Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   fremder zugriff auf mein MSN (https://www.trojaner-board.de/105505-fremder-zugriff-msn.html)

PinaColada 28.11.2011 11:23

fremder zugriff auf mein MSN
 
Hallo.

ich hoffe ich bin hier jetzt im richtigen Forum.

ich schilder mal eben mein Problem.. Jemand hat gestern scheinbar mein MSN geknackt und sich dadurch zugang zu meiner Hotmail, meinem Facebook konto und auch zu meinem Jappy account verschafft....
diese Person hatte alle Passwörter geändert so das ich erstmal dumm da stand wie ich mich nirgends wo anmelden konnte, ich war nur erstaunt das meine Freunde meinten das ich überall online war..

nach langem hin und her habe ich es über meine weitere MSN addy geschafft meine konten alle wieder zubekommen.
ich war sogar gleichzeitig mit der anderen Person bei Facebook online und durfe kurz mit ansehen was er dort für ein müll postet, daraufhin hab ich fix das konto gemeldet und deaktiviert...

meine Frage ist nun: Hat diese Peson noch zugriff auf meine Daten oder ist er weg??? und
wie kann ich verhindern das sowas erneut passiert?

Ich bedanke mich schonmal im vorraus

Gruß Pina Colada

cosinus 28.11.2011 14:12

Zitat:

und wie kann ich verhindern das sowas erneut passiert?
Wie wärs mit: Sichere Passwörter vergeben und aufpassen, dass die Windows-Kiste nicht vermüllt?

Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


PinaColada 28.11.2011 14:14

Danke schön für die hilfe

LG

cosinus 28.11.2011 14:15

Zitat:

Zitat von PinaColada (Beitrag 726432)
Danke schön für die hilfe

LG

Komtm da noch mehr? Machst du die Logs? :wtf::confused:

PinaColada 28.11.2011 14:26

ja bin gerade dabei es auszuführen :)

sobald die scans durch sind schreibe ich es

PinaColada 28.11.2011 15:21

Malwarebytes' Anti-Malware 1.51.2.1300
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: 8256

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

28.11.2011 15:18:51
mbam-log-2011-11-28 (15-18-51).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|)
Durchsuchte Objekte: 339293
Laufzeit: 55 Minute(n), 53 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

PinaColada 28.11.2011 15:22

werde jetzt ESET asführen

PinaColada 28.11.2011 16:49

und nun noch das ergebniss vom ESET scan
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=6b6407d8b2da6049882ff9e02852892a
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-10-23 12:27:13
# local_time=2011-10-23 02:27:13 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=5892 16776574 100 100 20505992 156856816 0 0
# compatibility_mode=8192 67108863 100 0 89 89 0 0
# scanned=112779
# found=0
# cleaned=0
# scan_time=5545
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=6b6407d8b2da6049882ff9e02852892a
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-27 08:01:55
# local_time=2011-11-27 09:01:55 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=5892 16776574 100 100 23598770 159949594 0 0
# compatibility_mode=8192 67108863 100 0 3092867 3092867 0 0
# scanned=190938
# found=0
# cleaned=0
# scan_time=7248
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=6b6407d8b2da6049882ff9e02852892a
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-28 01:32:22
# local_time=2011-11-28 02:32:22 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=5892 16776574 100 100 23668052 160018876 0 0
# compatibility_mode=8192 67108863 100 0 3162149 3162149 0 0
# scanned=10212
# found=0
# cleaned=0
# scan_time=994
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=6b6407d8b2da6049882ff9e02852892a
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-28 03:47:57
# local_time=2011-11-28 04:47:57 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=5892 16776574 100 100 23672174 160022998 0 0
# compatibility_mode=8192 67108863 100 0 3166271 3166271 0 0
# scanned=192840
# found=0
# cleaned=0
# scan_time=5006

cosinus 28.11.2011 18:24

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


PinaColada 28.11.2011 18:30

Ok mach ich sofort :)

Aber komisch ist immer noch das die mein MSN knacken konnten :(

Laut Hotmail war mein PW als sicher eingestuft. hatte viel groß und kleinschreibung, zahlen und sogar satzzeichen drin

PinaColada 28.11.2011 18:49

Soooo erledigt... und nochmal SUPER LIEBEN DANK fürs helfen :)
OTL Logfile:
Code:

OTL logfile created on: 28.11.2011 18:33:12 - Run 2
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Pizzaro\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 0,72 Gb Available Physical Memory | 36,01% Memory free
4,23 Gb Paging File | 2,23 Gb Available in Paging File | 52,77% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 244,14 Gb Total Space | 169,84 Gb Free Space | 69,57% Space Free | Partition Type: NTFS
Drive D: | 221,62 Gb Total Space | 207,04 Gb Free Space | 93,42% Space Free | Partition Type: NTFS
 
Computer Name: PIZZARO-PC | User Name: Pizzaro | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.11.28 10:08:35 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Pizzaro\Desktop\OTL.exe
PRC - [2011.11.11 07:52:37 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2011.09.20 11:39:48 | 000,801,792 | ---- | M] (Yuna Software) -- C:\Programme\Yuna Software\Messenger Plus!\PlusService.exe
PRC - [2011.06.15 14:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe
PRC - [2011.06.06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.05.13 15:03:34 | 004,283,256 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Live\Messenger\msnmsgr.exe
PRC - [2011.05.13 13:49:42 | 000,025,456 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Live\Contacts\wlcomm.exe
PRC - [2011.04.27 14:39:26 | 000,208,944 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\Antimalware\NisSrv.exe
PRC - [2011.04.27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2011.03.28 19:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011.03.28 19:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009.10.14 12:36:56 | 002,793,304 | ---- | M] () -- C:\Programme\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009.10.14 12:34:18 | 000,560,472 | ---- | M] () -- C:\Programme\Common Files\logishrd\LQCVFX\COCIManager.exe
PRC - [2009.10.07 00:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Programme\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2009.07.16 14:35:42 | 005,458,704 | ---- | M] (Logitech Inc.) -- C:\Programme\Logitech\Logitech Vid\Vid.exe
PRC - [2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2008.01.19 08:33:39 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2008.01.19 08:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.11.11 07:52:36 | 001,989,592 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll
MOD - [2011.08.21 07:35:59 | 006,277,280 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2011.08.07 14:54:16 | 000,004,096 | ---- | M] () -- C:\Programme\Yuna Software\Messenger Plus!\Detour32.dll
MOD - [2009.10.14 12:36:56 | 002,793,304 | ---- | M] () -- C:\Programme\Logitech\Logitech WebCam Software\LWS.exe
MOD - [2009.10.14 12:36:34 | 000,181,592 | ---- | M] () -- C:\Programme\Common Files\logishrd\LvApi11\LvApi11.dll
MOD - [2009.10.14 12:34:18 | 000,560,472 | ---- | M] () -- C:\Programme\Common Files\logishrd\LQCVFX\COCIManager.exe
MOD - [2009.07.16 14:36:20 | 000,138,000 | ---- | M] () -- C:\Programme\Logitech\Logitech Vid\plugins\imageformats\qjpeg4.dll
MOD - [2009.07.16 14:36:16 | 000,035,088 | ---- | M] () -- C:\Programme\Logitech\Logitech Vid\plugins\imageformats\qico4.dll
MOD - [2009.07.16 14:36:16 | 000,028,944 | ---- | M] () -- C:\Programme\Logitech\Logitech Vid\plugins\imageformats\qgif4.dll
MOD - [2009.07.16 14:35:30 | 000,027,408 | ---- | M] () -- C:\Programme\Logitech\Logitech Vid\SDL.dll
MOD - [2009.07.16 14:35:20 | 000,363,792 | ---- | M] () -- C:\Programme\Logitech\Logitech Vid\qtxml4.dll
MOD - [2009.07.16 14:35:08 | 011,311,888 | ---- | M] () -- C:\Programme\Logitech\Logitech Vid\QtWebKit4.dll
MOD - [2009.07.16 14:34:56 | 000,199,952 | ---- | M] () -- C:\Programme\Logitech\Logitech Vid\qtsql4.dll
MOD - [2009.07.16 14:34:46 | 000,475,408 | ---- | M] () -- C:\Programme\Logitech\Logitech Vid\QtOpenGL4.dll
MOD - [2009.07.16 14:34:34 | 000,968,976 | ---- | M] () -- C:\Programme\Logitech\Logitech Vid\QtNetwork4.dll
MOD - [2009.07.16 14:34:22 | 007,704,336 | ---- | M] () -- C:\Programme\Logitech\Logitech Vid\QtGui4.dll
MOD - [2009.07.16 14:34:22 | 002,140,944 | ---- | M] () -- C:\Programme\Logitech\Logitech Vid\QtCore4.dll
MOD - [2009.07.16 14:34:12 | 000,291,600 | ---- | M] () -- C:\Programme\Logitech\Logitech Vid\phonon4.dll
MOD - [2007.01.18 23:54:48 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.06.06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.04.27 14:39:26 | 000,208,944 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV - [2011.04.27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2009.10.07 00:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2008.01.19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.11.28 16:48:17 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{91485451-74BD-4B21-9C2B-1B14F7395BA0}\MpKsl7073bea5.sys -- (MpKsl7073bea5)
DRV - [2011.04.27 14:25:24 | 000,065,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011.04.18 12:18:50 | 000,043,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MpNWMon.sys -- (MpNWMon)
DRV - [2010.08.12 12:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVNET)
DRV - [2009.10.07 00:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009.04.30 21:55:58 | 002,687,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2007.08.09 18:12:30 | 000,110,624 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32)
DRV - [2007.01.19 00:03:24 | 002,314,752 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006.11.02 08:30:56 | 000,429,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm60x32.sys -- (NVENETFD)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook: {3d684ca7-5d30-4a7e-9768-e17df98df80f} - C:\Programme\Messenger_Plus_DE\prxtbMess.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN, Hotmail und Messenger sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 24 37 BA 3E B3 D6 CB 01  [binary data]
IE - HKCU\..\URLSearchHook: {3d684ca7-5d30-4a7e-9768-e17df98df80f} - C:\Programme\Messenger_Plus_DE\prxtbMess.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.de"
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2
FF - prefs.js..extensions.enabledItems: {3d684ca7-5d30-4a7e-9768-e17df98df80f}:3.3.3.2
FF - prefs.js..extensions.enabledItems: infofrimonde@83d.de:0.91
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties"
FF - prefs.js..network.proxy.type: 0
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.11 07:52:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.06.27 07:26:47 | 000,000,000 | ---D | M]
 
[2011.02.28 18:55:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pizzaro\AppData\Roaming\mozilla\Extensions
[2011.11.19 01:07:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pizzaro\AppData\Roaming\mozilla\Firefox\Profiles\vj33xm3l.default\extensions
[2011.07.31 09:56:19 | 000,002,399 | ---- | M] () -- C:\Users\Pizzaro\AppData\Roaming\Mozilla\Firefox\Profiles\vj33xm3l.default\searchplugins\askcom.xml
[2011.03.19 13:19:33 | 000,000,873 | ---- | M] () -- C:\Users\Pizzaro\AppData\Roaming\Mozilla\Firefox\Profiles\vj33xm3l.default\searchplugins\conduit.xml
[2011.10.09 09:38:11 | 000,002,770 | ---- | M] () -- C:\Users\Pizzaro\AppData\Roaming\Mozilla\Firefox\Profiles\vj33xm3l.default\searchplugins\Plusnetwork.xml
[2011.11.09 10:58:17 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.11.09 10:58:18 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
() (No name found) -- C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) -- C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011.11.11 07:52:37 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.03 09:23:23 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.03 09:23:23 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.03 09:23:23 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.03 09:23:23 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.03 09:23:23 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.03 09:23:23 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - Extension: Skype Extension = C:\Users\Pizzaro\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.3.0.7550_0\
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Messenger Plus DE Toolbar) - {3d684ca7-5d30-4a7e-9768-e17df98df80f} - C:\Programme\Messenger_Plus_DE\prxtbMess.dll (Conduit Ltd.)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Messenger Plus DE Toolbar) - {3d684ca7-5d30-4a7e-9768-e17df98df80f} - C:\Programme\Messenger_Plus_DE\prxtbMess.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (Messenger Plus DE Toolbar) - {3D684CA7-5D30-4A7E-9768-E17DF98DF80F} - C:\Programme\Messenger_Plus_DE\prxtbMess.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PlusService] C:\Programme\Yuna Software\Messenger Plus!\PlusService.exe (Yuna Software)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKCU..\Run: [EPSON SX100 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files\Logitech\Logitech Vid\vid.exe (Logitech Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Pizzaro\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B5C4F12B-F75C-44A9-A4C1-3DB7BBD83FAB}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Fotogalerie-Hintergrundbild.jpg
O24 - Desktop BackupWallPaper: C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Fotogalerie-Hintergrundbild.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{e7a9bf8e-41eb-11e0-b108-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{e7a9bf8e-41eb-11e0-b108-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpReg: Sidebar - hkey= - key= - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
MsConfig - StartUpReg: WMPNSCFG - hkey= - key= - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
MsConfig - State: "startup" - 2
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MsMpSvc - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: MsMpSvc - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.11.28 14:22:25 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Roaming\Malwarebytes
[2011.11.28 14:22:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.11.28 14:22:05 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.11.28 14:22:04 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.11.28 14:21:17 | 009,852,544 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Pizzaro\Desktop\mbam-setup-1.51.2.1300.exe
[2011.11.28 14:14:30 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Pizzaro\Desktop\esetsmartinstaller_enu.exe
[2011.11.28 11:45:03 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{CA0753A8-41AE-47BF-ABF3-576E3C534BFB}
[2011.11.28 11:45:00 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{149ACC53-759F-414D-ABC9-028F49F3497D}
[2011.11.28 10:08:24 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Pizzaro\Desktop\OTL.exe
[2011.11.27 22:46:46 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{D29F183C-F058-4B9D-BBAD-7C03259A2B40}
[2011.11.27 22:46:42 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{7F5AFA83-0F3B-4C7E-90E8-2165FAF6F8E9}
[2011.11.27 10:46:16 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{EF3454A7-BFE8-4A38-BAFB-5AD0CD56B59D}
[2011.11.27 10:46:06 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{D98D780E-D420-4E66-9F89-129200DE32EA}
[2011.11.26 22:39:36 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{D76CC415-6B0B-4657-8122-E8D25F35F564}
[2011.11.26 22:39:32 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{D9D6EA1C-D536-4749-84EC-7E2BE69214C5}
[2011.11.26 10:39:08 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{F0DE4794-E5A8-4BE3-A1B0-7F6A17C3BD95}
[2011.11.26 10:38:59 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{05BCA5C2-27A7-4D24-8638-0F238DFF3C4B}
[2011.11.25 10:27:37 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{C9D7CC17-6F9B-4DD2-B5F1-3235B278F659}
[2011.11.25 10:27:26 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{1BB86D78-B1ED-419C-B195-B0132600A2E6}
[2011.11.24 13:18:42 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{B700263C-18AF-4667-B323-6124CEF74387}
[2011.11.24 13:18:31 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{88F4610A-8C69-463F-8026-3220EF62405E}
[2011.11.23 12:15:20 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{92C08D3E-AF0D-45A5-B92D-1DDC7EB86B5A}
[2011.11.23 12:15:12 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{8A7B118F-43B3-41CC-92FA-57DF8B0C585D}
[2011.11.22 16:51:21 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan
[2011.11.22 16:51:21 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NSS
[2011.11.22 16:51:21 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Security Scan
[2011.11.22 16:51:21 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NSS\0305010.008
[2011.11.22 10:43:16 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{8751E8D7-A6D9-4E77-BE96-0FE26EB05B4C}
[2011.11.22 10:43:08 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{A0B35B89-EC70-49AA-97CF-39CB8E28F744}
[2011.11.21 09:59:00 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{E7B56B18-5088-4A62-B3AD-DE6A105D3E65}
[2011.11.21 09:58:52 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{A8E70826-D5B1-4975-8540-6F1D6576AF1F}
[2011.11.20 11:57:30 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{A53155A2-D93E-4529-9CAA-64709DDA995A}
[2011.11.20 11:57:21 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{647D67DC-A184-4C9F-9570-283670DF03C1}
[2011.11.19 20:33:09 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{D4AB4EDB-B507-40D6-B2AC-3429161039FD}
[2011.11.19 20:33:00 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{856175AC-887A-4327-98CE-35C67FAE8352}
[2011.11.19 01:07:30 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{F8473D43-1A20-453F-B7E1-8F1255B908D3}
[2011.11.19 01:07:22 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{424BF33D-3860-4A26-A6D9-F2392F219A15}
[2011.11.18 09:20:00 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{55B74A35-5561-45F7-9441-D2CB7D0CFDC4}
[2011.11.18 09:19:49 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{F1B96442-A43C-4915-A5E9-4C9F7F074ACF}
[2011.11.17 13:19:22 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{3C9106BD-26D8-4195-AFEF-327357A3BAE2}
[2011.11.17 13:19:12 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{AE41B320-45DF-494F-BE6A-99B96F8BE18A}
[2011.11.16 10:29:15 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{57EA2522-B63A-4BE3-8320-BE2EF18B3337}
[2011.11.16 10:29:06 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{5A66A524-0A68-4D3E-B995-9AA69F4CA01C}
[2011.11.15 12:19:15 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{D36CD698-84CF-4AC3-9373-024C4CD971F2}
[2011.11.15 12:19:06 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{843A0C4C-2C5C-47DA-A001-70A4CD061EB7}
[2011.11.14 19:57:12 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{7F5BDB99-4A27-4C50-ABC8-2D4F7706283C}
[2011.11.14 19:57:07 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{90DC7CA3-CE8D-4212-9448-813BD4E7BFF2}
[2011.11.14 07:56:29 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{2A539F61-FB5D-4C78-AEB8-9B1C26DBD269}
[2011.11.14 07:56:20 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{7A2D8C26-248A-4B24-B2FC-A0996DDC39EF}
[2011.11.13 10:11:45 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{B2441FB4-D06E-4CFD-ACD9-EC03B350A696}
[2011.11.13 10:11:42 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{ADB53CF8-6229-4613-91CB-B7038192B233}
[2011.11.12 22:11:25 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{7772D4D2-A63C-41B3-91FB-A6C6052BF8DE}
[2011.11.12 22:11:21 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{8A4807EF-5DA9-4D5B-B03A-A1252700CF4A}
[2011.11.12 10:10:58 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{8247DD13-1A02-4300-AEC2-553DA3FEFD99}
[2011.11.12 10:10:50 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{9F16CB59-3322-46D5-92D3-1CF8386A0C1E}
[2011.11.11 09:02:33 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{9B20A466-0803-4EF3-A148-681B74ABAD52}
[2011.11.11 09:02:25 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{669FE899-3E76-4F95-9014-761E24020C67}
[2011.11.11 07:50:48 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{1CEE3589-C63E-4B43-85AB-E694E69D0F83}
[2011.11.10 11:51:01 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{4D7EEF31-4924-4CF1-8554-3C77B7D78CB8}
[2011.11.10 11:50:54 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{BEFD93DB-34A5-42CD-89DF-46EB54265B77}
[2011.11.09 10:58:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011.11.09 09:35:59 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{051EA58D-8AF2-4D08-A9E5-A8088FC3D05D}
[2011.11.09 09:35:55 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{48B33551-A966-4D4D-84EE-E4A47806120D}
[2011.11.08 21:35:38 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{30EFF5E2-98FD-479D-89EC-70A451515511}
[2011.11.08 21:35:34 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{0D29CC57-F20F-4920-AD73-4B8CE6ADFDAF}
[2011.11.08 09:35:17 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{4628727E-659E-46AA-84C1-F867C108F73B}
[2011.11.08 09:35:13 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{BD44C70D-1604-4ED2-83DA-2C4E1660628F}
[2011.11.07 21:34:57 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{6EC32B06-510F-4A39-BA07-564DA069A00C}
[2011.11.07 21:34:53 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{85348CE2-4339-447B-8740-6BEADD30C78B}
[2011.11.07 09:34:23 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{CF3CFE52-17A9-41AD-8FA4-CA3B804E5B8F}
[2011.11.07 09:34:10 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{070E213E-42A7-4BBD-B0FA-4A5F212FB077}
[2011.11.06 10:20:00 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{86614248-4FB4-4078-B3A2-D9372CA59790}
[2011.11.06 10:19:49 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{099D50B5-FE37-4CF9-A332-9D30B3B3F6DE}
[2011.11.05 17:16:44 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{E86EF673-AAF2-44C6-9475-2921CFEA0521}
[2011.11.05 17:16:37 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{69BE9C85-A09F-4EA5-8287-0529048E278B}
[2011.11.05 10:21:24 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{C3609234-5D41-4F2D-9071-09BB0C517019}
[2011.11.04 08:57:30 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{24F15DEB-83A1-422D-B290-F7302571611E}
[2011.11.04 08:57:22 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{CA6CFFF8-B4D4-4D85-B145-C6F500F6BFA9}
[2011.11.03 13:33:01 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{73D8FC93-68AE-445A-8D66-5ECDE2E47F05}
[2011.11.03 13:32:48 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{9C25737D-DC68-40C8-9852-CE9C278DEFC7}
[2011.11.02 09:37:35 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{B249640F-E181-4D88-BFFC-5C901F3AB5DE}
[2011.11.02 09:37:23 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{50BC6FBC-FB11-4956-A8B3-0BB323B5F2EE}
[2011.11.01 15:47:50 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{349B9A7F-FE6E-4897-992C-CAD789BE2ECD}
[2011.11.01 15:47:38 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{6C1769CF-B1EE-4A9F-85E7-F1D4603D8503}
[2011.10.31 19:41:05 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{EEEDBDE4-393D-4C9C-8976-5BF6C1C704BD}
[2011.10.31 19:41:04 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{1E7D61AC-B4CA-40B9-A1C5-A90164B1395A}
[2011.10.31 19:22:01 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{F725BA34-9357-42F4-AAC8-42610EDC1C11}
[2011.10.30 10:13:19 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{3A0361C3-D767-4409-903E-73857899378A}
[2011.10.30 10:13:08 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{F2F96A10-4C47-4372-A038-6C344A1D5C2E}
[2011.10.29 20:26:34 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{896C953D-3180-4CFD-80DB-CB584DD64CDA}
[2011.10.29 20:26:31 | 000,000,000 | ---D | C] -- C:\Users\Pizzaro\AppData\Local\{51748274-5C16-4EF0-BCBE-21EBE155D540}
 
========== Files - Modified Within 30 Days ==========
 
[2011.11.28 18:05:33 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.11.28 18:05:33 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.11.28 14:22:13 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.11.28 14:21:23 | 009,852,544 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Pizzaro\Desktop\mbam-setup-1.51.2.1300.exe
[2011.11.28 14:14:33 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Pizzaro\Desktop\esetsmartinstaller_enu.exe
[2011.11.28 10:23:48 | 000,302,592 | ---- | M] () -- C:\Users\Pizzaro\Desktop\pfq22tqk.exe
[2011.11.28 10:11:24 | 000,673,312 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.11.28 10:11:24 | 000,634,042 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.11.28 10:11:24 | 000,145,186 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.11.28 10:11:24 | 000,119,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.11.28 10:08:35 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Pizzaro\Desktop\OTL.exe
[2011.11.28 10:07:19 | 000,000,000 | ---- | M] () -- C:\Users\Pizzaro\defogger_reenable
[2011.11.28 10:05:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.11.28 10:05:20 | 2145,849,344 | -HS- | M] () -- C:\hiberfil.sys
[2011.11.28 10:00:22 | 000,050,477 | ---- | M] () -- C:\Users\Pizzaro\Desktop\Defogger.exe
[2011.11.24 21:43:54 | 000,081,427 | ---- | M] () -- C:\Users\Pizzaro\Desktop\10_905036b4fc9bf2a9cb2ea6283abd6ec0.jpg
[2011.11.24 15:42:56 | 000,000,440 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Pizzaro.job
[2011.11.24 14:22:55 | 000,164,818 | ---- | M] () -- C:\Users\Pizzaro\Desktop\pflanzen3.pdf
[2011.11.22 16:51:25 | 000,001,128 | ---- | M] () -- C:\Users\Public\Desktop\Norton Security Scan.lnk
[2011.11.22 15:13:50 | 000,388,154 | ---- | M] () -- C:\Users\Pizzaro\Desktop\Probeliegen-erlaubt-Auslegungssache-a22825816.jpg
[2011.11.22 15:11:09 | 000,357,214 | ---- | M] () -- C:\Users\Pizzaro\Desktop\Vielleicht-machen-die-Umdrehungen-in-der-Wachmaschine-tatsaechlich-wach-a22974431.jpg
[2011.11.22 15:01:03 | 000,380,093 | ---- | M] () -- C:\Users\Pizzaro\Desktop\Eindeutig-zweideutig-a22750862.jpg
[2011.11.22 14:53:48 | 000,034,341 | ---- | M] () -- C:\Users\Pizzaro\Desktop\funny04720823071.jpg
[2011.11.21 11:21:40 | 000,023,049 | ---- | M] () -- C:\Users\Pizzaro\Desktop\18949446_401_ich_bin_nicht_da_H173442_L.jpg
[2011.11.19 14:28:20 | 002,395,077 | ---- | M] () -- C:\Users\Pizzaro\Desktop\DSC06574.JPG
[2011.11.19 14:26:48 | 002,478,386 | ---- | M] () -- C:\Users\Pizzaro\Desktop\DSC06573.JPG
[2011.11.19 14:26:40 | 000,326,763 | ---- | M] () -- C:\Users\Pizzaro\Desktop\DSC06572.JPG
[2011.11.19 14:26:30 | 002,206,247 | ---- | M] () -- C:\Users\Pizzaro\Desktop\DSC06571.JPG
[2011.11.13 09:39:50 | 002,234,975 | ---- | M] () -- C:\Users\Pizzaro\Desktop\DSC06563.JPG
[2011.11.13 09:39:36 | 002,252,303 | ---- | M] () -- C:\Users\Pizzaro\Desktop\DSC06562.JPG
[2011.11.12 12:34:27 | 000,006,061 | ---- | M] () -- C:\Users\Pizzaro\Desktop\Smiley_traurig.jpg
[2011.11.10 19:52:03 | 000,033,616 | ---- | M] () -- C:\Users\Pizzaro\Desktop\36271_192352800779622_100000147102749_773714_6972341_n.jpg
[2011.11.09 10:58:11 | 000,001,878 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011.11.02 15:00:13 | 000,093,994 | ---- | M] () -- C:\Users\Pizzaro\Desktop\391934_10150369415124528_69448024527_8066824_1134879033_n.jpg
 
========== Files Created - No Company Name ==========
 
[2011.11.28 14:22:13 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.11.28 10:23:40 | 000,302,592 | ---- | C] () -- C:\Users\Pizzaro\Desktop\pfq22tqk.exe
[2011.11.28 10:02:33 | 000,000,000 | ---- | C] () -- C:\Users\Pizzaro\defogger_reenable
[2011.11.28 10:00:21 | 000,050,477 | ---- | C] () -- C:\Users\Pizzaro\Desktop\Defogger.exe
[2011.11.24 21:43:53 | 000,081,427 | ---- | C] () -- C:\Users\Pizzaro\Desktop\10_905036b4fc9bf2a9cb2ea6283abd6ec0.jpg
[2011.11.24 14:22:55 | 000,164,818 | ---- | C] () -- C:\Users\Pizzaro\Desktop\pflanzen3.pdf
[2011.11.22 16:51:25 | 000,001,128 | ---- | C] () -- C:\Users\Public\Desktop\Norton Security Scan.lnk
[2011.11.22 16:51:21 | 000,000,172 | ---- | C] () -- C:\Windows\System32\drivers\NSS\0305010.008\isolate.ini
[2011.11.22 15:13:50 | 000,388,154 | ---- | C] () -- C:\Users\Pizzaro\Desktop\Probeliegen-erlaubt-Auslegungssache-a22825816.jpg
[2011.11.22 15:11:09 | 000,357,214 | ---- | C] () -- C:\Users\Pizzaro\Desktop\Vielleicht-machen-die-Umdrehungen-in-der-Wachmaschine-tatsaechlich-wach-a22974431.jpg
[2011.11.22 15:01:02 | 000,380,093 | ---- | C] () -- C:\Users\Pizzaro\Desktop\Eindeutig-zweideutig-a22750862.jpg
[2011.11.22 14:53:47 | 000,034,341 | ---- | C] () -- C:\Users\Pizzaro\Desktop\funny04720823071.jpg
[2011.11.21 11:21:39 | 000,023,049 | ---- | C] () -- C:\Users\Pizzaro\Desktop\18949446_401_ich_bin_nicht_da_H173442_L.jpg
[2011.11.19 21:00:14 | 002,478,386 | ---- | C] () -- C:\Users\Pizzaro\Desktop\DSC06573.JPG
[2011.11.19 21:00:14 | 002,395,077 | ---- | C] () -- C:\Users\Pizzaro\Desktop\DSC06574.JPG
[2011.11.19 21:00:14 | 002,206,247 | ---- | C] () -- C:\Users\Pizzaro\Desktop\DSC06571.JPG
[2011.11.19 21:00:14 | 000,326,763 | ---- | C] () -- C:\Users\Pizzaro\Desktop\DSC06572.JPG
[2011.11.14 15:36:15 | 002,252,303 | ---- | C] () -- C:\Users\Pizzaro\Desktop\DSC06562.JPG
[2011.11.14 15:36:15 | 002,234,975 | ---- | C] () -- C:\Users\Pizzaro\Desktop\DSC06563.JPG
[2011.11.12 12:34:24 | 000,006,061 | ---- | C] () -- C:\Users\Pizzaro\Desktop\Smiley_traurig.jpg
[2011.11.10 19:51:41 | 000,033,616 | ---- | C] () -- C:\Users\Pizzaro\Desktop\36271_192352800779622_100000147102749_773714_6972341_n.jpg
[2011.11.09 10:58:11 | 000,001,878 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2011.11.02 15:00:10 | 000,093,994 | ---- | C] () -- C:\Users\Pizzaro\Desktop\391934_10150369415124528_69448024527_8066824_1134879033_n.jpg
[2011.06.12 21:01:36 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.02.28 19:16:15 | 000,087,552 | ---- | C] () -- C:\Users\Pizzaro\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.02.28 19:11:21 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2011.02.28 19:11:21 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat
[2011.02.28 19:11:21 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat
[2011.02.28 19:11:21 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2011.02.28 19:11:21 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
[2011.02.28 19:11:21 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
[2011.02.28 19:11:21 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2011.02.28 19:11:21 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
[2011.02.28 19:11:21 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
[2011.02.28 19:11:21 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat
[2011.02.28 19:11:21 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
[2011.02.28 19:11:21 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
[2011.02.28 19:11:21 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
[2011.02.28 19:11:21 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
[2011.02.28 19:11:21 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
[2011.02.28 19:11:21 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat
[2011.02.28 19:11:21 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat
[2011.02.28 19:11:21 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
[2011.02.28 19:11:21 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2011.02.28 19:03:51 | 000,000,025 | ---- | C] () -- C:\Windows\CDESX100DEFGIPS.ini
[2011.02.27 20:48:01 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2011.02.27 15:42:38 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011.02.27 15:21:17 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011.02.27 15:21:17 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.02.26 22:00:20 | 000,011,164 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2009.10.07 00:46:36 | 000,025,752 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2009.10.07 00:23:08 | 000,013,584 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll
[2009.08.27 08:04:12 | 000,207,400 | R--- | C] () -- C:\Windows\GSetup.exe
[2009.04.30 21:39:36 | 000,082,289 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2006.12.11 05:06:31 | 000,000,000 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2006.11.02 16:33:31 | 000,673,312 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 16:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 16:33:31 | 000,145,186 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 16:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:47:37 | 000,256,800 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:33:01 | 000,634,042 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,119,568 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.02.28 17:18:34 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\Adobe
[2011.07.30 19:06:21 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\DVDVideoSoft
[2011.03.19 12:53:19 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.03.14 23:14:08 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\gtk-2.0
[2011.02.26 15:45:38 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\Identities
[2011.02.28 19:11:19 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\InstallShield
[2011.07.27 12:01:42 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\Kiddinx
[2011.06.12 21:37:57 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\Leadertech
[2011.02.28 20:04:06 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\Macromedia
[2011.11.28 14:22:25 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\Malwarebytes
[2006.11.02 13:37:34 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\Media Center Programs
[2011.04.04 19:23:34 | 000,000,000 | --SD | M] -- C:\Users\Pizzaro\AppData\Roaming\Microsoft
[2011.02.28 18:55:47 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\Mozilla
[2011.02.28 23:10:26 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\OpenOffice.org
[2011.10.26 09:18:13 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\Origin
[2011.11.28 18:05:47 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\Skype
[2011.11.09 10:00:10 | 000,000,000 | ---D | M] -- C:\Users\Pizzaro\AppData\Roaming\skypePM
 
< %APPDATA%\*.exe /s >
[2011.03.07 14:48:15 | 000,010,134 | R--- | M] () -- C:\Users\Pizzaro\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.19 08:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.19 08:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2007.04.17 09:30:38 | 000,021,688 | ---- | M] (Microsoft Corporation) MD5=78620BDA3EC87816E5D1FA86F920BC3A -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c2a1b5ae\atapi.sys
[2007.04.17 09:30:38 | 000,021,688 | ---- | M] (Microsoft Corporation) MD5=78620BDA3EC87816E5D1FA86F920BC3A -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20518_none_dbd8b4d73d81c9d0\atapi.sys
[2008.01.19 06:06:48 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.01.19 06:06:48 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.01.19 05:33:23 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_64dfd8ea\atapi.sys
[2008.01.19 05:33:23 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.19 08:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.19 08:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2006.11.02 10:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.19 08:35:36 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2007.01.05 21:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 -- C:\Windows\System32\drivers\nvstor.sys
[2007.01.05 21:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_45f67928\nvstor.sys
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.19 08:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.19 08:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: NVSTOR32.SYS  >
[2007.08.09 18:12:30 | 000,110,624 | ---- | M] (NVIDIA Corporation) MD5=DC5F166422BEEBF195E3E4BB8AB4EE22 -- C:\Windows\System32\drivers\nvstor32.sys
[2007.08.09 18:12:30 | 000,110,624 | ---- | M] (NVIDIA Corporation) MD5=DC5F166422BEEBF195E3E4BB8AB4EE22 -- C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_99d8b088\nvstor32.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.19 08:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 10:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2011.02.26 19:53:02 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=63B4F59D7C89B1BF5277F1FFEFD491CD -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_cb39bc5b7047127e\user32.dll
[2011.02.26 19:53:02 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=9D9F061EDA75425FC67F0365E3467C86 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_cbc258dc896598f1\user32.dll
[2008.01.19 08:36:46 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2006.11.02 10:46:13 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=E698A5437B89A285ACA3FF022356810A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_cb01aa4570716e5e\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 10:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.19 08:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.19 08:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2006.11.02 10:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 10:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 08:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2006.11.02 09:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys
[2008.01.19 06:56:49 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.19 06:56:49 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2011.04.18 12:18:50 | 000,043,392 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\drivers\MpNWMon.sys
 
< %systemroot%\System32\config\*.sav >
[2006.11.02 11:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006.11.02 11:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006.11.02 11:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---

PinaColada 28.11.2011 18:50

ich find es einfach super das es so eine seite wie diese gibt :taenzer:

cosinus 28.11.2011 19:53

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKLM\..\URLSearchHook: {3d684ca7-5d30-4a7e-9768-e17df98df80f} - C:\Programme\Messenger_Plus_DE\prxtbMess.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN, Hotmail und Messenger sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 24 37 BA 3E B3 D6 CB 01  [binary data]
IE - HKCU\..\URLSearchHook: {3d684ca7-5d30-4a7e-9768-e17df98df80f} - C:\Programme\Messenger_Plus_DE\prxtbMess.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2
FF - prefs.js..extensions.enabledItems: infofrimonde@83d.de:0.91
FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties"
FF - prefs.js..network.proxy.type: 0
[2011.07.31 09:56:19 | 000,002,399 | ---- | M] () -- C:\Users\Pizzaro\AppData\Roaming\Mozilla\Firefox\Profiles\vj33xm3l.default\searchplugins\askcom.xml
[2011.03.19 13:19:33 | 000,000,873 | ---- | M] () -- C:\Users\Pizzaro\AppData\Roaming\Mozilla\Firefox\Profiles\vj33xm3l.default\searchplugins\conduit.xml
[2011.10.09 09:38:11 | 000,002,770 | ---- | M] () -- C:\Users\Pizzaro\AppData\Roaming\Mozilla\Firefox\Profiles\vj33xm3l.default\searchplugins\Plusnetwork.xml
O2 - BHO: (Messenger Plus DE Toolbar) - {3d684ca7-5d30-4a7e-9768-e17df98df80f} - C:\Programme\Messenger_Plus_DE\prxtbMess.dll (Conduit Ltd.)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Messenger Plus DE Toolbar) - {3d684ca7-5d30-4a7e-9768-e17df98df80f} - C:\Programme\Messenger_Plus_DE\prxtbMess.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{e7a9bf8e-41eb-11e0-b108-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{e7a9bf8e-41eb-11e0-b108-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Autorun.exe
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

PinaColada 28.11.2011 20:19

Ich hatte konnte nur OK an klicken für einen neustart und danach war gleich folgendes Fenster auf :

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{3d684ca7-5d30-4a7e-9768-e17df98df80f} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3d684ca7-5d30-4a7e-9768-e17df98df80f}\ deleted successfully.
C:\Programme\Messenger_Plus_DE\prxtbMess.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ deleted successfully.
C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll moved successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{3d684ca7-5d30-4a7e-9768-e17df98df80f} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3d684ca7-5d30-4a7e-9768-e17df98df80f}\ not found.
File C:\Programme\Messenger_Plus_DE\prxtbMess.dll not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found.
File C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "Search" removed from browser.search.defaultthis.engineName
Prefs.js: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: engine@conduit.com:3.3.3.2 removed from extensions.enabledItems
Prefs.js: infofrimonde@83d.de:0.91 removed from extensions.enabledItems
Prefs.js: "chrome://browser-region/locale/region.properties" removed from keyword.URL
Prefs.js: 0 removed from network.proxy.type
C:\Users\Pizzaro\AppData\Roaming\Mozilla\Firefox\Profiles\vj33xm3l.default\searchplugins\askcom.xml moved successfully.
C:\Users\Pizzaro\AppData\Roaming\Mozilla\Firefox\Profiles\vj33xm3l.default\searchplugins\conduit.xml moved successfully.
C:\Users\Pizzaro\AppData\Roaming\Mozilla\Firefox\Profiles\vj33xm3l.default\searchplugins\Plusnetwork.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3d684ca7-5d30-4a7e-9768-e17df98df80f}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3d684ca7-5d30-4a7e-9768-e17df98df80f}\ not found.
File C:\Programme\Messenger_Plus_DE\prxtbMess.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found.
File C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{3d684ca7-5d30-4a7e-9768-e17df98df80f} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3d684ca7-5d30-4a7e-9768-e17df98df80f}\ not found.
File C:\Programme\Messenger_Plus_DE\prxtbMess.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found.
File C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e7a9bf8e-41eb-11e0-b108-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e7a9bf8e-41eb-11e0-b108-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e7a9bf8e-41eb-11e0-b108-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e7a9bf8e-41eb-11e0-b108-806e6f6e6963}\ not found.
File E:\Autorun.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Pizzaro
->Temp folder emptied: 203084754 bytes
->Temporary Internet Files folder emptied: 174631834 bytes
->Java cache emptied: 5372309 bytes
->FireFox cache emptied: 1043158669 bytes
->Google Chrome cache emptied: 819568 bytes
->Flash cache emptied: 23773 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1083212 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1.362,00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.31.0 log created on 11282011_200200

Files\Folders moved on Reboot...
File move failed. C:\Windows\temp\logishrd\LVPrcInj01.dll scheduled to be moved on reboot.

Registry entries deleted on Reboot...

cosinus 29.11.2011 09:43

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

PinaColada 29.11.2011 13:17

13:22:24.0988 2088 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44
13:22:25.0533 2088 ============================================================
13:22:25.0534 2088 Current date / time: 2011/11/29 13:22:25.0533
13:22:25.0534 2088 SystemInfo:
13:22:25.0534 2088
13:22:25.0534 2088 OS Version: 6.0.6002 ServicePack: 2.0
13:22:25.0534 2088 Product type: Workstation
13:22:25.0534 2088 ComputerName: PIZZARO-PC
13:22:25.0535 2088 UserName: Pizzaro
13:22:25.0535 2088 Windows directory: C:\Windows
13:22:25.0535 2088 System windows directory: C:\Windows
13:22:25.0535 2088 Processor architecture: Intel x86
13:22:25.0535 2088 Number of processors: 4
13:22:25.0535 2088 Page size: 0x1000
13:22:25.0535 2088 Boot type: Normal boot
13:22:25.0535 2088 ============================================================
13:22:26.0247 2088 Initialize success
13:22:31.0685 2604 ============================================================
13:22:31.0685 2604 Scan started
13:22:31.0685 2604 Mode: Manual; SigCheck; TDLFS;
13:22:31.0685 2604 ============================================================
13:22:31.0884 2604 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
13:22:32.0059 2604 ACPI - ok
13:22:32.0114 2604 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
13:22:32.0168 2604 adp94xx - ok
13:22:32.0211 2604 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
13:22:32.0257 2604 adpahci - ok
13:22:32.0278 2604 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
13:22:32.0323 2604 adpu160m - ok
13:22:32.0346 2604 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
13:22:32.0399 2604 adpu320 - ok
13:22:32.0443 2604 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
13:22:32.0514 2604 AFD - ok
13:22:32.0526 2604 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
13:22:32.0569 2604 aic78xx - ok
13:22:32.0594 2604 aliide (496eda16a127ac9a38bb285bef17dbb5) C:\Windows\system32\drivers\aliide.sys
13:22:32.0620 2604 aliide - ok
13:22:32.0641 2604 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
13:22:32.0676 2604 amdagp - ok
13:22:32.0694 2604 amdide (6f65f4147c54398d7280b18cebbed215) C:\Windows\system32\drivers\amdide.sys
13:22:32.0720 2604 amdide - ok
13:22:32.0733 2604 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
13:22:32.0828 2604 AmdK7 - ok
13:22:32.0845 2604 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
13:22:32.0946 2604 AmdK8 - ok
13:22:32.0968 2604 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
13:22:33.0008 2604 arc - ok
13:22:33.0022 2604 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
13:22:33.0062 2604 arcsas - ok
13:22:33.0107 2604 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
13:22:33.0171 2604 AsyncMac - ok
13:22:33.0207 2604 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
13:22:33.0241 2604 atapi - ok
13:22:33.0289 2604 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
13:22:33.0335 2604 Beep - ok
13:22:33.0354 2604 blbdrive - ok
13:22:33.0387 2604 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
13:22:33.0435 2604 bowser - ok
13:22:33.0452 2604 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
13:22:33.0508 2604 BrFiltLo - ok
13:22:33.0521 2604 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
13:22:33.0556 2604 BrFiltUp - ok
13:22:33.0580 2604 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
13:22:33.0704 2604 Brserid - ok
13:22:33.0719 2604 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
13:22:33.0826 2604 BrSerWdm - ok
13:22:33.0845 2604 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
13:22:33.0915 2604 BrUsbMdm - ok
13:22:33.0924 2604 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
13:22:33.0993 2604 BrUsbSer - ok
13:22:34.0013 2604 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
13:22:34.0082 2604 BTHMODEM - ok
13:22:34.0115 2604 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
13:22:34.0164 2604 cdfs - ok
13:22:34.0200 2604 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
13:22:34.0248 2604 cdrom - ok
13:22:34.0265 2604 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
13:22:34.0332 2604 circlass - ok
13:22:34.0366 2604 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
13:22:34.0424 2604 CLFS - ok
13:22:34.0458 2604 cmdide (59172a0724f2ab769f31d61b0571d75b) C:\Windows\system32\drivers\cmdide.sys
13:22:34.0489 2604 cmdide - ok
13:22:34.0499 2604 Compbatt (82b8c91d327cfecf76cb58716f7d4997) C:\Windows\system32\drivers\compbatt.sys
13:22:34.0534 2604 Compbatt - ok
13:22:34.0560 2604 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
13:22:34.0592 2604 crcdisk - ok
13:22:34.0610 2604 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
13:22:34.0713 2604 Crusoe - ok
13:22:34.0758 2604 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
13:22:34.0795 2604 DfsC - ok
13:22:34.0842 2604 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
13:22:34.0880 2604 disk - ok
13:22:34.0937 2604 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
13:22:34.0958 2604 drmkaud - ok
13:22:35.0011 2604 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
13:22:35.0086 2604 DXGKrnl - ok
13:22:35.0103 2604 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
13:22:35.0261 2604 E1G60 - ok
13:22:35.0286 2604 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
13:22:35.0346 2604 Ecache - ok
13:22:35.0381 2604 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
13:22:35.0425 2604 elxstor - ok
13:22:35.0481 2604 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
13:22:35.0532 2604 exfat - ok
13:22:35.0574 2604 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
13:22:35.0635 2604 fastfat - ok
13:22:35.0654 2604 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
13:22:35.0757 2604 fdc - ok
13:22:35.0780 2604 FETNDIS (b2b2c38e916184ff8523c7439ddd417f) C:\Windows\system32\DRIVERS\fetnd5.sys
13:22:35.0900 2604 FETNDIS - ok
13:22:35.0934 2604 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
13:22:35.0982 2604 FileInfo - ok
13:22:36.0006 2604 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
13:22:36.0072 2604 Filetrace - ok
13:22:36.0090 2604 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
13:22:36.0189 2604 flpydisk - ok
13:22:36.0224 2604 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
13:22:36.0287 2604 FltMgr - ok
13:22:36.0360 2604 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys
13:22:36.0401 2604 fssfltr - ok
13:22:36.0422 2604 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
13:22:36.0472 2604 Fs_Rec - ok
13:22:36.0489 2604 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
13:22:36.0535 2604 gagp30kx - ok
13:22:36.0554 2604 gdrv - ok
13:22:36.0607 2604 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
13:22:36.0660 2604 HdAudAddService - ok
13:22:36.0693 2604 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
13:22:36.0811 2604 HDAudBus - ok
13:22:36.0835 2604 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
13:22:36.0940 2604 HidBth - ok
13:22:36.0951 2604 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
13:22:37.0049 2604 HidIr - ok
13:22:37.0090 2604 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
13:22:37.0141 2604 HidUsb - ok
13:22:37.0170 2604 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
13:22:37.0208 2604 HpCISSs - ok
13:22:37.0247 2604 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
13:22:37.0345 2604 HTTP - ok
13:22:37.0374 2604 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
13:22:37.0407 2604 i2omp - ok
13:22:37.0460 2604 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
13:22:37.0518 2604 i8042prt - ok
13:22:37.0536 2604 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
13:22:37.0599 2604 iaStorV - ok
13:22:37.0621 2604 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
13:22:37.0661 2604 iirsp - ok
13:22:37.0809 2604 IntcAzAudAddService (f42f2f88017a2e2b6f783acef6c2c149) C:\Windows\system32\drivers\RTKVHDA.sys
13:22:38.0034 2604 IntcAzAudAddService - ok
13:22:38.0067 2604 intelide (e5ea1c17da5065032e346591ff64f3af) C:\Windows\system32\drivers\intelide.sys
13:22:38.0098 2604 intelide - ok
13:22:38.0116 2604 intelppm (ce44cc04262f28216dd4341e9e36a16f) C:\Windows\system32\DRIVERS\intelppm.sys
13:22:38.0221 2604 intelppm - ok
13:22:38.0260 2604 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:22:38.0312 2604 IpFilterDriver - ok
13:22:38.0325 2604 IpInIp - ok
13:22:38.0348 2604 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
13:22:38.0439 2604 IPMIDRV - ok
13:22:38.0462 2604 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
13:22:38.0517 2604 IPNAT - ok
13:22:38.0543 2604 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
13:22:38.0588 2604 IRENUM - ok
13:22:38.0603 2604 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
13:22:38.0629 2604 isapnp - ok
13:22:38.0668 2604 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
13:22:38.0704 2604 iScsiPrt - ok
13:22:38.0719 2604 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
13:22:38.0750 2604 iteatapi - ok
13:22:38.0765 2604 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
13:22:38.0796 2604 iteraid - ok
13:22:38.0824 2604 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
13:22:38.0859 2604 kbdclass - ok
13:22:38.0897 2604 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
13:22:38.0937 2604 kbdhid - ok
13:22:38.0969 2604 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
13:22:39.0031 2604 KSecDD - ok
13:22:39.0066 2604 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
13:22:39.0116 2604 lltdio - ok
13:22:39.0139 2604 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
13:22:39.0170 2604 LSI_FC - ok
13:22:39.0190 2604 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
13:22:39.0216 2604 LSI_SAS - ok
13:22:39.0238 2604 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
13:22:39.0269 2604 LSI_SCSI - ok
13:22:39.0280 2604 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
13:22:39.0350 2604 luafv - ok
13:22:39.0385 2604 LVPr2Mon (1a7db7a00a4b0d8da24cd691a4547291) C:\Windows\system32\DRIVERS\LVPr2Mon.sys
13:22:39.0420 2604 LVPr2Mon - ok
13:22:39.0454 2604 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
13:22:39.0483 2604 megasas - ok
13:22:39.0511 2604 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
13:22:39.0571 2604 Modem - ok
13:22:39.0600 2604 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
13:22:39.0666 2604 monitor - ok
13:22:39.0706 2604 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
13:22:39.0746 2604 mouclass - ok
13:22:39.0760 2604 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
13:22:39.0824 2604 mouhid - ok
13:22:39.0846 2604 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
13:22:39.0882 2604 MountMgr - ok
13:22:39.0911 2604 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\Windows\system32\DRIVERS\MpFilter.sys
13:22:39.0965 2604 MpFilter - ok
13:22:39.0992 2604 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
13:22:40.0016 2604 mpio - ok
13:22:40.0098 2604 MpKsl68467d7a (5f53edfead46fa7adb78eee9ecce8fdf) C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{57E5E858-A79F-4684-97DC-32B9A264A279}\MpKsl68467d7a.sys
13:22:40.0135 2604 MpKsl68467d7a - ok
13:22:40.0140 2604 MpKsla7066217 - ok
13:22:40.0146 2604 MpKslb6ab3838 - ok
13:22:40.0161 2604 MpNWMon (2c3489660d4a8d514c123c3f0d67df46) C:\Windows\system32\DRIVERS\MpNWMon.sys
13:22:40.0205 2604 MpNWMon - ok
13:22:40.0219 2604 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
13:22:40.0265 2604 mpsdrv - ok
13:22:40.0295 2604 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
13:22:40.0331 2604 Mraid35x - ok
13:22:40.0358 2604 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
13:22:40.0413 2604 MRxDAV - ok
13:22:40.0436 2604 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:22:40.0501 2604 mrxsmb - ok
13:22:40.0532 2604 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:22:40.0596 2604 mrxsmb10 - ok
13:22:40.0612 2604 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:22:40.0659 2604 mrxsmb20 - ok
13:22:40.0692 2604 msahci (86068b8b54a5eb092f51657f00b2222a) C:\Windows\system32\drivers\msahci.sys
13:22:40.0725 2604 msahci - ok
13:22:40.0747 2604 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
13:22:40.0789 2604 msdsm - ok
13:22:40.0819 2604 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
13:22:40.0884 2604 Msfs - ok
13:22:40.0916 2604 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
13:22:40.0948 2604 msisadrv - ok
13:22:40.0998 2604 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
13:22:41.0045 2604 MSKSSRV - ok
13:22:41.0086 2604 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
13:22:41.0132 2604 MSPCLOCK - ok
13:22:41.0142 2604 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
13:22:41.0189 2604 MSPQM - ok
13:22:41.0228 2604 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
13:22:41.0271 2604 MsRPC - ok
13:22:41.0287 2604 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
13:22:41.0330 2604 mssmbios - ok
13:22:41.0341 2604 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
13:22:41.0389 2604 MSTEE - ok
13:22:41.0413 2604 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
13:22:41.0450 2604 Mup - ok
13:22:41.0485 2604 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
13:22:41.0534 2604 NativeWifiP - ok
13:22:41.0579 2604 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
13:22:41.0657 2604 NDIS - ok
13:22:41.0694 2604 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
13:22:41.0744 2604 NdisTapi - ok
13:22:41.0770 2604 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
13:22:41.0826 2604 Ndisuio - ok
13:22:41.0841 2604 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
13:22:41.0894 2604 NdisWan - ok
13:22:41.0921 2604 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
13:22:41.0981 2604 NDProxy - ok
13:22:41.0992 2604 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
13:22:42.0046 2604 NetBIOS - ok
13:22:42.0090 2604 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
13:22:42.0190 2604 netbt - ok
13:22:42.0255 2604 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
13:22:42.0292 2604 nfrd960 - ok
13:22:42.0314 2604 NisDrv (7b01c6172cfd0b10116175e09200d4b4) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
13:22:42.0393 2604 NisDrv - ok
13:22:42.0439 2604 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
13:22:42.0499 2604 Npfs - ok
13:22:42.0525 2604 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
13:22:42.0590 2604 nsiproxy - ok
13:22:42.0656 2604 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
13:22:42.0921 2604 Ntfs - ok
13:22:42.0933 2604 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
13:22:43.0044 2604 ntrigdigi - ok
13:22:43.0073 2604 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
13:22:43.0119 2604 Null - ok
13:22:43.0157 2604 NVENETFD (1657f3fbd9061526c14ff37e79306f98) C:\Windows\system32\DRIVERS\nvm60x32.sys
13:22:43.0274 2604 NVENETFD - ok
13:22:43.0334 2604 NVNET (1efec38a852ab35883bfff3427b92b3f) C:\Windows\system32\DRIVERS\nvmfdx32.sys
13:22:43.0387 2604 NVNET - ok
13:22:43.0403 2604 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
13:22:43.0445 2604 nvraid - ok
13:22:43.0476 2604 nvstor (4a5fcab82d9bf6af8a023a66802fe9e9) C:\Windows\system32\drivers\nvstor.sys
13:22:43.0518 2604 nvstor - ok
13:22:43.0537 2604 nvstor32 (dc5f166422beebf195e3e4bb8ab4ee22) C:\Windows\system32\DRIVERS\nvstor32.sys
13:22:43.0578 2604 nvstor32 - ok
13:22:43.0600 2604 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
13:22:43.0656 2604 nv_agp - ok
13:22:43.0666 2604 NwlnkFlt - ok
13:22:43.0680 2604 NwlnkFwd - ok
13:22:43.0711 2604 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\DRIVERS\ohci1394.sys
13:22:43.0846 2604 ohci1394 - ok
13:22:43.0889 2604 Parport (8a79fdf04a73428597e2caf9d0d67850) C:\Windows\system32\DRIVERS\parport.sys
13:22:43.0944 2604 Parport - ok
13:22:43.0985 2604 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
13:22:44.0025 2604 partmgr - ok
13:22:44.0037 2604 Parvdm (6c580025c81caf3ae9e3617c22cad00e) C:\Windows\system32\DRIVERS\parvdm.sys
13:22:44.0078 2604 Parvdm - ok
13:22:44.0118 2604 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
13:22:44.0160 2604 pci - ok
13:22:44.0178 2604 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
13:22:44.0204 2604 pciide - ok
13:22:44.0222 2604 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
13:22:44.0267 2604 pcmcia - ok
13:22:44.0320 2604 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
13:22:44.0465 2604 PEAUTH - ok
13:22:44.0599 2604 PID_PEPI (dd184d9adfe2a8a21741dbdfe9e22f5c) C:\Windows\system32\DRIVERS\LV302V32.SYS
13:22:44.0808 2604 PID_PEPI - ok
13:22:44.0853 2604 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
13:22:44.0920 2604 PptpMiniport - ok
13:22:44.0958 2604 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\DRIVERS\processr.sys
13:22:45.0025 2604 Processor - ok
13:22:45.0073 2604 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
13:22:45.0137 2604 PSched - ok
13:22:45.0187 2604 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
13:22:45.0272 2604 ql2300 - ok
13:22:45.0291 2604 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
13:22:45.0346 2604 ql40xx - ok
13:22:45.0370 2604 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
13:22:45.0417 2604 QWAVEdrv - ok
13:22:45.0501 2604 R300 (9afa62db7f553a0f1f52c70b738b0064) C:\Windows\system32\DRIVERS\atikmdag.sys
13:22:45.0648 2604 R300 - ok
13:22:45.0681 2604 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
13:22:45.0728 2604 RasAcd - ok
13:22:45.0748 2604 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
13:22:45.0817 2604 Rasl2tp - ok
13:22:45.0856 2604 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
13:22:45.0901 2604 RasPppoe - ok
13:22:45.0925 2604 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
13:22:45.0960 2604 RasSstp - ok
13:22:45.0991 2604 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
13:22:46.0091 2604 rdbss - ok
13:22:46.0109 2604 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
13:22:46.0156 2604 RDPCDD - ok
13:22:46.0182 2604 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
13:22:46.0274 2604 rdpdr - ok
13:22:46.0286 2604 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
13:22:46.0321 2604 RDPENCDD - ok
13:22:46.0349 2604 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
13:22:46.0402 2604 RDPWD - ok
13:22:46.0433 2604 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
13:22:46.0484 2604 rspndr - ok
13:22:46.0508 2604 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
13:22:46.0540 2604 sbp2port - ok
13:22:46.0567 2604 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
13:22:46.0665 2604 secdrv - ok
13:22:46.0685 2604 Serenum (ce9ec966638ef0b10b864ddedf62a099) C:\Windows\system32\DRIVERS\serenum.sys
13:22:46.0749 2604 Serenum - ok
13:22:46.0780 2604 Serial (6d663022db3e7058907784ae14b69898) C:\Windows\system32\DRIVERS\serial.sys
13:22:46.0901 2604 Serial - ok
13:22:46.0933 2604 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
13:22:46.0991 2604 sermouse - ok
13:22:47.0020 2604 sffdisk (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys
13:22:47.0112 2604 sffdisk - ok
13:22:47.0130 2604 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
13:22:47.0188 2604 sffp_mmc - ok
13:22:47.0202 2604 sffp_sd (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys
13:22:47.0296 2604 sffp_sd - ok
13:22:47.0306 2604 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
13:22:47.0366 2604 sfloppy - ok
13:22:47.0386 2604 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
13:22:47.0412 2604 SiSRaid2 - ok
13:22:47.0434 2604 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
13:22:47.0459 2604 SiSRaid4 - ok
13:22:47.0510 2604 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
13:22:47.0564 2604 Smb - ok
13:22:47.0586 2604 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
13:22:47.0614 2604 spldr - ok
13:22:47.0654 2604 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
13:22:47.0718 2604 srv - ok
13:22:47.0743 2604 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
13:22:47.0797 2604 srv2 - ok
13:22:47.0821 2604 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
13:22:47.0884 2604 srvnet - ok
13:22:47.0925 2604 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
13:22:47.0961 2604 swenum - ok
13:22:47.0987 2604 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
13:22:48.0026 2604 Symc8xx - ok
13:22:48.0047 2604 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
13:22:48.0083 2604 Sym_hi - ok
13:22:48.0105 2604 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
13:22:48.0143 2604 Sym_u3 - ok
13:22:48.0220 2604 Tcpip (16731b631f28f63cd9f4cb60940e7ddd) C:\Windows\system32\drivers\tcpip.sys
13:22:48.0318 2604 Tcpip - ok
13:22:48.0369 2604 Tcpip6 (16731b631f28f63cd9f4cb60940e7ddd) C:\Windows\system32\DRIVERS\tcpip.sys
13:22:48.0466 2604 Tcpip6 - ok
13:22:48.0506 2604 tcpipreg (3fc13f09af9be487c7b4fac4070a036c) C:\Windows\system32\drivers\tcpipreg.sys
13:22:48.0548 2604 tcpipreg - ok
13:22:48.0580 2604 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
13:22:48.0644 2604 TDPIPE - ok
13:22:48.0658 2604 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
13:22:48.0722 2604 TDTCP - ok
13:22:48.0759 2604 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
13:22:48.0827 2604 tdx - ok
13:22:48.0865 2604 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
13:22:48.0912 2604 TermDD - ok
13:22:48.0954 2604 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
13:22:49.0018 2604 tssecsrv - ok
13:22:49.0048 2604 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
13:22:49.0088 2604 tunmp - ok
13:22:49.0108 2604 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
13:22:49.0148 2604 tunnel - ok
13:22:49.0163 2604 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\DRIVERS\uagp35.sys
13:22:49.0211 2604 uagp35 - ok
13:22:49.0239 2604 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
13:22:49.0304 2604 udfs - ok
13:22:49.0341 2604 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
13:22:49.0391 2604 uliagpkx - ok
13:22:49.0416 2604 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
13:22:49.0451 2604 uliahci - ok
13:22:49.0469 2604 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
13:22:49.0503 2604 UlSata - ok
13:22:49.0520 2604 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
13:22:49.0560 2604 ulsata2 - ok
13:22:49.0596 2604 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
13:22:49.0654 2604 umbus - ok
13:22:49.0697 2604 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
13:22:49.0803 2604 usbaudio - ok
13:22:49.0835 2604 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
13:22:49.0889 2604 usbccgp - ok
13:22:49.0907 2604 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
13:22:50.0004 2604 usbcir - ok
13:22:50.0044 2604 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
13:22:50.0089 2604 usbehci - ok
13:22:50.0110 2604 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
13:22:50.0169 2604 usbhub - ok
13:22:50.0183 2604 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
13:22:50.0218 2604 usbohci - ok
13:22:50.0252 2604 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
13:22:50.0302 2604 usbprint - ok
13:22:50.0325 2604 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
13:22:50.0369 2604 usbscan - ok
13:22:50.0383 2604 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:22:50.0430 2604 USBSTOR - ok
13:22:50.0447 2604 usbuhci (325dbbacb8a36af9988ccf40eac228cc) C:\Windows\system32\DRIVERS\usbuhci.sys
13:22:50.0542 2604 usbuhci - ok
13:22:50.0579 2604 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
13:22:50.0662 2604 vga - ok
13:22:50.0682 2604 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
13:22:50.0745 2604 VgaSave - ok
13:22:50.0763 2604 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
13:22:50.0809 2604 viaagp - ok
13:22:50.0823 2604 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
13:22:50.0926 2604 ViaC7 - ok
13:22:50.0963 2604 viaide (7aa7ec9a08dc2c39649c413b1a26e298) C:\Windows\system32\drivers\viaide.sys
13:22:50.0988 2604 viaide - ok
13:22:51.0026 2604 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
13:22:51.0059 2604 volmgr - ok
13:22:51.0103 2604 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
13:22:51.0153 2604 volmgrx - ok
13:22:51.0196 2604 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
13:22:51.0240 2604 volsnap - ok
13:22:51.0264 2604 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
13:22:51.0298 2604 vsmraid - ok
13:22:51.0321 2604 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
13:22:51.0427 2604 WacomPen - ok
13:22:51.0460 2604 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
13:22:51.0525 2604 Wanarp - ok
13:22:51.0531 2604 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
13:22:51.0596 2604 Wanarpv6 - ok
13:22:51.0625 2604 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
13:22:51.0660 2604 Wd - ok
13:22:51.0691 2604 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
13:22:51.0762 2604 Wdf01000 - ok
13:22:51.0864 2604 WmiAcpi (701a9f884a294327e9141d73746ee279) C:\Windows\system32\drivers\wmiacpi.sys
13:22:51.0963 2604 WmiAcpi - ok
13:22:52.0021 2604 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
13:22:52.0084 2604 ws2ifsl - ok
13:22:52.0123 2604 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
13:22:52.0254 2604 WUDFRd - ok
13:22:52.0279 2604 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
13:22:52.0349 2604 \Device\Harddisk0\DR0 - ok
13:22:52.0357 2604 MBR (0x1B8) (739b36f7a373fc81121d831231b6d311) \Device\Harddisk6\DR6
13:22:52.0805 2604 \Device\Harddisk6\DR6 - ok
13:22:52.0811 2604 Boot (0x1200) (c37b61aa1745ab95cd19680153653b2e) \Device\Harddisk0\DR0\Partition0
13:22:52.0812 2604 \Device\Harddisk0\DR0\Partition0 - ok
13:22:52.0839 2604 Boot (0x1200) (c96353d6f99f8499968a08216450c5a6) \Device\Harddisk0\DR0\Partition1
13:22:52.0840 2604 \Device\Harddisk0\DR0\Partition1 - ok
13:22:52.0846 2604 Boot (0x1200) (b85718e2880dd778dc96f01d7ff1ea4a) \Device\Harddisk6\DR6\Partition0
13:22:52.0848 2604 \Device\Harddisk6\DR6\Partition0 - ok
13:22:52.0850 2604 ============================================================
13:22:52.0850 2604 Scan finished
13:22:52.0850 2604 ============================================================
13:22:52.0868 0840 Detected object count: 0
13:22:52.0868 0840 Actual detected object count: 0

cosinus 29.11.2011 13:42

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

PinaColada 29.11.2011 15:17

So ComboFix hab ich dann auch fertig :)
Combofix Logfile:
Code:

ComboFix 11-11-29.04 - Pizzaro 29.11.2011  14:19:06.1.4 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.2046.1062 [GMT 1:00]
ausgeführt von:: c:\users\Pizzaro\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Pizzaro\AppData\Roaming\Microsoft\Windows\Recent\uweleue_21msn.pif
c:\windows\TEMP\logishrd\LVPrcInj01.dll
F:\Autorun.inf
F:\Setup.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-10-28 bis 2011-11-29  ))))))))))))))))))))))))))))))
.
.
2011-11-29 13:25 . 2011-11-29 13:25        56200        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{57E5E858-A79F-4684-97DC-32B9A264A279}\offreg.dll
2011-11-28 19:24 . 2011-10-07 03:48        6668624        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{57E5E858-A79F-4684-97DC-32B9A264A279}\mpengine.dll
2011-11-28 19:02 . 2011-11-28 19:02        --------        d-----w-        C:\_OTL
2011-11-28 13:22 . 2011-11-28 13:22        --------        d-----w-        c:\users\Pizzaro\AppData\Roaming\Malwarebytes
2011-11-28 13:22 . 2011-11-28 13:22        --------        d-----w-        c:\programdata\Malwarebytes
2011-11-28 13:22 . 2011-08-31 16:00        22216        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-11-28 13:22 . 2011-11-28 13:22        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2011-11-22 15:51 . 2011-11-22 15:51        --------        d-----w-        c:\windows\system32\drivers\NSS
2011-11-22 15:51 . 2011-11-22 15:51        --------        d-----w-        c:\program files\Norton Security Scan
2011-11-09 08:19 . 2011-10-17 11:41        2409784        ----a-w-        c:\program files\Windows Mail\OESpamFilter.dat
2011-11-09 08:19 . 2011-09-20 21:02        913280        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2011-11-09 08:19 . 2011-09-20 13:44        31232        ----a-w-        c:\windows\system32\drivers\tcpipreg.sys
2011-11-09 08:19 . 2011-09-30 15:57        707584        ----a-w-        c:\program files\Common Files\System\wab32.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-11 17:37 . 2011-10-11 17:38        703824        ------w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{525440BA-699B-43DB-AE9E-E29403028E68}\gapaengine.dll
2011-10-07 03:48 . 2011-08-17 17:39        6668624        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-03 03:06 . 2011-02-28 22:06        472808        ----a-w-        c:\windows\system32\deployJava1.dll
2011-09-06 13:30 . 2011-10-12 08:09        2043392        ----a-w-        c:\windows\system32\win32k.sys
2011-09-01 02:35 . 2011-10-12 09:24        1798144        ----a-w-        c:\windows\system32\jscript9.dll
2011-09-01 02:28 . 2011-10-12 09:24        1126912        ----a-w-        c:\windows\system32\wininet.dll
2011-09-01 02:22 . 2011-10-12 09:24        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2011-11-11 06:52 . 2011-05-07 19:30        134104        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" [2009-07-16 5458704]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-04-30 9210400]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"PlusService"="c:\program files\Yuna Software\Messenger Plus!\PlusService.exe" [2011-09-20 801792]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
c:\users\Pizzaro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28        1233920        ----a-w-        c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 07:33        202240        ----a-w-        c:\program files\Windows Media Player\wmpnscfg.exe
.
R1 MpKsla7066217;MpKsla7066217;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0E3B51B6-9FA0-46FE-8C15-216601980F80}\MpKsla7066217.sys [x]
R1 MpKslb6ab3838;MpKslb6ab3838;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FD9AAC6C-F5BF-4732-96A9-DFD2A3609BD0}\MpKslb6ab3838.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2011-11-28 c:\windows\Tasks\Norton Security Scan for Pizzaro.job
- c:\progra~1\NORTON~2\Engine\351~1.8\Nss.exe [2011-11-22 13:59]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page =
IE: Free YouTube Download - c:\users\Pizzaro\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Pizzaro\AppData\Roaming\Mozilla\Firefox\Profiles\vj33xm3l.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - Google
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
WebBrowser-{3D684CA7-5D30-4A7E-9768-E17DF98DF80F} - (no file)
WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file)
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2011-11-29 14:26
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\conime.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-11-29  14:31:17 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2011-11-29 13:31
.
Vor Suchlauf: 7 Verzeichnis(se), 184.327.450.624 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 184.246.767.616 Bytes frei
.
- - End Of File - - 5D1954A527C5EF11664D8E357C683AF3

--- --- ---

cosinus 29.11.2011 15:31

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).


PinaColada 29.11.2011 16:25

GMER Logfile:
Code:

GMER 1.0.15.15641 - GMER - Rootkit Detector and Remover
Rootkit scan 2011-11-29 16:24:40
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000052 WDC_WD50 rev.12.0
Running: pfq22tqk.exe; Driver: C:\Users\Pizzaro\AppData\Local\Temp\uftiyfow.sys


---- Kernel code sections - GMER 1.0.15 ----

?    C:\Users\Pizzaro\AppData\Local\Temp\catchme.sys                                                                Das System kann die angegebene Datei nicht finden. !
?    C:\Windows\system32\Drivers\PROCEXP113.SYS                                                                    Das System kann die angegebene Datei nicht finden. !

---- Registry - GMER 1.0.15 ----

Reg  HKCU\Software\Microsoft\Windows Live\Companion\melanie.161079@hotmail.de@27db1dcc51f38e1c94d613d0ab941b29\r\n  0xC6 0x87 0x9E 0x0A ...

---- EOF - GMER 1.0.15 ----

--- --- ---

PinaColada 29.11.2011 16:56

OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
Online Solutions. Complex Protection for Information Systems
Saved at 16:54:37 on 29.11.2011

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 8.0

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"Norton Security Scan for Pizzaro.job" - "Symantec Corporation" - C:\PROGRA~1\NORTON~2\Engine\351~1.8\Nss.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"catchme" (catchme) - ? - C:\Users\Pizzaro\AppData\Local\Temp\catchme.sys  (File not found)
"FssFltr" (fssfltr) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\fssfltr.sys
"gdrv" (gdrv) - ? - C:\Windows\gdrv.sys  (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"mbr" (mbr) - ? - C:\Users\Pizzaro\AppData\Local\Temp\mbr.sys  (Hidden registry entry, rootkit activity | File not found)
"MpKsla7066217" (MpKsla7066217) - ? - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0E3B51B6-9FA0-46FE-8C15-216601980F80}\MpKsla7066217.sys  (File not found)
"MpKslb6ab3838" (MpKslb6ab3838) - ? - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{FD9AAC6C-F5BF-4732-96A9-DFD2A3609BD0}\MpKslb6ab3838.sys  (File not found)
"MpKslc22dae8a" (MpKslc22dae8a) - "Microsoft Corporation" - C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AED283E7-80E5-45C7-B175-413F6A4B8F71}\MpKslc22dae8a.sys
"uftiyfow" (uftiyfow) - ? - C:\Users\Pizzaro\AppData\Local\Temp\uftiyfow.sys  (Hidden registry entry, rootkit activity | File not found)

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} "Album Download IE Asynchronous Pluggable Protocol Interface" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\Program Files\Windows Live\Messenger\msgrapp.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Messenger\msgrapp.dll
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{94586423-855F-4EB2-9F6A-D9DA5658DBE3} "Context menu" - ? - D:\PROGRA~1\FREEM4~1\m4a_menu.dll  (File found, but it contains no detailed information)
{09A47860-11B0-4DA5-AFA5-26D86198A780} "EPP" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\shellext.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -  (File not found | COM-object registry key not found)
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -  (File not found | COM-object registry key not found)
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
{0563DB41-F538-4B37-A92D-4659049B7766} "WLMD Message Handler" - ? -  (File not found | COM-object registry key not found)
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_29.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? -  (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} "@C:\Program Files\Windows Live\Companion\companionlang.dll,-600" - "Microsoft Corporation" - C:\Program Files\Windows Live\Companion\companioncore.dll
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "@C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004" - "Microsoft Corporation" - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} "Easy Photo Print" - "SEIKO EPSON CORPORATION / CyCom Technology Corp." - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} "Easy Photo Print" - "SEIKO EPSON CORPORATION / CyCom Technology Corp." - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID Sign-in Helper" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{9FDDE16B-836F-4806-AB1F-1455CBEFF289} "Windows Live Messenger Companion Helper" - "Microsoft Corporation" - C:\Program Files\Windows Live\Companion\companioncore.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"OpenOffice.org 3.3.lnk" - ? - C:\Program Files\OpenOffice.org 3\program\quickstart.exe  (Shortcut exists | File found, but it contains no detailed information | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Logitech Vid" - "Logitech Inc." - "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
"Skype" - "Skype Technologies S.A." - "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"LogitechQuickCamRibbon" - "Logitech Inc." - "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
"MSC" - "Microsoft Corporation" - "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"PlusService" - "Yuna Software" - C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243" (NisSrv) - "Microsoft Corporation" - C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"ASP.NET-Zustandsdienst" (aspnet_state) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Antimalware Service" (MsMpSvc) - "Microsoft Corporation" - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
"Process Monitor" (LVPrcSrv) - "Logitech Inc." - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
"Windows Live Family Safety Service" (fsssvc) - "Microsoft Corporation" - C:\Program Files\Windows Live\Family Safety\fsssvc.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---
If You have questions or want to get some help, You can visit Online Solutions :: Index

PinaColada 29.11.2011 17:12

So ich hoffe ich hab das auch richtig gemacht

aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-11-29 16:56:41
-----------------------------
16:56:41.333 OS Version: Windows 6.0.6002 Service Pack 2
16:56:41.334 Number of processors: 4 586 0x202
16:56:41.335 ComputerName: PIZZARO-PC UserName: Pizzaro
16:56:43.122 Initialize success
17:04:17.831 AVAST engine defs: 11112901
17:11:58.776 The log file has been saved successfully to "C:\Users\Pizzaro\Desktop\aswMBR.txt"

cosinus 29.11.2011 17:32

Bei aswMBR ist dir ein Fehler unterlaufen. Bitte wiederholen, beachte die Anleitung dazu und setze sie genau um

PinaColada 29.11.2011 17:50

ok danke..werd ich machen

PinaColada 29.11.2011 18:41

So da bin ich wieder

aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-11-29 16:56:41
-----------------------------
16:56:41.333 OS Version: Windows 6.0.6002 Service Pack 2
16:56:41.334 Number of processors: 4 586 0x202
16:56:41.335 ComputerName: PIZZARO-PC UserName: Pizzaro
16:56:43.122 Initialize success
17:04:17.831 AVAST engine defs: 11112901
17:11:58.776 The log file has been saved successfully to "C:\Users\Pizzaro\Desktop\aswMBR.txt"


aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-11-29 17:51:37
-----------------------------
17:51:37.803 OS Version: Windows 6.0.6002 Service Pack 2
17:51:37.804 Number of processors: 4 586 0x202
17:51:37.805 ComputerName: PIZZARO-PC UserName: Pizzaro
17:51:39.138 Initialize success
17:51:49.412 AVAST engine defs: 11112901
17:52:19.503 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000052
17:52:19.507 Disk 0 Vendor: WDC_WD50 12.0 Size: 476940MB BusType: 6
17:52:21.798 Disk 0 MBR read successfully
17:52:21.802 Disk 0 MBR scan
17:52:21.832 Disk 0 Windows VISTA default MBR code
17:52:21.976 Disk 0 scanning sectors +976771072
17:52:22.857 Disk 0 scanning C:\Windows\system32\drivers
17:54:46.835 Service scanning
17:54:47.375 Service MpKsl2de8a378 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{FF741A6B-0857-41E7-9AB7-3D447B1257FE}\MpKsl2de8a378.sys **LOCKED** 32
17:54:47.383 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32
17:54:48.009 Modules scanning
17:57:42.282 Disk 0 trace - called modules:
17:57:42.404 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys
17:57:42.757 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86224240]
17:57:42.768 3 CLASSPNP.SYS[82fb38b3] -> nt!IofCallDriver -> [0x85079e00]
17:57:42.778 5 acpi.sys[806166bc] -> nt!IofCallDriver -> \Device\00000052[0x850f47f0]
17:57:43.966 AVAST engine scan C:\Windows
18:02:28.755 AVAST engine scan C:\Windows\system32
18:10:09.663 AVAST engine scan C:\Windows\system32\drivers
18:10:28.981 AVAST engine scan C:\Users\Pizzaro
18:26:02.508 AVAST engine scan C:\ProgramData
18:27:55.984 Scan finished successfully
18:39:03.016 Disk 0 MBR has been saved successfully to "C:\Users\Pizzaro\Desktop\MBR.dat"
18:39:03.023 The log file has been saved successfully to "C:\Users\Pizzaro\Desktop\aswMBR.txt"

cosinus 29.11.2011 18:59

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!


Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


PinaColada 29.11.2011 19:04

Klingt supi :) dann werd ich das mal eben machen

PinaColada 29.11.2011 19:39

Malwarebytes' Anti-Malware 1.51.2.1300
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: 8256

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

29.11.2011 19:34:56
mbam-log-2011-11-29 (19-34-56).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|)
Durchsuchte Objekte: 252415
Laufzeit: 25 Minute(n), 43 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

PinaColada 29.11.2011 21:00

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=6b6407d8b2da6049882ff9e02852892a
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-10-23 12:27:13
# local_time=2011-10-23 02:27:13 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=5892 16776574 100 100 20505992 156856816 0 0
# compatibility_mode=8192 67108863 100 0 89 89 0 0
# scanned=112779
# found=0
# cleaned=0
# scan_time=5545
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=6b6407d8b2da6049882ff9e02852892a
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-27 08:01:55
# local_time=2011-11-27 09:01:55 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=5892 16776574 100 100 23598770 159949594 0 0
# compatibility_mode=8192 67108863 100 0 3092867 3092867 0 0
# scanned=190938
# found=0
# cleaned=0
# scan_time=7248
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=6b6407d8b2da6049882ff9e02852892a
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-28 01:32:22
# local_time=2011-11-28 02:32:22 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=5892 16776574 100 100 23668052 160018876 0 0
# compatibility_mode=8192 67108863 100 0 3162149 3162149 0 0
# scanned=10212
# found=0
# cleaned=0
# scan_time=994
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=6b6407d8b2da6049882ff9e02852892a
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-28 03:47:57
# local_time=2011-11-28 04:47:57 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=5892 16776574 100 100 23672174 160022998 0 0
# compatibility_mode=8192 67108863 100 0 3166271 3166271 0 0
# scanned=192840
# found=0
# cleaned=0
# scan_time=5006
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=6b6407d8b2da6049882ff9e02852892a
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-29 07:55:22
# local_time=2011-11-29 08:55:22 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=5892 16776574 100 100 23774393 160125217 0 0
# compatibility_mode=8192 67108863 100 0 3268490 3268490 0 0
# scanned=115537
# found=0
# cleaned=0
# scan_time=4033

PinaColada 29.11.2011 21:06

Irgendwie gehr das mit dem SuperAntispyware nicht :(
werd es weiter versuchen...

aber ich hab noch eine frage

Das meine IP adresse ich glaube einmal am tag (nachts) ändert das weiß ich aber es ist komisch das ich öfters am tag einen IP wechsel habe
normalerweise fängt meine mit 79.238...... und wechselt immer zu 91.38.........

cosinus 30.11.2011 11:35

Zitat:

Irgendwie gehr das mit dem SUPERAntiSpyware nicht
Tolle Fehlerbeschreibung...

Zitat:

komisch das ich öfters am tag einen IP wechsel habe
IdR bekommt man bei jeder neuen Einwahl ins Internet auch eine andere IP - dynamisch zugewiesen aus dem Adresspool des Providers. Wann bzw. ob sich die IP ändert ist aber provider- und vertragabhängig und kann man bei dir nicht sagen bei diesem Informationsgehalt.

PinaColada 30.11.2011 12:19

Ich hatte bei SUPERAntiSpyware ein anderes fenster auf :( hab den scan der mir dort angezeigt wurde gemacht

SUPERAntiSpyware Scan Log
SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

Generated 11/30/2011 at 12:11 PM

Application Version : 5.0.1136

Core Rules Database Version : 7997
Trace Rules Database Version: 5809

Scan type : Complete Scan
Total Scan Time : 00:28:55

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Administrator

Memory items scanned : 563
Memory threats detected : 0
Registry items scanned : 35755
Registry threats detected : 0
File items scanned : 57432
File threats detected : 74

Adware.Tracking Cookie
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\FH64CLG8.txt [ /adform.net ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\VO7HX39Y.txt [ /questionmarket.com ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\BF6F85GF.txt [ /microsoftwllivemkt.112.2o7.net ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\LYY5NUMT.txt [ /eaeacom.112.2o7.net ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\ZJ2ZU834.txt [ /invitemedia.com ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\7FD3JL4Q.txt [ /www.active-tracking.de ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\B7733BMR.txt [ /media6degrees.com ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\YLMROPCA.txt [ /adtech.de ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\622CZT04.txt [ /imrworldwide.com ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\9A3KLET0.txt [ /serving-sys.com ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\KH3XXF3Z.txt [ /doubleclick.net ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\IUDACIAO.txt [ /mediaplex.com ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\2NXNOCEI.txt [ /track.adform.net ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\TTTALSWL.txt [ /bs.serving-sys.com ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\DJCDGAAB.txt [ /atdmt.com ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\OTQCPZ63.txt [ /apmebf.com ]
C:\Users\Pizzaro\AppData\Roaming\Microsoft\Windows\Cookies\C38DUINB.txt [ /ad2.adfarm1.adition.com ]
C:\USERS\PIZZARO\AppData\Roaming\Microsoft\Windows\Cookies\Low\1SF5136V.txt [ Cookie:pizzaro@ad.yieldmanager.com/ ]
C:\USERS\PIZZARO\AppData\Roaming\Microsoft\Windows\Cookies\Low\TUQ8WENY.txt [ Cookie:pizzaro@msnportal.112.2o7.net/ ]
C:\USERS\PIZZARO\AppData\Roaming\Microsoft\Windows\Cookies\Low\QH873QWG.txt [ Cookie:pizzaro@hitbox.com/ ]
C:\USERS\PIZZARO\AppData\Roaming\Microsoft\Windows\Cookies\Low\MAVFBBL6.txt [ Cookie:pizzaro@clkads.com/adServe/banners ]
C:\USERS\PIZZARO\AppData\Roaming\Microsoft\Windows\Cookies\Low\1YJSQOJ5.txt [ Cookie:pizzaro@clkads.com/adServe/ ]
C:\USERS\PIZZARO\AppData\Roaming\Microsoft\Windows\Cookies\Low\9ZL24YVB.txt [ Cookie:pizzaro@atdmt.com/ ]
C:\USERS\PIZZARO\Cookies\VO7HX39Y.txt [ Cookie:pizzaro@questionmarket.com/ ]
C:\USERS\PIZZARO\Cookies\BF6F85GF.txt [ Cookie:pizzaro@microsoftwllivemkt.112.2o7.net/ ]
C:\USERS\PIZZARO\Cookies\ZJ2ZU834.txt [ Cookie:pizzaro@invitemedia.com/ ]
C:\USERS\PIZZARO\Cookies\7FD3JL4Q.txt [ Cookie:pizzaro@www.active-tracking.de/ ]
C:\USERS\PIZZARO\Cookies\B7733BMR.txt [ Cookie:pizzaro@media6degrees.com/ ]
C:\USERS\PIZZARO\Cookies\YLMROPCA.txt [ Cookie:pizzaro@adtech.de/ ]
C:\USERS\PIZZARO\Cookies\622CZT04.txt [ Cookie:pizzaro@imrworldwide.com/cgi-bin ]
C:\USERS\PIZZARO\Cookies\9A3KLET0.txt [ Cookie:pizzaro@serving-sys.com/ ]
C:\USERS\PIZZARO\Cookies\2NXNOCEI.txt [ Cookie:pizzaro@track.adform.net/ ]
C:\USERS\PIZZARO\Cookies\DJCDGAAB.txt [ Cookie:pizzaro@atdmt.com/ ]
C:\USERS\PIZZARO\Cookies\C38DUINB.txt [ Cookie:pizzaro@ad2.adfarm1.adition.com/ ]
wstat.wibiya.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.lego.112.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.msnportal.112.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
Online counter gratis - kostenlose Zhler mit Statistik fr Ihre Homepage: counter-gratis.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
tracking.tchibo.de [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.guj.122.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.xiti.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
etracker Home - forget log-file analysis, this is real-time Web Analytics and online market research [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
etracker Home - forget log-file analysis, this is real-time Web Analytics and online market research [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
» kostenloser Counter » Blog Counter » BlogCounter.de [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
Online counter gratis - kostenlose Zhler mit Statistik fr Ihre Homepage: counter-gratis.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.microsoftwllivemkt.112.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.deutschepostag.112.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
counter.de - Ihr kostenloser Counter! [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
etracker Home - forget log-file analysis, this is real-time Web Analytics and online market research [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.superrtl.122.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
statse.webtrendslive.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
etracker Home - forget log-file analysis, this is real-time Web Analytics and online market research [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.microsoftsto.112.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
etracker Home - forget log-file analysis, this is real-time Web Analytics and online market research [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.stats.ebay.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PIZZARO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJ33XM3L.DEFAULT\COOKIES.SQLITE ]

cosinus 30.11.2011 12:58

Sieht ok aus, da wurden nur Cookies gefunden.
Noch Probleme oder weitere Funde in der Zwischenzeit?

PinaColada 30.11.2011 15:02

Nein ist alles ok :)

hoffe nur das mir das mit dem Hacker nicht nochmal passiert, ist erstaunlich wie man so ein PW wie ich es hatte knacken konnte. aber gut wenn es profis sind dann geht das ruck zuck

aber super lieben dank für die schnelle hilfe :)

und daran das meine IP teilweise dreimal am tag wechselt gewöhn ich mich auch noch
war nur so irretiert das meine jetztige IP nummer zur Telekom AG in Annahütte gehört das ist mal eben 600 km von mir entfernt :D



LG PinaColada

cosinus 30.11.2011 15:55

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

PinaColada 30.11.2011 17:44

prima...
dann werd ich das nochmal alles machen :)


dicken knutscha für die Hilfe

LG PinaColada


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:15 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19