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7829

Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 9.0.8112.16421

29.09.2011 23:56:00
mbam-log-2011-09-29 (23-56-00).txt

Scan type: Full scan (C:\|)
Objects scanned: 532491
Time elapsed: 34 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

cosinus 30.09.2011 09:43

Führ bitte auch ESET aus, danach sehen wir weiter:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


ErichZann 01.10.2011 08:24

hi, hier kommt der eset log:

Zitat:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=2e2099035754ed42b2de10dc548dd22f
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-09-30 10:41:35
# local_time=2011-10-01 12:41:35 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=768 16777215 100 0 51409459 51409459 0 0
# compatibility_mode=5893 16776574 100 94 14183641 69039534 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=607081
# found=0
# cleaned=0
# scan_time=12810

cosinus 01.10.2011 21:01

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


ErichZann 02.10.2011 10:39

Guten morgen, hier ist der OTL log:

OTL Logfile:
Code:

OTL logfile created on: 02.10.2011 11:17:49 - Run 1
OTL by OldTimer - Version 3.2.29.1    Folder = C:\Users\Name\Downloads
64bit- An unknown product Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,91 Gb Available Physical Memory | 72,70% Memory free
8,00 Gb Paging File | 6,88 Gb Available in Paging File | 86,10% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 146,39 Gb Total Space | 77,39 Gb Free Space | 52,87% Space Free | Partition Type: NTFS
Drive D: | 785,03 Gb Total Space | 383,94 Gb Free Space | 48,91% Space Free | Partition Type: NTFS
Drive E: | 1863,01 Gb Total Space | 646,09 Gb Free Space | 34,68% Space Free | Partition Type: NTFS
 
Computer Name: Name | User Name: Benutzername1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.10.02 11:15:22 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Name\Downloads\OTL.exe
PRC - [2011.09.06 22:45:30 | 003,722,416 | ---- | M] (AVAST Software) -- C:\Programme\Alwil Software\Avast5\AvastUI.exe
PRC - [2011.09.06 22:45:28 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Programme\Alwil Software\Avast5\AvastSvc.exe
PRC - [2011.08.15 13:59:16 | 000,890,880 | ---- | M] (Ray Adams) -- C:\Program Files (x86)\ATI Tray Tools\atitray.exe
PRC - [2010.03.11 15:06:06 | 000,193,824 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2009.12.21 09:00:50 | 000,081,920 | ---- | M] (Realtime Soft Ltd) -- C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
PRC - [2009.10.22 06:00:04 | 000,395,824 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe
PRC - [2009.10.22 05:59:58 | 000,113,200 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
PRC - [2009.10.22 05:59:48 | 000,334,384 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe
PRC - [2009.10.22 04:47:54 | 000,563,760 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2009.02.23 11:43:54 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.02.19 23:14:48 | 000,187,904 | ---- | M] () -- C:\Program Files (x86)\ATI Tray Tools\raphook.dll
MOD - [2008.04.11 18:33:18 | 000,020,480 | ---- | M] () -- C:\Program Files (x86)\ATI Tray Tools\plugins\mg_intelcpu.dll
MOD - [2008.04.09 18:08:46 | 000,016,896 | ---- | M] () -- C:\Program Files (x86)\ATI Tray Tools\plugins\mg_amdcore.dll
MOD - [2007.09.14 17:35:34 | 000,020,480 | ---- | M] () -- C:\Program Files (x86)\ATI Tray Tools\plugins\mg_cpuload.dll
MOD - [2007.03.07 14:26:34 | 000,077,824 | ---- | M] () -- C:\Program Files (x86)\ATI Tray Tools\support.dll
MOD - [2007.03.07 14:25:26 | 000,024,576 | ---- | M] () -- C:\Program Files (x86)\ATI Tray Tools\kbdhook.dll
MOD - [2007.01.03 22:09:46 | 000,017,408 | ---- | M] () -- C:\Program Files (x86)\ATI Tray Tools\plugins\mg_xvlt.dll
MOD - [2006.12.26 19:53:28 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\ATI Tray Tools\plugins\mg_hdddtemp.dll
MOD - [2006.12.25 11:02:24 | 000,024,576 | ---- | M] () -- C:\Program Files (x86)\ATI Tray Tools\plugins\mongraphsexample.dll
MOD - [2005.11.29 19:38:20 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\ATI Tray Tools\plugins\hddtemp.dll
MOD - [2005.11.29 19:34:38 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\ATI Tray Tools\plugins\pciset.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2011.09.06 22:45:28 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2011.07.28 23:35:34 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011.07.28 17:43:58 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2010.05.07 19:45:16 | 000,197,976 | ---- | M] (Logitech Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe -- (LVPrcS64)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011.08.12 19:28:17 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.04.20 08:30:25 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2010.12.06 09:31:50 | 002,101,640 | ---- | M] (LogMeIn Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2010.06.09 17:31:25 | 002,480,048 | ---- | M] (Acronis) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2010.03.27 16:09:22 | 001,054,568 | ---- | M] (Acronis) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2010.03.11 15:06:06 | 000,193,824 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.10.27 10:26:36 | 000,657,408 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009.10.22 06:00:04 | 000,395,824 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2009.10.22 05:59:58 | 000,113,200 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService)
SRV - [2009.10.22 05:59:48 | 000,334,384 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2009.10.22 04:47:54 | 000,563,760 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe -- (VMUSBArbService)
SRV - [2009.10.12 15:32:24 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe -- (ufad-ws60)
SRV - [2009.07.26 06:43:14 | 000,025,832 | ---- | M] (BioWare) [On_Demand | Stopped] -- D:\Spiele\Dragon Age\bin_ship\daupdatersvc.service.exe -- (DAUpdaterSvc)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.02.23 11:43:54 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2011.09.06 22:38:18 | 000,601,944 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2011.09.06 22:38:16 | 000,301,912 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2011.09.06 22:36:41 | 000,058,200 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2011.09.06 22:36:41 | 000,042,328 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr.sys -- (aswRdr)
DRV:64bit: - [2011.09.06 22:36:30 | 000,065,368 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2011.09.06 22:36:14 | 000,024,408 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2011.07.29 00:23:16 | 009,980,416 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2011.07.29 00:23:16 | 009,980,416 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011.07.28 22:54:10 | 000,309,248 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011.07.11 12:36:25 | 000,272,992 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2011.06.07 00:07:00 | 000,231,440 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.12.17 00:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010.12.01 21:06:31 | 000,125,512 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AnyDVD.sys -- (AnyDVD)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 12:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010.11.10 03:45:54 | 004,162,784 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64) Logitech QuickCam Pro 9000(UVC)
DRV:64bit: - [2010.11.10 03:44:24 | 000,341,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2010.06.09 17:31:27 | 000,252,512 | ---- | M] (Acronis) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp)
DRV:64bit: - [2010.06.09 17:31:25 | 001,477,728 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm258.sys -- (tdrpman258) Acronis Try&Decide and Restore Points filter (build 258)
DRV:64bit: - [2010.06.09 17:31:19 | 000,943,712 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2010.05.07 19:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon)
DRV:64bit: - [2010.05.07 19:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64)
DRV:64bit: - [2010.05.05 21:30:52 | 001,561,688 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ha20x2k.sys -- (ha20x2k)
DRV:64bit: - [2010.05.05 21:30:42 | 000,118,360 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\emupia2k.sys -- (emupia)
DRV:64bit: - [2010.05.05 21:30:34 | 000,213,080 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV:64bit: - [2010.05.05 21:30:26 | 000,015,960 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV:64bit: - [2010.05.05 21:30:18 | 000,179,288 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctoss2k.sys -- (ossrv)
DRV:64bit: - [2010.05.05 21:30:10 | 000,684,376 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)
DRV:64bit: - [2010.05.05 21:30:02 | 000,580,696 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctac32k.sys -- (ctac32k)
DRV:64bit: - [2010.05.05 21:29:52 | 001,417,304 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX.SYS)
DRV:64bit: - [2010.05.05 21:29:52 | 001,417,304 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX)
DRV:64bit: - [2010.05.05 21:29:42 | 000,094,808 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT.SYS)
DRV:64bit: - [2010.05.05 21:29:42 | 000,094,808 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT)
DRV:64bit: - [2010.05.05 21:29:34 | 000,202,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT.SYS)
DRV:64bit: - [2010.05.05 21:29:34 | 000,202,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT)
DRV:64bit: - [2010.02.18 10:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2010.01.08 12:03:25 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009.10.22 06:01:10 | 000,080,944 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
DRV:64bit: - [2009.10.22 06:01:06 | 000,018,480 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\VMparport.sys -- (VMparport)
DRV:64bit: - [2009.10.22 06:01:04 | 000,029,744 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VMkbd.sys -- (vmkbd)
DRV:64bit: - [2009.10.22 06:00:58 | 000,068,144 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
DRV:64bit: - [2009.10.22 06:00:56 | 000,030,256 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2009.10.22 04:47:50 | 000,038,960 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:64bit: - [2009.10.22 01:13:34 | 000,037,680 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmusb.sys -- (vmusb)
DRV:64bit: - [2009.10.22 01:13:28 | 000,045,104 | R--- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2009.10.22 01:13:28 | 000,020,016 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2009.10.06 12:54:18 | 000,008,704 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64j.sys -- (UsbserFilt)
DRV:64bit: - [2009.10.06 12:53:56 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdcx64)
DRV:64bit: - [2009.10.06 12:53:56 | 000,008,704 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev)
DRV:64bit: - [2009.10.06 12:53:54 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcdx64)
DRV:64bit: - [2009.10.02 00:18:44 | 000,031,232 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2009.09.30 16:34:30 | 000,121,872 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009.09.11 12:49:18 | 000,076,552 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmXlCore.sys -- (WmXlCore)
DRV:64bit: - [2009.09.11 12:49:08 | 000,015,880 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmVirHid.sys -- (WmVirHid)
DRV:64bit: - [2009.09.11 12:48:58 | 000,036,872 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmHidLo.sys -- (WmHidLo)
DRV:64bit: - [2009.09.11 12:48:46 | 000,041,096 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmFilter.sys -- (WmFilter)
DRV:64bit: - [2009.09.11 12:48:36 | 000,026,248 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmBEnum.sys -- (WmBEnum)
DRV:64bit: - [2009.08.28 19:42:52 | 000,049,152 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2009.07.30 13:58:42 | 000,236,544 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009.07.17 20:52:00 | 000,201,472 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 02:01:09 | 000,679,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xnacc.sys -- (xnacc)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009.04.03 07:39:58 | 000,034,872 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:64bit: - [2008.08.28 12:44:42 | 000,025,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2007.04.17 12:51:50 | 000,014,112 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\regi.sys -- (regi)
DRV - [2011.06.24 06:31:02 | 000,055,424 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Programme\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.01)
DRV - [2010.12.01 21:06:31 | 000,125,512 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2009.10.12 15:31:04 | 000,032,816 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys -- (vstor2-ws60)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2008.11.14 03:11:42 | 000,020,512 | ---- | M] (Realtime Soft Ltd) [Kernel | Auto | Running] -- C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys -- (UltraMonUtility)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 46 BB 5A F3 A3 7F CC 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.09.27 22:45:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.07.30 02:50:27 | 000,000,000 | ---D | M]
 
[2009.12.04 04:46:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benutzername1\AppData\Roaming\mozilla\Extensions
[2009.12.04 04:46:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benutzername1\AppData\Roaming\mozilla\Firefox\Profiles\5czwg713.default\extensions
[2011.09.23 22:07:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010.06.12 10:05:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.10.29 22:48:56 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011.02.09 21:44:03 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.03.23 00:05:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.05.27 13:07:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011.06.21 18:26:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011.09.23 22:07:29 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011.09.27 22:45:02 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.07.19 05:05:25 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.09.23 22:04:26 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.09.23 22:04:26 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.09.23 22:04:26 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.09.23 22:04:26 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.23 22:04:26 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.09.23 22:04:26 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.05.26 21:37:54 | 000,000,856 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15116/CTPID.cab (Creative Software AutoUpdate Support Package 1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6715E457-8360-4B58-ACE8-49C8C8B187D1}: DhcpNameServer = 134.245.10.7 134.245.1.36
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A07F6A0B-06C6-4A24-9CD5-5755D6279919}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{68706b28-e040-11de-9af8-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{68706b28-e040-11de-9af8-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Run.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
MsConfig:64bit - StartUpFolder: C:^Users^Benutzername1^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ATI Tray Tools.lnk - C:\Program Files (x86)\ATI Tray Tools\atitray.exe - (Ray Adams)
MsConfig:64bit - StartUpFolder: C:^Users^Benutzername1^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Produktregistrierung.lnk - C:\Program Files (x86)\Logitech\Ereg\eReg.exe - (Leader Technologies/Logitech)
MsConfig:64bit - StartUpReg: Acronis Scheduler2 Service - hkey= - key= - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: AdobeAAMUpdater-1.0 - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: AdobeCS5ServiceManager - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: AnyDVD - hkey= - key= - C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVD.exe (SlySoft, Inc.)
MsConfig:64bit - StartUpReg: BDRegion - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: boincmgr - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: boinctray - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: BrMfcWnd - hkey= - key= - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
MsConfig:64bit - StartUpReg: ControlCenter3 - hkey= - key= - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
MsConfig:64bit - StartUpReg: CTxfiHlp - hkey= - key= - C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)
MsConfig:64bit - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
MsConfig:64bit - StartUpReg: Eraser - hkey= - key= - C:\Programme\Eraser\Eraser.exe (The Eraser Project)
MsConfig:64bit - StartUpReg: GrooveMonitor - hkey= - key= - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
MsConfig:64bit - StartUpReg: ICQ - hkey= - key= - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
MsConfig:64bit - StartUpReg: ISUSPM Startup - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: LightScribe Control Panel - hkey= - key= - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
MsConfig:64bit - StartUpReg: LogitechQuickCamRibbon - hkey= - key= - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
MsConfig:64bit - StartUpReg: LogMeIn Hamachi Ui - hkey= - key= - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
MsConfig:64bit - StartUpReg: LWS - hkey= - key= - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
MsConfig:64bit - StartUpReg: PDVD8LanguageShortcut - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: RemoteControl8 - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: RtHDVCpl - hkey= - key= - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
MsConfig:64bit - StartUpReg: Start WingMan Profiler - hkey= - key= - C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
MsConfig:64bit - StartUpReg: StartCCC - hkey= - key= - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
MsConfig:64bit - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig:64bit - StartUpReg: SwitchBoard - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: TrueImageMonitor.exe - hkey= - key= - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
MsConfig:64bit - StartUpReg: vmware-tray - hkey= - key= - C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
MsConfig:64bit - State: "startup" - Reg Error: Key error.
 
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: Hamachi2Svc - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {D9449623-CF8F-3361-83F6-609BD53FA221} - Internet Explorer
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.VMnc - C:\Windows\SysWow64\vmnc.dll (VMware, Inc.)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.09.28 19:33:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Schwedisch AKTIV
[2011.09.25 11:23:27 | 000,000,000 | ---D | C] -- C:\Program Files\UltraVNC
[2011.09.23 22:28:17 | 000,000,000 | ---D | C] -- C:\Users\Benutzername1\AppData\Roaming\Malwarebytes
[2011.09.23 22:28:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2011.09.23 22:28:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.09.23 22:28:08 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011.09.23 22:28:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2011.09.23 22:07:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011.09.18 13:02:02 | 000,000,000 | R--D | C] -- C:\Users\Benutzername1\AppData\Roaming\Brother
[2011.09.11 13:00:12 | 000,000,000 | ---D | C] -- C:\Users\Benutzername1\AppData\Roaming\atitray
[2011.09.11 12:58:41 | 000,000,000 | ---D | C] -- C:\Users\Benutzername1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ATI Tray Tools
[2011.09.11 12:58:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Tray Tools
[2011.09.11 12:53:40 | 000,000,000 | ---D | C] -- C:\Users\Benutzername1\AppData\Local\AMD
[2011.09.11 11:46:47 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2011.09.11 11:45:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2011.09.11 11:45:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2011.09.11 11:44:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
[2011.09.11 11:44:49 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2011.09.11 11:42:00 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2011.01.16 13:37:21 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Benutzername1\AppData\Roaming\pcouffin.sys
[2010.05.05 19:59:10 | 000,060,928 | ---- | C] ( ) -- C:\Windows\SysWow64\a3d.dll
[2010.05.05 19:38:18 | 000,012,800 | ---- | C] ( ) -- C:\Windows\SysWow64\killapps.exe
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.10.02 11:20:21 | 000,013,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.10.02 11:20:21 | 000,013,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.10.02 11:17:35 | 001,480,120 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.10.02 11:17:35 | 000,646,312 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.10.02 11:17:35 | 000,609,676 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.10.02 11:17:35 | 000,127,398 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.10.02 11:17:35 | 000,104,580 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.10.02 11:13:47 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.10.02 11:13:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.10.02 11:13:02 | 3220,037,632 | -HS- | M] () -- C:\hiberfil.sys
[2011.10.01 11:38:39 | 000,061,344 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000003-00000000-00000006-00001102-00000005-00211102}.rfx
[2011.10.01 11:38:39 | 000,061,344 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000003-00000000-00000006-00001102-00000005-00211102}.rfx
[2011.10.01 11:38:39 | 000,001,080 | ---- | M] () -- C:\Windows\SysNative\settingsbkup.sfm
[2011.10.01 11:38:39 | 000,001,080 | ---- | M] () -- C:\Windows\SysNative\settings.sfm
[2011.10.01 11:38:39 | 000,000,788 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000003-00000000-00000006-00001102-00000005-00211102}.rfx
[2011.10.01 10:59:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.09.25 17:57:33 | 000,000,425 | ---- | M] () -- C:\Windows\BRWMARK.INI
[2011.09.23 22:09:20 | 000,000,490 | ---- | M] () -- C:\Users\Public\Desktop\VPN to Chalmers.lnk
[2011.09.23 21:44:10 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2011.09.06 22:45:29 | 000,199,304 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2011.09.06 22:45:29 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2011.09.06 22:45:17 | 000,254,400 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2011.09.06 22:38:18 | 000,601,944 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2011.09.06 22:38:16 | 000,301,912 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2011.09.06 22:36:41 | 000,058,200 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2011.09.06 22:36:41 | 000,042,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2011.09.06 22:36:30 | 000,065,368 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2011.09.06 22:36:14 | 000,024,408 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.09.23 22:09:20 | 000,000,490 | ---- | C] () -- C:\Users\Public\Desktop\VPN to Chalmers.lnk
[2011.09.23 22:03:36 | 000,001,198 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB R2010a.lnk
[2011.09.23 22:02:55 | 000,002,060 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware Workstation.lnk
[2011.09.23 22:00:33 | 000,001,018 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Allway Sync.lnk
[2011.09.23 21:59:53 | 000,002,581 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Camtasia Recorder.lnk
[2011.09.23 21:59:17 | 000,001,602 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech Webcam Software.lnk
[2011.09.11 13:31:37 | 000,002,585 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UltraMon.lnk
[2011.05.12 20:27:00 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.04.20 08:29:21 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2011.04.20 08:29:21 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.03.18 20:11:12 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2011.03.17 19:51:44 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.01.16 13:37:21 | 000,099,384 | ---- | C] () -- C:\Users\Benutzername1\AppData\Roaming\inst.exe
[2011.01.16 13:37:21 | 000,007,859 | ---- | C] () -- C:\Users\Benutzername1\AppData\Roaming\pcouffin.cat
[2011.01.16 13:37:21 | 000,001,167 | ---- | C] () -- C:\Users\Benutzername1\AppData\Roaming\pcouffin.inf
[2010.12.27 09:37:05 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010.12.26 18:56:53 | 000,074,752 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2010.12.26 18:53:50 | 000,917,504 | ---- | C] () -- C:\Windows\SysWow64\dtsdecoderdll.dll
[2010.12.26 18:53:50 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll
[2010.12.24 18:18:13 | 000,003,766 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2010.12.24 18:18:13 | 000,000,008 | RHS- | C] () -- C:\ProgramData\CA8A93C200.sys
[2010.11.10 03:45:32 | 000,102,744 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2010.11.10 03:45:30 | 010,871,128 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2010.11.10 03:45:20 | 000,316,248 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2010.07.14 22:43:03 | 000,000,600 | ---- | C] () -- C:\Users\Benutzername1\AppData\Local\PUTTY.RND
[2010.05.05 20:37:52 | 000,021,204 | ---- | C] () -- C:\Windows\SysWow64\instwdm.ini
[2010.05.05 20:37:50 | 000,000,054 | ---- | C] () -- C:\Windows\SysWow64\ctzapxx.ini
[2010.05.05 19:56:46 | 000,002,560 | ---- | C] () -- C:\Windows\SysWow64\CtxfiRes.dll
[2010.05.05 19:46:30 | 000,321,512 | ---- | C] () -- C:\Windows\SysWow64\ctdlang.dat
[2010.05.05 19:46:30 | 000,056,509 | ---- | C] () -- C:\Windows\SysWow64\ctdnlstr.dat
[2010.05.05 19:38:22 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\enlocstr.exe
[2009.12.23 22:46:24 | 000,000,021 | ---- | C] () -- C:\Windows\progman.ini
[2009.12.13 17:43:13 | 000,003,072 | ---- | C] () -- C:\Windows\SysWow64\CTXFIGER.DLL
[2009.12.05 04:52:19 | 001,499,556 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009.12.04 17:36:14 | 000,003,328 | ---- | C] () -- C:\Windows\ulead32.ini
[2009.12.04 05:01:01 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2009.12.04 04:33:47 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009.08.27 09:04:12 | 000,207,400 | R--- | C] () -- C:\Windows\GSetup.exe
[2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009.05.27 10:49:00 | 000,000,285 | ---- | C] () -- C:\Windows\SysWow64\kill.ini
[2008.10.07 09:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\SysWow64\physxcudart_20.dll
[2008.10.07 09:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll
 
========== LOP Check ==========
 
[2010.06.09 17:34:45 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Acronis
[2011.03.18 19:31:39 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Canon
[2010.01.08 12:02:41 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\DAEMON Tools Lite
[2010.09.08 19:35:07 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\FileOpen
[2009.12.23 22:46:13 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\HaCon
[2011.05.26 21:36:15 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\ICQ
[2009.12.05 05:20:06 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Leadertech
[2011.04.03 18:06:55 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\ManyCam
[2010.03.18 16:08:49 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Nokia
[2009.12.04 17:48:34 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Pegasys Inc
[2009.12.04 20:04:35 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\scar5
[2011.02.02 11:10:43 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Steinberg
[2011.05.06 20:29:42 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\TightVNC
[2010.02.18 22:31:08 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\TrueCrypt
[2011.01.16 13:37:21 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Vso
[2011.08.30 06:13:01 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.06.09 17:34:45 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Acronis
[2010.09.08 19:35:06 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Adobe
[2010.12.26 19:05:30 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\ArcSoft
[2009.12.04 04:34:16 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\ATI
[2011.09.11 13:00:12 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\atitray
[2011.09.18 13:02:02 | 000,000,000 | R--D | M] -- C:\Users\Benutzername1\AppData\Roaming\Brother
[2011.03.18 19:31:39 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Canon
[2011.04.20 08:50:45 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Creative
[2010.12.24 17:19:45 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\CyberLink
[2010.01.08 12:02:41 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\DAEMON Tools Lite
[2010.09.08 19:35:07 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\FileOpen
[2009.12.23 22:46:13 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\HaCon
[2011.05.26 21:36:15 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\ICQ
[2009.12.04 04:23:51 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Identities
[2011.07.14 23:56:23 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\InstallShield Installation Information
[2009.12.05 05:20:06 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Leadertech
[2010.01.21 20:15:17 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Macromedia
[2011.09.23 22:28:17 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Malwarebytes
[2011.04.03 18:06:55 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\ManyCam
[2009.12.04 21:30:00 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Mathematica
[2009.07.14 20:18:34 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Media Center Programs
[2011.04.23 14:42:46 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Media Player Classic
[2010.12.20 00:12:57 | 000,000,000 | --SD | M] -- C:\Users\Benutzername1\AppData\Roaming\Microsoft
[2011.05.14 13:56:35 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\MiKTeX
[2009.12.04 04:46:03 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Mozilla
[2011.02.26 10:44:11 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\NCH Software
[2010.03.18 16:08:49 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Nokia
[2009.12.04 17:48:34 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Pegasys Inc
[2010.01.21 17:31:54 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Realtime Soft
[2009.12.04 20:04:35 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\scar5
[2011.02.02 11:10:43 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Steinberg
[2011.05.06 20:29:42 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\TightVNC
[2010.02.18 22:31:08 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\TrueCrypt
[2011.01.16 13:37:21 | 000,000,000 | ---D | M] -- C:\Users\Benutzername1\AppData\Roaming\Vso
 
< %APPDATA%\*.exe /s >
[2011.01.16 13:37:21 | 000,099,384 | ---- | M] () -- C:\Users\Benutzername1\AppData\Roaming\inst.exe
[2011.07.14 23:48:39 | 000,331,776 | ---- | M] () -- C:\Users\Benutzername1\AppData\Roaming\InstallShield Installation Information\{FDBBAF14-5ED8-49B7-A5BE-1C35668B074D}\SetupUT3.exe
[2010.12.09 17:56:10 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Benutzername1\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2010.10.02 21:06:49 | 001,288,704 | ---- | M] () -- C:\Users\Benutzername1\AppData\Roaming\MiKTeX\2.9\miktex\bin\miktex-taskbar-icon.exe
[2010.10.02 21:06:49 | 001,288,704 | ---- | M] () -- C:\Users\Benutzername1\AppData\Roaming\MiKTeX\2.9\miktex\bin\miktex-update.exe
[2010.10.02 21:06:51 | 001,288,704 | ---- | M] () -- C:\Users\Benutzername1\AppData\Roaming\MiKTeX\2.9\miktex\bin\miktex-update_admin.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2007.01.23 17:22:16 | 000,032,890 | ---- | M] () MD5=4FA5D1120762802A741F374F8B391E69 -- C:\Program Files\MATLAB\R2010a\sys\perl\win32\lib\auto\Win32\EventLog\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< End of report >

--- --- ---

cosinus 02.10.2011 13:06

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{68706b28-e040-11de-9af8-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{68706b28-e040-11de-9af8-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Run.exe
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

ErichZann 02.10.2011 22:03

Darf ich fragen, was dieser Fix macht? Ich finde da irgendwie nirgendwo Informationen drüber? Und kannst du vielleicht kurz ein Statement abgeben, was du bisher denkst, wie aussagekräftig das ist, dass die Scanner bisher gar nichts gefunden haben?

Ich bin da etwas vorsichtig, jetzt einfach mit solchen Fixes am System rumzuwerkeln, wenn ich nicht weiß, was da genau passiert... Oder passiert da nichts großartiges?

Grüße

cosinus 04.10.2011 15:07

CDROM-Autorun wird deaktiviert, müllige Moinpointeinträge werden entfernt, Tempordner geleert, Hosts zurückgesetzt.

Wenn ich dir jeden Fix zuerst verständlich machen muss, wird das hier eine lange Geschichte. Du musst deinen Helfern schon vertrauen...

ErichZann 04.10.2011 19:59

Ok danke, habe es jetzt aufgeführt, hier kommt der Log.

Grüße

Zitat:

All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{68706b28-e040-11de-9af8-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{68706b28-e040-11de-9af8-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{68706b28-e040-11de-9af8-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{68706b28-e040-11de-9af8-806e6f6e6963}\ not found.
File D:\Run.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 35979085 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: ErichZann
->Temp folder emptied: 68401451 bytes
->Temporary Internet Files folder emptied: 16302683 bytes
->Java cache emptied: 9201175 bytes
->FireFox cache emptied: 38193602 bytes
->Flash cache emptied: 790 bytes

User: Benutzername2
->Temp folder emptied: 28068790 bytes
->Temporary Internet Files folder emptied: 10591136 bytes
->Java cache emptied: 144624 bytes
->FireFox cache emptied: 367161142 bytes
->Flash cache emptied: 3924 bytes

User: Public

User: Name
->Temp folder emptied: 150377584 bytes
->Temporary Internet Files folder emptied: 41507855 bytes
->Java cache emptied: 1 bytes
->FireFox cache emptied: 52287466 bytes
->Flash cache emptied: 115 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 311296 bytes
%systemroot%\System32 .tmp files removed: 1619120 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 594600886 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67899 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1.349,00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.29.1 log created on 10042011_205316

Files\Folders moved on Reboot...
File move failed. C:\Users\Name\AppData\Local\Temp\vmware-Name\manifest.txt.1 scheduled to be moved on reboot.
File move failed. C:\Users\Name\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.
File\Folder C:\Users\Name\AppData\Local\Temp\~DFF120C5559F8F7084.TMP not found!
C:\Windows\temp\vmware-SYSTEM\vmware-usbarb-SYSTEM-2300.log moved successfully.

Registry entries deleted on Reboot...

cosinus 04.10.2011 21:48

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

ErichZann 05.10.2011 07:44

Ok, hier kommt der log. Der eine "Fund" gehört anscheinend zu daemon tools, was ich bei mir installiert habe.

Grüße

Zitat:

08:39:27.0695 4664 TDSS rootkit removing tool 2.6.4.0 Oct 3 2011 17:37:01
08:39:27.0914 4664 ============================================================
08:39:27.0914 4664 Current date / time: 2011/10/05 08:39:27.0914
08:39:27.0914 4664 SystemInfo:
08:39:27.0914 4664
08:39:27.0914 4664 OS Version: 6.1.7601 ServicePack: 1.0
08:39:27.0914 4664 Product type: Workstation
08:39:27.0914 4664 ComputerName: Name
08:39:27.0914 4664 UserName: ErichZann
08:39:27.0914 4664 Windows directory: C:\Windows
08:39:27.0914 4664 System windows directory: C:\Windows
08:39:27.0914 4664 Running under WOW64
08:39:27.0914 4664 Processor architecture: Intel x64
08:39:27.0914 4664 Number of processors: 4
08:39:27.0914 4664 Page size: 0x1000
08:39:27.0914 4664 Boot type: Normal boot
08:39:27.0914 4664 ============================================================
08:39:28.0912 4664 Initialize success
08:40:12.0374 3692 ============================================================
08:40:12.0374 3692 Scan started
08:40:12.0374 3692 Mode: Manual; SigCheck; TDLFS;
08:40:12.0374 3692 ============================================================
08:40:12.0842 3692 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
08:40:13.0013 3692 1394ohci - ok
08:40:13.0029 3692 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
08:40:13.0045 3692 ACPI - ok
08:40:13.0076 3692 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
08:40:13.0123 3692 AcpiPmi - ok
08:40:13.0169 3692 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
08:40:13.0185 3692 adp94xx - ok
08:40:13.0216 3692 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
08:40:13.0232 3692 adpahci - ok
08:40:13.0247 3692 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
08:40:13.0263 3692 adpu320 - ok
08:40:13.0294 3692 afcdp (d9a76e6e541e2e61c78140b65db63e6a) C:\Windows\system32\DRIVERS\afcdp.sys
08:40:28.0426 3692 afcdp - ok
08:40:28.0489 3692 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
08:40:28.0535 3692 AFD - ok
08:40:28.0551 3692 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
08:40:28.0567 3692 agp440 - ok
08:40:28.0582 3692 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
08:40:28.0598 3692 aliide - ok
08:40:28.0629 3692 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
08:40:28.0660 3692 amdide - ok
08:40:28.0707 3692 amdiox64 (6a2eeb0c4133b20773bb3dd0b7b377b4) C:\Windows\system32\DRIVERS\amdiox64.sys
08:40:28.0738 3692 amdiox64 - ok
08:40:28.0754 3692 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
08:40:28.0785 3692 AmdK8 - ok
08:40:28.0925 3692 amdkmdag (5b03217859b014b090cb5060c1d96875) C:\Windows\system32\DRIVERS\atikmdag.sys
08:40:29.0113 3692 amdkmdag - ok
08:40:29.0128 3692 amdkmdap (35d2184a99ad4cd5d17284d6c9f382c9) C:\Windows\system32\DRIVERS\atikmpag.sys
08:40:29.0159 3692 amdkmdap - ok
08:40:29.0175 3692 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
08:40:29.0191 3692 AmdPPM - ok
08:40:29.0222 3692 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
08:40:29.0237 3692 amdsata - ok
08:40:29.0253 3692 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
08:40:29.0253 3692 amdsbs - ok
08:40:29.0269 3692 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
08:40:29.0284 3692 amdxata - ok
08:40:29.0362 3692 AnyDVD (821e7e501226ee344fdb0f40ee46109d) C:\Windows\system32\Drivers\AnyDVD.sys
08:40:29.0409 3692 AnyDVD - ok
08:40:29.0471 3692 AODDriver4.01 (f312fad7dbd49ed21a194ac71b497832) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
08:40:29.0518 3692 AODDriver4.01 - ok
08:40:29.0549 3692 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
08:40:29.0627 3692 AppID - ok
08:40:29.0690 3692 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
08:40:29.0705 3692 arc - ok
08:40:29.0721 3692 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
08:40:29.0721 3692 arcsas - ok
08:40:29.0752 3692 aswFsBlk (5a68b880c16ad5a6aa20b49a47ffff24) C:\Windows\system32\drivers\aswFsBlk.sys
08:40:29.0783 3692 aswFsBlk - ok
08:40:29.0830 3692 aswMonFlt (230613be2d3da8053879be5ed2848f2d) C:\Windows\system32\drivers\aswMonFlt.sys
08:40:29.0861 3692 aswMonFlt - ok
08:40:29.0877 3692 aswRdr (0dc1996ae4178d7d14744ef6b3082313) C:\Windows\system32\drivers\aswRdr.sys
08:40:29.0893 3692 aswRdr - ok
08:40:29.0955 3692 aswSnx (b6ff911c23775cdfdd49612d92637af4) C:\Windows\system32\drivers\aswSnx.sys
08:40:30.0002 3692 aswSnx - ok
08:40:30.0017 3692 aswSP (5a590d8516376aed1829fc07d3bdaa4b) C:\Windows\system32\drivers\aswSP.sys
08:40:30.0033 3692 aswSP - ok
08:40:30.0049 3692 aswTdi (3239c0082fb0c1c4ee323730b85690a5) C:\Windows\system32\drivers\aswTdi.sys
08:40:30.0064 3692 aswTdi - ok
08:40:30.0095 3692 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
08:40:30.0173 3692 AsyncMac - ok
08:40:30.0205 3692 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
08:40:30.0205 3692 atapi - ok
08:40:30.0267 3692 AtiHDAudioService (dbb487d09f56c674430ac454fd8bcab9) C:\Windows\system32\drivers\AtihdW76.sys
08:40:30.0314 3692 AtiHDAudioService - ok
08:40:30.0361 3692 AtiHdmiService (fb7602c5c508be281368aae0b61b51c6) C:\Windows\system32\drivers\AtiHdmi.sys
08:40:30.0392 3692 AtiHdmiService - ok
08:40:30.0579 3692 atikmdag (5b03217859b014b090cb5060c1d96875) C:\Windows\system32\DRIVERS\atikmdag.sys
08:40:30.0673 3692 atikmdag - ok
08:40:30.0719 3692 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
08:40:30.0766 3692 b06bdrv - ok
08:40:30.0797 3692 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
08:40:30.0844 3692 b57nd60a - ok
08:40:30.0860 3692 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
08:40:30.0922 3692 Beep - ok
08:40:31.0156 3692 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
08:40:31.0203 3692 blbdrive - ok
08:40:31.0250 3692 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
08:40:31.0265 3692 bowser - ok
08:40:31.0297 3692 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
08:40:31.0312 3692 BrFiltLo - ok
08:40:31.0328 3692 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
08:40:31.0328 3692 BrFiltUp - ok
08:40:31.0359 3692 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
08:40:31.0390 3692 Brserid - ok
08:40:31.0406 3692 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
08:40:31.0453 3692 BrSerWdm - ok
08:40:31.0453 3692 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
08:40:31.0484 3692 BrUsbMdm - ok
08:40:31.0499 3692 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
08:40:31.0531 3692 BrUsbSer - ok
08:40:31.0531 3692 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
08:40:31.0562 3692 BTHMODEM - ok
08:40:31.0593 3692 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
08:40:31.0609 3692 cdfs - ok
08:40:31.0655 3692 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
08:40:31.0687 3692 cdrom - ok
08:40:31.0702 3692 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
08:40:31.0733 3692 circlass - ok
08:40:31.0765 3692 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
08:40:31.0780 3692 CLFS - ok
08:40:31.0796 3692 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
08:40:31.0827 3692 CmBatt - ok
08:40:31.0858 3692 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
08:40:31.0858 3692 cmdide - ok
08:40:31.0905 3692 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
08:40:31.0952 3692 CNG - ok
08:40:31.0967 3692 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
08:40:31.0967 3692 Compbatt - ok
08:40:31.0983 3692 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
08:40:32.0014 3692 CompositeBus - ok
08:40:32.0030 3692 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
08:40:32.0045 3692 crcdisk - ok
08:40:32.0061 3692 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
08:40:32.0092 3692 CSC - ok
08:40:32.0123 3692 CT20XUT (229e3b8f266abdafd54e4a372b9d5ddc) C:\Windows\system32\drivers\CT20XUT.SYS
08:40:32.0139 3692 CT20XUT - ok
08:40:32.0155 3692 CT20XUT.SYS (229e3b8f266abdafd54e4a372b9d5ddc) C:\Windows\System32\drivers\CT20XUT.SYS
08:40:32.0170 3692 CT20XUT.SYS - ok
08:40:32.0201 3692 ctac32k (eb3843a91a10150c9e05607cbcb44090) C:\Windows\system32\drivers\ctac32k.sys
08:40:32.0217 3692 ctac32k - ok
08:40:32.0233 3692 ctaud2k (bc06efb59a2316537765462dfe40f764) C:\Windows\system32\drivers\ctaud2k.sys
08:40:32.0248 3692 ctaud2k - ok
08:40:32.0279 3692 CTEXFIFX (63b2b6ce9d3ef182981fb64bd5433da4) C:\Windows\system32\drivers\CTEXFIFX.SYS
08:40:32.0295 3692 CTEXFIFX - ok
08:40:32.0311 3692 CTEXFIFX.SYS (63b2b6ce9d3ef182981fb64bd5433da4) C:\Windows\System32\drivers\CTEXFIFX.SYS
08:40:32.0342 3692 CTEXFIFX.SYS - ok
08:40:32.0357 3692 CTHWIUT (6d115cc80873b85fd80dda1c41f75a2c) C:\Windows\system32\drivers\CTHWIUT.SYS
08:40:32.0357 3692 CTHWIUT - ok
08:40:32.0373 3692 CTHWIUT.SYS (6d115cc80873b85fd80dda1c41f75a2c) C:\Windows\System32\drivers\CTHWIUT.SYS
08:40:32.0373 3692 CTHWIUT.SYS - ok
08:40:32.0389 3692 ctprxy2k (ebc9548ef5838cb5aa8f18b3ac28af12) C:\Windows\system32\drivers\ctprxy2k.sys
08:40:32.0404 3692 ctprxy2k - ok
08:40:32.0420 3692 ctsfm2k (459bee1682121842285c162e2d98d81a) C:\Windows\system32\drivers\ctsfm2k.sys
08:40:32.0420 3692 ctsfm2k - ok
08:40:32.0482 3692 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
08:40:32.0545 3692 DfsC - ok
08:40:32.0576 3692 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
08:40:32.0638 3692 discache - ok
08:40:32.0669 3692 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
08:40:32.0669 3692 Disk - ok
08:40:32.0716 3692 DRIVER_B - ok
08:40:32.0763 3692 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
08:40:32.0810 3692 drmkaud - ok
08:40:32.0857 3692 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
08:40:32.0872 3692 DXGKrnl - ok
08:40:32.0950 3692 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
08:40:33.0028 3692 ebdrv - ok
08:40:33.0059 3692 ElbyCDIO (a05fc7eca0966ebb70e4d17b855a853b) C:\Windows\system32\Drivers\ElbyCDIO.sys
08:40:33.0075 3692 ElbyCDIO - ok
08:40:33.0091 3692 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
08:40:33.0137 3692 elxstor - ok
08:40:33.0153 3692 emupia (c26133b6165928fbd156c6fe570f9ed2) C:\Windows\system32\drivers\emupia2k.sys
08:40:33.0153 3692 emupia - ok
08:40:33.0184 3692 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
08:40:33.0231 3692 ErrDev - ok
08:40:33.0262 3692 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
08:40:33.0309 3692 exfat - ok
08:40:33.0325 3692 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
08:40:33.0356 3692 fastfat - ok
08:40:33.0387 3692 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
08:40:33.0387 3692 fdc - ok
08:40:33.0418 3692 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
08:40:33.0418 3692 FileInfo - ok
08:40:33.0434 3692 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
08:40:33.0481 3692 Filetrace - ok
08:40:33.0481 3692 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
08:40:33.0496 3692 flpydisk - ok
08:40:33.0527 3692 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
08:40:33.0543 3692 FltMgr - ok
08:40:33.0543 3692 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
08:40:33.0559 3692 FsDepends - ok
08:40:33.0574 3692 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
08:40:33.0574 3692 Fs_Rec - ok
08:40:33.0605 3692 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
08:40:33.0637 3692 fvevol - ok
08:40:33.0652 3692 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
08:40:33.0668 3692 gagp30kx - ok
08:40:33.0683 3692 gdrv - ok
08:40:33.0715 3692 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
08:40:33.0715 3692 GEARAspiWDM - ok
08:40:33.0793 3692 ha20x2k (a3f010d5dbfb589a3b3288c05c2ea3f9) C:\Windows\system32\drivers\ha20x2k.sys
08:40:33.0839 3692 ha20x2k - ok
08:40:33.0855 3692 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys
08:40:33.0871 3692 hamachi - ok
08:40:33.0886 3692 hcmon (8cdad7b707ddd77d45588f74d59c9aff) C:\Windows\system32\drivers\hcmon.sys
08:40:33.0886 3692 hcmon - ok
08:40:33.0902 3692 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
08:40:33.0917 3692 hcw85cir - ok
08:40:33.0964 3692 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
08:40:33.0980 3692 HdAudAddService - ok
08:40:34.0011 3692 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
08:40:34.0058 3692 HDAudBus - ok
08:40:34.0058 3692 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
08:40:34.0073 3692 HidBatt - ok
08:40:34.0089 3692 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
08:40:34.0151 3692 HidBth - ok
08:40:34.0151 3692 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
08:40:34.0167 3692 HidIr - ok
08:40:34.0214 3692 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
08:40:34.0245 3692 HidUsb - ok
08:40:34.0276 3692 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
08:40:34.0292 3692 HpSAMD - ok
08:40:34.0323 3692 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
08:40:34.0385 3692 HTTP - ok
08:40:34.0417 3692 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
08:40:34.0417 3692 hwpolicy - ok
08:40:34.0448 3692 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
08:40:34.0448 3692 i8042prt - ok
08:40:34.0495 3692 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
08:40:34.0510 3692 iaStorV - ok
08:40:34.0526 3692 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
08:40:34.0541 3692 iirsp - ok
08:40:34.0588 3692 IntcAzAudAddService (f04d22d7a49a1b2210dbadf0b803e870) C:\Windows\system32\drivers\RTKVHD64.sys
08:40:34.0619 3692 IntcAzAudAddService - ok
08:40:34.0651 3692 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
08:40:34.0651 3692 intelide - ok
08:40:34.0666 3692 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
08:40:34.0697 3692 intelppm - ok
08:40:34.0729 3692 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
08:40:34.0791 3692 IpFilterDriver - ok
08:40:34.0807 3692 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
08:40:34.0822 3692 IPMIDRV - ok
08:40:34.0822 3692 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
08:40:34.0869 3692 IPNAT - ok
08:40:34.0900 3692 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
08:40:34.0916 3692 IRENUM - ok
08:40:34.0947 3692 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
08:40:34.0947 3692 isapnp - ok
08:40:34.0978 3692 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
08:40:34.0994 3692 iScsiPrt - ok
08:40:35.0009 3692 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
08:40:35.0025 3692 kbdclass - ok
08:40:35.0041 3692 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
08:40:35.0056 3692 kbdhid - ok
08:40:35.0056 3692 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
08:40:35.0072 3692 KSecDD - ok
08:40:35.0103 3692 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
08:40:35.0119 3692 KSecPkg - ok
08:40:35.0119 3692 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
08:40:35.0150 3692 ksthunk - ok
08:40:35.0197 3692 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
08:40:35.0243 3692 lltdio - ok
08:40:35.0275 3692 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
08:40:35.0275 3692 LSI_FC - ok
08:40:35.0290 3692 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
08:40:35.0306 3692 LSI_SAS - ok
08:40:35.0306 3692 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
08:40:35.0321 3692 LSI_SAS2 - ok
08:40:35.0337 3692 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
08:40:35.0337 3692 LSI_SCSI - ok
08:40:35.0368 3692 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
08:40:35.0431 3692 luafv - ok
08:40:35.0477 3692 LVPr2M64 (b3944d06eb4b64d57bd7e5fe89415f58) C:\Windows\system32\DRIVERS\LVPr2M64.sys
08:40:35.0509 3692 LVPr2M64 - ok
08:40:35.0524 3692 LVPr2Mon (b3944d06eb4b64d57bd7e5fe89415f58) C:\Windows\system32\DRIVERS\LVPr2M64.sys
08:40:35.0540 3692 LVPr2Mon - ok
08:40:35.0571 3692 LVRS64 (803085f59ec92b3827cc4d90fcbfd335) C:\Windows\system32\DRIVERS\lvrs64.sys
08:40:35.0587 3692 LVRS64 - ok
08:40:35.0680 3692 LVUVC64 (a8d7c97016e6b76ef472a4c7ab357ee3) C:\Windows\system32\DRIVERS\lvuvc64.sys
08:40:35.0743 3692 LVUVC64 - ok
08:40:35.0758 3692 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
08:40:35.0774 3692 megasas - ok
08:40:35.0789 3692 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
08:40:35.0789 3692 MegaSR - ok
08:40:35.0805 3692 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
08:40:35.0852 3692 Modem - ok
08:40:35.0867 3692 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
08:40:35.0899 3692 monitor - ok
08:40:35.0914 3692 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
08:40:35.0930 3692 mouclass - ok
08:40:35.0945 3692 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
08:40:35.0992 3692 mouhid - ok
08:40:36.0023 3692 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
08:40:36.0039 3692 mountmgr - ok
08:40:36.0055 3692 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
08:40:36.0070 3692 mpio - ok
08:40:36.0086 3692 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
08:40:36.0117 3692 mpsdrv - ok
08:40:36.0148 3692 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
08:40:36.0211 3692 MRxDAV - ok
08:40:36.0242 3692 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
08:40:36.0304 3692 mrxsmb - ok
08:40:36.0335 3692 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
08:40:36.0367 3692 mrxsmb10 - ok
08:40:36.0398 3692 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
08:40:36.0413 3692 mrxsmb20 - ok
08:40:36.0429 3692 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
08:40:36.0445 3692 msahci - ok
08:40:36.0460 3692 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
08:40:36.0460 3692 msdsm - ok
08:40:36.0491 3692 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
08:40:36.0507 3692 Msfs - ok
08:40:36.0523 3692 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
08:40:36.0601 3692 mshidkmdf - ok
08:40:36.0616 3692 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
08:40:36.0632 3692 msisadrv - ok
08:40:36.0663 3692 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
08:40:36.0679 3692 MSKSSRV - ok
08:40:36.0710 3692 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
08:40:36.0741 3692 MSPCLOCK - ok
08:40:36.0757 3692 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
08:40:36.0835 3692 MSPQM - ok
08:40:36.0866 3692 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
08:40:36.0913 3692 MsRPC - ok
08:40:36.0928 3692 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
08:40:36.0928 3692 mssmbios - ok
08:40:36.0944 3692 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
08:40:36.0991 3692 MSTEE - ok
08:40:37.0006 3692 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
08:40:37.0037 3692 MTConfig - ok
08:40:37.0053 3692 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
08:40:37.0069 3692 Mup - ok
08:40:37.0084 3692 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
08:40:37.0115 3692 NativeWifiP - ok
08:40:37.0147 3692 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
08:40:37.0178 3692 NDIS - ok
08:40:37.0193 3692 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
08:40:37.0225 3692 NdisCap - ok
08:40:37.0256 3692 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
08:40:37.0271 3692 NdisTapi - ok
08:40:37.0303 3692 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
08:40:37.0334 3692 Ndisuio - ok
08:40:37.0365 3692 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
08:40:37.0427 3692 NdisWan - ok
08:40:37.0443 3692 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
08:40:37.0474 3692 NDProxy - ok
08:40:37.0505 3692 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
08:40:37.0537 3692 NetBIOS - ok
08:40:37.0568 3692 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
08:40:37.0599 3692 NetBT - ok
08:40:37.0630 3692 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
08:40:37.0646 3692 nfrd960 - ok
08:40:37.0677 3692 nmwcdcx64 (4b300dc9b143c99674b6ecd917384155) C:\Windows\system32\drivers\ccdcmbox64.sys
08:40:37.0724 3692 nmwcdcx64 - ok
08:40:37.0739 3692 nmwcdx64 (dd1d06c2a7e048766482256ab8c755cf) C:\Windows\system32\drivers\ccdcmbx64.sys
08:40:37.0771 3692 nmwcdx64 - ok
08:40:37.0786 3692 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
08:40:37.0817 3692 Npfs - ok
08:40:37.0817 3692 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
08:40:37.0864 3692 nsiproxy - ok
08:40:37.0927 3692 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
08:40:38.0005 3692 Ntfs - ok
08:40:38.0020 3692 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
08:40:38.0051 3692 Null - ok
08:40:38.0083 3692 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
08:40:38.0098 3692 nvraid - ok
08:40:38.0114 3692 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
08:40:38.0129 3692 nvstor - ok
08:40:38.0161 3692 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
08:40:38.0161 3692 nv_agp - ok
08:40:38.0192 3692 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
08:40:38.0239 3692 ohci1394 - ok
08:40:38.0270 3692 ossrv (0e2de427ebe106e7e5b52869d5c99f68) C:\Windows\system32\drivers\ctoss2k.sys
08:40:38.0285 3692 ossrv - ok
08:40:38.0317 3692 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
08:40:38.0332 3692 Parport - ok
08:40:38.0348 3692 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
08:40:38.0348 3692 partmgr - ok
08:40:38.0395 3692 pccsmcfd (bc0018c2d29f655188a0ed3fa94fdb24) C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
08:40:38.0426 3692 pccsmcfd - ok
08:40:38.0457 3692 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
08:40:38.0473 3692 pci - ok
08:40:38.0488 3692 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
08:40:38.0504 3692 pciide - ok
08:40:38.0519 3692 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
08:40:38.0535 3692 pcmcia - ok
08:40:38.0535 3692 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
08:40:38.0551 3692 pcw - ok
08:40:38.0582 3692 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
08:40:38.0629 3692 PEAUTH - ok
08:40:38.0675 3692 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
08:40:38.0738 3692 PptpMiniport - ok
08:40:38.0753 3692 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
08:40:38.0769 3692 Processor - ok
08:40:38.0816 3692 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
08:40:38.0831 3692 Psched - ok
08:40:38.0894 3692 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
08:40:38.0941 3692 ql2300 - ok
08:40:38.0956 3692 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
08:40:38.0972 3692 ql40xx - ok
08:40:38.0987 3692 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
08:40:39.0003 3692 QWAVEdrv - ok
08:40:39.0019 3692 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
08:40:39.0081 3692 RasAcd - ok
08:40:39.0112 3692 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
08:40:39.0143 3692 RasAgileVpn - ok
08:40:39.0175 3692 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
08:40:39.0237 3692 Rasl2tp - ok
08:40:39.0237 3692 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
08:40:39.0268 3692 RasPppoe - ok
08:40:39.0299 3692 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
08:40:39.0315 3692 RasSstp - ok
08:40:39.0346 3692 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
08:40:39.0377 3692 rdbss - ok
08:40:39.0393 3692 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
08:40:39.0409 3692 rdpbus - ok
08:40:39.0409 3692 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
08:40:39.0440 3692 RDPCDD - ok
08:40:39.0471 3692 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
08:40:39.0502 3692 RDPDR - ok
08:40:39.0533 3692 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
08:40:39.0580 3692 RDPENCDD - ok
08:40:39.0580 3692 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
08:40:39.0611 3692 RDPREFMP - ok
08:40:39.0643 3692 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
08:40:39.0674 3692 RDPWD - ok
08:40:39.0705 3692 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
08:40:39.0721 3692 rdyboost - ok
08:40:39.0752 3692 regi (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\Windows\system32\drivers\regi.sys
08:40:39.0752 3692 regi - ok
08:40:39.0783 3692 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
08:40:39.0830 3692 rspndr - ok
08:40:39.0861 3692 RTHDMIAzAudService (34f05c417f038ffa3bef69b798d7d7dd) C:\Windows\system32\drivers\RtHDMIVX.sys
08:40:39.0908 3692 RTHDMIAzAudService - ok
08:40:39.0939 3692 RTL8167 (f65f171165fbb613f7aa3cc78e8cab42) C:\Windows\system32\DRIVERS\Rt64win7.sys
08:40:40.0001 3692 RTL8167 - ok
08:40:40.0017 3692 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
08:40:40.0048 3692 s3cap - ok
08:40:40.0064 3692 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
08:40:40.0079 3692 sbp2port - ok
08:40:40.0111 3692 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
08:40:40.0173 3692 scfilter - ok
08:40:40.0189 3692 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
08:40:40.0235 3692 secdrv - ok
08:40:40.0251 3692 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
08:40:40.0267 3692 Serenum - ok
08:40:40.0282 3692 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
08:40:40.0298 3692 Serial - ok
08:40:40.0329 3692 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
08:40:40.0329 3692 sermouse - ok
08:40:40.0360 3692 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
08:40:40.0376 3692 sffdisk - ok
08:40:40.0407 3692 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
08:40:40.0454 3692 sffp_mmc - ok
08:40:40.0469 3692 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
08:40:40.0501 3692 sffp_sd - ok
08:40:40.0516 3692 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
08:40:40.0547 3692 sfloppy - ok
08:40:40.0579 3692 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
08:40:40.0594 3692 SiSRaid2 - ok
08:40:40.0610 3692 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
08:40:40.0625 3692 SiSRaid4 - ok
08:40:40.0641 3692 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
08:40:40.0672 3692 Smb - ok
08:40:40.0703 3692 snapman (db0f68b3bbc1429826cca1e31ff8b00b) C:\Windows\system32\DRIVERS\snapman.sys
08:40:40.0750 3692 snapman - ok
08:40:40.0781 3692 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
08:40:40.0797 3692 spldr - ok
08:40:40.0859 3692 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
08:40:40.0859 3692 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
08:40:40.0859 3692 sptd ( LockedFile.Multi.Generic ) - warning
08:40:40.0859 3692 sptd - detected LockedFile.Multi.Generic (1)
08:40:40.0906 3692 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
08:40:40.0937 3692 srv - ok
08:40:40.0953 3692 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
08:40:40.0984 3692 srv2 - ok
08:40:41.0015 3692 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
08:40:41.0062 3692 srvnet - ok
08:40:41.0125 3692 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
08:40:41.0125 3692 stexstor - ok
08:40:41.0156 3692 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
08:40:41.0171 3692 storflt - ok
08:40:41.0187 3692 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
08:40:41.0203 3692 storvsc - ok
08:40:41.0218 3692 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
08:40:41.0218 3692 swenum - ok
08:40:41.0296 3692 tap0901 (6e8732acfd4c8d1ec4a4e872168b8b92) C:\Windows\system32\DRIVERS\tap0901.sys
08:40:41.0327 3692 tap0901 - ok
08:40:41.0374 3692 Tcpip (f0e98c00a09fdf791525829a1d14240f) C:\Windows\system32\drivers\tcpip.sys
08:40:41.0437 3692 Tcpip - ok
08:40:41.0468 3692 TCPIP6 (f0e98c00a09fdf791525829a1d14240f) C:\Windows\system32\DRIVERS\tcpip.sys
08:40:41.0499 3692 TCPIP6 - ok
08:40:41.0530 3692 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
08:40:41.0561 3692 tcpipreg - ok
08:40:41.0577 3692 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
08:40:41.0608 3692 TDPIPE - ok
08:40:41.0639 3692 tdrpman258 (bf7ac81df6fbe09438d9dc7188178ea9) C:\Windows\system32\DRIVERS\tdrpm258.sys
08:40:41.0671 3692 tdrpman258 - ok
08:40:41.0702 3692 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
08:40:41.0733 3692 TDTCP - ok
08:40:41.0764 3692 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
08:40:41.0827 3692 tdx - ok
08:40:41.0842 3692 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
08:40:41.0842 3692 TermDD - ok
08:40:41.0873 3692 timounter (2c1caf5563548a15515eab07d2a069c6) C:\Windows\system32\DRIVERS\timntr.sys
08:40:41.0905 3692 timounter - ok
08:40:41.0905 3692 truecrypt - ok
08:40:41.0936 3692 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
08:40:41.0998 3692 tssecsrv - ok
08:40:42.0029 3692 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
08:40:42.0045 3692 TsUsbFlt - ok
08:40:42.0092 3692 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
08:40:42.0154 3692 tunnel - ok
08:40:42.0170 3692 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
08:40:42.0170 3692 uagp35 - ok
08:40:42.0201 3692 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
08:40:42.0295 3692 udfs - ok
08:40:42.0341 3692 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
08:40:42.0373 3692 uliagpkx - ok
08:40:42.0451 3692 UltraMonUtility (694bcf23662f97d987cf4c6739c35f8b) C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys
08:40:42.0482 3692 UltraMonUtility - ok
08:40:42.0529 3692 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
08:40:42.0575 3692 umbus - ok
08:40:42.0591 3692 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
08:40:42.0622 3692 UmPass - ok
08:40:42.0638 3692 upperdev (69405c5429ef448b319f08042b897fc6) C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
08:40:42.0669 3692 upperdev - ok
08:40:42.0716 3692 USBAAPL64 (9e58997a211c8c9ac9e6cffa53614a73) C:\Windows\system32\Drivers\usbaapl64.sys
08:40:42.0763 3692 USBAAPL64 - ok
08:40:42.0794 3692 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
08:40:42.0825 3692 usbaudio - ok
08:40:42.0856 3692 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
08:40:42.0872 3692 usbccgp - ok
08:40:42.0903 3692 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
08:40:42.0934 3692 usbcir - ok
08:40:42.0965 3692 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
08:40:43.0012 3692 usbehci - ok
08:40:43.0043 3692 usbfilter (6648c6d7323a2ce0c4776c36cefbcb14) C:\Windows\system32\DRIVERS\usbfilter.sys
08:40:43.0059 3692 usbfilter - ok
08:40:43.0090 3692 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
08:40:43.0121 3692 usbhub - ok
08:40:43.0153 3692 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\DRIVERS\usbohci.sys
08:40:43.0168 3692 usbohci - ok
08:40:43.0199 3692 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
08:40:43.0215 3692 usbprint - ok
08:40:43.0246 3692 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
08:40:43.0277 3692 usbscan - ok
08:40:43.0324 3692 usbser (4acee387fa8fd39f83564fcd2fc234f2) C:\Windows\system32\drivers\usbser.sys
08:40:43.0340 3692 usbser - ok
08:40:43.0355 3692 UsbserFilt (0305d5f7d5751d0ae763250eb78dc5d7) C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys
08:40:43.0402 3692 UsbserFilt - ok
08:40:43.0433 3692 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
08:40:43.0465 3692 USBSTOR - ok
08:40:43.0496 3692 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
08:40:43.0527 3692 usbuhci - ok
08:40:43.0543 3692 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
08:40:43.0574 3692 usbvideo - ok
08:40:43.0589 3692 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
08:40:43.0605 3692 vdrvroot - ok
08:40:43.0636 3692 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
08:40:43.0667 3692 vga - ok
08:40:43.0683 3692 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
08:40:43.0730 3692 VgaSave - ok
08:40:43.0745 3692 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
08:40:43.0761 3692 vhdmp - ok
08:40:43.0792 3692 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
08:40:43.0823 3692 viaide - ok
08:40:43.0855 3692 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
08:40:43.0870 3692 vmbus - ok
08:40:43.0886 3692 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
08:40:43.0901 3692 VMBusHID - ok
08:40:43.0917 3692 vmci (cdaa992c18f3f3612444c818a478cf57) C:\Windows\system32\drivers\vmci.sys
08:40:43.0917 3692 vmci - ok
08:40:43.0933 3692 vmkbd (ea9c266cd4b4bb7c7d818c1c27461959) C:\Windows\system32\drivers\VMkbd.sys
08:40:43.0933 3692 vmkbd - ok
08:40:43.0948 3692 VMnetAdapter (9d54f1339e78c95bf3d9939ebcb66378) C:\Windows\system32\DRIVERS\vmnetadapter.sys
08:40:43.0948 3692 VMnetAdapter - ok
08:40:43.0964 3692 VMnetBridge (fb54ef3aa613d2832fd3812e7cb2fc75) C:\Windows\system32\DRIVERS\vmnetbridge.sys
08:40:43.0979 3692 VMnetBridge - ok
08:40:43.0995 3692 VMnetuserif (479948eb42e189c076b45ebaf2d12bbc) C:\Windows\system32\drivers\vmnetuserif.sys
08:40:44.0011 3692 VMnetuserif - ok
08:40:44.0026 3692 VMparport (a8a805479334da10cfe10a4e20b6f25b) C:\Windows\system32\drivers\VMparport.sys
08:40:44.0026 3692 VMparport - ok
08:40:44.0057 3692 vmusb (415b167695c4b5960a13098622ef3d80) C:\Windows\system32\Drivers\vmusb.sys
08:40:44.0073 3692 vmusb - ok
08:40:44.0089 3692 vmx86 (05645d6651ca7a02298aae475bbcad6e) C:\Windows\system32\drivers\vmx86.sys
08:40:44.0089 3692 vmx86 - ok
08:40:44.0104 3692 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
08:40:44.0120 3692 volmgr - ok
08:40:44.0151 3692 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
08:40:44.0198 3692 volmgrx - ok
08:40:44.0213 3692 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
08:40:44.0229 3692 volsnap - ok
08:40:44.0245 3692 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
08:40:44.0260 3692 vsmraid - ok
08:40:44.0307 3692 vstor2-ws60 (69f57e89e6ebc5012d210527af005a70) C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys
08:40:44.0323 3692 vstor2-ws60 - ok
08:40:44.0338 3692 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
08:40:44.0385 3692 vwifibus - ok
08:40:44.0401 3692 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
08:40:44.0432 3692 WacomPen - ok
08:40:44.0447 3692 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
08:40:44.0510 3692 WANARP - ok
08:40:44.0510 3692 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
08:40:44.0541 3692 Wanarpv6 - ok
08:40:44.0572 3692 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
08:40:44.0572 3692 Wd - ok
08:40:44.0588 3692 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
08:40:44.0603 3692 Wdf01000 - ok
08:40:44.0635 3692 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
08:40:44.0650 3692 WfpLwf - ok
08:40:44.0666 3692 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
08:40:44.0681 3692 WIMMount - ok
08:40:44.0713 3692 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
08:40:44.0744 3692 WinUsb - ok
08:40:44.0775 3692 WmBEnum (e7f4937b613b1e4294100c9d4efc36a9) C:\Windows\system32\drivers\WmBEnum.sys
08:40:44.0791 3692 WmBEnum - ok
08:40:44.0822 3692 WmFilter (6f6f2b263002b243d3501c7e6c8fc11d) C:\Windows\system32\drivers\WmFilter.sys
08:40:44.0837 3692 WmFilter - ok
08:40:44.0869 3692 WmHidLo (1584f8d5fdfe44c03dba85a2106b937f) C:\Windows\system32\drivers\WmHidLo.sys
08:40:44.0900 3692 WmHidLo - ok
08:40:44.0915 3692 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
08:40:44.0947 3692 WmiAcpi - ok
08:40:44.0978 3692 WmVirHid (52b4fcc6afaec0ffd80bda63f9b140cd) C:\Windows\system32\drivers\WmVirHid.sys
08:40:44.0993 3692 WmVirHid - ok
08:40:45.0009 3692 WmXlCore (395b3e7fba81bdc4501641b3b2cf2e20) C:\Windows\system32\drivers\WmXlCore.sys
08:40:45.0025 3692 WmXlCore - ok
08:40:45.0040 3692 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
08:40:45.0071 3692 ws2ifsl - ok
08:40:45.0103 3692 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
08:40:45.0181 3692 WudfPf - ok
08:40:45.0196 3692 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
08:40:45.0227 3692 WUDFRd - ok
08:40:45.0274 3692 xnacc (4a5ce13408945e525503b5f73d29b9c5) C:\Windows\system32\DRIVERS\xnacc.sys
08:40:45.0305 3692 xnacc - ok
08:40:45.0337 3692 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
08:40:45.0368 3692 \Device\Harddisk0\DR0 - ok
08:40:45.0383 3692 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
08:40:45.0430 3692 \Device\Harddisk1\DR1 - ok
08:40:45.0446 3692 Boot (0x1200) (b234af2efb73d5e37d390d2f3663bccc) \Device\Harddisk0\DR0\Partition0
08:40:45.0446 3692 \Device\Harddisk0\DR0\Partition0 - ok
08:40:45.0461 3692 Boot (0x1200) (1872abe5f860cee20c6ead0e6c93b373) \Device\Harddisk0\DR0\Partition1
08:40:45.0477 3692 \Device\Harddisk0\DR0\Partition1 - ok
08:40:45.0477 3692 Boot (0x1200) (6c820c33e15d55526f8dc94c47db34a2) \Device\Harddisk0\DR0\Partition2
08:40:45.0477 3692 \Device\Harddisk0\DR0\Partition2 - ok
08:40:45.0493 3692 Boot (0x1200) (b2d16a74b116effeb8695791a9fde18b) \Device\Harddisk1\DR1\Partition0
08:40:45.0493 3692 \Device\Harddisk1\DR1\Partition0 - ok
08:40:45.0493 3692 ============================================================
08:40:45.0493 3692 Scan finished
08:40:45.0493 3692 ============================================================
08:40:45.0508 4732 Detected object count: 1
08:40:45.0508 4732 Actual detected object count: 1
08:42:07.0736 4732 sptd ( LockedFile.Multi.Generic ) - skipped by user
08:42:07.0736 4732 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

cosinus 05.10.2011 15:10

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

ErichZann 05.10.2011 20:42

Liste der Anhänge anzeigen (Anzahl: 1)
Hm das funktioniert irgendwie nicht... ich führe das als administrator aus, aber gleich zu beginn des scans kommt eine fehlermeldung, und nach über einer Stunde lässt sich da keine Aktivität erkennen... Ich habe auch neugestartet und es nochmal probiert.. ich hänge einen screenshot an.

cosinus 05.10.2011 21:05

Oje, du bist schon der 2. mit dieser Meldung :(
Ich fürchte da hat sich ein Bug eingeschlichen.
Ist CF mittlerweile weiter oder bleibt es an dieser Stelle hängen?

ErichZann 05.10.2011 21:08

Öhm, ich habe es ja irgendwann, nach geschätzt 1,5 stunden abgebrochen, dann neugestartet und nur kurz getestet... aber beim ersten mal war auch keine festplattenaktivität oder so mehr zu hören.. hmm

cosinus 05.10.2011 21:12

Starte Windows neu, lösch die alte combofix.exe, lade CF neu runter und probier es bitte nochmal.

ErichZann 05.10.2011 21:48

Ok, hab ich gemacht, gleicher Fehler und es läuft nicht weiter.

cosinus 05.10.2011 22:04

Dann müssen wir erstmal abwarten oder lassen CF vorerst nur weg.

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe Vista und Win7 User mit Rechtsklick "als Admininstartor starten"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

ErichZann 06.10.2011 05:43

Ok, hier ist der log:

Zitat:

aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-10-06 06:36:47
-----------------------------
06:36:47.306 OS Version: Windows x64 6.1.7601 Service Pack 1
06:36:47.306 Number of processors: 4 586 0x402
06:36:47.306 ComputerName: Name UserName:
06:36:47.743 Initialize success
06:36:47.899 AVAST engine defs: 11100501
06:37:07.711 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
06:37:07.727 Disk 0 Vendor: SAMSUNG_HD103SJ 1AJ100E4 Size: 953869MB BusType: 3
06:37:07.727 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-1
06:37:07.742 Disk 1 Vendor: SAMSUNG_HD204UI 1AQ10001 Size: 1907729MB BusType: 3
06:37:09.755 Disk 0 MBR read successfully
06:37:09.755 Disk 0 MBR scan
06:37:09.770 Disk 0 Windows 7 default MBR code
06:37:09.770 Service scanning
06:37:13.171 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
06:37:14.747 Modules scanning
06:37:14.747 Disk 0 trace - called modules:
06:37:14.778 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa80039ab2c0]<<
06:37:14.778 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004b19060]
06:37:14.793 3 CLASSPNP.SYS[fffff8800168c43f] -> nt!IofCallDriver -> [0xfffffa8004802580]
06:37:14.809 5 ACPI.sys[fffff88000e3a7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004804060]
06:37:14.809 \Driver\atapi[0xfffffa8003ae2c70] -> IRP_MJ_CREATE -> 0xfffffa80039ab2c0
06:37:15.059 AVAST engine scan C:\Windows
06:37:17.102 AVAST engine scan C:\Windows\system32
06:38:24.276 AVAST engine scan C:\Windows\system32\drivers
06:38:31.218 AVAST engine scan C:\Users\Benutzername
06:39:03.728 AVAST engine scan C:\ProgramData
06:40:31.322 Scan finished successfully
06:41:59.666 Disk 0 MBR has been saved successfully to "C:\Users\Name\Downloads\MBR.dat"
06:41:59.666 The log file has been saved successfully to "C:\Users\Name\Downloads\aswMBR.txt"



cosinus 06.10.2011 13:08

Ok, der MBR ist i.O.

Starte Windows neu, lösch die alte combofix.exe, lade CF neu runter und probier es bitte nochmal.

ErichZann 06.10.2011 18:22

Ok, diesmal hat es geklappt:

Combofix Logfile:
Code:

ComboFix 11-10-06.03 - Benutzername1 06.10.2011  19:12:24.1.4 - x64
Microsoft Windows 7 Professional  6.1.7601.1.1252.49.1031.18.4094.2870 [GMT 2:00]
ausgeführt von:: c:\users\Name\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Benutzername1\AppData\Roaming\inst.exe
c:\users\Name\AppData\Roaming\vso_ts_preview.xml
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-09-06 bis 2011-10-06  ))))))))))))))))))))))))))))))
.
.
2011-10-06 17:18 . 2011-10-06 17:18        --------        d-----w-        c:\users\Benutzername2\AppData\Local\temp
2011-10-06 17:18 . 2011-10-06 17:18        --------        d-----w-        c:\users\Benutzername1\AppData\Local\temp
2011-10-06 17:18 . 2011-10-06 17:18        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-10-04 18:53 . 2011-10-04 18:53        --------        d-----w-        C:\_OTL
2011-09-28 17:35 . 2000-01-28 16:17        557328        ----a-w-        c:\program files\Common Files\Microsoft Shared\dao\dao360.dll
2011-09-28 17:33 . 2011-09-28 17:34        --------        d-----w-        c:\program files (x86)\Schwedisch AKTIV
2011-09-25 09:23 . 2011-09-25 10:15        --------        d-----w-        c:\program files\UltraVNC
2011-09-23 20:28 . 2011-09-23 20:28        --------        d-----w-        c:\users\Name\AppData\Roaming\Malwarebytes
2011-09-23 20:28 . 2011-09-23 20:28        --------        d-----w-        c:\users\Benutzername1\AppData\Roaming\Malwarebytes
2011-09-23 20:28 . 2011-09-23 20:28        --------        d-----w-        c:\programdata\Malwarebytes
2011-09-23 20:28 . 2011-09-23 20:28        --------        d-----w-        c:\program files (x86)\Malwarebytes Anti-Malware
2011-09-23 20:28 . 2011-08-31 15:00        25416        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-09-23 20:07 . 2011-09-23 20:07        --------        d-----w-        c:\program files (x86)\Common Files\Java
2011-09-18 11:02 . 2011-09-18 11:02        --------        d-----r-        c:\users\Benutzername1\AppData\Roaming\Brother
2011-09-11 11:01 . 2011-09-11 11:01        --------        d-----w-        c:\users\Name\AppData\Roaming\atitray
2011-09-11 11:00 . 2011-09-11 11:00        --------        d-----w-        c:\users\Benutzername1\AppData\Roaming\atitray
2011-09-11 10:58 . 2011-10-06 17:09        --------        d-----w-        c:\program files (x86)\ATI Tray Tools
2011-09-11 10:53 . 2011-09-11 10:53        --------        d-----w-        c:\users\Benutzername1\AppData\Local\AMD
2011-09-11 09:46 . 2011-09-11 09:46        --------        d-----w-        c:\users\Name\AppData\Local\AMD
2011-09-11 09:46 . 2011-09-11 09:46        --------        d-----w-        c:\programdata\ATI
2011-09-11 09:45 . 2011-09-11 09:45        --------        d-----w-        c:\program files\Common Files\ATI Technologies
2011-09-11 09:45 . 2011-09-11 09:45        --------        d-----w-        c:\program files (x86)\Common Files\ATI Technologies
2011-09-11 09:44 . 2011-09-11 09:44        --------        d-----w-        c:\programdata\AMD
2011-09-11 09:42 . 2011-09-11 09:44        --------        d-----w-        c:\program files\ATI Technologies
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-23 20:06 . 2011-05-16 16:18        404640        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-07 09:32 . 2010-06-24 10:33        18328        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-09-06 20:45 . 2010-06-29 06:20        41184        ----a-w-        c:\windows\avastSS.scr
2011-09-06 20:45 . 2010-02-12 18:43        199304        ----a-w-        c:\windows\SysWow64\aswBoot.exe
2011-09-06 20:45 . 2011-01-14 10:48        254400        ----a-w-        c:\windows\system32\aswBoot.exe
2011-09-06 20:38 . 2011-04-19 13:33        601944        ----a-w-        c:\windows\system32\drivers\aswSnx.sys
2011-09-06 20:38 . 2010-02-12 18:44        301912        ----a-w-        c:\windows\system32\drivers\aswSP.sys
2011-09-06 20:36 . 2010-02-12 18:44        42328        ----a-w-        c:\windows\system32\drivers\aswRdr.sys
2011-09-06 20:36 . 2010-02-12 18:44        58200        ----a-w-        c:\windows\system32\drivers\aswTdi.sys
2011-09-06 20:36 . 2010-02-12 18:44        65368        ----a-w-        c:\windows\system32\drivers\aswMonFlt.sys
2011-09-06 20:36 . 2010-02-12 18:44        24408        ----a-w-        c:\windows\system32\drivers\aswFsBlk.sys
2011-08-18 11:27 . 2010-12-24 16:18        3766        --sha-w-        c:\programdata\KGyGaAvL.sys
2011-07-28 22:23 . 2011-07-28 22:23        9980416        ----a-w-        c:\windows\system32\drivers\atikmdag.sys
2011-07-28 22:09 . 2011-07-28 22:09        23921664        ----a-w-        c:\windows\system32\atio6axx.dll
2011-07-28 21:44 . 2011-07-28 21:44        18388480        ----a-w-        c:\windows\SysWow64\atioglxx.dll
2011-07-28 21:40 . 2011-07-28 21:40        151552        ----a-w-        c:\windows\system32\atiapfxx.exe
2011-07-28 21:40 . 2011-07-28 21:40        726528        ----a-w-        c:\windows\SysWow64\aticfx32.dll
2011-07-28 21:39 . 2011-07-28 21:39        852992        ----a-w-        c:\windows\system32\aticfx64.dll
2011-07-28 21:36 . 2011-07-28 21:36        462848        ----a-w-        c:\windows\system32\ATIDEMGX.dll
2011-07-28 21:36 . 2011-07-28 21:36        485376        ----a-w-        c:\windows\system32\atieclxx.exe
2011-07-28 21:35 . 2011-07-28 21:35        204288        ----a-w-        c:\windows\system32\atiesrxx.exe
2011-07-28 21:34 . 2011-07-28 21:34        120320        ----a-w-        c:\windows\system32\atitmm64.dll
2011-07-28 21:34 . 2011-07-28 21:34        423424        ----a-w-        c:\windows\system32\atipdl64.dll
2011-07-28 21:33 . 2011-07-28 21:33        356352        ----a-w-        c:\windows\SysWow64\atipdlxx.dll
2011-07-28 21:33 . 2011-07-28 21:33        278528        ----a-w-        c:\windows\SysWow64\Oemdspif.dll
2011-07-28 21:33 . 2011-07-28 21:33        21504        ----a-w-        c:\windows\system32\atimuixx.dll
2011-07-28 21:33 . 2011-07-28 21:33        59392        ----a-w-        c:\windows\system32\atiedu64.dll
2011-07-28 21:33 . 2011-07-28 21:33        43520        ----a-w-        c:\windows\SysWow64\ati2edxx.dll
2011-07-28 21:30 . 2011-07-28 21:30        4198912        ----a-w-        c:\windows\SysWow64\atidxx32.dll
2011-07-28 21:20 . 2011-07-28 21:20        4943360        ----a-w-        c:\windows\system32\atidxx64.dll
2011-07-28 21:12 . 2011-07-28 21:12        1113088        ----a-w-        c:\windows\system32\atiumd6v.dll
2011-07-28 21:11 . 2011-07-28 21:11        1828864        ----a-w-        c:\windows\SysWow64\atiumdmv.dll
2011-07-28 21:11 . 2011-07-28 21:11        3871744        ----a-w-        c:\windows\system32\atiumd6a.dll
2011-07-28 21:11 . 2011-07-28 21:11        51200        ----a-w-        c:\windows\system32\aticalrt64.dll
2011-07-28 21:11 . 2011-07-28 21:11        46080        ----a-w-        c:\windows\SysWow64\aticalrt.dll
2011-07-28 21:11 . 2011-07-28 21:11        44544        ----a-w-        c:\windows\system32\aticalcl64.dll
2011-07-28 21:11 . 2011-07-28 21:11        44032        ----a-w-        c:\windows\SysWow64\aticalcl.dll
2011-07-28 21:10 . 2011-07-28 21:10        9644544        ----a-w-        c:\windows\system32\aticaldd64.dll
2011-07-28 21:09 . 2011-07-28 21:09        4256768        ----a-w-        c:\windows\SysWow64\atiumdag.dll
2011-07-28 21:07 . 2011-07-28 21:07        8247296        ----a-w-        c:\windows\SysWow64\aticaldd.dll
2011-07-28 21:03 . 2011-07-28 21:03        4056064        ----a-w-        c:\windows\SysWow64\atiumdva.dll
2011-07-28 21:02 . 2011-07-28 21:02        5399040        ----a-w-        c:\windows\system32\atiumd64.dll
2011-07-28 21:01 . 2011-07-28 21:01        58880        ----a-w-        c:\windows\system32\coinst.dll
2011-07-28 20:54 . 2011-07-28 20:54        378368        ----a-w-        c:\windows\system32\atiadlxx.dll
2011-07-28 20:54 . 2011-07-28 20:54        266240        ----a-w-        c:\windows\SysWow64\atiadlxy.dll
2011-07-28 20:54 . 2011-07-28 20:54        15360        ----a-w-        c:\windows\system32\atig6pxx.dll
2011-07-28 20:54 . 2011-07-28 20:54        13312        ----a-w-        c:\windows\SysWow64\atiglpxx.dll
2011-07-28 20:54 . 2011-07-28 20:54        13312        ----a-w-        c:\windows\system32\atiglpxx.dll
2011-07-28 20:54 . 2011-07-28 20:54        39936        ----a-w-        c:\windows\system32\atig6txx.dll
2011-07-28 20:54 . 2011-07-28 20:54        32768        ----a-w-        c:\windows\SysWow64\atigktxx.dll
2011-07-28 20:54 . 2011-07-28 20:54        309248        ----a-w-        c:\windows\system32\drivers\atikmpag.sys
2011-07-28 20:53 . 2011-07-28 20:53        40960        ----a-w-        c:\windows\system32\atiuxp64.dll
2011-07-28 20:53 . 2011-07-28 20:53        31744        ----a-w-        c:\windows\SysWow64\atiuxpag.dll
2011-07-28 20:53 . 2011-07-28 20:53        38912        ----a-w-        c:\windows\system32\atiu9p64.dll
2011-07-28 20:53 . 2011-07-28 20:53        29184        ----a-w-        c:\windows\SysWow64\atiu9pag.dll
2011-07-28 20:52 . 2011-07-28 20:52        53248        ----a-w-        c:\windows\system32\drivers\ati2erec.dll
2011-07-28 20:51 . 2011-07-28 20:51        53760        ----a-w-        c:\windows\system32\atimpc64.dll
2011-07-28 20:51 . 2011-07-28 20:51        53760        ----a-w-        c:\windows\system32\amdpcom64.dll
2011-07-28 20:51 . 2011-07-28 20:51        52736        ----a-w-        c:\windows\SysWow64\atimpc32.dll
2011-07-28 20:51 . 2011-07-28 20:51        52736        ----a-w-        c:\windows\SysWow64\amdpcom32.dll
2011-07-22 05:42 . 2011-09-04 19:49        2303488        ----a-w-        c:\windows\system32\jscript9.dll
2011-07-22 05:36 . 2011-09-04 19:49        1389056        ----a-w-        c:\windows\system32\wininet.dll
2011-07-22 05:32 . 2011-09-04 19:49        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2011-07-22 02:54 . 2011-09-04 19:49        1797632        ----a-w-        c:\windows\SysWow64\jscript9.dll
2011-07-22 02:48 . 2011-09-04 19:49        1126912        ----a-w-        c:\windows\SysWow64\wininet.dll
2011-07-22 02:44 . 2011-09-04 19:49        2382848        ----a-w-        c:\windows\SysWow64\mshtml.tlb
2011-07-19 03:05 . 2010-06-12 08:05        472808        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2011-07-16 05:41 . 2011-09-04 19:48        362496        ----a-w-        c:\windows\system32\wow64win.dll
2011-07-16 05:41 . 2011-09-04 19:48        243200        ----a-w-        c:\windows\system32\wow64.dll
2011-07-16 05:41 . 2011-09-04 19:48        13312        ----a-w-        c:\windows\system32\wow64cpu.dll
2011-07-16 05:39 . 2011-09-04 19:48        16384        ----a-w-        c:\windows\system32\ntvdm64.dll
2011-07-16 05:37 . 2011-09-04 19:48        421888        ----a-w-        c:\windows\system32\KernelBase.dll
2011-07-16 05:21 . 2011-09-04 19:48        6144        ---ha-w-        c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        4608        ---ha-w-        c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        4096        ---ha-w-        c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        4096        ---ha-w-        c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3584        ---ha-w-        c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        4608        ---ha-w-        c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        4096        ---ha-w-        c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3584        ---ha-w-        c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3584        ---ha-w-        c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3584        ---ha-w-        c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3584        ---ha-w-        c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3584        ---ha-w-        c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        4096        ---ha-w-        c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        5120        ---ha-w-        c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3584        ---ha-w-        c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-16 05:21 . 2011-09-04 19:48        3072        ---ha-w-        c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-09-06 3722416]
.
c:\users\Name\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ATI Tray Tools.lnk - c:\program files (x86)\ATI Tray Tools\atitray.exe [2011-8-15 890880]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
UltraMon.lnk - c:\windows\Installer\{FDE4D6B0-F762-4783-A850-63541BCA64FF}\IcoUltraMon.ico [2010-1-12 29310]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-06 135664]
R3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [x]
R3 afcdpsrv;Acronis Nonstop Backup service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2010-06-09 2480048]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-04-20 79360]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [x]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [x]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [x]
R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\spiele\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-06 135664]
R3 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2010-12-06 2101640]
R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [x]
R3 LVPrcS64;Process Monitor;c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe [2010-05-07 197976]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\DRIVERS\tdrpm258.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-07-28 361984]
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2011-06-24 55424]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [x]
S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2008-11-14 20512]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [x]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2009-10-22 563760]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [x]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [x]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [x]
S3 LVUVC64;Logitech QuickCam Pro 9000(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S4 DRIVER_B;DRIVER_B;c:\windows\system32\Drivers\DRIVER_BIN64 [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-08-16 11:43        451872        ----a-w-        c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2011-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-06 10:14]
.
2011-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-06 10:14]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45        134384        ----a-w-        c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
LSP: c:\program files (x86)\VMware\VMware Workstation\vsocklib.dll
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Benutzername1\AppData\Roaming\Mozilla\Firefox\Profiles\5czwg713.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-{E07B7A31-E160-466D-A003-3BB7B8989D52} - c:\program files (x86)\Full Tilt Poker.Net\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DRIVER_B]
"ImagePath"="\??\c:\windows\system32\Drivers\DRIVER_BIN64"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2011-10-06  19:21:18
ComboFix-quarantined-files.txt  2011-10-06 17:21
.
Vor Suchlauf: 7 Verzeichnis(se), 81.071.706.112 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 80.683.126.784 Bytes frei
.
- - End Of File - - ADAF7B7FB2CD5E03B51A09C055945FA4[/QUOTE]

--- --- ---

cosinus 07.10.2011 15:36

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!


Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


ErichZann 08.10.2011 14:44

hier kommen sie:

Zitat:

SUPERAntiSpyware Scan Log
SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

Generated 10/07/2011 at 10:58 PM

Application Version : 5.0.1128

Core Rules Database Version : 7771
Trace Rules Database Version: 5583

Scan type : Complete Scan
Total Scan Time : 01:23:29

Operating System Information
Windows 7 Professional 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned : 615
Memory threats detected : 0
Registry items scanned : 78780
Registry threats detected : 0
File items scanned : 357052
File threats detected : 146

Adware.Tracking Cookie
C:\Users\Benutzer1\AppData\Roaming\Microsoft\Windows\Cookies\Benutzer1@doubleclick[1].txt [ /doubleclick ]
C:\Users\Benutzer1\AppData\Roaming\Microsoft\Windows\Cookies\QQRZBZ19.txt [ /2o7.net ]
C:\Users\Benutzer1\AppData\Roaming\Microsoft\Windows\Cookies\330765TF.txt [ /mediaplex.com ]
C:\Users\Benutzer1\AppData\Roaming\Microsoft\Windows\Cookies\7P7L5EGT.txt [ /ad.yieldmanager.com ]
C:\Users\Benutzer1\AppData\Roaming\Microsoft\Windows\Cookies\N67VDKA4.txt [ /atdmt.com ]
C:\Users\Benutzer1\AppData\Roaming\Microsoft\Windows\Cookies\QU6KAF0P.txt [ /apmebf.com ]
C:\Users\Benutzer1\AppData\Roaming\Microsoft\Windows\Cookies\GA1GP1C9.txt [ /fl01.ct2.comclick.com ]
C:\USERS\Benutzer1\AppData\Roaming\Microsoft\Windows\Cookies\Low\Benutzer1@msnportal.112.2o7[1].txt [ Cookie:Benutzer1@msnportal.112.2o7.net/ ]
C:\USERS\Benutzer1\AppData\Roaming\Microsoft\Windows\Cookies\Low\Benutzer1@serving-sys[2].txt [ Cookie:Benutzer1@serving-sys.com/ ]
C:\USERS\Benutzer1\AppData\Roaming\Microsoft\Windows\Cookies\Low\Benutzer1@atdmt[2].txt [ Cookie:Benutzer1@atdmt.com/ ]
C:\USERS\Benutzer1\AppData\Roaming\Microsoft\Windows\Cookies\Low\Benutzer1@advertising[1].txt [ Cookie:Benutzer1@advertising.com/ ]
C:\USERS\Benutzer1\Cookies\330765TF.txt [ Cookie:Benutzer1@mediaplex.com/ ]
C:\USERS\Benutzer1\Cookies\7P7L5EGT.txt [ Cookie:Benutzer1@ad.yieldmanager.com/ ]
C:\USERS\Benutzer1\Cookies\N67VDKA4.txt [ Cookie:Benutzer1@atdmt.com/ ]
C:\USERS\Benutzer1\Cookies\QU6KAF0P.txt [ Cookie:Benutzer1@apmebf.com/ ]
C:\USERS\Benutzer1\Cookies\GA1GP1C9.txt [ Cookie:Benutzer1@fl01.ct2.comclick.com/ ]
C:\USERS\Benutzer2\AppData\Roaming\Microsoft\Windows\Cookies\Benutzer2@imrworldwide[2].txt [ Cookie:Benutzer2@imrworldwide.com/cgi-bin ]
C:\USERS\Benutzer2\AppData\Roaming\Microsoft\Windows\Cookies\Benutzer2@track.adform[1].txt [ Cookie:Benutzer2@track.adform.net/ ]
C:\USERS\Benutzer2\AppData\Roaming\Microsoft\Windows\Cookies\Benutzer2@adform[2].txt [ Cookie:Benutzer2@adform.net/ ]
C:\USERS\Benutzer2\AppData\Roaming\Microsoft\Windows\Cookies\Benutzer2@atdmt[2].txt [ Cookie:Benutzer2@atdmt.com/ ]
C:\USERS\Benutzer2\AppData\Roaming\Microsoft\Windows\Cookies\Benutzer2@eyewonder[2].txt [ Cookie:Benutzer2@eyewonder.com/ ]
C:\USERS\Benutzer2\AppData\Roaming\Microsoft\Windows\Cookies\Low\Benutzer2@imrworldwide[1].txt [ Cookie:Benutzer2@imrworldwide.com/cgi-bin ]
C:\USERS\Benutzer2\AppData\Roaming\Microsoft\Windows\Cookies\Low\Benutzer2@atdmt[2].txt [ Cookie:Benutzer2@atdmt.com/ ]
C:\USERS\Benutzer2\AppData\Roaming\Microsoft\Windows\Cookies\Low\Benutzer2@apmebf[1].txt [ Cookie:Benutzer2@apmebf.com/ ]
C:\USERS\Benutzer2\AppData\Roaming\Microsoft\Windows\Cookies\Low\Benutzer2@ad.yieldmanager[2].txt [ Cookie:Benutzer2@ad.yieldmanager.com/ ]
C:\USERS\Benutzer2\AppData\Roaming\Microsoft\Windows\Cookies\Low\Benutzer2@fl01.ct2.comclick[1].txt [ Cookie:Benutzer2@fl01.ct2.comclick.com/ ]
C:\USERS\Benutzer2\AppData\Roaming\Microsoft\Windows\Cookies\Low\Benutzer2@serving-sys[2].txt [ Cookie:Benutzer2@serving-sys.com/ ]
C:\USERS\Benutzer2\Cookies\Benutzer2@imrworldwide[2].txt [ Cookie:Benutzer2@imrworldwide.com/cgi-bin ]
C:\USERS\Benutzer2\Cookies\Benutzer2@track.adform[1].txt [ Cookie:Benutzer2@track.adform.net/ ]
C:\USERS\Benutzer2\Cookies\Benutzer2@adform[2].txt [ Cookie:Benutzer2@adform.net/ ]
C:\USERS\Benutzer2\Cookies\Benutzer2@atdmt[2].txt [ Cookie:Benutzer2@atdmt.com/ ]
C:\USERS\Benutzer2\Cookies\Benutzer2@eyewonder[2].txt [ Cookie:Benutzer2@eyewonder.com/ ]
C:\USERS\Benutzer1\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Benutzer1@BS.SERVING-SYS[1].TXT [ /BS.SERVING-SYS ]
.webmasterplan.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.ads.quartermedia.de [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.ads.quartermedia.de [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.im.banner.t-online.de [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.traffictrack.de [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.kontera.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.kontera.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.kontera.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.tacoda.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.tacoda.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.tacoda.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.at.atwola.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
tracking.mlsat02.de [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
ww251.smartadserver.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.content.yieldmanager.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.zanox.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.tribalfusion.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
statse.webtrendslive.com [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\Benutzer1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5CZWG713.DEFAULT\COOKIES.SQLITE ]
C:\USERS\Benutzer2\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Benutzer2@2O7[1].TXT [ /2O7 ]
C:\USERS\Benutzer2\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Benutzer2@BS.SERVING-SYS[1].TXT [ /BS.SERVING-SYS ]
.imrworldwide.com [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.svd.112.2o7.net [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.xiti.com [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.yadro.ru [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
statse.webtrendslive.com [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
stat.swedbank.se [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.adsby.webtraffic.se [ C:\USERS\Benutzer2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D2Q7RFN7.DEFAULT\COOKIES.SQLITE ]
.media browser [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.media browser [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.media browser [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
forum.pcstats.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
forum.pcstats.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
Windfinder - wind, wave & weather reports, forecasts & statistics / webcams, satellite images, isobar maps, tides [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.team-mediaportal.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.team-mediaportal.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.norbergmedia.de [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.nordclick.de [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
mediafiles-express.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.ddl-warez.in [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
tracking.klicktel.de [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
tracking.klicktel.de [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
Windfinder - wind, wave & weather reports, forecasts & statistics / webcams, satellite images, isobar maps, tides [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.zieltrack.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
ad.zanox.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.ero-advertising.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.networkedmediatank.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.networkedmediatank.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.networkedmediatank.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.networkedmediatank.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.networkedmediatank.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
tracking.fahrrad.de [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.test.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
Media Markt [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
sitestats.ets.org [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
livestat.derstandard.at [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.newsclick.de [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.newsclick.de [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.norstat.se [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.norstat.se [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
.norstat.se [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
stat.swedbank.se [ C:\USERS\Name\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWZXUYCN.DEFAULT\COOKIES.SQLITE ]
Zitat:

Malwarebytes' Anti-Malware 1.51.2.1300
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: 7898

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

08.10.2011 08:01:04
mbam-log-2011-10-08 (08-01-04).txt

Scan type: Full scan (C:\|)
Objects scanned: 520810
Time elapsed: 43 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Zitat:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=2e2099035754ed42b2de10dc548dd22f
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-10-08 09:57:23
# local_time=2011-10-08 11:57:23 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=768 16777215 100 0 52058503 52058503 0 0
# compatibility_mode=5893 16776574 100 94 14829085 69684978 0 0
# compatibility_mode=8192 67108863 100 0 107 107 0 0
# scanned=585458
# found=0
# cleaned=0
# scan_time=12714

cosinus 08.10.2011 17:21

Sieht ok aus, da wurden nur Cookies gefunden.
Noch Probleme oder weitere Funde in der Zwischenzeit?

ErichZann 08.10.2011 22:32

Nope, sieht alles gut aus soweit, danke! Muss ich nun noch irgendwas beachten? Hatte irgendwo gelesen, dass man ComboFix irgendwie deinstallieren sollte (combofix /uninstall) in eingabeaufforderung, hat bei mir aber nicht funktioniert, ist vermutlich auch nicht notwendig?

Grüße

cosinus 10.10.2011 11:16

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:37 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131