Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Nach Trojaner-Befall -> PC unglaublich langsam (https://www.trojaner-board.de/113333-trojaner-befall-pc-unglaublich-langsam.html)

dirknik 09.04.2012 15:16

Nach Trojaner-Befall -> PC unglaublich langsam
 
Hallo liebe Foren-Mitglieder :-)

Habe meinen PC, der ohnehin nicht gerade der schnellste ist, mit Malwarebytes gescannt und dabei ein Haufen Trojaner und Spyware entdeckt, die Antivir anscheinend schon seit Jahren nicht bemerkt hatte. Ich schätze durch diesen Trojanerbefall ist mein PC ziemlich in Mitleidenschaft gezogen worden und jetzt noch lahmer als jemals zuvor... Habe bereits die Trojaner beseitigt und Ccleaner durchlaufen lassen sowie defragmentiert, aber der PC wird nicht schneller. Wollte wissen, ob es wirklich nur an der Spyware liegen kann, dass der PC so langsam ist. Vielen Dank im Voraus :-)

Hier schon mal das Log-file von Malwarebytes:


Malwarebytes Anti-Malware (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.06.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
*** :: IBM-5D34BDAD641 [Administrator]

Schutz: Aktiviert

06.04.2012 13:23:15
mbam-log-2012-04-06 (13-23-15).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 260086
Laufzeit: 1 Stunde(n), 34 Minute(n), 29 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 7
HKCR\BookedSpace.Extension (Adware.BookedSpace) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\WUSN.1 (Adware.WhenU) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Bookedspace (Adware.BookedSpace) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\NetPumper (Adware.NetPumper) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\webhancer (Adware.WebHancer) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5 (Trojan.AntiLeechPlugin) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\System\CurrentControlSet\Services\Windows Overlay Components (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Daten: 0 -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 1
C:\Dokumente und Einstellungen\***\Anwendungsdaten\NetPumper (Adware.NetPumper) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien: 5
C:\WINDOWS\system32\model.dat (PUP.Spyware.MarketScore) -> Keine Aktion durchgeführt.
C:\WINDOWS\system32\SDRunner.dll (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\WINDOWS\Uninst2.htm (Malware.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\WINDOWS\Unist1.htm (Malware.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Dokumente und Einstellungen\***\Anwendungsdaten\NetPumper\***_20***.ini (Adware.NetPumper) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

cosinus 09.04.2012 17:46

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

dirknik 10.04.2012 12:10

Hallo cosinus :-)

Danke für deine Hilfe! Ich habe erst seit ein paar Tagen Malwarebytes runtergeladen und den PC gescannt. Außer dem bereits geposteten gibt es nur noch einen Log:

Malwarebytes Anti-Malware (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.06.03

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
*** :: IBM-5D34BDAD641 [Administrator]

Schutz: Aktiviert

06.04.2012 15:47:28
mbam-log-2012-04-06 (15-47-28).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 259818
Laufzeit: 1 Stunde(n), 53 Minute(n), 48 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\WINDOWS\system32\model.dat (PUP.Spyware.MarketScore) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


Ich kann aber natürlich nochmal scannen.

cosinus 10.04.2012 14:05

Führ bitte auch ESET aus, danach sehen wir weiter:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


dirknik 10.04.2012 21:29

Der eset-scanner hat anscheinend was gefunden:


ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=c187bd05b2a4d4418e3866a639cef36e
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-04-10 08:04:01
# local_time=2012-04-10 10:04:01 (+0100, Westeuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=1797 16775129 100 93 355582 70611494 261713 0
# compatibility_mode=8192 67108863 100 0 194 194 0 0
# scanned=71583
# found=1
# cleaned=0
# scan_time=13615
C:\WINDOWS\system32\ic2_win.dll a variant of Win32/Adware.Toolbar.ILookup.AA application (unable to clean) 00000000000000000000000000000000 I

cosinus 11.04.2012 12:44

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

dirknik 11.04.2012 15:12

Der normale Modus geht soweit uneingeschränkt nur, dass es mindestens 20 Min. dauert bis ich irgendetwas machen kann, nachdem der PC hochgefahren ist. Im Autostart hab ich bereits alle Programm, die unnötig sind deaktiviert und trotzdem dauert es ewig. Ich denke es liegt an der ganzen Schadsoftware, die Malwarebytes gefunden hat.

Unter alle Programm sind noch einige leere Ordner vom alten Microsoft Office 2000 und vom AdobeReader 7.0. Aber das sind Programme, die ich durch aufgrund der neueren Versionen deinstalliert habe. Das sind vermutl. die Überreste. Es fehlt also nichts.

cosinus 11.04.2012 15:40

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


dirknik 11.04.2012 16:42

so hier das Log:

Code:

OTL logfile created on: 11.04.2012 17:01:22 - Run 1
OTL by OldTimer - Version 3.2.39.2    Folder = C:\Dokumente und Einstellungen\***\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
246,98 Mb Total Physical Memory | 116,05 Mb Available Physical Memory | 46,99% Memory free
933,29 Mb Paging File | 574,60 Mb Available in Paging File | 61,57% Paging File free
Paging file location(s): C:\pagefile.sys 700 744 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 33,58 Gb Total Space | 8,98 Gb Free Space | 26,73% Space Free | Partition Type: NTFS
 
Computer Name: IBM-5D34BDAD641 | User Name: Marc Nikolaus | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.04.11 16:54:41 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\***\Desktop\OTL.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011.06.30 17:43:08 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.04.29 08:18:10 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2010.11.02 15:09:04 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.03.04 23:38:00 | 000,071,096 | ---- | M] () -- C:\Programme\CDBurnerXP\NMSAccessU.exe
PRC - [2010.01.14 22:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2008.04.14 04:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004.03.19 23:21:10 | 000,339,968 | ---- | M] () -- C:\Programme\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2010.03.04 23:38:00 | 000,071,096 | ---- | M] () -- C:\Programme\CDBurnerXP\NMSAccessU.exe
MOD - [2010.01.28 13:57:53 | 000,355,688 | ---- | M] () -- C:\Programme\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2007.07.29 18:56:54 | 000,051,716 | ---- | M] () -- C:\WINDOWS\system32\pdf995mon.dll
MOD - [2004.12.26 21:34:38 | 000,121,344 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2004.07.20 17:04:02 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\TosBtHcrpAPI.dll
MOD - [2004.03.19 23:21:10 | 000,339,968 | ---- | M] () -- C:\Programme\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
MOD - [2004.03.19 22:12:10 | 000,045,056 | ---- | M] () -- C:\WINDOWS\system32\pwdmon.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012.04.06 15:42:51 | 000,253,600 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.07.20 06:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2011.06.30 17:43:08 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.29 08:18:10 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.03.04 23:38:00 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Programme\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)
SRV - [2006.10.26 15:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2006.09.05 15:57:56 | 000,024,072 | ---- | M] (TuneUp Software GmbH) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2005.04.04 00:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2004.03.19 23:21:10 | 000,339,968 | ---- | M] () [Auto | Running] -- C:\Programme\IBM\IBM Rapid Restore Ultra\rrpcsb.exe -- (IBM Rapid Restore Ultra Service)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SipIMNDI.sys -- (SipIMNDI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\PCDRSRVC.pkms -- (PCDRSRVC)
DRV - File not found [Kernel | System | Stopped] -- system32\DRIVERS\obvious.sys -- (obvious)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\delprot.sys -- (delprot)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - File not found [Kernel | System | Stopped] --  -- (Aspi32)
DRV - [2012.04.10 13:09:16 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011.06.30 17:43:10 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.06.30 17:43:10 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009.11.12 14:48:56 | 000,005,504 | ---- | M] () [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009.05.11 12:49:19 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009.05.11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2008.04.13 20:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2007.04.13 17:53:25 | 000,115,000 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2007.02.18 12:18:13 | 000,223,128 | ---- | M] (Alcohol Soft Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vaxscsi.sys -- (vaxscsi)
DRV - [2007.02.18 12:15:55 | 000,611,064 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2006.09.12 14:25:56 | 000,165,376 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2006.09.12 14:25:55 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2006.07.31 12:13:51 | 000,223,128 | ---- | M] (DT Soft Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dtscsi.sys -- (dtscsi)
DRV - [2006.01.25 15:26:26 | 000,014,336 | ---- | M] (RapidSolution Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2005.03.14 07:01:38 | 000,041,984 | ---- | M] (DeviceGuys, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\DGIVECP.SYS -- (DgiVecp)
DRV - [2005.01.08 01:15:40 | 000,051,582 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Tosporte.sys -- (tosporte)
DRV - [2005.01.06 13:42:42 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfnds.sys -- (tosrfnds)
DRV - [2004.12.24 18:36:38 | 000,097,792 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TosRfbd.sys -- (Tosrfbd)
DRV - [2004.12.21 11:38:12 | 000,034,816 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2004.12.15 17:30:14 | 000,050,048 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TosRfSnd.sys -- (TosRfSnd) Bluetooth Audio Device (WDM)
DRV - [2004.12.14 09:48:52 | 000,013,312 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\psadd.sys -- (psadd)
DRV - [2004.11.15 22:51:54 | 000,050,048 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TosRfhid.sys -- (Tosrfhid)
DRV - [2004.10.04 10:33:02 | 000,062,799 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2004.09.24 03:39:58 | 000,064,256 | ---- | M] (IBM) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ibmfilter.sys -- (ibmfilter)
DRV - [2004.07.08 17:07:34 | 000,036,531 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfbnp.sys -- (Tosrfbnp)
DRV - [2004.03.09 12:18:09 | 000,065,504 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\prohlp02.sys -- (prohlp02)
DRV - [2004.03.09 11:45:49 | 000,077,184 | ---- | M] (Protection Technology) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\prodrv06.sys -- (prodrv06)
DRV - [2003.12.01 17:20:52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfhlp01.sys -- (sfhlp01)
DRV - [2003.09.06 14:22:08 | 000,006,944 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\prosync1.sys -- (prosync1)
DRV - [2003.02.11 23:25:14 | 000,009,216 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PELUSBLF.SYS -- (pelusblf)
DRV - [2003.01.10 23:55:32 | 000,016,384 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PELMOUSE.SYS -- (pelmouse)
DRV - [2002.10.16 13:55:48 | 000,002,851 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Toshidpt.sys -- (toshidpt)
DRV - [2001.08.18 14:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2001.08.18 14:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
 
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://home.microsoft.com/search/lobby/search.asp
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://home.microsoft.com/search/lobby/search.asp
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.begin2search.com/sidesearch.html
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://home.microsoft.com/search/lobby/search.asp
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://home.microsoft.com/search/lobby/search.asp
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.begin2search.com/sidesearch.html
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:PA
IE - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8&q={searchTerms}
IE - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "www.t-online.de"
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_228.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
 
 
[2005.12.03 22:08:35 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dur603b9.default\extensions
[2005.12.03 12:29:54 | 000,000,000 | ---D | M] (Adblock) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dur603b9.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2005.12.03 22:08:28 | 000,000,000 | ---D | M] (Html Validator) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dur603b9.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}
[2005.12.03 12:29:54 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dur603b9.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2005.05.09 10:17:35 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dur603b9.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2005.12.03 12:29:54 | 000,000,000 | ---D | M] ("gTranslate") -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dur603b9.default\extensions\{aff87fa2-a58e-4edd-b852-0a20203c1e17}
[2005.12.03 12:29:54 | 000,000,000 | ---D | M] (Leo Search) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dur603b9.default\extensions\{c666c018-6409-4479-afa3-68e4129e7eff}
[2011.12.11 12:23:54 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2006.10.18 22:05:42 | 000,000,000 | ---D | M] (WhenU) -- C:\Programme\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Programme\Google\Chrome\Application\18.0.1025.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Programme\Google\Chrome\Application\18.0.1025.152\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Programme\Google\Chrome\Application\18.0.1025.152\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_228.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Programme\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Programme\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programme\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programme\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Programme\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: YouTube = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AdBlock = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.25_0\
CHR - Extension: Ghostery = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\3.0.0_0\
CHR - Extension: Google Mail = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2005.10.23 18:36:17 | 000,000,847 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {00000000-0002-0002-0000-000000000000} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {00000000-5736-4205-0008-781CD0E19F00} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {00000000-0002-0002-0000-000000000000} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {00000000-5736-4205-0008-781CD0E19F00} - No CLSID value found.
O3 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..\Toolbar\WebBrowser: (no name) - {00000000-0002-0002-0000-000000000000} - No CLSID value found.
O3 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..\Toolbar\WebBrowser: (no name) - {00000000-5736-4205-0008-781CD0E19F00} - No CLSID value found.
O3 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStrCmpLogical = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00  [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00  [binary data]
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 1
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = FF 00 00 00  [binary data]
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoTrayNotify = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 1
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoColorChoice = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVisualStyleChoice = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSizeChoice = 0
O8 - Extra context menu item: Bild in &Microsoft PhotoDraw öffnen - C:\Programme\Microsoft Office\Office\1031\PHDINTL.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_02\bin\npjpi160_02.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..Trusted Domains:  ([]msn in My Computer)
O15 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..Trusted Domains: sipgate.de ([www] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} hxxp://java.sun.com/products/plugin/1.4.1/jinstall-141-win.cab (Java Plug-in 1.4.1)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9F751A4D-E82C-4F14-B8FF-1AD793E9B753}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004.12.23 05:03:10 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{d4086694-16f5-11de-b3f6-0011254cab70}\Shell\AutoRun\command - "" = E:\Menu.exe
O33 - MountPoints2\{fd28d66c-d721-11dd-b390-0011254cab70}\Shell - "" = AutoRun
O33 - MountPoints2\{fd28d66c-d721-11dd-b390-0011254cab70}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{fd28d66c-d721-11dd-b390-0011254cab70}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: 6to4 -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: Irmon -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH)
NetSvcs: WmdmPmSp -  File not found
 
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Gamma Loader.lnk - C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe - (Adobe Systems, Inc.)
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Reader - Schnellstart.lnk - C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe - (Adobe Systems Incorporated)
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Bluetooth Manager.lnk - C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe - ()
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Microsoft Office.lnk - Reg Error: Value error. - File not found
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^sipgate X-Lite.lnk - Reg Error: Value error. - File not found
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^***^Startmenü^Programme^Autostart^Corel Print House Registration.lnk - Reg Error: Value error. - File not found
MsConfig - StartUpReg: 151518181F191E1E1 - hkey= - key= -  File not found
MsConfig - StartUpReg: bxxs5 - hkey= - key= -  File not found
MsConfig - StartUpReg: ctfmon.exe - hkey= - key= -  File not found
MsConfig - StartUpReg: GrooveMonitor - hkey= - key= - C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
MsConfig - StartUpReg: IBMPRC - hkey= - key= - C:\IBMTOOLS\utils\ibmprc.exe (IBM Corp.)
MsConfig - StartUpReg: KernelFaultCheck - hkey= - key= -  File not found
MsConfig - StartUpReg: Mouse Suite 98 Daemon - hkey= - key= -  File not found
MsConfig - StartUpReg: P2kAutostart - hkey= - key= -  File not found
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Programme\QuickTime\qttask.exe (Apple Inc.)
MsConfig - StartUpReg: Run - hkey= - key= - C:\WINDOWS\hpfsched.exe ()
MsConfig - StartUpReg: Samsung Common SM - hkey= - key= - C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe (Samsung Electronics.)
MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Programme\Java\jre1.6.0_02\bin\jusched.exe (Sun Microsystems, Inc.)
MsConfig - StartUpReg: UC_SMB - hkey= - key= -  File not found
MsConfig - StartUpReg: UC_Start - hkey= - key= - C:\Programme\IBM\Updater\\ucstartup.exe ()
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 2
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: nm -  File not found
SafeBootNet: nm.sys -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: UploadMgr -  File not found
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
ActiveX: {0213C6AF-5562-4D09-884C-2ADCFC8C2F35} - Microsoft .NET Framework 1.1 Security Update (KB2656353)
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {1897C549-AE52-4571-8996-44854F5612B2} - Microsoft .NET Framework 1.1 Security Update (KB2656370)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Sicherheitsupdate für Windows XP (KB923789)
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player 9 ActiveX
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E78BFA60-5393-4C38-82AB-E8019E464EB4} - .NET Framework
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
 
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Ligos Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.ffds - ff_vfw.dll File not found
Drivers32: vidc.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll (Ligos Corporation)
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll (Ligos Corporation)
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Ligos Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\iyvu9_32.dll ()
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.04.11 16:54:34 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\***\Desktop\OTL.exe
[2012.04.11 16:18:56 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Startmenü\Programme\Free Registry Cleaner
[2012.04.11 16:18:50 | 000,000,000 | ---D | C] -- C:\Programme\Eusing Free Registry Cleaner
[2012.04.10 18:14:04 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2012.04.10 18:11:26 | 002,322,184 | ---- | C] (ESET) -- C:\Dokumente und Einstellungen\***\Desktop\esetsmartinstaller_enu.exe
[2012.04.10 11:47:41 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012.04.07 12:43:37 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Auslogics
[2012.04.07 12:43:26 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Auslogics
[2012.04.07 12:43:17 | 000,000,000 | ---D | C] -- C:\Programme\Auslogics
[2012.04.07 12:41:20 | 005,114,528 | ---- | C] (Auslogics Software Pty Ltd                                  ) -- C:\Dokumente und Einstellungen\***\Desktop\disk-defrag-setup_3.4.2.exe
[2012.04.07 12:27:00 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\JAM Software
[2012.04.07 12:26:45 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\TreeSize Free
[2012.04.07 12:26:42 | 000,000,000 | ---D | C] -- C:\Programme\JAM Software
[2012.04.07 12:24:35 | 003,350,608 | ---- | C] (JAM Software                                                ) -- C:\Dokumente und Einstellungen\***\Desktop\TreeSizeFreeSetup_2.7.exe
[2012.04.07 12:12:29 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\***\Recent
[2012.04.06 19:40:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Google Chrome
[2012.04.06 19:40:22 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Google
[2012.04.06 19:38:58 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\CCleaner
[2012.04.06 19:36:06 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Google
[2012.04.06 19:36:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Temp
[2012.04.06 19:35:05 | 000,000,000 | ---D | C] -- C:\Programme\Google
[2012.04.06 19:35:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Google
[2012.04.06 19:31:27 | 003,645,656 | ---- | C] (Piriform Ltd) -- C:\Dokumente und Einstellungen\***\Desktop\ccsetup317.exe
[2012.04.06 18:59:57 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Systweak
[2012.04.06 18:59:08 | 000,017,280 | ---- | C] (Systweak Inc., (www.systweak.com)) -- C:\WINDOWS\System32\roboot.exe
[2012.04.06 18:55:20 | 003,603,312 | ---- | C] (Systweak Inc                                                ) -- C:\Dokumente und Einstellungen\***\Desktop\rcpsetup_onlyad.exe
[2012.04.06 13:21:10 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Malwarebytes
[2012.04.06 13:20:47 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.04.06 13:20:46 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2012.04.06 13:20:43 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.04.06 13:20:42 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2012.04.06 13:18:28 | 009,502,424 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Dokumente und Einstellungen\***\Desktop\mbam-setup-1.60.1.1000.exe
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.04.11 16:57:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.04.11 16:54:41 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\***\Desktop\OTL.exe
[2012.04.11 16:47:10 | 000,001,104 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.04.11 16:18:56 | 000,000,731 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Desktop\Eusing Free Registry Cleaner.lnk
[2012.04.11 16:06:48 | 000,002,503 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Desktop\Word 2007.lnk
[2012.04.11 13:03:45 | 000,001,100 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.04.11 13:03:34 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.04.11 13:03:32 | 259,051,520 | -HS- | M] () -- C:\hiberfil.sys
[2012.04.11 12:10:01 | 000,474,652 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2012.04.11 12:10:01 | 000,454,308 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.04.11 12:10:01 | 000,090,232 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2012.04.11 12:10:01 | 000,074,262 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.04.11 12:02:42 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012.04.10 18:11:37 | 002,322,184 | ---- | M] (ESET) -- C:\Dokumente und Einstellungen\***\Desktop\esetsmartinstaller_enu.exe
[2012.04.10 17:57:55 | 000,002,526 | ---- | M] () -- C:\WINDOWS\System32\ASOROSet.bin
[2012.04.10 13:09:16 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012.04.10 12:53:53 | 000,001,230 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.04.10 12:48:35 | 000,000,767 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.04.10 10:58:44 | 000,001,788 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Google Chrome.lnk
[2012.04.09 15:30:30 | 000,000,215 | -HS- | M] () -- C:\BOOT.INI
[2012.04.07 12:43:26 | 000,000,882 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Desktop\Auslogics Disk Defrag.lnk
[2012.04.07 12:41:30 | 005,114,528 | ---- | M] (Auslogics Software Pty Ltd                                  ) -- C:\Dokumente und Einstellungen\***\Desktop\disk-defrag-setup_3.4.2.exe
[2012.04.07 12:24:50 | 003,350,608 | ---- | M] (JAM Software                                                ) -- C:\Dokumente und Einstellungen\***\Desktop\TreeSizeFreeSetup_2.7.exe
[2012.04.06 19:38:57 | 000,000,665 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\CCleaner.lnk
[2012.04.06 19:31:36 | 003,645,656 | ---- | M] (Piriform Ltd) -- C:\Dokumente und Einstellungen\***\Desktop\ccsetup317.exe
[2012.04.06 18:55:23 | 003,603,312 | ---- | M] (Systweak Inc                                                ) -- C:\Dokumente und Einstellungen\***\Desktop\rcpsetup_onlyad.exe
[2012.04.06 13:19:12 | 074,920,720 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Desktop\avast_free_antivirus_setup.exe
[2012.04.06 13:18:38 | 009,502,424 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Dokumente und Einstellungen\***\Desktop\mbam-setup-1.60.1.1000.exe
[2012.04.06 12:50:38 | 005,419,507 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Desktop\Arbeitsmethoden.pdf
[2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.03.18 19:29:20 | 000,372,080 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.04.11 16:18:56 | 000,000,731 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Desktop\Eusing Free Registry Cleaner.lnk
[2012.04.11 12:02:39 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2012.04.10 14:49:51 | 000,002,526 | ---- | C] () -- C:\WINDOWS\System32\ASOROSet.bin
[2012.04.07 12:43:26 | 000,000,882 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Desktop\Auslogics Disk Defrag.lnk
[2012.04.06 19:40:46 | 000,001,788 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Google Chrome.lnk
[2012.04.06 19:38:56 | 000,000,665 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\CCleaner.lnk
[2012.04.06 19:35:31 | 000,001,104 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.04.06 19:35:27 | 000,001,100 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.04.06 15:42:55 | 000,000,884 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.04.06 13:20:52 | 000,000,767 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.04.06 13:18:00 | 074,920,720 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Desktop\avast_free_antivirus_setup.exe
[2012.04.06 13:05:37 | 005,419,507 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Desktop\Arbeitsmethoden.pdf
[2012.01.26 22:13:43 | 000,663,552 | ---- | C] () -- C:\WINDOWS\System32\Tx12.dll
[2012.01.26 22:13:42 | 000,000,530 | ---- | C] () -- C:\WINDOWS\System32\tx12_ic.ini
[2011.11.06 15:49:42 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
 
========== LOP Check ==========
 
[2010.07.16 16:29:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AntiVir PersonalEdition Classic
[2011.11.06 15:52:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Canneverbe Limited
[2004.12.14 09:36:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\IBM
[2008.05.15 21:46:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\pdf995
[2010.09.02 11:35:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SecTaskMan
[2005.07.04 16:57:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\T-DSL SpeedManager
[2006.06.04 13:20:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2009.12.27 18:55:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ulead Systems
[2012.04.07 12:43:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Auslogics
[2012.04.07 11:39:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\M***\Anwendungsdaten\Azureus
[2011.11.06 15:52:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Canneverbe Limited
[2007.04.11 14:13:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\concept design
[2005.01.29 20:34:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\M***\Anwendungsdaten\DMCache
[2006.07.29 18:54:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\FrostWire
[2004.12.22 20:45:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\IBM
[2006.02.02 13:55:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\ICQ
[2012.04.07 12:27:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\JAM Software
[2005.11.23 22:21:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Leadertech
[2007.05.28 17:54:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\LimeWire
[2006.03.11 16:06:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Opera
[2007.07.29 18:59:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\pdf995
[2007.04.11 14:11:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\phonostar-Player
[2007.02.20 12:57:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\SecondLife
[2012.04.11 12:39:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Systweak
[2005.03.30 13:16:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\T-DSL SpeedManager
[2005.02.18 17:57:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird
[2007.04.10 11:54:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Toshiba
[2006.03.15 13:43:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\tunebite
[2006.06.04 13:21:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\TuneUp Software
[2006.01.28 18:32:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Ulead Systems
[2009.12.25 18:15:01 | 000,000,412 | ---- | M] () -- C:\WINDOWS\Tasks\1-Klick-Wartung.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2006.02.10 15:30:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Adobe
[2008.05.13 11:28:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\AdobeUM
[2007.06.17 19:33:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Ahead
[2006.09.16 17:36:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Apple Computer
[2012.04.07 12:43:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Auslogics
[2010.07.16 16:40:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Avira
[2012.04.07 11:39:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Azureus
[2011.11.06 15:52:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Canneverbe Limited
[2007.04.11 14:13:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\concept design
[2006.12.13 21:33:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Corel
[2005.01.29 20:34:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\DMCache
[2005.11.23 19:06:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\dvdcss
[2006.07.29 18:54:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\FrostWire
[2005.08.01 13:35:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Google
[2005.01.13 19:06:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Help
[2004.12.22 20:45:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\IBM
[2006.02.02 13:55:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\ICQ
[2003.02.24 17:53:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Identities
[2012.04.07 12:27:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\JAM Software
[2006.10.03 12:24:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Lavasoft
[2005.11.23 22:21:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Leadertech
[2007.05.28 17:54:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\LimeWire
[2004.12.23 05:27:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Macromedia
[2012.04.06 13:21:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Malwarebytes
[2011.02.06 13:16:07 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Microsoft
[2004.12.22 22:33:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Microsoft Web Folders
[2012.04.07 12:20:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Mozilla
[2007.04.12 20:14:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\MSN6
[2006.03.11 16:06:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Opera
[2007.07.29 18:59:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\pdf995
[2007.04.11 14:11:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\phonostar-Player
[2008.03.20 16:20:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Real
[2007.02.20 12:57:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\SecondLife
[2005.11.23 22:21:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Sonic
[2005.03.16 13:36:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Sun
[2004.12.14 09:38:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Symantec
[2012.04.11 12:39:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Systweak
[2005.03.30 13:16:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\T-DSL SpeedManager
[2005.02.18 17:51:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Talkback
[2005.02.18 17:57:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Thunderbird
[2007.04.10 11:54:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Toshiba
[2006.03.15 13:43:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\tunebite
[2006.06.04 13:21:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\TuneUp Software
[2008.12.31 12:03:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\U3
[2006.01.28 18:32:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Ulead Systems
[2006.10.18 22:17:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\vlc
 
< %APPDATA%\*.exe /s >
[2007.01.19 11:41:32 | 023,813,608 | ---- | M] (                            ) -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Adobe\Acrobat\7.0\Updater\AdbeRdr709_de_DE.exe
[2008.05.10 19:23:49 | 022,319,360 | ---- | M] (                                  ) -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Adobe\Acrobat\7.0\Updater\AdbeRdr710_de_DE.exe
[2008.01.24 18:15:13 | 001,491,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
[2008.03.20 16:01:13 | 000,353,840 | ---- | M] (RealNetworks, Inc.) -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Real\Update\setup\setup.exe
[2008.03.20 16:08:54 | 006,871,480 | ---- | M] () -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Real\Update\setup\data\firefoxgoogletoolbarsetup.exe
[2008.03.20 16:16:29 | 005,955,584 | ---- | M] () -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Real\Update\setup\data\RealPlayer11GOLD.exe
[2008.03.20 16:10:13 | 001,145,896 | ---- | M] (Google) -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\Real\Update\setup\data\GOOGLE_TOOLBAR\googletoolbarinstaller.exe
[2007.10.23 10:27:20 | 000,110,592 | ---- | M] () -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\U3\temp\cleanup.exe
[2008.05.02 11:41:48 | 003,493,888 | -H-- | M] (SanDisk Corporation) -- C:\Dokumente und Einstellungen\Marc Nikolaus\Anwendungsdaten\U3\temp\Launchpad Removal.exe
 
< %SYSTEMDRIVE%\*.exe >
[2001.05.24 12:59:30 | 000,162,304 | ---- | M] () -- C:\UNWISE.EXE
 
< MD5 for: AGP440.SYS  >
[2004.08.04 11:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\I386\sp2.cab:AGP440.sys
[2004.08.04 11:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.08.29 10:39:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.08.29 10:39:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\7d084ddd2c07c476a226e31c4ef032ff\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004.08.04 09:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
 
< MD5 for: ATAPI.SYS  >
[2002.08.29 13:52:58 | 010,180,476 | ---- | M] () .cab file -- C:\I386\sp1.cab:atapi.sys
[2004.08.04 11:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
[2002.08.29 13:52:58 | 010,180,476 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004.08.04 11:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.08.29 10:39:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.08.29 10:39:53 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2002.08.29 11:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\7d084ddd2c07c476a226e31c4ef032ff\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.04 08:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
 
< MD5 for: EVENTLOG.DLL  >
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll
[2004.08.04 10:57:20 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
 
< MD5 for: NETLOGON.DLL  >
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll
[2004.08.04 10:57:32 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
 
< MD5 for: SCECLI.DLL  >
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll
[2004.08.04 10:57:34 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
 
< MD5 for: USER32.DLL  >
[2005.03.02 20:09:46 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=3751D7CF0E0A113D84414992146BCE6A -- C:\WINDOWS\$NtUninstallKB925902$\user32.dll
[2007.03.08 17:36:30 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=492E166CFD26A50FB9160DB536FF7D2B -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2005.03.02 20:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
[2004.08.04 10:57:38 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=56785FD5236D7B22CF471A6DA9DB46D8 -- C:\WINDOWS\$NtUninstallKB890859$\user32.dll
[2007.03.08 17:48:39 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=78785EFF8CB90CEC1862A4CCFD9A3C3A -- C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe
[2004.08.04 10:58:18 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
 
< MD5 for: VAXSCSI.SYS  >
[2007.02.18 12:18:13 | 000,223,128 | ---- | M] (Alcohol Soft Co., Ltd.) MD5=92CEBC2BC7BE2C8D49391B365569F306 -- C:\WINDOWS\system32\drivers\vaxscsi.sys
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Programme\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2004.08.04 10:58:20 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2001.08.18 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2001.08.18 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2007.02.18 12:15:55 | 000,611,064 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
 
< %systemroot%\System32\config\*.sav >
[2003.02.24 17:36:14 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< End of report >


dirknik 11.04.2012 16:49

Ich weiß nicht, ob das auch noch wichtig ist, aber hier gabs noch ein "Extra" Log:

Code:

OTL Extras logfile created on: 11.04.2012 17:01:22 - Run 1
OTL by OldTimer - Version 3.2.39.2    Folder = C:\Dokumente und Einstellungen\Marc Nikolaus\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
246,98 Mb Total Physical Memory | 116,05 Mb Available Physical Memory | 46,99% Memory free
933,29 Mb Paging File | 574,60 Mb Available in Paging File | 61,57% Paging File free
Paging file location(s): C:\pagefile.sys 700 744 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 33,58 Gb Total Space | 8,98 Gb Free Space | 26,73% Space Free | Partition Type: NTFS
 
Computer Name: IBM-5D34BDAD641 | User Name: Marc Nikolaus | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] -- C:\Programme\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Programme\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Programme\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%ProgramFiles%\IBM\Updater\ucsmb.exe" = %ProgramFiles%\IBM\Updater\ucsmb.exe:*:enabled:IBM Update Connector -- (IBM Corporation, Inc.)
"%ProgramFiles%\IBM\Updater\jre\bin\java.exe" = %ProgramFiles%\IBM\Updater\jre\bin\java.exe:*:enabled:IBM Update Connector -- (IBM)
"%ProgramFiles%\IBM\Updater\jre\bin\javaw.exe" = %ProgramFiles%\IBM\Updater\jre\bin\javaw.exe:*:enabled:IBM Update Connector -- (IBM)
"C:\Programme\concept design\onlineTV 3\onlineTV.exe" = C:\Programme\concept design\onlineTV 3\onlineTV.exe:*:Enabled:onlineTV
"C:\Programme\Windows Live\Messenger\msnmsgr.exe" = C:\Programme\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
"C:\Programme\Windows Live\Messenger\livecall.exe" = C:\Programme\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%ProgramFiles%\IBM\Updater\ucsmb.exe" = %ProgramFiles%\IBM\Updater\ucsmb.exe:*:enabled:IBM Update Connector -- (IBM Corporation, Inc.)
"%ProgramFiles%\IBM\Updater\jre\bin\java.exe" = %ProgramFiles%\IBM\Updater\jre\bin\java.exe:*:enabled:IBM Update Connector -- (IBM)
"%ProgramFiles%\IBM\Updater\jre\bin\javaw.exe" = %ProgramFiles%\IBM\Updater\jre\bin\javaw.exe:*:enabled:IBM Update Connector -- (IBM)
"C:\Dokumente und Einstellungen\All Users\Dokumente\LimeWire\LimeWire.exe" = C:\Dokumente und Einstellungen\All Users\Dokumente\LimeWire\LimeWire.exe:*:Disabled:LimeWire
"C:\Programme\eDonkey2000\edonkey2000.exe" = C:\Programme\eDonkey2000\edonkey2000.exe:*:Disabled:edonkey2000
"C:\Programme\eMule.de\emule.exe" = C:\Programme\eMule.de\emule.exe:*:Disabled:eMule
"C:\Dokumente und Einstellungen\Marc Nikolaus\Desktop\emule\eDonkey2000\edonkey2000.exe" = C:\Dokumente und Einstellungen\Marc Nikolaus\Desktop\emule\eDonkey2000\edonkey2000.exe:*:Disabled:edonkey2000
"C:\Programme\Warez P2P Client\warez.exe" = C:\Programme\Warez P2P Client\warez.exe:*:Disabled:Warez p2p client
"C:\Programme\Anti-Leech\ALIE_1.0.1.6\alhlp.exe" = C:\Programme\Anti-Leech\ALIE_1.0.1.6\alhlp.exe:*:Disabled:Anti-Leech plugin helper program
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Disabled:Microsoft Management Console -- (Microsoft Corporation)
"C:\Programme\Mozilla Firefox\plugins\alhlp.exe" = C:\Programme\Mozilla Firefox\plugins\alhlp.exe:*:Enabled:Anti-Leech plugin helper program
"C:\Programme\Mozilla Firefox\firefox.exe" = C:\Programme\Mozilla Firefox\firefox.exe:*:Enabled:Firefox
"C:\Programme\LimeWire\LimeWire.exe" = C:\Programme\LimeWire\LimeWire.exe:*:Disabled:LimeWire
"C:\Programme\Diablo II\Game.exe" = C:\Programme\Diablo II\Game.exe:*:Enabled:Diablo II
"C:\Programme\Diablo II\Game_crk.exe" = C:\Programme\Diablo II\Game_crk.exe:*:Enabled:Diablo II
"C:\Programme\LucasArts\Star Wars JK II Jedi Outcast\GameData\jk2mp.exe" = C:\Programme\LucasArts\Star Wars JK II Jedi Outcast\GameData\jk2mp.exe:*:Enabled:jk2mp
"C:\Programme\Call of Duty\CoDMP.exe" = C:\Programme\Call of Duty\CoDMP.exe:*:Enabled:CoDMP
"C:\Westwood\SUN\PATCHGET.DAT" = C:\Westwood\SUN\PATCHGET.DAT:*:Enabled:patchgrabber
"C:\Westwood\SUN\GAME.ICD" = C:\Westwood\SUN\GAME.ICD:*:Enabled:Main executable for Tiberian Sun
"C:\Programme\LucasArts\Star Wars Jedi Knight Jedi Academy\GameData\jamp.exe" = C:\Programme\LucasArts\Star Wars Jedi Knight Jedi Academy\GameData\jamp.exe:*:Enabled:Jedi Academy MultiPlayer
"C:\Westwood\Renegade\multiplayer.exe" = C:\Westwood\Renegade\multiplayer.exe:*:Enabled:Renegade
"C:\Westwood\Renegade\Game.exe" = C:\Westwood\Renegade\Game.exe:*:Enabled:Renegade
"C:\Programme\Real\RealPlayer\realplay.exe" = C:\Programme\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer
"C:\Programme\GameJack4\GameJack.exe" = C:\Programme\GameJack4\GameJack.exe:*:Disabled:GameJack
"C:\Programme\Electronic Arts\Need for Speed\nfsHs.icd" = C:\Programme\Electronic Arts\Need for Speed\nfsHs.icd:*:Disabled:Need For Speed High Stakes for Win32
"C:\Programme\ICQ\Icq.exe" = C:\Programme\ICQ\Icq.exe:*:Enabled:ICQ
"C:\Programme\Skype\Phone\Skype.exe" = C:\Programme\Skype\Phone\Skype.exe:*:Enabled:Skype
"C:\Programme\sipgate X-Lite\sipgateXLite.exe" = C:\Programme\sipgate X-Lite\sipgateXLite.exe:*:Enabled:sipgateXLite
"C:\Programme\Opera\Opera.exe" = C:\Programme\Opera\Opera.exe:*:Enabled:Opera Internet Browser
"c:\windows\rk.exe" = c:\windows\rk.exe:*:Enabled:rk.exe
"C:\Dokumente und Einstellungen\Marc Nikolaus\Lokale Einstellungen\Temp\~osAE.tmp\ossproxy.exe" = C:\Dokumente und Einstellungen\Marc Nikolaus\Lokale Einstellungen\Temp\~osAE.tmp\ossproxy.exe:*:Enabled:ossproxy.exe
"c:\windows\rlvknlg.exe" = c:\windows\rlvknlg.exe:*:Enabled:rlvknlg.exe
"C:\Dokumente und Einstellungen\Marc Nikolaus\Lokale Einstellungen\Temp\~os8.tmp\ossproxy.exe" = C:\Dokumente und Einstellungen\Marc Nikolaus\Lokale Einstellungen\Temp\~os8.tmp\ossproxy.exe:*:Enabled:ossproxy.exe
"C:\Dokumente und Einstellungen\Marc Nikolaus\Lokale Einstellungen\Temp\~os6.tmp\ossproxy.exe" = C:\Dokumente und Einstellungen\Marc Nikolaus\Lokale Einstellungen\Temp\~os6.tmp\ossproxy.exe:*:Enabled:ossproxy.exe
"C:\Programme\Java\jre1.5.0_04\bin\javaw.exe" = C:\Programme\Java\jre1.5.0_04\bin\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary
"C:\Programme\Azureus\Azureus.exe" = C:\Programme\Azureus\Azureus.exe:*:Enabled:Azureus
"C:\Programme\concept design\onlineTV 3\onlineTV.exe" = C:\Programme\concept design\onlineTV 3\onlineTV.exe:*:Enabled:onlineTV
"C:\Programme\Windows Live\Messenger\msnmsgr.exe" = C:\Programme\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
"C:\Programme\Windows Live\Messenger\livecall.exe" = C:\Programme\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
"C:\Programme\QuickTime\QuickTimePlayer.exe" = C:\Programme\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player -- (Apple Inc.)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1007F41F-7D69-468E-8017-3849A5A973C2}" = IBM ThinkVantage Technologies Welcome Message
"{11783F13-C3A9-44A8-929B-21A476F65272}" = IBM Rescue and Recovery with Rapid Restore
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java(TM) SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C5EA394-1031-11D2-A2CB-00C04F72F31D}" = Microsoft PhotoDraw 2000 V2
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6C72E14A-C1F3-45E5-8810-83CE3C19ED63}" = IBM 32-bit Runtime Environment for Java 2, v1.4.1
"{6CE96A14-61E2-48CC-837E-22710A953ADE}" = IBM Themes
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{80380166-A872-4B78-B98A-33447A032BDF}" = ThinkCentre Wallpaper
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Extreme Graphics 2 Driver
"{8D815BF3-2399-459C-B121-49373FEFB9E8}" = IBM Update Connector
"{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders  (German) 12
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007
"{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-A71000000002}" = Adobe Reader 7.1.0 - Deutsch
"{C911A0C2-2236-3164-AA47-F2566C01AE5E}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = TOSHIBA Bluetooth Stack for Apache by CSR
"{D271DAE0-8D68-4C97-8356-A126D48A1D8C}" = Ulead Photo Explorer 8.0 SE Basic
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{EC6AF20D-4376-4070-BEE4-D3A0DFF7E140}" = Access IBM
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Ashampoo WinOptimizer 4 FREE_is1" = Ashampoo WinOptimizer 4 FREE
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Bewerbung um eine Ausbildungsstelle 2004/2005" = Bewerbung um eine Ausbildungsstelle 2004/2005
"CCleaner" = CCleaner
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESET Online Scanner" = ESET Online Scanner v3
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"Google Chrome" = Google Chrome
"HP PrecisionScan LTX" = HP PrecisionScan LTX
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{6C72E14A-C1F3-45E5-8810-83CE3C19ED63}" = IBM 32-bit Runtime Environment for Java 2, v1.4.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"MouseSuite98" = Mouse Suite
"Mozilla Thunderbird (1.0.6)" = Mozilla Thunderbird (1.0.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Pdf995" = Pdf995
"PROSet" = Intel(R) PRO Network Adapters and Drivers
"Samsung ML-2010 Series" = Samsung ML-2010 Series
"Security Task Manager" = Security Task Manager 1.7h
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"TreeSize Free_is1" = TreeSize Free V2.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WINZD_is1" = WINZD 2011-08
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 02.10.2010 17:22:14 | Computer Name = IBM-5D34BDAD641 | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung plugin-container.exe, Version 1.9.2.3909,
 fehlgeschlagenes Modul ntdll.dll, Version 5.1.2600.5755, Fehleradresse 0x0000100b.
 
Error - 03.10.2010 05:51:35 | Computer Name = IBM-5D34BDAD641 | Source = MsiInstaller | ID = 11706
Description = Produkt: Microsoft PhotoDraw 2000 V2 -- Fehler 1706. Es wurde keine
 gültige Quelle für das Produkt "Microsoft PhotoDraw 2000 V2" gefunden. Die Installation
 kann nicht fortgesetzt werden.
 
Error - 20.11.2010 17:40:40 | Computer Name = IBM-5D34BDAD641 | Source = MsiInstaller | ID = 11935
Description = Produkt: Microsoft Office Enterprise 2007 -- Fehler 1935.Fehler beim
 Installieren der Assemblykomponente '{F534BD05-F37C-49D0-B70E-92A30F9FE1C3}'. HRESULT:
 0x80070005. Assemblyschnittstelle: IAssemblyCacheItem, Funktion: Commit, Assemblyname:
 Policy.11.0.office,fileVersion="12.0.6425.1000",version="12.0.0.0000000",culture="neutral",publicKeyToken="71E9BCE111E9429C"
 
Error - 20.11.2010 17:45:47 | Computer Name = IBM-5D34BDAD641 | Source = MsiInstaller | ID = 1024
Description = Produkt: Microsoft Office Enterprise 2007 - Update "Microsoft Office
 2007 Service Pack 2 (SP2)" konnte nicht installiert werden. Fehlercode 1603. Windows
 Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der
 Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link,
 um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127
 
Error - 21.11.2010 11:09:47 | Computer Name = IBM-5D34BDAD641 | Source = MsiInstaller | ID = 11935
Description = Produkt: Microsoft Office Enterprise 2007 -- Fehler 1935.Fehler beim
 Installieren der Assemblykomponente '{580CB155-841D-4D48-9F59-866A035C2241}'. HRESULT:
 0x80070005. Assemblyschnittstelle: IAssemblyCacheItem, Funktion: Commit, Assemblyname:
 Microsoft.Office.Interop.Graph,fileVersion="12.0.6425.1000",version="12.0.0.0000000",culture="neutral",publicKeyToken="71E9BCE111E9429C"
 
Error - 21.11.2010 11:13:47 | Computer Name = IBM-5D34BDAD641 | Source = MsiInstaller | ID = 1024
Description = Produkt: Microsoft Office Enterprise 2007 - Update "Microsoft Office
 2007 Service Pack 2 (SP2)" konnte nicht installiert werden. Fehlercode 1603. Windows
 Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der
 Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link,
 um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127
 
Error - 27.12.2010 04:45:23 | Computer Name = IBM-5D34BDAD641 | Source = crypt32 | ID = 131080
Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer
 von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
 ist fehlgeschlagen mit dem Fehler: Dieser Vorgang wurde wegen Zeitüberschreitung
 zurückgegeben.  .
 
Error - 02.07.2011 14:40:08 | Computer Name = IBM-5D34BDAD641 | Source = Microsoft Office 12 | ID = 1000
Description = Faulting application winword.exe, version 12.0.6545.5000, stamp 4c653e57,
 faulting module wwlib.dll, version 12.0.6545.5000, stamp 4c653fe2, debug? 0, fault
 address 0x003424c2.
 
Error - 06.11.2011 07:16:53 | Computer Name = IBM-5D34BDAD641 | Source = crypt32 | ID = 131083
Description = Die Extrahierung der Drittanbieterstammlisten aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
 ist fehlgeschlagen mit dem Fehler: Ein erforderliches Zertifikat befindet sich
nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel
 in der signierten Datei.  .
 
Error - 06.11.2011 07:16:53 | Computer Name = IBM-5D34BDAD641 | Source = crypt32 | ID = 131083
Description = Die Extrahierung der Drittanbieterstammlisten aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
 ist fehlgeschlagen mit dem Fehler: Ein erforderliches Zertifikat befindet sich
nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel
 in der signierten Datei.  .
 
[ OSession Events ]
Error - 12.12.2010 06:06:45 | Computer Name = IBM-5D34BDAD641 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2950
 seconds with 2760 seconds of active time.  This session ended with a crash.
 
Error - 18.01.2011 15:06:50 | Computer Name = IBM-5D34BDAD641 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 142
 seconds with 120 seconds of active time.  This session ended with a crash.
 
Error - 02.07.2011 14:40:00 | Computer Name = IBM-5D34BDAD641 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 74
 seconds with 60 seconds of active time.  This session ended with a crash.
 
Error - 03.10.2011 13:56:59 | Computer Name = IBM-5D34BDAD641 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4494
 seconds with 1020 seconds of active time.  This session ended with a crash.
 
Error - 08.11.2011 12:12:49 | Computer Name = IBM-5D34BDAD641 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1519
 seconds with 840 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 10.04.2012 04:42:08 | Computer Name = IBM-5D34BDAD641 | Source = Service Control Manager | ID = 7000
Description = Der Dienst "IMAPI-CD-Brenn-COM-Dienste" wurde aufgrund folgenden Fehlers
 nicht gestartet:  %%1053
 
Error - 10.04.2012 06:52:58 | Computer Name = IBM-5D34BDAD641 | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  Aspi32  delprot  obvious
 
Error - 10.04.2012 12:03:05 | Computer Name = IBM-5D34BDAD641 | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  Aspi32  delprot  obvious
 
Error - 10.04.2012 12:03:57 | Computer Name = IBM-5D34BDAD641 | Source = Service Control Manager | ID = 7009
Description = Zeitüberschreitung (30000 ms) beim Verbindungsversuch mit Dienst IMAPI-CD-Brenn-COM-Dienste.
 
Error - 10.04.2012 12:03:57 | Computer Name = IBM-5D34BDAD641 | Source = Service Control Manager | ID = 7000
Description = Der Dienst "IMAPI-CD-Brenn-COM-Dienste" wurde aufgrund folgenden Fehlers
 nicht gestartet:  %%1053
 
Error - 10.04.2012 12:04:10 | Computer Name = IBM-5D34BDAD641 | Source = DCOM | ID = 10010
Description = Der Server "{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}" konnte innerhalb
 des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
 
Error - 11.04.2012 04:53:22 | Computer Name = IBM-5D34BDAD641 | Source = Service Control Manager | ID = 7022
Description = Der Dienst "Avira AntiVir Guard" wurde nicht ordnungsgemäß gestartet.
 
Error - 11.04.2012 04:53:22 | Computer Name = IBM-5D34BDAD641 | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  Aspi32  delprot  obvious
 
Error - 11.04.2012 07:08:07 | Computer Name = IBM-5D34BDAD641 | Source = Service Control Manager | ID = 7022
Description = Der Dienst "Avira AntiVir Guard" wurde nicht ordnungsgemäß gestartet.
 
Error - 11.04.2012 07:08:07 | Computer Name = IBM-5D34BDAD641 | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  Aspi32  delprot  obvious
 
 
< End of report >

Vielen Dank für deine Hilfe :-)

cosinus 11.04.2012 18:25

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/sidesearch.html
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/sidesearch.html
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0:  File not found
[2006.10.18 22:05:42 | 000,000,000 | ---D | M] (WhenU) -- C:\Programme\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}
O3 - HKU\.DEFAULT\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {00000000-0002-0002-0000-000000000000} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {00000000-5736-4205-0008-781CD0E19F00} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {00000000-0002-0002-0000-000000000000} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {00000000-5736-4205-0008-781CD0E19F00} - No CLSID value found.
O3 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..\Toolbar\WebBrowser: (no name) - {00000000-0002-0002-0000-000000000000} - No CLSID value found.
O3 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..\Toolbar\WebBrowser: (no name) - {00000000-5736-4205-0008-781CD0E19F00} - No CLSID value found.
O3 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStrCmpLogical = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00  [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00  [binary data]
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 1
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = FF 00 00 00  [binary data]
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoTrayNotify = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 1
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoColorChoice = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVisualStyleChoice = 0
O7 - HKU\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSizeChoice = 0
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004.12.23 05:03:10 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{d4086694-16f5-11de-b3f6-0011254cab70}\Shell\AutoRun\command - "" = E:\Menu.exe
O33 - MountPoints2\{fd28d66c-d721-11dd-b390-0011254cab70}\Shell - "" = AutoRun
O33 - MountPoints2\{fd28d66c-d721-11dd-b390-0011254cab70}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{fd28d66c-d721-11dd-b390-0011254cab70}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

dirknik 11.04.2012 20:28

Hatte den Text in OTL reinkopiert und den Fix-Button gedrückt. Doch steht jetzt seit ca. 2 Std. ganz unten im OTL-Programmfeld: "Killing processes. DO NOT INTERRUPT." Und es schaut so aus, als hätte sich der PC aufgehängt. Was soll ich jetzt tun?

cosinus 12.04.2012 09:02

Wiederhol den Fix im abgesicherten Modus bitte

dirknik 12.04.2012 10:57

Ok, im abgesicherten Modus hat alles geklappt :-):

Code:

All processes killed
========== OTL ==========
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0\ deleted successfully.
C:\Programme\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\chrome folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34} folder moved successfully.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{00000000-0002-0002-0000-000000000000} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-0002-0002-0000-000000000000}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{00000000-5736-4205-0008-781CD0E19F00} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-5736-4205-0008-781CD0E19F00}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{00000000-0002-0002-0000-000000000000} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-0002-0002-0000-000000000000}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{00000000-5736-4205-0008-781CD0E19F00} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-5736-4205-0008-781CD0E19F00}\ not found.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{00000000-0002-0002-0000-000000000000} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-0002-0002-0000-000000000000}\ not found.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{00000000-5736-4205-0008-781CD0E19F00} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-5736-4205-0008-781CD0E19F00}\ not found.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Infodelivery\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoRemoteRecursiveEvents deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoStrCmpLogical deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoClose deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoCDBurning deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\HonorAutoRunSetting deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunStartupScriptSync deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\SynchronousMachineGroupPolicy deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\SynchronousUserGroupPolicy deleted successfully.
Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun not found.
Registry key HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer not found.
Registry value HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoSMBalloonTip deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoSaveSettings deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoLowDiskSpaceChecks deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\MemCheckBoxInRunDlg deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoClose deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoAutoTrayNotify deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoResolveTrack deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoResolveSearch deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\LinkResolveIgnoreLinkInfo deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoWelcomeScreen deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoRecentDocsNetHood deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDesktopCleanupWizard deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoSharedDocuments deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoThemesTab deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\NoDispAppearancePage deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\NoColorChoice deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\NoDispCPL deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\NoDispSettingsPage deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\NoDispScrSavPage deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\NoVisualStyleChoice deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2647820290-600059833-1480542432-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\NoSizeChoice deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\AUTOEXEC.BAT moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d4086694-16f5-11de-b3f6-0011254cab70}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d4086694-16f5-11de-b3f6-0011254cab70}\ not found.
File E:\Menu.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fd28d66c-d721-11dd-b390-0011254cab70}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fd28d66c-d721-11dd-b390-0011254cab70}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fd28d66c-d721-11dd-b390-0011254cab70}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fd28d66c-d721-11dd-b390-0011254cab70}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fd28d66c-d721-11dd-b390-0011254cab70}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fd28d66c-d721-11dd-b390-0011254cab70}\ not found.
File E:\LaunchU3.exe -a not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 2035745 bytes
->Temporary Internet Files folder emptied: 32768 bytes
 
User: All Users
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
 
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32969 bytes
 
User: Marc Nikolaus
->Temp folder emptied: 1514303 bytes
->Temporary Internet Files folder emptied: 491814 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 6986234 bytes
->Flash cache emptied: 0 bytes
 
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 34702 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 711240 bytes
%systemroot%\System32 .tmp files removed: 2951 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 255 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 11,00 mb
 
 
[EMPTYFLASH]
 
User: Administrator
 
User: All Users
 
User: Default User
 
User: LocalService
 
User: Marc Nikolaus
->Flash cache emptied: 0 bytes
 
User: NetworkService
 
Total Flash Files Cleaned = 0,00 mb
 
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.39.2 log created on 04122012_113030

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...


cosinus 12.04.2012 15:09

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten, Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

dirknik 12.04.2012 16:57

Sorry, ich hab beim ersten Durchlauf eine Bedrohung gelöscht, weil ich nach der Anleitung im Link vorgegangen bin. Hoffe, dass war nichts wichtiges. So hier das Log nach dem zweiten Scan mit den entsprechenden Voreinstellungen (die ich beim ersten mal auch nicht gemacht habe, weil ich, wie gesagt, zuerst alles so durchgeführt hatte, wie im Link beschrieben war. Entschuldige bitte!):

Code:

17:48:28.0515 3180        TDSS rootkit removing tool 2.7.28.0 Apr 10 2012 16:54:05
17:48:30.0546 3180        ============================================================
17:48:30.0546 3180        Current date / time: 2012/04/12 17:48:30.0546
17:48:30.0546 3180        SystemInfo:
17:48:30.0546 3180       
17:48:30.0546 3180        OS Version: 5.1.2600 ServicePack: 3.0
17:48:30.0546 3180        Product type: Workstation
17:48:30.0546 3180        ComputerName: IBM-5D34BDAD641
17:48:30.0546 3180        UserName: Marc Nikolaus
17:48:30.0546 3180        Windows directory: C:\WINDOWS
17:48:30.0546 3180        System windows directory: C:\WINDOWS
17:48:30.0546 3180        Processor architecture: Intel x86
17:48:30.0546 3180        Number of processors: 1
17:48:30.0546 3180        Page size: 0x1000
17:48:30.0546 3180        Boot type: Normal boot
17:48:30.0546 3180        ============================================================
17:48:34.0375 3180        Drive \Device\Harddisk0\DR0 - Size: 0x951240000 (37.27 Gb), SectorSize: 0x200, Cylinders: 0x1301, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
17:48:34.0484 3180        \Device\Harddisk0\DR0:
17:48:34.0500 3180        MBR used
17:48:34.0500 3180        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x432A8E1
17:48:34.0578 3180        Initialize success
17:48:34.0578 3180        ============================================================
17:53:14.0812 2948        ============================================================
17:53:14.0812 2948        Scan started
17:53:14.0812 2948        Mode: Manual; SigCheck; TDLFS;
17:53:14.0812 2948        ============================================================
17:53:15.0437 2948        Abiosdsk - ok
17:53:15.0515 2948        abp480n5        (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS
17:53:18.0296 2948        abp480n5 - ok
17:53:18.0406 2948        ac97intc        (0f2d66d5f08ebe2f77bb904288dcf6f0) C:\WINDOWS\system32\drivers\ac97intc.sys
17:53:18.0671 2948        ac97intc - ok
17:53:18.0781 2948        ACPI            (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
17:53:19.0000 2948        ACPI - ok
17:53:19.0109 2948        ACPIEC          (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\drivers\ACPIEC.sys
17:53:19.0359 2948        ACPIEC - ok
17:53:19.0468 2948        AdobeFlashPlayerUpdateSvc (0d4c486a24a711a45fd83acdf4d18506) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
17:53:19.0531 2948        AdobeFlashPlayerUpdateSvc - ok
17:53:19.0625 2948        adpu160m        (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\System32\DRIVERS\adpu160m.sys
17:53:19.0875 2948        adpu160m - ok
17:53:19.0968 2948        aeaudio        (3cb6ae5435987b1f8c83fd2730479878) C:\WINDOWS\system32\drivers\aeaudio.sys
17:53:20.0015 2948        aeaudio - ok
17:53:20.0140 2948        aec            (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
17:53:20.0375 2948        aec - ok
17:53:20.0500 2948        AFD            (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
17:53:20.0578 2948        AFD - ok
17:53:20.0687 2948        agp440          (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
17:53:20.0921 2948        agp440 - ok
17:53:21.0015 2948        agpCPQ          (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\System32\DRIVERS\agpCPQ.sys
17:53:21.0250 2948        agpCPQ - ok
17:53:21.0328 2948        Aha154x        (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\System32\DRIVERS\aha154x.sys
17:53:21.0484 2948        Aha154x - ok
17:53:21.0593 2948        aic78u2        (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\System32\DRIVERS\aic78u2.sys
17:53:21.0812 2948        aic78u2 - ok
17:53:21.0890 2948        aic78xx        (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\System32\DRIVERS\aic78xx.sys
17:53:22.0125 2948        aic78xx - ok
17:53:22.0203 2948        Alerter        (738d80cc01d7bc7584be917b7f544394) C:\WINDOWS\system32\alrsvc.dll
17:53:22.0437 2948        Alerter - ok
17:53:22.0546 2948        ALG            (190cd73d4984f94d823f9444980513e5) C:\WINDOWS\System32\alg.exe
17:53:22.0765 2948        ALG - ok
17:53:22.0859 2948        AliIde          (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\System32\DRIVERS\aliide.sys
17:53:23.0078 2948        AliIde - ok
17:53:23.0171 2948        alim1541        (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\System32\DRIVERS\alim1541.sys
17:53:23.0406 2948        alim1541 - ok
17:53:23.0500 2948        amdagp          (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\System32\DRIVERS\amdagp.sys
17:53:23.0734 2948        amdagp - ok
17:53:23.0828 2948        amsint          (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\System32\DRIVERS\amsint.sys
17:53:23.0984 2948        amsint - ok
17:53:24.0062 2948        AntiVirSchedulerService (c27d46b06d340293670450fce9dfb166) C:\Programme\Avira\AntiVir Desktop\sched.exe
17:53:24.0093 2948        AntiVirSchedulerService - ok
17:53:24.0171 2948        AntiVirService  (72d90e56563165984224493069c69ed4) C:\Programme\Avira\AntiVir Desktop\avguard.exe
17:53:24.0203 2948        AntiVirService - ok
17:53:24.0296 2948        AppMgmt        (d45960be52c3c610d361977057f98c54) C:\WINDOWS\System32\appmgmts.dll
17:53:24.0515 2948        AppMgmt - ok
17:53:24.0625 2948        asc            (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\System32\DRIVERS\asc.sys
17:53:24.0859 2948        asc - ok
17:53:24.0953 2948        asc3350p        (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\System32\DRIVERS\asc3350p.sys
17:53:25.0093 2948        asc3350p - ok
17:53:25.0187 2948        asc3550        (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\System32\DRIVERS\asc3550.sys
17:53:25.0421 2948        asc3550 - ok
17:53:25.0531 2948        Aspi32 - ok
17:53:25.0640 2948        aspnet_state    (776acefa0ca9df0faa51a5fb2f435705) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
17:53:25.0734 2948        aspnet_state - ok
17:53:25.0828 2948        AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
17:53:26.0046 2948        AsyncMac - ok
17:53:26.0140 2948        atapi          (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
17:53:26.0359 2948        atapi - ok
17:53:26.0453 2948        Atdisk - ok
17:53:26.0531 2948        atksgt          (5b80e84af6b02ecab72dae9afee06309) C:\WINDOWS\system32\DRIVERS\atksgt.sys
17:53:26.0562 2948        atksgt ( UnsignedFile.Multi.Generic ) - warning
17:53:26.0562 2948        atksgt - detected UnsignedFile.Multi.Generic (1)
17:53:26.0656 2948        Atmarpc        (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
17:53:26.0890 2948        Atmarpc - ok
17:53:26.0968 2948        AudioSrv        (58ed0d5452df7be732193e7999c6b9a4) C:\WINDOWS\System32\audiosrv.dll
17:53:27.0187 2948        AudioSrv - ok
17:53:27.0359 2948        audstub        (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
17:53:27.0593 2948        audstub - ok
17:53:27.0671 2948        avgio          (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Programme\Avira\AntiVir Desktop\avgio.sys
17:53:27.0687 2948        avgio - ok
17:53:27.0796 2948        avgntflt        (1e4114685de1ffa9675e09c6a1fb3f4b) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
17:53:27.0937 2948        avgntflt - ok
17:53:28.0046 2948        avipbb          (0f78d3dae6dedd99ae54c9491c62adf2) C:\WINDOWS\system32\DRIVERS\avipbb.sys
17:53:28.0062 2948        avipbb - ok
17:53:28.0171 2948        Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
17:53:28.0390 2948        Beep - ok
17:53:28.0484 2948        BITS            (d6f603772a789bb3228f310d650b8bd1) C:\WINDOWS\system32\qmgr.dll
17:53:28.0781 2948        BITS - ok
17:53:28.0859 2948        Browser        (b42057f06bbb98b31876c0b3f2b54e33) C:\WINDOWS\System32\browser.dll
17:53:29.0078 2948        Browser - ok
17:53:29.0156 2948        cbidf          (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\System32\DRIVERS\cbidf2k.sys
17:53:29.0390 2948        cbidf - ok
17:53:29.0484 2948        cbidf2k        (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
17:53:29.0687 2948        cbidf2k - ok
17:53:29.0765 2948        cd20xrnt        (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\System32\DRIVERS\cd20xrnt.sys
17:53:29.0906 2948        cd20xrnt - ok
17:53:29.0984 2948        Cdaudio        (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
17:53:30.0218 2948        Cdaudio - ok
17:53:30.0296 2948        Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
17:53:30.0515 2948        Cdfs - ok
17:53:30.0593 2948        Cdrom          (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
17:53:30.0828 2948        Cdrom - ok
17:53:30.0906 2948        Changer - ok
17:53:30.0984 2948        CiSvc          (28e3040d1f1ca2008cd6b29dfebc9a5e) C:\WINDOWS\system32\cisvc.exe
17:53:31.0187 2948        CiSvc - ok
17:53:31.0265 2948        ClipSrv        (778a30ed3c134eb7e406afc407e9997d) C:\WINDOWS\system32\clipsrv.exe
17:53:31.0484 2948        ClipSrv - ok
17:53:31.0609 2948        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:53:31.0812 2948        clr_optimization_v4.0.30319_32 - ok
17:53:31.0906 2948        CmdIde          (c687f81290303d90099b027a6474f99f) C:\WINDOWS\System32\DRIVERS\cmdide.sys
17:53:32.0125 2948        CmdIde - ok
17:53:32.0171 2948        COMSysApp - ok
17:53:32.0250 2948        Cpqarray        (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\System32\DRIVERS\cpqarray.sys
17:53:32.0484 2948        Cpqarray - ok
17:53:32.0562 2948        CryptSvc        (611f824e5c703a5a899f84c5f1699e4d) C:\WINDOWS\System32\cryptsvc.dll
17:53:32.0781 2948        CryptSvc - ok
17:53:32.0875 2948        dac2w2k        (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\System32\DRIVERS\dac2w2k.sys
17:53:33.0093 2948        dac2w2k - ok
17:53:33.0187 2948        dac960nt        (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\System32\DRIVERS\dac960nt.sys
17:53:33.0406 2948        dac960nt - ok
17:53:33.0500 2948        DcomLaunch      (3127afbf2c1ed0ab14a1bbb7aaecb85b) C:\WINDOWS\system32\rpcss.dll
17:53:33.0765 2948        DcomLaunch - ok
17:53:33.0843 2948        delprot - ok
17:53:33.0968 2948        DfSdkS          (92ae26f2caf4a67e24a0ba6ddf32cc3c) C:\Programme\Ashampoo\Ashampoo WinOptimizer 9\DfsdkS.exe
17:53:34.0046 2948        DfSdkS ( UnsignedFile.Multi.Generic ) - warning
17:53:34.0046 2948        DfSdkS - detected UnsignedFile.Multi.Generic (1)
17:53:34.0140 2948        DgiVecp        (a5034f77b278f07e224fe07cf98a8b76) C:\WINDOWS\system32\Drivers\DgiVecp.sys
17:53:34.0187 2948        DgiVecp ( UnsignedFile.Multi.Generic ) - warning
17:53:34.0187 2948        DgiVecp - detected UnsignedFile.Multi.Generic (1)
17:53:34.0250 2948        Dhcp            (c29a1c9b75ba38fa37f8c44405dec360) C:\WINDOWS\System32\dhcpcsvc.dll
17:53:34.0468 2948        Dhcp - ok
17:53:34.0546 2948        Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
17:53:34.0765 2948        Disk - ok
17:53:34.0812 2948        dmadmin - ok
17:53:34.0921 2948        dmboot          (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
17:53:35.0187 2948        dmboot - ok
17:53:35.0265 2948        dmio            (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
17:53:35.0484 2948        dmio - ok
17:53:35.0578 2948        dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
17:53:35.0796 2948        dmload - ok
17:53:35.0890 2948        dmserver        (25c83ffbba13b554eb6d59a9b2e2ee78) C:\WINDOWS\System32\dmserver.dll
17:53:36.0093 2948        dmserver - ok
17:53:36.0187 2948        DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
17:53:36.0421 2948        DMusic - ok
17:53:36.0484 2948        Dnscache        (407f3227ac618fd1ca54b335b083de07) C:\WINDOWS\System32\dnsrslvr.dll
17:53:36.0593 2948        Dnscache - ok
17:53:36.0671 2948        Dot3svc        (676e36c4ff5bcea1900f44182b9723e6) C:\WINDOWS\System32\dot3svc.dll
17:53:36.0890 2948        Dot3svc - ok
17:53:36.0984 2948        dpti2o          (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\System32\DRIVERS\dpti2o.sys
17:53:37.0203 2948        dpti2o - ok
17:53:37.0296 2948        drmkaud        (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
17:53:37.0515 2948        drmkaud - ok
17:53:37.0625 2948        dtscsi          (6461e57bb51a848aae26f52427b7cf9e) C:\WINDOWS\System32\Drivers\dtscsi.sys
17:53:37.0718 2948        dtscsi - ok
17:53:38.0078 2948        E100B          (98b46b331404a951cabad8b4877e1276) C:\WINDOWS\system32\DRIVERS\e100b325.sys
17:53:38.0140 2948        E100B - ok
17:53:38.0218 2948        EapHost        (4e4f2fddab0a0736d7671134dcce91fb) C:\WINDOWS\System32\eapsvc.dll
17:53:38.0437 2948        EapHost - ok
17:53:38.0500 2948        EGATHDRV        (7f220875288944c9c7856e2bc8613b1f) C:\WINDOWS\SYSTEM32\EGATHDRV.SYS
17:53:38.0531 2948        EGATHDRV ( UnsignedFile.Multi.Generic ) - warning
17:53:38.0531 2948        EGATHDRV - detected UnsignedFile.Multi.Generic (1)
17:53:38.0609 2948        ERSvc          (877c18558d70587aa7823a1a308ac96b) C:\WINDOWS\System32\ersvc.dll
17:53:38.0812 2948        ERSvc - ok
17:53:38.0890 2948        Eventlog        (a3edbe9053889fb24ab22492472b39dc) C:\WINDOWS\system32\services.exe
17:53:39.0015 2948        Eventlog - ok
17:53:39.0125 2948        EventSystem    (af4f6b5739d18ca7972ab53e091cbc74) C:\WINDOWS\System32\es.dll
17:53:39.0187 2948        EventSystem - ok
17:53:39.0312 2948        Fastfat        (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
17:53:39.0515 2948        Fastfat - ok
17:53:39.0593 2948        FastUserSwitchingCompatibility (2db7d303c36ddd055215052f118e8e75) C:\WINDOWS\System32\shsvcs.dll
17:53:39.0687 2948        FastUserSwitchingCompatibility - ok
17:53:39.0781 2948        Fdc            (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
17:53:39.0984 2948        Fdc - ok
17:53:40.0078 2948        Fips            (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
17:53:40.0281 2948        Fips - ok
17:53:40.0375 2948        Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
17:53:40.0593 2948        Flpydisk - ok
17:53:40.0687 2948        FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
17:53:40.0906 2948        FltMgr - ok
17:53:41.0000 2948        Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
17:53:41.0234 2948        Fs_Rec - ok
17:53:41.0328 2948        Ftdisk          (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
17:53:41.0562 2948        Ftdisk - ok
17:53:41.0671 2948        GEARAspiWDM    (6f55305289a0765bd8ae8e8d32f17117) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
17:53:41.0703 2948        GEARAspiWDM - ok
17:53:41.0812 2948        Gpc            (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
17:53:42.0015 2948        Gpc - ok
17:53:42.0109 2948        gupdate        (f02a533f517eb38333cb12a9e8963773) C:\Programme\Google\Update\GoogleUpdate.exe
17:53:42.0125 2948        gupdate - ok
17:53:42.0140 2948        gupdatem        (f02a533f517eb38333cb12a9e8963773) C:\Programme\Google\Update\GoogleUpdate.exe
17:53:42.0171 2948        gupdatem - ok
17:53:42.0250 2948        helpsvc        (cb66bf85bf599befd6c6a57c2e20357f) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
17:53:42.0468 2948        helpsvc - ok
17:53:42.0531 2948        HidServ        (b35da85e60c0103f2e4104532da2f12b) C:\WINDOWS\System32\hidserv.dll
17:53:42.0921 2948        HidServ - ok
17:53:43.0046 2948        HidUsb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
17:53:43.0250 2948        HidUsb - ok
17:53:43.0328 2948        hkmsvc          (ed29f14101523a6e0e808107405d452c) C:\WINDOWS\System32\kmsvc.dll
17:53:43.0546 2948        hkmsvc - ok
17:53:43.0625 2948        hpn            (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\System32\DRIVERS\hpn.sys
17:53:43.0843 2948        hpn - ok
17:53:43.0937 2948        HTTP            (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
17:53:44.0000 2948        HTTP - ok
17:53:44.0078 2948        HTTPFilter      (9e4adb854cebcfb81a4b36718feecd16) C:\WINDOWS\System32\w3ssl.dll
17:53:44.0296 2948        HTTPFilter - ok
17:53:44.0406 2948        i2omgmt        (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
17:53:44.0609 2948        i2omgmt - ok
17:53:44.0703 2948        i2omp          (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\System32\DRIVERS\i2omp.sys
17:53:44.0906 2948        i2omp - ok
17:53:45.0000 2948        i8042prt        (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
17:53:45.0187 2948        i8042prt - ok
17:53:45.0281 2948        ialm            (cfc89f98c436c6687bd818abb6a4480b) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
17:53:45.0515 2948        ialm - ok
17:53:45.0609 2948        IBM Rapid Restore Ultra Service (1a1b8fd95d598d9d772333283154a1b5) C:\Programme\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
17:53:45.0687 2948        IBM Rapid Restore Ultra Service ( UnsignedFile.Multi.Generic ) - warning
17:53:45.0687 2948        IBM Rapid Restore Ultra Service - detected UnsignedFile.Multi.Generic (1)
17:53:45.0796 2948        ibmfilter      (4dc41ab5aa3f96fa7f01587dd9ccf467) C:\WINDOWS\system32\drivers\ibmfilter.sys
17:53:45.0812 2948        ibmfilter ( UnsignedFile.Multi.Generic ) - warning
17:53:45.0812 2948        ibmfilter - detected UnsignedFile.Multi.Generic (1)
17:53:45.0921 2948        IDriverT        (1cf03c69b49acb70c722df92755c0c8c) C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
17:53:46.0000 2948        IDriverT ( UnsignedFile.Multi.Generic ) - warning
17:53:46.0000 2948        IDriverT - detected UnsignedFile.Multi.Generic (1)
17:53:46.0109 2948        Imapi          (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
17:53:46.0328 2948        Imapi - ok
17:53:46.0406 2948        ImapiService    (d4b413aa210c21e46aedd2ba5b68d38e) C:\WINDOWS\System32\imapi.exe
17:53:46.0625 2948        ImapiService - ok
17:53:46.0718 2948        ini910u        (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\System32\DRIVERS\ini910u.sys
17:53:46.0953 2948        ini910u - ok
17:53:47.0046 2948        IntelIde        (69c4e3c9e67a1f103b94e14fdd5f3213) C:\WINDOWS\System32\DRIVERS\intelide.sys
17:53:47.0250 2948        IntelIde - ok
17:53:47.0343 2948        intelppm        (4c7d2750158ed6e7ad642d97bffae351) C:\WINDOWS\system32\DRIVERS\intelppm.sys
17:53:47.0562 2948        intelppm - ok
17:53:47.0640 2948        ip6fw          (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
17:53:47.0843 2948        ip6fw - ok
17:53:47.0937 2948        IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
17:53:48.0156 2948        IpFilterDriver - ok
17:53:48.0250 2948        IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
17:53:48.0453 2948        IpInIp - ok
17:53:48.0531 2948        IpNat          (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
17:53:48.0734 2948        IpNat - ok
17:53:48.0843 2948        IPSec          (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
17:53:49.0062 2948        IPSec - ok
17:53:49.0156 2948        IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
17:53:49.0359 2948        IRENUM - ok
17:53:49.0468 2948        isapnp          (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
17:53:49.0687 2948        isapnp - ok
17:53:49.0781 2948        Kbdclass        (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
17:53:50.0000 2948        Kbdclass - ok
17:53:50.0093 2948        kmixer          (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
17:53:50.0312 2948        kmixer - ok
17:53:50.0437 2948        KSecDD          (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
17:53:50.0718 2948        KSecDD - ok
17:53:50.0796 2948        lanmanserver    (2bbdcb79900990f0716dfcb714e72de7) C:\WINDOWS\System32\srvsvc.dll
17:53:50.0859 2948        lanmanserver - ok
17:53:50.0921 2948        lanmanworkstation (1869b14b06b44b44af70548e1ea3303f) C:\WINDOWS\System32\wkssvc.dll
17:53:50.0984 2948        lanmanworkstation - ok
17:53:51.0062 2948        lbrtfdc - ok
17:53:51.0156 2948        lirsgt          (975b6cf65f44e95883f3855bae8cecaf) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
17:53:51.0171 2948        lirsgt ( UnsignedFile.Multi.Generic ) - warning
17:53:51.0171 2948        lirsgt - detected UnsignedFile.Multi.Generic (1)
17:53:51.0281 2948        LiveTunerPM    (1307c0131756a1160b1821ce8293fe64) C:\Programme\Ashampoo\Ashampoo WinOptimizer 9\LiveTunerProcessMonitor32.sys
17:53:51.0296 2948        LiveTunerPM - ok
17:53:51.0359 2948        LmHosts        (636714b7d43c8d0c80449123fd266920) C:\WINDOWS\System32\lmhsvc.dll
17:53:51.0578 2948        LmHosts - ok
17:53:51.0687 2948        MBAMProtector  (fb097bbc1a18f044bd17bd2fccf97865) C:\WINDOWS\system32\drivers\mbam.sys
17:53:51.0703 2948        MBAMProtector - ok
17:53:51.0765 2948        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
17:53:51.0843 2948        MBAMService - ok
17:53:51.0937 2948        MBAMSwissArmy  (0db7527db188c7d967a37bb51bbf3963) C:\WINDOWS\system32\drivers\mbamswissarmy.sys
17:53:51.0953 2948        MBAMSwissArmy - ok
17:53:52.0031 2948        Messenger      (b7550a7107281d170ce85524b1488c98) C:\WINDOWS\System32\msgsvc.dll
17:53:52.0234 2948        Messenger - ok
17:53:52.0328 2948        Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe
17:53:52.0375 2948        Microsoft Office Groove Audit Service - ok
17:53:52.0453 2948        mnmdd          (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
17:53:52.0671 2948        mnmdd - ok
17:53:52.0750 2948        mnmsrvc        (c2f1d365fd96791b037ee504868065d3) C:\WINDOWS\System32\mnmsrvc.exe
17:53:52.0968 2948        mnmsrvc - ok
17:53:53.0062 2948        Modem          (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
17:53:53.0281 2948        Modem - ok
17:53:53.0406 2948        Mouclass        (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
17:53:53.0625 2948        Mouclass - ok
17:53:53.0734 2948        mouhid          (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
17:53:53.0937 2948        mouhid - ok
17:53:54.0031 2948        MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
17:53:54.0234 2948        MountMgr - ok
17:53:54.0312 2948        mraid35x        (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\System32\DRIVERS\mraid35x.sys
17:53:54.0546 2948        mraid35x - ok
17:53:54.0671 2948        MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
17:53:54.0875 2948        MRxDAV - ok
17:53:54.0984 2948        MRxSmb          (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
17:53:55.0109 2948        MRxSmb - ok
17:53:55.0171 2948        MSDTC          (35a031af38c55f92d28aa03ee9f12cc9) C:\WINDOWS\system32\msdtc.exe
17:53:55.0375 2948        MSDTC - ok
17:53:55.0484 2948        Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
17:53:55.0703 2948        Msfs - ok
17:53:55.0781 2948        MSIServer - ok
17:53:55.0859 2948        MSKSSRV        (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
17:53:56.0062 2948        MSKSSRV - ok
17:53:56.0171 2948        MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
17:53:56.0375 2948        MSPCLOCK - ok
17:53:56.0484 2948        MSPQM          (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
17:53:56.0687 2948        MSPQM - ok
17:53:56.0781 2948        mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
17:53:56.0984 2948        mssmbios - ok
17:53:57.0109 2948        Mup            (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
17:53:57.0171 2948        Mup - ok
17:53:57.0265 2948        napagent        (46bb15ae2ac7d025d6d2567b876817bd) C:\WINDOWS\System32\qagentrt.dll
17:53:57.0515 2948        napagent - ok
17:53:57.0625 2948        NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
17:53:57.0843 2948        NDIS - ok
17:53:57.0937 2948        NdisTapi        (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
17:53:58.0000 2948        NdisTapi - ok
17:53:58.0109 2948        Ndisuio        (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
17:53:58.0328 2948        Ndisuio - ok
17:53:58.0437 2948        NdisWan        (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
17:53:58.0640 2948        NdisWan - ok
17:53:58.0750 2948        NDProxy        (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
17:53:58.0828 2948        NDProxy - ok
17:53:58.0921 2948        NetBIOS        (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
17:53:59.0109 2948        NetBIOS - ok
17:53:59.0218 2948        NetBT          (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
17:53:59.0437 2948        NetBT - ok
17:53:59.0531 2948        NetDDE          (8ace4251bffd09ce75679fe940e996cc) C:\WINDOWS\system32\netdde.exe
17:53:59.0765 2948        NetDDE - ok
17:53:59.0812 2948        NetDDEdsdm      (8ace4251bffd09ce75679fe940e996cc) C:\WINDOWS\system32\netdde.exe
17:54:00.0031 2948        NetDDEdsdm - ok
17:54:00.0109 2948        Netlogon        (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\System32\lsass.exe
17:54:00.0328 2948        Netlogon - ok
17:54:00.0437 2948        Netman          (e6d88f1f6745bf00b57e7855a2ab696c) C:\WINDOWS\System32\netman.dll
17:54:00.0656 2948        Netman - ok
17:54:00.0765 2948        NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:54:00.0812 2948        NetTcpPortSharing - ok
17:54:00.0921 2948        Nla            (f1b67b6b0751ae0e6e964b02821206a3) C:\WINDOWS\System32\mswsock.dll
17:54:01.0062 2948        Nla - ok
17:54:01.0125 2948        NMSAccess      (7aea4df1ca68fd45dd4bbe1f0243ce7f) C:\Programme\CDBurnerXP\NMSAccessU.exe
17:54:01.0171 2948        NMSAccess - ok
17:54:01.0265 2948        Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
17:54:01.0453 2948        Npfs - ok
17:54:01.0531 2948        Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
17:54:01.0796 2948        Ntfs - ok
17:54:01.0890 2948        NtLmSsp        (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\System32\lsass.exe
17:54:02.0078 2948        NtLmSsp - ok
17:54:02.0187 2948        NtmsSvc        (56af4064996fa5bac9c449b1514b4770) C:\WINDOWS\system32\ntmssvc.dll
17:54:02.0453 2948        NtmsSvc - ok
17:54:02.0562 2948        Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
17:54:02.0781 2948        Null - ok
17:54:02.0906 2948        nv              (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
17:54:03.0218 2948        nv - ok
17:54:03.0343 2948        NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
17:54:03.0578 2948        NwlnkFlt - ok
17:54:03.0671 2948        NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
17:54:03.0890 2948        NwlnkFwd - ok
17:54:04.0000 2948        NwlnkIpx        (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
17:54:04.0203 2948        NwlnkIpx - ok
17:54:04.0296 2948        NwlnkNb        (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
17:54:04.0515 2948        NwlnkNb - ok
17:54:04.0593 2948        NwlnkSpx        (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
17:54:04.0812 2948        NwlnkSpx - ok
17:54:04.0859 2948        obvious - ok
17:54:04.0968 2948        odserv          (785f487a64950f3cb8e9f16253ba3b7b) C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE
17:54:05.0031 2948        odserv - ok
17:54:05.0125 2948        ose            (5a432a042dae460abe7199b758e8606c) C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE
17:54:05.0156 2948        ose - ok
17:54:05.0281 2948        Parport        (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\DRIVERS\parport.sys
17:54:05.0500 2948        Parport - ok
17:54:05.0593 2948        PartMgr        (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
17:54:05.0796 2948        PartMgr - ok
17:54:05.0875 2948        ParVdm          (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
17:54:06.0093 2948        ParVdm - ok
17:54:06.0156 2948        PCDRSRVC - ok
17:54:06.0218 2948        PCI            (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
17:54:06.0421 2948        PCI - ok
17:54:06.0500 2948        PCIDump - ok
17:54:06.0578 2948        PCIIde          (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
17:54:06.0812 2948        PCIIde - ok
17:54:06.0906 2948        Pcmcia          (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\drivers\Pcmcia.sys
17:54:07.0125 2948        Pcmcia - ok
17:54:07.0187 2948        PDCOMP - ok
17:54:07.0250 2948        PDFRAME - ok
17:54:07.0312 2948        PDRELI - ok
17:54:07.0375 2948        PDRFRAME - ok
17:54:07.0453 2948        pelmouse        (e541a80cdffd6077c761b4578efc0450) C:\WINDOWS\system32\DRIVERS\pelmouse.sys
17:54:07.0500 2948        pelmouse - ok
17:54:07.0609 2948        pelusblf        (6432858a4493e906a7d61b9b17a0672a) C:\WINDOWS\system32\DRIVERS\pelusblf.sys
17:54:07.0640 2948        pelusblf - ok
17:54:07.0734 2948        perc2          (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\System32\DRIVERS\perc2.sys
17:54:07.0968 2948        perc2 - ok
17:54:08.0046 2948        perc2hib        (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\System32\DRIVERS\perc2hib.sys
17:54:08.0281 2948        perc2hib - ok
17:54:08.0375 2948        PlugPlay        (a3edbe9053889fb24ab22492472b39dc) C:\WINDOWS\system32\services.exe
17:54:08.0500 2948        PlugPlay - ok
17:54:08.0578 2948        PMEM            (fa292805788528c083f416e151b60ab6) C:\WINDOWS\system32\drivers\PMEMNT.SYS
17:54:08.0609 2948        PMEM ( UnsignedFile.Multi.Generic ) - warning
17:54:08.0609 2948        PMEM - detected UnsignedFile.Multi.Generic (1)
17:54:08.0687 2948        PolicyAgent    (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\System32\lsass.exe
17:54:08.0890 2948        PolicyAgent - ok
17:54:08.0984 2948        PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
17:54:09.0187 2948        PptpMiniport - ok
17:54:09.0265 2948        Processor      (2cb55427c58679f49ad600fccba76360) C:\WINDOWS\system32\DRIVERS\processr.sys
17:54:09.0468 2948        Processor - ok
17:54:09.0578 2948        prodrv06        (6d3b2fc5dec2f59b28fe5fa17250a7b0) C:\WINDOWS\System32\drivers\prodrv06.sys
17:54:09.0609 2948        prodrv06 ( UnsignedFile.Multi.Generic ) - warning
17:54:09.0609 2948        prodrv06 - detected UnsignedFile.Multi.Generic (1)
17:54:09.0718 2948        prohlp02        (c5f47b7ec2ec906847d5f80ba779a5bd) C:\WINDOWS\system32\drivers\prohlp02.sys
17:54:09.0750 2948        prohlp02 ( UnsignedFile.Multi.Generic ) - warning
17:54:09.0750 2948        prohlp02 - detected UnsignedFile.Multi.Generic (1)
17:54:09.0859 2948        prosync1        (f3471e7971ee62420451d958da635064) C:\WINDOWS\system32\drivers\prosync1.sys
17:54:09.0875 2948        prosync1 ( UnsignedFile.Multi.Generic ) - warning
17:54:09.0875 2948        prosync1 - detected UnsignedFile.Multi.Generic (1)
17:54:09.0953 2948        ProtectedStorage (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
17:54:10.0156 2948        ProtectedStorage - ok
17:54:10.0234 2948        psadd          (dc23b0d9a0282cb0d8281dbda431ac14) C:\WINDOWS\system32\Drivers\psadd.sys
17:54:10.0312 2948        psadd ( UnsignedFile.Multi.Generic ) - warning
17:54:10.0312 2948        psadd - detected UnsignedFile.Multi.Generic (1)
17:54:10.0437 2948        PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
17:54:10.0640 2948        PSched - ok
17:54:10.0718 2948        Ptilink        (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
17:54:10.0953 2948        Ptilink - ok
17:54:11.0015 2948        PxHelp20        (86724469cd077901706854974cd13c3e) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
17:54:11.0046 2948        PxHelp20 ( UnsignedFile.Multi.Generic ) - warning
17:54:11.0046 2948        PxHelp20 - detected UnsignedFile.Multi.Generic (1)
17:54:11.0156 2948        ql1080          (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\System32\DRIVERS\ql1080.sys
17:54:11.0375 2948        ql1080 - ok
17:54:11.0468 2948        Ql10wnt        (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\System32\DRIVERS\ql10wnt.sys
17:54:11.0687 2948        Ql10wnt - ok
17:54:11.0781 2948        ql12160        (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\System32\DRIVERS\ql12160.sys
17:54:11.0984 2948        ql12160 - ok
17:54:12.0062 2948        ql1240          (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\System32\DRIVERS\ql1240.sys
17:54:12.0296 2948        ql1240 - ok
17:54:12.0390 2948        ql1280          (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\System32\DRIVERS\ql1280.sys
17:54:12.0609 2948        ql1280 - ok
17:54:12.0687 2948        RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
17:54:12.0890 2948        RasAcd - ok
17:54:12.0968 2948        RasAuto        (f5ba6caccdb66c8f048e867563203246) C:\WINDOWS\System32\rasauto.dll
17:54:13.0187 2948        RasAuto - ok
17:54:13.0296 2948        Rasl2tp        (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
17:54:13.0500 2948        Rasl2tp - ok
17:54:13.0578 2948        RasMan          (f9a7b66ea345726edb5862a46b1eccd5) C:\WINDOWS\System32\rasmans.dll
17:54:13.0781 2948        RasMan - ok
17:54:13.0875 2948        RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
17:54:14.0078 2948        RasPppoe - ok
17:54:14.0187 2948        Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
17:54:14.0437 2948        Raspti - ok
17:54:14.0531 2948        Rdbss          (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
17:54:14.0750 2948        Rdbss - ok
17:54:14.0859 2948        RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
17:54:15.0062 2948        RDPCDD - ok
17:54:15.0140 2948        rdpdr          (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
17:54:15.0359 2948        rdpdr - ok
17:54:15.0468 2948        RDPWD          (5b3055daa788bd688594d2f5981f2a83) C:\WINDOWS\system32\drivers\RDPWD.sys
17:54:15.0531 2948        RDPWD - ok
17:54:15.0625 2948        RDSessMgr      (263af18af0f3db99f574c95f284ccec9) C:\WINDOWS\system32\sessmgr.exe
17:54:15.0828 2948        RDSessMgr - ok
17:54:15.0921 2948        redbook        (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
17:54:16.0125 2948        redbook - ok
17:54:16.0203 2948        RemoteAccess    (0e97ec96d6942ceec2d188cc2eb69a01) C:\WINDOWS\System32\mprdim.dll
17:54:16.0406 2948        RemoteAccess - ok
17:54:16.0500 2948        RemoteRegistry  (e4cd1f3d84e1c2ca0b8cf7501e201593) C:\WINDOWS\system32\regsvc.dll
17:54:16.0718 2948        RemoteRegistry - ok
17:54:16.0796 2948        ROOTMODEM      (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
17:54:17.0031 2948        ROOTMODEM - ok
17:54:17.0093 2948        RpcLocator      (2a02e21867497df20b8fc95631395169) C:\WINDOWS\System32\locator.exe
17:54:17.0296 2948        RpcLocator - ok
17:54:17.0375 2948        RpcSs          (3127afbf2c1ed0ab14a1bbb7aaecb85b) C:\WINDOWS\system32\rpcss.dll
17:54:17.0500 2948        RpcSs - ok
17:54:17.0578 2948        RSVP            (4bdd71b4b521521499dfd14735c4f398) C:\WINDOWS\System32\rsvp.exe
17:54:17.0796 2948        RSVP - ok
17:54:17.0875 2948        SamSs          (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
17:54:18.0062 2948        SamSs - ok
17:54:18.0140 2948        SCardSvr        (dcec079fad95d36c8dd5cb6d779dfe32) C:\WINDOWS\System32\SCardSvr.exe
17:54:18.0359 2948        SCardSvr - ok
17:54:18.0453 2948        Schedule        (a050194a44d7fa8d7186ed2f4e8367ae) C:\WINDOWS\system32\schedsvc.dll
17:54:18.0671 2948        Schedule - ok
17:54:18.0781 2948        Secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
17:54:19.0046 2948        Secdrv - ok
17:54:19.0109 2948        seclogon        (bee4cfd1d48c23b44cf4b974b0b79b2b) C:\WINDOWS\System32\seclogon.dll
17:54:19.0328 2948        seclogon - ok
17:54:19.0437 2948        SENS            (2aac9b6ed9eddffb721d6452e34d67e3) C:\WINDOWS\system32\sens.dll
17:54:19.0656 2948        SENS - ok
17:54:19.0750 2948        serenum        (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
17:54:19.0953 2948        serenum - ok
17:54:20.0078 2948        Serial          (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\DRIVERS\serial.sys
17:54:20.0281 2948        Serial - ok
17:54:20.0421 2948        sfhlp01        (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
17:54:20.0453 2948        sfhlp01 ( UnsignedFile.Multi.Generic ) - warning
17:54:20.0453 2948        sfhlp01 - detected UnsignedFile.Multi.Generic (1)
17:54:20.0546 2948        Sfloppy        (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
17:54:20.0750 2948        Sfloppy - ok
17:54:20.0843 2948        SharedAccess    (cad058d5f8b889a87ca3eb3cf624dcef) C:\WINDOWS\System32\ipnathlp.dll
17:54:21.0093 2948        SharedAccess - ok
17:54:21.0156 2948        ShellHWDetection (2db7d303c36ddd055215052f118e8e75) C:\WINDOWS\System32\shsvcs.dll
17:54:21.0203 2948        ShellHWDetection - ok
17:54:21.0296 2948        Simbad - ok
17:54:21.0343 2948        SipIMNDI - ok
17:54:21.0421 2948        sisagp          (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\System32\DRIVERS\sisagp.sys
17:54:21.0640 2948        sisagp - ok
17:54:21.0765 2948        smwdm          (f41896d591106713649b7eba668324e6) C:\WINDOWS\system32\drivers\smwdm.sys
17:54:21.0843 2948        smwdm - ok
17:54:21.0937 2948        Sparrow        (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\System32\DRIVERS\sparrow.sys
17:54:22.0062 2948        Sparrow - ok
17:54:22.0156 2948        splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
17:54:22.0359 2948        splitter - ok
17:54:22.0437 2948        Spooler        (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
17:54:22.0484 2948        Spooler - ok
17:54:22.0578 2948        sr              (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
17:54:22.0796 2948        sr - ok
17:54:22.0890 2948        srservice      (fe77a85495065f3ad59c5c65b6c54182) C:\WINDOWS\System32\srsvc.dll
17:54:23.0093 2948        srservice - ok
17:54:23.0218 2948        Srv            (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
17:54:23.0296 2948        Srv - ok
17:54:23.0359 2948        SSDPSRV        (4df5b05dfaec29e13e1ed6f6ee12c500) C:\WINDOWS\System32\ssdpsrv.dll
17:54:23.0593 2948        SSDPSRV - ok
17:54:23.0703 2948        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
17:54:23.0718 2948        ssmdrv - ok
17:54:23.0796 2948        StarOpen        (e57b778208c783d8debab320c16a1b82) C:\WINDOWS\system32\drivers\StarOpen.sys
17:54:23.0812 2948        StarOpen ( UnsignedFile.Multi.Generic ) - warning
17:54:23.0812 2948        StarOpen - detected UnsignedFile.Multi.Generic (1)
17:54:23.0890 2948        stisvc          (bc2c5985611c5356b24aeb370953ded9) C:\WINDOWS\system32\wiaservc.dll
17:54:24.0156 2948        stisvc - ok
17:54:24.0250 2948        swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
17:54:24.0453 2948        swenum - ok
17:54:24.0546 2948        swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
17:54:24.0765 2948        swmidi - ok
17:54:24.0812 2948        SwPrv - ok
17:54:24.0890 2948        symc810        (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\System32\DRIVERS\symc810.sys
17:54:25.0109 2948        symc810 - ok
17:54:25.0203 2948        symc8xx        (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\System32\DRIVERS\symc8xx.sys
17:54:25.0421 2948        symc8xx - ok
17:54:25.0531 2948        SymEvent        (403bd24fa5c55fc648abdd039629a954) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
17:54:25.0578 2948        SymEvent - ok
17:54:25.0671 2948        sym_hi          (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\System32\DRIVERS\sym_hi.sys
17:54:25.0890 2948        sym_hi - ok
17:54:25.0968 2948        sym_u3          (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\System32\DRIVERS\sym_u3.sys
17:54:26.0187 2948        sym_u3 - ok
17:54:26.0265 2948        sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
17:54:26.0484 2948        sysaudio - ok
17:54:26.0562 2948        SysmonLog      (2903fffa2523926d6219428040dce6b9) C:\WINDOWS\system32\smlogsvc.exe
17:54:26.0765 2948        SysmonLog - ok
17:54:26.0859 2948        TapiSrv        (05903cac4b98908d55ea5774775b382e) C:\WINDOWS\System32\tapisrv.dll
17:54:27.0062 2948        TapiSrv - ok
17:54:27.0171 2948        tbhsd          (adeb5b39e08282a81ef6998e8c76e269) C:\WINDOWS\system32\drivers\tbhsd.sys
17:54:27.0203 2948        tbhsd ( UnsignedFile.Multi.Generic ) - warning
17:54:27.0203 2948        tbhsd - detected UnsignedFile.Multi.Generic (1)
17:54:27.0312 2948        Tcpip          (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
17:54:27.0453 2948        Tcpip - ok
17:54:27.0531 2948        TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
17:54:27.0718 2948        TDPIPE - ok
17:54:27.0796 2948        TDTCP          (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
17:54:28.0015 2948        TDTCP - ok
17:54:28.0093 2948        TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
17:54:28.0312 2948        TermDD - ok
17:54:28.0406 2948        TermService    (b7de02c863d8f5a005a7bf375375a6a4) C:\WINDOWS\System32\termsrv.dll
17:54:28.0625 2948        TermService - ok
17:54:28.0703 2948        Themes          (2db7d303c36ddd055215052f118e8e75) C:\WINDOWS\System32\shsvcs.dll
17:54:28.0734 2948        Themes - ok
17:54:28.0812 2948        TlntSvr        (03681a1ce77f51586903869a5ab1deab) C:\WINDOWS\System32\tlntsvr.exe
17:54:29.0015 2948        TlntSvr - ok
17:54:29.0125 2948        toshidpt        (62c57e7411b5f20980e70530ca69d5a7) C:\WINDOWS\system32\drivers\Toshidpt.sys
17:54:29.0140 2948        toshidpt ( UnsignedFile.Multi.Generic ) - warning
17:54:29.0140 2948        toshidpt - detected UnsignedFile.Multi.Generic (1)
17:54:29.0250 2948        TosIde          (d213a9247dc347f305a2d4cc9b951487) C:\WINDOWS\System32\DRIVERS\toside.sys
17:54:29.0468 2948        TosIde - ok
17:54:29.0562 2948        tosporte        (09505abeae3de953442417a48256684a) C:\WINDOWS\system32\DRIVERS\tosporte.sys
17:54:29.0593 2948        tosporte ( UnsignedFile.Multi.Generic ) - warning
17:54:29.0593 2948        tosporte - detected UnsignedFile.Multi.Generic (1)
17:54:29.0687 2948        Tosrfbd        (9b478a68d0f627ed3c4c4a48e86c5509) C:\WINDOWS\system32\Drivers\tosrfbd.sys
17:54:29.0703 2948        Tosrfbd ( UnsignedFile.Multi.Generic ) - warning
17:54:29.0703 2948        Tosrfbd - detected UnsignedFile.Multi.Generic (1)
17:54:29.0812 2948        Tosrfbnp        (fe200eece7521061cdad658c6ee4f341) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
17:54:29.0843 2948        Tosrfbnp ( UnsignedFile.Multi.Generic ) - warning
17:54:29.0843 2948        Tosrfbnp - detected UnsignedFile.Multi.Generic (1)
17:54:29.0953 2948        Tosrfcom        (d185be751021bcf1e5d58566d408314a) C:\WINDOWS\system32\Drivers\tosrfcom.sys
17:54:29.0984 2948        Tosrfcom ( UnsignedFile.Multi.Generic ) - warning
17:54:29.0984 2948        Tosrfcom - detected UnsignedFile.Multi.Generic (1)
17:54:30.0078 2948        Tosrfhid        (341612b9758054e5965bcd6ae111b8f9) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
17:54:30.0109 2948        Tosrfhid ( UnsignedFile.Multi.Generic ) - warning
17:54:30.0109 2948        Tosrfhid - detected UnsignedFile.Multi.Generic (1)
17:54:30.0203 2948        tosrfnds        (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
17:54:30.0218 2948        tosrfnds ( UnsignedFile.Multi.Generic ) - warning
17:54:30.0218 2948        tosrfnds - detected UnsignedFile.Multi.Generic (1)
17:54:30.0328 2948        TosRfSnd        (350814a87f8ba3b0e28278feddf36f82) C:\WINDOWS\system32\drivers\TosRfSnd.sys
17:54:30.0343 2948        TosRfSnd ( UnsignedFile.Multi.Generic ) - warning
17:54:30.0343 2948        TosRfSnd - detected UnsignedFile.Multi.Generic (1)
17:54:30.0453 2948        Tosrfusb        (ddb8a339e57d514768f45d33b11bdb50) C:\WINDOWS\system32\Drivers\tosrfusb.sys
17:54:30.0484 2948        Tosrfusb ( UnsignedFile.Multi.Generic ) - warning
17:54:30.0484 2948        Tosrfusb - detected UnsignedFile.Multi.Generic (1)
17:54:30.0578 2948        TrkWks          (626504572b175867f30f3215c04b3e2f) C:\WINDOWS\system32\trkwks.dll
17:54:30.0781 2948        TrkWks - ok
17:54:30.0890 2948        Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
17:54:31.0109 2948        Udfs - ok
17:54:31.0203 2948        ultra          (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\System32\DRIVERS\ultra.sys
17:54:31.0328 2948        ultra - ok
17:54:31.0453 2948        Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
17:54:31.0703 2948        Update - ok
17:54:31.0796 2948        upnphost        (1dfd8975d8c89214b98d9387c1125b49) C:\WINDOWS\System32\upnphost.dll
17:54:32.0015 2948        upnphost - ok
17:54:32.0109 2948        UPS            (9b11e6118958e63e1fef129466e2bda7) C:\WINDOWS\System32\ups.exe
17:54:32.0312 2948        UPS - ok
17:54:32.0437 2948        usbaudio        (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
17:54:32.0671 2948        usbaudio - ok
17:54:32.0765 2948        usbccgp        (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
17:54:32.0968 2948        usbccgp - ok
17:54:33.0078 2948        usbehci        (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
17:54:33.0265 2948        usbehci - ok
17:54:33.0343 2948        usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
17:54:33.0578 2948        usbhub - ok
17:54:33.0671 2948        usbprint        (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
17:54:33.0875 2948        usbprint - ok
17:54:33.0968 2948        usbscan        (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
17:54:34.0171 2948        usbscan - ok
17:54:34.0265 2948        USBSTOR        (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:54:34.0484 2948        USBSTOR - ok
17:54:34.0546 2948        usbuhci        (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
17:54:34.0750 2948        usbuhci - ok
17:54:34.0859 2948        UxTuneUp        (1ff581035c4ea7a75dfb3939c7b7cbd2) C:\WINDOWS\System32\uxtuneup.dll
17:54:34.0875 2948        UxTuneUp - ok
17:54:34.0968 2948        vaxscsi        (92cebc2bc7be2c8d49391b365569f306) C:\WINDOWS\System32\Drivers\vaxscsi.sys
17:54:35.0000 2948        vaxscsi - ok
17:54:35.0093 2948        VgaSave        (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
17:54:35.0296 2948        VgaSave - ok
17:54:35.0375 2948        viaagp          (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\System32\DRIVERS\viaagp.sys
17:54:35.0593 2948        viaagp - ok
17:54:35.0703 2948        ViaIde          (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\System32\DRIVERS\viaide.sys
17:54:35.0906 2948        ViaIde - ok
17:54:35.0984 2948        VolSnap        (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
17:54:36.0171 2948        VolSnap - ok
17:54:36.0281 2948        VSS            (68f106273be29e7b7ef8266977268e78) C:\WINDOWS\System32\vssvc.exe
17:54:36.0515 2948        VSS - ok
17:54:36.0625 2948        W32Time        (7b353059e665f8b7ad2bbeaef597cf45) C:\WINDOWS\System32\w32time.dll
17:54:36.0843 2948        W32Time - ok
17:54:36.0937 2948        Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
17:54:37.0140 2948        Wanarp - ok
17:54:37.0203 2948        WDICA - ok
17:54:37.0281 2948        wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
17:54:37.0500 2948        wdmaud - ok
17:54:37.0578 2948        WebClient      (81727c9873e3905a2ffc1ebd07265002) C:\WINDOWS\System32\webclnt.dll
17:54:37.0781 2948        WebClient - ok
17:54:37.0921 2948        winmgmt        (6f3f3973d97714cc5f906a19fe883729) C:\WINDOWS\system32\wbem\WMIsvc.dll
17:54:38.0125 2948        winmgmt - ok
17:54:38.0250 2948        WmdmPmSN        (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll
17:54:38.0359 2948        WmdmPmSN - ok
17:54:38.0468 2948        Wmi            (ffa4d901d46d07a5bab2d8307fbb51a6) C:\WINDOWS\System32\advapi32.dll
17:54:38.0640 2948        Wmi - ok
17:54:38.0750 2948        WmiApSrv        (93908111ba57a6e60ec2fa2de202105c) C:\WINDOWS\System32\wbem\wmiapsrv.exe
17:54:38.0953 2948        WmiApSrv - ok
17:54:39.0062 2948        WMPNetworkSvc  (bf05650bb7df5e9ebdd25974e22403bb) C:\Programme\Windows Media Player\WMPNetwk.exe
17:54:39.0156 2948        WMPNetworkSvc - ok
17:54:39.0281 2948        WO_LiveService  (f491c8e5ee9d75a06dc36ede5a7a8938) C:\Programme\Ashampoo\Ashampoo WinOptimizer 9\LiveTunerService.exe
17:54:39.0375 2948        WO_LiveService - ok
17:54:39.0546 2948        WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
17:54:39.0625 2948        WPFFontCache_v0400 - ok
17:54:39.0718 2948        WS2IFSL        (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
17:54:39.0937 2948        WS2IFSL - ok
17:54:40.0031 2948        wscsvc          (300b3e84faf1a5c1f791c159ba28035d) C:\WINDOWS\system32\wscsvc.dll
17:54:40.0250 2948        wscsvc - ok
17:54:40.0328 2948        wuauserv        (7b4fe05202aa6bf9f4dfd0e6a0d8a085) C:\WINDOWS\system32\wuauserv.dll
17:54:40.0531 2948        wuauserv - ok
17:54:40.0656 2948        WudfPf          (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
17:54:40.0718 2948        WudfPf - ok
17:54:40.0828 2948        WudfRd          (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
17:54:40.0859 2948        WudfRd - ok
17:54:40.0953 2948        WudfSvc        (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
17:54:40.0984 2948        WudfSvc - ok
17:54:41.0078 2948        WZCSVC          (c4f109c005f6725162d2d12ca751e4a7) C:\WINDOWS\System32\wzcsvc.dll
17:54:41.0328 2948        WZCSVC - ok
17:54:41.0406 2948        xmlprov        (0ada34871a2e1cd2caafed1237a47750) C:\WINDOWS\System32\xmlprov.dll
17:54:41.0625 2948        xmlprov - ok
17:54:41.0718 2948        {6080A529-897E-4629-A488-ABA0C29B635E} (5ff57eedf48f189859d6e9bf81e297c5) C:\WINDOWS\system32\drivers\ialmsbw.sys
17:54:41.0781 2948        {6080A529-897E-4629-A488-ABA0C29B635E} - ok
17:54:41.0875 2948        {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (c2eb14d84069443437f1b3b856bcb665) C:\WINDOWS\system32\drivers\ialmkchw.sys
17:54:41.0921 2948        {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
17:54:41.0937 2948        MBR (0x1B8)    (eb5d8b1054084399a9e2887ab969ae15) \Device\Harddisk0\DR0
17:54:42.0015 2948        \Device\Harddisk0\DR0 - ok
17:54:42.0031 2948        Boot (0x1200)  (29ba236c840db6ae0978678f9ce8cdb8) \Device\Harddisk0\DR0\Partition0
17:54:42.0031 2948        \Device\Harddisk0\DR0\Partition0 - ok
17:54:42.0031 2948        ============================================================
17:54:42.0031 2948        Scan finished
17:54:42.0031 2948        ============================================================
17:54:42.0187 2940        Detected object count: 26
17:54:42.0187 2940        Actual detected object count: 26
17:54:57.0843 2940        atksgt ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        atksgt ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0843 2940        DfSdkS ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        DfSdkS ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0843 2940        DgiVecp ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        DgiVecp ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0843 2940        EGATHDRV ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        EGATHDRV ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0843 2940        IBM Rapid Restore Ultra Service ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        IBM Rapid Restore Ultra Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0843 2940        ibmfilter ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        ibmfilter ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0843 2940        IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0843 2940        lirsgt ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        lirsgt ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0843 2940        PMEM ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        PMEM ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0843 2940        prodrv06 ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        prodrv06 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0843 2940        prohlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        prohlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0843 2940        prosync1 ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        prosync1 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0843 2940        psadd ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0843 2940        psadd ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0859 2940        PxHelp20 ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0859 2940        PxHelp20 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0859 2940        sfhlp01 ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0859 2940        sfhlp01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0859 2940        StarOpen ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0859 2940        StarOpen ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0859 2940        tbhsd ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0859 2940        tbhsd ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0859 2940        toshidpt ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0859 2940        toshidpt ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0859 2940        tosporte ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0859 2940        tosporte ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0859 2940        Tosrfbd ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0859 2940        Tosrfbd ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0875 2940        Tosrfbnp ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0875 2940        Tosrfbnp ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0875 2940        Tosrfcom ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0875 2940        Tosrfcom ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0875 2940        Tosrfhid ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0875 2940        Tosrfhid ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0875 2940        tosrfnds ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0875 2940        tosrfnds ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0875 2940        TosRfSnd ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0875 2940        TosRfSnd ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:54:57.0875 2940        Tosrfusb ( UnsignedFile.Multi.Generic ) - skipped by user
17:54:57.0875 2940        Tosrfusb ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 12.04.2012 19:26

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

dirknik 13.04.2012 08:53

Ich hatte combofix über Nacht laufen lassen, doch glaube ich nicht, dass sich was getan hat. Heut morgen lief zwar der Rechner doch der Bildschirm war schwarz und ich konnte auch nichts tun. Die combofix.txt habe ich auch nicht gefunden. Soll ichs nochmal im abgesicherten Modus durchführen? Danke für alles :-)

cosinus 13.04.2012 11:39

Ja probier es nochmal im abgesicherten mit Netzwerk
Lad die combofix.exe bitte vorher neu runter

dirknik 14.04.2012 07:04

Habe combofix noch mehrmals deinstalliert und wieder neu runtergeladen und ausprobiert. Sowohl im abgesicherten Modus mit Netzwerk, als auch nur im abgesicherten Modus und im normalen Modus. Jedes mal hängt sich der Rechner auf und zwar immer nachdem combofix den Systemwiederherstellungspunkt erstellt hat und dann in etwa so was da steht: "Vorgang kann ca. 10 min dauern. Dieser kann sich jedoch bei stark infizierten Rechnern leicht verdoppeln." Was soll ich jetzt machen?

cosinus 15.04.2012 15:30

Dann überspringen wir CF erstmal

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

dirknik 15.04.2012 17:30

Hallo cosinus,
ich habe leider für längere Zeit keinen Zugriff mehr auf den zu behandelnden PC. Kann man hier den Thread vorübergehend schließen und dann wieder öffnen? Wenn das nicht geht, kann ich leider erst in einigen Monaten wieder antworten. Bis hierher vielen Dank. Ich werde auf jeden Fall deine Anweisungen, sobald es möglich ist durchführen. Danke nochmal :-)

cosinus 15.04.2012 18:35

Wir warten einfach ab was bis dahin passiert. Normalerweise können in diesen Strang nur du, die Helfer/Kompetenzler und Mods/Admins hier posten, ich seh daher keinen Anlass zur Schließung. Meld dich hier einfacher wieder wenn du an den PC rankommst


Alle Zeitangaben in WEZ +1. Es ist jetzt 08:05 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131