Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Gema-Trojaner? (https://www.trojaner-board.de/114833-gema-trojaner.html)

vtopy 06.05.2012 18:07

Gema-Trojaner?
 
Guten Abend zusammen!

Habe mir den hier ja bekannten Trojaner eingefangen, der den Bildschirm weiß färbt und Text anzeigt "Bitte warten Sie während die Verbindung hergestellt wird" (sowohl wenn ich Windows normal starte, als auch im abgesicherten Modus).
Wenn ich das richtig verstanden habe, sollte ich - damit ihr mir helfen könnt - eine otl.txt Datei erstellen & hier posten. Hoffe, ich habe das richtig gemacht und ihr wisst Rat. Danke!

cosinus 06.05.2012 19:35

Mach einen OTL-Fix über OTLPE, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:56889
[2011.06.04 10:21:18 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Ralf\AppData\Roaming\mozilla\Firefox\Profiles\3prngalu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.06.04 10:21:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ralf\AppData\Roaming\mozilla\Firefox\Profiles\3prngalu.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011.05.27 22:32:39 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Ralf\AppData\Roaming\mozilla\Firefox\Profiles\3prngalu.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}-trash
[2008.09.22 22:48:56 | 000,000,273 | -H-- | M] () -- C:\Users\Ralf\AppData\Roaming\Mozilla\Firefox\Profiles\3prngalu.default\searchplugins\search.xml
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [HP Health Check Scheduler]  File not found
O4 - HKLM..\Run: [StormCodec_Helper]  File not found
O4 - HKLM..\Run: [SunJavaUpdateSched]  File not found
O4 - HKU\S-1-5-21-3987592142-182742332-1528639515-1000..\Run: [c9798u3A8Yxm3bS] C:\Users\Ralf\AppData\Roaming\DNS_Servicex86.exe ()
O4 - HKU\S-1-5-21-3987592142-182742332-1528639515-1000..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O7 - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O7 - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O20 - HKU\S-1-5-21-3987592142-182742332-1528639515-1000 Winlogon: Shell - (C:\Users\Ralf\AppData\Roaming\DNS_Servicex86.exe) - C:\Users\Ralf\AppData\Roaming\DNS_Servicex86.exe ()
O20 - HKU\S-1-5-21-3987592142-182742332-1528639515-1000 Winlogon: UserInit - (C:\Users\Ralf\AppData\Roaming\DNS_Servicex86.exe) - C:\Users\Ralf\AppData\Roaming\DNS_Servicex86.exe ()
O31 - SafeBoot: UseAlternatShell - 1
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005.09.11 17:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O32 - AutoRun File - [2006.03.24 13:06:41 | 000,000,053 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{bfdb7b43-8e87-11e0-bee2-001e68006adf}\Shell - "" = AutoRun
O33 - MountPoints2\{bfdb7b43-8e87-11e0-bee2-001e68006adf}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{dd814b79-a557-11df-baf0-001e68006adf}\Shell - "" = AutoRun
O33 - MountPoints2\{dd814b79-a557-11df-baf0-001e68006adf}\Shell\AutoRun\command - "" = G:\start.exe
O33 - MountPoints2\{e67114cd-d0e0-11dc-92b6-001e68006adf}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Recycled\ctfmon.exe
O33 - MountPoints2\{e67114cd-d0e0-11dc-92b6-001e68006adf}\Shell\Open(&0)\command - "" = F:\Recycled\ctfmon.exe
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 72 bytes -> C:\Windows:7C4F1067358138F3
:Files
C:\Users\Ralf\AppData\Roaming\DNS_Servicex86.exe
C:\Users\Ralf\AppData\Roaming\DL
F:\Recycled\ctfmon.exe
C:\Users\Ralf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\msuu0.exe.lnk
C:\ProgramData\31776504
C:\Users\Ralf\AppData\Roaming\E144.07E
C:\Users\Ralf\AppData\Roaming\xmldm
:Commands
[purity]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Danach sollte Windows wieder normal starten - stell uns bitte den Quarantäneordner von OTL zur Verfügung. Dabei bitte so vorgehen:

1.) GANZ WICHTIG!! Virenscanner deaktivieren, der darf das Packen nicht beeinträchtigen!
2.) Ordner movedfiles in C:\_OTL in eine Datei zippen
3.) Die erstellte ZIP-Datei hier hochladen => http://www.trojaner-board.de/54791-a...ner-board.html
4.) Wenns erfolgreich war Bescheid sagen
5.) Erst dann wieder den Virenscanner einschalten

vtopy 07.05.2012 13:13

Vielen Dank für die Hilfe! Habe den Quarantäneordner wie beschrieben hochgeladen - sollte er jetzt hier im Thema angezeigt werden? Und bin ich den Trojaner jetzt los?

cosinus 07.05.2012 13:33

Das Log zum FIx solltest du auch posten!

vtopy 07.05.2012 13:50

Oh, ich dachte, das wäre mit in Movedfiles enthalten. Ist es nicht die Datei 05062012_220510.log?

cosinus 07.05.2012 13:57

Naja, wenn es darin ist, ich finds aber immer schöner wenn man gleich im Strang sieht wie der Fix verlief


Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

vtopy 07.05.2012 19:08

Habe jetzt die beiden Scans durchgeführt. Malwarebytes hat nichts gefunden, ESET dagegen schon. Hänge beide logs an. Und noch einmal vielen Dank für die Mühe, die du dir mit meinem Problem machst!

cosinus 07.05.2012 19:41

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

vtopy 07.05.2012 20:02

So weit ich das feststellen kann, läuft der normale Modus ohne Einschränkungen. Bin jedenfalls auf keine gestoßen. Im Startmenü vermisse ich auch nichts (auch wenn es tatsächlich 2 leere Ordner gibt, die Rückstände von deinstallierten Programmen sind - aber darauf zielt Deine Frage sicher nicht ab ...).

cosinus 07.05.2012 20:19

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


vtopy 07.05.2012 21:03

Okay, hier ist das OTL-Log:

Code:

OTL logfile created on: 07.05.2012 21:38:56 - Run 1
OTL by OldTimer - Version 3.2.42.3    Folder = C:\Users\Ralf\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,94 Gb Total Physical Memory | 1,06 Gb Available Physical Memory | 54,95% Memory free
2,88 Gb Paging File | 1,98 Gb Available in Paging File | 68,58% Paging File free
Paging file location(s): c:\pagefile.sys 1024 1024 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137,58 Gb Total Space | 56,90 Gb Free Space | 41,36% Space Free | Partition Type: NTFS
Drive D: | 11,47 Gb Total Space | 2,13 Gb Free Space | 18,57% Space Free | Partition Type: NTFS
Drive F: | 436,59 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
 
Computer Name: SCHREIBMASCHINE | User Name: Ralf | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.05.07 21:37:56 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Users\Ralf\Desktop\OTL.exe
PRC - [2011.12.15 16:00:00 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.12.15 15:59:48 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011.12.15 15:59:38 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.12.15 15:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2010.06.03 02:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.03.22 01:20:39 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.01.18 23:38:40 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007.12.19 08:04:22 | 001,649,600 | ---- | M] (SlySoft, Inc.) -- C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
PRC - [2007.09.15 10:29:10 | 000,102,400 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPStart.exe
PRC - [2005.03.08 13:46:00 | 000,651,264 | ---- | M] (AVM Berlin) -- C:\Program Files\FRITZ!DSL\StCenter.exe
PRC - [2005.03.04 12:50:00 | 000,118,784 | ---- | M] (AVM Berlin) -- C:\Program Files\FRITZ!DSL\IGDCTRL.EXE
PRC - [2005.01.31 09:45:20 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
 
 
========== Modules (No Company Name) ==========


cosinus 08.05.2012 09:41

Log ist unvollständig

vtopy 08.05.2012 10:40

Stimmt, das geht ja noch ewig weiter! Okay, hier das komplette Log:

OTL Logfile:
Code:

OTL logfile created on: 07.05.2012 21:38:56 - Run 1
OTL by OldTimer - Version 3.2.42.3    Folder = C:\Users\Ralf\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,94 Gb Total Physical Memory | 1,06 Gb Available Physical Memory | 54,95% Memory free
2,88 Gb Paging File | 1,98 Gb Available in Paging File | 68,58% Paging File free
Paging file location(s): c:\pagefile.sys 1024 1024 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137,58 Gb Total Space | 56,90 Gb Free Space | 41,36% Space Free | Partition Type: NTFS
Drive D: | 11,47 Gb Total Space | 2,13 Gb Free Space | 18,57% Space Free | Partition Type: NTFS
Drive F: | 436,59 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
 
Computer Name: SCHREIBMASCHINE | User Name: Ralf | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.05.07 21:37:56 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Users\Ralf\Desktop\OTL.exe
PRC - [2011.12.15 16:00:00 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.12.15 15:59:48 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011.12.15 15:59:38 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.12.15 15:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2010.06.03 02:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.03.22 01:20:39 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.01.18 23:38:40 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007.12.19 08:04:22 | 001,649,600 | ---- | M] (SlySoft, Inc.) -- C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
PRC - [2007.09.15 10:29:10 | 000,102,400 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPStart.exe
PRC - [2005.03.08 13:46:00 | 000,651,264 | ---- | M] (AVM Berlin) -- C:\Program Files\FRITZ!DSL\StCenter.exe
PRC - [2005.03.04 12:50:00 | 000,118,784 | ---- | M] (AVM Berlin) -- C:\Program Files\FRITZ!DSL\IGDCTRL.EXE
PRC - [2005.01.31 09:45:20 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2010.06.03 02:51:08 | 000,095,528 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2010.06.03 02:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.12.15 15:59:48 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.12.15 15:59:38 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2008.04.10 21:01:10 | 000,110,592 | ---- | M] (NinjaVideo) [Auto | Stopped] -- C:\Program Files\NinjaVideo\NinjaVideo Helper\NinjaVideo Helper.exe -- (NinjaVideo Helper.exe)
SRV - [2008.02.01 12:55:56 | 000,948,616 | ---- | M] (PC Tools) [Disabled | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2008.02.01 12:55:54 | 000,747,912 | ---- | M] (PC Tools) [Disabled | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2008.01.18 23:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.03.05 11:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)
SRV - [2005.03.04 12:50:00 | 000,118,784 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Program Files\FRITZ!DSL\IGDCTRL.EXE -- (AVM IGD CTRL Service)
SRV - [2005.03.04 11:42:08 | 000,315,392 | ---- | M] (AVM Berlin) [On_Demand | Stopped] -- C:\Program Files\Common Files\AVM\De_serv.exe -- (de_serv)
SRV - [2005.01.31 09:45:20 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (SymIMMP)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (SymIM)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys -- (Lavasoft Kernexplorer)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2012.02.15 17:33:04 | 000,137,416 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.12.15 16:00:00 | 000,074,640 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.12.15 16:00:00 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.05.13 13:36:38 | 000,048,640 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2008.07.17 17:01:00 | 000,269,760 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OA004Vid.sys -- (OA004Vid)
DRV - [2008.07.07 19:06:59 | 000,271,360 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2008.07.07 19:06:46 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2008.06.03 09:30:24 | 000,144,672 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OA004Ufd.sys -- (OA004Ufd)
DRV - [2008.02.01 12:55:52 | 000,042,376 | ---- | M] (PCTools Research Pty Ltd.) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\ikfilesec.sys -- (IKFileSec)
DRV - [2007.12.10 14:53:28 | 000,081,288 | ---- | M] (PCTools Research Pty Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\iksyssec.sys -- (IKSysSec)
DRV - [2007.12.10 14:53:28 | 000,066,952 | ---- | M] (PCTools Research Pty Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\iksysflt.sys -- (IKSysFlt)
DRV - [2007.12.06 23:30:05 | 000,097,216 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2007.10.09 05:21:00 | 007,626,304 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2007.09.09 09:12:28 | 000,176,640 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDART.sys -- (HdAudAddService)
DRV - [2007.07.10 01:27:56 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007.06.22 11:59:24 | 000,479,232 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emBDA.sys -- (USB28xxBGA)
DRV - [2007.06.18 18:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007.05.30 16:40:42 | 000,735,232 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2007.04.25 14:42:15 | 000,045,696 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emOEM.sys -- (USB28xxOEM)
DRV - [2007.03.06 15:15:58 | 001,059,112 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2007.02.16 10:50:32 | 000,012,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2007.02.16 02:56:49 | 000,011,984 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ElbyDelay.sys -- (ElbyDelay)
DRV - [2006.06.28 11:54:00 | 000,009,472 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CPQBttn.sys -- (HBtnKey)
DRV - [2003.11.28 18:34:40 | 000,011,264 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\asapiW2k.sys -- (ASAPIW2K)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=HP&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=HP&pf=laptop
IE - HKLM\..\SearchScopes,DefaultScope = {18E12AD8-C569-42FB-B8CC-1B37D8789C15}
IE - HKLM\..\SearchScopes\{18E12AD8-C569-42FB-B8CC-1B37D8789C15}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKLM\..\SearchScopes\{94C202E1-A521-49A2-B0F0-F07F5EBBED99}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\..\SearchScopes\{18E12AD8-C569-42FB-B8CC-1B37D8789C15}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\..\SearchScopes\{94C202E1-A521-49A2-B0F0-F07F5EBBED99}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "search"
FF - prefs.js..browser.startup.homepage: "www.google.de"
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.8
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0:  File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2008.02.10 14:40:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.03.22 01:22:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.14 16:56:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.28 21:02:23 | 000,000,000 | ---D | M]
 
[2009.01.08 23:28:01 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Ralf\AppData\Roaming\mozilla\Extensions
[2012.05.07 20:07:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ralf\AppData\Roaming\mozilla\Firefox\Profiles\3prngalu.default\extensions
[2012.04.03 10:35:18 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Ralf\AppData\Roaming\mozilla\Firefox\Profiles\3prngalu.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.06 16:20:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.11.28 20:56:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2009.01.08 23:27:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\google-cjk@partners.mozilla.com
[2009.01.08 23:27:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org
[2010.03.22 01:22:15 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2009.09.03 16:58:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011.11.28 20:55:51 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010.03.24 22:18:23 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.03.24 22:18:23 | 000,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2010.03.24 22:18:23 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.03.24 22:18:24 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.03.24 22:18:24 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.05.06 22:05:16 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1      localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3987592142-182742332-1528639515-1000..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe (SlySoft, Inc.)
O8 - Extra context menu item: Free YouTube Download - C:\Users\Ralf\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\..Trusted Ranges: Range1 ([http] in Lokales Intranet)
O15 - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\..Trusted Ranges: Range30 ([*] in Lokales Intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A105F18-5AEF-4424-ACBA-293396E011AF}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3D5846D2-3B79-4D34-8C50-3F9E1642C26A}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-3987592142-182742332-1528639515-1000 Winlogon: UserInit - (c:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Ralf\Bilder\72LIGHTCIGARETTE7.jpg
O24 - Desktop BackupWallPaper: C:\Ralf\Bilder\72LIGHTCIGARETTE7.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.03.24 13:06:41 | 000,000,053 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{37ac0e8f-d209-11e0-a5cd-001e68006adf}\Shell - "" = AutoRun
O33 - MountPoints2\{37ac0e8f-d209-11e0-a5cd-001e68006adf}\Shell\AutoRun\command - "" = F:\reatogoMenu.exe -- [2005.07.16 23:36:50 | 000,240,128 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - State: "services" - 2
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sdauxservice - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SafeBootMin: sdcoreservice - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger -  File not found
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sdauxservice - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SafeBootNet: sdcoreservice - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 10.1
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 10.1
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
 
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\VIO\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.iac2 - C:\Windows\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.MPEGacm - C:\Program Files\Common Files\Ulead Systems\MPEG\MPEGACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.ulmp3acm - C:\Program Files\Common Files\Ulead Systems\MPEG\ulmp3acm.acm (Ulead systems)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS hxxp://hp.vector.co.jp/authors/VA012897/)
Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.FLV4 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP62 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP6F - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp70 - C:\Windows\System32\vp7vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.05.07 21:37:55 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Users\Ralf\Desktop\OTL.exe
[2012.05.07 15:02:45 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.05.07 15:02:06 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Ralf\Desktop\esetsmartinstaller_enu.exe
[2012.05.06 22:05:10 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.04.21 16:17:46 | 000,000,000 | ---D | C] -- C:\Users\Ralf\.Zettelkasten
[2012.04.21 16:17:35 | 004,112,119 | ---- | C] (Daniel Luedecke) -- C:\Users\Ralf\Desktop\Zettelkasten.exe
[2012.04.19 13:54:54 | 000,000,000 | ---D | C] -- C:\Users\Ralf\AppData\Roaming\Malwarebytes
[2012.04.19 13:54:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.04.19 13:54:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.04.19 13:53:59 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.04.19 13:53:59 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.05.07 21:37:56 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Users\Ralf\Desktop\OTL.exe
[2012.05.07 19:52:33 | 000,000,125 | -HS- | M] () -- C:\ProgramData\.zreglib
[2012.05.07 19:52:17 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.05.07 19:52:17 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.05.07 19:52:10 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.05.07 15:02:07 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Ralf\Desktop\esetsmartinstaller_enu.exe
[2012.05.07 15:01:24 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.05.07 15:01:24 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.05.07 15:01:24 | 000,126,260 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.05.07 15:01:24 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.05.06 22:05:16 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2012.05.06 16:22:50 | 000,025,866 | ---- | M] () -- C:\Users\Ralf\Desktop\config.xml
[2012.04.30 23:59:52 | 000,799,232 | ---- | M] () -- C:\Users\Ralf\Desktop\Avira-RansomFileUnlocker.exe
[2012.04.20 14:25:24 | 004,112,119 | ---- | M] (Daniel Luedecke) -- C:\Users\Ralf\Desktop\Zettelkasten.exe
[2012.04.19 13:54:03 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.05.06 16:22:49 | 000,025,866 | ---- | C] () -- C:\Users\Ralf\Desktop\config.xml
[2012.05.06 16:22:26 | 000,799,232 | ---- | C] () -- C:\Users\Ralf\Desktop\Avira-RansomFileUnlocker.exe
[2012.04.19 13:54:03 | 000,000,866 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011.10.13 16:38:08 | 000,000,206 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2011.09.13 10:15:33 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011.06.21 20:49:45 | 000,001,466 | ---- | C] () -- C:\Users\Ralf\AppData\Local\RecConfig.xml
[2010.12.11 13:51:12 | 000,033,019 | ---- | C] () -- C:\Windows\System32\CoreAAC-uninstall.exe
[2010.07.26 23:05:49 | 000,000,081 | ---- | C] () -- C:\Windows\MrSetup.ini
[2010.06.13 20:09:19 | 000,017,408 | -H-- | C] () -- C:\Users\Ralf\AppData\Local\WebpageIcons.db
 
========== LOP Check ==========
 
[2011.12.22 13:40:53 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\Audacity
[2012.04.03 10:35:36 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\DVDVideoSoft
[2012.04.03 10:35:14 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.05.12 19:36:07 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\elsterformular
[2009.05.14 19:46:13 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\eMule
[2009.02.01 18:40:15 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\FRITZ!
[2011.06.22 22:11:41 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\HMC
[2011.08.25 15:33:37 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\kock
[2010.05.05 21:22:04 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\Lingo4u
[2010.10.05 20:56:59 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\LogoManager
[2011.02.18 11:13:38 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\MAXQDA2007
[2011.09.13 10:15:39 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\pdfforge
[2009.09.20 15:10:55 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\Template
[2012.05.06 14:17:58 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\uTorrent
[2010.05.01 16:10:57 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\X-TENSIONS Multimedia
[2012.05.07 00:02:49 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2009.07.22 00:49:20 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\Adobe
[2008.06.25 17:27:29 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\Ahead
[2011.12.22 13:40:53 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\Audacity
[2012.02.10 11:35:43 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\Avira
[2009.04.05 19:06:29 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\CyberLink
[2010.04.27 17:15:35 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\DivX
[2011.06.04 10:21:18 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\DVD Flick
[2012.03.26 13:56:45 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\dvdcss
[2012.04.03 10:35:36 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\DVDVideoSoft
[2012.04.03 10:35:14 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.05.12 19:36:07 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\elsterformular
[2009.05.14 19:46:13 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\eMule
[2009.02.01 18:40:15 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\FRITZ!
[2012.04.19 16:48:04 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\Help
[2008.01.31 20:31:15 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\Hewlett-Packard
[2011.06.22 22:11:41 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\HMC
[2008.02.05 23:31:22 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\HP
[2008.01.31 20:29:45 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\Identities
[2011.08.25 15:33:37 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\kock
[2010.05.05 21:22:04 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\Lingo4u
[2010.10.05 20:56:59 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\LogoManager
[2008.01.31 20:27:25 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\Macromedia
[2012.04.19 13:54:54 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\Malwarebytes
[2011.02.18 11:13:38 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\MAXQDA2007
[2006.11.02 14:37:34 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\Media Center Programs
[2008.03.01 05:53:51 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\Media Player Classic
[2011.06.21 20:33:19 | 000,000,000 | --SD | M] -- C:\Users\Ralf\AppData\Roaming\Microsoft
[2008.02.19 22:07:54 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\Microsoft Web Folders
[2009.01.08 23:28:01 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\Mozilla
[2008.07.02 17:17:28 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\Nero
[2008.03.31 20:11:41 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\PC Tools
[2011.09.13 10:15:39 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\pdfforge
[2010.03.22 01:23:14 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\Real
[2012.04.10 19:14:08 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\Skype
[2012.04.10 16:01:31 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\skypePM
[2008.01.31 20:30:42 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\Symantec
[2008.02.10 14:51:23 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\Talkback
[2009.09.20 15:10:55 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\Template
[2012.05.06 14:17:58 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\uTorrent
[2012.05.03 12:36:49 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\vlc
[2011.07.13 15:37:51 | 000,000,000 | -H-D | M] -- C:\Users\Ralf\AppData\Roaming\WinRAR
[2010.05.01 16:10:57 | 000,000,000 | ---D | M] -- C:\Users\Ralf\AppData\Roaming\X-TENSIONS Multimedia
 
< %APPDATA%\*.exe /s >
[2011.06.21 20:33:20 | 000,003,262 | R--- | M] () -- C:\Users\Ralf\AppData\Roaming\Microsoft\Installer\{22B0E143-2B0B-435B-9F56-136A3D16065F}\controlPanelIcon.exe
[2011.06.21 20:33:20 | 000,010,134 | R--- | M] () -- C:\Users\Ralf\AppData\Roaming\Microsoft\Installer\{22B0E143-2B0B-435B-9F56-136A3D16065F}\SystemFolder_msiexec.exe
[2010.02.18 00:18:02 | 000,738,824 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Ralf\AppData\Roaming\Real\RealPlayer\setup\AU_setup20100217.exe
[2010.02.13 21:56:03 | 000,439,816 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Ralf\AppData\Roaming\Real\Update\setup3.09\setup.exe
[2010.03.09 00:27:39 | 000,443,912 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Ralf\AppData\Roaming\Real\Update\setup3.10\setup.exe
[2010.03.16 21:47:59 | 000,079,368 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Ralf\AppData\Roaming\Real\Update\setup3.10\RUP\vista.exe
[2011.01.10 22:01:23 | 000,510,120 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Ralf\AppData\Roaming\Real\Update\setup3.13\setup.exe
 
< %SYSTEMDRIVE%\*.exe >
[2011.07.13 04:55:05 | 002,237,440 | R--- | M] (OldTimer Tools) -- C:\OTLPE.exe
 
< MD5 for: AGP440.SYS  >
[2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2007.11.06 19:25:54 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=313FF294978EA6AF715722D708FB249F -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20494_none_b858f78adaed51b3\AGP440.sys
[2007.11.06 19:25:54 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f2490cb0\AGP440.sys
[2007.11.06 19:25:54 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16399_none_b7d45c31c1cb309c\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.03.01 04:13:34 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.03.01 04:13:34 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.03.01 04:13:33 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2007.01.12 23:30:08 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.18 23:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.18 23:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.18 23:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.18 23:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.18 23:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.18 23:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2007.11.06 17:58:16 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=63B4F59D7C89B1BF5277F1FFEFD491CD -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_cb39bc5b7047127e\user32.dll
[2007.11.06 17:58:17 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=9D9F061EDA75425FC67F0365E3467C86 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_cbc258dc896598f1\user32.dll
[2008.01.18 23:36:48 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2006.11.02 11:46:13 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=E698A5437B89A285ACA3FF022356810A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_cb01aa4570716e5e\user32.dll
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.18 23:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.18 23:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2006.11.02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.18 23:33:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2006.11.02 10:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys
[2008.01.18 21:56:50 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.18 21:56:50 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006.11.02 12:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---

[/CODE]

cosinus 08.05.2012 12:00

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=HP&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=HP&pf=laptop
IE - HKLM\..\SearchScopes,DefaultScope = {18E12AD8-C569-42FB-B8CC-1B37D8789C15}
IE - HKLM\..\SearchScopes\{18E12AD8-C569-42FB-B8CC-1B37D8789C15}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKLM\..\SearchScopes\{94C202E1-A521-49A2-B0F0-F07F5EBBED99}: "URL" = http://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\..\SearchScopes\{18E12AD8-C569-42FB-B8CC-1B37D8789C15}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-3987592142-182742332-1528639515-1000\..\SearchScopes\{94C202E1-A521-49A2-B0F0-F07F5EBBED99}: "URL" = http://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
FF - user.js - File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{37ac0e8f-d209-11e0-a5cd-001e68006adf}\Shell - "" = AutoRun
O33 - MountPoints2\{37ac0e8f-d209-11e0-a5cd-001e68006adf}\Shell\AutoRun\command - "" = F:\reatogoMenu.exe -- [2005.07.16 23:36:50 | 000,240,128 | R--- | M] ()
:Files
C:\Users\Ralf\AppData\Roaming\kock
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

vtopy 08.05.2012 12:33

Habe den Fix gemacht, danach gab es einen Neustart. Zunächst wurde mir angezeigt: "Operating System not found", als ich Enter drückte, wurde dann aber doch Vista ganz normal gestartet. Hier das Log:

Code:

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{18E12AD8-C569-42FB-B8CC-1B37D8789C15}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{18E12AD8-C569-42FB-B8CC-1B37D8789C15}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{94C202E1-A521-49A2-B0F0-F07F5EBBED99}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94C202E1-A521-49A2-B0F0-F07F5EBBED99}\ not found.
HKEY_USERS\S-1-5-21-3987592142-182742332-1528639515-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3987592142-182742332-1528639515-1000\Software\Microsoft\Internet Explorer\SearchScopes\{18E12AD8-C569-42FB-B8CC-1B37D8789C15}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{18E12AD8-C569-42FB-B8CC-1B37D8789C15}\ not found.
Registry key HKEY_USERS\S-1-5-21-3987592142-182742332-1528639515-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_USERS\S-1-5-21-3987592142-182742332-1528639515-1000\Software\Microsoft\Internet Explorer\SearchScopes\{94C202E1-A521-49A2-B0F0-F07F5EBBED99}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94C202E1-A521-49A2-B0F0-F07F5EBBED99}\ not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{37ac0e8f-d209-11e0-a5cd-001e68006adf}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37ac0e8f-d209-11e0-a5cd-001e68006adf}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{37ac0e8f-d209-11e0-a5cd-001e68006adf}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37ac0e8f-d209-11e0-a5cd-001e68006adf}\ not found.
File F:\reatogoMenu.exe not found.
========== FILES ==========
C:\Users\Ralf\AppData\Roaming\kock folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: Ralf
->Temp folder emptied: 69443088 bytes
->Temporary Internet Files folder emptied: 55540946 bytes
->Java cache emptied: 200234 bytes
->FireFox cache emptied: 67391082 bytes
->Flash cache emptied: 200139 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 53156348 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 235,00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
 
User: Default User
 
User: Public
 
User: Ralf
->Flash cache emptied: 0 bytes
 
Total Flash Files Cleaned = 0,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.42.3 log created on 05082012_130444

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...


cosinus 08.05.2012 15:35

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten, Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

vtopy 08.05.2012 21:48

Okay, hier das Ergebnis des Killers:

Code:

22:44:12.0471 2008        TDSS rootkit removing tool 2.7.34.0 May  2 2012 09:59:18
22:44:12.0920 2008        ============================================================
22:44:12.0920 2008        Current date / time: 2012/05/08 22:44:12.0920
22:44:12.0920 2008        SystemInfo:
22:44:12.0921 2008       
22:44:12.0921 2008        OS Version: 6.0.6002 ServicePack: 2.0
22:44:12.0921 2008        Product type: Workstation
22:44:12.0921 2008        ComputerName: SCHREIBMASCHINE
22:44:12.0921 2008        UserName: Ralf
22:44:12.0921 2008        Windows directory: C:\Windows
22:44:12.0921 2008        System windows directory: C:\Windows
22:44:12.0921 2008        Processor architecture: Intel x86
22:44:12.0921 2008        Number of processors: 2
22:44:12.0921 2008        Page size: 0x1000
22:44:12.0921 2008        Boot type: Normal boot
22:44:12.0921 2008        ============================================================
22:44:14.0517 2008        Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:44:14.0519 2008        ============================================================
22:44:14.0520 2008        \Device\Harddisk0\DR0:
22:44:14.0520 2008        MBR partitions:
22:44:14.0520 2008        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x113293E9
22:44:14.0520 2008        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x11329428, BlocksNum 0x16EF699
22:44:14.0520 2008        ============================================================
22:44:14.0529 2008        C: <-> \Device\Harddisk0\DR0\Partition0
22:44:14.0576 2008        D: <-> \Device\Harddisk0\DR0\Partition1
22:44:14.0576 2008        ============================================================
22:44:14.0576 2008        Initialize success
22:44:14.0576 2008        ============================================================
22:44:47.0450 1796        ============================================================
22:44:47.0451 1796        Scan started
22:44:47.0451 1796        Mode: Manual; SigCheck; TDLFS;
22:44:47.0451 1796        ============================================================
22:44:48.0088 1796        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
22:44:48.0227 1796        ACPI - ok
22:44:48.0358 1796        AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
22:44:48.0374 1796        AdobeARMservice - ok
22:44:48.0422 1796        adp94xx        (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
22:44:48.0465 1796        adp94xx - ok
22:44:48.0498 1796        adpahci        (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
22:44:48.0527 1796        adpahci - ok
22:44:48.0549 1796        adpu160m        (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
22:44:48.0567 1796        adpu160m - ok
22:44:48.0595 1796        adpu320        (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
22:44:48.0612 1796        adpu320 - ok
22:44:48.0646 1796        AeLookupSvc    (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll
22:44:48.0766 1796        AeLookupSvc - ok
22:44:48.0822 1796        AFD            (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
22:44:48.0881 1796        AFD - ok
22:44:48.0922 1796        agp440          (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys
22:44:48.0938 1796        agp440 - ok
22:44:48.0962 1796        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
22:44:48.0978 1796        aic78xx - ok
22:44:49.0000 1796        ALG            (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe
22:44:49.0394 1796        ALG - ok
22:44:49.0415 1796        aliide          (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
22:44:49.0446 1796        aliide - ok
22:44:49.0478 1796        amdagp          (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
22:44:49.0502 1796        amdagp - ok
22:44:49.0512 1796        amdide          (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
22:44:49.0528 1796        amdide - ok
22:44:49.0544 1796        AmdK7          (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
22:44:49.0767 1796        AmdK7 - ok
22:44:49.0806 1796        AmdK8          (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
22:44:49.0862 1796        AmdK8 - ok
22:44:49.0955 1796        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files\Avira\AntiVir Desktop\sched.exe
22:44:49.0981 1796        AntiVirSchedulerService - ok
22:44:50.0042 1796        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
22:44:50.0057 1796        AntiVirService - ok
22:44:50.0100 1796        AnyDVD          (cdc4bec57bce9fa87433a3655a31176f) C:\Windows\system32\Drivers\AnyDVD.sys
22:44:50.0166 1796        AnyDVD - ok
22:44:50.0232 1796        Appinfo        (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll
22:44:50.0260 1796        Appinfo - ok
22:44:50.0291 1796        arc            (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
22:44:50.0308 1796        arc - ok
22:44:50.0342 1796        arcsas          (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
22:44:50.0360 1796        arcsas - ok
22:44:50.0397 1796        ASAPIW2K        (4f9cbbf95e8f7a0d4c0edcfe3b78102e) C:\Windows\system32\Drivers\ASAPIW2K.sys
22:44:50.0425 1796        ASAPIW2K ( UnsignedFile.Multi.Generic ) - warning
22:44:50.0425 1796        ASAPIW2K - detected UnsignedFile.Multi.Generic (1)
22:44:50.0469 1796        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
22:44:50.0516 1796        AsyncMac - ok
22:44:50.0542 1796        atapi          (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
22:44:50.0559 1796        atapi - ok
22:44:50.0632 1796        athr            (0437199c88f6e88a387cfec8a8886a6e) C:\Windows\system32\DRIVERS\athr.sys
22:44:50.0732 1796        athr - ok
22:44:50.0792 1796        atksgt          (6e996cf8459a2594e0e9609d0e34d41f) C:\Windows\system32\DRIVERS\atksgt.sys
22:44:50.0834 1796        atksgt ( UnsignedFile.Multi.Generic ) - warning
22:44:50.0834 1796        atksgt - detected UnsignedFile.Multi.Generic (1)
22:44:50.0907 1796        AudioEndpointBuilder (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
22:44:50.0955 1796        AudioEndpointBuilder - ok
22:44:50.0963 1796        Audiosrv        (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
22:44:50.0994 1796        Audiosrv - ok
22:44:51.0043 1796        avgntflt        (d5541f0afb767e85fc412fc609d96a74) C:\Windows\system32\DRIVERS\avgntflt.sys
22:44:51.0067 1796        avgntflt - ok
22:44:51.0085 1796        avipbb          (7d967a682d4694df7fa57d63a2db01fe) C:\Windows\system32\DRIVERS\avipbb.sys
22:44:51.0103 1796        avipbb - ok
22:44:51.0122 1796        avkmgr          (271cfd1a989209b1964e24d969552bf7) C:\Windows\system32\DRIVERS\avkmgr.sys
22:44:51.0137 1796        avkmgr - ok
22:44:51.0254 1796        AVM IGD CTRL Service (6345d23c4e69e35f3d70169153b5d048) C:\Program Files\FRITZ!DSL\IGDCTRL.EXE
22:44:51.0280 1796        AVM IGD CTRL Service ( UnsignedFile.Multi.Generic ) - warning
22:44:51.0281 1796        AVM IGD CTRL Service - detected UnsignedFile.Multi.Generic (1)
22:44:51.0358 1796        BCM43XV        (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys
22:44:51.0472 1796        BCM43XV - ok
22:44:51.0515 1796        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
22:44:51.0575 1796        Beep - ok
22:44:51.0652 1796        BFE            (c789af0f724fda5852fb9a7d3a432381) C:\Windows\System32\bfe.dll
22:44:51.0714 1796        BFE - ok
22:44:51.0809 1796        BITS            (93952506c6d67330367f7e7934b6a02f) C:\Windows\System32\qmgr.dll
22:44:51.0927 1796        BITS - ok
22:44:51.0941 1796        blbdrive - ok
22:44:52.0066 1796        bowser          (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
22:44:52.0109 1796        bowser - ok
22:44:52.0138 1796        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
22:44:52.0173 1796        BrFiltLo - ok
22:44:52.0189 1796        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
22:44:52.0228 1796        BrFiltUp - ok
22:44:52.0253 1796        Browser        (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll
22:44:52.0303 1796        Browser - ok
22:44:52.0333 1796        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
22:44:52.0408 1796        Brserid - ok
22:44:52.0459 1796        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
22:44:52.0524 1796        BrSerWdm - ok
22:44:52.0568 1796        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
22:44:52.0637 1796        BrUsbMdm - ok
22:44:52.0646 1796        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
22:44:52.0706 1796        BrUsbSer - ok
22:44:52.0729 1796        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
22:44:52.0782 1796        BTHMODEM - ok
22:44:52.0817 1796        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
22:44:52.0869 1796        cdfs - ok
22:44:52.0916 1796        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
22:44:52.0956 1796        cdrom - ok
22:44:53.0006 1796        CertPropSvc    (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
22:44:53.0046 1796        CertPropSvc - ok
22:44:53.0068 1796        circlass        (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
22:44:53.0123 1796        circlass - ok
22:44:53.0158 1796        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
22:44:53.0189 1796        CLFS - ok
22:44:53.0244 1796        clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:44:53.0260 1796        clr_optimization_v2.0.50727_32 - ok
22:44:53.0340 1796        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:44:53.0357 1796        clr_optimization_v4.0.30319_32 - ok
22:44:53.0396 1796        CmBatt          (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
22:44:53.0443 1796        CmBatt - ok
22:44:53.0463 1796        cmdide          (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
22:44:53.0478 1796        cmdide - ok
22:44:53.0592 1796        Com4Qlb        (d8774ace03b46c9b01a49818055f9ad4) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
22:44:53.0624 1796        Com4Qlb ( UnsignedFile.Multi.Generic ) - warning
22:44:53.0625 1796        Com4Qlb - detected UnsignedFile.Multi.Generic (1)
22:44:53.0665 1796        Compbatt        (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
22:44:53.0697 1796        Compbatt - ok
22:44:53.0702 1796        COMSysApp - ok
22:44:53.0712 1796        crcdisk        (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
22:44:53.0728 1796        crcdisk - ok
22:44:53.0746 1796        Crusoe          (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
22:44:53.0828 1796        Crusoe - ok
22:44:53.0864 1796        CryptSvc        (fb27772beaf8e1d28ccd825c09da939b) C:\Windows\system32\cryptsvc.dll
22:44:53.0905 1796        CryptSvc - ok
22:44:53.0977 1796        DcomLaunch      (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
22:44:54.0066 1796        DcomLaunch - ok
22:44:54.0135 1796        de_serv        (3946a70bd9d2c758bbea429c7d0f7ca0) C:\Program Files\Common Files\AVM\de_serv.exe
22:44:54.0189 1796        de_serv ( UnsignedFile.Multi.Generic ) - warning
22:44:54.0189 1796        de_serv - detected UnsignedFile.Multi.Generic (1)
22:44:54.0223 1796        DfsC            (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
22:44:54.0257 1796        DfsC - ok
22:44:54.0476 1796        DFSR            (2cc3dcfb533a1035b13dcab6160ab38b) C:\Windows\system32\DFSR.exe
22:44:54.0679 1796        DFSR - ok
22:44:54.0845 1796        Dhcp            (9028559c132146fb75eb7acf384b086a) C:\Windows\System32\dhcpcsvc.dll
22:44:54.0906 1796        Dhcp - ok
22:44:54.0967 1796        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
22:44:54.0984 1796        disk - ok
22:44:55.0014 1796        Dnscache        (57d762f6f5974af0da2be88a3349baaa) C:\Windows\System32\dnsrslvr.dll
22:44:55.0067 1796        Dnscache - ok
22:44:55.0101 1796        dot3svc        (324fd74686b1ef5e7c19a8af49e748f6) C:\Windows\System32\dot3svc.dll
22:44:55.0150 1796        dot3svc - ok
22:44:55.0207 1796        DPS            (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll
22:44:55.0262 1796        DPS - ok
22:44:55.0287 1796        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
22:44:55.0313 1796        drmkaud - ok
22:44:55.0377 1796        DXGKrnl        (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
22:44:55.0416 1796        DXGKrnl - ok
22:44:55.0477 1796        E100B          (c0b00e55cf82d122d25983c7a6a53dea) C:\Windows\system32\DRIVERS\e100b325.sys
22:44:55.0559 1796        E100B - ok
22:44:55.0581 1796        E1G60          (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
22:44:55.0658 1796        E1G60 - ok
22:44:55.0696 1796        EapHost        (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll
22:44:55.0741 1796        EapHost - ok
22:44:55.0811 1796        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
22:44:55.0833 1796        Ecache - ok
22:44:55.0879 1796        ehRecvr        (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe
22:44:55.0920 1796        ehRecvr - ok
22:44:55.0954 1796        ehSched        (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe
22:44:55.0971 1796        ehSched - ok
22:44:55.0986 1796        ehstart        (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll
22:44:56.0010 1796        ehstart - ok
22:44:56.0065 1796        ElbyCDIO        (28cb0b64134ad62c2acf77db8501a619) C:\Windows\system32\Drivers\ElbyCDIO.sys
22:44:56.0080 1796        ElbyCDIO - ok
22:44:56.0129 1796        ElbyDelay      (e205c313417da6fa7afe85912a310a65) C:\Windows\system32\Drivers\ElbyDelay.sys
22:44:56.0143 1796        ElbyDelay - ok
22:44:56.0219 1796        elxstor        (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
22:44:56.0277 1796        elxstor - ok
22:44:56.0359 1796        EMDMgmt        (4e6b23dfc917ea39306b529b773950f4) C:\Windows\system32\emdmgmt.dll
22:44:56.0481 1796        EMDMgmt - ok
22:44:56.0582 1796        EventSystem    (67058c46504bc12d821f38cf99b7b28f) C:\Windows\system32\es.dll
22:44:56.0614 1796        EventSystem - ok
22:44:56.0675 1796        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
22:44:56.0729 1796        exfat - ok
22:44:56.0775 1796        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
22:44:56.0821 1796        fastfat - ok
22:44:56.0842 1796        fdc            (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
22:44:56.0913 1796        fdc - ok
22:44:56.0949 1796        fdPHost        (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll
22:44:56.0999 1796        fdPHost - ok
22:44:57.0021 1796        FDResPub        (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll
22:44:57.0100 1796        FDResPub - ok
22:44:57.0122 1796        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
22:44:57.0139 1796        FileInfo - ok
22:44:57.0156 1796        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
22:44:57.0204 1796        Filetrace - ok
22:44:57.0219 1796        flpydisk        (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
22:44:57.0293 1796        flpydisk - ok
22:44:57.0332 1796        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
22:44:57.0354 1796        FltMgr - ok
22:44:57.0472 1796        FontCache      (8ce364388c8eca59b14b539179276d44) C:\Windows\system32\FntCache.dll
22:44:57.0563 1796        FontCache - ok
22:44:57.0636 1796        FontCache3.0.0.0 (c7fbdd1ed42f82bfa35167a5c9803ea3) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
22:44:57.0653 1796        FontCache3.0.0.0 - ok
22:44:57.0685 1796        Fs_Rec          (b972a66758577e0bfd1de0f91aaa27b5) C:\Windows\system32\drivers\Fs_Rec.sys
22:44:57.0720 1796        Fs_Rec - ok
22:44:57.0746 1796        gagp30kx        (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
22:44:57.0763 1796        gagp30kx - ok
22:44:57.0820 1796        gpsvc          (cd5d0aeee35dfd4e986a5aa1500a6e66) C:\Windows\System32\gpsvc.dll
22:44:57.0900 1796        gpsvc - ok
22:44:57.0941 1796        HBtnKey        (de15777902a5d9121857d155873a1d1b) C:\Windows\system32\DRIVERS\cpqbttn.sys
22:44:57.0982 1796        HBtnKey - ok
22:44:58.0032 1796        HdAudAddService (7be40bb4cd16d8760e18ea981ff452ec) C:\Windows\system32\drivers\CHDART.sys
22:44:58.0066 1796        HdAudAddService - ok
22:44:58.0129 1796        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:44:58.0205 1796        HDAudBus - ok
22:44:58.0234 1796        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
22:44:58.0331 1796        HidBth - ok
22:44:58.0350 1796        HidIr          (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
22:44:58.0429 1796        HidIr - ok
22:44:58.0458 1796        hidserv        (84067081f3318162797385e11a8f0582) C:\Windows\system32\hidserv.dll
22:44:58.0476 1796        hidserv - ok
22:44:58.0501 1796        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
22:44:58.0538 1796        HidUsb - ok
22:44:58.0568 1796        hkmsvc          (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll
22:44:58.0603 1796        hkmsvc - ok
22:44:58.0712 1796        HP Health Check Service (0d26c438e2938a3e6bdd91173bc96ff0) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
22:44:58.0728 1796        HP Health Check Service ( UnsignedFile.Multi.Generic ) - warning
22:44:58.0728 1796        HP Health Check Service - detected UnsignedFile.Multi.Generic (1)
22:44:58.0745 1796        HpCISSs        (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
22:44:58.0758 1796        HpCISSs - ok
22:44:58.0788 1796        HpqKbFiltr      (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
22:44:58.0819 1796        HpqKbFiltr - ok
22:44:58.0857 1796        hpqwmiex        (04c1dcbb226c6ae647b794833ce3ceb6) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
22:44:58.0875 1796        hpqwmiex ( UnsignedFile.Multi.Generic ) - warning
22:44:58.0876 1796        hpqwmiex - detected UnsignedFile.Multi.Generic (1)
22:44:58.0913 1796        HSFHWAZL        (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
22:44:58.0959 1796        HSFHWAZL - ok
22:44:59.0028 1796        HSF_DPV        (1882827f41dee51c70e24c567c35bfb5) C:\Windows\system32\DRIVERS\HSX_DPV.sys
22:44:59.0140 1796        HSF_DPV - ok
22:44:59.0181 1796        HSXHWAZL        (a44ddf3ba83e4664bf4de9220097578c) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
22:44:59.0228 1796        HSXHWAZL - ok
22:44:59.0304 1796        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
22:44:59.0553 1796        HTTP - ok
22:44:59.0626 1796        i2omp          (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
22:44:59.0642 1796        i2omp - ok
22:44:59.0696 1796        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
22:44:59.0723 1796        i8042prt - ok
22:44:59.0832 1796        ialm            (496db78e6a0c4c44023d9a92b4a7ac31) C:\Windows\system32\DRIVERS\igdkmd32.sys
22:45:00.0001 1796        ialm - ok
22:45:00.0109 1796        iaStorV        (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
22:45:00.0142 1796        iaStorV - ok
22:45:00.0240 1796        IDriverT        (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
22:45:00.0265 1796        IDriverT ( UnsignedFile.Multi.Generic ) - warning
22:45:00.0265 1796        IDriverT - detected UnsignedFile.Multi.Generic (1)
22:45:00.0364 1796        idsvc          (98477b08e61945f974ed9fdc4cb6bdab) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
22:45:00.0421 1796        idsvc - ok
22:45:00.0459 1796        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
22:45:00.0474 1796        iirsp - ok
22:45:00.0526 1796        IKEEXT          (9908d8a397b76cd8d31d0d383c5773c9) C:\Windows\System32\ikeext.dll
22:45:00.0580 1796        IKEEXT - ok
22:45:00.0623 1796        IKFileSec      (3d8a88bd1e6a640807691198a8342e8c) C:\Windows\system32\drivers\ikfilesec.sys
22:45:00.0636 1796        IKFileSec - ok
22:45:00.0651 1796        IKSysFlt        (7583e2211097d273fca4e3fce04f639f) C:\Windows\system32\drivers\iksysflt.sys
22:45:00.0666 1796        IKSysFlt - ok
22:45:00.0688 1796        IKSysSec        (2402f65f1eca5159c8f0f16066f4bded) C:\Windows\system32\drivers\iksyssec.sys
22:45:00.0700 1796        IKSysSec - ok
22:45:00.0730 1796        intelide        (97469037714070e45194ed318d636401) C:\Windows\system32\drivers\intelide.sys
22:45:00.0744 1796        intelide - ok
22:45:00.0771 1796        intelppm        (ce44cc04262f28216dd4341e9e36a16f) C:\Windows\system32\DRIVERS\intelppm.sys
22:45:00.0825 1796        intelppm - ok
22:45:00.0862 1796        IPBusEnum      (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll
22:45:00.0908 1796        IPBusEnum - ok
22:45:00.0931 1796        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:45:00.0971 1796        IpFilterDriver - ok
22:45:01.0028 1796        iphlpsvc        (1998bd97f950680bb55f55a7244679c2) C:\Windows\System32\iphlpsvc.dll
22:45:01.0074 1796        iphlpsvc - ok
22:45:01.0079 1796        IpInIp - ok
22:45:01.0100 1796        IPMIDRV        (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
22:45:01.0157 1796        IPMIDRV - ok
22:45:01.0170 1796        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
22:45:01.0213 1796        IPNAT - ok
22:45:01.0231 1796        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
22:45:01.0270 1796        IRENUM - ok
22:45:01.0295 1796        isapnp          (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
22:45:01.0310 1796        isapnp - ok
22:45:01.0356 1796        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
22:45:01.0375 1796        iScsiPrt - ok
22:45:01.0387 1796        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
22:45:01.0403 1796        iteatapi - ok
22:45:01.0414 1796        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
22:45:01.0430 1796        iteraid - ok
22:45:01.0462 1796        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
22:45:01.0479 1796        kbdclass - ok
22:45:01.0510 1796        kbdhid          (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
22:45:01.0537 1796        kbdhid - ok
22:45:01.0597 1796        KeyIso          (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
22:45:01.0647 1796        KeyIso - ok
22:45:01.0703 1796        KSecDD          (2b2f1638466e8cb091400c9019cc730e) C:\Windows\system32\Drivers\ksecdd.sys
22:45:01.0759 1796        KSecDD - ok
22:45:01.0819 1796        KtmRm          (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll
22:45:01.0930 1796        KtmRm - ok
22:45:01.0993 1796        LanmanServer    (1bf5eebfd518dd7298434d8c862f825d) C:\Windows\system32\srvsvc.dll
22:45:02.0027 1796        LanmanServer - ok
22:45:02.0068 1796        LanmanWorkstation (1db69705b695b987082c8baec0c6b34f) C:\Windows\System32\wkssvc.dll
22:45:02.0100 1796        LanmanWorkstation - ok
22:45:02.0141 1796        Lavasoft Kernexplorer - ok
22:45:02.0191 1796        lirsgt          (975b6cf65f44e95883f3855bae8cecaf) C:\Windows\system32\DRIVERS\lirsgt.sys
22:45:02.0210 1796        lirsgt ( UnsignedFile.Multi.Generic ) - warning
22:45:02.0210 1796        lirsgt - detected UnsignedFile.Multi.Generic (1)
22:45:02.0244 1796        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
22:45:02.0294 1796        lltdio - ok
22:45:02.0320 1796        lltdsvc        (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll
22:45:02.0356 1796        lltdsvc - ok
22:45:02.0378 1796        lmhosts        (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll
22:45:02.0439 1796        lmhosts - ok
22:45:02.0473 1796        LSI_FC          (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
22:45:02.0491 1796        LSI_FC - ok
22:45:02.0505 1796        LSI_SAS        (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
22:45:02.0523 1796        LSI_SAS - ok
22:45:02.0560 1796        LSI_SCSI        (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
22:45:02.0576 1796        LSI_SCSI - ok
22:45:02.0610 1796        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
22:45:02.0653 1796        luafv - ok
22:45:02.0680 1796        Mcx2Svc        (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll
22:45:02.0713 1796        Mcx2Svc - ok
22:45:02.0738 1796        mdmxsdk        (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
22:45:02.0760 1796        mdmxsdk - ok
22:45:02.0776 1796        megasas        (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
22:45:02.0792 1796        megasas - ok
22:45:02.0819 1796        MMCSS          (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
22:45:02.0868 1796        MMCSS - ok
22:45:02.0883 1796        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
22:45:02.0919 1796        Modem - ok
22:45:02.0945 1796        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
22:45:02.0990 1796        monitor - ok
22:45:03.0016 1796        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
22:45:03.0034 1796        mouclass - ok
22:45:03.0062 1796        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
22:45:03.0103 1796        mouhid - ok
22:45:03.0132 1796        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
22:45:03.0150 1796        MountMgr - ok
22:45:03.0196 1796        mpio            (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
22:45:03.0213 1796        mpio - ok
22:45:03.0234 1796        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
22:45:03.0277 1796        mpsdrv - ok
22:45:03.0331 1796        MpsSvc          (5de62c6e9108f14f6794060a9bdecaec) C:\Windows\system32\mpssvc.dll
22:45:03.0395 1796        MpsSvc - ok
22:45:03.0415 1796        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
22:45:03.0431 1796        Mraid35x - ok
22:45:03.0472 1796        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
22:45:03.0508 1796        MRxDAV - ok
22:45:03.0555 1796        mrxsmb          (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:45:03.0597 1796        mrxsmb - ok
22:45:03.0641 1796        mrxsmb10        (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:45:03.0661 1796        mrxsmb10 - ok
22:45:03.0680 1796        mrxsmb20        (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:45:03.0705 1796        mrxsmb20 - ok
22:45:03.0723 1796        msahci          (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys
22:45:03.0740 1796        msahci - ok
22:45:03.0761 1796        msdsm          (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
22:45:03.0778 1796        msdsm - ok
22:45:03.0811 1796        MSDTC          (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe
22:45:03.0862 1796        MSDTC - ok
22:45:03.0898 1796        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
22:45:03.0943 1796        Msfs - ok
22:45:03.0985 1796        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
22:45:04.0002 1796        msisadrv - ok
22:45:04.0041 1796        MSiSCSI        (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll
22:45:04.0094 1796        MSiSCSI - ok
22:45:04.0100 1796        msiserver - ok
22:45:04.0142 1796        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
22:45:04.0191 1796        MSKSSRV - ok
22:45:04.0215 1796        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
22:45:04.0265 1796        MSPCLOCK - ok
22:45:04.0283 1796        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
22:45:04.0335 1796        MSPQM - ok
22:45:04.0371 1796        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
22:45:04.0393 1796        MsRPC - ok
22:45:04.0413 1796        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
22:45:04.0430 1796        mssmbios - ok
22:45:04.0436 1796        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
22:45:04.0470 1796        MSTEE - ok
22:45:04.0478 1796        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
22:45:04.0496 1796        Mup - ok
22:45:04.0541 1796        napagent        (e4eaf0c5c1b41b5c83386cf212ca9584) C:\Windows\system32\qagentRT.dll
22:45:04.0588 1796        napagent - ok
22:45:04.0670 1796        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
22:45:04.0703 1796        NativeWifiP - ok
22:45:04.0762 1796        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
22:45:04.0790 1796        NDIS - ok
22:45:04.0821 1796        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
22:45:04.0854 1796        NdisTapi - ok
22:45:04.0860 1796        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
22:45:04.0903 1796        Ndisuio - ok
22:45:04.0938 1796        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:45:04.0980 1796        NdisWan - ok
22:45:04.0998 1796        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
22:45:05.0035 1796        NDProxy - ok
22:45:05.0062 1796        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
22:45:05.0107 1796        NetBIOS - ok
22:45:05.0142 1796        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
22:45:05.0189 1796        netbt - ok
22:45:05.0252 1796        Netlogon        (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
22:45:05.0269 1796        Netlogon - ok
22:45:05.0309 1796        Netman          (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll
22:45:05.0359 1796        Netman - ok
22:45:05.0407 1796        netprofm        (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll
22:45:05.0455 1796        netprofm - ok
22:45:05.0519 1796        NetTcpPortSharing (d6c4e4a39a36029ac0813d476fbd0248) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:45:05.0537 1796        NetTcpPortSharing - ok
22:45:05.0564 1796        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
22:45:05.0580 1796        nfrd960 - ok
22:45:05.0646 1796        NinjaVideo Helper.exe (1ed90400ce0f398adb4faedda77acb89) C:\Program Files\NinjaVideo\NinjaVideo Helper\NinjaVideo Helper.exe
22:45:05.0663 1796        NinjaVideo Helper.exe ( UnsignedFile.Multi.Generic ) - warning
22:45:05.0663 1796        NinjaVideo Helper.exe - detected UnsignedFile.Multi.Generic (1)
22:45:05.0697 1796        NlaSvc          (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll
22:45:05.0751 1796        NlaSvc - ok
22:45:05.0778 1796        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
22:45:05.0819 1796        Npfs - ok
22:45:05.0858 1796        nsi            (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll
22:45:05.0901 1796        nsi - ok
22:45:05.0916 1796        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
22:45:05.0951 1796        nsiproxy - ok
22:45:06.0051 1796        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
22:45:06.0219 1796        Ntfs - ok
22:45:06.0244 1796        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
22:45:06.0337 1796        ntrigdigi - ok
22:45:06.0357 1796        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
22:45:06.0405 1796        Null - ok
22:45:06.0501 1796        NVENETFD        (a1108084b0d2fc43dcc401735770e2a3) C:\Windows\system32\DRIVERS\nvmfdx32.sys
22:45:06.0629 1796        NVENETFD - ok
22:45:07.0214 1796        nvlddmkm        (3c65f41ebb779a0f16ff965bfd0df179) C:\Windows\system32\DRIVERS\nvlddmkm.sys
22:45:07.0850 1796        nvlddmkm - ok
22:45:07.0954 1796        nvraid          (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
22:45:07.0969 1796        nvraid - ok
22:45:07.0992 1796        nvsmu          (9aebc32f9d6e02ebee0369ab296fe7c8) C:\Windows\system32\DRIVERS\nvsmu.sys
22:45:08.0022 1796        nvsmu - ok
22:45:08.0044 1796        nvstor          (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
22:45:08.0057 1796        nvstor - ok
22:45:08.0084 1796        nv_agp          (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
22:45:08.0100 1796        nv_agp - ok
22:45:08.0113 1796        NwlnkFlt - ok
22:45:08.0125 1796        NwlnkFwd - ok
22:45:08.0172 1796        OA004Ufd        (a015dd2ba6009c8bdd00a6c431302d06) C:\Windows\system32\DRIVERS\OA004Ufd.sys
22:45:08.0223 1796        OA004Ufd - ok
22:45:08.0268 1796        OA004Vid        (12a4366ff51befbdf018f654ff8b22b8) C:\Windows\system32\DRIVERS\OA004Vid.sys
22:45:08.0307 1796        OA004Vid - ok
22:45:08.0345 1796        ohci1394        (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
22:45:08.0419 1796        ohci1394 - ok
22:45:08.0676 1796        ose            (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:45:08.0691 1796        ose - ok
22:45:09.0212 1796        p2pimsvc        (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
22:45:09.0331 1796        p2pimsvc - ok
22:45:09.0361 1796        p2psvc          (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
22:45:09.0434 1796        p2psvc - ok
22:45:09.0584 1796        Parport        (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
22:45:09.0650 1796        Parport - ok
22:45:09.0763 1796        partmgr        (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
22:45:09.0779 1796        partmgr - ok
22:45:09.0823 1796        Parvdm          (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
22:45:09.0897 1796        Parvdm - ok
22:45:09.0978 1796        PcaSvc          (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll
22:45:09.0996 1796        PcaSvc - ok
22:45:10.0177 1796        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
22:45:10.0197 1796        pci - ok
22:45:10.0229 1796        pciide          (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
22:45:10.0246 1796        pciide - ok
22:45:10.0280 1796        pcmcia          (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
22:45:10.0298 1796        pcmcia - ok
22:45:10.0390 1796        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
22:45:10.0508 1796        PEAUTH - ok
22:45:11.0090 1796        pla            (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll
22:45:11.0257 1796        pla - ok
22:45:12.0206 1796        PlugPlay        (c5e7f8a996ec0a82d508fd9064a5569e) C:\Windows\system32\umpnpmgr.dll
22:45:12.0284 1796        PlugPlay - ok
22:45:12.0419 1796        PNRPAutoReg    (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
22:45:12.0453 1796        PNRPAutoReg - ok
22:45:12.0464 1796        PNRPsvc        (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
22:45:12.0498 1796        PNRPsvc - ok
22:45:12.0564 1796        PolicyAgent    (d0494460421a03cd5225cca0059aa146) C:\Windows\System32\ipsecsvc.dll
22:45:12.0618 1796        PolicyAgent - ok
22:45:12.0717 1796        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
22:45:12.0761 1796        PptpMiniport - ok
22:45:12.0787 1796        Processor      (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
22:45:12.0869 1796        Processor - ok
22:45:12.0905 1796        ProfSvc        (0508faa222d28835310b7bfca7a77346) C:\Windows\system32\profsvc.dll
22:45:12.0946 1796        ProfSvc - ok
22:45:13.0006 1796        ProtectedStorage (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
22:45:13.0034 1796        ProtectedStorage - ok
22:45:13.0073 1796        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
22:45:13.0116 1796        PSched - ok
22:45:13.0190 1796        ql2300          (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
22:45:13.0266 1796        ql2300 - ok
22:45:13.0286 1796        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
22:45:13.0303 1796        ql40xx - ok
22:45:13.0346 1796        QWAVE          (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll
22:45:13.0383 1796        QWAVE - ok
22:45:13.0413 1796        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
22:45:13.0440 1796        QWAVEdrv - ok
22:45:13.0461 1796        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
22:45:13.0504 1796        RasAcd - ok
22:45:13.0529 1796        RasAuto        (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll
22:45:13.0567 1796        RasAuto - ok
22:45:13.0605 1796        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:45:13.0637 1796        Rasl2tp - ok
22:45:13.0684 1796        RasMan          (75d47445d70ca6f9f894b032fbc64fcf) C:\Windows\System32\rasmans.dll
22:45:13.0723 1796        RasMan - ok
22:45:13.0754 1796        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
22:45:13.0786 1796        RasPppoe - ok
22:45:13.0817 1796        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
22:45:13.0846 1796        RasSstp - ok
22:45:13.0889 1796        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
22:45:13.0930 1796        rdbss - ok
22:45:13.0960 1796        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:45:13.0991 1796        RDPCDD - ok
22:45:14.0045 1796        rdpdr          (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
22:45:14.0121 1796        rdpdr - ok
22:45:14.0134 1796        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
22:45:14.0166 1796        RDPENCDD - ok
22:45:14.0210 1796        RDPWD          (79c6df8477250f5c54f7c5ae1d6b814e) C:\Windows\system32\drivers\RDPWD.sys
22:45:14.0268 1796        RDPWD - ok
22:45:14.0306 1796        RemoteAccess    (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll
22:45:14.0352 1796        RemoteAccess - ok
22:45:14.0384 1796        RemoteRegistry  (9e6894ea18daff37b63e1005f83ae4ab) C:\Windows\system32\regsvc.dll
22:45:14.0421 1796        RemoteRegistry - ok
22:45:14.0515 1796        RichVideo      (17e0bef5ca5c9ce52cc8082ac6ebc449) C:\Program Files\CyberLink\Shared Files\RichVideo.exe
22:45:14.0543 1796        RichVideo - ok
22:45:14.0569 1796        RpcLocator      (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe
22:45:14.0595 1796        RpcLocator - ok
22:45:14.0651 1796        RpcSs          (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
22:45:14.0705 1796        RpcSs - ok
22:45:14.0755 1796        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
22:45:14.0787 1796        rspndr - ok
22:45:14.0852 1796        SamSs          (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
22:45:14.0870 1796        SamSs - ok
22:45:14.0906 1796        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
22:45:14.0924 1796        sbp2port - ok
22:45:14.0964 1796        SCardSvr        (77b7a11a0c3d78d3386398fbbea1b632) C:\Windows\System32\SCardSvr.dll
22:45:15.0013 1796        SCardSvr - ok
22:45:15.0094 1796        Schedule        (1a58069db21d05eb2ab58ee5753ebe8d) C:\Windows\system32\schedsvc.dll
22:45:15.0145 1796        Schedule - ok
22:45:15.0180 1796        SCPolicySvc    (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
22:45:15.0206 1796        SCPolicySvc - ok
22:45:15.0313 1796        sdAuxService    (0d608069a10354474a986f3bc301e024) C:\Program Files\Spyware Doctor\pctsAuxs.exe
22:45:15.0372 1796        sdAuxService - ok
22:45:15.0458 1796        sdbus          (7b3973cc28b8aa3e9e2e5d53e720e2c9) C:\Windows\system32\DRIVERS\sdbus.sys
22:45:15.0484 1796        sdbus - ok
22:45:15.0588 1796        sdCoreService  (f4cdcbd7ad2e0c60d3eed62a55877834) C:\Program Files\Spyware Doctor\pctsSvc.exe
22:45:15.0658 1796        sdCoreService - ok
22:45:15.0702 1796        SDRSVC          (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll
22:45:15.0722 1796        SDRSVC - ok
22:45:15.0745 1796        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
22:45:15.0807 1796        secdrv - ok
22:45:15.0816 1796        seclogon        (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll
22:45:15.0853 1796        seclogon - ok
22:45:15.0881 1796        SENS            (a9bbab5759771e523f55563d6cbe140f) C:\Windows\System32\sens.dll
22:45:15.0916 1796        SENS - ok
22:45:15.0960 1796        Ser2pl          (2ec41a96d0dc98bd119bf325e0b9f392) C:\Windows\system32\DRIVERS\ser2pl.sys
22:45:15.0973 1796        Ser2pl - ok
22:45:15.0986 1796        Serenum        (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\DRIVERS\serenum.sys
22:45:16.0039 1796        Serenum - ok
22:45:16.0056 1796        Serial          (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
22:45:16.0129 1796        Serial - ok
22:45:16.0160 1796        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
22:45:16.0190 1796        sermouse - ok
22:45:16.0228 1796        SessionEnv      (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll
22:45:16.0261 1796        SessionEnv - ok
22:45:16.0278 1796        sffdisk        (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys
22:45:16.0350 1796        sffdisk - ok
22:45:16.0373 1796        sffp_mmc        (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
22:45:16.0427 1796        sffp_mmc - ok
22:45:16.0443 1796        sffp_sd        (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys
22:45:16.0497 1796        sffp_sd - ok
22:45:16.0513 1796        sfloppy        (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
22:45:16.0574 1796        sfloppy - ok
22:45:16.0617 1796        SharedAccess    (e1499bd0ff76b1b2fbbf1af339d91165) C:\Windows\System32\ipnathlp.dll
22:45:16.0660 1796        SharedAccess - ok
22:45:16.0705 1796        ShellHWDetection (c7230fbee14437716701c15be02c27b8) C:\Windows\System32\shsvcs.dll
22:45:16.0726 1796        ShellHWDetection - ok
22:45:16.0747 1796        sisagp          (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys
22:45:16.0761 1796        sisagp - ok
22:45:16.0777 1796        SiSRaid2        (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
22:45:16.0792 1796        SiSRaid2 - ok
22:45:16.0812 1796        SiSRaid4        (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
22:45:16.0828 1796        SiSRaid4 - ok
22:45:17.0060 1796        slsvc          (862bb4cbc05d80c5b45be430e5ef872f) C:\Windows\system32\SLsvc.exe
22:45:17.0404 1796        slsvc - ok
22:45:17.0522 1796        SLUINotify      (6edc422215cd78aa8a9cde6b30abbd35) C:\Windows\system32\SLUINotify.dll
22:45:17.0560 1796        SLUINotify - ok
22:45:17.0611 1796        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
22:45:17.0638 1796        Smb - ok
22:45:17.0669 1796        SNMPTRAP        (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe
22:45:17.0700 1796        SNMPTRAP - ok
22:45:17.0730 1796        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
22:45:17.0748 1796        spldr - ok
22:45:17.0815 1796        Spooler        (8554097e5136c3bf9f69fe578a1b35f4) C:\Windows\System32\spoolsv.exe
22:45:17.0852 1796        Spooler - ok
22:45:17.0905 1796        srv            (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
22:45:17.0953 1796        srv - ok
22:45:17.0987 1796        srv2            (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
22:45:18.0017 1796        srv2 - ok
22:45:18.0045 1796        srvnet          (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
22:45:18.0082 1796        srvnet - ok
22:45:18.0121 1796        SSDPSRV        (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll
22:45:18.0175 1796        SSDPSRV - ok
22:45:18.0239 1796        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
22:45:18.0252 1796        ssmdrv - ok
22:45:18.0304 1796        SstpSvc        (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll
22:45:18.0336 1796        SstpSvc - ok
22:45:18.0405 1796        stisvc          (5de7d67e49b88f5f07f3e53c4b92a352) C:\Windows\System32\wiaservc.dll
22:45:18.0438 1796        stisvc - ok
22:45:18.0472 1796        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
22:45:18.0489 1796        swenum - ok
22:45:18.0535 1796        swprv          (f21fd248040681cca1fb6c9a03aaa93d) C:\Windows\System32\swprv.dll
22:45:18.0581 1796        swprv - ok
22:45:18.0614 1796        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
22:45:18.0630 1796        Symc8xx - ok
22:45:18.0636 1796        SymIM - ok
22:45:18.0645 1796        SymIMMP - ok
22:45:18.0661 1796        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
22:45:18.0676 1796        Sym_hi - ok
22:45:18.0685 1796        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
22:45:18.0701 1796        Sym_u3 - ok
22:45:18.0740 1796        SynTP          (3d6316279c3540aa268bf025f4621ef3) C:\Windows\system32\DRIVERS\SynTP.sys
22:45:18.0760 1796        SynTP - ok
22:45:18.0818 1796        SysMain        (9a51b04e9886aa4ee90093586b0ba88d) C:\Windows\system32\sysmain.dll
22:45:18.0890 1796        SysMain - ok
22:45:18.0915 1796        TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll
22:45:18.0937 1796        TabletInputService - ok
22:45:18.0988 1796        TapiSrv        (d7673e4b38ce21ee54c59eeeb65e2483) C:\Windows\System32\tapisrv.dll
22:45:19.0022 1796        TapiSrv - ok
22:45:19.0123 1796        TBS            (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll
22:45:19.0162 1796        TBS - ok
22:45:19.0327 1796        Tcpip          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys
22:45:19.0465 1796        Tcpip - ok
22:45:19.0483 1796        Tcpip6          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys
22:45:19.0543 1796        Tcpip6 - ok
22:45:19.0593 1796        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
22:45:19.0624 1796        tcpipreg - ok
22:45:19.0650 1796        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
22:45:19.0701 1796        TDPIPE - ok
22:45:19.0740 1796        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
22:45:19.0786 1796        TDTCP - ok
22:45:19.0823 1796        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
22:45:19.0851 1796        tdx - ok
22:45:19.0978 1796        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
22:45:20.0031 1796        TermDD - ok
22:45:20.0100 1796        TermService    (bb95da09bef6e7a131bff3ba5032090d) C:\Windows\System32\termsrv.dll
22:45:20.0199 1796        TermService - ok
22:45:20.0237 1796        Themes          (c7230fbee14437716701c15be02c27b8) C:\Windows\system32\shsvcs.dll
22:45:20.0259 1796        Themes - ok
22:45:20.0283 1796        THREADORDER    (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
22:45:20.0319 1796        THREADORDER - ok
22:45:20.0346 1796        TrkWks          (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll
22:45:20.0384 1796        TrkWks - ok
22:45:20.0421 1796        TrustedInstaller (97d9d6a04e3ad9b6c626b9931db78dba) C:\Windows\servicing\TrustedInstaller.exe
22:45:20.0449 1796        TrustedInstaller - ok
22:45:20.0486 1796        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:45:20.0532 1796        tssecsrv - ok
22:45:20.0566 1796        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
22:45:20.0594 1796        tunmp - ok
22:45:20.0660 1796        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
22:45:20.0676 1796        tunnel - ok
22:45:20.0707 1796        uagp35          (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
22:45:20.0724 1796        uagp35 - ok
22:45:20.0769 1796        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
22:45:20.0807 1796        udfs - ok
22:45:20.0833 1796        UI0Detect      (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe
22:45:20.0885 1796        UI0Detect - ok
22:45:20.0985 1796        UleadBurningHelper (332d341d92b933600d41953b08360dfb) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
22:45:21.0010 1796        UleadBurningHelper ( UnsignedFile.Multi.Generic ) - warning
22:45:21.0011 1796        UleadBurningHelper - detected UnsignedFile.Multi.Generic (1)
22:45:21.0034 1796        uliagpkx        (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
22:45:21.0068 1796        uliagpkx - ok
22:45:21.0102 1796        uliahci        (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
22:45:21.0124 1796        uliahci - ok
22:45:21.0142 1796        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
22:45:21.0161 1796        UlSata - ok
22:45:21.0180 1796        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
22:45:21.0197 1796        ulsata2 - ok
22:45:21.0223 1796        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
22:45:21.0258 1796        umbus - ok
22:45:21.0311 1796        upnphost        (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll
22:45:21.0368 1796        upnphost - ok
22:45:21.0440 1796        USB28xxBGA      (01f43ddc94653cd68d2794ec4500debc) C:\Windows\system32\DRIVERS\emBDA.sys
22:45:21.0565 1796        USB28xxBGA - ok
22:45:21.0603 1796        USB28xxOEM      (925e82ffe06a37799e5cb486528ed835) C:\Windows\system32\DRIVERS\emOEM.sys
22:45:21.0636 1796        USB28xxOEM - ok
22:45:21.0672 1796        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
22:45:21.0713 1796        usbccgp - ok
22:45:21.0770 1796        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
22:45:21.0897 1796        usbcir - ok
22:45:21.0921 1796        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
22:45:21.0944 1796        usbehci - ok
22:45:21.0992 1796        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
22:45:22.0020 1796        usbhub - ok
22:45:22.0061 1796        usbohci        (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
22:45:22.0084 1796        usbohci - ok
22:45:22.0102 1796        usbprint        (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys
22:45:22.0157 1796        usbprint - ok
22:45:22.0168 1796        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:45:22.0192 1796        USBSTOR - ok
22:45:22.0211 1796        usbuhci        (325dbbacb8a36af9988ccf40eac228cc) C:\Windows\system32\DRIVERS\usbuhci.sys
22:45:22.0282 1796        usbuhci - ok
22:45:22.0333 1796        usbvideo        (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
22:45:22.0376 1796        usbvideo - ok
22:45:22.0399 1796        UxSms          (1509e705f3ac1d474c92454a5c2dd81f) C:\Windows\System32\uxsms.dll
22:45:22.0441 1796        UxSms - ok
22:45:22.0496 1796        vds            (cd88d1b7776dc17a119049742ec07eb4) C:\Windows\System32\vds.exe
22:45:22.0578 1796        vds - ok
22:45:22.0585 1796        vga            (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
22:45:22.0663 1796        vga - ok
22:45:22.0688 1796        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
22:45:22.0724 1796        VgaSave - ok
22:45:22.0737 1796        viaagp          (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
22:45:22.0754 1796        viaagp - ok
22:45:22.0770 1796        ViaC7          (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
22:45:22.0834 1796        ViaC7 - ok
22:45:22.0848 1796        viaide          (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
22:45:22.0863 1796        viaide - ok
22:45:22.0898 1796        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
22:45:22.0916 1796        volmgr - ok
22:45:22.0956 1796        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
22:45:22.0979 1796        volmgrx - ok
22:45:23.0027 1796        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
22:45:23.0052 1796        volsnap - ok
22:45:23.0076 1796        vsmraid        (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
22:45:23.0093 1796        vsmraid - ok
22:45:23.0190 1796        VSS            (db3d19f850c6eb32bdcb9bc0836acddb) C:\Windows\system32\vssvc.exe
22:45:23.0274 1796        VSS - ok
22:45:23.0327 1796        W32Time        (96ea68b9eb310a69c25ebb0282b2b9de) C:\Windows\system32\w32time.dll
22:45:23.0374 1796        W32Time - ok
22:45:23.0410 1796        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
22:45:23.0487 1796        WacomPen - ok
22:45:23.0519 1796        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
22:45:23.0558 1796        Wanarp - ok
22:45:23.0563 1796        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
22:45:23.0590 1796        Wanarpv6 - ok
22:45:23.0634 1796        wcncsvc        (a3cd60fd826381b49f03832590e069af) C:\Windows\System32\wcncsvc.dll
22:45:23.0688 1796        wcncsvc - ok
22:45:23.0776 1796        WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll
22:45:23.0805 1796        WcsPlugInService - ok
22:45:23.0818 1796        Wd              (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
22:45:23.0833 1796        Wd - ok
22:45:23.0887 1796        Wdf01000        (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
22:45:23.0928 1796        Wdf01000 - ok
22:45:23.0959 1796        WdiServiceHost  (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
22:45:24.0012 1796        WdiServiceHost - ok
22:45:24.0017 1796        WdiSystemHost  (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
22:45:24.0057 1796        WdiSystemHost - ok
22:45:24.0103 1796        WebClient      (04c37d8107320312fbae09926103d5e2) C:\Windows\System32\webclnt.dll
22:45:24.0141 1796        WebClient - ok
22:45:24.0174 1796        Wecsvc          (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll
22:45:24.0207 1796        Wecsvc - ok
22:45:24.0232 1796        wercplsupport  (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll
22:45:24.0275 1796        wercplsupport - ok
22:45:24.0320 1796        WerSvc          (32b88481d3b326da6deb07b1d03481e7) C:\Windows\System32\WerSvc.dll
22:45:24.0364 1796        WerSvc - ok
22:45:24.0431 1796        winachsf        (e096ffb754f1e45ae1bddac1275ae2c5) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
22:45:24.0513 1796        winachsf - ok
22:45:24.0607 1796        WinDefend      (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll
22:45:24.0653 1796        WinDefend - ok
22:45:24.0672 1796        WinHttpAutoProxySvc - ok
22:45:24.0747 1796        Winmgmt        (6b2a1d0e80110e3d04e6863c6e62fd8a) C:\Windows\system32\wbem\WMIsvc.dll
22:45:24.0771 1796        Winmgmt - ok
22:45:24.0876 1796        WinRM          (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll
22:45:24.0986 1796        WinRM - ok
22:45:25.0097 1796        Wlansvc        (c008405e4feeb069e30da1d823910234) C:\Windows\System32\wlansvc.dll
22:45:25.0149 1796        Wlansvc - ok
22:45:25.0255 1796        WmiAcpi        (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:45:25.0286 1796        WmiAcpi - ok
22:45:25.0332 1796        wmiApSrv        (43be3875207dcb62a85c8c49970b66cc) C:\Windows\system32\wbem\WmiApSrv.exe
22:45:25.0376 1796        wmiApSrv - ok
22:45:25.0487 1796        WMPNetworkSvc  (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe
22:45:25.0565 1796        WMPNetworkSvc - ok
22:45:25.0599 1796        WPCSvc          (cfc5a04558f5070cee3e3a7809f3ff52) C:\Windows\System32\wpcsvc.dll
22:45:25.0620 1796        WPCSvc - ok
22:45:25.0660 1796        WPDBusEnum      (801fbdb89d472b3c467eb112a0fc9246) C:\Windows\system32\wpdbusenum.dll
22:45:25.0681 1796        WPDBusEnum - ok
22:45:25.0737 1796        WpdUsb          (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
22:45:25.0755 1796        WpdUsb - ok
22:45:25.0946 1796        WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
22:45:26.0006 1796        WPFFontCache_v0400 - ok
22:45:26.0034 1796        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
22:45:26.0078 1796        ws2ifsl - ok
22:45:26.0111 1796        wscsvc          (1ca6c40261ddc0425987980d0cd2aaab) C:\Windows\System32\wscsvc.dll
22:45:26.0145 1796        wscsvc - ok
22:45:26.0151 1796        WSearch - ok
22:45:26.0330 1796        wuauserv        (6298277b73c77fa99106b271a7525163) C:\Windows\system32\wuaueng.dll
22:45:26.0491 1796        wuauserv - ok
22:45:26.0610 1796        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:45:26.0642 1796        WUDFRd - ok
22:45:26.0677 1796        wudfsvc        (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll
22:45:26.0713 1796        wudfsvc - ok
22:45:26.0732 1796        XAudio          (19e7c173b6242ad7521e537ae54768bf) C:\Windows\system32\DRIVERS\xaudio.sys
22:45:26.0756 1796        XAudio - ok
22:45:26.0790 1796        XAudioService  (cda0bc78672b50c43649ff34e1fd0ff8) C:\Windows\system32\DRIVERS\xaudio.exe
22:45:26.0845 1796        XAudioService - ok
22:45:26.0873 1796        MBR (0x1B8)    (1a1a06f62e891045814007163c1c76c3) \Device\Harddisk0\DR0
22:45:26.0983 1796        \Device\Harddisk0\DR0 - ok
22:45:26.0988 1796        Boot (0x1200)  (b19fc7c5644e3be6c92a2c6c7ac94748) \Device\Harddisk0\DR0\Partition0
22:45:26.0990 1796        \Device\Harddisk0\DR0\Partition0 - ok
22:45:26.0997 1796        Boot (0x1200)  (5089dcfff5e3d138ede892a593ae173f) \Device\Harddisk0\DR0\Partition1
22:45:26.0999 1796        \Device\Harddisk0\DR0\Partition1 - ok
22:45:27.0002 1796        ============================================================
22:45:27.0002 1796        Scan finished
22:45:27.0002 1796        ============================================================
22:45:27.0023 3056        Detected object count: 11
22:45:27.0023 3056        Actual detected object count: 11
22:46:22.0406 3056        ASAPIW2K ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:22.0407 3056        ASAPIW2K ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:22.0416 3056        atksgt ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:22.0416 3056        atksgt ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:22.0423 3056        AVM IGD CTRL Service ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:22.0424 3056        AVM IGD CTRL Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:22.0430 3056        Com4Qlb ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:22.0431 3056        Com4Qlb ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:22.0439 3056        de_serv ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:22.0439 3056        de_serv ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:22.0445 3056        HP Health Check Service ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:22.0445 3056        HP Health Check Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:22.0454 3056        hpqwmiex ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:22.0455 3056        hpqwmiex ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:22.0455 3056        IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:22.0456 3056        IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:22.0462 3056        lirsgt ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:22.0462 3056        lirsgt ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:22.0469 3056        NinjaVideo Helper.exe ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:22.0469 3056        NinjaVideo Helper.exe ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:22.0470 3056        UleadBurningHelper ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:22.0470 3056        UleadBurningHelper ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 11.05.2012 10:11

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 12:45 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131