Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Trojanisches Pferd TR/Crypt.zpack.gen2 gefunden. Kein Internet! (https://www.trojaner-board.de/110493-trojanisches-pferd-tr-crypt-zpack-gen2-gefunden-kein-internet.html)

snowly1 27.02.2012 01:35

Trojanisches Pferd TR/Crypt.zpack.gen2 gefunden. Kein Internet!
 
Hallo. Nachdem ich stundenlang gesucht habe, konnte ich heute Nacht die Systemwiederherstellung über den abgesicherten Modus ausführen auf den 20.2.2012. Vorher gings nicht, Fehlermeldung. Antivir fand Folgendes:
Code:

Exportierte Ereignisse:

27.02.2012 00:16 [Guard] Lizenzfehler
      Lizenzfehler

25.02.2012 13:03 [Scanner] Malware gefunden
      Die Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      enthielt einen Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan].
      Durchgeführte Aktion(en):
      Der Registrierungseintrag
      <HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSp
      ace_Catalog5\Catalog_Entries\000000000010\LibraryPath> wurde erfolgreich      repariert.
      Der Registrierungseintrag
      <HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSp
      ace_Catalog5\Catalog_Entries\000000000010\DisplayString> wurde erfolgreich      repariert.
      Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4aed63ab.qua'
      verschoben!

25.02.2012 13:03 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:03 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:03 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:03 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

 Exportierte Ereignisse:

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]
      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:02 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:01 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:01 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:01 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:01 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

25.02.2012 13:01 [Guard] Malware gefunden
      In der Datei 'C:\Windows\System32\d3dy2i0ki.dll'
      wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan]      gefunden.
      Ausgeführte Aktion: Zugriff verweigern

Ich habe dann gemäss Eurer Anleitung defogger gemacht (ohne Fehlermeldung) und hier sind die dds:
Code:

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7601.17514
Run by Acer at 0:54:35 on 2012-02-27
Microsoft Windows 7 Starter  6.1.7601.1.1252.41.1031.18.1014.334 [GMT 1:00]
.
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
C:\Program Files\Acer\Registration\GregHSRW.exe
C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Acer\Acer VCM\RS_Service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k Update-Service
C:\Program Files\Acer\Acer Updater\UpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe
C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2736476
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_one&r=07b511093115l03e4ww85w47323005
mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_one&r=07b511093115l03e4ww85w47323005
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_one&r=07b511093115l03e4ww85w47323005
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
uURLSearchHooks: Freeware.de Toolbar: {7e111a5c-3d11-4f56-9463-5310c3c69025} - c:\program files\freeware.de\prxtbFree.dll
mURLSearchHooks: Freeware.de Toolbar: {7e111a5c-3d11-4f56-9463-5310c3c69025} - c:\program files\freeware.de\prxtbFree.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File
BHO: Freeware.de Toolbar: {7e111a5c-3d11-4f56-9463-5310c3c69025} - c:\program files\freeware.de\prxtbFree.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers runtime\YontooIEClient.dll
TB: Freeware.de Toolbar: {7e111a5c-3d11-4f56-9463-5310c3c69025} - c:\program files\freeware.de\prxtbFree.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [FreeCT] c:\program files\freecountdowntimer\FreeCountdownTimer.exe -autorun
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [LManager] c:\program files\launch manager\LManager.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [Acer ePower Management] c:\program files\acer\acer epower management\ePowerTray.exe
mRun: [EgisTecLiveUpdate] "c:\program files\egistec egis software update\EgisUpdate.exe"
mRun: [mwlDaemon] c:\program files\egistec\mywinlocker 3\x86\mwlDaemon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [NortonOnlineBackupReminder] "c:\program files\symantec\norton online backup\activation\NobuActivation.exe" UNATTENDED
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [FILSHtray] "c:\program files\filshtray\FILSHtray.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\acervc~1.lnk - c:\program files\acer\acer vcm\AcerVCM.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
TCP: Interfaces\{19C2AB69-811A-4D9F-9E47-0C2D40CD0D5F} : DhcpNameServer = 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
TCP: Interfaces\{19C2AB69-811A-4D9F-9E47-0C2D40CD0D5F}\370716E67696E65647A7775627B6 : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{19C2AB69-811A-4D9F-9E47-0C2D40CD0D5F}\4656661657C647 : DhcpNameServer = 62.2.17.61 192.168.0.1
TCP: Interfaces\{E1D1366E-035D-4E53-81A1-B77285C9AC87} : DhcpNameServer = 10.60.100.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\acer\acer vcm\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\drivers\mwlPSDFilter.sys [2009-6-2 18992]
R1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\drivers\mwlPSDNserv.sys [2009-6-2 16432]
R1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\drivers\mwlPSDVDisk.sys [2009-6-2 60976]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\avira\antivir desktop\sched.exe [2011-3-28 136360]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-3-28 66616]
R2 ePowerSvc;Acer ePower Service;c:\program files\acer\acer epower management\ePowerSvc.exe [2009-8-14 727584]
R2 Greg_Service;GRegService;c:\program files\acer\registration\GregHSRW.exe [2009-6-4 1150496]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-2-7 652360]
R2 MWLService;MyWinLocker Service;c:\program files\egistec\mywinlocker 3\x86\MWLService.exe [2009-8-6 311592]
R2 RS_Service;Raw Socket Service;c:\program files\acer\acer vcm\RS_Service.exe [2009-8-14 253952]
R2 Update-Service;Update-Service;c:\windows\system32\svchost.exe -k Update-Service [2009-7-14 20992]
R2 Updater Service;Updater Service;c:\program files\acer\acer updater\UpdaterService.exe [2009-8-14 240160]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2009-8-14 51712]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-30 20464]
S2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-3-28 269480]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-8-14 167424]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-7-24 52224]
.
=============== Created Last 30 ================
.
2012-02-18 12:02:06        478720        ----a-w-        c:\windows\system32\timedate.cpl
2012-02-18 12:00:19        2343424        ----a-w-        c:\windows\system32\win32k.sys
2012-02-11 15:10:45        --------        d-----w-        c:\users\acer\appdata\local\{E09BE6F8-59E7-489F-B41E-CCB4F4175006}
2012-02-11 15:10:28        --------        d-----w-        c:\users\acer\appdata\local\{11BC444D-7AF9-43B6-B0AF-BF4BC8FF9787}
2012-02-07 19:30:40        497664        ----a-w-        c:\windows\system32\ac3filter.acm
2012-02-07 19:30:39        --------        d-----w-        c:\program files\AC3Filter
2012-01-30 13:57:39        --------        d-----w-        c:\programdata\Firefly Studios
2012-01-30 13:53:11        251672        ----a-w-        c:\windows\system32\xactengine2_5.dll
2012-01-30 13:53:10        3426072        ----a-w-        c:\windows\system32\d3dx9_32.dll
2012-01-30 13:53:09        68888        ----a-w-        c:\windows\system32\xinput1_3.dll
2012-01-30 13:53:09        2414360        ----a-w-        c:\windows\system32\d3dx9_31.dll
2012-01-30 13:53:09        237848        ----a-w-        c:\windows\system32\xactengine2_4.dll
2012-01-30 13:53:09        15128        ----a-w-        c:\windows\system32\x3daudio1_1.dll
2012-01-30 13:53:08        62744        ----a-w-        c:\windows\system32\xinput1_2.dll
2012-01-30 13:53:08        236824        ----a-w-        c:\windows\system32\xactengine2_3.dll
2012-01-30 13:44:57        --------        d-----w-        c:\program files\Firefly Studios
.
==================== Find3M  ====================
.
2012-02-06 19:12:16        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-24 16:35:34        212992        ----a-w-        c:\windows\system32\aptw2s8pj.dll
2012-01-10 14:39:42        98304        ----a-w-        c:\windows\system32\CmdLineExt.dll
2012-01-04 08:58:41        442880        ----a-w-        c:\windows\system32\ntshrui.dll
2011-12-16 07:54:22        981504        ----a-w-        c:\windows\system32\wininet.dll
2011-12-16 07:52:58        690688        ----a-w-        c:\windows\system32\msvcrt.dll
2011-12-16 06:09:17        1638912        ----a-w-        c:\windows\system32\mshtml.tlb
2011-12-10 14:24:06        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-12-07 15:39:30        472808        ----a-w-        c:\windows\system32\deployJava1.dll
.
============= FINISH:  0:57:02.63 ===============

und die attach.txt:
Code:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Starter
Boot Device: \Device\HarddiskVolume2
Install Date: 22.02.2011 23:44:39
System Uptime: 27.02.2012 00:15:09 (0 hours ago)
.
Motherboard: Acer |  | Aspire one     
Processor: Intel(R) Atom(TM) CPU N270  @ 1.60GHz | CPU | 1600/533mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 135 GiB total, 64.141 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP80: 07.02.2012 23:31:04 - Windows Update
RP81: 19.02.2012 03:00:31 - Windows Update
RP82: 20.02.2012 00:06:55 - Windows Update
RP83: 25.02.2012 16:00:47 - Wiederherstellungsvorgang
RP84: 25.02.2012 17:53:56 - Windows Modules Installer
RP85: 25.02.2012 17:55:03 - Windows Modules Installer
RP86: 25.02.2012 18:32:26 - Windows Modules Installer
RP87: 25.02.2012 18:34:05 - Windows Modules Installer
RP88: 25.02.2012 18:35:11 - Windows Modules Installer
RP89: 25.02.2012 18:35:46 - Windows Modules Installer
RP90: 25.02.2012 19:36:56 - Wiederherstellungsvorgang
RP91: 26.02.2012 21:19:04 - Removed Microsoft Silverlight
RP92: 26.02.2012 21:40:52 - Wiederherstellungsvorgang
.
==== Installed Programs ======================
.
 Update for Microsoft Office 2007 (KB2508958)
AC3Filter 1.63b
Acer Crystal Eye webcam
Acer ePower Management
Acer eRecovery Management
Acer GameZone Console
Acer Registration
Acer ScreenSaver
Acer Updater
Acer VCM
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 9.1 MUI
Alice Greenfingers
Amazonia
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
Avira AntiVir Personal - Free Antivirus
Bonjour
Chicken Invaders 2
D3DX10
Dairy Dash
devolo dLAN-Konfigurationsassistent
devolo EasyClean
devolo EasyShare
devolo Informer
Dream Day First Home
eBay Worldwide
ESET Online Scanner v3
eSobi v2
Farm Frenzy 2
FILSHtray Version 0.7
Free Countdown Timer 2.3.0
Freeware.de Toolbar
GameShadow
Granny In Paradise
Heroes of Hellas
Identity Card
Intel(R) Graphics Media Accelerator Driver
Intel® Matrix Storage Manager
iTunes
Java Auto Updater
Java(TM) 6 Update 29
Launch Manager
Malwarebytes Anti-Malware Version 1.60.1.1000
Media Go
Media Go Video Playback Engine 1.84.112.07020
Merriam Websters Spell Jam
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MSVCRT
MyWinLocker
Norton Online Backup
PlayStation(R)Network Downloader
PlayStation(R)Store
QuickTime
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
Safari
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Skype Click to Call
Skype™ 5.5
Star Defender 4
Stronghold Legends
Synaptics Pointing Device Driver
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition
Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Welcome Center
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotogalerie
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Wizard101(DE)
Yontoo Layers Runtime 1.10.01
Zulu DJ Software
.
==== End Of File ===========================

Hoffe Ihr könnt mir helfen! Danke schon mal.

Psychotic 27.02.2012 09:28

:hallo:

Ich habe dein Thema in Arbeit und melde mich so schnell als möglich mit weiteren Anweisungen.

Bitte beachte, dass alle meine Antworten zuerst von einem Ausbilder freigegeben werden müssen, bevor ich diese hier posten darf. Dies garantiert, dass Du Hilfe von einem ausgebildeten Helfer bekommst.

Ich bedanke mich für deine Geduld :)

Gruß,
PsYcHoTiC

Psychotic 27.02.2012 14:24

:hallo:

Mein Name ist Marius und ich werde dir bei deinem Problem helfen.

Eines vorneweg:

Hinweis: Wir können hier nie dafür garantieren, dass wir sämtliche Reste von Schadsoftware gefunden haben. Eine Formatierung ist meist der schnellere und immer der sicherste Weg.

Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis dir jemand vom Team sagt, dass du clean bist.

Eine Bereinigung ist mitunter mit viel Arbeit für dich verbunden.
  • Bitte arbeite alle Schritte der Reihe nach ab.
  • Lese die Anleitungen sorgfältig. Sollte es Probleme geben, bitte stoppen und hier so gut es geht beschreiben.
  • Nur Scans durchführen zu denen du von einem Helfer aufgefordert wirst.
  • Bitte kein Crossposting ( posten in mehreren Foren).
  • Installiere oder Deinstalliere während der Bereinigung keine Software (ausser, du wurdest dazu aufgefordert).
  • Lese Dir die Anleitung zuerst vollständig durch. Sollte etwas unklar sein, frage bevor Du beginnst.
  • Poste die Logfiles direkt in deinen Thread. Nicht anhängen, außer, ich fordere dich dazu auf. Erschwert mir nämlich das Auswerten.


Vista und Win7 User
Alle Tools mit Rechtsklick "als Administrator ausführen" starten.


GMER

Bitte
  • alle anderen Scanner gegen Viren, Spyware, usw. deaktivieren,
  • keine bestehende Verbindung zu einem Netzwerk/Internet (WLAN nicht vergessen),
  • nichts am Rechner arbeiten,
  • nach jedem Scan der Rechner neu gestarten.
Gmer scannen lassen
  • Lade Dir Gmer von dieser Seite herunter (auf den Button Download EXE drücken) und das Programm auf dem Desktop speichern.
  • Alle anderen Programme sollen geschlossen sein.
  • Starte gmer.exe (Programm hat einen willkürlichen Programm-Namen). Vista und Win7 User mit Rechtsklick und als Administrator starten.
  • Sollte sich ein Fenster mit folgender Warnung öffnen:
    WARNING !!! GMER has found system modification, which might have been caused by ROOTKIT activity. Do you want to fully scan your system ?
    Unbedingt auf "No" klicken.
  • Entferne rechts den Haken bei:
    • IAT/EAT
    • Alle Festplatten ausser die Systemplatte (normalerweise ist nur C:\ angehackt)
    • Show all (sollte abgehackt sein)
  • Starte den Scan mit "Scan". Mache nichts am Computer während der Scan läuft.
  • Wenn der Scan fertig ist klicke auf Save und speichere die Logfile unter Gmer.txt auf deinem Desktop. Mit "Ok" wird GMER beendet.
Antiviren-Programm und sonstige Scanner wieder einschalten, bevor Du ins Netz gehst!

snowly1 27.02.2012 22:32

So nun hier ist der Gmer:
GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-02-27 22:23:45
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD16 rev.11.0
Running: g20q7onb.exe; Driver: C:\Users\Acer\AppData\Local\Temp\kwldrpob.sys


---- System - GMER 1.0.15 ----

SSDT            8062A30E                                                                                ZwCreateSection
SSDT            8062A313                                                                                ZwSetContextThread
SSDT            8062A2AF                                                                                ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text          ntoskrnl.exe!ZwSaveKey + 13CD                                                            8203C9A9 1 Byte  [06]
.text          ntoskrnl.exe!KiDispatchInterrupt + 5A2                                                  8205C4E2 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text          ntoskrnl.exe!KeRemoveQueueEx + 14BF                                                      8206387C 4 Bytes  [0E, A3, 62, 80]
.text          ntoskrnl.exe!KeRemoveQueueEx + 185F                                                      82063C1C 4 Bytes  [13, A3, 62, 80]
.text          ntoskrnl.exe!KeRemoveQueueEx + 1937                                                      82063CF4 4 Bytes  [AF, A2, 62, 80]

---- User code sections - GMER 1.0.15 ----

.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtClose                                  777A54C8 5 Bytes  JMP 01171B91
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtCreateSection                          777A56E8 5 Bytes  JMP 011708F8
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtMapViewOfSection                        777A5C28 5 Bytes  JMP 01170BD4
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtOpenFile                                777A5CD8 5 Bytes  JMP 011718B4
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtOpenSection                            777A5DC8 5 Bytes  JMP 01170683
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtQueryAttributesFile                    777A5F38 5 Bytes  JMP 011715E1
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtQuerySection                            777A6188 5 Bytes  JMP 0117116D
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtQueryVirtualMemory                      777A6258 5 Bytes  JMP 01171D66
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtUnmapViewOfSection                      777A69B8 5 Bytes  JMP 01170F2E

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                  Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                  Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)

Device          \Driver\ACPI_HAL \Device\00000048                                                        halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                  rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                  rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                  rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
---- Processes - GMER 1.0.15 ----

Library        C:\Windows\system32\6340a.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [984]  0x04290000                                                                                                                                         

---- EOF - GMER 1.0.15 ----

--- --- ---

Das libryry C .. etc. war ganz in rot markiert. Ist das der Virus? Antivir meldet den Virus immer wieder. Muss ich auf entfernen drücken? Dann stürzt mein pc aber ab und ich habe wieder kein internet und keine Dienste... Was muss ich tun? Vielen Dank für die Hilfe!

Psychotic 28.02.2012 00:03

Schritt 1: Combofix
Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.
Downloade dir bitte Combofix von einem dieser Downloadspiegel

Link 1
Link 2


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Schritt 2: Farbar´s Service Scanner

Downloade dir bitte Farbar's Service Scanner
  • Starte das Tool mit Doppelklick auf die FSS.exe
  • Gehe sicher, dass folgende Optionen angehakt sind.
    • Internet Services
    • Windows Firewall
    • System Restore
  • Klicke auf Scan.
  • Wenn das Tool fertig ist, wird es eine FSS.txt in dem Verzeichnis erstellen, wo das Tool gelaufen ist.
Poste bitte den Inhalt hier.

snowly1 28.02.2012 01:39

Hallo Marius
Hier das Combofix

Code:

ComboFix 12-02-27.02 - Acer 28.02.2012  1:03.1.2 - x86
Microsoft Windows 7 Starter  6.1.7601.1.1252.41.1031.18.1014.254 [GMT 1:00]
ausgeführt von:: c:\users\Acer\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\Acer GameZone online.ico
c:\programdata\Tarma Installer
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\windows\system32\1.cmd
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-01-28 bis 2012-02-28  ))))))))))))))))))))))))))))))
.
.
2012-02-28 00:17 . 2012-02-28 00:17        --------        d-----w-        c:\users\Acer\AppData\Local\temp
2012-02-18 12:38 . 2012-02-18 12:38        --------        d-----w-        c:\windows\Sun
2012-02-18 12:02 . 2011-12-30 05:27        478720        ----a-w-        c:\windows\system32\timedate.cpl
2012-02-18 12:00 . 2012-01-14 03:35        2343424        ----a-w-        c:\windows\system32\win32k.sys
2012-02-07 19:30 . 2009-08-11 20:18        497664        ----a-w-        c:\windows\system32\ac3filter.acm
2012-02-07 19:30 . 2012-02-07 19:30        --------        d-----w-        c:\program files\AC3Filter
2012-01-30 13:57 . 2012-01-30 13:57        --------        d-----w-        c:\programdata\Firefly Studios
2012-01-30 13:53 . 2006-12-08 11:02        251672        ----a-w-        c:\windows\system32\xactengine2_5.dll
2012-01-30 13:53 . 2006-11-29 12:06        3426072        ----a-w-        c:\windows\system32\d3dx9_32.dll
2012-01-30 13:53 . 2006-11-15 10:38        15128        ----a-w-        c:\windows\system32\x3daudio1_1.dll
2012-01-30 13:53 . 2006-09-28 15:05        237848        ----a-w-        c:\windows\system32\xactengine2_4.dll
2012-01-30 13:53 . 2006-09-28 15:05        2414360        ----a-w-        c:\windows\system32\d3dx9_31.dll
2012-01-30 13:53 . 2006-09-28 15:04        68888        ----a-w-        c:\windows\system32\xinput1_3.dll
2012-01-30 13:53 . 2006-07-28 08:30        236824        ----a-w-        c:\windows\system32\xactengine2_3.dll
2012-01-30 13:53 . 2006-07-28 08:30        62744        ----a-w-        c:\windows\system32\xinput1_2.dll
2012-01-30 13:44 . 2012-01-30 13:44        --------        d-----w-        c:\program files\Firefly Studios
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-06 19:12 . 2011-09-08 18:45        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-24 16:35 . 2012-01-24 16:35        212992        ----a-w-        c:\windows\system32\aptw2s8pj.dll
2012-01-10 14:39 . 2011-08-27 14:12        98304        ----a-w-        c:\windows\system32\CmdLineExt.dll
2011-12-10 14:24 . 2011-12-30 10:46        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-12-07 15:39 . 2011-12-07 15:39        472808        ----a-w-        c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
2011-05-09 08:49        176936        ----a-w-        c:\program files\Freeware.de\prxtbFree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53        787744        ----a-w-        c:\program files\Yontoo Layers Runtime\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7E111A5C-3D11-4F56-9463-5310C3C69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-08-06 17:18        120104        ----a-w-        c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeCT"="c:\program files\FreeCountdownTimer\FreeCountdownTimer.exe" [2011-05-24 2033488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-06-02 1130504]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-08-06 707104]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-08-04 199464]
"mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-08-06 349480]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"NortonOnlineBackupReminder"="c:\program files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-18 1537320]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-29 281768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2009-8-14 708608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FILSHtray]
2012-01-10 12:08        596992        ----a-w-        c:\program files\FILSHtray\FILSHtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-08-18 23:07        421736        ----a-w-        c:\program files\iTunes\iTunesHelper.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-24 167424]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 18992]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 16432]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60976]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-05-01 136360]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2009-08-06 727584]
S2 Greg_Service;GRegService;c:\program files\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
S2 Update-Service;Update-Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - kwldrpob
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
Update-Service-Installer-Service        REG_MULTI_SZ          Update-Service-Installer-Service
Update-Service        REG_MULTI_SZ          Update-Service
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2736476
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_one&r=07b511093115l03e4ww85w47323005
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{37483b40-c254-4a72-bda4-22ee90182c1e} - (no file)
Toolbar-Locked - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-02-28  01:22:35
ComboFix-quarantined-files.txt  2012-02-28 00:22
ComboFix2.txt  2012-01-06 19:22
.
Vor Suchlauf: 13 Verzeichnis(se), 70'466'732'032 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 72'754'233'344 Bytes frei
.
- - End Of File - - 4A2C0D9A955B8FCA95C20FFDE0568E75

fss.txt:
Code:

Farbar Service Scanner Version: 22-02-2012
Ran by Acer (administrator) on 28-02-2012 at 01:30:24
Running from "C:\Users\Acer\Downloads"
Microsoft Windows 7 Starter  Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
There is no connection to network.
Attempt to access Google IP returned error: Google IP is unreachable
Attempt to access Yahoo IP returend error: Yahoo IP is unreachable


Windows Firewall:
=============

Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****

Bemerkung: Ich hatte das WLAN und die Windows Firewall deaktiviert, war das korrekt?

snowly1 28.02.2012 10:43

Hallo Marius. Als ich gestern Nacht den Laptop herunterfuhr, installierte er 2 Windowos updates! Ich wusste nicht, wie man das verhindern konnte... was mache ich nun? Gruss Eve

snowly1 28.02.2012 15:56

Hallo Marius. Frage: Kann ich den Virus über Avira entfernen lassen oder muss ich noch warten? Es poppt immer ein Fenster auf mit der Meldung, dass der Zugriff auf diese Datei verweigert wurde.

Psychotic 28.02.2012 20:11

Schritt 1: CF-Script

Hinweis für Mitleser:
Folgendes ComboFix Skript ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

Lösche die vorhandene Combofix.exe von deinem Desktop und lade das Programm von einem der folgenden Download-Spiegel neu herunter:
BleepingComputer.com - ForoSpyware.com
und speichere es erneut auf dem Desktop (nicht woanders hin, das ist wichtig)!

Drücke die Windows + R Taste --> Notepad (hinein schreiben) --> OK

Kopiere nun den Text aus der folgenden Codebox komplett in das leere Textdokument.
Code:

FILELOOK::
C:\Windows\system32\6340a.dll

Speichere dies als CFScript.txt auf Deinem Desktop.

Wichtig:
  • Stelle deine Anti Viren Software temprär ab. Dies kann ComboFix nämlich bei der Arbeit behindern.
    Danach wieder anstellen nicht vergessen!
  • Bewege nicht die Maus über das ComboFix-Fenster oder klicke in dieses hinein.
    Dies kann dazu führen, dass ComboFix sich aufhängt.
  • Schließe alle laufenden Programme. Gehe sicher das ComboFix ungehindert arbeiten kann.
  • Mache nichts am PC solange ComboFix läuft.
http://i266.photobucket.com/albums/i.../CFScriptB.gif
  • In Bezug auf obiges Bild, ziehe CFScript.txt in die ComboFix.exe
  • Wenn ComboFix fertig ist, wird es ein Log erstellen, C:\ComboFix.txt. Bitte füge es hier als Antwort ein.
Falls im Skript die Anweisung Suspect:: oder Collect:: enthalten ist, wird eine Message-Box erscheinen, nachdem Combofix fertig ist. Klicke OK und folge den Aufforderungen/Anweisungen, um die Dateien hochzuladen.


Schritt 2: MBAM

Downloade Dir bitte Malwarebytes
  • Installiere das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere Quick-Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.


Schritt 3: GMER


Bitte
  • alle anderen Scanner gegen Viren, Spyware, usw. deaktivieren,
  • keine bestehende Verbindung zu einem Netzwerk/Internet (WLAN nicht vergessen),
  • nichts am Rechner arbeiten,
  • nach jedem Scan der Rechner neu gestarten.
Gmer scannen lassen
  • Lade Dir Gmer von dieser Seite herunter (auf den Button Download EXE drücken) und das Programm auf dem Desktop speichern.
  • Alle anderen Programme sollen geschlossen sein.
  • Starte gmer.exe (Programm hat einen willkürlichen Programm-Namen). Vista und Win7 User mit Rechtsklick und als Administrator starten.
  • Sollte sich ein Fenster mit folgender Warnung öffnen:
    WARNING !!! GMER has found system modification, which might have been caused by ROOTKIT activity. Do you want to fully scan your system ?
    Unbedingt auf "No" klicken.
  • Entferne rechts den Haken bei:
    • IAT/EAT
    • Alle Festplatten ausser die Systemplatte (normalerweise ist nur C:\ angehackt)
    • Show all (sollte abgehackt sein)
  • Starte den Scan mit "Scan". Mache nichts am Computer während der Scan läuft.
  • Wenn der Scan fertig ist klicke auf Save und speichere die Logfile unter Gmer.txt auf deinem Desktop. Mit "Ok" wird GMER beendet.
Antiviren-Programm und sonstige Scanner wieder einschalten, bevor Du ins Netz gehst!

snowly1 29.02.2012 01:11

Hallo. Ich habe die Scans gemacht. Siehe weiter unten. Avira meldet immer noch "Malware gefunden". Ich habe den Virus NICHT entfernt. Ist das richtig? (Ich habe noch keine Antwort auf meine heutigen Fragen erhalten.) CF:
[code]
Combofix Logfile:
Code:

ComboFix 12-02-27.02 - Acer 28.02.2012  23:22:09.2.2 - x86
Microsoft Windows 7 Starter  6.1.7601.1.1252.41.1031.18.1014.491 [GMT 1:00]
ausgeführt von:: c:\users\Acer\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Acer\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-01-28 bis 2012-02-28  ))))))))))))))))))))))))))))))
.
.
2012-02-28 22:37 . 2012-02-28 22:37        --------        d-----w-        c:\users\Public\AppData\Local\temp
2012-02-28 22:37 . 2012-02-28 22:37        --------        d-----w-        c:\users\Gast\AppData\Local\temp
2012-02-28 22:37 . 2012-02-28 22:37        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-02-28 09:32 . 2012-02-28 09:32        --------        d-----w-        c:\windows\system32\wbem\en-US
2012-02-28 00:22 . 2012-02-28 22:37        --------        d-----w-        c:\users\Acer\AppData\Local\temp
2012-02-18 12:38 . 2012-02-18 12:38        --------        d-----w-        c:\windows\Sun
2012-02-18 12:02 . 2011-12-30 05:27        478720        ----a-w-        c:\windows\system32\timedate.cpl
2012-02-18 12:01 . 2011-12-16 07:52        690688        ----a-w-        c:\windows\system32\msvcrt.dll
2012-02-18 12:01 . 2012-01-04 08:58        442880        ----a-w-        c:\windows\system32\ntshrui.dll
2012-02-18 12:00 . 2012-01-14 03:35        2343424        ----a-w-        c:\windows\system32\win32k.sys
2012-02-07 19:30 . 2009-08-11 20:18        497664        ----a-w-        c:\windows\system32\ac3filter.acm
2012-02-07 19:30 . 2012-02-07 19:30        --------        d-----w-        c:\program files\AC3Filter
2012-01-30 13:57 . 2012-01-30 13:57        --------        d-----w-        c:\programdata\Firefly Studios
2012-01-30 13:53 . 2006-12-08 11:02        251672        ----a-w-        c:\windows\system32\xactengine2_5.dll
2012-01-30 13:53 . 2006-11-29 12:06        3426072        ----a-w-        c:\windows\system32\d3dx9_32.dll
2012-01-30 13:53 . 2006-11-15 10:38        15128        ----a-w-        c:\windows\system32\x3daudio1_1.dll
2012-01-30 13:53 . 2006-09-28 15:05        237848        ----a-w-        c:\windows\system32\xactengine2_4.dll
2012-01-30 13:53 . 2006-09-28 15:05        2414360        ----a-w-        c:\windows\system32\d3dx9_31.dll
2012-01-30 13:53 . 2006-09-28 15:04        68888        ----a-w-        c:\windows\system32\xinput1_3.dll
2012-01-30 13:53 . 2006-07-28 08:30        236824        ----a-w-        c:\windows\system32\xactengine2_3.dll
2012-01-30 13:53 . 2006-07-28 08:30        62744        ----a-w-        c:\windows\system32\xinput1_2.dll
2012-01-30 13:44 . 2012-01-30 13:44        --------        d-----w-        c:\program files\Firefly Studios
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-06 19:12 . 2011-09-08 18:45        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-24 16:35 . 2012-01-24 16:35        212992        ----a-w-        c:\windows\system32\aptw2s8pj.dll
2012-01-10 14:39 . 2011-08-27 14:12        98304        ----a-w-        c:\windows\system32\CmdLineExt.dll
2011-12-10 14:24 . 2011-12-30 10:46        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-12-07 15:39 . 2011-12-07 15:39        472808        ----a-w-        c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
2011-05-09 08:49        176936        ----a-w-        c:\program files\Freeware.de\prxtbFree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53        787744        ----a-w-        c:\program files\Yontoo Layers Runtime\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7E111A5C-3D11-4F56-9463-5310C3C69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-08-06 17:18        120104        ----a-w-        c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeCT"="c:\program files\FreeCountdownTimer\FreeCountdownTimer.exe" [2011-05-24 2033488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-06-02 1130504]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-08-06 707104]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-08-04 199464]
"mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-08-06 349480]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"NortonOnlineBackupReminder"="c:\program files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-18 1537320]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-29 281768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2009-8-14 708608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FILSHtray]
2012-01-10 12:08        596992        ----a-w-        c:\program files\FILSHtray\FILSHtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-08-18 23:07        421736        ----a-w-        c:\program files\iTunes\iTunesHelper.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-24 167424]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 18992]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 16432]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60976]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-05-01 136360]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2009-08-06 727584]
S2 Greg_Service;GRegService;c:\program files\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
S2 Update-Service;Update-Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
Update-Service-Installer-Service        REG_MULTI_SZ          Update-Service-Installer-Service
Update-Service        REG_MULTI_SZ          Update-Service
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2736476
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_one&r=07b511093115l03e4ww85w47323005
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(3936)
c:\program files\EgisTec\MyWinLocker 3\x86\psdprotect.dll
c:\program files\EgisTec\MyWinLocker 3\x86\sysenv.dll
c:\program files\Acer\Acer ePower Management\SysHook.dll
.
Zeit der Fertigstellung: 2012-02-28  23:43:13
ComboFix-quarantined-files.txt  2012-02-28 22:43
ComboFix2.txt  2012-02-28 00:22
ComboFix3.txt  2012-01-06 19:22
.
Vor Suchlauf: 16 Verzeichnis(se), 69'864'243'200 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 69'815'042'048 Bytes frei
.
- - End Of File - - 6D4BD0D7517FF81B7140B430997A2394

--- --- ---

MBAM:
Code:

Malwarebytes Anti-Malware (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.02.28.05

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Acer :: ACER-PC [Administrator]

Schutz: Deaktiviert

28.02.2012 23:47:20
mbam-log-2012-02-28 (23-47-20).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 194561
Laufzeit: 6 Minute(n), 3 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Gmer:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-02-29 00:57:36
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD16 rev.11.0
Running: r8z3xleh.exe; Driver: C:\Users\Acer\AppData\Local\Temp\kwldrpob.sys


---- System - GMER 1.0.15 ----

SSDT            8075A486                                                                                ZwCreateSection
SSDT            8075A48B                                                                                ZwSetContextThread
SSDT            8075A427                                                                                ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text          ntoskrnl.exe!ZwSaveKey + 13CD                                                            820839A9 1 Byte  [06]
.text          ntoskrnl.exe!KiDispatchInterrupt + 5A2                                                  820A34E2 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text          ntoskrnl.exe!KeRemoveQueueEx + 14BF                                                      820AA87C 4 Bytes  [86, A4, 75, 80]
.text          ntoskrnl.exe!KeRemoveQueueEx + 185F                                                      820AAC1C 4 Bytes  [8B, A4, 75, 80]
.text          ntoskrnl.exe!KeRemoveQueueEx + 1937                                                      820AACF4 4 Bytes  [27, A4, 75, 80] {DAA ; MOVSB ; JNZ 0xffffffffffffff84}

---- User code sections - GMER 1.0.15 ----

.text          C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose                                  77CB54C8 5 Bytes  JMP 01041B91
.text          C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection                          77CB56E8 5 Bytes  JMP 010408F8
.text          C:\Windows\system32\svchost.exe[964] ntdll.dll!NtMapViewOfSection                        77CB5C28 5 Bytes  JMP 01040BD4
.text          C:\Windows\system32\svchost.exe[964] ntdll.dll!NtOpenFile                                77CB5CD8 5 Bytes  JMP 010418B4
.text          C:\Windows\system32\svchost.exe[964] ntdll.dll!NtOpenSection                            77CB5DC8 5 Bytes  JMP 01040683
.text          C:\Windows\system32\svchost.exe[964] ntdll.dll!NtQueryAttributesFile                    77CB5F38 5 Bytes  JMP 010415E1
.text          C:\Windows\system32\svchost.exe[964] ntdll.dll!NtQuerySection                            77CB6188 5 Bytes  JMP 0104116D
.text          C:\Windows\system32\svchost.exe[964] ntdll.dll!NtQueryVirtualMemory                      77CB6258 5 Bytes  JMP 01041D66
.text          C:\Windows\system32\svchost.exe[964] ntdll.dll!NtUnmapViewOfSection                      77CB69B8 5 Bytes  JMP 01040F2E

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                  Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                  Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                  rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                  rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                  rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device          \Driver\ACPI_HAL \Device\0000004a                                                        halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
---- Processes - GMER 1.0.15 ----

Library        C:\Windows\system32\6340a.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [964]  0x03D30000                                                                                                                                         

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch2@Epoch                        4398

---- EOF - GMER 1.0.15 ----

Besten Dank. Was nun?

Psychotic 01.03.2012 00:07

Hallo,

du könntest natürlich versuchen, die Datei via antivir zu entfernen - nur glaube ich nicht, dass das viel bringen wird! Mach bitte einmal folgendes:


Schritt 1: CF-Script

Hinweis für Mitleser:
Folgendes ComboFix Skript ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

Lösche die vorhandene Combofix.exe von deinem Desktop und lade das Programm von einem der folgenden Download-Spiegel neu herunter:
BleepingComputer.com - ForoSpyware.com
und speichere es erneut auf dem Desktop (nicht woanders hin, das ist wichtig)!

Drücke die Windows + R Taste --> Notepad (hinein schreiben) --> OK

Kopiere nun den Text aus der folgenden Codebox komplett in das leere Textdokument.
Code:

ROOTKIT::
C:\Windows\system32\6340a.dll

Speichere dies als CFScript.txt auf Deinem Desktop.

Wichtig:
  • Stelle deine Anti Viren Software temprär ab. Dies kann ComboFix nämlich bei der Arbeit behindern.
    Danach wieder anstellen nicht vergessen!
  • Bewege nicht die Maus über das ComboFix-Fenster oder klicke in dieses hinein.
    Dies kann dazu führen, dass ComboFix sich aufhängt.
  • Schließe alle laufenden Programme. Gehe sicher das ComboFix ungehindert arbeiten kann.
  • Mache nichts am PC solange ComboFix läuft.
http://i266.photobucket.com/albums/i.../CFScriptB.gif
  • In Bezug auf obiges Bild, ziehe CFScript.txt in die ComboFix.exe
  • Wenn ComboFix fertig ist, wird es ein Log erstellen, C:\ComboFix.txt. Bitte füge es hier als Antwort ein.
Falls im Skript die Anweisung Suspect:: oder Collect:: enthalten ist, wird eine Message-Box erscheinen, nachdem Combofix fertig ist. Klicke OK und folge den Aufforderungen/Anweisungen, um die Dateien hochzuladen.



Schritt 2: Prüfung über Virustotal



Bitte lasse die Datei aus der Code-Box bei Virustotal überprüfen.
  • Klicke auf Durchsuchen
  • Kopiere nun folgendes in die Suchleiste.
    Code:

    c:\windows\system32\aptw2s8pj.dll
  • und klicke auf Öffnen.
  • Klicke auf Send File.

Warte bitte bis die Datei vollständig hochgeladen wurde. Solltest Du folgende Meldung bekommen.

klicke auf Reanalyse.
Warte bis unter Current status: Finished steht.

Kopiere den Link aus deiner Adresszeile und poste ihn hier.

snowly1 01.03.2012 16:45

Hallo Marius.
Combofix habe ich gemacht. Es gab eine Fehlermeldung: PEV.exe funktioniert nicht mehr. Irgendetwas von warten, bis es eine Lösung gibt, und dass das Prog. beendet wird. Windows hat dann neu gestartet und die Datei .txt erstellt:

Combofix Logfile:
Code:

ComboFix 12-03-01.01 - Acer 01.03.2012  16:08:21.3.2 - x86
Microsoft Windows 7 Starter  6.1.7601.1.1252.41.1031.18.1014.407 [GMT 1:00]
ausgeführt von:: c:\users\Acer\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Acer\Desktop\cfscript.txt
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-02-01 bis 2012-03-01  ))))))))))))))))))))))))))))))
.
.
2012-03-01 15:23 . 2012-03-01 15:23        --------        d-----w-        c:\users\Public\AppData\Local\temp
2012-03-01 15:23 . 2012-03-01 15:23        --------        d-----w-        c:\users\Gast\AppData\Local\temp
2012-03-01 15:23 . 2012-03-01 15:23        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-02-28 09:32 . 2012-02-28 09:32        --------        d-----w-        c:\windows\system32\wbem\en-US
2012-02-28 00:22 . 2012-03-01 15:25        --------        d-----w-        c:\users\Acer\AppData\Local\temp
2012-02-18 12:38 . 2012-02-18 12:38        --------        d-----w-        c:\windows\Sun
2012-02-18 12:02 . 2011-12-30 05:27        478720        ----a-w-        c:\windows\system32\timedate.cpl
2012-02-18 12:01 . 2011-12-16 07:52        690688        ----a-w-        c:\windows\system32\msvcrt.dll
2012-02-18 12:01 . 2012-01-04 08:58        442880        ----a-w-        c:\windows\system32\ntshrui.dll
2012-02-18 12:00 . 2012-01-14 03:35        2343424        ----a-w-        c:\windows\system32\win32k.sys
2012-02-07 19:30 . 2009-08-11 20:18        497664        ----a-w-        c:\windows\system32\ac3filter.acm
2012-02-07 19:30 . 2012-02-07 19:30        --------        d-----w-        c:\program files\AC3Filter
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-06 19:12 . 2011-09-08 18:45        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-24 16:35 . 2012-01-24 16:35        212992        ----a-w-        c:\windows\system32\aptw2s8pj.dll
2012-01-10 14:39 . 2011-08-27 14:12        98304        ----a-w-        c:\windows\system32\CmdLineExt.dll
2011-12-10 14:24 . 2011-12-30 10:46        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-12-07 15:39 . 2011-12-07 15:39        472808        ----a-w-        c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
2011-05-09 08:49        176936        ----a-w-        c:\program files\Freeware.de\prxtbFree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53        787744        ----a-w-        c:\program files\Yontoo Layers Runtime\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7E111A5C-3D11-4F56-9463-5310C3C69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-08-06 17:18        120104        ----a-w-        c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeCT"="c:\program files\FreeCountdownTimer\FreeCountdownTimer.exe" [2011-05-24 2033488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-06-02 1130504]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-08-06 707104]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-08-04 199464]
"mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-08-06 349480]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"NortonOnlineBackupReminder"="c:\program files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-18 1537320]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-29 281768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2009-8-14 708608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FILSHtray]
2012-01-10 12:08        596992        ----a-w-        c:\program files\FILSHtray\FILSHtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-08-18 23:07        421736        ----a-w-        c:\program files\iTunes\iTunesHelper.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-24 167424]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 18992]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 16432]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60976]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-05-01 136360]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2009-08-06 727584]
S2 Greg_Service;GRegService;c:\program files\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
S2 Update-Service;Update-Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
Update-Service-Installer-Service        REG_MULTI_SZ          Update-Service-Installer-Service
Update-Service        REG_MULTI_SZ          Update-Service
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2736476
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_one&r=07b511093115l03e4ww85w47323005
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(2884)
c:\program files\EgisTec\MyWinLocker 3\x86\psdprotect.dll
c:\program files\EgisTec\MyWinLocker 3\x86\sysenv.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conhost.exe
c:\program files\EgisTec\MyWinLocker 3\x86\MWLService.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conhost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-03-01  16:31:53 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-03-01 15:31
ComboFix2.txt  2012-02-28 22:43
ComboFix3.txt  2012-02-28 00:22
ComboFix4.txt  2012-01-06 19:22
.
Vor Suchlauf: 16 Verzeichnis(se), 70'979'403'776 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 70'969'298'944 Bytes frei
.
- - End Of File - - E218FA2C28B96C709C84A87E61D39A7A

--- --- ---


Der Link von Virustotal:
Code:

https://www.virustotal.com/file/04e26ac84d0d2485632d9b17f77ec1727f2e20f6783f09464ffa026cd1d3f07a/analysis/1330616310/
Was nun?

Psychotic 02.03.2012 18:37

Schritt 1: Fix mit The Avenger


Lade dir das Tool Avenger und speichere es auf dem Desktop:

http://larusso.trojaner-board.de/Images/avenger.jpg
  1. Kopiere nun folgenden Text in das weiße Feld (bei -> "input script here")
    Code:

    Files to delete:
    C:\Windows\system32\6340a.dll

  2. Setze den Haken bei Automatically disable any rootkits found
  3. Schließe alle laufenden Programme. Trenne Dich vom Internet.
  4. Starte Avenger mit Klick auf Execute
  5. Bestätige mit Yes den Neustart des Rechners.
  6. Nachdem das System neu gestartet ist, findest du hier einen Report vom Avenger -> C:\avenger.txt
    Poste mir in deiner nächsten Antwort den Inhalt der Avenger.txt

snowly1 02.03.2012 21:53

Hier das post:
Code:

Logfile of The Avenger Version 2.0, (c) by Swandog46
hxxp://swandog46.geekstogo.com

Platform:  Windows Vista

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error:  file "C:\Windows\system32\6340a.dll" not found!
Deletion of file "C:\Windows\system32\6340a.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Completed script processing.

*******************

Finished!  Terminate.

Antivir meldet keinen Virus mehr. Sind wir durch?

Psychotic 03.03.2012 18:52

FRST


Downloade dir bitte Farbar's Recovery Scan Tool und speichere diese auf einen USB Stick. Schließe den USB Stick an das infizierte System an Du musst das System nun in die System Reparatur Option booten. Über den Boot Manager
  • Starte den Rechner neu auf.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu auf und starte von der CD
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !!
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument --> Datei --> Speichern unter und wähle Computer Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein. e:\frst.exe Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Yes und klicke Scan
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier.

snowly1 03.03.2012 23:45

Hier ist frst.txt:
Code:

Scan result of Farbar Recovery Scan Tool (FRST written by farbar) Version: 01-03-2012
Ran by SYSTEM at 03-03-2012 23:33:36
Running from F:\
Windows 7 Starter  (X86) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM\...\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe [1130504 2009-06-01] (Dritek System Inc.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7600672 2009-07-06] (Realtek Semiconductor)
HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [707104 2009-08-05] (Acer Incorporated)
HKLM\...\Run: [EgisTecLiveUpdate] "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe" [199464 2009-08-03] (Egis Technology Inc.)
HKLM\...\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-08-06] (Egis Technology Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM\...\Run: [NortonOnlineBackupReminder] "C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED [588648 2009-07-24] (Symantec Corporation)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1537320 2009-06-18] (Synaptics Incorporated)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2009-09-23] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [173592 2009-09-23] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [150552 2009-09-23] (Intel Corporation)
HKLM\...\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min [281768 2011-03-29] (Avira GmbH)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [460872 2012-01-13] (Malwarebytes Corporation)
HKU\Acer\...\Run: [FreeCT] C:\Program Files\FreeCountdownTimer\FreeCountdownTimer.exe -autorun [2033488 2011-05-24] (Comfort Software Group)
HKU\Acer\...\Policies\system: [LogonHoursAction] 2
HKU\Acer\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Gast\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162

================================ Services (Whitelisted) ==================

2 AntiVirSchedulerService; "C:\Program Files\Avira\AntiVir Desktop\sched.exe" [136360 2011-04-30] (Avira GmbH)
2 AntiVirService; "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [269480 2011-07-24] (Avira GmbH)
2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [727584 2009-08-05] (Acer Incorporated)
2 Greg_Service; C:\Program Files\Acer\Registration\GregHSRW.exe [1150496 2009-06-04] (Acer Incorporated)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [652360 2012-01-13] (Malwarebytes Corporation)
2 MWLService; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [311592 2009-08-06] (Egis Technology Inc.)
2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated)
2 Update-Service; C:\Windows\System32\UpdSvc.dll [114000 2011-11-11] (Joosoft.com GmbH)
2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [240160 2009-07-03] (Acer)

========================== Drivers (Whitelisted) =============

2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [66616 2011-07-24] (Avira GmbH)
1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [138192 2011-07-24] (Avira GmbH)
3 BridgeMP; C:\Windows\System32\DRIVERS\bridge.sys [78336 2009-07-13] (Microsoft Corporation)
3 DKbFltr; C:\Windows\System32\DRIVERS\DKbFltr.sys [21000 2009-03-25] (Dritek System Inc.)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [20464 2011-12-10] (Malwarebytes Corporation)
1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [18992 2009-06-02] (Egis Technology Inc.)
1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2009-06-02] (Egis Technology Inc.)
1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [60976 2009-06-02] (Egis Technology Inc.)
1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-05-11] (Avira GmbH)
3 catchme; \??\C:\Users\Acer\AppData\Local\Temp\catchme.sys [x]
3 RtsUIR; C:\Windows\System32\DRIVERS\Rts516xIR.sys [x]
3 USBCCID; C:\Windows\System32\DRIVERS\RtsUCcid.sys [x]

========================== NetSvcs (Whitelisted) ===========

============ One Month Created Files and Folders ==============

2012-03-02 12:42 - 2012-03-02 12:43 - 0000000 ____D C:\Avenger
2012-03-02 12:42 - 2012-03-02 12:42 - 0001298 ____A C:\avenger.txt
2012-03-02 12:36 - 2012-03-02 12:37 - 0731136 ____A C:\Users\Acer\Desktop\avenger.exe
2012-03-01 07:31 - 2012-03-01 07:31 - 0010851 ____A C:\ComboFix.txt
2012-03-01 07:25 - 2012-03-01 07:25 - 0000000 __SHD C:\$RECYCLE.BIN
2012-03-01 07:03 - 2012-03-01 07:32 - 0000000 ____D C:\ComboFix
2012-03-01 06:58 - 2012-03-01 06:58 - 4423209 ____R (Swearware) C:\Users\Acer\Desktop\ComboFix.exe
2012-02-28 15:07 - 2012-02-28 15:07 - 0302592 ____A C:\Users\Acer\Desktop\r8z3xleh.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 9705472 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 3695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-02-27 16:57 - 2012-02-27 16:57 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-02-27 16:57 - 2012-02-27 16:57 - 1798656 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1792000 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1427456 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-02-27 16:57 - 2012-02-27 16:57 - 12282368 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1127424 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1103360 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0580608 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0434176 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0367104 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-02-27 16:57 - 2012-02-27 16:57 - 0353792 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0353584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0227840 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0223232 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0203776 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0162304 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0161792 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0152064 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0130560 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0123392 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0118784 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0101888 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0086528 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0078848 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0076800 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0074240 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0072822 ____A C:\Windows\System32\ieuinit.inf
2012-02-27 16:57 - 2012-02-27 16:57 - 0072704 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0066048 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0063488 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-02-27 16:57 - 2012-02-27 16:57 - 0054272 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0041472 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0035840 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0031744 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0023552 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0011776 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-02-27 16:30 - 2012-02-27 16:30 - 0001629 ____A C:\Windows\System32\FSS.txt
2012-02-27 15:59 - 2011-06-25 22:45 - 0256000 ____A C:\Windows\PEV.exe
2012-02-27 15:59 - 2010-11-07 09:20 - 0208896 ____A C:\Windows\MBR.exe
2012-02-27 15:59 - 2009-04-19 20:56 - 0060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-02-27 15:59 - 2000-08-30 16:00 - 0518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-02-27 15:59 - 2000-08-30 16:00 - 0406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-02-27 15:59 - 2000-08-30 16:00 - 0098816 ____A C:\Windows\sed.exe
2012-02-27 15:59 - 2000-08-30 16:00 - 0080412 ____A C:\Windows\grep.exe
2012-02-27 15:59 - 2000-08-30 16:00 - 0068096 ____A C:\Windows\zip.exe
2012-02-27 15:55 - 2012-02-27 15:55 - 0337133 ____A C:\Users\Acer\Downloads\FSS.exe
2012-02-27 15:49 - 2012-02-27 15:50 - 4420957 ____A (Swearware) C:\Users\Acer\Downloads\ComboFix.exe
2012-02-27 13:23 - 2012-02-28 15:57 - 0004900 ____A C:\Users\Acer\Desktop\gmer.txt
2012-02-27 09:06 - 2012-02-27 09:06 - 0144960 ____A C:\Windows\Minidump\022712-17643-01.dmp
2012-02-27 09:06 - 2012-02-27 09:06 - 0000000 ____D C:\Windows\Minidump
2012-02-27 09:05 - 2012-02-27 09:05 - 326712483 ____A C:\Windows\MEMORY.DMP
2012-02-27 08:29 - 2012-02-27 08:29 - 0302592 ____A C:\Users\Acer\Downloads\g20q7onb.exe
2012-02-26 16:04 - 2012-02-26 16:04 - 0005885 ____A C:\Users\Acer\Desktop\Attach.txt
2012-02-26 16:00 - 2012-02-26 16:00 - 0012813 ____A C:\Users\Acer\Desktop\DDS.txt
2012-02-26 15:50 - 2012-02-26 15:50 - 0000000 ____A C:\Users\Acer\defogger_reenable
2012-02-26 15:47 - 2012-02-26 15:47 - 0302592 ____A C:\Users\Acer\Downloads\hk4txtc9.exe
2012-02-26 15:43 - 2012-02-26 15:43 - 0607260 ____R (Swearware) C:\Users\Acer\Downloads\dds.com
2012-02-26 15:41 - 2012-02-26 15:41 - 0050477 ____A C:\Users\Acer\Downloads\Defogger.exe
2012-02-26 15:31 - 2012-02-26 15:31 - 0004008 ____A C:\Users\Acer\Desktop\Ereignisse2.txt
2012-02-26 15:30 - 2012-02-26 15:30 - 0008624 ____A C:\Users\Acer\Desktop\Ereignisse.txt
2012-02-19 09:26 - 2012-02-19 09:26 - 0553863 ____A C:\Users\Acer\Downloads\2011_06_29_SkinEdit_alpha3_pre7_fix.zip
2012-02-19 06:39 - 2012-02-19 06:42 - 24554628 ____A C:\Users\Acer\Downloads\GammlerPlay.zip
2012-02-18 16:03 - 2012-02-18 16:05 - 0000022 ____A C:\Users\Acer\Downloads\Star Wars Skin Pack V4.zip
2012-02-18 15:26 - 2012-02-18 15:41 - 14513553 ____A C:\Users\Acer\Downloads\DokuCraft - The Saga Continues 1.2.zip
2012-02-18 15:18 - 2012-02-18 15:18 - 4389435 ____A C:\Users\Acer\Downloads\DokuCraft_218326.zip
2012-02-18 14:20 - 2012-02-21 11:08 - 0000426 ____A C:\Users\Acer\Desktop\settings.xml
2012-02-18 10:53 - 2012-02-18 11:17 - 0000417 ____A C:\Windows\System32\settings.xml
2012-02-18 04:38 - 2012-02-18 04:38 - 0000000 ____D C:\Windows\Sun
2012-02-18 04:02 - 2011-12-29 21:27 - 0478720 ____A (Microsoft Corporation) C:\Windows\System32\timedate.cpl
2012-02-18 04:01 - 2012-02-18 04:01 - 0000681 ____A C:\Users\Acer\Desktop\Minecraft.exe - Verknüpfung.lnk
2012-02-18 04:01 - 2012-01-04 00:59 - 12872704 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-02-18 04:01 - 2012-01-04 00:58 - 0442880 ____A (Microsoft Corporation) C:\Windows\System32\ntshrui.dll
2012-02-18 04:01 - 2011-12-15 23:52 - 0690688 ____A (Microsoft Corporation) C:\Windows\System32\msvcrt.dll
2012-02-18 04:00 - 2012-01-13 19:35 - 2343424 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-02-18 03:39 - 2012-02-18 03:39 - 0510657 ____A C:\Users\Acer\Downloads\MCSkinEdit_a3_pre5.zip
2012-02-11 08:58 - 2012-02-26 12:49 - 0000000 ___RD C:\Users\Acer\Desktop\let's play's svenweisven
2012-02-11 07:10 - 2012-02-11 07:10 - 0000000 ____D C:\Users\Acer\AppData\Local\{E09BE6F8-59E7-489F-B41E-CCB4F4175006}
2012-02-11 07:10 - 2012-02-11 07:10 - 0000000 ____D C:\Users\Acer\AppData\Local\{11BC444D-7AF9-43B6-B0AF-BF4BC8FF9787}
2012-02-11 03:09 - 2012-02-11 03:10 - 0270142 ____A C:\Users\Acer\Downloads\Minecraft.exe
2012-02-07 11:30 - 2012-02-07 11:30 - 0000000 ____D C:\Program Files\AC3Filter
2012-02-07 11:30 - 2009-08-11 12:18 - 0497664 ____A C:\Windows\System32\ac3filter.acm


============ 3 Months Modified Files and Folders ===============

2012-03-03 23:33 - 2012-03-03 23:33 - 0000000 ____D C:\FRST
2012-03-03 14:24 - 2009-07-13 20:34 - 0009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-03-03 14:24 - 2009-07-13 20:34 - 0009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-03-03 14:21 - 2009-09-16 10:36 - 797396992 __ASH C:\hiberfil.sys
2012-03-03 14:21 - 2009-08-14 01:26 - 0845514 ____A C:\Windows\PFRO.log
2012-03-03 14:21 - 2009-07-13 20:53 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2012-03-03 14:21 - 2009-07-13 20:39 - 0057650 ____A C:\Windows\setupact.log
2012-03-03 14:12 - 2009-09-16 10:39 - 1797165 ____A C:\Windows\WindowsUpdate.log
2012-03-03 14:11 - 2009-08-14 00:37 - 1498506 ____A C:\Windows\System32\PerfStringBackup.INI
2012-03-02 12:43 - 2012-03-02 12:42 - 0000000 ____D C:\Avenger
2012-03-02 12:42 - 2012-03-02 12:42 - 0001298 ____A C:\avenger.txt
2012-03-02 12:37 - 2012-03-02 12:36 - 0731136 ____A C:\Users\Acer\Desktop\avenger.exe
2012-03-01 07:32 - 2012-03-01 07:03 - 0000000 ____D C:\ComboFix
2012-03-01 07:32 - 2012-01-06 11:00 - 0000000 ____D C:\Qoobox
2012-03-01 07:31 - 2012-03-01 07:31 - 0010851 ____A C:\ComboFix.txt
2012-03-01 07:25 - 2012-03-01 07:25 - 0000000 __SHD C:\$RECYCLE.BIN
2012-03-01 07:25 - 2009-07-13 18:04 - 0000215 ____A C:\Windows\system.ini
2012-03-01 07:25 - 2009-07-13 18:04 - 0000027 ____A C:\Windows\System32\Drivers\etc\hosts
2012-03-01 07:23 - 2012-01-06 11:00 - 0000000 ____D C:\Windows\ERDNT
2012-03-01 06:58 - 2012-03-01 06:58 - 4423209 ____R (Swearware) C:\Users\Acer\Desktop\ComboFix.exe
2012-02-28 15:57 - 2012-02-27 13:23 - 0004900 ____A C:\Users\Acer\Desktop\gmer.txt
2012-02-28 15:07 - 2012-02-28 15:07 - 0302592 ____A C:\Users\Acer\Desktop\r8z3xleh.exe
2012-02-28 04:32 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\rescache
2012-02-28 02:18 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\Microsoft.NET
2012-02-28 01:32 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\de-DE
2012-02-27 16:59 - 2011-10-11 06:42 - 0021282 ____A C:\Windows\IE9_main.log
2012-02-27 16:57 - 2012-02-27 16:57 - 9705472 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 3695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-02-27 16:57 - 2012-02-27 16:57 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-02-27 16:57 - 2012-02-27 16:57 - 1798656 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1792000 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1427456 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-02-27 16:57 - 2012-02-27 16:57 - 12282368 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1127424 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1103360 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0580608 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0434176 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0367104 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-02-27 16:57 - 2012-02-27 16:57 - 0353792 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0353584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0227840 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0223232 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0203776 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0162304 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0161792 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0152064 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0130560 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0123392 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0118784 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0101888 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0086528 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0078848 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0076800 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0074240 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0072822 ____A C:\Windows\System32\ieuinit.inf
2012-02-27 16:57 - 2012-02-27 16:57 - 0072704 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0066048 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0063488 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-02-27 16:57 - 2012-02-27 16:57 - 0054272 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0041472 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0035840 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0031744 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0023552 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0011776 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-02-27 16:30 - 2012-02-27 16:30 - 0001629 ____A C:\Windows\System32\FSS.txt
2012-02-27 15:55 - 2012-02-27 15:55 - 0337133 ____A C:\Users\Acer\Downloads\FSS.exe
2012-02-27 15:50 - 2012-02-27 15:49 - 4420957 ____A (Swearware) C:\Users\Acer\Downloads\ComboFix.exe
2012-02-27 14:13 - 2012-01-07 02:19 - 0000000 ____D C:\Users\Acer\AppData\Local\ElevatedDiagnostics
2012-02-27 09:06 - 2012-02-27 09:06 - 0144960 ____A C:\Windows\Minidump\022712-17643-01.dmp
2012-02-27 09:06 - 2012-02-27 09:06 - 0000000 ____D C:\Windows\Minidump
2012-02-27 09:05 - 2012-02-27 09:05 - 326712483 ____A C:\Windows\MEMORY.DMP
2012-02-27 08:29 - 2012-02-27 08:29 - 0302592 ____A C:\Users\Acer\Downloads\g20q7onb.exe
2012-02-26 16:04 - 2012-02-26 16:04 - 0005885 ____A C:\Users\Acer\Desktop\Attach.txt
2012-02-26 16:00 - 2012-02-26 16:00 - 0012813 ____A C:\Users\Acer\Desktop\DDS.txt
2012-02-26 15:50 - 2012-02-26 15:50 - 0000000 ____A C:\Users\Acer\defogger_reenable
2012-02-26 15:50 - 2011-02-26 21:18 - 0000000 ____D C:\Program Files\Safari
2012-02-26 15:50 - 2011-02-22 14:44 - 0000000 ____D C:\users\Acer
2012-02-26 15:47 - 2012-02-26 15:47 - 0302592 ____A C:\Users\Acer\Downloads\hk4txtc9.exe
2012-02-26 15:43 - 2012-02-26 15:43 - 0607260 ____R (Swearware) C:\Users\Acer\Downloads\dds.com
2012-02-26 15:41 - 2012-02-26 15:41 - 0050477 ____A C:\Users\Acer\Downloads\Defogger.exe
2012-02-26 15:31 - 2012-02-26 15:31 - 0004008 ____A C:\Users\Acer\Desktop\Ereignisse2.txt
2012-02-26 15:30 - 2012-02-26 15:30 - 0008624 ____A C:\Users\Acer\Desktop\Ereignisse.txt
2012-02-26 15:16 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\config\TxR
2012-02-26 15:14 - 2012-01-21 05:38 - 0000000 ____D C:\Program Files\Freeware.de
2012-02-26 15:14 - 2012-01-10 15:17 - 0000000 ___RD C:\Users\Acer\Desktop\SHL
2012-02-26 15:14 - 2011-09-25 07:17 - 0000000 ____D C:\Users\Acer\AppData\Local\Conduit
2012-02-26 15:14 - 2011-09-25 07:17 - 0000000 ____D C:\Program Files\Yontoo Layers Runtime
2012-02-26 15:14 - 2011-08-16 01:57 - 0000000 ____D C:\users\Gast
2012-02-26 15:14 - 2011-02-22 14:44 - 0000000 ____D C:\Users\Acer\AppData\LocalLow
2012-02-26 15:14 - 2009-08-14 01:28 - 0000000 ____D C:\Users\All Users\Symantec
2012-02-26 15:14 - 2009-08-14 01:28 - 0000000 ____D C:\ProgramData\Symantec
2012-02-26 15:14 - 2009-08-14 01:04 - 0000000 ____D C:\Program Files\Microsoft Silverlight
2012-02-26 15:14 - 2009-07-13 18:37 - 0000000 __RSD C:\Windows\Media
2012-02-26 15:14 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\wfp
2012-02-26 15:14 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\NDF
2012-02-26 15:14 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\DriverStore
2012-02-26 15:14 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\AppCompat
2012-02-26 15:14 - 2009-07-13 18:37 - 0000000 ____D C:\Program Files\Common Files\microsoft shared
2012-02-26 15:13 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\registration
2012-02-26 15:11 - 2011-12-30 02:46 - 0000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-02-26 15:11 - 2011-09-23 12:39 - 0000000 ____D C:\Users\Acer\AppData\Roaming\Skype
2012-02-26 15:11 - 2009-08-14 00:56 - 0000000 ____D C:\Program Files\Microsoft Works
2012-02-26 12:49 - 2012-02-11 08:58 - 0000000 ___RD C:\Users\Acer\Desktop\let's play's svenweisven
2012-02-26 12:49 - 2011-12-08 11:56 - 0000000 ___RD C:\Users\Acer\Desktop\Sender
2012-02-26 12:49 - 2011-04-11 21:49 - 0000000 ___RD C:\Users\Acer\Desktop\star wars the clone wars
2012-02-21 11:08 - 2012-02-18 14:20 - 0000426 ____A C:\Users\Acer\Desktop\settings.xml
2012-02-19 09:26 - 2012-02-19 09:26 - 0553863 ____A C:\Users\Acer\Downloads\2011_06_29_SkinEdit_alpha3_pre7_fix.zip
2012-02-19 07:41 - 2011-12-07 07:40 - 0000000 ____D C:\Users\Acer\AppData\Roaming\.minecraft
2012-02-19 06:42 - 2012-02-19 06:39 - 24554628 ____A C:\Users\Acer\Downloads\GammlerPlay.zip
2012-02-19 00:05 - 2011-12-14 10:21 - 0000000 ____D C:\Users\Acer\Documents\FILSHtray
2012-02-19 00:03 - 2011-02-22 14:45 - 0000174 ___SH C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
2012-02-18 18:37 - 2009-07-13 20:33 - 0302320 ____A C:\Windows\System32\FNTCACHE.DAT
2012-02-18 18:15 - 2011-02-22 15:33 - 52550552 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-02-18 16:05 - 2012-02-18 16:03 - 0000022 ____A C:\Users\Acer\Downloads\Star Wars Skin Pack V4.zip
2012-02-18 15:41 - 2012-02-18 15:26 - 14513553 ____A C:\Users\Acer\Downloads\DokuCraft - The Saga Continues 1.2.zip
2012-02-18 15:18 - 2012-02-18 15:18 - 4389435 ____A C:\Users\Acer\Downloads\DokuCraft_218326.zip
2012-02-18 14:19 - 2010-06-03 12:19 - 0155762 ____A C:\Users\Acer\Desktop\MCSkinEdit.jar
2012-02-18 11:17 - 2012-02-18 10:53 - 0000417 ____A C:\Windows\System32\settings.xml
2012-02-18 04:38 - 2012-02-18 04:38 - 0000000 ____D C:\Windows\Sun
2012-02-18 04:01 - 2012-02-18 04:01 - 0000681 ____A C:\Users\Acer\Desktop\Minecraft.exe - Verknüpfung.lnk
2012-02-18 03:39 - 2012-02-18 03:39 - 0510657 ____A C:\Users\Acer\Downloads\MCSkinEdit_a3_pre5.zip
2012-02-11 07:11 - 2011-10-15 01:54 - 0000000 ____D C:\Users\Acer\AppData\Local\Windows Live
2012-02-11 07:10 - 2012-02-11 07:10 - 0000000 ____D C:\Users\Acer\AppData\Local\{E09BE6F8-59E7-489F-B41E-CCB4F4175006}
2012-02-11 07:10 - 2012-02-11 07:10 - 0000000 ____D C:\Users\Acer\AppData\Local\{11BC444D-7AF9-43B6-B0AF-BF4BC8FF9787}
2012-02-11 03:10 - 2012-02-11 03:09 - 0270142 ____A C:\Users\Acer\Downloads\Minecraft.exe
2012-02-07 14:36 - 2009-08-14 00:54 - 0000000 ____D C:\Users\All Users\Microsoft Help
2012-02-07 14:36 - 2009-08-14 00:54 - 0000000 ____D C:\ProgramData\Microsoft Help
2012-02-07 13:38 - 2011-12-30 02:46 - 0001075 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-02-07 11:30 - 2012-02-07 11:30 - 0000000 ____D C:\Program Files\AC3Filter
2012-02-06 11:12 - 2011-09-08 10:45 - 0414368 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-02-05 05:46 - 2009-07-13 18:37 - 0000000 ___HD C:\Windows\System32\GroupPolicyUsers
2012-02-04 00:30 - 2012-01-30 05:57 - 0000000 ____D C:\Users\Acer\Documents\Stronghold Legends
2012-01-30 05:57 - 2012-01-30 05:57 - 0000000 ____D C:\Users\All Users\Firefly Studios
2012-01-30 05:57 - 2012-01-30 05:57 - 0000000 ____D C:\ProgramData\Firefly Studios
2012-01-30 05:53 - 2011-08-27 06:10 - 0233989 ____A C:\Windows\DirectX.log
2012-01-30 05:51 - 2012-01-30 05:51 - 0001972 ____A C:\Users\Public\Desktop\Stronghold Legends.lnk
2012-01-30 05:44 - 2012-01-30 05:44 - 0000000 ____D C:\Program Files\Firefly Studios
2012-01-30 05:44 - 2009-08-14 00:34 - 0000000 ___HD C:\Program Files\InstallShield Installation Information
2012-01-24 08:35 - 2012-01-24 08:35 - 0212992 ____A (Works Ltd.) C:\Windows\System32\aptw2s8pj.dll
2012-01-21 05:39 - 2012-01-21 05:39 - 0000941 ____A C:\Users\Public\Desktop\vipstegano.lnk
2012-01-21 05:39 - 2012-01-21 05:39 - 0000000 ____D C:\Program Files\vipstegano
2012-01-21 05:38 - 2012-01-21 05:38 - 0560470 ____A C:\Users\Acer\Documents\vipstegano.zip
2012-01-21 05:38 - 2012-01-21 05:38 - 0000000 ____D C:\Program Files\Conduit
2012-01-21 05:36 - 2012-01-21 05:36 - 0512000 ____A (www.download-sponsor.de) C:\Users\Acer\Downloads\Downloader-fuer-vipstegano.exe
2012-01-21 04:36 - 2011-12-14 10:21 - 0000000 ____D C:\Program Files\FILSHtray
2012-01-13 19:35 - 2012-02-18 04:00 - 2343424 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-01-12 10:25 - 2012-01-12 10:19 - 0001278 ____A C:\Users\Acer\Desktop\easyshare.exe - Verknüpfung.lnk
2012-01-11 05:25 - 2012-01-11 05:25 - 0000000 ____D C:\Users\Acer\Downloads\hosts
2012-01-11 05:25 - 2012-01-11 05:24 - 0149201 ____A C:\Users\Acer\Downloads\hosts.zip
2012-01-10 14:42 - 2012-01-10 14:42 - 0264192 ____A C:\Users\Acer\Documents\Direkte Rede.doc
2012-01-10 14:35 - 2012-01-10 14:35 - 0000000 ____D C:\Program Files\devolo
2012-01-10 12:28 - 2011-02-22 14:45 - 0067856 ____A C:\Users\Acer\AppData\Local\GDIPFONTCACHEV1.DAT
2012-01-10 06:57 - 2011-02-26 21:19 - 0100216 ___AH C:\Windows\System32\mlfcache.dat
2012-01-10 06:51 - 2011-09-23 12:39 - 0000000 ___RD C:\Program Files\Skype
2012-01-10 06:39 - 2011-08-27 06:12 - 0098304 ____A (Sony DADC Austria AG.) C:\Windows\System32\CmdLineExt.dll
2012-01-10 05:35 - 2011-02-22 14:45 - 0000000 ____D C:\Users\Acer\AppData\Roaming\Macromedia
2012-01-09 15:05 - 2012-01-05 14:55 - 0026286 ____A C:\Users\Acer\Downloads\Extras.Txt
2012-01-09 15:04 - 2012-01-05 14:54 - 0104106 ____A C:\Users\Acer\Downloads\OTL.Txt
2012-01-09 14:03 - 2012-01-09 14:03 - 0584192 ____A (OldTimer Tools) C:\Users\Acer\Downloads\OTL-1.exe
2012-01-09 08:52 - 2012-01-09 08:52 - 2322184 ____A (ESET) C:\Users\Acer\Downloads\esetsmartinstaller_deu.exe
2012-01-09 07:41 - 2009-08-14 01:14 - 0000000 ____D C:\Program Files\Google
2012-01-09 07:07 - 2009-08-14 00:54 - 0000000 ____D C:\Program Files\Microsoft Office
2012-01-09 06:58 - 2012-01-09 06:58 - 18690352 ____A (Microsoft Corporation) C:\Users\Acer\Downloads\IE9-Windows7-x86-deu.exe
2012-01-09 06:46 - 2011-02-22 16:43 - 0000000 ____D C:\Users\Acer\AppData\Local\Google
2012-01-09 06:46 - 2009-08-14 01:14 - 0000000 ____D C:\Users\All Users\Google
2012-01-09 06:46 - 2009-08-14 01:14 - 0000000 ____D C:\ProgramData\Google
2012-01-09 06:08 - 2012-01-06 15:03 - 0000000 ____D C:\Program Files\SUPERAntiSpyware
2012-01-09 06:04 - 2009-07-13 18:37 - 0000000 ___RD C:\users\Public
2012-01-08 07:13 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\LogFiles
2012-01-07 13:38 - 2012-01-07 12:26 - 0003917 ____A C:\ipconfig.txt
2012-01-07 01:50 - 2012-01-07 01:49 - 0000000 ____D C:\Users\All Users\SUPERSetup
2012-01-07 01:50 - 2012-01-07 01:49 - 0000000 ____D C:\ProgramData\SUPERSetup
2012-01-06 15:05 - 2012-01-06 15:05 - 0000000 ____D C:\Users\Acer\AppData\Roaming\SUPERAntiSpyware.com
2012-01-06 15:03 - 2012-01-06 15:03 - 0000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-01-06 15:03 - 2012-01-06 15:03 - 0000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2012-01-06 10:50 - 2012-01-06 10:37 - 0064960 ____A C:\TDSSKiller.2.5.5.0_06.01.2012_19.37.46_log.txt
2012-01-06 10:37 - 2012-01-06 10:29 - 0064960 ____A C:\TDSSKiller.2.5.5.0_06.01.2012_19.29.26_log.txt
2012-01-06 05:39 - 2012-01-06 05:39 - 0000000 ____D C:\_OTL
2012-01-05 14:56 - 2012-01-05 14:56 - 0103440 ____A C:\Users\Acer\Downloads\OTL2012-01-05.Txt
2012-01-05 14:00 - 2012-01-05 14:00 - 0584192 ____A (OldTimer Tools) C:\Users\Acer\Downloads\OTL.exe
2012-01-05 05:21 - 2012-01-05 05:21 - 0000000 ____D C:\Program Files\ESET
2012-01-05 05:21 - 2009-07-13 20:52 - 0000000 ____D C:\Windows\Downloaded Program Files
2012-01-04 00:59 - 2012-02-18 04:01 - 12872704 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-01-04 00:58 - 2012-02-18 04:01 - 0442880 ____A (Microsoft Corporation) C:\Windows\System32\ntshrui.dll
2011-12-30 04:19 - 2011-12-30 04:19 - 0000000 ____D C:\Users\Acer\AppData\Roaming\Avira
2011-12-30 02:47 - 2011-12-30 02:47 - 0000000 ____D C:\Users\Acer\AppData\Roaming\Malwarebytes
2011-12-30 02:46 - 2011-12-30 02:46 - 0000000 ____D C:\Users\All Users\Malwarebytes
2011-12-30 02:46 - 2011-12-30 02:46 - 0000000 ____D C:\ProgramData\Malwarebytes
2011-12-29 21:27 - 2012-02-18 04:02 - 0478720 ____A (Microsoft Corporation) C:\Windows\System32\timedate.cpl
2011-12-27 09:14 - 2011-12-27 09:14 - 0000000 ____D C:\Users\Acer\AppData\Local\{115E1736-518B-4589-B5B5-F709AA32BC06}
2011-12-27 09:14 - 2011-12-27 09:14 - 0000000 ____D C:\Users\Acer\AppData\Local\{0F565D71-DE68-4225-83FB-B4D36303A680}
2011-12-24 05:02 - 2011-12-24 05:02 - 0000000 ____D C:\Users\Acer\AppData\Local\{FAA63628-9185-4ACE-A674-E50A3E857458}
2011-12-24 05:02 - 2011-12-24 05:01 - 0000000 ____D C:\Users\Acer\AppData\Local\{72DE4261-EA77-42B3-87C2-8DF7F7D32AD8}
2011-12-24 05:00 - 2011-12-24 05:00 - 0001045 ____A C:\Users\Acer\Desktop\Bilder.lnk
2011-12-21 08:31 - 2011-12-21 08:31 - 0000680 _RASH C:\Users\Acer\ntuser.pol
2011-12-21 08:31 - 2009-07-13 18:37 - 0000000 ___HD C:\Windows\System32\GroupPolicy
2011-12-21 08:15 - 2011-12-21 08:15 - 0000000 ____D C:\Users\Gast\Documents\FILSHtray
2011-12-21 08:15 - 2011-12-21 08:15 - 0000000 ____D C:\Users\Gast\AppData\Local\FILSH_Media_GmbH
2011-12-21 08:15 - 2011-08-16 01:57 - 0000000 ____D C:\Users\Gast\AppData\Local\VirtualStore
2011-12-21 08:14 - 2011-08-16 01:58 - 0068352 ____A C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT
2011-12-21 08:05 - 2011-09-08 10:43 - 0000000 ____D C:\Users\Acer\AppData\Roaming\Sony
2011-12-21 08:04 - 2011-09-08 10:46 - 0001859 ____A C:\Users\Public\Desktop\Media Go.lnk
2011-12-21 08:03 - 2011-09-08 10:46 - 0000000 ____D C:\Program Files\Common Files\Sony Shared
2011-12-21 08:01 - 2011-09-08 10:46 - 0000000 ____D C:\Users\Acer\AppData\Local\Downloaded Installations
2011-12-21 08:00 - 2011-12-21 07:52 - 0000000 ____D C:\Program Files\Sony Media Go Install
2011-12-21 08:00 - 2011-09-08 10:45 - 0000000 ____D C:\Program Files\Sony
2011-12-21 07:50 - 2011-12-21 07:44 - 94445720 ____A (Sony Creative Software Inc.) C:\Users\Acer\Downloads\mediago_setup.exe
2011-12-21 07:41 - 2011-09-08 10:50 - 0000000 ____D C:\Users\Acer\AppData\Local\Sony
2011-12-21 07:41 - 2011-09-08 10:45 - 0000000 ____D C:\Users\All Users\Sony Corporation
2011-12-21 07:41 - 2011-09-08 10:45 - 0000000 ____D C:\ProgramData\Sony Corporation
2011-12-18 10:40 - 2011-12-18 10:30 - 0000000 ____D C:\Users\Acer\Documents\Invizimals startvideo
2011-12-18 10:32 - 2011-12-18 10:32 - 0000000 ____D C:\Users\Acer\AppData\Local\{09BDA3BB-AABA-4CBB-9FBE-DC3733D68621}
2011-12-18 10:32 - 2011-12-18 10:31 - 0000000 ____D C:\Users\Acer\AppData\Local\{5CF51BF5-D3A5-42EA-B2AE-B664282FE9F6}
2011-12-15 23:52 - 2012-02-18 04:01 - 0690688 ____A (Microsoft Corporation) C:\Windows\System32\msvcrt.dll
2011-12-14 12:45 - 2011-12-14 12:45 - 0000000 ____D C:\Users\Acer\AppData\Local\{38E3FD9E-18AC-4BD7-AD71-F06A21880B91}
2011-12-14 12:45 - 2011-12-14 12:44 - 0000000 ____D C:\Users\Acer\AppData\Local\{602FBEA2-3F58-4E66-9A09-EFBA9F9B7134}
2011-12-14 10:21 - 2011-12-14 10:21 - 0000000 ____D C:\Users\Acer\AppData\Local\FILSH_Media_GmbH
2011-12-14 10:19 - 2011-12-14 10:19 - 5135327 ____A (FILSH Media GmbH                                            ) C:\Users\Acer\Documents\filsh-setup-0.7.exe
2011-12-14 04:41 - 2011-12-14 04:41 - 0000000 ____D C:\Users\Acer\AppData\Local\{EDFEB785-2DCC-4FA7-A040-80E1145A37B1}
2011-12-10 13:55 - 2011-12-10 13:55 - 0706899 ____A C:\Users\Acer\Downloads\Invizimals_Wallpaper_1024_768_de_CH.zip
2011-12-10 06:24 - 2011-12-30 02:46 - 0020464 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2011-12-07 07:40 - 2011-12-07 07:40 - 0000000 ____D C:\Users\All Users\Sun
2011-12-07 07:40 - 2011-12-07 07:40 - 0000000 ____D C:\ProgramData\Sun
2011-12-07 07:40 - 2011-12-07 07:40 - 0000000 ____D C:\Program Files\Common Files\Java
2011-12-07 07:39 - 2011-12-07 07:39 - 0472808 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2011-12-07 07:39 - 2011-12-07 07:39 - 0157472 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2011-12-07 07:39 - 2011-12-07 07:39 - 0145184 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2011-12-07 07:39 - 2011-12-07 07:39 - 0145184 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2011-12-07 07:39 - 2011-12-07 07:39 - 0000000 ____D C:\Program Files\Java

========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

========================= Memory info ======================

Percentage of memory in use: 37%
Total physical RAM: 1013.95 MB
Available physical RAM: 637.18 MB
Total Pagefile: 1013.95 MB
Available Pagefile: 640.69 MB
Total Virtual: 2047.88 MB
Available Virtual: 1970.31 MB

======================= Partitions =========================

1 Drive c: (Acer) (Fixed) (Total:135.05 GB) (Free:66.33 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:12 GB) (Free:6.01 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (USB FILME) (Removable) (Total:14.91 GB) (Free:4.34 GB) NTFS
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (SYSTEM RESERVED) (Fixed) (Total:1.99 GB) (Free:1.96 GB) NTFS ==>[System with boot components (obtained from reading drive)]

  Disk ###  Status        Size    Free    Dyn  Gpt
  --------  -------------  -------  -------  ---  ---
  Disk 0    Online          149 GB      0 B       
  Disk 1    Online          14 GB      0 B       

Partitions of Disk 0:
===============

  Partition ###  Type              Size    Offset
  -------------  ----------------  -------  -------
  Partition 1    Recovery            12 GB    31 KB
  Partition 2    Primary          2039 MB    12 GB
  Partition 3    Primary            135 GB    13 GB

======================================================================================================

Disk: 0
Partition 1
Type  : 27
Hidden: Yes
Active: No

  Volume ###  Ltr  Label        Fs    Type        Size    Status    Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 2    E  PQSERVICE    NTFS  Partition    12 GB  Healthy    Hidden 

======================================================================================================

Disk: 0
Partition 2
Type  : 07
Hidden: No
Active: Yes

  Volume ###  Ltr  Label        Fs    Type        Size    Status    Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 0    Y  SYSTEM RESE  NTFS  Partition  2039 MB  Healthy           

======================================================================================================

Disk: 0
Partition 3
Type  : 07
Hidden: No
Active: No

  Volume ###  Ltr  Label        Fs    Type        Size    Status    Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 1    C  Acer        NTFS  Partition    135 GB  Healthy           

======================================================================================================

Partitions of Disk 1:
===============

  Partition ###  Type              Size    Offset
  -------------  ----------------  -------  -------
  Partition 1    Primary            14 GB  4032 KB

======================================================================================================

Disk: 1
Partition 1
Type  : 07
Hidden: No
Active: No

  Volume ###  Ltr  Label        Fs    Type        Size    Status    Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 3    F  USB FILME    NTFS  Removable    14 GB  Healthy           

======================================================================================================

==========================================================

Last Boot: 2012-02-18 19:07

======================= End Of Log ==========================


Psychotic 04.03.2012 12:02

Schritt 1: aswMBR


Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung) Vista und Win7 User mit Rechtsklick "als Admininstartor starten"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. ( Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen ) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.


Schritt 2: Scsn mit TDSS-Killer


Lese bitte folgende Anweisungen genau. Wir wollen hier noch nichts "fixen" sondern nur einen Scan Report sehen. Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und speichere das Logfile. TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern ( Meistens C:\ ) Als Beispiel: C:\TDSSKiller.<version_date_time>log.txt
Poste den Inhalt bitte hier in deinen Thread.

snowly1 04.03.2012 15:48

Hallo Hier aswmbr.txt:
Code:

aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-03-04 15:10:35
-----------------------------
15:10:35.509    OS Version: Windows 6.1.7601 Service Pack 1
15:10:35.509    Number of processors: 2 586 0x1C02
15:10:35.524    ComputerName: ACER-PC  UserName: Acer
15:11:24.768    Initialize success
15:13:03.766    AVAST engine defs: 12030400
15:17:33.633    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
15:17:33.648    Disk 0 Vendor: WDC_WD16 11.0 Size: 152627MB BusType: 3
15:17:33.695    Disk 0 MBR read successfully
15:17:33.711    Disk 0 MBR scan
15:17:33.742    Disk 0 Windows 7 default MBR code
15:17:33.742    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        12291 MB offset 63
15:17:33.773    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        2039 MB offset 25173855
15:17:33.789    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      138293 MB offset 29350755
15:17:33.804    Disk 0 scanning sectors +312576705
15:17:33.913    Disk 0 scanning C:\Windows\system32\drivers
15:17:53.602    Service scanning
15:18:31.293    Modules scanning
15:18:44.368    Disk 0 trace - called modules:
15:18:44.415    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys
15:18:44.431    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85152030]
15:18:44.446    3 CLASSPNP.SYS[87b7f59e] -> nt!IofCallDriver -> [0x8476c8e0]
15:18:44.462    5 ACPI.sys[872363d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84713028]
15:18:45.975    AVAST engine scan C:\Windows
15:18:51.747    AVAST engine scan C:\Windows\system32
15:23:59.042    AVAST engine scan C:\Windows\system32\drivers
15:24:22.208    AVAST engine scan C:\Users\Acer
15:35:15.811    AVAST engine scan C:\ProgramData
15:35:48.087    Scan finished successfully
15:40:49.511    Disk 0 MBR has been saved successfully to "C:\Users\Acer\Desktop\MBR.dat"
15:40:49.620    The log file has been saved successfully to "C:\Users\Acer\Desktop\aswMBR.txt"

TDS killer:
Code:

15:42:06.0415 2280        TDSS rootkit removing tool 2.7.18.0 Mar  2 2012 09:40:07
15:42:06.0914 2280        ============================================================
15:42:06.0914 2280        Current date / time: 2012/03/04 15:42:06.0914
15:42:06.0914 2280        SystemInfo:
15:42:06.0914 2280       
15:42:06.0914 2280        OS Version: 6.1.7601 ServicePack: 1.0
15:42:06.0914 2280        Product type: Workstation
15:42:06.0930 2280        ComputerName: ACER-PC
15:42:06.0930 2280        UserName: Acer
15:42:06.0930 2280        Windows directory: C:\Windows
15:42:06.0930 2280        System windows directory: C:\Windows
15:42:06.0930 2280        Processor architecture: Intel x86
15:42:06.0930 2280        Number of processors: 2
15:42:06.0930 2280        Page size: 0x1000
15:42:06.0930 2280        Boot type: Normal boot
15:42:06.0930 2280        ============================================================
15:42:08.0053 2280        Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
15:42:08.0069 2280        \Device\Harddisk0\DR0:
15:42:08.0069 2280        MBR used
15:42:08.0069 2280        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1801F5F, BlocksNum 0x3FBC04
15:42:08.0069 2280        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1BFDB63, BlocksNum 0x10E1AF5E
15:42:08.0194 2280        Initialize success
15:42:08.0194 2280        ============================================================
15:42:13.0030 3192        ============================================================
15:42:13.0030 3192        Scan started
15:42:13.0030 3192        Mode: Manual;
15:42:13.0030 3192        ============================================================
15:42:13.0404 3192        1394ohci        (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
15:42:13.0420 3192        1394ohci - ok
15:42:13.0513 3192        ACPI            (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
15:42:13.0529 3192        ACPI - ok
15:42:13.0576 3192        AcpiPmi        (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
15:42:13.0591 3192        AcpiPmi - ok
15:42:13.0654 3192        adp94xx        (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
15:42:13.0654 3192        adp94xx - ok
15:42:13.0700 3192        adpahci        (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
15:42:13.0716 3192        adpahci - ok
15:42:13.0763 3192        adpu320        (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
15:42:13.0778 3192        adpu320 - ok
15:42:13.0872 3192        AFD            (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
15:42:13.0888 3192        AFD - ok
15:42:13.0934 3192        agp440          (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
15:42:13.0934 3192        agp440 - ok
15:42:14.0012 3192        aic78xx        (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
15:42:14.0012 3192        aic78xx - ok
15:42:14.0090 3192        aliide          (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
15:42:14.0090 3192        aliide - ok
15:42:14.0153 3192        amdagp          (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
15:42:14.0153 3192        amdagp - ok
15:42:14.0184 3192        amdide          (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
15:42:14.0200 3192        amdide - ok
15:42:14.0246 3192        AmdK8          (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
15:42:14.0262 3192        AmdK8 - ok
15:42:14.0293 3192        AmdPPM          (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
15:42:14.0293 3192        AmdPPM - ok
15:42:14.0356 3192        amdsata        (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
15:42:14.0356 3192        amdsata - ok
15:42:14.0418 3192        amdsbs          (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
15:42:14.0418 3192        amdsbs - ok
15:42:14.0449 3192        amdxata        (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
15:42:14.0449 3192        amdxata - ok
15:42:14.0543 3192        AppID          (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
15:42:14.0543 3192        AppID - ok
15:42:14.0668 3192        arc            (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
15:42:14.0668 3192        arc - ok
15:42:14.0714 3192        arcsas          (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
15:42:14.0730 3192        arcsas - ok
15:42:14.0777 3192        AsyncMac        (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
15:42:14.0792 3192        AsyncMac - ok
15:42:14.0839 3192        atapi          (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
15:42:14.0839 3192        atapi - ok
15:42:14.0980 3192        athr            (2eb96571fe865f07ed1fd6017575026f) C:\Windows\system32\DRIVERS\athr.sys
15:42:15.0026 3192        athr - ok
15:42:15.0089 3192        avgntflt        (1e4114685de1ffa9675e09c6a1fb3f4b) C:\Windows\system32\DRIVERS\avgntflt.sys
15:42:15.0104 3192        avgntflt - ok
15:42:15.0136 3192        avipbb          (0f78d3dae6dedd99ae54c9491c62adf2) C:\Windows\system32\DRIVERS\avipbb.sys
15:42:15.0136 3192        avipbb - ok
15:42:15.0214 3192        b06bdrv        (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
15:42:15.0214 3192        b06bdrv - ok
15:42:15.0260 3192        b57nd60x        (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
15:42:15.0260 3192        b57nd60x - ok
15:42:15.0432 3192        BCM43XX        (f9ce9b5e049efc66b8e6c73c18ee8438) C:\Windows\system32\DRIVERS\bcmwl6.sys
15:42:15.0541 3192        BCM43XX - ok
15:42:15.0619 3192        Beep            (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
15:42:15.0635 3192        Beep - ok
15:42:15.0682 3192        blbdrive        (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
15:42:15.0682 3192        blbdrive - ok
15:42:15.0744 3192        bowser          (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
15:42:15.0744 3192        bowser - ok
15:42:15.0791 3192        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
15:42:15.0791 3192        BrFiltLo - ok
15:42:15.0806 3192        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
15:42:15.0822 3192        BrFiltUp - ok
15:42:15.0900 3192        BridgeMP        (77361d72a04f18809d0efb6cceb74d4b) C:\Windows\system32\DRIVERS\bridge.sys
15:42:15.0900 3192        BridgeMP - ok
15:42:15.0962 3192        Brserid        (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
15:42:15.0978 3192        Brserid - ok
15:42:15.0994 3192        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
15:42:15.0994 3192        BrSerWdm - ok
15:42:16.0040 3192        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
15:42:16.0040 3192        BrUsbMdm - ok
15:42:16.0072 3192        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
15:42:16.0072 3192        BrUsbSer - ok
15:42:16.0103 3192        BTHMODEM        (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
15:42:16.0103 3192        BTHMODEM - ok
15:42:16.0243 3192        catchme - ok
15:42:16.0337 3192        cdfs            (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
15:42:16.0337 3192        cdfs - ok
15:42:16.0430 3192        cdrom          (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\DRIVERS\cdrom.sys
15:42:16.0430 3192        cdrom - ok
15:42:16.0493 3192        circlass        (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
15:42:16.0493 3192        circlass - ok
15:42:16.0555 3192        CLFS            (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
15:42:16.0571 3192        CLFS - ok
15:42:16.0633 3192        CmBatt          (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
15:42:16.0633 3192        CmBatt - ok
15:42:16.0711 3192        cmdide          (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
15:42:16.0711 3192        cmdide - ok
15:42:16.0789 3192        CNG            (6427525d76f61d0c519b008d3680e8e7) C:\Windows\system32\Drivers\cng.sys
15:42:16.0805 3192        CNG - ok
15:42:16.0852 3192        Compbatt        (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
15:42:16.0852 3192        Compbatt - ok
15:42:16.0930 3192        CompositeBus    (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
15:42:16.0945 3192        CompositeBus - ok
15:42:16.0976 3192        crcdisk        (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
15:42:16.0976 3192        crcdisk - ok
15:42:17.0101 3192        DfsC            (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
15:42:17.0101 3192        DfsC - ok
15:42:17.0148 3192        discache        (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
15:42:17.0148 3192        discache - ok
15:42:17.0210 3192        Disk            (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
15:42:17.0226 3192        Disk - ok
15:42:17.0304 3192        DKbFltr        (c701324c9e0c25dd9d60311bd87fbc84) C:\Windows\system32\DRIVERS\DKbFltr.sys
15:42:17.0304 3192        DKbFltr - ok
15:42:17.0382 3192        drmkaud        (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
15:42:17.0382 3192        drmkaud - ok
15:42:17.0444 3192        DXGKrnl        (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
15:42:17.0476 3192        DXGKrnl - ok
15:42:17.0647 3192        ebdrv          (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
15:42:17.0756 3192        ebdrv - ok
15:42:17.0819 3192        elxstor        (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
15:42:17.0834 3192        elxstor - ok
15:42:17.0897 3192        ErrDev          (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
15:42:17.0912 3192        ErrDev - ok
15:42:17.0975 3192        exfat          (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
15:42:17.0990 3192        exfat - ok
15:42:18.0022 3192        fastfat        (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
15:42:18.0068 3192        fastfat - ok
15:42:18.0178 3192        fdc            (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
15:42:18.0178 3192        fdc - ok
15:42:18.0224 3192        FileInfo        (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
15:42:18.0224 3192        FileInfo - ok
15:42:18.0256 3192        Filetrace      (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
15:42:18.0256 3192        Filetrace - ok
15:42:18.0302 3192        flpydisk        (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
15:42:18.0302 3192        flpydisk - ok
15:42:18.0349 3192        FltMgr          (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
15:42:18.0365 3192        FltMgr - ok
15:42:18.0412 3192        FsDepends      (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
15:42:18.0412 3192        FsDepends - ok
15:42:18.0427 3192        Fs_Rec          (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
15:42:18.0427 3192        Fs_Rec - ok
15:42:18.0505 3192        fvevol          (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
15:42:18.0505 3192        fvevol - ok
15:42:18.0568 3192        gagp30kx        (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
15:42:18.0568 3192        gagp30kx - ok
15:42:18.0630 3192        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
15:42:18.0630 3192        GEARAspiWDM - ok
15:42:18.0708 3192        hcw85cir        (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
15:42:18.0708 3192        hcw85cir - ok
15:42:18.0786 3192        HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
15:42:18.0802 3192        HdAudAddService - ok
15:42:18.0848 3192        HDAudBus        (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
15:42:18.0848 3192        HDAudBus - ok
15:42:18.0895 3192        HidBatt        (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
15:42:18.0895 3192        HidBatt - ok
15:42:18.0926 3192        HidBth          (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
15:42:18.0926 3192        HidBth - ok
15:42:18.0958 3192        HidIr          (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
15:42:18.0958 3192        HidIr - ok
15:42:19.0004 3192        HidUsb          (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\drivers\hidusb.sys
15:42:19.0004 3192        HidUsb - ok
15:42:19.0082 3192        HpSAMD          (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
15:42:19.0082 3192        HpSAMD - ok
15:42:19.0160 3192        HTTP            (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
15:42:19.0192 3192        HTTP - ok
15:42:19.0207 3192        hwpolicy        (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
15:42:19.0207 3192        hwpolicy - ok
15:42:19.0285 3192        i8042prt        (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
15:42:19.0285 3192        i8042prt - ok
15:42:19.0363 3192        iaStor          (d483687eace0c065ee772481a96e05f5) C:\Windows\system32\DRIVERS\iaStor.sys
15:42:19.0379 3192        iaStor - ok
15:42:19.0441 3192        iaStorV        (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
15:42:19.0457 3192        iaStorV - ok
15:42:19.0675 3192        igfx            (9467514ea189475a6e7fdc5d7bde9d3f) C:\Windows\system32\DRIVERS\igdkmd32.sys
15:42:19.0831 3192        igfx - ok
15:42:19.0894 3192        iirsp          (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
15:42:19.0894 3192        iirsp - ok
15:42:20.0050 3192        IntcAzAudAddService (f2baa4ff548f7f0317f7638951c1cd9c) C:\Windows\system32\drivers\RTKVHDA.sys
15:42:20.0159 3192        IntcAzAudAddService - ok
15:42:20.0206 3192        intelide        (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
15:42:20.0206 3192        intelide - ok
15:42:20.0252 3192        intelppm        (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
15:42:20.0252 3192        intelppm - ok
15:42:20.0299 3192        IpFilterDriver  (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
15:42:20.0299 3192        IpFilterDriver - ok
15:42:20.0377 3192        IPMIDRV        (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
15:42:20.0377 3192        IPMIDRV - ok
15:42:20.0408 3192        IPNAT          (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
15:42:20.0408 3192        IPNAT - ok
15:42:20.0471 3192        IRENUM          (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
15:42:20.0471 3192        IRENUM - ok
15:42:20.0518 3192        isapnp          (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
15:42:20.0518 3192        isapnp - ok
15:42:20.0580 3192        iScsiPrt        (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
15:42:20.0580 3192        iScsiPrt - ok
15:42:20.0627 3192        kbdclass        (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
15:42:20.0627 3192        kbdclass - ok
15:42:20.0689 3192        kbdhid          (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
15:42:20.0689 3192        kbdhid - ok
15:42:20.0752 3192        KSecDD          (f4647bb23db9038a7536cf6b68f4207f) C:\Windows\system32\Drivers\ksecdd.sys
15:42:20.0752 3192        KSecDD - ok
15:42:20.0783 3192        KSecPkg        (e73cae53bbb72ba26918492c6b4c229d) C:\Windows\system32\Drivers\ksecpkg.sys
15:42:20.0783 3192        KSecPkg - ok
15:42:20.0845 3192        L1C            (a158cea8644b8a5c1ec0e9a81b70f65a) C:\Windows\system32\DRIVERS\L1C62x86.sys
15:42:20.0845 3192        L1C - ok
15:42:20.0923 3192        lltdio          (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
15:42:20.0939 3192        lltdio - ok
15:42:21.0017 3192        LSI_FC          (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
15:42:21.0017 3192        LSI_FC - ok
15:42:21.0064 3192        LSI_SAS        (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
15:42:21.0064 3192        LSI_SAS - ok
15:42:21.0079 3192        LSI_SAS2        (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
15:42:21.0079 3192        LSI_SAS2 - ok
15:42:21.0110 3192        LSI_SCSI        (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
15:42:21.0110 3192        LSI_SCSI - ok
15:42:21.0157 3192        luafv          (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
15:42:21.0157 3192        luafv - ok
15:42:21.0220 3192        MBAMProtector  (b7ca8cc3f978201856b6ab82f40953c3) C:\Windows\system32\drivers\mbam.sys
15:42:21.0220 3192        MBAMProtector - ok
15:42:21.0282 3192        megasas        (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
15:42:21.0282 3192        megasas - ok
15:42:21.0329 3192        MegaSR          (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
15:42:21.0329 3192        MegaSR - ok
15:42:21.0376 3192        Modem          (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
15:42:21.0376 3192        Modem - ok
15:42:21.0407 3192        monitor        (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
15:42:21.0407 3192        monitor - ok
15:42:21.0469 3192        mouclass        (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys
15:42:21.0469 3192        mouclass - ok
15:42:21.0500 3192        mouhid          (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
15:42:21.0500 3192        mouhid - ok
15:42:21.0563 3192        mountmgr        (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
15:42:21.0563 3192        mountmgr - ok
15:42:21.0610 3192        mpio            (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
15:42:21.0610 3192        mpio - ok
15:42:21.0641 3192        mpsdrv          (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
15:42:21.0641 3192        mpsdrv - ok
15:42:21.0719 3192        MRxDAV          (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
15:42:21.0719 3192        MRxDAV - ok
15:42:21.0766 3192        mrxsmb          (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
15:42:21.0781 3192        mrxsmb - ok
15:42:21.0828 3192        mrxsmb10        (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
15:42:21.0844 3192        mrxsmb10 - ok
15:42:21.0890 3192        mrxsmb20        (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
15:42:21.0890 3192        mrxsmb20 - ok
15:42:21.0937 3192        msahci          (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
15:42:21.0937 3192        msahci - ok
15:42:21.0984 3192        msdsm          (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
15:42:21.0984 3192        msdsm - ok
15:42:22.0062 3192        Msfs            (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
15:42:22.0078 3192        Msfs - ok
15:42:22.0093 3192        mshidkmdf      (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
15:42:22.0093 3192        mshidkmdf - ok
15:42:22.0156 3192        msisadrv        (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
15:42:22.0156 3192        msisadrv - ok
15:42:22.0218 3192        MSKSSRV        (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
15:42:22.0218 3192        MSKSSRV - ok
15:42:22.0234 3192        MSPCLOCK        (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
15:42:22.0249 3192        MSPCLOCK - ok
15:42:22.0265 3192        MSPQM          (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
15:42:22.0265 3192        MSPQM - ok
15:42:22.0312 3192        MsRPC          (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
15:42:22.0312 3192        MsRPC - ok
15:42:22.0343 3192        mssmbios        (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
15:42:22.0343 3192        mssmbios - ok
15:42:22.0374 3192        MSTEE          (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
15:42:22.0374 3192        MSTEE - ok
15:42:22.0421 3192        MTConfig        (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
15:42:22.0421 3192        MTConfig - ok
15:42:22.0452 3192        Mup            (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
15:42:22.0452 3192        Mup - ok
15:42:22.0499 3192        mwlPSDFilter    (cb47c414e083ca6e50e634b148f28f64) C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
15:42:22.0514 3192        mwlPSDFilter - ok
15:42:22.0546 3192        mwlPSDNServ    (647b953019559bff07536f5c6121f333) C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
15:42:22.0546 3192        mwlPSDNServ - ok
15:42:22.0577 3192        mwlPSDVDisk    (5a236a36db8687d1e64dc81c03eaabe1) C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
15:42:22.0577 3192        mwlPSDVDisk - ok
15:42:22.0686 3192        NativeWifiP    (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
15:42:22.0686 3192        NativeWifiP - ok
15:42:22.0780 3192        NDIS            (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
15:42:22.0811 3192        NDIS - ok
15:42:22.0873 3192        NdisCap        (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
15:42:22.0873 3192        NdisCap - ok
15:42:22.0920 3192        NdisTapi        (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
15:42:22.0920 3192        NdisTapi - ok
15:42:22.0998 3192        Ndisuio        (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
15:42:22.0998 3192        Ndisuio - ok
15:42:23.0045 3192        NdisWan        (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
15:42:23.0045 3192        NdisWan - ok
15:42:23.0107 3192        NDProxy        (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
15:42:23.0107 3192        NDProxy - ok
15:42:23.0154 3192        NetBIOS        (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
15:42:23.0154 3192        NetBIOS - ok
15:42:23.0216 3192        NetBT          (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
15:42:23.0232 3192        NetBT - ok
15:42:23.0294 3192        nfrd960        (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
15:42:23.0294 3192        nfrd960 - ok
15:42:23.0341 3192        Npfs            (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
15:42:23.0341 3192        Npfs - ok
15:42:23.0372 3192        nsiproxy        (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
15:42:23.0388 3192        nsiproxy - ok
15:42:23.0466 3192        Ntfs            (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
15:42:23.0497 3192        Ntfs - ok
15:42:23.0528 3192        Null            (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
15:42:23.0528 3192        Null - ok
15:42:23.0591 3192        nvraid          (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
15:42:23.0591 3192        nvraid - ok
15:42:23.0638 3192        nvstor          (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
15:42:23.0638 3192        nvstor - ok
15:42:23.0700 3192        nv_agp          (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
15:42:23.0700 3192        nv_agp - ok
15:42:23.0747 3192        ohci1394        (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
15:42:23.0762 3192        ohci1394 - ok
15:42:23.0840 3192        Parport        (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
15:42:23.0840 3192        Parport - ok
15:42:23.0903 3192        partmgr        (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
15:42:23.0903 3192        partmgr - ok
15:42:23.0934 3192        Parvdm          (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
15:42:23.0934 3192        Parvdm - ok
15:42:24.0012 3192        pci            (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
15:42:24.0012 3192        pci - ok
15:42:24.0043 3192        pciide          (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
15:42:24.0059 3192        pciide - ok
15:42:24.0090 3192        pcmcia          (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
15:42:24.0090 3192        pcmcia - ok
15:42:24.0137 3192        pcw            (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
15:42:24.0137 3192        pcw - ok
15:42:24.0184 3192        PEAUTH          (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
15:42:24.0199 3192        PEAUTH - ok
15:42:24.0324 3192        PptpMiniport    (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
15:42:24.0324 3192        PptpMiniport - ok
15:42:24.0371 3192        Processor      (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
15:42:24.0371 3192        Processor - ok
15:42:24.0433 3192        Psched          (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
15:42:24.0433 3192        Psched - ok
15:42:24.0511 3192        ql2300          (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
15:42:24.0589 3192        ql2300 - ok
15:42:24.0636 3192        ql40xx          (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
15:42:24.0636 3192        ql40xx - ok
15:42:24.0683 3192        QWAVEdrv        (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
15:42:24.0683 3192        QWAVEdrv - ok
15:42:24.0714 3192        RasAcd          (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
15:42:24.0714 3192        RasAcd - ok
15:42:24.0776 3192        RasAgileVpn    (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
15:42:24.0776 3192        RasAgileVpn - ok
15:42:24.0808 3192        Rasl2tp        (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
15:42:24.0823 3192        Rasl2tp - ok
15:42:24.0854 3192        RasPppoe        (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
15:42:24.0854 3192        RasPppoe - ok
15:42:24.0901 3192        RasSstp        (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
15:42:24.0901 3192        RasSstp - ok
15:42:24.0964 3192        rdbss          (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
15:42:24.0964 3192        rdbss - ok
15:42:25.0010 3192        rdpbus          (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
15:42:25.0010 3192        rdpbus - ok
15:42:25.0057 3192        RDPCDD          (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
15:42:25.0057 3192        RDPCDD - ok
15:42:25.0104 3192        RDPENCDD        (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
15:42:25.0104 3192        RDPENCDD - ok
15:42:25.0151 3192        RDPREFMP        (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
15:42:25.0151 3192        RDPREFMP - ok
15:42:25.0198 3192        RDPWD          (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
15:42:25.0198 3192        RDPWD - ok
15:42:25.0276 3192        rdyboost        (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
15:42:25.0276 3192        rdyboost - ok
15:42:25.0354 3192        rspndr          (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
15:42:25.0354 3192        rspndr - ok
15:42:25.0416 3192        RSUSBSTOR      (96f8dd546677aa5102150acc140377b3) C:\Windows\system32\Drivers\RtsUStor.sys
15:42:25.0432 3192        RSUSBSTOR - ok
15:42:25.0478 3192        RtsUIR - ok
15:42:25.0572 3192        sbp2port        (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
15:42:25.0572 3192        sbp2port - ok
15:42:25.0634 3192        scfilter        (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
15:42:25.0634 3192        scfilter - ok
15:42:25.0712 3192        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
15:42:25.0712 3192        secdrv - ok
15:42:25.0775 3192        Serenum        (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
15:42:25.0775 3192        Serenum - ok
15:42:25.0822 3192        Serial          (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
15:42:25.0822 3192        Serial - ok
15:42:25.0884 3192        sermouse        (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
15:42:25.0884 3192        sermouse - ok
15:42:25.0978 3192        sffdisk        (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
15:42:25.0978 3192        sffdisk - ok
15:42:26.0009 3192        sffp_mmc        (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
15:42:26.0009 3192        sffp_mmc - ok
15:42:26.0056 3192        sffp_sd        (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
15:42:26.0056 3192        sffp_sd - ok
15:42:26.0087 3192        sfloppy        (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
15:42:26.0087 3192        sfloppy - ok
15:42:26.0180 3192        sisagp          (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
15:42:26.0180 3192        sisagp - ok
15:42:26.0227 3192        SiSRaid2        (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
15:42:26.0227 3192        SiSRaid2 - ok
15:42:26.0258 3192        SiSRaid4        (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
15:42:26.0258 3192        SiSRaid4 - ok
15:42:26.0321 3192        Smb            (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
15:42:26.0321 3192        Smb - ok
15:42:26.0368 3192        spldr          (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
15:42:26.0383 3192        spldr - ok
15:42:26.0461 3192        srv            (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
15:42:26.0461 3192        srv - ok
15:42:26.0508 3192        srv2            (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
15:42:26.0524 3192        srv2 - ok
15:42:26.0555 3192        srvnet          (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
15:42:26.0555 3192        srvnet - ok
15:42:26.0602 3192        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
15:42:26.0602 3192        ssmdrv - ok
15:42:26.0664 3192        stexstor        (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
15:42:26.0664 3192        stexstor - ok
15:42:26.0726 3192        swenum          (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
15:42:26.0726 3192        swenum - ok
15:42:26.0820 3192        SynTP          (47183e3520c88fadd5b0c87d57040da5) C:\Windows\system32\DRIVERS\SynTP.sys
15:42:26.0820 3192        SynTP - ok
15:42:26.0945 3192        Tcpip          (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys
15:42:26.0992 3192        Tcpip - ok
15:42:27.0070 3192        TCPIP6          (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys
15:42:27.0085 3192        TCPIP6 - ok
15:42:27.0163 3192        tcpipreg        (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
15:42:27.0163 3192        tcpipreg - ok
15:42:27.0226 3192        TDPIPE          (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
15:42:27.0226 3192        TDPIPE - ok
15:42:27.0241 3192        TDTCP          (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
15:42:27.0257 3192        TDTCP - ok
15:42:27.0319 3192        tdx            (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
15:42:27.0319 3192        tdx - ok
15:42:27.0382 3192        TermDD          (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
15:42:27.0382 3192        TermDD - ok
15:42:27.0475 3192        tssecsrv        (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
15:42:27.0491 3192        tssecsrv - ok
15:42:27.0553 3192        TsUsbFlt        (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
15:42:27.0553 3192        TsUsbFlt - ok
15:42:27.0631 3192        tunnel          (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
15:42:27.0647 3192        tunnel - ok
15:42:27.0678 3192        uagp35          (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
15:42:27.0678 3192        uagp35 - ok
15:42:27.0740 3192        udfs            (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
15:42:27.0740 3192        udfs - ok
15:42:27.0818 3192        uliagpkx        (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
15:42:27.0818 3192        uliagpkx - ok
15:42:27.0896 3192        umbus          (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
15:42:27.0896 3192        umbus - ok
15:42:27.0928 3192        UmPass          (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
15:42:27.0928 3192        UmPass - ok
15:42:28.0006 3192        USBAAPL        (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys
15:42:28.0006 3192        USBAAPL - ok
15:42:28.0084 3192        usbaudio        (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys
15:42:28.0084 3192        usbaudio - ok
15:42:28.0146 3192        usbccgp        (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys
15:42:28.0146 3192        usbccgp - ok
15:42:28.0193 3192        USBCCID - ok
15:42:28.0255 3192        usbcir          (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
15:42:28.0255 3192        usbcir - ok
15:42:28.0286 3192        usbehci        (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys
15:42:28.0302 3192        usbehci - ok
15:42:28.0364 3192        usbhub          (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
15:42:28.0364 3192        usbhub - ok
15:42:28.0442 3192        usbohci        (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\drivers\usbohci.sys
15:42:28.0442 3192        usbohci - ok
15:42:28.0489 3192        usbprint        (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
15:42:28.0489 3192        usbprint - ok
15:42:28.0536 3192        USBSTOR        (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
15:42:28.0536 3192        USBSTOR - ok
15:42:28.0567 3192        usbuhci        (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\DRIVERS\usbuhci.sys
15:42:28.0567 3192        usbuhci - ok
15:42:28.0614 3192        usbvideo        (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\system32\Drivers\usbvideo.sys
15:42:28.0630 3192        usbvideo - ok
15:42:28.0708 3192        vdrvroot        (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
15:42:28.0708 3192        vdrvroot - ok
15:42:28.0770 3192        vga            (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
15:42:28.0770 3192        vga - ok
15:42:28.0801 3192        VgaSave        (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
15:42:28.0801 3192        VgaSave - ok
15:42:28.0848 3192        vhdmp          (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
15:42:28.0848 3192        vhdmp - ok
15:42:28.0879 3192        viaagp          (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
15:42:28.0879 3192        viaagp - ok
15:42:28.0926 3192        ViaC7          (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
15:42:28.0926 3192        ViaC7 - ok
15:42:28.0957 3192        viaide          (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
15:42:28.0957 3192        viaide - ok
15:42:29.0004 3192        volmgr          (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
15:42:29.0020 3192        volmgr - ok
15:42:29.0051 3192        volmgrx        (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
15:42:29.0066 3192        volmgrx - ok
15:42:29.0113 3192        volsnap        (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
15:42:29.0129 3192        volsnap - ok
15:42:29.0176 3192        vsmraid        (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
15:42:29.0176 3192        vsmraid - ok
15:42:29.0222 3192        vwifibus        (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys
15:42:29.0238 3192        vwifibus - ok
15:42:29.0285 3192        vwififlt        (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys
15:42:29.0285 3192        vwififlt - ok
15:42:29.0332 3192        WacomPen        (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
15:42:29.0332 3192        WacomPen - ok
15:42:29.0378 3192        WANARP          (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
15:42:29.0378 3192        WANARP - ok
15:42:29.0394 3192        Wanarpv6        (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
15:42:29.0394 3192        Wanarpv6 - ok
15:42:29.0456 3192        Wd              (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
15:42:29.0456 3192        Wd - ok
15:42:29.0503 3192        Wdf01000        (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
15:42:29.0519 3192        Wdf01000 - ok
15:42:29.0612 3192        WfpLwf          (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
15:42:29.0628 3192        WfpLwf - ok
15:42:29.0659 3192        WIMMount        (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
15:42:29.0659 3192        WIMMount - ok
15:42:29.0815 3192        WinUsb          (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
15:42:29.0815 3192        WinUsb - ok
15:42:29.0924 3192        WmiAcpi        (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
15:42:29.0924 3192        WmiAcpi - ok
15:42:30.0018 3192        ws2ifsl        (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
15:42:30.0018 3192        ws2ifsl - ok
15:42:30.0127 3192        WudfPf          (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
15:42:30.0127 3192        WudfPf - ok
15:42:30.0190 3192        WUDFRd          (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
15:42:30.0190 3192        WUDFRd - ok
15:42:30.0268 3192        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
15:42:30.0330 3192        \Device\Harddisk0\DR0 - ok
15:42:30.0346 3192        Boot (0x1200)  (6005e54591185526d6606abffed89502) \Device\Harddisk0\DR0\Partition0
15:42:30.0361 3192        \Device\Harddisk0\DR0\Partition0 - ok
15:42:30.0377 3192        Boot (0x1200)  (267810886754289918c0711d7e9c623b) \Device\Harddisk0\DR0\Partition1
15:42:30.0377 3192        \Device\Harddisk0\DR0\Partition1 - ok
15:42:30.0377 3192        ============================================================
15:42:30.0377 3192        Scan finished
15:42:30.0377 3192        ============================================================
15:42:30.0408 1524        Detected object count: 0
15:42:30.0408 1524        Actual detected object count: 0
15:43:20.0205 1556        Deinitialize success


Psychotic 04.03.2012 16:12

CF-Script


Hinweis für Mitleser:
Folgendes ComboFix Skript ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

Lösche die vorhandene Combofix.exe von deinem Desktop und lade das Programm von einem der folgenden Download-Spiegel neu herunter:
BleepingComputer.com - ForoSpyware.com
und speichere es erneut auf dem Desktop (nicht woanders hin, das ist wichtig)!

Drücke die Windows + R Taste --> Notepad (hinein schreiben) --> OK

Kopiere nun den Text aus der folgenden Codebox komplett in das leere Textdokument.
Code:

DirLook::
C:\qoobox\quarantine

Speichere dies als CFScript.txt auf Deinem Desktop.

Wichtig:
  • Stelle deine Anti Viren Software temprär ab. Dies kann ComboFix nämlich bei der Arbeit behindern.
    Danach wieder anstellen nicht vergessen!
  • Bewege nicht die Maus über das ComboFix-Fenster oder klicke in dieses hinein.
    Dies kann dazu führen, dass ComboFix sich aufhängt.
  • Schließe alle laufenden Programme. Gehe sicher das ComboFix ungehindert arbeiten kann.
  • Mache nichts am PC solange ComboFix läuft.
http://i266.photobucket.com/albums/i.../CFScriptB.gif
  • In Bezug auf obiges Bild, ziehe CFScript.txt in die ComboFix.exe
  • Wenn ComboFix fertig ist, wird es ein Log erstellen, C:\ComboFix.txt. Bitte füge es hier als Antwort ein.
Falls im Skript die Anweisung Suspect:: oder Collect:: enthalten ist, wird eine Message-Box erscheinen, nachdem Combofix fertig ist. Klicke OK und folge den Aufforderungen/Anweisungen, um die Dateien hochzuladen.

snowly1 04.03.2012 18:54

Combofix Logfile:
Code:

ComboFix 12-03-04.01 - Acer 04.03.2012  18:27:10.4.2 - x86
Microsoft Windows 7 Starter  6.1.7601.1.1252.41.1031.18.1014.373 [GMT 1:00]
ausgeführt von:: c:\users\Acer\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Acer\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-02-04 bis 2012-03-04  ))))))))))))))))))))))))))))))
.
.
2012-03-04 17:42 . 2012-03-04 17:42        --------        d-----w-        c:\users\Public\AppData\Local\temp
2012-03-04 17:42 . 2012-03-04 17:42        --------        d-----w-        c:\users\Gast\AppData\Local\temp
2012-03-04 17:42 . 2012-03-04 17:42        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-03-04 07:33 . 2012-03-04 07:35        --------        d-----w-        C:\FRST
2012-02-28 09:32 . 2012-02-28 09:32        --------        d-----w-        c:\windows\system32\wbem\en-US
2012-02-28 00:22 . 2012-03-04 17:42        --------        d-----w-        c:\users\Acer\AppData\Local\temp
2012-02-18 12:38 . 2012-02-18 12:38        --------        d-----w-        c:\windows\Sun
2012-02-18 12:02 . 2011-12-30 05:27        478720        ----a-w-        c:\windows\system32\timedate.cpl
2012-02-18 12:01 . 2011-12-16 07:52        690688        ----a-w-        c:\windows\system32\msvcrt.dll
2012-02-18 12:01 . 2012-01-04 08:58        442880        ----a-w-        c:\windows\system32\ntshrui.dll
2012-02-18 12:00 . 2012-01-14 03:35        2343424        ----a-w-        c:\windows\system32\win32k.sys
2012-02-07 19:30 . 2009-08-11 20:18        497664        ----a-w-        c:\windows\system32\ac3filter.acm
2012-02-07 19:30 . 2012-02-07 19:30        --------        d-----w-        c:\program files\AC3Filter
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-06 19:12 . 2011-09-08 18:45        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-24 16:35 . 2012-01-24 16:35        212992        ----a-w-        c:\windows\system32\aptw2s8pj.dll
2012-01-10 14:39 . 2011-08-27 14:12        98304        ----a-w-        c:\windows\system32\CmdLineExt.dll
2011-12-10 14:24 . 2011-12-30 10:46        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-12-07 15:39 . 2011-12-07 15:39        472808        ----a-w-        c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((((((((((  Look  )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\qoobox\quarantine ----
.
2012-02-28 22:21 . 2012-03-04 17:27        0        ----a-w-        c:\qoobox\quarantine\catchme.txt
2012-02-28 00:19 . 2012-02-28 00:19        92        ----a-w-        c:\qoobox\quarantine\Registry_backups\Toolbar-Locked.reg.dat
2012-02-28 00:12 . 2012-03-04 17:37        10680        ----a-w-        c:\qoobox\quarantine\Registry_backups\tcpip.reg
2012-01-06 19:20 . 2012-01-06 19:20        2052        ----a-w-        c:\qoobox\quarantine\Registry_backups\AddRemove-{889DF117-14D1-44EE-9F31-C5FB5D47F68B}.reg.dat
2012-01-06 19:18 . 2012-02-28 00:19        118        ----a-w-        c:\qoobox\quarantine\Registry_backups\URLSearchHooks-{37483b40-c254-4a72-bda4-22ee90182c1e}.reg.dat
2012-01-06 19:00 . 2012-03-04 17:27        410        ----a-w-        c:\qoobox\quarantine\catchme.log
2011-09-25 15:17 . 2011-09-25 15:17        97614        ----a-w-        c:\qoobox\quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat.vir
2011-09-25 15:17 . 2011-07-22 23:53        471040        ----a-w-        c:\qoobox\quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir
2011-09-25 15:17 . 2009-11-19 06:12        4846        ----a-w-        c:\qoobox\quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico.vir
2011-09-25 15:17 . 2011-07-22 23:55        847872        ----a-w-        c:\qoobox\quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll.vir
2011-09-25 15:17 . 2011-03-11 03:29        227984        ----a-w-        c:\qoobox\quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe.vir
2009-09-16 18:58 . 2009-09-16 18:58        22        ----a-w-        c:\qoobox\quarantine\C\Windows\System32\1.cmd.vir
2009-08-14 08:46 . 2009-02-10 19:23        192484        ----a-w-        c:\qoobox\quarantine\C\Program Files\Common Files\Acer GameZone online.ico.vir
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
2011-05-09 08:49        176936        ----a-w-        c:\program files\Freeware.de\prxtbFree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53        787744        ----a-w-        c:\program files\Yontoo Layers Runtime\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7E111A5C-3D11-4F56-9463-5310C3C69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-08-06 17:18        120104        ----a-w-        c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeCT"="c:\program files\FreeCountdownTimer\FreeCountdownTimer.exe" [2011-05-24 2033488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-06-02 1130504]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-08-06 707104]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-08-04 199464]
"mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-08-06 349480]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"NortonOnlineBackupReminder"="c:\program files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-18 1537320]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-29 281768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2009-8-14 708608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FILSHtray]
2012-01-10 12:08        596992        ----a-w-        c:\program files\FILSHtray\FILSHtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-08-18 23:07        421736        ----a-w-        c:\program files\iTunes\iTunesHelper.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-24 167424]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 18992]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 16432]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60976]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-05-01 136360]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2009-08-06 727584]
S2 Greg_Service;GRegService;c:\program files\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
S2 Update-Service;Update-Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
Update-Service-Installer-Service        REG_MULTI_SZ          Update-Service-Installer-Service
Update-Service        REG_MULTI_SZ          Update-Service
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2736476
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_one&r=07b511093115l03e4ww85w47323005
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(984)
c:\program files\EgisTec\MyWinLocker 3\x86\psdprotect.dll
c:\program files\EgisTec\MyWinLocker 3\x86\sysenv.dll
c:\program files\Acer\Acer ePower Management\SysHook.dll
.
Zeit der Fertigstellung: 2012-03-04  18:47:20
ComboFix-quarantined-files.txt  2012-03-04 17:47
ComboFix2.txt  2012-03-01 15:31
ComboFix3.txt  2012-02-28 22:43
ComboFix4.txt  2012-02-28 00:22
ComboFix5.txt  2012-03-04 17:22
.
Vor Suchlauf: 18 Verzeichnis(se), 70'772'531'200 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 71'257'128'960 Bytes frei
.
- - End Of File - - 09627C2F0ECCD9AD2F6C52299EEC7E29

--- --- ---

Psychotic 05.03.2012 07:13

Suche mit FRST


Schließe den USB Stick, der FRST enthält, an das infizierte System an Du musst das System nun in die System Reparatur Option booten. Über den Boot Manager
  • Starte den Rechner neu auf.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu auf und starte von der CD
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !!
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument --> Datei --> Speichern unter und wähle Computer Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein. e:\frst.exe Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Yes und klicke Search file(s).
  • Es öfnet sich ein Fenster, in dem bereits search: steht.
    Füge hier folgendes hinzu:
    Code:

    6340a.dll

Klicke auf search - das Tool erstellt eine search.txt auf deinem Stick. Poste den Inhalt bitte hier.

snowly1 05.03.2012 18:20

Hier ist search.txt.
Code:

Farbar Recovery Scan Tool Version: 01-03-2012
Ran by SYSTEM at 2012-03-05 18:10:14
Running from F:\

================== Search: "6340a.dll" ===================

=== End Of Search ===


Psychotic 05.03.2012 18:27

Sehr seltsam! :wtf:

Erstelle mir bitte nochmal ein Gmer-Log, ich muss da noch Erkundigungen einholen.

Die Datei wird NUR von Gmer gefunden und kann demzufolge auch nicht gekillt werden.

Bitte hab etwas Geduld! :)


GMER


Bitte
  • alle anderen Scanner gegen Viren, Spyware, usw. deaktivieren,
  • keine bestehende Verbindung zu einem Netzwerk/Internet (WLAN nicht vergessen),
  • nichts am Rechner arbeiten,
  • nach jedem Scan der Rechner neu gestarten.
Gmer scannen lassen
  • Lade Dir Gmer von dieser Seite herunter (auf den Button Download EXE drücken) und das Programm auf dem Desktop speichern.
  • Alle anderen Programme sollen geschlossen sein.
  • Starte gmer.exe (Programm hat einen willkürlichen Programm-Namen). Vista und Win7 User mit Rechtsklick und als Administrator starten.
  • Sollte sich ein Fenster mit folgender Warnung öffnen:
    WARNING !!! GMER has found system modification, which might have been caused by ROOTKIT activity. Do you want to fully scan your system ?
    Unbedingt auf "No" klicken.
  • Entferne rechts den Haken bei:
    • IAT/EAT
    • Alle Festplatten ausser die Systemplatte (normalerweise ist nur C:\ angehackt)
    • Show all (sollte abgehackt sein)
  • Starte den Scan mit "Scan". Mache nichts am Computer während der Scan läuft.
  • Wenn der Scan fertig ist klicke auf Save und speichere die Logfile unter Gmer.txt auf deinem Desktop. Mit "Ok" wird GMER beendet.
Antiviren-Programm und sonstige Scanner wieder einschalten, bevor Du ins Netz gehst!

snowly1 05.03.2012 19:19

Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-03-05 19:15:27
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD16 rev.11.0
Running: 8kn8rjxd.exe; Driver: C:\Users\Acer\AppData\Local\Temp\kwldrpob.sys


---- System - GMER 1.0.15 ----

SSDT            806B2076                                                                                ZwCreateSection
SSDT            806B207B                                                                                ZwSetContextThread
SSDT            806B2017                                                                                ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text          ntoskrnl.exe!ZwSaveKey + 13CD                                                            8204F9A9 1 Byte  [06]
.text          ntoskrnl.exe!KiDispatchInterrupt + 5A2                                                  8206F4E2 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text          ntoskrnl.exe!KeRemoveQueueEx + 14BF                                                      8207687C 4 Bytes  [76, 20, 6B, 80]
.text          ntoskrnl.exe!KeRemoveQueueEx + 185F                                                      82076C1C 4 Bytes  [7B, 20, 6B, 80]
.text          ntoskrnl.exe!KeRemoveQueueEx + 1937                                                      82076CF4 4 Bytes  [17, 20, 6B, 80] {POP SS; AND [EBX-0x80], CH}

---- User code sections - GMER 1.0.15 ----

.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtClose                                  770C54C8 5 Bytes  JMP 01101B91
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtCreateSection                          770C56E8 5 Bytes  JMP 011008F8
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtMapViewOfSection                        770C5C28 5 Bytes  JMP 01100BD4
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtOpenFile                                770C5CD8 5 Bytes  JMP 011018B4
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtOpenSection                            770C5DC8 5 Bytes  JMP 01100683
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtQueryAttributesFile                    770C5F38 5 Bytes  JMP 011015E1
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtQuerySection                            770C6188 5 Bytes  JMP 0110116D
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtQueryVirtualMemory                      770C6258 5 Bytes  JMP 01101D66
.text          C:\Windows\system32\svchost.exe[984] ntdll.dll!NtUnmapViewOfSection                      770C69B8 5 Bytes  JMP 01100F2E

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                  Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                  Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device          \Driver\ACPI_HAL \Device\0000004a                                                        halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
---- Processes - GMER 1.0.15 ----

Library        C:\Windows\system32\6340a.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [984]  0x03CD0000                                                                                                                                         

---- EOF - GMER 1.0.15 ----

Und nun? Danke für die Hilfe.

Psychotic 05.03.2012 22:54

Nun bitte ich dich, ein paar Stunden Geduld mitzubringen. ;)

snowly1 06.03.2012 01:09

Ok. Ich hoffe, es gibt eine Lösung. Danke erstmal.

Psychotic 06.03.2012 11:14

RKU


Downloade Dir bitte RKUnhookerLE
und speichere die Datei auf deinem Desktop.
  • Trenne dich vom Internet ( Wlan nicht vergessen ), deaktiviere alle Hintergrundwächter, besonders den deiner Anti-Viren Software.
  • Schließe alle offenen Programme.
  • Starte die RKUnhookerLE.exe
    Windows Vista und Windows 7 mit Rechtsklick "Als Administrator ausführen"
  • Klicke rechts auf Report und anschließend auf den Scan Button.
  • Setze ein Häkchen vor
    • Drivers
    • Stealth Code
    • Files
    • Code Hooks
  • Entferne alle anderen Haken.
  • Bestätige mit Ok.
  • Wenn Du gefragt wirst, welcher Bereich gescannt werden soll, gehe sicher das dein Systemlaufwerk ( meistens C: ) angehakt ist. Deaktiviere alle anderen Laufwerke. Bestätige wieder mit Ok.
  • Das Tool scannt nun deinen Rechner. Hab Geduld.
  • Wenn der Scan beendet ist, klicke auf File -> Save Report
  • Speichere die Datei als RKU.txt auf deinem Desktop.
  • Klicke auf Close und bestätige mit Ja.
  • Poste das Logfile mit deiner nächsten Antwort.
Hinweis: Solltest Du folgende Warnung bekommen
Zitat:

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
Klicke auf OK

snowly1 06.03.2012 16:44

Die Datei ist zu lang. ich versuche, sie als Anhang in 3 Teile zu senden. Hoffe, es klappt. Musste 4 Teile machen.

Psychotic 07.03.2012 07:14

Hallo snowly1,

nach Rücksprache mit den Experten machen wir jetzt mal folgendes!


CF-Script


Hinweis für Mitleser:
Folgendes ComboFix Skript ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

Lösche die vorhandene Combofix.exe von deinem Desktop und lade das Programm von einem der folgenden Download-Spiegel neu herunter:
BleepingComputer.com - ForoSpyware.com
und speichere es erneut auf dem Desktop (nicht woanders hin, das ist wichtig)!

Drücke die Windows + R Taste --> Notepad (hinein schreiben) --> OK

Kopiere nun den Text aus der folgenden Codebox komplett in das leere Textdokument.
Code:

c:\windows\system32\aptw2s8pj.dll
Speichere dies als CFScript.txt auf Deinem Desktop.

Wichtig:
  • Stelle deine Anti Viren Software temprär ab. Dies kann ComboFix nämlich bei der Arbeit behindern.
    Danach wieder anstellen nicht vergessen!
  • Bewege nicht die Maus über das ComboFix-Fenster oder klicke in dieses hinein.
    Dies kann dazu führen, dass ComboFix sich aufhängt.
  • Schließe alle laufenden Programme. Gehe sicher das ComboFix ungehindert arbeiten kann.
  • Mache nichts am PC solange ComboFix läuft.
http://i266.photobucket.com/albums/i.../CFScriptB.gif
  • In Bezug auf obiges Bild, ziehe CFScript.txt in die ComboFix.exe
  • Wenn ComboFix fertig ist, wird es ein Log erstellen, C:\ComboFix.txt. Bitte füge es hier als Antwort ein.
Falls im Skript die Anweisung Suspect:: oder Collect:: enthalten ist, wird eine Message-Box erscheinen, nachdem Combofix fertig ist. Klicke OK und folge den Aufforderungen/Anweisungen, um die Dateien hochzuladen.

snowly1 07.03.2012 14:16

Hier das CF:
Ich konnte danach nicht mehr ins Internet, irgendeine Fehlermeldung von einer gelöschten Datei. Nachdem ich PC neu gestartet habe, gings wieder.
Code:

Combofix Logfile:

       
Code:

       
ComboFix 12-03-06.01 - Acer 07.03.2012  13:43:54.5.2 - x86
Microsoft Windows 7 Starter   6.1.7601.1.1252.41.1031.18.1014.481 [GMT 1:00]
ausgeführt von:: c:\users\Acer\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Acer\Desktop\cfscript.txt
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-02-07 bis 2012-03-07  ))))))))))))))))))))))))))))))
.
.
2012-03-07 12:57 . 2012-03-07 12:57        --------        d-----w-        c:\users\Public\AppData\Local\temp
2012-03-07 12:57 . 2012-03-07 12:57        --------        d-----w-        c:\users\Gast\AppData\Local\temp
2012-03-07 12:57 . 2012-03-07 12:57        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-03-04 07:33 . 2012-03-04 07:35        --------        d-----w-        C:\FRST
2012-02-28 09:32 . 2012-02-28 09:32        --------        d-----w-        c:\windows\system32\wbem\en-US
2012-02-28 00:22 . 2012-03-07 12:57        --------        d-----w-        c:\users\Acer\AppData\Local\temp
2012-02-18 12:38 . 2012-02-18 12:38        --------        d-----w-        c:\windows\Sun
2012-02-18 12:02 . 2011-12-30 05:27        478720        ----a-w-        c:\windows\system32\timedate.cpl
2012-02-18 12:01 . 2011-12-16 07:52        690688        ----a-w-        c:\windows\system32\msvcrt.dll
2012-02-18 12:01 . 2012-01-04 08:58        442880        ----a-w-        c:\windows\system32\ntshrui.dll
2012-02-18 12:00 . 2012-01-14 03:35        2343424        ----a-w-        c:\windows\system32\win32k.sys
2012-02-07 19:30 . 2009-08-11 20:18        497664        ----a-w-        c:\windows\system32\ac3filter.acm
2012-02-07 19:30 . 2012-02-07 19:30        --------        d-----w-        c:\program files\AC3Filter
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-06 19:12 . 2011-09-08 18:45        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-24 16:35 . 2012-01-24 16:35        212992        ----a-w-        c:\windows\system32\aptw2s8pj.dll
2012-01-10 14:39 . 2011-08-27 14:12        98304        ----a-w-        c:\windows\system32\CmdLineExt.dll
2011-12-10 14:24 . 2011-12-30 10:46        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
2011-05-09 08:49        176936        ----a-w-        c:\program files\Freeware.de\prxtbFree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7E111A5C-3D11-4F56-9463-5310C3C69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-08-06 17:18        120104        ----a-w-        c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeCT"="c:\program files\FreeCountdownTimer\FreeCountdownTimer.exe" [2011-05-24 2033488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-06-02 1130504]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-08-06 707104]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-08-04 199464]
"mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-08-06 349480]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"NortonOnlineBackupReminder"="c:\program files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-18 1537320]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-29 281768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2009-8-14 708608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ           kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FILSHtray]
2012-01-10 12:08        596992        ----a-w-        c:\program files\FILSHtray\FILSHtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-08-18 23:07        421736        ----a-w-        c:\program files\iTunes\iTunesHelper.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-24 167424]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 18992]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 16432]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60976]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-05-01 136360]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2009-08-06 727584]
S2 Greg_Service;GRegService;c:\program files\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
S2 Update-Service;Update-Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - BLACKBOX
*Deregistered* - BlackBox
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ           SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
Update-Service-Installer-Service        REG_MULTI_SZ           Update-Service-Installer-Service
Update-Service        REG_MULTI_SZ           Update-Service
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2736476
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_one&r=07b511093115l03e4ww85w47323005
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(4244)
c:\program files\EgisTec\MyWinLocker 3\x86\psdprotect.dll
c:\program files\EgisTec\MyWinLocker 3\x86\sysenv.dll
c:\program files\Acer\Acer ePower Management\SysHook.dll
.
Zeit der Fertigstellung: 2012-03-07  14:02:51
ComboFix-quarantined-files.txt  2012-03-07 13:02
ComboFix2.txt  2012-03-04 17:47
ComboFix3.txt  2012-03-01 15:31
ComboFix4.txt  2012-02-28 22:43
ComboFix5.txt  2012-03-07 12:41
.
Vor Suchlauf: 18 Verzeichnis(se), 70'796'939'264 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 70'611'955'712 Bytes frei
.
- - End Of File - - 1C68EF63E1E6DEAA7CAB64419AEB320E


--- --- ---


Psychotic 07.03.2012 14:19

OK, noch was:


Schritt 1:CF-Script


Hinweis für Mitleser:
Folgendes ComboFix Skript ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

Lösche die vorhandene Combofix.exe von deinem Desktop und lade das Programm von einem der folgenden Download-Spiegel neu herunter:
BleepingComputer.com - ForoSpyware.com
und speichere es erneut auf dem Desktop (nicht woanders hin, das ist wichtig)!

Drücke die Windows + R Taste --> Notepad (hinein schreiben) --> OK

Kopiere nun den Text aus der folgenden Codebox komplett in das leere Textdokument.
Code:

FILE::
c:\windows\system32\aptw2s8pj.dll

Speichere dies als CFScript.txt auf Deinem Desktop.

Wichtig:
  • Stelle deine Anti Viren Software temprär ab. Dies kann ComboFix nämlich bei der Arbeit behindern.
    Danach wieder anstellen nicht vergessen!
  • Bewege nicht die Maus über das ComboFix-Fenster oder klicke in dieses hinein.
    Dies kann dazu führen, dass ComboFix sich aufhängt.
  • Schließe alle laufenden Programme. Gehe sicher das ComboFix ungehindert arbeiten kann.
  • Mache nichts am PC solange ComboFix läuft.
http://i266.photobucket.com/albums/i.../CFScriptB.gif
  • In Bezug auf obiges Bild, ziehe CFScript.txt in die ComboFix.exe
  • Wenn ComboFix fertig ist, wird es ein Log erstellen, C:\ComboFix.txt. Bitte füge es hier als Antwort ein.
Falls im Skript die Anweisung Suspect:: oder Collect:: enthalten ist, wird eine Message-Box erscheinen, nachdem Combofix fertig ist. Klicke OK und folge den Aufforderungen/Anweisungen, um die Dateien hochzuladen.


Schritt 2: Prüfung über Virustotal.com


Bitte lasse die Datei aus der Code-Box bei Virustotal überprüfen.
  • Klicke auf Durchsuchen
  • Kopiere nun folgendes in die Suchleiste.
    Code:

    C:\Users\Acer\Desktop\MBR.dat
  • und klicke auf Öffnen.
  • Klicke auf Send File.
Warte bitte bis die Datei vollständig hochgeladen wurde. Solltest Du folgende Meldung bekommen.
Zitat:

File already submitted: The file sent has already been analysed by VirusTotal in the past. This is same basic info regarding the sample itself and its last analysis:
klicke auf Reanalyse. Warte bis unter Current status: Finished steht. Kopiere den Link aus deiner Adresszeile und poste ihn hier.

snowly1 07.03.2012 15:36

[CODE][/Combofix Logfile:
Code:

ComboFix 12-03-07.02 - Acer 07.03.2012  15:05:37.6.2 - x86
Microsoft Windows 7 Starter  6.1.7601.1.1252.41.1031.18.1014.381 [GMT 1:00]
ausgeführt von:: c:\users\Acer\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Acer\Desktop\cfscript.txt
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\aptw2s8pj.dll"
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-02-07 bis 2012-03-07  ))))))))))))))))))))))))))))))
.
.
2012-03-07 14:20 . 2012-03-07 14:20        --------        d-----w-        c:\users\Acer\AppData\Local\temp
2012-03-07 14:20 . 2012-03-07 14:20        --------        d-----w-        c:\users\Public\AppData\Local\temp
2012-03-07 14:20 . 2012-03-07 14:20        --------        d-----w-        c:\users\Gast\AppData\Local\temp
2012-03-07 14:20 . 2012-03-07 14:20        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-03-04 07:33 . 2012-03-04 07:35        --------        d-----w-        C:\FRST
2012-02-28 09:32 . 2012-02-28 09:32        --------        d-----w-        c:\windows\system32\wbem\en-US
2012-02-18 12:38 . 2012-02-18 12:38        --------        d-----w-        c:\windows\Sun
2012-02-18 12:02 . 2011-12-30 05:27        478720        ----a-w-        c:\windows\system32\timedate.cpl
2012-02-18 12:01 . 2011-12-16 07:52        690688        ----a-w-        c:\windows\system32\msvcrt.dll
2012-02-18 12:01 . 2012-01-04 08:58        442880        ----a-w-        c:\windows\system32\ntshrui.dll
2012-02-18 12:00 . 2012-01-14 03:35        2343424        ----a-w-        c:\windows\system32\win32k.sys
2012-02-07 19:30 . 2009-08-11 20:18        497664        ----a-w-        c:\windows\system32\ac3filter.acm
2012-02-07 19:30 . 2012-02-07 19:30        --------        d-----w-        c:\program files\AC3Filter
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-06 19:12 . 2011-09-08 18:45        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-24 16:35 . 2012-01-24 16:35        212992        ----a-w-        c:\windows\system32\aptw2s8pj.dll
2012-01-10 14:39 . 2011-08-27 14:12        98304        ----a-w-        c:\windows\system32\CmdLineExt.dll
2011-12-10 14:24 . 2011-12-30 10:46        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
2011-05-09 08:49        176936        ----a-w-        c:\program files\Freeware.de\prxtbFree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7E111A5C-3D11-4F56-9463-5310C3C69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-08-06 17:18        120104        ----a-w-        c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeCT"="c:\program files\FreeCountdownTimer\FreeCountdownTimer.exe" [2011-05-24 2033488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-06-02 1130504]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-08-06 707104]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-08-04 199464]
"mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-08-06 349480]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"NortonOnlineBackupReminder"="c:\program files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-18 1537320]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-29 281768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FILSHtray]
2012-01-10 12:08        596992        ----a-w-        c:\program files\FILSHtray\FILSHtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-08-18 23:07        421736        ----a-w-        c:\program files\iTunes\iTunesHelper.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-24 167424]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 18992]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 16432]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60976]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-05-01 136360]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2009-08-06 727584]
S2 Greg_Service;GRegService;c:\program files\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
S2 Update-Service;Update-Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
Update-Service-Installer-Service        REG_MULTI_SZ          Update-Service-Installer-Service
Update-Service        REG_MULTI_SZ          Update-Service
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2736476
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_one&r=07b511093115l03e4ww85w47323005
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-03-07  15:25:21
ComboFix-quarantined-files.txt  2012-03-07 14:25
ComboFix2.txt  2012-03-07 13:02
ComboFix3.txt  2012-03-04 17:47
ComboFix4.txt  2012-03-01 15:31
ComboFix5.txt  2012-03-07 14:02
.
Vor Suchlauf: 18 Verzeichnis(se), 70'809'776'128 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 70'757'662'720 Bytes frei
.
- - End Of File - - 8FC4FBAEBE8286F0CF0DBE1DD2B91DD8

--- --- ---
CODE]


Code:

https://www.virustotal.com/file/036acff85d0b7d364c7fcfcbf9ce7b215885fa78fddbb95205ecd0ca85c690a0/analysis/1331130777/
Sagt Ihnen das was?

Psychotic 07.03.2012 15:40

Das sagt mir sogar sehr viel! ;)

ESET-Onlinescan



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


snowly1 07.03.2012 19:17

Code:

C:\Qoobox\Quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir        a variant of Win32/Adware.Yontoo.B application
C:\Users\Acer\AppData\Local\Babylon\Setup\Setup.exe        Win32/Toolbar.Babylon application
C:\Users\Acer\Documents\minianwendung countdown.exe        a variant of Win32/SoftonicDownloader.A application
C:\Users\Acer\Documents\minianwendung sprache ü..exe        a variant of Win32/SoftonicDownloader.A application

und nun? Wie entfernen? Die hatte ich im Jan. schon mal.

Psychotic 07.03.2012 22:31

Hm...dem Ding ist so nicht beizukommen.

Mach mal folgendes:

CF-Script

Hinweis für Mitleser:
Folgendes ComboFix Skript ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

Lösche die vorhandene Combofix.exe von deinem Desktop und lade das Programm von einem der folgenden Download-Spiegel neu herunter:
BleepingComputer.com - ForoSpyware.com
und speichere es erneut auf dem Desktop (nicht woanders hin, das ist wichtig)!

Lade dir die von mir an diese Antwort angehängte CFScript.txt herunter und speichere sie auf deinem Desktop.

Wichtig:
  • Stelle deine Anti Viren Software temprär ab. Dies kann ComboFix nämlich bei der Arbeit behindern.
    Danach wieder anstellen nicht vergessen!
  • Bewege nicht die Maus über das ComboFix-Fenster oder klicke in dieses hinein.
    Dies kann dazu führen, dass ComboFix sich aufhängt.
  • Schließe alle laufenden Programme. Gehe sicher das ComboFix ungehindert arbeiten kann.
  • Mache nichts am PC solange ComboFix läuft.
http://i266.photobucket.com/albums/i.../CFScriptB.gif
  • In Bezug auf obiges Bild, ziehe CFScript.txt in die ComboFix.exe
  • Wenn ComboFix fertig ist, wird es ein Log erstellen, C:\ComboFix.txt. Bitte füge es hier als Antwort ein.
Falls im Skript die Anweisung Suspect:: oder Collect:: enthalten ist, wird eine Message-Box erscheinen, nachdem Combofix fertig ist. Klicke OK und folge den Aufforderungen/Anweisungen, um die Dateien hochzuladen.

Psychotic 07.03.2012 23:39

Zitat:

Zitat von PsYcHoTiC (Beitrag 788112)
Lade dir die von mir an diese Antwort angehängte CFScript.txt herunter und speichere sie auf deinem Desktop.

Vergessen anzuhängen - hier, bitte! :pfeiff:

snowly1 08.03.2012 14:29

Code:

ComboFix 12-03-08.01 - Acer 08.03.2012  13:58:48.7.2 - x86
Microsoft Windows 7 Starter  6.1.7601.1.1252.41.1031.18.1014.367 [GMT 1:00]
ausgeführt von:: c:\users\Acer\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Acer\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
file zipped: c:\windows\system32\aptw2s8pj.dll
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-02-08 bis 2012-03-08  ))))))))))))))))))))))))))))))
.
.
2012-03-08 13:13 . 2012-03-08 13:13        --------        d-----w-        c:\users\Public\AppData\Local\temp
2012-03-08 13:13 . 2012-03-08 13:13        --------        d-----w-        c:\users\Gast\AppData\Local\temp
2012-03-08 13:13 . 2012-03-08 13:13        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-03-07 14:25 . 2012-03-08 13:16        --------        d-----w-        c:\users\Acer\AppData\Local\temp
2012-03-04 07:33 . 2012-03-04 07:35        --------        d-----w-        C:\FRST
2012-02-28 09:32 . 2012-02-28 09:32        --------        d-----w-        c:\windows\system32\wbem\en-US
2012-02-18 12:38 . 2012-02-18 12:38        --------        d-----w-        c:\windows\Sun
2012-02-18 12:02 . 2011-12-30 05:27        478720        ----a-w-        c:\windows\system32\timedate.cpl
2012-02-18 12:01 . 2011-12-16 07:52        690688        ----a-w-        c:\windows\system32\msvcrt.dll
2012-02-18 12:01 . 2012-01-04 08:58        442880        ----a-w-        c:\windows\system32\ntshrui.dll
2012-02-18 12:00 . 2012-01-14 03:35        2343424        ----a-w-        c:\windows\system32\win32k.sys
2012-02-07 19:30 . 2009-08-11 20:18        497664        ----a-w-        c:\windows\system32\ac3filter.acm
2012-02-07 19:30 . 2012-02-07 19:30        --------        d-----w-        c:\program files\AC3Filter
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-06 19:12 . 2011-09-08 18:45        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-10 14:39 . 2011-08-27 14:12        98304        ----a-w-        c:\windows\system32\CmdLineExt.dll
2011-12-10 14:24 . 2011-12-30 10:46        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
2011-05-09 08:49        176936        ----a-w-        c:\program files\Freeware.de\prxtbFree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7e111a5c-3d11-4f56-9463-5310c3c69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7E111A5C-3D11-4F56-9463-5310C3C69025}"= "c:\program files\Freeware.de\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7e111a5c-3d11-4f56-9463-5310c3c69025}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-08-06 17:18        120104        ----a-w-        c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeCT"="c:\program files\FreeCountdownTimer\FreeCountdownTimer.exe" [2011-05-24 2033488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-06-02 1130504]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-08-06 707104]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-08-04 199464]
"mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-08-06 349480]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"NortonOnlineBackupReminder"="c:\program files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-18 1537320]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-29 281768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2009-8-14 708608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FILSHtray]
2012-01-10 12:08        596992        ----a-w-        c:\program files\FILSHtray\FILSHtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-08-18 23:07        421736        ----a-w-        c:\program files\iTunes\iTunesHelper.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CFcatchme;CFcatchme;c:\users\Acer\AppData\Local\Temp\CFcatchme.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-24 167424]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 18992]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 16432]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60976]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-05-01 136360]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2009-08-06 727584]
S2 Greg_Service;GRegService;c:\program files\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
S2 Update-Service;Update-Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
Update-Service-Installer-Service        REG_MULTI_SZ          Update-Service-Installer-Service
Update-Service        REG_MULTI_SZ          Update-Service
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2736476
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_one&r=07b511093115l03e4ww85w47323005
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(936)
c:\program files\EgisTec\MyWinLocker 3\x86\psdprotect.dll
c:\program files\EgisTec\MyWinLocker 3\x86\sysenv.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\taskhost.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conhost.exe
c:\program files\EgisTec\MyWinLocker 3\x86\MWLService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conhost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-03-08  14:22:56 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-03-08 13:22
ComboFix2.txt  2012-03-07 14:25
ComboFix3.txt  2012-03-07 13:02
ComboFix4.txt  2012-03-04 17:47
ComboFix5.txt  2012-03-08 12:55
.
Vor Suchlauf: 18 Verzeichnis(se), 69'960'032'256 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 69'902'893'056 Bytes frei
.
- - End Of File - - C79853E6D5E17AFD540BC14AB2C98070
Hochladen war erfolgreich


Psychotic 08.03.2012 14:44

Zitat:

C:\Users\Acer\AppData\Local\Babylon\Setup\Setup.exe Win32/Toolbar.Babylon application
C:\Users\Acer\Documents\minianwendung countdown.exe a variant of Win32/SoftonicDownloader.A application
C:\Users\Acer\Documents\minianwendung sprache ü..exe a variant of Win32/SoftonicDownloader.A application
Diese Dateien sind nicht direkt schädlich, installieren aber unnötigen und potentiell die Sicherheit gefährdenden Ballast auf deinem Rechner.

Ich empfehle dir, sie ungeöffnet zu löschen.


Macht der Rechner noch Probleme?

snowly1 08.03.2012 14:54

Nein, bis jetzt gibt es keine Probleme mehr. Kann ich die neue Avira-Free-Antivirus 2012 Software nun herunterladen? Ich habe eine Meldung bekommen, dass Antivir veraltet ist. Muss ich dann Antivir deinstallieren? Ich danke vielmals für die Hilfe. Sind wir nun durch?

snowly1 08.03.2012 14:56

Noch eine Frage: Es hat unter den Angaben im angegebenen Pfad ein Ordner Babylon. Kann ich den ganz löschen?

Psychotic 08.03.2012 14:58

Ich möchte dich bitten, noch etwas zu warten. Ich halte gerade nocheinmal Rücksprache mit den Experten, ob wir noch einen Scan durchführen müssen. ;)

Danach gibt es von mir Anweisungen, wie du die benutzten Tools sauber von deinem Rechner entfernst.
Außerdem bekommst du Tipps, wie du so etwas in Zukunft vermeiden kannst.

Das beinhaltet auch die Wahl des Antivirenprogramms! ;-) Hier würde ich dir nämlich zu einer Alternative raten, da Antivir in der freien Version eine Komponente installiert, die wir hier im Forum von den Rechnern der User entfernen.

Siehe hier: http://forum.chip.de/personal-firewa...r-1530736.html

Den Ordner Babylon kannst du ohne Bedenken komplett löschen!

snowly1 08.03.2012 15:08

Ich habe die Dateien gelöscht. Was ist mit dem obersten, Tarma Installer? Muss ich den auch löschen?

Psychotic 08.03.2012 15:10

Zitat:

Zitat von snowly1 (Beitrag 788489)
Ich habe die Dateien gelöscht. Was ist mit dem obersten, Tarma Installer? Muss ich den auch löschen?

Nein - wenn du auf den Anfang des Pfades schaust, kannst du sehen, dass diese Datei sich in Quarantäne befindet. Sie wird nachher beim entfernen der Tools mit gelöscht werden! :)

snowly1 08.03.2012 15:14

ok. Danke. Dann bin ich mal gespannt auf Deine Antwort.

snowly1 08.03.2012 15:25

Oh, nun hat der Guard folgendes gefunden:
Code:

In der Datei 'C:\Windows\System32\aptw2s8pj.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Trash.Gen' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

War das beabsichtigt? Diese Meldung ist vom 08.03.2012, 14.17 Uhr.

Psychotic 09.03.2012 08:35

OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

/md5start
d1.tmp.dll
aptw2s8pj.*
/md5stop

  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread

snowly1 09.03.2012 14:19

Hier ist OTL:
Code:

OTL logfile created on: 3/9/2012 2:04:21 PM - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Acer\Desktop
 Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Schweiz | Language: DES | Date Format: dd.MM.yyyy
 
1013.95 Mb Total Physical Memory | 513.23 Mb Available Physical Memory | 50.62% Memory free
2.07 Gb Paging File | 1.17 Gb Available in Paging File | 56.77% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 135.05 Gb Total Space | 63.76 Gb Free Space | 47.21% Space Free | Partition Type: NTFS
 
Computer Name: ACER-PC | User Name: Acer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/01/05 23:00:03 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Acer\Desktop\OTL.exe
PRC - [2011/07/24 15:41:42 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/06/24 05:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011/05/01 07:07:35 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011/03/29 17:45:31 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011/03/28 19:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011/03/28 19:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/11/20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010/11/20 13:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/01/15 06:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009/08/06 18:18:54 | 000,311,592 | ---- | M] (Egis Technology Inc.) -- C:\Programme\EgisTec\MyWinLocker 3\x86\MWLService.exe
PRC - [2009/08/06 18:18:42 | 000,349,480 | ---- | M] (Egis Technology Inc.) -- C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
PRC - [2009/08/06 05:31:06 | 000,727,584 | ---- | M] (Acer Incorporated) -- C:\Programme\Acer\Acer ePower Management\ePowerSvc.exe
PRC - [2009/08/06 05:31:06 | 000,707,104 | ---- | M] (Acer Incorporated) -- C:\Programme\Acer\Acer ePower Management\ePowerTray.exe
PRC - [2009/08/06 05:31:02 | 000,440,864 | ---- | M] (Acer Incorporated) -- C:\Programme\Acer\Acer ePower Management\ePowerEvent.exe
PRC - [2009/08/04 06:09:34 | 000,199,464 | ---- | M] (Egis Technology Inc.) -- C:\Programme\EgisTec Egis Software Update\EgisUpdate.exe
PRC - [2009/07/10 10:54:44 | 000,253,952 | ---- | M] (Acer Incorporated) -- C:\Programme\Acer\Acer VCM\RS_Service.exe
PRC - [2009/07/04 02:47:12 | 000,240,160 | ---- | M] (Acer) -- C:\Programme\Acer\Acer Updater\UpdaterService.exe
PRC - [2009/06/05 03:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/06/05 03:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009/06/04 14:04:50 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Programme\Acer\Registration\GregHSRW.exe
PRC - [2009/06/02 08:58:02 | 001,130,504 | ---- | M] (Dritek System Inc.) -- C:\Programme\Launch Manager\LManager.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2003/06/07 06:30:08 | 000,057,344 | ---- | M] () -- C:\Programme\Launch Manager\PowerUtl.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/11/11 18:59:11 | 000,114,000 | ---- | M] (Joosoft.com GmbH) [Auto | Running] -- C:\Windows\System32\UpdSvc.dll -- (Update-Service)
SRV - [2011/07/24 15:41:42 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/05/01 07:07:35 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2009/08/06 18:18:54 | 000,311,592 | ---- | M] () [Auto | Running] -- C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe -- (MWLService)
SRV - [2009/08/06 05:31:06 | 000,727,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Programme\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV - [2009/07/14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/07/10 10:54:44 | 000,253,952 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Programme\Acer\Acer VCM\RS_Service.exe -- (RS_Service)
SRV - [2009/07/04 02:47:12 | 000,240,160 | ---- | M] (Acer) [Auto | Running] -- C:\Programme\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV - [2009/06/05 03:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2009/06/04 14:04:50 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Programme\Acer\Registration\GregHSRW.exe -- (Greg_Service)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/07/24 15:41:45 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/07/24 15:41:45 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010/11/20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/27 08:06:44 | 000,051,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20)
DRV - [2009/07/16 12:31:38 | 001,176,064 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/07/14 00:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\serial.sys -- (Serial)
DRV - [2009/06/24 03:59:10 | 000,167,424 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009/06/02 12:15:40 | 000,060,976 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV - [2009/06/02 12:15:38 | 000,016,432 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV - [2009/06/02 12:15:34 | 000,018,992 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\System32\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV - [2009/05/11 18:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_one&r=07b511093115l03e4ww85w47323005
IE - HKLM\..\URLSearchHook: {7e111a5c-3d11-4f56-9463-5310c3c69025} - C:\Programme\Freeware.de\prxtbFree.dll (Conduit Ltd.)
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2736476
IE - HKCU\..\URLSearchHook: {7e111a5c-3d11-4f56-9463-5310c3c69025} - C:\Programme\Freeware.de\prxtbFree.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
 
 
 
O1 HOSTS File: ([2012/03/08 14:15:39 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (no name) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No CLSID value found.
O2 - BHO: (Freeware.de Toolbar) - {7e111a5c-3d11-4f56-9463-5310c3c69025} - C:\Programme\Freeware.de\prxtbFree.dll (Conduit Ltd.)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Freeware.de Toolbar) - {7e111a5c-3d11-4f56-9463-5310c3c69025} - C:\Programme\Freeware.de\prxtbFree.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Freeware.de Toolbar) - {7E111A5C-3D11-4F56-9463-5310C3C69025} - C:\Programme\Freeware.de\prxtbFree.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Acer ePower Management] C:\Programme\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [EgisTecLiveUpdate] C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mwlDaemon] C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKCU..\Run: [FreeCT] C:\Program Files\FreeCountdownTimer\FreeCountdownTimer.exe (Comfort Software Group)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil11e_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Windows\System32\d3dy2i0ki.dll ()
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{19C2AB69-811A-4D9F-9E47-0C2D40CD0D5F}: DhcpNameServer = 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E1D1366E-035D-4E53-81A1-B77285C9AC87}: DhcpNameServer = 10.60.100.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Acer\Acer VCM\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/03/08 14:24:31 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/03/08 14:15:46 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/03/08 13:49:39 | 004,431,034 | R--- | C] (Swearware) -- C:\Users\Acer\Desktop\ComboFix.exe
[2012/03/07 16:48:17 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Acer\Desktop\esetsmartinstaller_enu.exe
[2012/03/07 15:25:24 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\temp
[2012/03/04 15:07:43 | 002,062,896 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Acer\Desktop\tdsskiller.exe
[2012/03/04 15:05:27 | 004,730,880 | ---- | C] (AVAST Software) -- C:\Users\Acer\Desktop\aswMBR.exe
[2012/03/04 08:33:18 | 000,000,000 | ---D | C] -- C:\FRST
[2012/03/02 21:42:10 | 000,000,000 | ---D | C] -- C:\Avenger
[2012/02/28 00:59:13 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/02/28 00:59:13 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/02/28 00:59:13 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/02/27 18:06:03 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012/02/18 13:38:43 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2012/02/11 17:58:20 | 000,000,000 | R--D | C] -- C:\Users\Acer\Desktop\let's play's svenweisven
[2012/02/11 16:10:45 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\{E09BE6F8-59E7-489F-B41E-CCB4F4175006}
[2012/02/11 16:10:28 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\{11BC444D-7AF9-43B6-B0AF-BF4BC8FF9787}
[2009/08/14 09:46:50 | 000,036,136 | ---- | C] (Oberon Media) -- C:\ProgramData\FullRemove.exe
 
========== Files - Modified Within 30 Days ==========
 
[2012/03/09 13:55:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/03/08 15:17:45 | 000,009,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/08 15:17:45 | 000,009,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/08 15:09:57 | 797,396,992 | -HS- | M] () -- C:\hiberfil.sys
[2012/03/08 14:15:39 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/03/08 13:58:41 | 000,212,992 | ---- | M] () -- C:\Windows\System32\aptw2s8pj.dll
[2012/03/08 13:49:45 | 004,431,034 | R--- | M] (Swearware) -- C:\Users\Acer\Desktop\ComboFix.exe
[2012/03/07 16:48:32 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Acer\Desktop\esetsmartinstaller_enu.exe
[2012/03/07 15:31:58 | 000,451,963 | ---- | M] () -- C:\Users\Acer\Desktop\Trojanisches Pferd TR-Crypt.zpack.gen2 gefunden. Kein Internet! - Seite 4 - Trojaner-Board.webarchive
[2012/03/06 13:59:54 | 000,139,264 | ---- | M] () -- C:\Users\Acer\Desktop\RKUnhookerLE.EXE
[2012/03/05 18:30:52 | 000,302,592 | ---- | M] () -- C:\Users\Acer\Desktop\8kn8rjxd.exe
[2012/03/04 15:40:49 | 000,000,512 | ---- | M] () -- C:\Users\Acer\Desktop\MBR.dat
[2012/03/04 15:07:56 | 002,062,896 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Acer\Desktop\tdsskiller.exe
[2012/03/04 15:05:59 | 004,730,880 | ---- | M] (AVAST Software) -- C:\Users\Acer\Desktop\aswMBR.exe
[2012/03/03 23:41:52 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012/03/03 23:41:52 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/03/03 23:41:52 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012/03/03 23:41:52 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/03/02 21:37:12 | 000,731,136 | ---- | M] () -- C:\Users\Acer\Desktop\avenger.exe
[2012/02/29 00:07:33 | 000,302,592 | ---- | M] () -- C:\Users\Acer\Desktop\r8z3xleh.exe
[2012/02/28 01:57:50 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2012/02/27 18:05:59 | 326,712,483 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/02/27 00:50:54 | 000,000,000 | ---- | M] () -- C:\Users\Acer\defogger_reenable
[2012/02/21 20:08:42 | 000,000,426 | ---- | M] () -- C:\Users\Acer\Desktop\settings.xml
[2012/02/19 03:37:27 | 000,302,320 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/02/18 23:19:44 | 000,155,762 | ---- | M] () -- C:\Users\Acer\Desktop\MCSkinEdit.jar
[2012/02/18 20:17:22 | 000,000,417 | ---- | M] () -- C:\Windows\System32\settings.xml
[2012/02/18 13:01:46 | 000,000,681 | ---- | M] () -- C:\Users\Acer\Desktop\Minecraft.exe - Verknüpfung.lnk
 
========== Files Created - No Company Name ==========
 
[2012/03/07 15:31:58 | 000,451,963 | ---- | C] () -- C:\Users\Acer\Desktop\Trojanisches Pferd TR-Crypt.zpack.gen2 gefunden. Kein Internet! - Seite 4 - Trojaner-Board.webarchive
[2012/03/06 13:59:50 | 000,139,264 | ---- | C] () -- C:\Users\Acer\Desktop\RKUnhookerLE.EXE
[2012/03/05 18:30:50 | 000,302,592 | ---- | C] () -- C:\Users\Acer\Desktop\8kn8rjxd.exe
[2012/03/04 15:40:49 | 000,000,512 | ---- | C] () -- C:\Users\Acer\Desktop\MBR.dat
[2012/03/02 21:36:59 | 000,731,136 | ---- | C] () -- C:\Users\Acer\Desktop\avenger.exe
[2012/02/29 00:07:31 | 000,302,592 | ---- | C] () -- C:\Users\Acer\Desktop\r8z3xleh.exe
[2012/02/28 01:57:50 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2012/02/28 00:59:13 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/02/28 00:59:13 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/02/28 00:59:13 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/02/28 00:59:13 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/02/28 00:59:13 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/02/27 18:05:59 | 326,712,483 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/02/27 00:50:54 | 000,000,000 | ---- | C] () -- C:\Users\Acer\defogger_reenable
[2012/02/18 23:20:31 | 000,000,426 | ---- | C] () -- C:\Users\Acer\Desktop\settings.xml
[2012/02/18 19:53:17 | 000,000,417 | ---- | C] () -- C:\Windows\System32\settings.xml
[2012/02/18 13:01:46 | 000,000,681 | ---- | C] () -- C:\Users\Acer\Desktop\Minecraft.exe - Verknüpfung.lnk
[2012/01/24 17:35:34 | 000,212,992 | ---- | C] () -- C:\Windows\System32\aptw2s8pj.dll
[2011/10/05 12:11:55 | 000,000,000 | ---- | C] () -- C:\Users\Acer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/24 13:28:45 | 000,405,504 | ---- | C] () -- C:\Windows\System32\d3dy2i0ki.dll
[2011/03/30 01:40:23 | 000,000,037 | ---- | C] () -- C:\Windows\Viewer.ini
[2011/03/30 00:20:08 | 000,000,447 | ---- | C] () -- C:\Windows\SIERRA.INI
[2011/02/27 06:19:40 | 000,100,216 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2009/09/16 20:13:36 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009/09/16 20:13:35 | 000,654,166 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009/09/16 20:13:35 | 000,130,006 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009/09/16 20:13:35 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009/08/14 09:44:02 | 000,123,780 | ---- | C] () -- C:\Windows\System32\drivers\RtConvEQ.DAT
[2009/08/14 09:44:02 | 000,001,496 | ---- | C] () -- C:\Windows\System32\drivers\RtkAcerM.dat
[2009/08/14 09:44:02 | 000,000,728 | ---- | C] () -- C:\Windows\System32\drivers\RtHdatEx.dat
[2009/08/14 09:44:02 | 000,000,712 | ---- | C] () -- C:\Windows\System32\drivers\SamSfPa.dat
[2009/08/14 09:44:02 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX2.dat
[2009/08/14 09:44:02 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX1.dat
[2009/08/14 09:44:02 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX0.dat
[2009/08/14 09:44:02 | 000,000,008 | ---- | C] () -- C:\Windows\System32\drivers\rtkhdaud.dat
[2009/07/14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 05:33:53 | 000,302,320 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 03:05:48 | 000,616,008 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 03:05:48 | 000,106,388 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
 
========== LOP Check ==========
 
[2012/03/04 13:46:48 | 000,000,000 | ---D | M] -- C:\Users\Acer\AppData\Roaming\.minecraft
[2011/12/21 17:05:48 | 000,000,000 | ---D | M] -- C:\Users\Acer\AppData\Roaming\Sony
[2011/11/11 18:57:30 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
 
< MD5 for: APTW2S8PJ.DLL  >
[2012/03/08 13:58:41 | 000,212,992 | ---- | M] () MD5=4DD85E80FEF52E06BB1FF950FF9CA99E -- C:\Windows\System32\aptw2s8pj.dll

< End of report >


snowly1 09.03.2012 14:21

Fast vergessen: Extra.txt [CODE][/OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 3/9/2012 2:04:21 PM - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Acer\Desktop
 Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Schweiz | Language: DES | Date Format: dd.MM.yyyy
 
1013.95 Mb Total Physical Memory | 513.23 Mb Available Physical Memory | 50.62% Memory free
2.07 Gb Paging File | 1.17 Gb Available in Paging File | 56.77% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 135.05 Gb Total Space | 63.76 Gb Free Space | 47.21% Space Free | Partition Type: NTFS
 
Computer Name: ACER-PC | User Name: Acer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM
"{0483BE07-260D-4E4D-815E-F737C0A72E40}" = Adobe Flash Player 10 ActiveX
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation(R)Store
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{167A1F6A-9BF2-4B24-83DB-C6D659F680EA}" = Media Go
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java(TM) 6 Update 29
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34EF7358-ABC7-8469-5FB6-C5C0146F099E}" = Media Go Video Playback Engine 1.84.112.07020
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{404245D0-E836-4737-9C12-D4D0034540F5}_is1" = Free Countdown Timer 2.3.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51F026FA-5146-4232-A8BA-1364740BD053}" = Acer Crystal Eye webcam
"{5928359F-BF46-4646-BF19-B64E55171EB5}_is1" = FILSHtray Version 0.7
"{5A2F371F-8B5D-46B4-833C-0612B065BEC7}" = GameShadow
"{66A405D2-BA14-4594-BF36-B3B544F0754E}" = Stronghold Legends
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68301905-2DEA-41CE-A4D4-E8B443B099BA}" = MyWinLocker
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{735619D4-B42A-437A-958C-199BFCAEDB38}" = Safari
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}" = Chicken Invaders 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110551697}" = Granny In Paradise
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}" = Merriam Websters Spell Jam
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477}" = Amazonia
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}" = Heroes of Hellas
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}" = Dream Day First Home
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114803710}" = Star Defender 4
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}" = Dairy Dash
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}" = Farm Frenzy 2
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Runtime 1.10.01
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8ed9688e-4f79-4308-91ca-f1c37ca142b4}_is1" = Acer GameZone Console
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAF89271-2594-468D-B578-96B2E30C41C4}" = eBay Worldwide
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation(R)Network Downloader
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Norton Online Backup
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"AC3Filter_is1" = AC3Filter 1.63b
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"dlanconf" = devolo dLAN-Konfigurationsassistent
"dslmon" = devolo Informer
"easyclean" = devolo EasyClean
"easyshare" = devolo EasyShare
"ESET Online Scanner" = ESET Online Scanner v3
"Freeware.de Toolbar" = Freeware.de Toolbar
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Identity Card" = Identity Card
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.1.1000
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinLiveSuite" = Windows Live Essentials
"Zulu" = Zulu DJ Software
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Wizard101(DE)_is1" = Wizard101(DE)
 
========== Last 10 Event Log Errors ==========
 
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
 
< End of report >

--- --- ---
CODE]

Psychotic 10.03.2012 12:11

FRST


Downloade dir bitte Farbar's Recovery Scan Tool und speichere diese auf einen USB Stick. Schließe den USB Stick an das infizierte System an Du musst das System nun in die System Reparatur Option booten. Über den Boot Manager
  • Starte den Rechner neu auf.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu auf und starte von der CD
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !!
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument --> Datei --> Speichern unter und wähle Computer Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein. e:\frst.exe Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Yes.
  • Entferne die Haken bei "whitelist" von Registry, Services, Drivers, und known DLL's
  • Hake an: List Drivers MD5
  • klicke Scan
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier.

snowly1 10.03.2012 14:46

Code:

Scan result of Farbar Recovery Scan Tool (FRST written by farbar) Version: 07-03-2012 01
Ran by SYSTEM at 10-03-2012 14:35:25
Running from F:\
Windows 7 Starter  (X86) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry ==========================

HKLM\...\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe [1130504 2009-06-01] (Dritek System Inc.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7600672 2009-07-06] (Realtek Semiconductor)
HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [707104 2009-08-05] (Acer Incorporated)
HKLM\...\Run: [EgisTecLiveUpdate] "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe" [199464 2009-08-03] (Egis Technology Inc.)
HKLM\...\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-08-06] (Egis Technology Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM\...\Run: [NortonOnlineBackupReminder] "C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED [588648 2009-07-24] (Symantec Corporation)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1537320 2009-06-18] (Synaptics Incorporated)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2009-09-23] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [173592 2009-09-23] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [150552 2009-09-23] (Intel Corporation)
HKLM\...\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min [281768 2011-03-29] (Avira GmbH)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [460872 2012-01-13] (Malwarebytes Corporation)
HKU\Acer\...\Run: [FreeCT] C:\Program Files\FreeCountdownTimer\FreeCountdownTimer.exe -autorun [2033488 2011-05-24] (Comfort Software Group)
HKU\Acer\...\Policies\system: [LogonHoursAction] 2
HKU\Acer\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [1174016 2010-11-20] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [1174016 2010-11-20] (Microsoft Corporation)
HKU\Gast\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe, [26624 2010-11-20] (Microsoft Corporation)
HKLM\...\Winlogon: [Shell] Explorer.exe [2616320 2011-02-24] (Microsoft Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
Lsa: [Authentication Packages] msv1_0
Lsa: [Notification Packages] scecli

========================== Services ==========================

3 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [62464 2009-07-13] (Microsoft Corporation)
3 ALG; C:\Windows\System32\alg.exe [59392 2009-07-13] (Microsoft Corporation)
2 AntiVirSchedulerService; "C:\Program Files\Avira\AntiVir Desktop\sched.exe" [136360 2011-04-30] (Avira GmbH)
2 AntiVirService; "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [269480 2011-07-24] (Avira GmbH)
3 AppIDSvc; C:\Windows\System32\appidsvc.dll [27648 2009-07-13] (Microsoft Corporation)
3 Appinfo; C:\Windows\System32\appinfo.dll [47104 2010-11-20] (Microsoft Corporation)
2 Apple Mobile Device; "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" [37664 2011-02-18] (Apple Inc.)
2 AudioEndpointBuilder; C:\Windows\System32\Audiosrv.dll [473600 2010-11-20] (Microsoft Corporation)
2 Audiosrv; C:\Windows\System32\Audiosrv.dll [473600 2010-11-20] (Microsoft Corporation)
3 AxInstSV; C:\Windows\System32\AxInstSV.dll [88064 2010-11-20] (Microsoft Corporation)
3 BDESVC; C:\Windows\System32\bdesvc.dll [76800 2009-07-13] (Microsoft Corporation)
2 BFE; C:\Windows\System32\bfe.dll [494592 2010-11-20] (Microsoft Corporation)
2 BITS; C:\Windows\System32\qmgr.dll [585728 2010-11-20] (Microsoft Corporation)
2 Bonjour Service; "C:\Program Files\Bonjour\mDNSResponder.exe" [387944 2011-07-12] (Apple Inc.)
3 Browser; C:\Windows\System32\browser.dll [102400 2010-11-20] (Microsoft Corporation)
3 bthserv; C:\Windows\System32\bthserv.dll [64512 2009-07-13] (Microsoft Corporation)
3 CertPropSvc; C:\Windows\System32\certprop.dll [67584 2010-11-20] (Microsoft Corporation)
4 clr_optimization_v2.0.50727_32; C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [66384 2009-06-10] (Microsoft Corporation)
2 clr_optimization_v4.0.30319_32; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [130384 2010-03-18] (Microsoft Corporation)
3 COMSysApp; C:\Windows\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} [7168 2009-07-13] (Microsoft Corporation)
2 CryptSvc; C:\Windows\System32\cryptsvc.dll [136192 2010-11-20] (Microsoft Corporation)
2 DcomLaunch; C:\Windows\System32\rpcss.dll [376832 2010-11-20] (Microsoft Corporation)
3 defragsvc; C:\Windows\System32\defragsvc.dll [218624 2009-07-13] (Microsoft Corporation)
2 Dhcp; C:\Windows\System32\dhcpcore.dll [254464 2010-11-20] (Microsoft Corporation)
2 Dnscache; C:\Windows\System32\dnsrslvr.dll [132608 2011-03-02] (Microsoft Corporation)
3 dot3svc; C:\Windows\System32\dot3svc.dll [214016 2010-11-20] (Microsoft Corporation)
2 DPS; C:\Windows\System32\dps.dll [144384 2010-11-20] (Microsoft Corporation)
3 EapHost; C:\Windows\System32\eapsvc.dll [98304 2009-07-13] (Microsoft Corporation)
3 EFS; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [727584 2009-08-05] (Acer Incorporated)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 EventSystem; C:\Windows\System32\es.dll [271360 2009-07-13] (Microsoft Corporation)
3 Fax; C:\Windows\System32\fxssvc.exe [523264 2010-11-20] (Microsoft Corporation)
3 fdPHost; C:\Windows\System32\fdPHost.dll [12800 2009-07-13] (Microsoft Corporation)
3 FDResPub; C:\Windows\System32\fdrespub.dll [28160 2009-07-13] (Microsoft Corporation)
2 FontCache; C:\Windows\System32\FntCache.dll [805376 2011-02-18] (Microsoft Corporation)
3 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [42856 2009-06-10] (Microsoft Corporation)
2 gpsvc; C:\Windows\System32\gpsvc.dll [593408 2010-11-20] (Microsoft Corporation)
2 Greg_Service; C:\Program Files\Acer\Registration\GregHSRW.exe [1150496 2009-06-04] (Acer Incorporated)
3 hidserv; C:\Windows\System32\hidserv.dll [49152 2009-07-13] (Microsoft Corporation)
3 hkmsvc; C:\Windows\System32\kmsvc.dll [71168 2010-11-20] (Microsoft Corporation)
3 HomeGroupListener; C:\Windows\System32\ListSvc.dll [194560 2010-11-20] (Microsoft Corporation)
3 HomeGroupProvider; C:\Windows\System32\provsvc.dll [165376 2010-11-20] (Microsoft Corporation)
2 IAANTMON; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [354840 2009-06-04] (Intel Corporation)
3 idsvc; "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" [878416 2010-11-04] (Microsoft Corporation)
2 IKEEXT; C:\Windows\System32\ikeext.dll [674304 2010-11-20] (Microsoft Corporation)
3 IPBusEnum; C:\Windows\System32\ipbusenum.dll [78848 2009-07-13] (Microsoft Corporation)
2 iphlpsvc; C:\Windows\System32\iphlpsvc.dll [499712 2010-11-20] (Microsoft Corporation)
3 iPod Service; "C:\Program Files\iPod\bin\iPodService.exe" [821096 2011-08-18] (Apple Inc.)
3 KeyIso; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 KtmRm; C:\Windows\System32\msdtckrm.dll [308736 2009-07-13] (Microsoft Corporation)
2 LanmanServer; C:\Windows\System32\srvsvc.dll [168960 2010-11-20] (Microsoft Corporation)
3 lltdsvc; C:\Windows\System32\lltdsvc.dll [189952 2009-07-13] (Microsoft Corporation)
2 lmhosts; C:\Windows\System32\lmhsvc.dll [18432 2009-07-13] (Microsoft Corporation)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [652360 2012-01-13] (Malwarebytes Corporation)
2 MMCSS; C:\Windows\System32\mmcss.dll [49664 2009-07-13] (Microsoft Corporation)
2 MpsSvc; C:\Windows\System32\mpssvc.dll [566272 2010-11-20] (Microsoft Corporation)
3 MSDTC; C:\Windows\System32\msdtc.exe [134144 2009-07-13] (Microsoft Corporation)
3 MSiSCSI; C:\Windows\System32\iscsiexe.dll [114688 2009-07-13] (Microsoft Corporation)
3 msiserver; C:\Windows\System32\msiexec.exe /V [73216 2010-11-20] (Microsoft Corporation)
2 MWLService; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [311592 2009-08-06] (Egis Technology Inc.)
3 napagent; C:\Windows\System32\qagentRT.dll [330240 2010-11-20] (Microsoft Corporation)
3 Netlogon; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 Netman; C:\Windows\System32\netman.dll [280576 2009-07-13] (Microsoft Corporation)
3 netprofm; C:\Windows\System32\netprofm.dll [360448 2009-07-13] (Microsoft Corporation)
4 NetTcpPortSharing; "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe" [128848 2010-11-04] (Microsoft Corporation)
2 NlaSvc; C:\Windows\System32\nlasvc.dll [242688 2010-11-20] (Microsoft Corporation)
2 nsi; C:\Windows\System32\nsisvc.dll [19456 2009-07-13] (Microsoft Corporation)
3 odserv; "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE" [440696 2011-07-19] (Microsoft Corporation)
3 ose; "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" [145184 2006-10-26] (Microsoft Corporation)
3 p2pimsvc; C:\Windows\System32\pnrpsvc.dll [269824 2009-07-13] (Microsoft Corporation)
3 p2psvc; C:\Windows\System32\p2psvc.dll [327680 2009-07-13] (Microsoft Corporation)
3 PcaSvc; C:\Windows\System32\pcasvc.dll [154624 2009-07-13] (Microsoft Corporation)
3 pla; C:\Windows\System32\pla.dll [1508864 2010-11-20] (Microsoft Corporation)
2 PlugPlay; C:\Windows\System32\umpnpmgr.dll [293376 2011-05-24] (Microsoft Corporation)
3 PNRPAutoReg; C:\Windows\System32\pnrpauto.dll [20480 2009-07-13] (Microsoft Corporation)
3 PNRPsvc; C:\Windows\System32\pnrpsvc.dll [269824 2009-07-13] (Microsoft Corporation)
3 PolicyAgent; C:\Windows\System32\ipsecsvc.dll [350208 2010-11-20] (Microsoft Corporation)
2 Power; C:\Windows\System32\umpo.dll [119808 2010-11-20] (Microsoft Corporation)
2 ProfSvc; C:\Windows\System32\profsvc.dll [164352 2010-11-20] (Microsoft Corporation)
3 ProtectedStorage; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 QWAVE; C:\Windows\system32\qwave.dll [210944 2009-07-13] (Microsoft Corporation)
3 RasAuto; C:\Windows\System32\rasauto.dll [90624 2009-07-13] (Microsoft Corporation)
2 RasMan; C:\Windows\System32\rasmans.dll [286208 2010-11-20] (Microsoft Corporation)
4 RemoteAccess; C:\Windows\System32\mprdim.dll [75264 2009-07-13] (Microsoft Corporation)
3 RemoteRegistry; C:\Windows\System32\regsvc.dll [112640 2009-07-13] (Microsoft Corporation)
2 RpcEptMapper; C:\Windows\System32\RpcEpMap.dll [43520 2009-07-13] (Microsoft Corporation)
3 RpcLocator; C:\Windows\System32\locator.exe [9216 2009-07-13] (Microsoft Corporation)
2 RpcSs; C:\Windows\System32\rpcss.dll [376832 2010-11-20] (Microsoft Corporation)
2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated)
2 SamSs; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 SCardSvr; C:\Windows\System32\SCardSvr.dll [132608 2009-07-13] (Microsoft Corporation)
2 Schedule; C:\Windows\System32\schedsvc.dll [750592 2010-11-20] (Microsoft Corporation)
3 SCPolicySvc; C:\Windows\System32\certprop.dll [67584 2010-11-20] (Microsoft Corporation)
3 SDRSVC; C:\Windows\System32\SDRSVC.dll [125952 2010-11-20] (Microsoft Corporation)
2 seclogon; C:\Windows\system32\seclogon.dll [21504 2009-07-13] (Microsoft Corporation)
2 SENS; C:\Windows\System32\sens.dll [49664 2009-07-13] (Microsoft Corporation)
3 SessionEnv; C:\Windows\System32\sessenv.dll [113664 2010-11-20] (Microsoft Corporation)
2 SharedAccess; C:\Windows\System32\ipnathlp.dll [300544 2009-07-13] (Microsoft Corporation)
2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [328192 2010-11-20] (Microsoft Corporation)
3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [12800 2009-07-13] (Microsoft Corporation)
2 Spooler; C:\Windows\System32\spoolsv.exe [317440 2010-11-20] (Microsoft Corporation)
2 sppsvc; C:\Windows\System32\sppsvc.exe [3179520 2010-11-20] (Microsoft Corporation)
3 sppuinotify; C:\Windows\System32\sppuinotify.dll [53760 2010-11-20] (Microsoft Corporation)
3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [162816 2009-07-13] (Microsoft Corporation)
3 SstpSvc; C:\Windows\System32\sstpsvc.dll [90112 2009-07-13] (Microsoft Corporation)
2 StiSvc; C:\Windows\System32\wiaservc.dll [463360 2010-11-20] (Microsoft Corporation)
3 swprv; C:\Windows\System32\swprv.dll [313856 2009-07-13] (Microsoft Corporation)
2 SysMain; C:\Windows\System32\sysmain.dll [1159168 2010-11-20] (Microsoft Corporation)
3 TabletInputService; C:\Windows\System32\TabSvc.dll [73216 2010-11-20] (Microsoft Corporation)
3 TapiSrv; C:\Windows\System32\tapisrv.dll [242176 2010-11-20] (Microsoft Corporation)
3 TBS; C:\Windows\System32\tbssvc.dll [55808 2009-07-13] (Microsoft Corporation)
3 TermService; C:\Windows\System32\termsrv.dll [521216 2010-11-20] (Microsoft Corporation)
2 Themes; C:\Windows\System32\themeservice.dll [37376 2009-07-13] (Microsoft Corporation)
3 THREADORDER; C:\Windows\System32\mmcss.dll [49664 2009-07-13] (Microsoft Corporation)
2 TrkWks; C:\Windows\System32\trkwks.dll [77312 2009-07-13] (Microsoft Corporation)
3 TrustedInstaller; C:\Windows\servicing\TrustedInstaller.exe [204800 2010-11-20] (Microsoft Corporation)
3 UI0Detect; C:\Windows\System32\UI0Detect.exe [35840 2009-07-13] (Microsoft Corporation)
2 Update-Service; C:\Windows\System32\UpdSvc.dll [114000 2011-11-11] (Joosoft.com GmbH)
2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [240160 2009-07-03] (Acer)
3 upnphost; C:\Windows\System32\upnphost.dll [266752 2009-07-13] (Microsoft Corporation)
2 UxSms; C:\Windows\System32\uxsms.dll [29696 2009-07-13] (Microsoft Corporation)
3 VaultSvc; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 vds; C:\Windows\System32\vds.exe [453632 2010-11-20] (Microsoft Corporation)
3 VSS; C:\Windows\System32\vssvc.exe [1025536 2010-11-20] (Microsoft Corporation)
3 W32Time; C:\Windows\System32\w32time.dll [288768 2009-07-13] (Microsoft Corporation)
3 wbengine; "C:\Windows\system32\wbengine.exe" [1203200 2010-11-20] (Microsoft Corporation)
3 WbioSrvc; C:\Windows\System32\wbiosrvc.dll [151552 2009-07-13] (Microsoft Corporation)
3 wcncsvc; C:\Windows\System32\wcncsvc.dll [276992 2010-11-20] (Microsoft Corporation)
3 WcsPlugInService; C:\Windows\System32\WcsPlugInService.dll [32768 2009-07-13] (Microsoft Corporation)
3 WdiServiceHost; C:\Windows\System32\wdi.dll [76288 2009-07-13] (Microsoft Corporation)
3 WdiSystemHost; C:\Windows\System32\wdi.dll [76288 2009-07-13] (Microsoft Corporation)
3 WebClient; C:\Windows\System32\webclnt.dll [204800 2010-11-20] (Microsoft Corporation)
3 Wecsvc; C:\Windows\System32\wecsvc.dll [147968 2009-07-13] (Microsoft Corporation)
3 wercplsupport; C:\Windows\System32\wercplsupport.dll [61440 2009-07-13] (Microsoft Corporation)
3 WerSvc; C:\Windows\System32\WerSvc.dll [65024 2009-07-13] (Microsoft Corporation)
3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Corporation)
3 WinHttpAutoProxySvc; winhttp.dll [351232 2010-11-20] (Microsoft Corporation)
2 Winmgmt; C:\Windows\System32\wbem\WMIsvc.dll [168960 2009-07-13] (Microsoft Corporation)
3 WinRM; C:\Windows\System32\WsmSvc.dll [1175040 2010-11-20] (Microsoft Corporation)
2 Wlansvc; C:\Windows\System32\wlansvc.dll [829440 2009-07-13] (Microsoft Corporation)
2 wlidsvc; "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" [1713536 2011-03-28] (Microsoft Corp.)
3 wmiApSrv; C:\Windows\System32\wbem\WmiApSrv.exe [136192 2009-07-13] (Microsoft Corporation)
3 WMPNetworkSvc; "C:\Program Files\Windows Media Player\wmpnetwk.exe" [1121792 2010-11-20] (Microsoft Corporation)
3 WPCSvc; C:\Windows\System32\wpcsvc.dll [10752 2009-07-13] (Microsoft Corporation)
3 WPDBusEnum; C:\Windows\System32\wpdbusenum.dll [85504 2010-11-20] (Microsoft Corporation)
2 wscsvc; C:\Windows\System32\wscsvc.dll [73728 2009-07-13] (Microsoft Corporation)
2 WSearch; C:\Windows\System32\SearchIndexer.exe /Embedding [427520 2011-05-03] (Microsoft Corporation)
2 wuauserv; C:\Windows\System32\wuaueng.dll [1914368 2010-11-20] (Microsoft Corporation)
2 wudfsvc; C:\Windows\System32\WUDFSvc.dll [67584 2010-11-20] (Microsoft Corporation)
3 WwanSvc; C:\Windows\System32\wwansvc.dll [185856 2009-07-13] (Microsoft Corporation)

========================== Drivers ===========================

3 1394ohci; C:\Windows\System32\drivers\1394ohci.sys [164864 2010-11-20] (Microsoft Corporation)
0 ACPI; C:\Windows\System32\drivers\ACPI.sys [274304 2010-11-20] (Microsoft Corporation)
3 AcpiPmi; C:\Windows\System32\drivers\acpipmi.sys [10240 2010-11-20] (Microsoft Corporation)
3 adp94xx; C:\Windows\System32\DRIVERS\adp94xx.sys [422976 2009-07-13] (Adaptec, Inc.)
3 adpahci; C:\Windows\System32\DRIVERS\adpahci.sys [297552 2009-07-13] (Adaptec, Inc.)
3 adpu320; C:\Windows\System32\DRIVERS\adpu320.sys [146512 2009-07-13] (Adaptec, Inc.)
1 AFD; C:\Windows\System32\drivers\afd.sys [338944 2011-04-24] (Microsoft Corporation)
3 agp440; C:\Windows\System32\drivers\agp440.sys [53312 2009-07-13] (Microsoft Corporation)
3 aic78xx; C:\Windows\System32\DRIVERS\djsvs.sys [70720 2009-07-13] (Adaptec, Inc.)
3 aliide; C:\Windows\System32\drivers\aliide.sys [14400 2009-07-13] (Acer Laboratories Inc.)
3 amdagp; C:\Windows\System32\drivers\amdagp.sys [53312 2009-07-13] (Microsoft Corporation)
3 amdide; C:\Windows\System32\drivers\amdide.sys [14912 2009-07-13] (Microsoft Corporation)
3 AmdK8; C:\Windows\System32\DRIVERS\amdk8.sys [55296 2009-07-13] (Microsoft Corporation)
3 AmdPPM; C:\Windows\System32\DRIVERS\amdppm.sys [52736 2009-07-13] (Microsoft Corporation)
3 amdsata; C:\Windows\System32\drivers\amdsata.sys [80256 2011-03-10] (Advanced Micro Devices)
3 amdsbs; C:\Windows\System32\DRIVERS\amdsbs.sys [159312 2009-07-13] (AMD Technologies Inc.)
0 amdxata; C:\Windows\System32\drivers\amdxata.sys [22400 2011-03-10] (Advanced Micro Devices)
3 AppID; C:\Windows\System32\drivers\appid.sys [50176 2010-11-20] (Microsoft Corporation)
3 arc; C:\Windows\System32\DRIVERS\arc.sys [76368 2009-07-13] (Adaptec, Inc.)
3 arcsas; C:\Windows\System32\DRIVERS\arcsas.sys [86608 2009-07-13] (Adaptec, Inc.)
3 AsyncMac; C:\Windows\System32\DRIVERS\asyncmac.sys [17920 2009-07-13] (Microsoft Corporation)
0 atapi; C:\Windows\System32\drivers\atapi.sys [21584 2009-07-13] (Microsoft Corporation)
3 athr; C:\Windows\System32\DRIVERS\athr.sys [1176064 2009-07-16] (Atheros Communications, Inc.)
2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [66616 2011-07-24] (Avira GmbH)
1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [138192 2011-07-24] (Avira GmbH)
3 b06bdrv; C:\Windows\System32\DRIVERS\bxvbdx.sys [430080 2009-07-13] (Broadcom Corporation)
3 b57nd60x; C:\Windows\System32\DRIVERS\b57nd60x.sys [229888 2009-07-13] (Broadcom Corporation)
3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl6.sys [2506232 2009-07-07] (Broadcom Corporation)
1 Beep; C:\Windows\System32\Drivers\Beep.sys [6144 2009-07-13] (Microsoft Corporation)
1 blbdrive; C:\Windows\System32\DRIVERS\blbdrive.sys [35328 2009-07-13] (Microsoft Corporation)
3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [69632 2011-02-22] (Microsoft Corporation)
3 BrFiltLo; C:\Windows\System32\DRIVERS\BrFiltLo.sys [13568 2009-07-13] (Brother Industries, Ltd.)
3 BrFiltUp; C:\Windows\System32\DRIVERS\BrFiltUp.sys [5248 2009-07-13] (Brother Industries, Ltd.)
3 BridgeMP; C:\Windows\System32\DRIVERS\bridge.sys [78336 2009-07-13] (Microsoft Corporation)
3 Brserid; C:\Windows\System32\Drivers\Brserid.sys [272128 2009-07-13] (Brother Industries Ltd.)
3 BrSerWdm; C:\Windows\System32\Drivers\BrSerWdm.sys [62336 2009-07-13] (Brother Industries Ltd.)
3 BrUsbMdm; C:\Windows\System32\Drivers\BrUsbMdm.sys [12160 2009-07-13] (Brother Industries Ltd.)
3 BrUsbSer; C:\Windows\System32\Drivers\BrUsbSer.sys [11904 2009-07-13] (Brother Industries Ltd.)
3 BTHMODEM; C:\Windows\System32\DRIVERS\bthmodem.sys [56320 2009-07-13] (Microsoft Corporation)
4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [70656 2009-07-13] (Microsoft Corporation)
1 cdrom; C:\Windows\System32\DRIVERS\cdrom.sys [108544 2010-11-20] (Microsoft Corporation)
3 circlass; C:\Windows\System32\DRIVERS\circlass.sys [37888 2009-07-13] (Microsoft Corporation)
0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-13] (Microsoft Corporation)
3 CmBatt; C:\Windows\System32\DRIVERS\CmBatt.sys [14080 2009-07-13] (Microsoft Corporation)
3 cmdide; C:\Windows\System32\drivers\cmdide.sys [15952 2009-07-13] (CMD Technology, Inc.)
0 CNG; C:\Windows\System32\Drivers\cng.sys [369352 2011-11-16] (Microsoft Corporation)
0 Compbatt; C:\Windows\System32\DRIVERS\compbatt.sys [19024 2009-07-13] (Microsoft Corporation)
3 CompositeBus; C:\Windows\System32\drivers\CompositeBus.sys [31232 2010-11-20] (Microsoft Corporation)
4 crcdisk; C:\Windows\System32\DRIVERS\crcdisk.sys [22096 2009-07-13] (Microsoft Corporation)
1 DfsC; C:\Windows\System32\Drivers\dfsc.sys [78336 2010-11-20] (Microsoft Corporation)
1 discache; C:\Windows\System32\drivers\discache.sys [32256 2009-07-13] (Microsoft Corporation)
0 Disk; C:\Windows\System32\DRIVERS\disk.sys [57424 2009-07-13] (Microsoft Corporation)
3 DKbFltr; C:\Windows\System32\DRIVERS\DKbFltr.sys [21000 2009-03-25] (Dritek System Inc.)
3 drmkaud; C:\Windows\System32\drivers\drmkaud.sys [5120 2009-07-13] (Microsoft Corporation)
3 DXGKrnl; C:\Windows\System32\drivers\dxgkrnl.sys [728448 2010-11-20] (Microsoft Corporation)
3 ebdrv; C:\Windows\System32\DRIVERS\evbdx.sys [3100160 2009-07-13] (Broadcom Corporation)
3 elxstor; C:\Windows\System32\DRIVERS\elxstor.sys [453712 2009-07-13] (Emulex)
3 ErrDev; C:\Windows\System32\drivers\errdev.sys [7168 2009-07-13] (Microsoft Corporation)
3 exfat; C:\Windows\System32\Drivers\exfat.sys [142336 2009-07-13] (Microsoft Corporation)
3 fastfat; C:\Windows\System32\Drivers\fastfat.sys [148480 2009-07-13] (Microsoft Corporation)
3 fdc; C:\Windows\System32\DRIVERS\fdc.sys [25088 2009-07-13] (Microsoft Corporation)
0 FileInfo; C:\Windows\System32\drivers\fileinfo.sys [58448 2009-07-13] (Microsoft Corporation)
3 Filetrace; C:\Windows\System32\drivers\filetrace.sys [28160 2009-07-13] (Microsoft Corporation)
3 flpydisk; C:\Windows\System32\DRIVERS\flpydisk.sys [19968 2009-07-13] (Microsoft Corporation)
0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [198208 2009-07-13] (Microsoft Corporation)
3 FsDepends; C:\Windows\System32\drivers\FsDepends.sys [46160 2009-07-13] (Microsoft Corporation)
0 Fs_Rec; C:\Windows\System32\Drivers\Fs_Rec.sys [19536 2009-07-13] (Microsoft Corporation)
0 fvevol; C:\Windows\System32\DRIVERS\fvevol.sys [194800 2010-11-20] (Microsoft Corporation)
3 gagp30kx; C:\Windows\System32\DRIVERS\gagp30kx.sys [57936 2009-07-13] (Microsoft Corporation)
3 GEARAspiWDM; C:\Windows\System32\DRIVERS\GEARAspiWDM.sys [26600 2009-05-18] (GEAR Software Inc.)
3 hcw85cir; C:\Windows\System32\drivers\hcw85cir.sys [26624 2009-07-13] (Hauppauge Computer Works, Inc.)
3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [304128 2010-11-20] (Microsoft Corporation)
3 HDAudBus; C:\Windows\System32\drivers\HDAudBus.sys [108544 2010-11-20] (Microsoft Corporation)
3 HidBatt; C:\Windows\System32\DRIVERS\HidBatt.sys [21504 2009-07-13] (Microsoft Corporation)
3 HidBth; C:\Windows\System32\DRIVERS\hidbth.sys [91136 2009-07-13] (Microsoft Corporation)
3 HidIr; C:\Windows\System32\DRIVERS\hidir.sys [37888 2009-07-13] (Microsoft Corporation)
3 HidUsb; C:\Windows\System32\drivers\hidusb.sys [24064 2010-11-20] (Microsoft Corporation)
3 HpSAMD; C:\Windows\System32\drivers\HpSAMD.sys [67152 2009-07-13] (Hewlett-Packard Company)
3 HTTP; C:\Windows\System32\drivers\HTTP.sys [513536 2010-11-20] (Microsoft Corporation)
0 hwpolicy; C:\Windows\System32\drivers\hwpolicy.sys [14208 2010-11-20] (Microsoft Corporation)
3 i8042prt; C:\Windows\System32\drivers\i8042prt.sys [80896 2009-07-13] (Microsoft Corporation)
0 iaStor; C:\Windows\System32\DRIVERS\iaStor.sys [330264 2009-06-04] (Intel Corporation)
3 iaStorV; C:\Windows\System32\drivers\iaStorV.sys [332160 2011-03-10] (Intel Corporation)
3 igfx; C:\Windows\System32\DRIVERS\igdkmd32.sys [4808192 2009-09-23] (Intel Corporation)
3 iirsp; C:\Windows\System32\DRIVERS\iirsp.sys [41040 2009-07-13] (Intel Corp./ICP vortex GmbH)
3 IntcAzAudAddService; C:\Windows\System32\drivers\RTKVHDA.sys [2657120 2009-07-06] (Realtek Semiconductor Corp.)
0 intelide; C:\Windows\System32\drivers\intelide.sys [15424 2009-07-13] (Microsoft Corporation)
3 intelppm; C:\Windows\System32\DRIVERS\intelppm.sys [53760 2009-07-13] (Microsoft Corporation)
3 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [58880 2009-07-13] (Microsoft Corporation)
3 IPMIDRV; C:\Windows\System32\drivers\IPMIDrv.sys [65536 2010-11-20] (Microsoft Corporation)
3 IPNAT; C:\Windows\System32\drivers\ipnat.sys [101888 2009-07-13] (Microsoft Corporation)
3 IRENUM; C:\Windows\System32\drivers\irenum.sys [13824 2009-07-13] (Microsoft Corporation)
3 isapnp; C:\Windows\System32\drivers\isapnp.sys [46656 2009-07-13] (Microsoft Corporation)
3 iScsiPrt; C:\Windows\System32\drivers\msiscsi.sys [233344 2010-11-20] (Microsoft Corporation)
3 kbdclass; C:\Windows\System32\drivers\kbdclass.sys [42576 2009-07-13] (Microsoft Corporation)
3 kbdhid; C:\Windows\System32\drivers\kbdhid.sys [28160 2010-11-20] (Microsoft Corporation)
0 KSecDD; C:\Windows\System32\Drivers\ksecdd.sys [67440 2011-11-16] (Microsoft Corporation)
0 KSecPkg; C:\Windows\System32\Drivers\ksecpkg.sys [134000 2011-11-16] (Microsoft Corporation)
3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [51712 2009-07-26] (Atheros Communications, Inc.)
2 lltdio; C:\Windows\System32\DRIVERS\lltdio.sys [48128 2009-07-13] (Microsoft Corporation)
3 LSI_FC; C:\Windows\System32\DRIVERS\lsi_fc.sys [95824 2009-07-13] (LSI Corporation)
3 LSI_SAS; C:\Windows\System32\DRIVERS\lsi_sas.sys [89168 2009-07-13] (LSI Corporation)
3 LSI_SAS2; C:\Windows\System32\DRIVERS\lsi_sas2.sys [54864 2009-07-13] (LSI Corporation)
3 LSI_SCSI; C:\Windows\System32\DRIVERS\lsi_scsi.sys [96848 2009-07-13] (LSI Corporation)
2 luafv; C:\Windows\System32\drivers\luafv.sys [86528 2009-07-13] (Microsoft Corporation)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [20464 2011-12-10] (Malwarebytes Corporation)
3 megasas; C:\Windows\System32\DRIVERS\megasas.sys [30800 2009-07-13] (LSI Corporation)
3 MegaSR; C:\Windows\System32\DRIVERS\MegaSR.sys [235584 2009-07-13] (LSI Corporation, Inc.)
3 Modem; C:\Windows\System32\drivers\modem.sys [31744 2009-07-13] (Microsoft Corporation)
3 monitor; C:\Windows\System32\DRIVERS\monitor.sys [23552 2009-07-13] (Microsoft Corporation)
3 mouclass; C:\Windows\System32\drivers\mouclass.sys [41552 2009-07-13] (Microsoft Corporation)
3 mouhid; C:\Windows\System32\DRIVERS\mouhid.sys [26112 2009-07-13] (Microsoft Corporation)
0 mountmgr; C:\Windows\System32\drivers\mountmgr.sys [78208 2010-11-20] (Microsoft Corporation)
3 mpio; C:\Windows\System32\drivers\mpio.sys [130432 2010-11-20] (Microsoft Corporation)
3 mpsdrv; C:\Windows\System32\drivers\mpsdrv.sys [60416 2009-07-13] (Microsoft Corporation)
3 MRxDAV; C:\Windows\System32\drivers\mrxdav.sys [115712 2010-11-20] (Microsoft Corporation)
3 mrxsmb; C:\Windows\System32\DRIVERS\mrxsmb.sys [123904 2011-04-26] (Microsoft Corporation)
3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [223744 2011-07-08] (Microsoft Corporation)
3 mrxsmb20; C:\Windows\System32\DRIVERS\mrxsmb20.sys [96768 2011-04-26] (Microsoft Corporation)
3 msahci; C:\Windows\System32\drivers\msahci.sys [28032 2010-11-20] (Microsoft Corporation)
3 msdsm; C:\Windows\System32\drivers\msdsm.sys [116096 2010-11-20] (Microsoft Corporation)
1 Msfs; C:\Windows\System32\Drivers\Msfs.sys [22528 2009-07-13] (Microsoft Corporation)
3 mshidkmdf; C:\Windows\System32\drivers\mshidkmdf.sys [4096 2009-07-13] (Microsoft Corporation)
0 msisadrv; C:\Windows\System32\drivers\msisadrv.sys [13888 2009-07-13] (Microsoft Corporation)
3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [8320 2009-07-13] (Microsoft Corporation)
3 MSPCLOCK; C:\Windows\System32\drivers\MSPCLOCK.sys [5888 2009-07-13] (Microsoft Corporation)
3 MSPQM; C:\Windows\System32\drivers\MSPQM.sys [5504 2009-07-13] (Microsoft Corporation)
3 MsRPC; C:\Windows\System32\Drivers\MsRPC.sys [162896 2009-07-13] (Microsoft Corporation)
1 mssmbios; C:\Windows\System32\drivers\mssmbios.sys [28240 2009-07-13] (Microsoft Corporation)
3 MSTEE; C:\Windows\System32\drivers\MSTEE.sys [6144 2009-07-13] (Microsoft Corporation)
3 MTConfig; C:\Windows\System32\DRIVERS\MTConfig.sys [12288 2009-07-13] (Microsoft Corporation)
0 Mup; C:\Windows\System32\Drivers\mup.sys [49728 2009-07-13] (Microsoft Corporation)
1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [18992 2009-06-02] (Egis Technology Inc.)
1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2009-06-02] (Egis Technology Inc.)
1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [60976 2009-06-02] (Egis Technology Inc.)
3 NativeWifiP; C:\Windows\System32\DRIVERS\nwifi.sys [267264 2009-07-13] (Microsoft Corporation)
0 NDIS; C:\Windows\System32\drivers\ndis.sys [712576 2010-11-20] (Microsoft Corporation)
3 NdisCap; C:\Windows\System32\DRIVERS\ndiscap.sys [27136 2009-07-13] (Microsoft Corporation)
3 NdisTapi; C:\Windows\System32\DRIVERS\ndistapi.sys [20992 2009-07-13] (Microsoft Corporation)
3 Ndisuio; C:\Windows\System32\DRIVERS\ndisuio.sys [46080 2010-11-20] (Microsoft Corporation)
3 NdisWan; C:\Windows\System32\DRIVERS\ndiswan.sys [118784 2010-11-20] (Microsoft Corporation)
3 NDProxy; C:\Windows\System32\Drivers\NDProxy.sys [48640 2010-11-20] (Microsoft Corporation)
1 NetBIOS; C:\Windows\System32\DRIVERS\netbios.sys [36352 2009-07-13] (Microsoft Corporation)
1 NetBT; C:\Windows\System32\DRIVERS\netbt.sys [187904 2010-11-20] (Microsoft Corporation)
3 nfrd960; C:\Windows\System32\DRIVERS\nfrd960.sys [44624 2009-07-13] (IBM Corporation)
1 Npfs; C:\Windows\System32\Drivers\Npfs.sys [35328 2009-07-13] (Microsoft Corporation)
1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [16896 2009-07-13] (Microsoft Corporation)
3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1211264 2011-03-10] (Microsoft Corporation)
1 Null; C:\Windows\System32\Drivers\Null.sys [4608 2009-07-13] (Microsoft Corporation)
3 nvraid; C:\Windows\System32\drivers\nvraid.sys [117120 2011-03-10] (NVIDIA Corporation)
3 nvstor; C:\Windows\System32\drivers\nvstor.sys [143744 2011-03-10] (NVIDIA Corporation)
3 nv_agp; C:\Windows\System32\drivers\nv_agp.sys [105024 2009-07-13] (Microsoft Corporation)
3 ohci1394; C:\Windows\System32\drivers\ohci1394.sys [62464 2009-07-13] (Microsoft Corporation)
3 Parport; C:\Windows\System32\DRIVERS\parport.sys [79360 2009-07-13] (Microsoft Corporation)
0 partmgr; C:\Windows\System32\drivers\partmgr.sys [56192 2010-11-20] (Microsoft Corporation)
2 Parvdm; C:\Windows\System32\DRIVERS\parvdm.sys [8704 2009-07-13] (Microsoft Corporation)
0 pci; C:\Windows\System32\drivers\pci.sys [153984 2010-11-20] (Microsoft Corporation)
3 pciide; C:\Windows\System32\drivers\pciide.sys [12368 2009-07-13] (Microsoft Corporation)
3 pcmcia; C:\Windows\System32\DRIVERS\pcmcia.sys [180288 2009-07-13] (Microsoft Corporation)
0 pcw; C:\Windows\System32\drivers\pcw.sys [43088 2009-07-13] (Microsoft Corporation)
2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [586752 2009-07-13] (Microsoft Corporation)
3 PptpMiniport; C:\Windows\System32\DRIVERS\raspptp.sys [73728 2009-07-13] (Microsoft Corporation)
3 Processor; C:\Windows\System32\DRIVERS\processr.sys [52224 2009-07-13] (Microsoft Corporation)
1 Psched; C:\Windows\System32\DRIVERS\pacer.sys [104448 2009-07-13] (Microsoft Corporation)
3 ql2300; C:\Windows\System32\DRIVERS\ql2300.sys [1383488 2009-07-13] (QLogic Corporation)
3 ql40xx; C:\Windows\System32\DRIVERS\ql40xx.sys [106064 2009-07-13] (QLogic Corporation)
3 QWAVEdrv; C:\Windows\System32\drivers\qwavedrv.sys [31744 2009-07-13] (Microsoft Corporation)
3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [11776 2009-07-13] (Microsoft Corporation)
3 RasAgileVpn; C:\Windows\System32\DRIVERS\AgileVpn.sys [49152 2009-07-13] (Microsoft Corporation)
3 Rasl2tp; C:\Windows\System32\DRIVERS\rasl2tp.sys [78848 2009-07-13] (Microsoft Corporation)
3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [77824 2009-07-13] (Microsoft Corporation)
3 RasSstp; C:\Windows\System32\DRIVERS\rassstp.sys [75264 2009-07-13] (Microsoft Corporation)
1 rdbss; C:\Windows\System32\DRIVERS\rdbss.sys [242688 2010-11-20] (Microsoft Corporation)
3 rdpbus; C:\Windows\System32\DRIVERS\rdpbus.sys [18944 2009-07-13] (Microsoft Corporation)
1 RDPCDD; C:\Windows\System32\DRIVERS\RDPCDD.sys [6656 2010-11-20] (Microsoft Corporation)
1 RDPENCDD; C:\Windows\System32\drivers\rdpencdd.sys [6656 2009-07-13] (Microsoft Corporation)
1 RDPREFMP; C:\Windows\System32\drivers\rdprefmp.sys [7168 2009-07-13] (Microsoft Corporation)
3 RDPWD; C:\Windows\System32\Drivers\RDPWD.sys [183808 2010-11-20] (Microsoft Corporation)
0 rdyboost; C:\Windows\System32\drivers\rdyboost.sys [173440 2010-11-20] (Microsoft Corporation)
2 rspndr; C:\Windows\System32\DRIVERS\rspndr.sys [60928 2009-07-13] (Microsoft Corporation)
3 RSUSBSTOR; C:\Windows\System32\Drivers\RtsUStor.sys [167424 2009-06-23] (Realtek Semiconductor Corp.)
3 sbp2port; C:\Windows\System32\drivers\sbp2port.sys [85376 2010-11-20] (Microsoft Corporation)
3 scfilter; C:\Windows\System32\DRIVERS\scfilter.sys [26624 2010-11-20] (Microsoft Corporation)
2 secdrv; C:\Windows\System32\Drivers\secdrv.sys [20480 2009-07-13] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
3 Serenum; C:\Windows\System32\DRIVERS\serenum.sys [17920 2009-07-13] (Microsoft Corporation)
3 Serial; C:\Windows\System32\DRIVERS\serial.sys [83456 2009-07-13] (Microsoft Corporation)
3 sermouse; C:\Windows\System32\DRIVERS\sermouse.sys [19968 2009-07-13] (Microsoft Corporation)
3 sffdisk; C:\Windows\System32\drivers\sffdisk.sys [11264 2009-07-13] (Microsoft Corporation)
3 sffp_mmc; C:\Windows\System32\drivers\sffp_mmc.sys [12288 2009-07-13] (Microsoft Corporation)
3 sffp_sd; C:\Windows\System32\drivers\sffp_sd.sys [12800 2010-11-20] (Microsoft Corporation)
3 sfloppy; C:\Windows\System32\DRIVERS\sfloppy.sys [13824 2009-07-13] (Microsoft Corporation)
3 sisagp; C:\Windows\System32\drivers\sisagp.sys [52304 2009-07-13] (Microsoft Corporation)
3 SiSRaid2; C:\Windows\System32\DRIVERS\SiSRaid2.sys [40016 2009-07-13] (Silicon Integrated Systems Corp.)
3 SiSRaid4; C:\Windows\System32\DRIVERS\sisraid4.sys [77888 2009-07-13] (Silicon Integrated Systems)
3 Smb; C:\Windows\System32\DRIVERS\smb.sys [71168 2009-07-13] (Microsoft Corporation)
0 spldr; C:\Windows\System32\Drivers\spldr.sys [17472 2009-07-13] (Microsoft Corporation)
3 srv; C:\Windows\System32\DRIVERS\srv.sys [311808 2011-04-28] (Microsoft Corporation)
3 srv2; C:\Windows\System32\DRIVERS\srv2.sys [310272 2011-04-28] (Microsoft Corporation)
3 srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [114688 2011-04-28] (Microsoft Corporation)
1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-05-11] (Avira GmbH)
3 stexstor; C:\Windows\System32\DRIVERS\stexstor.sys [21072 2009-07-13] (Promise Technology)
3 swenum; C:\Windows\System32\drivers\swenum.sys [12240 2009-07-13] (Microsoft Corporation)
3 SynTP; C:\Windows\System32\DRIVERS\SynTP.sys [212400 2009-06-18] (Synaptics Incorporated)
0 Tcpip; C:\Windows\System32\drivers\tcpip.sys [1290608 2011-09-29] (Microsoft Corporation)
3 TCPIP6; C:\Windows\System32\DRIVERS\tcpip.sys [1290608 2011-09-29] (Microsoft Corporation)
2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [35328 2010-11-20] (Microsoft Corporation)
3 TDPIPE; C:\Windows\System32\drivers\tdpipe.sys [18432 2010-11-20] (Microsoft Corporation)
3 TDTCP; C:\Windows\System32\drivers\tdtcp.sys [24576 2010-11-20] (Microsoft Corporation)
1 tdx; C:\Windows\System32\DRIVERS\tdx.sys [74752 2010-11-20] (Microsoft Corporation)
1 TermDD; C:\Windows\System32\drivers\termdd.sys [53120 2010-11-20] (Microsoft Corporation)
3 tssecsrv; C:\Windows\System32\DRIVERS\tssecsrv.sys [31232 2010-11-20] (Microsoft Corporation)
3 TsUsbFlt; C:\Windows\System32\drivers\tsusbflt.sys [52224 2010-11-20] (Microsoft Corporation)
3 tunnel; C:\Windows\System32\DRIVERS\tunnel.sys [108544 2010-11-20] (Microsoft Corporation)
3 uagp35; C:\Windows\System32\DRIVERS\uagp35.sys [55888 2009-07-13] (Microsoft Corporation)
4 udfs; C:\Windows\System32\DRIVERS\udfs.sys [246784 2010-11-20] (Microsoft Corporation)
3 uliagpkx; C:\Windows\System32\drivers\uliagpkx.sys [57424 2009-07-13] (Microsoft Corporation)
3 umbus; C:\Windows\System32\drivers\umbus.sys [39936 2010-11-20] (Microsoft Corporation)
3 UmPass; C:\Windows\System32\DRIVERS\umpass.sys [8192 2009-07-13] (Microsoft Corporation)
3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [42496 2011-05-09] (Apple, Inc.)
3 usbaudio; C:\Windows\System32\drivers\usbaudio.sys [80768 2010-11-20] (Microsoft Corporation)
3 usbccgp; C:\Windows\System32\DRIVERS\usbccgp.sys [75776 2011-03-24] (Microsoft Corporation)
3 usbcir; C:\Windows\System32\drivers\usbcir.sys [86016 2009-07-13] (Microsoft Corporation)
3 usbehci; C:\Windows\System32\DRIVERS\usbehci.sys [43008 2011-03-24] (Microsoft Corporation)
3 usbhub; C:\Windows\System32\DRIVERS\usbhub.sys [258560 2011-03-24] (Microsoft Corporation)
3 usbohci; C:\Windows\System32\drivers\usbohci.sys [20480 2011-03-24] (Microsoft Corporation)
3 usbprint; C:\Windows\System32\DRIVERS\usbprint.sys [19968 2009-07-13] (Microsoft Corporation)
3 USBSTOR; C:\Windows\System32\DRIVERS\USBSTOR.SYS [76288 2011-03-10] (Microsoft Corporation)
3 usbuhci; C:\Windows\System32\DRIVERS\usbuhci.sys [24064 2011-03-24] (Microsoft Corporation)
3 usbvideo; C:\Windows\System32\Drivers\usbvideo.sys [146432 2010-11-20] (Microsoft Corporation)
0 vdrvroot; C:\Windows\System32\drivers\vdrvroot.sys [32832 2009-07-13] (Microsoft Corporation)
3 vga; C:\Windows\System32\DRIVERS\vgapnp.sys [26112 2009-07-13] (Microsoft Corporation)
1 VgaSave; C:\Windows\System32\drivers\vga.sys [25088 2009-07-13] (Microsoft Corporation)
3 vhdmp; C:\Windows\System32\drivers\vhdmp.sys [160128 2010-11-20] (Microsoft Corporation)
3 viaagp; C:\Windows\System32\drivers\viaagp.sys [53328 2009-07-13] (Microsoft Corporation)
3 ViaC7; C:\Windows\System32\DRIVERS\viac7.sys [52736 2009-07-13] (Microsoft Corporation)
3 viaide; C:\Windows\System32\drivers\viaide.sys [16976 2009-07-13] (VIA Technologies, Inc.)
0 volmgr; C:\Windows\System32\drivers\volmgr.sys [53120 2010-11-20] (Microsoft Corporation)
0 volmgrx; C:\Windows\System32\drivers\volmgrx.sys [297040 2009-07-13] (Microsoft Corporation)
0 volsnap; C:\Windows\System32\drivers\volsnap.sys [245632 2010-11-20] (Microsoft Corporation)
3 vsmraid; C:\Windows\System32\DRIVERS\vsmraid.sys [141904 2009-07-13] (VIA Technologies Inc.,Ltd)
3 vwifibus; C:\Windows\System32\DRIVERS\vwifibus.sys [19968 2009-07-13] (Microsoft Corporation)
1 vwififlt; C:\Windows\System32\DRIVERS\vwififlt.sys [48128 2009-07-13] (Microsoft Corporation)
3 WacomPen; C:\Windows\System32\DRIVERS\wacompen.sys [21632 2009-07-13] (Microsoft Corporation)
3 WANARP; C:\Windows\System32\DRIVERS\wanarp.sys [63488 2010-11-20] (Microsoft Corporation)
1 Wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [63488 2010-11-20] (Microsoft Corporation)
3 Wd; C:\Windows\System32\DRIVERS\wd.sys [19024 2009-07-13] (Microsoft Corporation)
0 Wdf01000; C:\Windows\System32\drivers\Wdf01000.sys [445008 2009-07-13] (Microsoft Corporation)
1 WfpLwf; C:\Windows\System32\DRIVERS\wfplwf.sys [9728 2009-07-13] (Microsoft Corporation)
3 WIMMount; C:\Windows\System32\drivers\wimmount.sys [19008 2009-07-13] (Microsoft Corporation)
3 WinUsb; C:\Windows\System32\DRIVERS\WinUsb.sys [35968 2010-11-20] (Microsoft Corporation)
3 WmiAcpi; C:\Windows\System32\drivers\wmiacpi.sys [11264 2009-07-13] (Microsoft Corporation)
1 ws2ifsl; C:\Windows\System32\drivers\ws2ifsl.sys [16384 2009-07-13] (Microsoft Corporation)
3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [92672 2010-11-20] (Microsoft Corporation)
3 WUDFRd; C:\Windows\System32\DRIVERS\WUDFRd.sys [132224 2010-11-20] (Microsoft Corporation)
3 catchme; \??\C:\Users\Acer\AppData\Local\Temp\catchme.sys [x]
3 CFcatchme; \??\C:\Users\Acer\AppData\Local\Temp\CFcatchme.sys [x]
3 RtsUIR; C:\Windows\System32\DRIVERS\Rts516xIR.sys [x]
3 USBCCID; C:\Windows\System32\DRIVERS\RtsUCcid.sys [x]

========================== NetSvcs (Whitelisted) ===========

============ One Month Created Files and Folders ==============

2012-03-09 05:16 - 2012-03-09 05:16 - 0027936 ____A C:\Users\Acer\Desktop\Extras.Txt
2012-03-08 05:22 - 2012-03-08 05:24 - 0010692 ____A C:\ComboFix.txt
2012-03-08 05:15 - 2012-03-08 05:15 - 0000000 __SHD C:\$RECYCLE.BIN
2012-03-08 04:49 - 2012-03-08 04:49 - 4431034 ____R (Swearware) C:\Users\Acer\Desktop\ComboFix.exe
2012-03-07 10:13 - 2012-03-08 06:22 - 0000167 ____A C:\Users\Acer\Desktop\08.03.14.17 Uhr.txt
2012-03-07 07:48 - 2012-03-07 07:48 - 2322184 ____A (ESET) C:\Users\Acer\Desktop\esetsmartinstaller_enu.exe
2012-03-07 06:31 - 2012-03-07 06:31 - 0451963 ____A C:\Users\Acer\Desktop\Trojanisches Pferd TR-Crypt.zpack.gen2 gefunden. Kein Internet! - Seite 4 - Trojaner-Board.webarchive
2012-03-06 04:59 - 2012-03-06 04:59 - 0139264 ____A () C:\Users\Acer\Desktop\RKUnhookerLE.EXE
2012-03-05 10:15 - 2012-03-06 07:35 - 0094663 ____A C:\Users\Acer\Desktop\RKU1.txt
2012-03-05 09:30 - 2012-03-05 09:30 - 0302592 ____A C:\Users\Acer\Desktop\8kn8rjxd.exe
2012-03-04 06:42 - 2012-03-04 06:43 - 0077840 ____A C:\TDSSKiller.2.7.18.0_04.03.2012_15.42.06_log.txt
2012-03-04 06:40 - 2012-03-04 06:40 - 0000512 ____A C:\Users\Acer\Desktop\MBR.dat
2012-03-04 06:07 - 2012-03-04 06:07 - 2062896 ____A (Kaspersky Lab ZAO) C:\Users\Acer\Desktop\tdsskiller.exe
2012-03-04 06:05 - 2012-03-04 06:05 - 4730880 ____A (AVAST Software) C:\Users\Acer\Desktop\aswMBR.exe
2012-03-03 23:33 - 2012-03-10 14:35 - 0000000 ____D C:\FRST
2012-03-02 12:42 - 2012-03-02 12:43 - 0000000 ____D C:\Avenger
2012-03-02 12:42 - 2012-03-02 12:42 - 0001298 ____A C:\avenger.txt
2012-03-02 12:36 - 2012-03-02 12:37 - 0731136 ____A C:\Users\Acer\Desktop\avenger.exe
2012-02-28 15:07 - 2012-02-28 15:07 - 0302592 ____A C:\Users\Acer\Desktop\r8z3xleh.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 9705472 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 3695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-02-27 16:57 - 2012-02-27 16:57 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-02-27 16:57 - 2012-02-27 16:57 - 1798656 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1792000 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1427456 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-02-27 16:57 - 2012-02-27 16:57 - 12282368 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1127424 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1103360 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0580608 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0434176 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0367104 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-02-27 16:57 - 2012-02-27 16:57 - 0353792 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0353584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0227840 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0223232 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0203776 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0162304 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0161792 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0152064 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0130560 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0123392 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0118784 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0101888 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0086528 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0078848 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0076800 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0074240 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0072822 ____A C:\Windows\System32\ieuinit.inf
2012-02-27 16:57 - 2012-02-27 16:57 - 0072704 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0066048 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0063488 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-02-27 16:57 - 2012-02-27 16:57 - 0054272 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0041472 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0035840 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0031744 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0023552 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0011776 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-02-27 16:30 - 2012-02-27 16:30 - 0001629 ____A C:\Windows\System32\FSS.txt
2012-02-27 15:59 - 2011-06-25 22:45 - 0256000 ____A C:\Windows\PEV.exe
2012-02-27 15:59 - 2010-11-07 09:20 - 0208896 ____A C:\Windows\MBR.exe
2012-02-27 15:59 - 2009-04-19 20:56 - 0060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-02-27 15:59 - 2000-08-30 16:00 - 0518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-02-27 15:59 - 2000-08-30 16:00 - 0406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-02-27 15:59 - 2000-08-30 16:00 - 0098816 ____A C:\Windows\sed.exe
2012-02-27 15:59 - 2000-08-30 16:00 - 0080412 ____A C:\Windows\grep.exe
2012-02-27 15:59 - 2000-08-30 16:00 - 0068096 ____A C:\Windows\zip.exe
2012-02-27 15:55 - 2012-02-27 15:55 - 0337133 ____A C:\Users\Acer\Downloads\FSS.exe
2012-02-27 15:49 - 2012-02-27 15:50 - 4420957 ____A (Swearware) C:\Users\Acer\Downloads\ComboFix.exe
2012-02-27 09:06 - 2012-02-27 09:06 - 0144960 ____A C:\Windows\Minidump\022712-17643-01.dmp
2012-02-27 09:06 - 2012-02-27 09:06 - 0000000 ____D C:\Windows\Minidump
2012-02-27 09:05 - 2012-02-27 09:05 - 326712483 ____A C:\Windows\MEMORY.DMP
2012-02-27 08:29 - 2012-02-27 08:29 - 0302592 ____A C:\Users\Acer\Downloads\g20q7onb.exe
2012-02-26 15:50 - 2012-02-26 15:50 - 0000000 ____A C:\Users\Acer\defogger_reenable
2012-02-26 15:47 - 2012-02-26 15:47 - 0302592 ____A C:\Users\Acer\Downloads\hk4txtc9.exe
2012-02-26 15:43 - 2012-02-26 15:43 - 0607260 ____R (Swearware) C:\Users\Acer\Downloads\dds.com
2012-02-26 15:41 - 2012-02-26 15:41 - 0050477 ____A C:\Users\Acer\Downloads\Defogger.exe
2012-02-19 09:26 - 2012-02-19 09:26 - 0553863 ____A C:\Users\Acer\Downloads\2011_06_29_SkinEdit_alpha3_pre7_fix.zip
2012-02-19 06:39 - 2012-02-19 06:42 - 24554628 ____A C:\Users\Acer\Downloads\GammlerPlay.zip
2012-02-18 16:03 - 2012-02-18 16:05 - 0000022 ____A C:\Users\Acer\Downloads\Star Wars Skin Pack V4.zip
2012-02-18 15:26 - 2012-02-18 15:41 - 14513553 ____A C:\Users\Acer\Downloads\DokuCraft - The Saga Continues 1.2.zip
2012-02-18 15:18 - 2012-02-18 15:18 - 4389435 ____A C:\Users\Acer\Downloads\DokuCraft_218326.zip
2012-02-18 14:20 - 2012-02-21 11:08 - 0000426 ____A C:\Users\Acer\Desktop\settings.xml
2012-02-18 10:53 - 2012-02-18 11:17 - 0000417 ____A C:\Windows\System32\settings.xml
2012-02-18 04:38 - 2012-02-18 04:38 - 0000000 ____D C:\Windows\Sun
2012-02-18 04:02 - 2011-12-29 21:27 - 0478720 ____A (Microsoft Corporation) C:\Windows\System32\timedate.cpl
2012-02-18 04:01 - 2012-02-18 04:01 - 0000681 ____A C:\Users\Acer\Desktop\Minecraft.exe - Verknüpfung.lnk
2012-02-18 04:01 - 2012-01-04 00:59 - 12872704 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-02-18 04:01 - 2012-01-04 00:58 - 0442880 ____A (Microsoft Corporation) C:\Windows\System32\ntshrui.dll
2012-02-18 04:01 - 2011-12-15 23:52 - 0690688 ____A (Microsoft Corporation) C:\Windows\System32\msvcrt.dll
2012-02-18 04:00 - 2012-01-13 19:35 - 2343424 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-02-18 03:39 - 2012-02-18 03:39 - 0510657 ____A C:\Users\Acer\Downloads\MCSkinEdit_a3_pre5.zip
2012-02-11 08:58 - 2012-02-26 12:49 - 0000000 ___RD C:\Users\Acer\Desktop\let's play's svenweisven
2012-02-11 07:10 - 2012-02-11 07:10 - 0000000 ____D C:\Users\Acer\AppData\Local\{E09BE6F8-59E7-489F-B41E-CCB4F4175006}
2012-02-11 07:10 - 2012-02-11 07:10 - 0000000 ____D C:\Users\Acer\AppData\Local\{11BC444D-7AF9-43B6-B0AF-BF4BC8FF9787}
2012-02-11 03:09 - 2012-02-11 03:10 - 0270142 ____A C:\Users\Acer\Downloads\Minecraft.exe


============ 3 Months Modified Files and Folders ===============

2012-03-10 14:35 - 2012-03-03 23:33 - 0000000 ____D C:\FRST
2012-03-10 05:29 - 2009-09-16 10:36 - 797396992 __ASH C:\hiberfil.sys
2012-03-10 05:29 - 2009-08-14 01:26 - 0852842 ____A C:\Windows\PFRO.log
2012-03-10 05:29 - 2009-07-13 20:53 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2012-03-10 05:29 - 2009-07-13 20:39 - 0058322 ____A C:\Windows\setupact.log
2012-03-10 05:28 - 2009-09-16 10:39 - 1918483 ____A C:\Windows\WindowsUpdate.log
2012-03-09 05:16 - 2012-03-09 05:16 - 0054154 ____A C:\Users\Acer\Desktop\OTL.Txt
2012-03-09 05:16 - 2012-03-09 05:16 - 0027936 ____A C:\Users\Acer\Desktop\Extras.Txt
2012-03-08 06:22 - 2012-03-07 10:13 - 0000167 ____A C:\Users\Acer\Desktop\08.03.14.17 Uhr.txt
2012-03-08 06:17 - 2009-07-13 20:34 - 0009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-03-08 06:17 - 2009-07-13 20:34 - 0009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-03-08 05:24 - 2012-03-08 05:22 - 0010692 ____A C:\ComboFix.txt
2012-03-08 05:24 - 2012-01-06 11:00 - 0000000 ____D C:\Qoobox
2012-03-08 05:15 - 2012-03-08 05:15 - 0000000 __SHD C:\$RECYCLE.BIN
2012-03-08 05:15 - 2009-07-13 18:04 - 0000215 ____A C:\Windows\system.ini
2012-03-08 05:15 - 2009-07-13 18:04 - 0000027 ____A C:\Windows\System32\Drivers\etc\hosts
2012-03-08 04:58 - 2012-01-24 08:35 - 0212992 ____A C:\Windows\System32\aptw2s8pj.dll
2012-03-08 04:49 - 2012-03-08 04:49 - 4431034 ____R (Swearware) C:\Users\Acer\Desktop\ComboFix.exe
2012-03-07 07:48 - 2012-03-07 07:48 - 2322184 ____A (ESET) C:\Users\Acer\Desktop\esetsmartinstaller_enu.exe
2012-03-07 06:31 - 2012-03-07 06:31 - 0451963 ____A C:\Users\Acer\Desktop\Trojanisches Pferd TR-Crypt.zpack.gen2 gefunden. Kein Internet! - Seite 4 - Trojaner-Board.webarchive
2012-03-06 07:35 - 2012-03-05 10:15 - 0094663 ____A C:\Users\Acer\Desktop\RKU1.txt
2012-03-06 04:59 - 2012-03-06 04:59 - 0139264 ____A () C:\Users\Acer\Desktop\RKUnhookerLE.EXE
2012-03-05 09:30 - 2012-03-05 09:30 - 0302592 ____A C:\Users\Acer\Desktop\8kn8rjxd.exe
2012-03-04 06:43 - 2012-03-04 06:42 - 0077840 ____A C:\TDSSKiller.2.7.18.0_04.03.2012_15.42.06_log.txt
2012-03-04 06:40 - 2012-03-04 06:40 - 0000512 ____A C:\Users\Acer\Desktop\MBR.dat
2012-03-04 06:07 - 2012-03-04 06:07 - 2062896 ____A (Kaspersky Lab ZAO) C:\Users\Acer\Desktop\tdsskiller.exe
2012-03-04 06:05 - 2012-03-04 06:05 - 4730880 ____A (AVAST Software) C:\Users\Acer\Desktop\aswMBR.exe
2012-03-04 04:46 - 2011-12-07 07:40 - 0000000 ____D C:\Users\Acer\AppData\Roaming\.minecraft
2012-03-04 03:33 - 2011-09-23 12:39 - 0000000 ____D C:\Users\Acer\AppData\Roaming\Skype
2012-03-03 14:41 - 2009-08-14 00:37 - 1498506 ____A C:\Windows\System32\PerfStringBackup.INI
2012-03-02 12:43 - 2012-03-02 12:42 - 0000000 ____D C:\Avenger
2012-03-02 12:42 - 2012-03-02 12:42 - 0001298 ____A C:\avenger.txt
2012-03-02 12:37 - 2012-03-02 12:36 - 0731136 ____A C:\Users\Acer\Desktop\avenger.exe
2012-03-01 07:23 - 2012-01-06 11:00 - 0000000 ____D C:\Windows\ERDNT
2012-02-28 15:07 - 2012-02-28 15:07 - 0302592 ____A C:\Users\Acer\Desktop\r8z3xleh.exe
2012-02-28 04:32 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\rescache
2012-02-28 02:18 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\Microsoft.NET
2012-02-28 01:32 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\de-DE
2012-02-27 16:59 - 2011-10-11 06:42 - 0021282 ____A C:\Windows\IE9_main.log
2012-02-27 16:57 - 2012-02-27 16:57 - 9705472 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 3695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-02-27 16:57 - 2012-02-27 16:57 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-02-27 16:57 - 2012-02-27 16:57 - 1798656 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1792000 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1427456 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-02-27 16:57 - 2012-02-27 16:57 - 12282368 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1127424 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 1103360 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0580608 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0434176 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0367104 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-02-27 16:57 - 2012-02-27 16:57 - 0353792 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0353584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0227840 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0223232 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0203776 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0162304 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0161792 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0152064 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0130560 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0123392 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0118784 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0101888 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0086528 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0078848 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0076800 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0074240 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0072822 ____A C:\Windows\System32\ieuinit.inf
2012-02-27 16:57 - 2012-02-27 16:57 - 0072704 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0066048 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0063488 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-02-27 16:57 - 2012-02-27 16:57 - 0054272 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0041472 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0035840 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0031744 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0023552 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-02-27 16:57 - 2012-02-27 16:57 - 0011776 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-02-27 16:57 - 2012-02-27 16:57 - 0010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-02-27 16:30 - 2012-02-27 16:30 - 0001629 ____A C:\Windows\System32\FSS.txt
2012-02-27 15:55 - 2012-02-27 15:55 - 0337133 ____A C:\Users\Acer\Downloads\FSS.exe
2012-02-27 15:50 - 2012-02-27 15:49 - 4420957 ____A (Swearware) C:\Users\Acer\Downloads\ComboFix.exe
2012-02-27 14:13 - 2012-01-07 02:19 - 0000000 ____D C:\Users\Acer\AppData\Local\ElevatedDiagnostics
2012-02-27 09:06 - 2012-02-27 09:06 - 0144960 ____A C:\Windows\Minidump\022712-17643-01.dmp
2012-02-27 09:06 - 2012-02-27 09:06 - 0000000 ____D C:\Windows\Minidump
2012-02-27 09:05 - 2012-02-27 09:05 - 326712483 ____A C:\Windows\MEMORY.DMP
2012-02-27 08:29 - 2012-02-27 08:29 - 0302592 ____A C:\Users\Acer\Downloads\g20q7onb.exe
2012-02-26 15:50 - 2012-02-26 15:50 - 0000000 ____A C:\Users\Acer\defogger_reenable
2012-02-26 15:50 - 2011-02-26 21:18 - 0000000 ____D C:\Program Files\Safari
2012-02-26 15:50 - 2011-02-22 14:44 - 0000000 ____D C:\users\Acer
2012-02-26 15:47 - 2012-02-26 15:47 - 0302592 ____A C:\Users\Acer\Downloads\hk4txtc9.exe
2012-02-26 15:43 - 2012-02-26 15:43 - 0607260 ____R (Swearware) C:\Users\Acer\Downloads\dds.com
2012-02-26 15:41 - 2012-02-26 15:41 - 0050477 ____A C:\Users\Acer\Downloads\Defogger.exe
2012-02-26 15:16 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\config\TxR
2012-02-26 15:14 - 2012-01-21 05:38 - 0000000 ____D C:\Program Files\Freeware.de
2012-02-26 15:14 - 2012-01-10 15:17 - 0000000 ___RD C:\Users\Acer\Desktop\SHL
2012-02-26 15:14 - 2011-09-25 07:17 - 0000000 ____D C:\Users\Acer\AppData\Local\Conduit
2012-02-26 15:14 - 2011-09-25 07:17 - 0000000 ____D C:\Program Files\Yontoo Layers Runtime
2012-02-26 15:14 - 2011-08-16 01:57 - 0000000 ____D C:\users\Gast
2012-02-26 15:14 - 2011-02-22 14:44 - 0000000 ____D C:\Users\Acer\AppData\LocalLow
2012-02-26 15:14 - 2009-08-14 01:28 - 0000000 ____D C:\Users\All Users\Symantec
2012-02-26 15:14 - 2009-08-14 01:28 - 0000000 ____D C:\ProgramData\Symantec
2012-02-26 15:14 - 2009-08-14 01:04 - 0000000 ____D C:\Program Files\Microsoft Silverlight
2012-02-26 15:14 - 2009-07-13 18:37 - 0000000 __RSD C:\Windows\Media
2012-02-26 15:14 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\wfp
2012-02-26 15:14 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\NDF
2012-02-26 15:14 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\DriverStore
2012-02-26 15:14 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\AppCompat
2012-02-26 15:14 - 2009-07-13 18:37 - 0000000 ____D C:\Program Files\Common Files\microsoft shared
2012-02-26 15:13 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\registration
2012-02-26 15:11 - 2011-12-30 02:46 - 0000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-02-26 15:11 - 2009-08-14 00:56 - 0000000 ____D C:\Program Files\Microsoft Works
2012-02-26 12:49 - 2012-02-11 08:58 - 0000000 ___RD C:\Users\Acer\Desktop\let's play's svenweisven
2012-02-26 12:49 - 2011-12-08 11:56 - 0000000 ___RD C:\Users\Acer\Desktop\Sender
2012-02-26 12:49 - 2011-04-11 21:49 - 0000000 ___RD C:\Users\Acer\Desktop\star wars the clone wars
2012-02-21 11:08 - 2012-02-18 14:20 - 0000426 ____A C:\Users\Acer\Desktop\settings.xml
2012-02-19 09:26 - 2012-02-19 09:26 - 0553863 ____A C:\Users\Acer\Downloads\2011_06_29_SkinEdit_alpha3_pre7_fix.zip
2012-02-19 06:42 - 2012-02-19 06:39 - 24554628 ____A C:\Users\Acer\Downloads\GammlerPlay.zip
2012-02-19 00:05 - 2011-12-14 10:21 - 0000000 ____D C:\Users\Acer\Documents\FILSHtray
2012-02-19 00:03 - 2011-02-22 14:45 - 0000174 ___SH C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
2012-02-18 18:37 - 2009-07-13 20:33 - 0302320 ____A C:\Windows\System32\FNTCACHE.DAT
2012-02-18 18:15 - 2011-02-22 15:33 - 52550552 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-02-18 16:05 - 2012-02-18 16:03 - 0000022 ____A C:\Users\Acer\Downloads\Star Wars Skin Pack V4.zip
2012-02-18 15:41 - 2012-02-18 15:26 - 14513553 ____A C:\Users\Acer\Downloads\DokuCraft - The Saga Continues 1.2.zip
2012-02-18 15:18 - 2012-02-18 15:18 - 4389435 ____A C:\Users\Acer\Downloads\DokuCraft_218326.zip
2012-02-18 14:19 - 2010-06-03 12:19 - 0155762 ____A C:\Users\Acer\Desktop\MCSkinEdit.jar
2012-02-18 11:17 - 2012-02-18 10:53 - 0000417 ____A C:\Windows\System32\settings.xml
2012-02-18 04:38 - 2012-02-18 04:38 - 0000000 ____D C:\Windows\Sun
2012-02-18 04:01 - 2012-02-18 04:01 - 0000681 ____A C:\Users\Acer\Desktop\Minecraft.exe - Verknüpfung.lnk
2012-02-18 03:39 - 2012-02-18 03:39 - 0510657 ____A C:\Users\Acer\Downloads\MCSkinEdit_a3_pre5.zip
2012-02-11 07:11 - 2011-10-15 01:54 - 0000000 ____D C:\Users\Acer\AppData\Local\Windows Live
2012-02-11 07:10 - 2012-02-11 07:10 - 0000000 ____D C:\Users\Acer\AppData\Local\{E09BE6F8-59E7-489F-B41E-CCB4F4175006}
2012-02-11 07:10 - 2012-02-11 07:10 - 0000000 ____D C:\Users\Acer\AppData\Local\{11BC444D-7AF9-43B6-B0AF-BF4BC8FF9787}
2012-02-11 03:10 - 2012-02-11 03:09 - 0270142 ____A C:\Users\Acer\Downloads\Minecraft.exe
2012-02-07 14:36 - 2009-08-14 00:54 - 0000000 ____D C:\Users\All Users\Microsoft Help
2012-02-07 14:36 - 2009-08-14 00:54 - 0000000 ____D C:\ProgramData\Microsoft Help
2012-02-07 13:38 - 2011-12-30 02:46 - 0001075 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-02-07 11:30 - 2012-02-07 11:30 - 0000000 ____D C:\Program Files\AC3Filter
2012-02-06 11:12 - 2011-09-08 10:45 - 0414368 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-02-05 05:46 - 2009-07-13 18:37 - 0000000 ___HD C:\Windows\System32\GroupPolicyUsers
2012-02-04 00:30 - 2012-01-30 05:57 - 0000000 ____D C:\Users\Acer\Documents\Stronghold Legends
2012-01-30 05:57 - 2012-01-30 05:57 - 0000000 ____D C:\Users\All Users\Firefly Studios
2012-01-30 05:57 - 2012-01-30 05:57 - 0000000 ____D C:\ProgramData\Firefly Studios
2012-01-30 05:53 - 2011-08-27 06:10 - 0233989 ____A C:\Windows\DirectX.log
2012-01-30 05:51 - 2012-01-30 05:51 - 0001972 ____A C:\Users\Public\Desktop\Stronghold Legends.lnk
2012-01-30 05:44 - 2012-01-30 05:44 - 0000000 ____D C:\Program Files\Firefly Studios
2012-01-30 05:44 - 2009-08-14 00:34 - 0000000 ___HD C:\Program Files\InstallShield Installation Information
2012-01-21 05:39 - 2012-01-21 05:39 - 0000941 ____A C:\Users\Public\Desktop\vipstegano.lnk
2012-01-21 05:39 - 2012-01-21 05:39 - 0000000 ____D C:\Program Files\vipstegano
2012-01-21 05:38 - 2012-01-21 05:38 - 0560470 ____A C:\Users\Acer\Documents\vipstegano.zip
2012-01-21 05:38 - 2012-01-21 05:38 - 0000000 ____D C:\Program Files\Conduit
2012-01-21 05:36 - 2012-01-21 05:36 - 0512000 ____A (www.download-sponsor.de) C:\Users\Acer\Downloads\Downloader-fuer-vipstegano.exe
2012-01-21 04:36 - 2011-12-14 10:21 - 0000000 ____D C:\Program Files\FILSHtray
2012-01-13 19:35 - 2012-02-18 04:00 - 2343424 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-01-12 10:25 - 2012-01-12 10:19 - 0001278 ____A C:\Users\Acer\Desktop\easyshare.exe - Verknüpfung.lnk
2012-01-11 05:25 - 2012-01-11 05:25 - 0000000 ____D C:\Users\Acer\Downloads\hosts
2012-01-11 05:25 - 2012-01-11 05:24 - 0149201 ____A C:\Users\Acer\Downloads\hosts.zip
2012-01-10 14:42 - 2012-01-10 14:42 - 0264192 ____A C:\Users\Acer\Documents\Direkte Rede.doc
2012-01-10 14:35 - 2012-01-10 14:35 - 0000000 ____D C:\Program Files\devolo
2012-01-10 12:28 - 2011-02-22 14:45 - 0067856 ____A C:\Users\Acer\AppData\Local\GDIPFONTCACHEV1.DAT
2012-01-10 06:57 - 2011-02-26 21:19 - 0100216 ___AH C:\Windows\System32\mlfcache.dat
2012-01-10 06:51 - 2011-09-23 12:39 - 0000000 ___RD C:\Program Files\Skype
2012-01-10 06:39 - 2011-08-27 06:12 - 0098304 ____A (Sony DADC Austria AG.) C:\Windows\System32\CmdLineExt.dll
2012-01-10 05:35 - 2011-02-22 14:45 - 0000000 ____D C:\Users\Acer\AppData\Roaming\Macromedia
2012-01-09 15:05 - 2012-01-05 14:55 - 0026286 ____A C:\Users\Acer\Downloads\Extras.Txt
2012-01-09 15:04 - 2012-01-05 14:54 - 0104106 ____A C:\Users\Acer\Downloads\OTL.Txt
2012-01-09 14:03 - 2012-01-09 14:03 - 0584192 ____A (OldTimer Tools) C:\Users\Acer\Downloads\OTL-1.exe
2012-01-09 08:52 - 2012-01-09 08:52 - 2322184 ____A (ESET) C:\Users\Acer\Downloads\esetsmartinstaller_deu.exe
2012-01-09 07:41 - 2009-08-14 01:14 - 0000000 ____D C:\Program Files\Google
2012-01-09 07:07 - 2009-08-14 00:54 - 0000000 ____D C:\Program Files\Microsoft Office
2012-01-09 06:58 - 2012-01-09 06:58 - 18690352 ____A (Microsoft Corporation) C:\Users\Acer\Downloads\IE9-Windows7-x86-deu.exe
2012-01-09 06:46 - 2011-02-22 16:43 - 0000000 ____D C:\Users\Acer\AppData\Local\Google
2012-01-09 06:46 - 2009-08-14 01:14 - 0000000 ____D C:\Users\All Users\Google
2012-01-09 06:46 - 2009-08-14 01:14 - 0000000 ____D C:\ProgramData\Google
2012-01-09 06:08 - 2012-01-06 15:03 - 0000000 ____D C:\Program Files\SUPERAntiSpyware
2012-01-09 06:04 - 2009-07-13 18:37 - 0000000 ___RD C:\users\Public
2012-01-08 07:13 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\LogFiles
2012-01-07 13:38 - 2012-01-07 12:26 - 0003917 ____A C:\ipconfig.txt
2012-01-07 01:50 - 2012-01-07 01:49 - 0000000 ____D C:\Users\All Users\SUPERSetup
2012-01-07 01:50 - 2012-01-07 01:49 - 0000000 ____D C:\ProgramData\SUPERSetup
2012-01-06 15:05 - 2012-01-06 15:05 - 0000000 ____D C:\Users\Acer\AppData\Roaming\SUPERAntiSpyware.com
2012-01-06 15:03 - 2012-01-06 15:03 - 0000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-01-06 15:03 - 2012-01-06 15:03 - 0000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2012-01-06 10:50 - 2012-01-06 10:37 - 0064960 ____A C:\TDSSKiller.2.5.5.0_06.01.2012_19.37.46_log.txt
2012-01-06 10:37 - 2012-01-06 10:29 - 0064960 ____A C:\TDSSKiller.2.5.5.0_06.01.2012_19.29.26_log.txt
2012-01-06 05:39 - 2012-01-06 05:39 - 0000000 ____D C:\_OTL
2012-01-05 14:56 - 2012-01-05 14:56 - 0103440 ____A C:\Users\Acer\Downloads\OTL2012-01-05.Txt
2012-01-05 14:00 - 2012-01-05 14:00 - 0584192 ____A (OldTimer Tools) C:\Users\Acer\Desktop\OTL.exe
2012-01-05 05:21 - 2012-01-05 05:21 - 0000000 ____D C:\Program Files\ESET
2012-01-05 05:21 - 2009-07-13 20:52 - 0000000 ____D C:\Windows\Downloaded Program Files
2012-01-04 00:59 - 2012-02-18 04:01 - 12872704 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-01-04 00:58 - 2012-02-18 04:01 - 0442880 ____A (Microsoft Corporation) C:\Windows\System32\ntshrui.dll
2011-12-30 04:19 - 2011-12-30 04:19 - 0000000 ____D C:\Users\Acer\AppData\Roaming\Avira
2011-12-30 02:47 - 2011-12-30 02:47 - 0000000 ____D C:\Users\Acer\AppData\Roaming\Malwarebytes
2011-12-30 02:46 - 2011-12-30 02:46 - 0000000 ____D C:\Users\All Users\Malwarebytes
2011-12-30 02:46 - 2011-12-30 02:46 - 0000000 ____D C:\ProgramData\Malwarebytes
2011-12-29 21:27 - 2012-02-18 04:02 - 0478720 ____A (Microsoft Corporation) C:\Windows\System32\timedate.cpl
2011-12-27 09:14 - 2011-12-27 09:14 - 0000000 ____D C:\Users\Acer\AppData\Local\{115E1736-518B-4589-B5B5-F709AA32BC06}
2011-12-27 09:14 - 2011-12-27 09:14 - 0000000 ____D C:\Users\Acer\AppData\Local\{0F565D71-DE68-4225-83FB-B4D36303A680}
2011-12-24 05:02 - 2011-12-24 05:02 - 0000000 ____D C:\Users\Acer\AppData\Local\{FAA63628-9185-4ACE-A674-E50A3E857458}
2011-12-24 05:02 - 2011-12-24 05:01 - 0000000 ____D C:\Users\Acer\AppData\Local\{72DE4261-EA77-42B3-87C2-8DF7F7D32AD8}
2011-12-24 05:00 - 2011-12-24 05:00 - 0001045 ____A C:\Users\Acer\Desktop\Bilder.lnk
2011-12-21 08:31 - 2011-12-21 08:31 - 0000680 _RASH C:\Users\Acer\ntuser.pol
2011-12-21 08:31 - 2009-07-13 18:37 - 0000000 ___HD C:\Windows\System32\GroupPolicy
2011-12-21 08:15 - 2011-12-21 08:15 - 0000000 ____D C:\Users\Gast\Documents\FILSHtray
2011-12-21 08:15 - 2011-12-21 08:15 - 0000000 ____D C:\Users\Gast\AppData\Local\FILSH_Media_GmbH
2011-12-21 08:15 - 2011-08-16 01:57 - 0000000 ____D C:\Users\Gast\AppData\Local\VirtualStore
2011-12-21 08:14 - 2011-08-16 01:58 - 0068352 ____A C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT
2011-12-21 08:05 - 2011-09-08 10:43 - 0000000 ____D C:\Users\Acer\AppData\Roaming\Sony
2011-12-21 08:04 - 2011-09-08 10:46 - 0001859 ____A C:\Users\Public\Desktop\Media Go.lnk
2011-12-21 08:03 - 2011-09-08 10:46 - 0000000 ____D C:\Program Files\Common Files\Sony Shared
2011-12-21 08:01 - 2011-09-08 10:46 - 0000000 ____D C:\Users\Acer\AppData\Local\Downloaded Installations
2011-12-21 08:00 - 2011-12-21 07:52 - 0000000 ____D C:\Program Files\Sony Media Go Install
2011-12-21 08:00 - 2011-09-08 10:45 - 0000000 ____D C:\Program Files\Sony
2011-12-21 07:50 - 2011-12-21 07:44 - 94445720 ____A (Sony Creative Software Inc.) C:\Users\Acer\Downloads\mediago_setup.exe
2011-12-21 07:41 - 2011-09-08 10:50 - 0000000 ____D C:\Users\Acer\AppData\Local\Sony
2011-12-21 07:41 - 2011-09-08 10:45 - 0000000 ____D C:\Users\All Users\Sony Corporation
2011-12-21 07:41 - 2011-09-08 10:45 - 0000000 ____D C:\ProgramData\Sony Corporation
2011-12-18 10:40 - 2011-12-18 10:30 - 0000000 ____D C:\Users\Acer\Documents\Invizimals startvideo
2011-12-18 10:32 - 2011-12-18 10:32 - 0000000 ____D C:\Users\Acer\AppData\Local\{09BDA3BB-AABA-4CBB-9FBE-DC3733D68621}
2011-12-18 10:32 - 2011-12-18 10:31 - 0000000 ____D C:\Users\Acer\AppData\Local\{5CF51BF5-D3A5-42EA-B2AE-B664282FE9F6}
2011-12-15 23:52 - 2012-02-18 04:01 - 0690688 ____A (Microsoft Corporation) C:\Windows\System32\msvcrt.dll
2011-12-14 12:45 - 2011-12-14 12:45 - 0000000 ____D C:\Users\Acer\AppData\Local\{38E3FD9E-18AC-4BD7-AD71-F06A21880B91}
2011-12-14 12:45 - 2011-12-14 12:44 - 0000000 ____D C:\Users\Acer\AppData\Local\{602FBEA2-3F58-4E66-9A09-EFBA9F9B7134}
2011-12-14 10:21 - 2011-12-14 10:21 - 0000000 ____D C:\Users\Acer\AppData\Local\FILSH_Media_GmbH
2011-12-14 10:19 - 2011-12-14 10:19 - 5135327 ____A (FILSH Media GmbH                                            ) C:\Users\Acer\Documents\filsh-setup-0.7.exe
2011-12-14 04:41 - 2011-12-14 04:41 - 0000000 ____D C:\Users\Acer\AppData\Local\{EDFEB785-2DCC-4FA7-A040-80E1145A37B1}

========================= Known DLLs =========================

[2009-07-13 15:44] - [2009-07-13 17:15] - 0522240 ____A (Microsoft Corporation) C:\Windows\System32\clbcatq.dll
[2011-07-24 04:28] - [2010-11-20 04:20] - 1414144 ____A (Microsoft Corporation) C:\Windows\System32\ole32.dll
[2011-07-24 03:52] - [2010-11-20 04:18] - 0640512 ____A (Microsoft Corporation) C:\Windows\System32\advapi32.dll
[2011-07-24 03:52] - [2010-11-20 04:18] - 0485888 ____A (Microsoft Corporation) C:\Windows\System32\COMDLG32.dll
[2011-07-24 03:51] - [2010-11-20 04:19] - 0304640 ____A (Microsoft Corporation) C:\Windows\System32\gdi32.dll
[2012-02-27 16:57] - [2012-02-27 16:57] - 1792000 ____A (Microsoft Corporation) C:\Windows\System32\IERTUTIL.dll
[2011-07-24 03:48] - [2010-11-20 04:19] - 0155136 ____A (Microsoft Corporation) C:\Windows\System32\IMAGEHLP.dll
[2011-07-24 03:49] - [2010-11-20 04:19] - 0118272 ____A (Microsoft Corporation) C:\Windows\System32\IMM32.dll
[2011-08-14 00:26] - [2011-07-15 20:27] - 0868352 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
[2009-07-13 15:25] - [2009-07-13 17:15] - 0026624 ____A (Microsoft Corporation) C:\Windows\System32\LPK.dll
[2009-07-13 15:28] - [2009-07-13 17:15] - 0828928 ____A (Microsoft Corporation) C:\Windows\System32\MSCTF.dll
[2012-02-18 04:01] - [2011-12-15 23:52] - 0690688 ____A (Microsoft Corporation) C:\Windows\System32\MSVCRT.dll
[2009-07-13 15:15] - [2009-07-13 17:09] - 0002048 ____A (Microsoft Corporation) C:\Windows\System32\NORMALIZ.dll
[2009-07-13 15:12] - [2009-07-13 17:16] - 0008704 ____A (Microsoft Corporation) C:\Windows\System32\NSI.dll
[2011-10-13 11:46] - [2011-08-26 20:26] - 0571904 ____A (Microsoft Corporation) C:\Windows\System32\OLEAUT32.dll
[2009-07-13 15:15] - [2009-07-13 17:16] - 0006144 ____A (Microsoft Corporation) C:\Windows\System32\PSAPI.dll
[2011-07-24 03:52] - [2010-11-20 04:21] - 0653312 ____A (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
[2009-07-13 15:11] - [2009-07-13 17:16] - 0092160 ____A (Microsoft Corporation) C:\Windows\System32\sechost.dll
[2011-07-24 03:52] - [2010-11-20 04:21] - 1667584 ____A (Microsoft Corporation) C:\Windows\System32\Setupapi.dll
[2012-02-18 04:01] - [2012-01-04 00:59] - 12872704 ____A (Microsoft Corporation) C:\Windows\System32\SHELL32.dll
[2011-07-24 03:52] - [2010-11-20 04:21] - 0350208 ____A (Microsoft Corporation) C:\Windows\System32\SHLWAPI.dll
[2012-02-27 16:57] - [2012-02-27 16:57] - 1103360 ____A (Microsoft Corporation) C:\Windows\System32\URLMON.dll
[2011-07-24 03:52] - [2010-11-20 04:21] - 0811520 ____A (Microsoft Corporation) C:\Windows\System32\user32.dll
[2011-07-24 03:52] - [2010-11-20 04:21] - 0626176 ____A (Microsoft Corporation) C:\Windows\System32\USP10.dll
[2012-02-27 16:57] - [2012-02-27 16:57] - 1127424 ____A (Microsoft Corporation) C:\Windows\System32\WININET.dll
[2011-07-24 03:52] - [2010-11-20 04:21] - 0269824 ____A (Microsoft Corporation) C:\Windows\System32\WLDAP32.dll
[2011-07-24 03:51] - [2010-11-20 04:21] - 0206848 ____A (Microsoft Corporation) C:\Windows\System32\WS2_32.dll
[2009-07-13 15:16] - [2009-07-13 17:15] - 0315904 ____N (Microsoft Corporation) C:\Windows\System32\DifxApi.dll

========================= Bamital & volsnap Check ============

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

========================= Memory info ======================

Percentage of memory in use: 37%
Total physical RAM: 1013.95 MB
Available physical RAM: 632.31 MB
Total Pagefile: 1013.95 MB
Available Pagefile: 630.11 MB
Total Virtual: 2047.88 MB
Available Virtual: 1979.23 MB

======================= Partitions =========================

1 Drive c: (Acer) (Fixed) (Total:135.05 GB) (Free:63.97 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:12 GB) (Free:6.01 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (USB FILME) (Removable) (Total:14.91 GB) (Free:4.34 GB) NTFS
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (SYSTEM RESERVED) (Fixed) (Total:1.99 GB) (Free:1.96 GB) NTFS ==>[System with boot components (obtained from reading drive)]

  Disk ###  Status        Size    Free    Dyn  Gpt
  --------  -------------  -------  -------  ---  ---
  Disk 0    Online          149 GB      0 B       
  Disk 1    Online          14 GB      0 B       

Partitions of Disk 0:
===============

  Partition ###  Type              Size    Offset
  -------------  ----------------  -------  -------
  Partition 1    Recovery            12 GB    31 KB
  Partition 2    Primary          2039 MB    12 GB
  Partition 3    Primary            135 GB    13 GB

======================================================================================================

Disk: 0
Partition 1
Type  : 27
Hidden: Yes
Active: No

  Volume ###  Ltr  Label        Fs    Type        Size    Status    Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 2    E  PQSERVICE    NTFS  Partition    12 GB  Healthy    Hidden 

======================================================================================================

Disk: 0
Partition 2
Type  : 07
Hidden: No
Active: Yes

  Volume ###  Ltr  Label        Fs    Type        Size    Status    Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 0    Y  SYSTEM RESE  NTFS  Partition  2039 MB  Healthy           

======================================================================================================

Disk: 0
Partition 3
Type  : 07
Hidden: No
Active: No

  Volume ###  Ltr  Label        Fs    Type        Size    Status    Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 1    C  Acer        NTFS  Partition    135 GB  Healthy           

======================================================================================================

Partitions of Disk 1:
===============

  Partition ###  Type              Size    Offset
  -------------  ----------------  -------  -------
  Partition 1    Primary            14 GB  4032 KB

======================================================================================================

Disk: 1
Partition 1
Type  : 07
Hidden: No
Active: No

  Volume ###  Ltr  Label        Fs    Type        Size    Status    Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 3    F  USB FILME    NTFS  Removable    14 GB  Healthy           

======================================================================================================

==========================================================

Last Boot: 2012-03-03 15:17

======================= End Of Log ==========================


Psychotic 11.03.2012 17:54

Hallo,

die FRST-Logdatei ist ok, allerdings fehlen uns die md5-Werte!

Zitat:

Hake an: List Drivers MD5
Das darfst du nicht vergessen!

Bitte erstelle ein neues Log nach den Vorgaben.

snowly1 11.03.2012 22:40

Hallo. Ich mache frst nun noch einmal. Allerdings gibt es nur ein "Drivers MD5" und nicht "List Drivers MD5". Das hatte ich aber letztes Mal auch angekreuzt. Ich habe diesmal das Kreuz noch zusätzlich bei "List Files and Folders" rausgenommen. Hoffe diesmal hats geklappt!
Code:

Scan result of Farbar Recovery Scan Tool (FRST written by farbar) Version: 07-03-2012 01
Ran by SYSTEM at 11-03-2012 22:35:28
Running from F:\
Windows 7 Starter  (X86) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry ==========================

HKLM\...\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe [1130504 2009-06-01] (Dritek System Inc.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7600672 2009-07-06] (Realtek Semiconductor)
HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [707104 2009-08-05] (Acer Incorporated)
HKLM\...\Run: [EgisTecLiveUpdate] "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe" [199464 2009-08-03] (Egis Technology Inc.)
HKLM\...\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-08-06] (Egis Technology Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM\...\Run: [NortonOnlineBackupReminder] "C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED [588648 2009-07-24] (Symantec Corporation)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1537320 2009-06-18] (Synaptics Incorporated)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2009-09-23] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [173592 2009-09-23] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [150552 2009-09-23] (Intel Corporation)
HKLM\...\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min [281768 2011-03-29] (Avira GmbH)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [460872 2012-01-13] (Malwarebytes Corporation)
HKU\Acer\...\Run: [FreeCT] C:\Program Files\FreeCountdownTimer\FreeCountdownTimer.exe -autorun [2033488 2011-05-24] (Comfort Software Group)
HKU\Acer\...\Policies\system: [LogonHoursAction] 2
HKU\Acer\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [1174016 2010-11-20] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [1174016 2010-11-20] (Microsoft Corporation)
HKU\Gast\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe, [26624 2010-11-20] (Microsoft Corporation)
HKLM\...\Winlogon: [Shell] Explorer.exe [2616320 2011-02-24] (Microsoft Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 62.2.17.61 62.2.24.158 62.2.17.60 62.2.24.162
Lsa: [Authentication Packages] msv1_0
Lsa: [Notification Packages] scecli

========================== Services ==========================

3 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [62464 2009-07-13] (Microsoft Corporation)
3 ALG; C:\Windows\System32\alg.exe [59392 2009-07-13] (Microsoft Corporation)
2 AntiVirSchedulerService; "C:\Program Files\Avira\AntiVir Desktop\sched.exe" [136360 2011-04-30] (Avira GmbH)
2 AntiVirService; "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [269480 2011-07-24] (Avira GmbH)
3 AppIDSvc; C:\Windows\System32\appidsvc.dll [27648 2009-07-13] (Microsoft Corporation)
3 Appinfo; C:\Windows\System32\appinfo.dll [47104 2010-11-20] (Microsoft Corporation)
2 Apple Mobile Device; "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" [37664 2011-02-18] (Apple Inc.)
2 AudioEndpointBuilder; C:\Windows\System32\Audiosrv.dll [473600 2010-11-20] (Microsoft Corporation)
2 Audiosrv; C:\Windows\System32\Audiosrv.dll [473600 2010-11-20] (Microsoft Corporation)
3 AxInstSV; C:\Windows\System32\AxInstSV.dll [88064 2010-11-20] (Microsoft Corporation)
3 BDESVC; C:\Windows\System32\bdesvc.dll [76800 2009-07-13] (Microsoft Corporation)
2 BFE; C:\Windows\System32\bfe.dll [494592 2010-11-20] (Microsoft Corporation)
2 BITS; C:\Windows\System32\qmgr.dll [585728 2010-11-20] (Microsoft Corporation)
2 Bonjour Service; "C:\Program Files\Bonjour\mDNSResponder.exe" [387944 2011-07-12] (Apple Inc.)
3 Browser; C:\Windows\System32\browser.dll [102400 2010-11-20] (Microsoft Corporation)
3 bthserv; C:\Windows\System32\bthserv.dll [64512 2009-07-13] (Microsoft Corporation)
3 CertPropSvc; C:\Windows\System32\certprop.dll [67584 2010-11-20] (Microsoft Corporation)
4 clr_optimization_v2.0.50727_32; C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [66384 2009-06-10] (Microsoft Corporation)
2 clr_optimization_v4.0.30319_32; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [130384 2010-03-18] (Microsoft Corporation)
3 COMSysApp; C:\Windows\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} [7168 2009-07-13] (Microsoft Corporation)
2 CryptSvc; C:\Windows\System32\cryptsvc.dll [136192 2010-11-20] (Microsoft Corporation)
2 DcomLaunch; C:\Windows\System32\rpcss.dll [376832 2010-11-20] (Microsoft Corporation)
3 defragsvc; C:\Windows\System32\defragsvc.dll [218624 2009-07-13] (Microsoft Corporation)
2 Dhcp; C:\Windows\System32\dhcpcore.dll [254464 2010-11-20] (Microsoft Corporation)
2 Dnscache; C:\Windows\System32\dnsrslvr.dll [132608 2011-03-02] (Microsoft Corporation)
3 dot3svc; C:\Windows\System32\dot3svc.dll [214016 2010-11-20] (Microsoft Corporation)
2 DPS; C:\Windows\System32\dps.dll [144384 2010-11-20] (Microsoft Corporation)
3 EapHost; C:\Windows\System32\eapsvc.dll [98304 2009-07-13] (Microsoft Corporation)
3 EFS; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [727584 2009-08-05] (Acer Incorporated)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 EventSystem; C:\Windows\System32\es.dll [271360 2009-07-13] (Microsoft Corporation)
3 Fax; C:\Windows\System32\fxssvc.exe [523264 2010-11-20] (Microsoft Corporation)
3 fdPHost; C:\Windows\System32\fdPHost.dll [12800 2009-07-13] (Microsoft Corporation)
3 FDResPub; C:\Windows\System32\fdrespub.dll [28160 2009-07-13] (Microsoft Corporation)
2 FontCache; C:\Windows\System32\FntCache.dll [805376 2011-02-18] (Microsoft Corporation)
3 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [42856 2009-06-10] (Microsoft Corporation)
2 gpsvc; C:\Windows\System32\gpsvc.dll [593408 2010-11-20] (Microsoft Corporation)
2 Greg_Service; C:\Program Files\Acer\Registration\GregHSRW.exe [1150496 2009-06-04] (Acer Incorporated)
3 hidserv; C:\Windows\System32\hidserv.dll [49152 2009-07-13] (Microsoft Corporation)
3 hkmsvc; C:\Windows\System32\kmsvc.dll [71168 2010-11-20] (Microsoft Corporation)
3 HomeGroupListener; C:\Windows\System32\ListSvc.dll [194560 2010-11-20] (Microsoft Corporation)
3 HomeGroupProvider; C:\Windows\System32\provsvc.dll [165376 2010-11-20] (Microsoft Corporation)
2 IAANTMON; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [354840 2009-06-04] (Intel Corporation)
3 idsvc; "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" [878416 2010-11-04] (Microsoft Corporation)
2 IKEEXT; C:\Windows\System32\ikeext.dll [674304 2010-11-20] (Microsoft Corporation)
3 IPBusEnum; C:\Windows\System32\ipbusenum.dll [78848 2009-07-13] (Microsoft Corporation)
2 iphlpsvc; C:\Windows\System32\iphlpsvc.dll [499712 2010-11-20] (Microsoft Corporation)
3 iPod Service; "C:\Program Files\iPod\bin\iPodService.exe" [821096 2011-08-18] (Apple Inc.)
3 KeyIso; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 KtmRm; C:\Windows\System32\msdtckrm.dll [308736 2009-07-13] (Microsoft Corporation)
2 LanmanServer; C:\Windows\System32\srvsvc.dll [168960 2010-11-20] (Microsoft Corporation)
3 lltdsvc; C:\Windows\System32\lltdsvc.dll [189952 2009-07-13] (Microsoft Corporation)
2 lmhosts; C:\Windows\System32\lmhsvc.dll [18432 2009-07-13] (Microsoft Corporation)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [652360 2012-01-13] (Malwarebytes Corporation)
2 MMCSS; C:\Windows\System32\mmcss.dll [49664 2009-07-13] (Microsoft Corporation)
2 MpsSvc; C:\Windows\System32\mpssvc.dll [566272 2010-11-20] (Microsoft Corporation)
3 MSDTC; C:\Windows\System32\msdtc.exe [134144 2009-07-13] (Microsoft Corporation)
3 MSiSCSI; C:\Windows\System32\iscsiexe.dll [114688 2009-07-13] (Microsoft Corporation)
3 msiserver; C:\Windows\System32\msiexec.exe /V [73216 2010-11-20] (Microsoft Corporation)
2 MWLService; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [311592 2009-08-06] (Egis Technology Inc.)
3 napagent; C:\Windows\System32\qagentRT.dll [330240 2010-11-20] (Microsoft Corporation)
3 Netlogon; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 Netman; C:\Windows\System32\netman.dll [280576 2009-07-13] (Microsoft Corporation)
3 netprofm; C:\Windows\System32\netprofm.dll [360448 2009-07-13] (Microsoft Corporation)
4 NetTcpPortSharing; "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe" [128848 2010-11-04] (Microsoft Corporation)
2 NlaSvc; C:\Windows\System32\nlasvc.dll [242688 2010-11-20] (Microsoft Corporation)
2 nsi; C:\Windows\System32\nsisvc.dll [19456 2009-07-13] (Microsoft Corporation)
3 odserv; "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE" [440696 2011-07-19] (Microsoft Corporation)
3 ose; "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" [145184 2006-10-26] (Microsoft Corporation)
3 p2pimsvc; C:\Windows\System32\pnrpsvc.dll [269824 2009-07-13] (Microsoft Corporation)
3 p2psvc; C:\Windows\System32\p2psvc.dll [327680 2009-07-13] (Microsoft Corporation)
3 PcaSvc; C:\Windows\System32\pcasvc.dll [154624 2009-07-13] (Microsoft Corporation)
3 pla; C:\Windows\System32\pla.dll [1508864 2010-11-20] (Microsoft Corporation)
2 PlugPlay; C:\Windows\System32\umpnpmgr.dll [293376 2011-05-24] (Microsoft Corporation)
3 PNRPAutoReg; C:\Windows\System32\pnrpauto.dll [20480 2009-07-13] (Microsoft Corporation)
3 PNRPsvc; C:\Windows\System32\pnrpsvc.dll [269824 2009-07-13] (Microsoft Corporation)
3 PolicyAgent; C:\Windows\System32\ipsecsvc.dll [350208 2010-11-20] (Microsoft Corporation)
2 Power; C:\Windows\System32\umpo.dll [119808 2010-11-20] (Microsoft Corporation)
2 ProfSvc; C:\Windows\System32\profsvc.dll [164352 2010-11-20] (Microsoft Corporation)
3 ProtectedStorage; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 QWAVE; C:\Windows\system32\qwave.dll [210944 2009-07-13] (Microsoft Corporation)
3 RasAuto; C:\Windows\System32\rasauto.dll [90624 2009-07-13] (Microsoft Corporation)
2 RasMan; C:\Windows\System32\rasmans.dll [286208 2010-11-20] (Microsoft Corporation)
4 RemoteAccess; C:\Windows\System32\mprdim.dll [75264 2009-07-13] (Microsoft Corporation)
3 RemoteRegistry; C:\Windows\System32\regsvc.dll [112640 2009-07-13] (Microsoft Corporation)
2 RpcEptMapper; C:\Windows\System32\RpcEpMap.dll [43520 2009-07-13] (Microsoft Corporation)
3 RpcLocator; C:\Windows\System32\locator.exe [9216 2009-07-13] (Microsoft Corporation)
2 RpcSs; C:\Windows\System32\rpcss.dll [376832 2010-11-20] (Microsoft Corporation)
2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated)
2 SamSs; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 SCardSvr; C:\Windows\System32\SCardSvr.dll [132608 2009-07-13] (Microsoft Corporation)
2 Schedule; C:\Windows\System32\schedsvc.dll [750592 2010-11-20] (Microsoft Corporation)
3 SCPolicySvc; C:\Windows\System32\certprop.dll [67584 2010-11-20] (Microsoft Corporation)
3 SDRSVC; C:\Windows\System32\SDRSVC.dll [125952 2010-11-20] (Microsoft Corporation)
2 seclogon; C:\Windows\system32\seclogon.dll [21504 2009-07-13] (Microsoft Corporation)
2 SENS; C:\Windows\System32\sens.dll [49664 2009-07-13] (Microsoft Corporation)
3 SessionEnv; C:\Windows\System32\sessenv.dll [113664 2010-11-20] (Microsoft Corporation)
2 SharedAccess; C:\Windows\System32\ipnathlp.dll [300544 2009-07-13] (Microsoft Corporation)
2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [328192 2010-11-20] (Microsoft Corporation)
3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [12800 2009-07-13] (Microsoft Corporation)
2 Spooler; C:\Windows\System32\spoolsv.exe [317440 2010-11-20] (Microsoft Corporation)
2 sppsvc; C:\Windows\System32\sppsvc.exe [3179520 2010-11-20] (Microsoft Corporation)
3 sppuinotify; C:\Windows\System32\sppuinotify.dll [53760 2010-11-20] (Microsoft Corporation)
3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [162816 2009-07-13] (Microsoft Corporation)
3 SstpSvc; C:\Windows\System32\sstpsvc.dll [90112 2009-07-13] (Microsoft Corporation)
2 StiSvc; C:\Windows\System32\wiaservc.dll [463360 2010-11-20] (Microsoft Corporation)
3 swprv; C:\Windows\System32\swprv.dll [313856 2009-07-13] (Microsoft Corporation)
2 SysMain; C:\Windows\System32\sysmain.dll [1159168 2010-11-20] (Microsoft Corporation)
3 TabletInputService; C:\Windows\System32\TabSvc.dll [73216 2010-11-20] (Microsoft Corporation)
3 TapiSrv; C:\Windows\System32\tapisrv.dll [242176 2010-11-20] (Microsoft Corporation)
3 TBS; C:\Windows\System32\tbssvc.dll [55808 2009-07-13] (Microsoft Corporation)
3 TermService; C:\Windows\System32\termsrv.dll [521216 2010-11-20] (Microsoft Corporation)
2 Themes; C:\Windows\System32\themeservice.dll [37376 2009-07-13] (Microsoft Corporation)
3 THREADORDER; C:\Windows\System32\mmcss.dll [49664 2009-07-13] (Microsoft Corporation)
2 TrkWks; C:\Windows\System32\trkwks.dll [77312 2009-07-13] (Microsoft Corporation)
3 TrustedInstaller; C:\Windows\servicing\TrustedInstaller.exe [204800 2010-11-20] (Microsoft Corporation)
3 UI0Detect; C:\Windows\System32\UI0Detect.exe [35840 2009-07-13] (Microsoft Corporation)
2 Update-Service; C:\Windows\System32\UpdSvc.dll [114000 2011-11-11] (Joosoft.com GmbH)
2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [240160 2009-07-03] (Acer)
3 upnphost; C:\Windows\System32\upnphost.dll [266752 2009-07-13] (Microsoft Corporation)
2 UxSms; C:\Windows\System32\uxsms.dll [29696 2009-07-13] (Microsoft Corporation)
3 VaultSvc; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 vds; C:\Windows\System32\vds.exe [453632 2010-11-20] (Microsoft Corporation)
3 VSS; C:\Windows\System32\vssvc.exe [1025536 2010-11-20] (Microsoft Corporation)
3 W32Time; C:\Windows\System32\w32time.dll [288768 2009-07-13] (Microsoft Corporation)
3 wbengine; "C:\Windows\system32\wbengine.exe" [1203200 2010-11-20] (Microsoft Corporation)
3 WbioSrvc; C:\Windows\System32\wbiosrvc.dll [151552 2009-07-13] (Microsoft Corporation)
3 wcncsvc; C:\Windows\System32\wcncsvc.dll [276992 2010-11-20] (Microsoft Corporation)
3 WcsPlugInService; C:\Windows\System32\WcsPlugInService.dll [32768 2009-07-13] (Microsoft Corporation)
3 WdiServiceHost; C:\Windows\System32\wdi.dll [76288 2009-07-13] (Microsoft Corporation)
3 WdiSystemHost; C:\Windows\System32\wdi.dll [76288 2009-07-13] (Microsoft Corporation)
3 WebClient; C:\Windows\System32\webclnt.dll [204800 2010-11-20] (Microsoft Corporation)
3 Wecsvc; C:\Windows\System32\wecsvc.dll [147968 2009-07-13] (Microsoft Corporation)
3 wercplsupport; C:\Windows\System32\wercplsupport.dll [61440 2009-07-13] (Microsoft Corporation)
3 WerSvc; C:\Windows\System32\WerSvc.dll [65024 2009-07-13] (Microsoft Corporation)
3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Corporation)
3 WinHttpAutoProxySvc; winhttp.dll [351232 2010-11-20] (Microsoft Corporation)
2 Winmgmt; C:\Windows\System32\wbem\WMIsvc.dll [168960 2009-07-13] (Microsoft Corporation)
3 WinRM; C:\Windows\System32\WsmSvc.dll [1175040 2010-11-20] (Microsoft Corporation)
2 Wlansvc; C:\Windows\System32\wlansvc.dll [829440 2009-07-13] (Microsoft Corporation)
2 wlidsvc; "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" [1713536 2011-03-28] (Microsoft Corp.)
3 wmiApSrv; C:\Windows\System32\wbem\WmiApSrv.exe [136192 2009-07-13] (Microsoft Corporation)
3 WMPNetworkSvc; "C:\Program Files\Windows Media Player\wmpnetwk.exe" [1121792 2010-11-20] (Microsoft Corporation)
3 WPCSvc; C:\Windows\System32\wpcsvc.dll [10752 2009-07-13] (Microsoft Corporation)
3 WPDBusEnum; C:\Windows\System32\wpdbusenum.dll [85504 2010-11-20] (Microsoft Corporation)
2 wscsvc; C:\Windows\System32\wscsvc.dll [73728 2009-07-13] (Microsoft Corporation)
2 WSearch; C:\Windows\System32\SearchIndexer.exe /Embedding [427520 2011-05-03] (Microsoft Corporation)
2 wuauserv; C:\Windows\System32\wuaueng.dll [1914368 2010-11-20] (Microsoft Corporation)
2 wudfsvc; C:\Windows\System32\WUDFSvc.dll [67584 2010-11-20] (Microsoft Corporation)
3 WwanSvc; C:\Windows\System32\wwansvc.dll [185856 2009-07-13] (Microsoft Corporation)

========================== Drivers ===========================

3 1394ohci; C:\Windows\System32\drivers\1394ohci.sys [164864 2010-11-20] (Microsoft Corporation)
0 ACPI; C:\Windows\System32\drivers\ACPI.sys [274304 2010-11-20] (Microsoft Corporation)
3 AcpiPmi; C:\Windows\System32\drivers\acpipmi.sys [10240 2010-11-20] (Microsoft Corporation)
3 adp94xx; C:\Windows\System32\DRIVERS\adp94xx.sys [422976 2009-07-13] (Adaptec, Inc.)
3 adpahci; C:\Windows\System32\DRIVERS\adpahci.sys [297552 2009-07-13] (Adaptec, Inc.)
3 adpu320; C:\Windows\System32\DRIVERS\adpu320.sys [146512 2009-07-13] (Adaptec, Inc.)
1 AFD; C:\Windows\System32\drivers\afd.sys [338944 2011-04-24] (Microsoft Corporation)
3 agp440; C:\Windows\System32\drivers\agp440.sys [53312 2009-07-13] (Microsoft Corporation)
3 aic78xx; C:\Windows\System32\DRIVERS\djsvs.sys [70720 2009-07-13] (Adaptec, Inc.)
3 aliide; C:\Windows\System32\drivers\aliide.sys [14400 2009-07-13] (Acer Laboratories Inc.)
3 amdagp; C:\Windows\System32\drivers\amdagp.sys [53312 2009-07-13] (Microsoft Corporation)
3 amdide; C:\Windows\System32\drivers\amdide.sys [14912 2009-07-13] (Microsoft Corporation)
3 AmdK8; C:\Windows\System32\DRIVERS\amdk8.sys [55296 2009-07-13] (Microsoft Corporation)
3 AmdPPM; C:\Windows\System32\DRIVERS\amdppm.sys [52736 2009-07-13] (Microsoft Corporation)
3 amdsata; C:\Windows\System32\drivers\amdsata.sys [80256 2011-03-10] (Advanced Micro Devices)
3 amdsbs; C:\Windows\System32\DRIVERS\amdsbs.sys [159312 2009-07-13] (AMD Technologies Inc.)
0 amdxata; C:\Windows\System32\drivers\amdxata.sys [22400 2011-03-10] (Advanced Micro Devices)
3 AppID; C:\Windows\System32\drivers\appid.sys [50176 2010-11-20] (Microsoft Corporation)
3 arc; C:\Windows\System32\DRIVERS\arc.sys [76368 2009-07-13] (Adaptec, Inc.)
3 arcsas; C:\Windows\System32\DRIVERS\arcsas.sys [86608 2009-07-13] (Adaptec, Inc.)
3 AsyncMac; C:\Windows\System32\DRIVERS\asyncmac.sys [17920 2009-07-13] (Microsoft Corporation)
0 atapi; C:\Windows\System32\drivers\atapi.sys [21584 2009-07-13] (Microsoft Corporation)
3 athr; C:\Windows\System32\DRIVERS\athr.sys [1176064 2009-07-16] (Atheros Communications, Inc.)
2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [66616 2011-07-24] (Avira GmbH)
1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [138192 2011-07-24] (Avira GmbH)
3 b06bdrv; C:\Windows\System32\DRIVERS\bxvbdx.sys [430080 2009-07-13] (Broadcom Corporation)
3 b57nd60x; C:\Windows\System32\DRIVERS\b57nd60x.sys [229888 2009-07-13] (Broadcom Corporation)
3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl6.sys [2506232 2009-07-07] (Broadcom Corporation)
1 Beep; C:\Windows\System32\Drivers\Beep.sys [6144 2009-07-13] (Microsoft Corporation)
1 blbdrive; C:\Windows\System32\DRIVERS\blbdrive.sys [35328 2009-07-13] (Microsoft Corporation)
3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [69632 2011-02-22] (Microsoft Corporation)
3 BrFiltLo; C:\Windows\System32\DRIVERS\BrFiltLo.sys [13568 2009-07-13] (Brother Industries, Ltd.)
3 BrFiltUp; C:\Windows\System32\DRIVERS\BrFiltUp.sys [5248 2009-07-13] (Brother Industries, Ltd.)
3 BridgeMP; C:\Windows\System32\DRIVERS\bridge.sys [78336 2009-07-13] (Microsoft Corporation)
3 Brserid; C:\Windows\System32\Drivers\Brserid.sys [272128 2009-07-13] (Brother Industries Ltd.)
3 BrSerWdm; C:\Windows\System32\Drivers\BrSerWdm.sys [62336 2009-07-13] (Brother Industries Ltd.)
3 BrUsbMdm; C:\Windows\System32\Drivers\BrUsbMdm.sys [12160 2009-07-13] (Brother Industries Ltd.)
3 BrUsbSer; C:\Windows\System32\Drivers\BrUsbSer.sys [11904 2009-07-13] (Brother Industries Ltd.)
3 BTHMODEM; C:\Windows\System32\DRIVERS\bthmodem.sys [56320 2009-07-13] (Microsoft Corporation)
4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [70656 2009-07-13] (Microsoft Corporation)
1 cdrom; C:\Windows\System32\DRIVERS\cdrom.sys [108544 2010-11-20] (Microsoft Corporation)
3 circlass; C:\Windows\System32\DRIVERS\circlass.sys [37888 2009-07-13] (Microsoft Corporation)
0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-13] (Microsoft Corporation)
3 CmBatt; C:\Windows\System32\DRIVERS\CmBatt.sys [14080 2009-07-13] (Microsoft Corporation)
3 cmdide; C:\Windows\System32\drivers\cmdide.sys [15952 2009-07-13] (CMD Technology, Inc.)
0 CNG; C:\Windows\System32\Drivers\cng.sys [369352 2011-11-16] (Microsoft Corporation)
0 Compbatt; C:\Windows\System32\DRIVERS\compbatt.sys [19024 2009-07-13] (Microsoft Corporation)
3 CompositeBus; C:\Windows\System32\drivers\CompositeBus.sys [31232 2010-11-20] (Microsoft Corporation)
4 crcdisk; C:\Windows\System32\DRIVERS\crcdisk.sys [22096 2009-07-13] (Microsoft Corporation)
1 DfsC; C:\Windows\System32\Drivers\dfsc.sys [78336 2010-11-20] (Microsoft Corporation)
1 discache; C:\Windows\System32\drivers\discache.sys [32256 2009-07-13] (Microsoft Corporation)
0 Disk; C:\Windows\System32\DRIVERS\disk.sys [57424 2009-07-13] (Microsoft Corporation)
3 DKbFltr; C:\Windows\System32\DRIVERS\DKbFltr.sys [21000 2009-03-25] (Dritek System Inc.)
3 drmkaud; C:\Windows\System32\drivers\drmkaud.sys [5120 2009-07-13] (Microsoft Corporation)
3 DXGKrnl; C:\Windows\System32\drivers\dxgkrnl.sys [728448 2010-11-20] (Microsoft Corporation)
3 ebdrv; C:\Windows\System32\DRIVERS\evbdx.sys [3100160 2009-07-13] (Broadcom Corporation)
3 elxstor; C:\Windows\System32\DRIVERS\elxstor.sys [453712 2009-07-13] (Emulex)
3 ErrDev; C:\Windows\System32\drivers\errdev.sys [7168 2009-07-13] (Microsoft Corporation)
3 exfat; C:\Windows\System32\Drivers\exfat.sys [142336 2009-07-13] (Microsoft Corporation)
3 fastfat; C:\Windows\System32\Drivers\fastfat.sys [148480 2009-07-13] (Microsoft Corporation)
3 fdc; C:\Windows\System32\DRIVERS\fdc.sys [25088 2009-07-13] (Microsoft Corporation)
0 FileInfo; C:\Windows\System32\drivers\fileinfo.sys [58448 2009-07-13] (Microsoft Corporation)
3 Filetrace; C:\Windows\System32\drivers\filetrace.sys [28160 2009-07-13] (Microsoft Corporation)
3 flpydisk; C:\Windows\System32\DRIVERS\flpydisk.sys [19968 2009-07-13] (Microsoft Corporation)
0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [198208 2009-07-13] (Microsoft Corporation)
3 FsDepends; C:\Windows\System32\drivers\FsDepends.sys [46160 2009-07-13] (Microsoft Corporation)
0 Fs_Rec; C:\Windows\System32\Drivers\Fs_Rec.sys [19536 2009-07-13] (Microsoft Corporation)
0 fvevol; C:\Windows\System32\DRIVERS\fvevol.sys [194800 2010-11-20] (Microsoft Corporation)
3 gagp30kx; C:\Windows\System32\DRIVERS\gagp30kx.sys [57936 2009-07-13] (Microsoft Corporation)
3 GEARAspiWDM; C:\Windows\System32\DRIVERS\GEARAspiWDM.sys [26600 2009-05-18] (GEAR Software Inc.)
3 hcw85cir; C:\Windows\System32\drivers\hcw85cir.sys [26624 2009-07-13] (Hauppauge Computer Works, Inc.)
3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [304128 2010-11-20] (Microsoft Corporation)
3 HDAudBus; C:\Windows\System32\drivers\HDAudBus.sys [108544 2010-11-20] (Microsoft Corporation)
3 HidBatt; C:\Windows\System32\DRIVERS\HidBatt.sys [21504 2009-07-13] (Microsoft Corporation)
3 HidBth; C:\Windows\System32\DRIVERS\hidbth.sys [91136 2009-07-13] (Microsoft Corporation)
3 HidIr; C:\Windows\System32\DRIVERS\hidir.sys [37888 2009-07-13] (Microsoft Corporation)
3 HidUsb; C:\Windows\System32\drivers\hidusb.sys [24064 2010-11-20] (Microsoft Corporation)
3 HpSAMD; C:\Windows\System32\drivers\HpSAMD.sys [67152 2009-07-13] (Hewlett-Packard Company)
3 HTTP; C:\Windows\System32\drivers\HTTP.sys [513536 2010-11-20] (Microsoft Corporation)
0 hwpolicy; C:\Windows\System32\drivers\hwpolicy.sys [14208 2010-11-20] (Microsoft Corporation)
3 i8042prt; C:\Windows\System32\drivers\i8042prt.sys [80896 2009-07-13] (Microsoft Corporation)
0 iaStor; C:\Windows\System32\DRIVERS\iaStor.sys [330264 2009-06-04] (Intel Corporation)
3 iaStorV; C:\Windows\System32\drivers\iaStorV.sys [332160 2011-03-10] (Intel Corporation)
3 igfx; C:\Windows\System32\DRIVERS\igdkmd32.sys [4808192 2009-09-23] (Intel Corporation)
3 iirsp; C:\Windows\System32\DRIVERS\iirsp.sys [41040 2009-07-13] (Intel Corp./ICP vortex GmbH)
3 IntcAzAudAddService; C:\Windows\System32\drivers\RTKVHDA.sys [2657120 2009-07-06] (Realtek Semiconductor Corp.)
0 intelide; C:\Windows\System32\drivers\intelide.sys [15424 2009-07-13] (Microsoft Corporation)
3 intelppm; C:\Windows\System32\DRIVERS\intelppm.sys [53760 2009-07-13] (Microsoft Corporation)
3 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [58880 2009-07-13] (Microsoft Corporation)
3 IPMIDRV; C:\Windows\System32\drivers\IPMIDrv.sys [65536 2010-11-20] (Microsoft Corporation)
3 IPNAT; C:\Windows\System32\drivers\ipnat.sys [101888 2009-07-13] (Microsoft Corporation)
3 IRENUM; C:\Windows\System32\drivers\irenum.sys [13824 2009-07-13] (Microsoft Corporation)
3 isapnp; C:\Windows\System32\drivers\isapnp.sys [46656 2009-07-13] (Microsoft Corporation)
3 iScsiPrt; C:\Windows\System32\drivers\msiscsi.sys [233344 2010-11-20] (Microsoft Corporation)
3 kbdclass; C:\Windows\System32\drivers\kbdclass.sys [42576 2009-07-13] (Microsoft Corporation)
3 kbdhid; C:\Windows\System32\drivers\kbdhid.sys [28160 2010-11-20] (Microsoft Corporation)
0 KSecDD; C:\Windows\System32\Drivers\ksecdd.sys [67440 2011-11-16] (Microsoft Corporation)
0 KSecPkg; C:\Windows\System32\Drivers\ksecpkg.sys [134000 2011-11-16] (Microsoft Corporation)
3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [51712 2009-07-26] (Atheros Communications, Inc.)
2 lltdio; C:\Windows\System32\DRIVERS\lltdio.sys [48128 2009-07-13] (Microsoft Corporation)
3 LSI_FC; C:\Windows\System32\DRIVERS\lsi_fc.sys [95824 2009-07-13] (LSI Corporation)
3 LSI_SAS; C:\Windows\System32\DRIVERS\lsi_sas.sys [89168 2009-07-13] (LSI Corporation)
3 LSI_SAS2; C:\Windows\System32\DRIVERS\lsi_sas2.sys [54864 2009-07-13] (LSI Corporation)
3 LSI_SCSI; C:\Windows\System32\DRIVERS\lsi_scsi.sys [96848 2009-07-13] (LSI Corporation)
2 luafv; C:\Windows\System32\drivers\luafv.sys [86528 2009-07-13] (Microsoft Corporation)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [20464 2011-12-10] (Malwarebytes Corporation)
3 megasas; C:\Windows\System32\DRIVERS\megasas.sys [30800 2009-07-13] (LSI Corporation)
3 MegaSR; C:\Windows\System32\DRIVERS\MegaSR.sys [235584 2009-07-13] (LSI Corporation, Inc.)
3 Modem; C:\Windows\System32\drivers\modem.sys [31744 2009-07-13] (Microsoft Corporation)
3 monitor; C:\Windows\System32\DRIVERS\monitor.sys [23552 2009-07-13] (Microsoft Corporation)
3 mouclass; C:\Windows\System32\drivers\mouclass.sys [41552 2009-07-13] (Microsoft Corporation)
3 mouhid; C:\Windows\System32\DRIVERS\mouhid.sys [26112 2009-07-13] (Microsoft Corporation)
0 mountmgr; C:\Windows\System32\drivers\mountmgr.sys [78208 2010-11-20] (Microsoft Corporation)
3 mpio; C:\Windows\System32\drivers\mpio.sys [130432 2010-11-20] (Microsoft Corporation)
3 mpsdrv; C:\Windows\System32\drivers\mpsdrv.sys [60416 2009-07-13] (Microsoft Corporation)
3 MRxDAV; C:\Windows\System32\drivers\mrxdav.sys [115712 2010-11-20] (Microsoft Corporation)
3 mrxsmb; C:\Windows\System32\DRIVERS\mrxsmb.sys [123904 2011-04-26] (Microsoft Corporation)
3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [223744 2011-07-08] (Microsoft Corporation)
3 mrxsmb20; C:\Windows\System32\DRIVERS\mrxsmb20.sys [96768 2011-04-26] (Microsoft Corporation)
3 msahci; C:\Windows\System32\drivers\msahci.sys [28032 2010-11-20] (Microsoft Corporation)
3 msdsm; C:\Windows\System32\drivers\msdsm.sys [116096 2010-11-20] (Microsoft Corporation)
1 Msfs; C:\Windows\System32\Drivers\Msfs.sys [22528 2009-07-13] (Microsoft Corporation)
3 mshidkmdf; C:\Windows\System32\drivers\mshidkmdf.sys [4096 2009-07-13] (Microsoft Corporation)
0 msisadrv; C:\Windows\System32\drivers\msisadrv.sys [13888 2009-07-13] (Microsoft Corporation)
3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [8320 2009-07-13] (Microsoft Corporation)
3 MSPCLOCK; C:\Windows\System32\drivers\MSPCLOCK.sys [5888 2009-07-13] (Microsoft Corporation)
3 MSPQM; C:\Windows\System32\drivers\MSPQM.sys [5504 2009-07-13] (Microsoft Corporation)
3 MsRPC; C:\Windows\System32\Drivers\MsRPC.sys [162896 2009-07-13] (Microsoft Corporation)
1 mssmbios; C:\Windows\System32\drivers\mssmbios.sys [28240 2009-07-13] (Microsoft Corporation)
3 MSTEE; C:\Windows\System32\drivers\MSTEE.sys [6144 2009-07-13] (Microsoft Corporation)
3 MTConfig; C:\Windows\System32\DRIVERS\MTConfig.sys [12288 2009-07-13] (Microsoft Corporation)
0 Mup; C:\Windows\System32\Drivers\mup.sys [49728 2009-07-13] (Microsoft Corporation)
1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [18992 2009-06-02] (Egis Technology Inc.)
1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2009-06-02] (Egis Technology Inc.)
1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [60976 2009-06-02] (Egis Technology Inc.)
3 NativeWifiP; C:\Windows\System32\DRIVERS\nwifi.sys [267264 2009-07-13] (Microsoft Corporation)
0 NDIS; C:\Windows\System32\drivers\ndis.sys [712576 2010-11-20] (Microsoft Corporation)
3 NdisCap; C:\Windows\System32\DRIVERS\ndiscap.sys [27136 2009-07-13] (Microsoft Corporation)
3 NdisTapi; C:\Windows\System32\DRIVERS\ndistapi.sys [20992 2009-07-13] (Microsoft Corporation)
3 Ndisuio; C:\Windows\System32\DRIVERS\ndisuio.sys [46080 2010-11-20] (Microsoft Corporation)
3 NdisWan; C:\Windows\System32\DRIVERS\ndiswan.sys [118784 2010-11-20] (Microsoft Corporation)
3 NDProxy; C:\Windows\System32\Drivers\NDProxy.sys [48640 2010-11-20] (Microsoft Corporation)
1 NetBIOS; C:\Windows\System32\DRIVERS\netbios.sys [36352 2009-07-13] (Microsoft Corporation)
1 NetBT; C:\Windows\System32\DRIVERS\netbt.sys [187904 2010-11-20] (Microsoft Corporation)
3 nfrd960; C:\Windows\System32\DRIVERS\nfrd960.sys [44624 2009-07-13] (IBM Corporation)
1 Npfs; C:\Windows\System32\Drivers\Npfs.sys [35328 2009-07-13] (Microsoft Corporation)
1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [16896 2009-07-13] (Microsoft Corporation)
3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1211264 2011-03-10] (Microsoft Corporation)
1 Null; C:\Windows\System32\Drivers\Null.sys [4608 2009-07-13] (Microsoft Corporation)
3 nvraid; C:\Windows\System32\drivers\nvraid.sys [117120 2011-03-10] (NVIDIA Corporation)
3 nvstor; C:\Windows\System32\drivers\nvstor.sys [143744 2011-03-10] (NVIDIA Corporation)
3 nv_agp; C:\Windows\System32\drivers\nv_agp.sys [105024 2009-07-13] (Microsoft Corporation)
3 ohci1394; C:\Windows\System32\drivers\ohci1394.sys [62464 2009-07-13] (Microsoft Corporation)
3 Parport; C:\Windows\System32\DRIVERS\parport.sys [79360 2009-07-13] (Microsoft Corporation)
0 partmgr; C:\Windows\System32\drivers\partmgr.sys [56192 2010-11-20] (Microsoft Corporation)
2 Parvdm; C:\Windows\System32\DRIVERS\parvdm.sys [8704 2009-07-13] (Microsoft Corporation)
0 pci; C:\Windows\System32\drivers\pci.sys [153984 2010-11-20] (Microsoft Corporation)
3 pciide; C:\Windows\System32\drivers\pciide.sys [12368 2009-07-13] (Microsoft Corporation)
3 pcmcia; C:\Windows\System32\DRIVERS\pcmcia.sys [180288 2009-07-13] (Microsoft Corporation)
0 pcw; C:\Windows\System32\drivers\pcw.sys [43088 2009-07-13] (Microsoft Corporation)
2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [586752 2009-07-13] (Microsoft Corporation)
3 PptpMiniport; C:\Windows\System32\DRIVERS\raspptp.sys [73728 2009-07-13] (Microsoft Corporation)
3 Processor; C:\Windows\System32\DRIVERS\processr.sys [52224 2009-07-13] (Microsoft Corporation)
1 Psched; C:\Windows\System32\DRIVERS\pacer.sys [104448 2009-07-13] (Microsoft Corporation)
3 ql2300; C:\Windows\System32\DRIVERS\ql2300.sys [1383488 2009-07-13] (QLogic Corporation)
3 ql40xx; C:\Windows\System32\DRIVERS\ql40xx.sys [106064 2009-07-13] (QLogic Corporation)
3 QWAVEdrv; C:\Windows\System32\drivers\qwavedrv.sys [31744 2009-07-13] (Microsoft Corporation)
3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [11776 2009-07-13] (Microsoft Corporation)
3 RasAgileVpn; C:\Windows\System32\DRIVERS\AgileVpn.sys [49152 2009-07-13] (Microsoft Corporation)
3 Rasl2tp; C:\Windows\System32\DRIVERS\rasl2tp.sys [78848 2009-07-13] (Microsoft Corporation)
3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [77824 2009-07-13] (Microsoft Corporation)
3 RasSstp; C:\Windows\System32\DRIVERS\rassstp.sys [75264 2009-07-13] (Microsoft Corporation)
1 rdbss; C:\Windows\System32\DRIVERS\rdbss.sys [242688 2010-11-20] (Microsoft Corporation)
3 rdpbus; C:\Windows\System32\DRIVERS\rdpbus.sys [18944 2009-07-13] (Microsoft Corporation)
1 RDPCDD; C:\Windows\System32\DRIVERS\RDPCDD.sys [6656 2010-11-20] (Microsoft Corporation)
1 RDPENCDD; C:\Windows\System32\drivers\rdpencdd.sys [6656 2009-07-13] (Microsoft Corporation)
1 RDPREFMP; C:\Windows\System32\drivers\rdprefmp.sys [7168 2009-07-13] (Microsoft Corporation)
3 RDPWD; C:\Windows\System32\Drivers\RDPWD.sys [183808 2010-11-20] (Microsoft Corporation)
0 rdyboost; C:\Windows\System32\drivers\rdyboost.sys [173440 2010-11-20] (Microsoft Corporation)
2 rspndr; C:\Windows\System32\DRIVERS\rspndr.sys [60928 2009-07-13] (Microsoft Corporation)
3 RSUSBSTOR; C:\Windows\System32\Drivers\RtsUStor.sys [167424 2009-06-23] (Realtek Semiconductor Corp.)
3 sbp2port; C:\Windows\System32\drivers\sbp2port.sys [85376 2010-11-20] (Microsoft Corporation)
3 scfilter; C:\Windows\System32\DRIVERS\scfilter.sys [26624 2010-11-20] (Microsoft Corporation)
2 secdrv; C:\Windows\System32\Drivers\secdrv.sys [20480 2009-07-13] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
3 Serenum; C:\Windows\System32\DRIVERS\serenum.sys [17920 2009-07-13] (Microsoft Corporation)
3 Serial; C:\Windows\System32\DRIVERS\serial.sys [83456 2009-07-13] (Microsoft Corporation)
3 sermouse; C:\Windows\System32\DRIVERS\sermouse.sys [19968 2009-07-13] (Microsoft Corporation)
3 sffdisk; C:\Windows\System32\drivers\sffdisk.sys [11264 2009-07-13] (Microsoft Corporation)
3 sffp_mmc; C:\Windows\System32\drivers\sffp_mmc.sys [12288 2009-07-13] (Microsoft Corporation)
3 sffp_sd; C:\Windows\System32\drivers\sffp_sd.sys [12800 2010-11-20] (Microsoft Corporation)
3 sfloppy; C:\Windows\System32\DRIVERS\sfloppy.sys [13824 2009-07-13] (Microsoft Corporation)
3 sisagp; C:\Windows\System32\drivers\sisagp.sys [52304 2009-07-13] (Microsoft Corporation)
3 SiSRaid2; C:\Windows\System32\DRIVERS\SiSRaid2.sys [40016 2009-07-13] (Silicon Integrated Systems Corp.)
3 SiSRaid4; C:\Windows\System32\DRIVERS\sisraid4.sys [77888 2009-07-13] (Silicon Integrated Systems)
3 Smb; C:\Windows\System32\DRIVERS\smb.sys [71168 2009-07-13] (Microsoft Corporation)
0 spldr; C:\Windows\System32\Drivers\spldr.sys [17472 2009-07-13] (Microsoft Corporation)
3 srv; C:\Windows\System32\DRIVERS\srv.sys [311808 2011-04-28] (Microsoft Corporation)
3 srv2; C:\Windows\System32\DRIVERS\srv2.sys [310272 2011-04-28] (Microsoft Corporation)
3 srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [114688 2011-04-28] (Microsoft Corporation)
1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-05-11] (Avira GmbH)
3 stexstor; C:\Windows\System32\DRIVERS\stexstor.sys [21072 2009-07-13] (Promise Technology)
3 swenum; C:\Windows\System32\drivers\swenum.sys [12240 2009-07-13] (Microsoft Corporation)
3 SynTP; C:\Windows\System32\DRIVERS\SynTP.sys [212400 2009-06-18] (Synaptics Incorporated)
0 Tcpip; C:\Windows\System32\drivers\tcpip.sys [1290608 2011-09-29] (Microsoft Corporation)
3 TCPIP6; C:\Windows\System32\DRIVERS\tcpip.sys [1290608 2011-09-29] (Microsoft Corporation)
2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [35328 2010-11-20] (Microsoft Corporation)
3 TDPIPE; C:\Windows\System32\drivers\tdpipe.sys [18432 2010-11-20] (Microsoft Corporation)
3 TDTCP; C:\Windows\System32\drivers\tdtcp.sys [24576 2010-11-20] (Microsoft Corporation)
1 tdx; C:\Windows\System32\DRIVERS\tdx.sys [74752 2010-11-20] (Microsoft Corporation)
1 TermDD; C:\Windows\System32\drivers\termdd.sys [53120 2010-11-20] (Microsoft Corporation)
3 tssecsrv; C:\Windows\System32\DRIVERS\tssecsrv.sys [31232 2010-11-20] (Microsoft Corporation)
3 TsUsbFlt; C:\Windows\System32\drivers\tsusbflt.sys [52224 2010-11-20] (Microsoft Corporation)
3 tunnel; C:\Windows\System32\DRIVERS\tunnel.sys [108544 2010-11-20] (Microsoft Corporation)
3 uagp35; C:\Windows\System32\DRIVERS\uagp35.sys [55888 2009-07-13] (Microsoft Corporation)
4 udfs; C:\Windows\System32\DRIVERS\udfs.sys [246784 2010-11-20] (Microsoft Corporation)
3 uliagpkx; C:\Windows\System32\drivers\uliagpkx.sys [57424 2009-07-13] (Microsoft Corporation)
3 umbus; C:\Windows\System32\drivers\umbus.sys [39936 2010-11-20] (Microsoft Corporation)
3 UmPass; C:\Windows\System32\DRIVERS\umpass.sys [8192 2009-07-13] (Microsoft Corporation)
3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [42496 2011-05-09] (Apple, Inc.)
3 usbaudio; C:\Windows\System32\drivers\usbaudio.sys [80768 2010-11-20] (Microsoft Corporation)
3 usbccgp; C:\Windows\System32\DRIVERS\usbccgp.sys [75776 2011-03-24] (Microsoft Corporation)
3 usbcir; C:\Windows\System32\drivers\usbcir.sys [86016 2009-07-13] (Microsoft Corporation)
3 usbehci; C:\Windows\System32\DRIVERS\usbehci.sys [43008 2011-03-24] (Microsoft Corporation)
3 usbhub; C:\Windows\System32\DRIVERS\usbhub.sys [258560 2011-03-24] (Microsoft Corporation)
3 usbohci; C:\Windows\System32\drivers\usbohci.sys [20480 2011-03-24] (Microsoft Corporation)
3 usbprint; C:\Windows\System32\DRIVERS\usbprint.sys [19968 2009-07-13] (Microsoft Corporation)
3 USBSTOR; C:\Windows\System32\DRIVERS\USBSTOR.SYS [76288 2011-03-10] (Microsoft Corporation)
3 usbuhci; C:\Windows\System32\DRIVERS\usbuhci.sys [24064 2011-03-24] (Microsoft Corporation)
3 usbvideo; C:\Windows\System32\Drivers\usbvideo.sys [146432 2010-11-20] (Microsoft Corporation)
0 vdrvroot; C:\Windows\System32\drivers\vdrvroot.sys [32832 2009-07-13] (Microsoft Corporation)
3 vga; C:\Windows\System32\DRIVERS\vgapnp.sys [26112 2009-07-13] (Microsoft Corporation)
1 VgaSave; C:\Windows\System32\drivers\vga.sys [25088 2009-07-13] (Microsoft Corporation)
3 vhdmp; C:\Windows\System32\drivers\vhdmp.sys [160128 2010-11-20] (Microsoft Corporation)
3 viaagp; C:\Windows\System32\drivers\viaagp.sys [53328 2009-07-13] (Microsoft Corporation)
3 ViaC7; C:\Windows\System32\DRIVERS\viac7.sys [52736 2009-07-13] (Microsoft Corporation)
3 viaide; C:\Windows\System32\drivers\viaide.sys [16976 2009-07-13] (VIA Technologies, Inc.)
0 volmgr; C:\Windows\System32\drivers\volmgr.sys [53120 2010-11-20] (Microsoft Corporation)
0 volmgrx; C:\Windows\System32\drivers\volmgrx.sys [297040 2009-07-13] (Microsoft Corporation)
0 volsnap; C:\Windows\System32\drivers\volsnap.sys [245632 2010-11-20] (Microsoft Corporation)
3 vsmraid; C:\Windows\System32\DRIVERS\vsmraid.sys [141904 2009-07-13] (VIA Technologies Inc.,Ltd)
3 vwifibus; C:\Windows\System32\DRIVERS\vwifibus.sys [19968 2009-07-13] (Microsoft Corporation)
1 vwififlt; C:\Windows\System32\DRIVERS\vwififlt.sys [48128 2009-07-13] (Microsoft Corporation)
3 WacomPen; C:\Windows\System32\DRIVERS\wacompen.sys [21632 2009-07-13] (Microsoft Corporation)
3 WANARP; C:\Windows\System32\DRIVERS\wanarp.sys [63488 2010-11-20] (Microsoft Corporation)
1 Wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [63488 2010-11-20] (Microsoft Corporation)
3 Wd; C:\Windows\System32\DRIVERS\wd.sys [19024 2009-07-13] (Microsoft Corporation)
0 Wdf01000; C:\Windows\System32\drivers\Wdf01000.sys [445008 2009-07-13] (Microsoft Corporation)
1 WfpLwf; C:\Windows\System32\DRIVERS\wfplwf.sys [9728 2009-07-13] (Microsoft Corporation)
3 WIMMount; C:\Windows\System32\drivers\wimmount.sys [19008 2009-07-13] (Microsoft Corporation)
3 WinUsb; C:\Windows\System32\DRIVERS\WinUsb.sys [35968 2010-11-20] (Microsoft Corporation)
3 WmiAcpi; C:\Windows\System32\drivers\wmiacpi.sys [11264 2009-07-13] (Microsoft Corporation)
1 ws2ifsl; C:\Windows\System32\drivers\ws2ifsl.sys [16384 2009-07-13] (Microsoft Corporation)
3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [92672 2010-11-20] (Microsoft Corporation)
3 WUDFRd; C:\Windows\System32\DRIVERS\WUDFRd.sys [132224 2010-11-20] (Microsoft Corporation)
3 catchme; \??\C:\Users\Acer\AppData\Local\Temp\catchme.sys [x]
3 CFcatchme; \??\C:\Users\Acer\AppData\Local\Temp\CFcatchme.sys [x]
3 RtsUIR; C:\Windows\System32\DRIVERS\Rts516xIR.sys [x]
3 USBCCID; C:\Windows\System32\DRIVERS\RtsUCcid.sys [x]

========================== NetSvcs (Whitelisted) ===========

========================= Known DLLs =========================

[2009-07-13 15:44] - [2009-07-13 17:15] - 0522240 ____A (Microsoft Corporation) C:\Windows\System32\clbcatq.dll
[2011-07-24 04:28] - [2010-11-20 04:20] - 1414144 ____A (Microsoft Corporation) C:\Windows\System32\ole32.dll
[2011-07-24 03:52] - [2010-11-20 04:18] - 0640512 ____A (Microsoft Corporation) C:\Windows\System32\advapi32.dll
[2011-07-24 03:52] - [2010-11-20 04:18] - 0485888 ____A (Microsoft Corporation) C:\Windows\System32\COMDLG32.dll
[2011-07-24 03:51] - [2010-11-20 04:19] - 0304640 ____A (Microsoft Corporation) C:\Windows\System32\gdi32.dll
[2012-02-27 16:57] - [2012-02-27 16:57] - 1792000 ____A (Microsoft Corporation) C:\Windows\System32\IERTUTIL.dll
[2011-07-24 03:48] - [2010-11-20 04:19] - 0155136 ____A (Microsoft Corporation) C:\Windows\System32\IMAGEHLP.dll
[2011-07-24 03:49] - [2010-11-20 04:19] - 0118272 ____A (Microsoft Corporation) C:\Windows\System32\IMM32.dll
[2011-08-14 00:26] - [2011-07-15 20:27] - 0868352 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
[2009-07-13 15:25] - [2009-07-13 17:15] - 0026624 ____A (Microsoft Corporation) C:\Windows\System32\LPK.dll
[2009-07-13 15:28] - [2009-07-13 17:15] - 0828928 ____A (Microsoft Corporation) C:\Windows\System32\MSCTF.dll
[2012-02-18 04:01] - [2011-12-15 23:52] - 0690688 ____A (Microsoft Corporation) C:\Windows\System32\MSVCRT.dll
[2009-07-13 15:15] - [2009-07-13 17:09] - 0002048 ____A (Microsoft Corporation) C:\Windows\System32\NORMALIZ.dll
[2009-07-13 15:12] - [2009-07-13 17:16] - 0008704 ____A (Microsoft Corporation) C:\Windows\System32\NSI.dll
[2011-10-13 11:46] - [2011-08-26 20:26] - 0571904 ____A (Microsoft Corporation) C:\Windows\System32\OLEAUT32.dll
[2009-07-13 15:15] - [2009-07-13 17:16] - 0006144 ____A (Microsoft Corporation) C:\Windows\System32\PSAPI.dll
[2011-07-24 03:52] - [2010-11-20 04:21] - 0653312 ____A (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
[2009-07-13 15:11] - [2009-07-13 17:16] - 0092160 ____A (Microsoft Corporation) C:\Windows\System32\sechost.dll
[2011-07-24 03:52] - [2010-11-20 04:21] - 1667584 ____A (Microsoft Corporation) C:\Windows\System32\Setupapi.dll
[2012-02-18 04:01] - [2012-01-04 00:59] - 12872704 ____A (Microsoft Corporation) C:\Windows\System32\SHELL32.dll
[2011-07-24 03:52] - [2010-11-20 04:21] - 0350208 ____A (Microsoft Corporation) C:\Windows\System32\SHLWAPI.dll
[2012-02-27 16:57] - [2012-02-27 16:57] - 1103360 ____A (Microsoft Corporation) C:\Windows\System32\URLMON.dll
[2011-07-24 03:52] - [2010-11-20 04:21] - 0811520 ____A (Microsoft Corporation) C:\Windows\System32\user32.dll
[2011-07-24 03:52] - [2010-11-20 04:21] - 0626176 ____A (Microsoft Corporation) C:\Windows\System32\USP10.dll
[2012-02-27 16:57] - [2012-02-27 16:57] - 1127424 ____A (Microsoft Corporation) C:\Windows\System32\WININET.dll
[2011-07-24 03:52] - [2010-11-20 04:21] - 0269824 ____A (Microsoft Corporation) C:\Windows\System32\WLDAP32.dll
[2011-07-24 03:51] - [2010-11-20 04:21] - 0206848 ____A (Microsoft Corporation) C:\Windows\System32\WS2_32.dll
[2009-07-13 15:16] - [2009-07-13 17:15] - 0315904 ____N (Microsoft Corporation) C:\Windows\System32\DifxApi.dll

========================= Bamital & volsnap Check ============

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

========================= Memory info ======================

Percentage of memory in use: 37%
Total physical RAM: 1013.95 MB
Available physical RAM: 638.6 MB
Total Pagefile: 1013.95 MB
Available Pagefile: 633.75 MB
Total Virtual: 2047.88 MB
Available Virtual: 1979.23 MB

======================= Partitions =========================

1 Drive c: (Acer) (Fixed) (Total:135.05 GB) (Free:63.72 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:12 GB) (Free:6.01 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (USB FILME) (Removable) (Total:14.91 GB) (Free:4.34 GB) NTFS
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (SYSTEM RESERVED) (Fixed) (Total:1.99 GB) (Free:1.96 GB) NTFS ==>[System with boot components (obtained from reading drive)]

  Disk ###  Status        Size    Free    Dyn  Gpt
  --------  -------------  -------  -------  ---  ---
  Disk 0    Online          149 GB      0 B       
  Disk 1    Online          14 GB      0 B       

Partitions of Disk 0:
===============

  Partition ###  Type              Size    Offset
  -------------  ----------------  -------  -------
  Partition 1    Recovery            12 GB    31 KB
  Partition 2    Primary          2039 MB    12 GB
  Partition 3    Primary            135 GB    13 GB

======================================================================================================

Disk: 0
Partition 1
Type  : 27
Hidden: Yes
Active: No

  Volume ###  Ltr  Label        Fs    Type        Size    Status    Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 2    E  PQSERVICE    NTFS  Partition    12 GB  Healthy    Hidden 

======================================================================================================

Disk: 0
Partition 2
Type  : 07
Hidden: No
Active: Yes

  Volume ###  Ltr  Label        Fs    Type        Size    Status    Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 0    Y  SYSTEM RESE  NTFS  Partition  2039 MB  Healthy           

======================================================================================================

Disk: 0
Partition 3
Type  : 07
Hidden: No
Active: No

  Volume ###  Ltr  Label        Fs    Type        Size    Status    Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 1    C  Acer        NTFS  Partition    135 GB  Healthy           

======================================================================================================

Partitions of Disk 1:
===============

  Partition ###  Type              Size    Offset
  -------------  ----------------  -------  -------
  Partition 1    Primary            14 GB  4032 KB

======================================================================================================

Disk: 1
Partition 1
Type  : 07
Hidden: No
Active: No

  Volume ###  Ltr  Label        Fs    Type        Size    Status    Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 3    F  USB FILME    NTFS  Removable    14 GB  Healthy           

======================================================================================================

==========================================================

Last Boot: 2012-03-10 06:15

======================= End Of Log ==========================


Psychotic 11.03.2012 23:20

Wann wurde diese Software installiert?

Zitat:

EgisTec\MyWinLocker 3

snowly1 11.03.2012 23:37

Unter Programme steht: Installiert am 14.08.2009. Was ist das genau? Hat das damit zu tun, dass einige Ordner mit einem Schloss gekennzeichnet sind und nicht mehr geöffnet werden können? Kann man dieses Programm löschen?

Psychotic 12.03.2012 10:26

Genau dafür ist der Winlocker da, ja! ;)
Der ist auf manchen Notebooks von vorneherein drauf...

Manche Ordner auf deiner Festplatte sind für den Zugriff des normalen Users gesperrt (und tragen deshalb das Schloß). Meist beinhalten sie wichtige Systemdateien.

Die Experten arbeiten grade an einer Lösung - auf deinem System ist nämlich noch nicht alles so, wie es sein sollte!

snowly1 13.03.2012 13:34

Hallo. Ich hatte gestern direkt auf dem Outlook Deine E-Mail beantwortet. Das hat wohl nicht geklappt. Ich wollte nur fragen, ob ich dieses Programm aus dem Startmenu entfernen kann? (Winlocker 3?) Danke für Eure Hilfe.

Psychotic 13.03.2012 13:37

Warte erst einmal ab, bevor du etwas am System änderst.

Die Mails sind im übrigen ausschließlich Benachrichtigungen - darauf zu antworten macht keinen Sinn, da die Antworten ins Leere laufen. Steht aber so auch in jeder Email!

;)

Psychotic 13.03.2012 22:51

Schritt 1: CF-Script


Hinweis für Mitleser:
Folgendes ComboFix Skript ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

Lösche die vorhandene Combofix.exe von deinem Desktop und lade das Programm von einem der folgenden Download-Spiegel neu herunter:
BleepingComputer.com - ForoSpyware.com
und speichere es erneut auf dem Desktop (nicht woanders hin, das ist wichtig)!

Drücke die Windows + R Taste --> Notepad (hinein schreiben) --> OK

Kopiere nun den Text aus der folgenden Codebox komplett in das leere Textdokument.
Code:

DRIVER::
Update-Service

ROOTKIT::
C:\Windows\System32\UpdSvc.dll
C:\Windows\System32\aptw2s8pj.dll

Speichere dies als CFScript.txt auf Deinem Desktop.

Wichtig:
  • Stelle deine Anti Viren Software temprär ab. Dies kann ComboFix nämlich bei der Arbeit behindern.
    Danach wieder anstellen nicht vergessen!
  • Bewege nicht die Maus über das ComboFix-Fenster oder klicke in dieses hinein.
    Dies kann dazu führen, dass ComboFix sich aufhängt.
  • Schließe alle laufenden Programme. Gehe sicher das ComboFix ungehindert arbeiten kann.
  • Mache nichts am PC solange ComboFix läuft.
http://i266.photobucket.com/albums/i.../CFScriptB.gif
  • In Bezug auf obiges Bild, ziehe CFScript.txt in die ComboFix.exe
  • Wenn ComboFix fertig ist, wird es ein Log erstellen, C:\ComboFix.txt. Bitte füge es hier als Antwort ein.
Falls im Skript die Anweisung Suspect:: oder Collect:: enthalten ist, wird eine Message-Box erscheinen, nachdem Combofix fertig ist. Klicke OK und folge den Aufforderungen/Anweisungen, um die Dateien hochzuladen.



Schritt 2: GMER


Bitte
  • alle anderen Scanner gegen Viren, Spyware, usw. deaktivieren,
  • keine bestehende Verbindung zu einem Netzwerk/Internet (WLAN nicht vergessen),
  • nichts am Rechner arbeiten,
  • nach jedem Scan der Rechner neu gestarten.
Gmer scannen lassen
  • Lade Dir Gmer von dieser Seite herunter (auf den Button Download EXE drücken) und das Programm auf dem Desktop speichern.
  • Alle anderen Programme sollen geschlossen sein.
  • Starte gmer.exe (Programm hat einen willkürlichen Programm-Namen). Vista und Win7 User mit Rechtsklick und als Administrator starten.
  • Sollte sich ein Fenster mit folgender Warnung öffnen:
    WARNING !!! GMER has found system modification, which might have been caused by ROOTKIT activity. Do you want to fully scan your system ?
    Unbedingt auf "No" klicken.
  • Entferne rechts den Haken bei:
    • IAT/EAT
    • Alle Festplatten ausser die Systemplatte (normalerweise ist nur C:\ angehackt)
    • Show all (sollte abgehackt sein)
  • Starte den Scan mit "Scan". Mache nichts am Computer während der Scan läuft.
  • Wenn der Scan fertig ist klicke auf Save und speichere die Logfile unter Gmer.txt auf deinem Desktop. Mit "Ok" wird GMER beendet.
Antiviren-Programm und sonstige Scanner wieder einschalten, bevor Du ins Netz gehst!

snowly1 14.03.2012 19:51

Hallo Marius. Als wir heute das Netbook aufgestartet haben, konnten wir kein Programm starten, der PC hängte sich auf. Neu gestartet, da kam Virusmeldung von Avira, wieder genau in der gleichen Datei wie in meinem Eröffnungsbeitrag! Derselbe Virus Zpack.gen2 Wieder keine Windows Dienste und kein Internet. Konnte im abgesicherten Modus die Systemwiederherstellung auf den 07.03. zurücksetzen. Nun wird der Virus wieder angezeigt, habe ihn aber nicht mehr entfernt. Was muss ich nun tun? Da scheint wirklich irgend etwas gar nicht zu stimmen...

Psychotic 14.03.2012 19:59

Ja, da ist irgendwas ganz und gar faul!

Bereinigung würde hier zu keinem vertrauenswürdigen Ergebnis führen.
Du solltest den Rechner formatieren, neu aufsetzen und absichern.

Hier können wir dir leider nicht anders helfen! :(

snowly1 15.03.2012 00:25

Ja, das werde ich wohl mal versuchen müssen, wenn ich Zeit habe. Nur mit den Treibern habe ich keine Erfahrung. Hab mal im Internet geschaut aber für mein Netbook unter "Acer" nichts gefunden. Meins scheint nicht aufgeführt zu sein. Weisst Du, wie ich an die richtigen Treiber komme und welche ich brauche?
Und du hast mir noch sagen wollen, welches Antivirusprogramm ich nehmen soll, weil das Antivir nicht so gut sei. Hast Du einen Tipp? Danke!

Psychotic 15.03.2012 07:47

Waren bei dem Rechner keine Datenträger mit den Treibern dabei? :wtf:

Ansonsten: Wenn Win7 bei der Installation über eine funktionierende Internetverbindung verfügt, holt es sich die fehlenden Treiber über Microsoft Update, spätestens beim ersten Updatelauf.

Ansonsten hat der Rechner unten drauf eine Seriennummer, über diese und die ebenfalls dort stehende Modellreihe findest du im Internet alles, was du brauchst.


Antivirusprogramme:


Antivirenprogramme sind kein Allheilmittel für alle Gefahren - sie können lediglich als eine Art Sicherheitsgurt fungieren. Demzufolge ist es relativ egal, welches Produkt du einsetzt.

Eine gute Alternative zu Antivir ist Avast!.

Psychotic 19.03.2012 07:59

Dieses Thema scheint erledigt und wurde aus meinen Abos gelöscht.
Solltest du das Thema erneut brauchen, schicke mir bitte eine PM.

Jeder andere bitte hier klicken und ein eigenes Thema erstellen!


Alle Zeitangaben in WEZ +1. Es ist jetzt 13:21 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129