Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Trojan.Agent.CWIGen (https://www.trojaner-board.de/117851-trojan-agent-cwigen.html)

KastorPollux 23.06.2012 21:39

Trojan.Agent.CWIGen
 
Ich habe einen Verschlüsselungstrojaner eingefangen. Nach Anweisung habe ich Malwarebytes eingesetzt und den folgenden logfile erhalten:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.23.05

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Ingeborg :: INGEBORG-PC [Administrator]

23.06.2012 19:36:04
mbam-log-2012-06-23 (19-36-04).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 421540
Laufzeit: 1 Stunde(n), 33 Minute(n), 56 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\Hans\AppData\Local\Temp\mkpjorvwmi.pre (Trojan.Agent.CWIGen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Hans\AppData\Roaming\Xdtsrk\nbyytbkun.exe (Trojan.Agent.CWIGen) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Soll ich jetzt wie unter 2. angegeben den Rechner reinigen? Lassen sich die verschlüsselten Datein wieder entschlüsseln?

Vielen Dank

KastorPollux

KastorPollux 24.06.2012 10:01

Ergänzend zum vorigen Posting - Hier das Log von OTL und angehängt die zwei Logfiles von GMER und EXTRA:OTL Logfile:
Code:

OTL logfile created on: 6/24/2012 6:57:13 AM - Run 1
OTL by OldTimer - Version 3.2.53.0    Folder = C:\Users\Ingeborg\Desktop
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2.93 Gb Total Physical Memory | 2.10 Gb Available Physical Memory | 71.64% Memory free
5.86 Gb Paging File | 4.30 Gb Available in Paging File | 73.37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 141.49 Gb Total Space | 78.03 Gb Free Space | 55.15% Space Free | Partition Type: NTFS
Drive D: | 58.86 Gb Total Space | 56.58 Gb Free Space | 96.12% Space Free | Partition Type: NTFS
Drive F: | 14.90 Gb Total Space | 14.83 Gb Free Space | 99.52% Space Free | Partition Type: FAT32
 
Computer Name: INGEBORG-PC | User Name: Ingeborg | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/06/24 06:54:50 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\Ingeborg\Desktop\OTL.exe
PRC - [2012/06/24 06:38:46 | 000,050,477 | ---- | M] () -- C:\Users\Ingeborg\Desktop\Defogger.exe
PRC - [2012/06/07 10:13:22 | 000,096,792 | ---- | M] (Google Inc.) -- C:\Users\Hans\AppData\Local\Google\Chrome\Application\19.0.1084.56\chrome_frame_helper.exe
PRC - [2012/04/19 08:21:26 | 000,308,392 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\VirusScan\McVsShld.exe
PRC - [2012/03/21 21:16:10 | 001,318,816 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2012/03/20 13:11:32 | 000,151,880 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
PRC - [2012/03/20 13:05:00 | 000,161,632 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
PRC - [2012/03/20 13:04:32 | 000,166,288 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
PRC - [2012/01/18 08:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
PRC - [2012/01/03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/11/18 15:51:12 | 003,673,944 | ---- | M] () -- C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe
PRC - [2011/11/11 15:08:06 | 000,205,336 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2011/11/11 15:07:54 | 000,265,240 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
PRC - [2011/08/24 18:30:58 | 000,651,832 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
PRC - [2011/08/24 18:30:58 | 000,430,136 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
PRC - [2011/08/12 13:19:40 | 000,680,984 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
PRC - [2011/07/22 00:07:38 | 000,718,720 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
PRC - [2011/07/11 23:47:06 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe
PRC - [2011/06/24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011/04/25 03:24:16 | 000,726,976 | ---- | M] (Citrix Systems, Inc.) -- C:\Users\Hans\AppData\Local\Citrix\ICA Client\wfcrun32.exe
PRC - [2011/04/25 03:22:40 | 000,305,088 | ---- | M] (Citrix Systems, Inc.) -- C:\Users\Hans\AppData\Local\Citrix\ICA Client\concentr.exe
PRC - [2011/04/08 14:59:50 | 000,419,904 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MAT\McPvTray.exe
PRC - [2011/02/25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
PRC - [2010/12/16 00:46:06 | 000,151,056 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\Core\mchost.exe
PRC - [2010/11/20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/04/13 21:11:14 | 000,229,688 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Online Backup\MOBKbackup.exe
PRC - [2010/01/19 11:34:48 | 002,201,192 | ---- | M] (SEC) -- C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
PRC - [2009/12/03 10:12:12 | 000,976,320 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\Event Manager\EEventManager.exe
PRC - [2009/09/14 07:00:00 | 000,153,600 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE
PRC - [2009/09/14 07:00:00 | 000,121,856 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
PRC - [2009/09/08 01:47:52 | 000,832,512 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2009/09/07 12:42:04 | 000,093,184 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
PRC - [2009/08/23 06:47:34 | 000,716,800 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2009/08/13 22:58:10 | 000,044,312 | ---- | M] () -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe
PRC - [2009/05/14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
PRC - [2008/01/16 10:51:44 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012/06/24 06:38:46 | 000,050,477 | ---- | M] () -- C:\Users\Ingeborg\Desktop\Defogger.exe
MOD - [2011/11/11 15:09:20 | 000,336,408 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll
MOD - [2011/11/11 15:07:54 | 000,265,240 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/12 13:19:40 | 000,680,984 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
MOD - [2011/08/12 13:18:56 | 000,342,552 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2011/08/12 13:18:56 | 000,128,536 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2011/08/12 13:18:56 | 000,029,208 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2011/08/12 13:18:54 | 007,956,504 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2011/08/12 13:18:54 | 002,145,304 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2011/03/17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2006/08/12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012/05/06 06:20:18 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/04/19 08:21:16 | 000,361,976 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2012/03/20 13:11:32 | 000,151,880 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe -- (mfevtp)
SRV - [2012/03/20 13:05:00 | 000,161,632 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV - [2012/03/20 13:04:32 | 000,166,288 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV - [2012/02/23 13:45:31 | 000,690,352 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) [Auto | Stopped] -- C:\Program Files\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe -- (StarMoney 8.0 OnlineUpdate)
SRV - [2012/01/18 08:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2012/01/03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/11/18 15:51:12 | 003,673,944 | ---- | M] () [Auto | Running] -- C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe -- (Radio.fx)
SRV - [2011/11/08 12:54:25 | 000,554,160 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) [Auto | Stopped] -- C:\Program Files\StarMoney 7.0\ouservice\StarMoneyOnlineUpdate.exe -- (StarMoney 7.0 OnlineUpdate)
SRV - [2011/08/24 18:30:58 | 000,430,136 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2011/07/01 11:34:50 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/06/12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (MSK80Service)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McProxy)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV - [2010/04/13 21:11:14 | 000,229,688 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee Online Backup\MOBKbackup.exe -- (MOBKbackup)
SRV - [2009/09/14 07:00:00 | 000,153,600 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE -- (EPSON_EB_RPCV4_04) EPSON V5 Service4(04)
SRV - [2009/09/14 07:00:00 | 000,121,856 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE -- (EPSON_PM_RPCV4_04) EPSON V3 Service4(04)
SRV - [2009/08/13 22:58:10 | 000,044,312 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe -- (OberonGameConsoleService)
SRV - [2009/07/14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/05/14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)
SRV - [2008/01/16 10:51:44 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
SRV - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (mfeavfk01)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_jubusenum.sys -- (huawei_enumerator)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2012/02/22 13:29:46 | 000,464,304 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2012/02/22 13:29:46 | 000,340,920 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2012/02/22 13:29:46 | 000,180,848 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2012/02/22 13:29:46 | 000,169,608 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2012/02/22 13:29:46 | 000,121,544 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2012/02/22 13:29:46 | 000,087,656 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2012/02/22 13:29:46 | 000,064,912 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk)
DRV - [2012/02/22 13:29:46 | 000,059,456 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2012/02/22 13:29:46 | 000,057,600 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cfwids.sys -- (cfwids)
DRV - [2012/01/18 08:44:52 | 004,332,960 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC) Logitech HD Webcam C525(UVC)
DRV - [2012/01/18 08:44:28 | 000,312,096 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS)
DRV - [2012/01/18 08:44:14 | 000,022,176 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvbusflt.sys -- (CompFilter)
DRV - [2011/04/25 02:49:16 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2011/04/11 15:29:16 | 000,064,048 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\McPvDrv.sys -- (McPvDrv)
DRV - [2010/11/20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/06/10 04:43:18 | 001,271,808 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2010/04/13 21:10:22 | 000,054,776 | ---- | M] (Mozy, Inc.) [File_System | System | Running] -- C:\Windows\System32\drivers\MOBK.sys -- (MOBKFilter)
DRV - [2009/07/14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)
IE - HKLM\..\SearchScopes,DefaultScope = {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-winamp-chromesbox-en-us&tb_uuid=20110703054604248&tb_oid=03-07-2011&tb_mrud=03-07-2011
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.surfstartseite.de
IE - HKCU\..\URLSearchHook: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_de
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/02/27 05:53:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/06/23 21:46:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.20\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/03/24 21:35:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.20\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
 
[2010/12/23 23:13:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ingeborg\AppData\Roaming\mozilla\Extensions
[2010/12/23 23:13:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ingeborg\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Ingeborg\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Ingeborg\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google-Suche = C:\Users\Ingeborg\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: SiteAdvisor = C:\Users\Ingeborg\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\
CHR - Extension: Google Mail = C:\Users\Ingeborg\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\
 
O1 HOSTS File: ([2009/06/10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120428175728.dll (McAfee, Inc.)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Users\Hans\AppData\Local\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [McPvTray_exe] C:\Program Files\McAfee\MAT\McPvTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: An OneNote s&enden - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 78.42.43.62 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C08167AA-3C9D-4EE9-B072-3226732BC7F5}: DhcpNameServer = 78.42.43.62 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E366DA8A-EC55-4CAC-9A1B-0C76A4645162}: DhcpNameServer = 219.147.1.66 219.146.1.66
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011/08/04 18:13:52 | 000,000,110 | -H-- | M] () - F:\autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/06/24 06:56:39 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Users\Ingeborg\Desktop\OTL.exe
[2012/06/23 19:34:56 | 000,000,000 | ---D | C] -- C:\Users\Ingeborg\AppData\Roaming\Malwarebytes
[2012/06/23 19:34:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/23 19:34:36 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2012/06/23 19:34:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/06/23 19:34:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/06/23 19:33:50 | 010,063,000 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Ingeborg\Desktop\mbam-setup-1.61.0.1400.exe
[2012/05/27 09:31:04 | 000,000,000 | ---D | C] -- C:\ProgramData\DatacardService
 
========== Files - Modified Within 30 Days ==========
 
[2012/06/24 06:54:50 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\Ingeborg\Desktop\OTL.exe
[2012/06/24 06:51:47 | 000,000,000 | ---- | M] () -- C:\Users\Ingeborg\defogger_reenable
[2012/06/24 06:40:26 | 000,001,116 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1131658597-4005637612-88016806-1008UA.job
[2012/06/24 06:40:26 | 000,001,102 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/24 06:40:16 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/06/24 06:40:08 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/06/24 06:38:46 | 000,050,477 | ---- | M] () -- C:\Users\Ingeborg\Desktop\Defogger.exe
[2012/06/23 21:51:29 | 000,001,788 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2012/06/23 21:50:05 | 000,015,056 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/23 21:50:05 | 000,015,056 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/23 21:46:44 | 000,001,098 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/23 21:42:08 | 000,065,536 | ---- | M] () -- C:\windows\System32\Ikeext.etl
[2012/06/23 21:41:56 | 2362,920,960 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/23 19:34:37 | 000,001,027 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/23 19:22:18 | 000,711,370 | ---- | M] () -- C:\windows\System32\perfh007.dat
[2012/06/23 19:22:18 | 000,662,950 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2012/06/23 19:22:18 | 000,153,766 | ---- | M] () -- C:\windows\System32\perfc007.dat
[2012/06/23 19:22:18 | 000,124,144 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2012/06/23 19:15:05 | 000,003,108 | ---- | M] () -- C:\windows\MOBK.blk
[2012/06/23 19:15:04 | 000,002,010 | ---- | M] () -- C:\windows\MOBK.flt
[2012/06/23 17:12:00 | 010,063,000 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Ingeborg\Desktop\mbam-setup-1.61.0.1400.exe
[2012/06/12 11:53:04 | 000,001,064 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1131658597-4005637612-88016806-1008Core.job
[2012/05/27 09:38:00 | 000,000,000 | -H-- | M] () -- C:\windows\System32\drivers\Msft_Kernel_ew_jucdcacm_01009.Wdf
[2012/05/27 09:34:29 | 000,000,000 | -H-- | M] () -- C:\windows\System32\drivers\Msft_Kernel_ew_jubusenum_01009.Wdf
 
========== Files Created - No Company Name ==========
 
[2012/06/24 06:51:47 | 000,000,000 | ---- | C] () -- C:\Users\Ingeborg\defogger_reenable
[2012/06/24 06:51:14 | 000,050,477 | ---- | C] () -- C:\Users\Ingeborg\Desktop\Defogger.exe
[2012/06/23 19:34:37 | 000,001,027 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/07 09:13:24 | 000,065,536 | ---- | C] () -- C:\windows\System32\Ikeext.etl
[2012/05/27 09:38:00 | 000,000,000 | -H-- | C] () -- C:\windows\System32\drivers\Msft_Kernel_ew_jucdcacm_01009.Wdf
[2012/05/27 09:34:29 | 000,000,000 | -H-- | C] () -- C:\windows\System32\drivers\Msft_Kernel_ew_jubusenum_01009.Wdf
[2012/01/18 08:44:00 | 010,920,984 | ---- | C] () -- C:\windows\System32\LogiDPP.dll
[2012/01/18 08:44:00 | 000,336,408 | ---- | C] () -- C:\windows\System32\DevManagerCore.dll
[2012/01/18 08:44:00 | 000,104,472 | ---- | C] () -- C:\windows\System32\LogiDPPApp.exe
[2011/08/12 13:20:14 | 000,015,896 | ---- | C] () -- C:\windows\System32\drivers\iKeyLFT2.dll
[2011/07/26 07:48:54 | 000,028,418 | ---- | C] () -- C:\windows\System32\lvcoinst.ini
[2011/04/08 18:28:57 | 000,554,496 | ---- | C] () -- C:\windows\System32\dvmsg.dll
[2010/11/28 18:12:44 | 000,056,320 | ---- | C] () -- C:\windows\System32\iyvu9_32.dll
[2010/10/19 20:45:03 | 000,000,400 | ---- | C] () -- C:\windows\ODBC.INI
[2010/09/06 17:42:07 | 000,003,584 | ---- | C] () -- C:\Users\Ingeborg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/25 20:30:02 | 000,439,308 | ---- | C] () -- C:\windows\System32\igcompkrng500.bin
[2010/08/25 20:30:00 | 000,982,240 | ---- | C] () -- C:\windows\System32\igkrng500.bin
[2010/08/25 20:30:00 | 000,092,356 | ---- | C] () -- C:\windows\System32\igfcg500m.bin
[2010/08/25 19:59:08 | 000,004,096 | ---- | C] ( ) -- C:\windows\System32\IGFXDEVLib.dll
[2010/08/06 18:12:10 | 000,000,600 | ---- | C] () -- C:\Users\Ingeborg\AppData\Roaming\winscp.rnd
[2010/02/25 21:08:32 | 000,007,605 | ---- | C] () -- C:\Users\Ingeborg\AppData\Local\Resmon.ResmonCfg
[2009/12/26 08:39:38 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe
 
========== LOP Check ==========
 
[2010/02/06 23:08:57 | 000,000,000 | -HSD | M] -- C:\Users\Ingeborg\AppData\Roaming\.#
[2010/05/08 17:12:25 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\Babylon
[2011/08/19 19:24:01 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\EndNote
[2011/04/19 16:00:05 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\Epson
[2010/02/06 23:08:39 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\GameConsole
[2010/06/06 11:00:09 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\IrfanView
[2011/12/25 13:06:58 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\Leadertech
[2009/12/30 20:37:02 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\OpenOffice.org
[2010/12/23 23:13:52 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\Thunderbird
[2011/04/12 21:14:15 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\Tobit
[2012/06/07 22:08:11 | 000,032,640 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:A42A9F39

< End of report >

--- --- ---

cosinus 28.06.2012 11:49

Zitat:

Soll ich jetzt wie unter 2. angegeben den Rechner reinigen? Lassen sich die verschlüsselten Datein wieder entschlüsseln?
Warum wird immer wieder nach etwas gefragt was oben in der fetten Hinweisbox schon "laut" und deutlich steht bzw. verlinkt ist!


Bitte erstmal routinemäßig einen neuen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

KastorPollux 08.07.2012 13:05

Hallo Cosinus,
vielen Dank für die Antwort. Leider bin erst jetzt dazu gekommen die empfohlenen Scans durchzuführen.
Ich poste jetzt alle Malwarebyte Scans, die ich habe und den ESET Scan.
(OTL und GMER habe ich schon gepostet).
Code:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.23.05

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Ingeborg :: INGEBORG-PC [Administrator]

23.06.2012 19:36:04
mbam-log-2012-06-23 (19-36-04).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 421540
Laufzeit: 1 Stunde(n), 33 Minute(n), 56 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\Hans\AppData\Local\Temp\mkpjorvwmi.pre (Trojan.Agent.CWIGen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Hans\AppData\Roaming\Xdtsrk\nbyytbkun.exe (Trojan.Agent.CWIGen) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Code:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Database version: v2012.07.04.02

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Hans :: INGEBORG-PC [administrator]

04.07.2012 07:48:14
mbam-log-2012-07-04 (07-48-14).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 5096
Time elapsed: 2 minute(s), 34 second(s) [aborted]

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Code:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Database version: v2012.07.04.02

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Hans :: INGEBORG-PC [administrator]

04.07.2012 07:51:49
mbam-log-2012-07-04 (07-51-49).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 425044
Time elapsed: 2 hour(s), 22 minute(s), 8 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
F:\DecryptHelper-0.5.3.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

(end)

Code:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Database version: v2012.07.04.02

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Hans :: INGEBORG-PC [administrator]

07.07.2012 20:38:42
mbam-log-2012-07-07 (20-38-42).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 422668
Time elapsed: 1 hour(s), 20 minute(s), 23 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Code:

C:\Users\Hans\AppData\Local\Temp\jar_cache4204658694695458036.tmp        Java/Exploit.Agent.NBC trojan
C:\Users\Hans\AppData\Local\Temp\jar_cache4775772330973992911.tmp        multiple threats
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\3e2b60ff-3c54f369        a variant of Java/Exploit.Blacole.AN trojan
C:\Users\Ingeborg\AppData\Local\Temp\jar_cache6483116802633796897.tmp        probably a variant of Java/TrojanDownloader.Agent.IVJRHQB trojan
C:\Users\Ingeborg\AppData\Local\Temp\jar_cache7752808509623869412.tmp        probably a variant of Java/TrojanDownloader.Agent.IVJRHQB trojan

Ich hoffe ich habe es richtig gemacht.
Vielen herzlichen Dank für Ihre Mühen
KastorPollux
Ich hatte es doch nicht richtig gemacht. Hier folgt der richtige logfile von ESET:
Code:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=89f840751b4a3e44a4375294c2d282b8
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-04 11:05:03
# local_time=2012-07-04 01:05:03 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5121 16777213 100 75 2295732 6620948 0 0
# compatibility_mode=5893 16776574 100 94 11744419 93026607 0 0
# compatibility_mode=8192 67108863 100 0 609 609 0 0
# scanned=107474
# found=5
# cleaned=0
# scan_time=4487
C:\Users\Hans\AppData\Local\Temp\jar_cache4204658694695458036.tmp        Java/Exploit.Agent.NBC trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Hans\AppData\Local\Temp\jar_cache4775772330973992911.tmp        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\3e2b60ff-3c54f369        a variant of Java/Exploit.Blacole.AN trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Ingeborg\AppData\Local\Temp\jar_cache6483116802633796897.tmp        probably a variant of Java/TrojanDownloader.Agent.IVJRHQB trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Ingeborg\AppData\Local\Temp\jar_cache7752808509623869412.tmp        probably a variant of Java/TrojanDownloader.Agent.IVJRHQB trojan (unable to clean)        00000000000000000000000000000000        I
esets_scanner_update returned -1 esets_gle=53251
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=89f840751b4a3e44a4375294c2d282b8
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-04 01:32:49
# local_time=2012-07-04 03:32:49 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5121 16777213 100 75 2300404 6625620 0 0
# compatibility_mode=5893 16776574 100 94 11749091 93031279 0 0
# compatibility_mode=8192 67108863 100 0 5281 5281 0 0
# scanned=169982
# found=5
# cleaned=0
# scan_time=8680
C:\Users\Hans\AppData\Local\Temp\jar_cache4204658694695458036.tmp        Java/Exploit.Agent.NBC trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Hans\AppData\Local\Temp\jar_cache4775772330973992911.tmp        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\3e2b60ff-3c54f369        a variant of Java/Exploit.Blacole.AN trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Ingeborg\AppData\Local\Temp\jar_cache6483116802633796897.tmp        probably a variant of Java/TrojanDownloader.Agent.IVJRHQB trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Ingeborg\AppData\Local\Temp\jar_cache7752808509623869412.tmp        probably a variant of Java/TrojanDownloader.Agent.IVJRHQB trojan (unable to clean)        00000000000000000000000000000000        I

Jetzt ist es wohl richtig.
KastorPollux

cosinus 09.07.2012 11:43

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

KastorPollux 09.07.2012 18:15

Hallo Cosinus,
alles geht offensichtlich ohne Probleme. Alle Programme sind offensichtlich vorhanden. Starmoney startet jedoch nicht, da die resources.mdb nicht auffindbar ist. Mit den anderen Programmen hatte ich keine Probleme ausser dass die meisten Dateien verschlüsselt sind.
KastorPollux

cosinus 10.07.2012 09:28

Zitat:

Starmoney startet jedoch nicht, da die resources.mdb nicht auffindbar ist.
Wenn die auch verschlüsselt ist wäre das jedenfalls kein Wunder

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

KastorPollux 11.07.2012 08:52

Hallo Arne,
hier der logfile von Adwcleaner:
Code:

# AdwCleaner v1.701 - Logfile created 07/11/2012 at 08:45:14
# Updated 02/07/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (32 bits)
# User : Hans - INGEBORG-PC
# Running from : C:\Users\Hans\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Users\Ingeborg\AppData\Local\Babylon
Folder Found : C:\Users\Ingeborg\AppData\Local\Conduit
Folder Found : C:\Users\Ingeborg\AppData\Local\Winamp Toolbar
Folder Found : C:\Users\Hans\AppData\Local\OpenCandy
Folder Found : C:\Users\Hans\AppData\Local\Winamp Toolbar
Folder Found : C:\Users\Ingeborg\AppData\Local\Temp\Babylon
Folder Found : C:\Users\Ingeborg\AppData\LocalLow\Conduit
Folder Found : C:\Users\Ingeborg\AppData\Roaming\Babylon
Folder Found : C:\Users\Hans\AppData\Roaming\OpenCandy
Folder Found : C:\ProgramData\Winamp Toolbar
Folder Found : C:\Program Files\Babylon
Folder Found : C:\Program Files\Winamp Toolbar
Folder Found : C:\Program Files\Common Files\Software Update Utility

***** [Registry] *****
[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT1460988
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar
Key Found : HKCU\Software\Winamp Toolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\winamptbServer.exe
Key Found : HKLM\SOFTWARE\Classes\dnUpdate
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Found : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch
Key Found : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch.1
Key Found : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand
Key Found : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand.1
Key Found : HKLM\SOFTWARE\Classes\WinampTb.Downloader
Key Found : HKLM\SOFTWARE\Classes\WinampTb.Downloader.1
Key Found : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo
Key Found : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo.1
Key Found : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams
Key Found : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams.1
Key Found : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper
Key Found : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper.1
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar
Key Found : HKLM\SOFTWARE\Winamp Toolbar

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Found : HKLM\SOFTWARE\Classes\AppID\{B27D9527-3762-4D71-963D-FB7A94FDD678}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EF4E91D-DDD5-4478-BCA7-DA04435934C0}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B38D6EDE-390B-4620-8365-29E16459EBDA}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F20F11FD-203E-45A9-B7BB-AFC1B4FEA7A6}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FE178B09-C8AA-4734-804D-1849BCCA0C29}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{507591C2-2F4E-46A7-92D6-E6CFF82E5F26}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{538CD77C-BFDD-49B0-9562-77419CAB89D1}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Google Chrome v [Unable to get version]

File : C:\Users\Ingeborg\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

File : C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [6896 octets] - [11/07/2012 08:45:14]

########## EOF - C:\AdwCleaner[R1].txt - [7024 octets] ##########

Soll ich die nach ESET infizierten files in TEMP ordnern löschen?
Gruß und danke
Hans

cosinus 11.07.2012 10:52

Nein bitte nichts mit ESET löschen

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

KastorPollux 11.07.2012 21:24

Hallo,
hier ist die logdatei:
Code:

# AdwCleaner v1.701 - Logfile created 07/11/2012 at 22:14:51
# Updated 02/07/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (32 bits)
# User : Hans - INGEBORG-PC
# Running from : C:\Users\Hans\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\Ingeborg\AppData\Local\Babylon
Folder Deleted : C:\Users\Ingeborg\AppData\Local\Conduit
Folder Deleted : C:\Users\Ingeborg\AppData\Local\Winamp Toolbar
Folder Deleted : C:\Users\Hans\AppData\Local\OpenCandy
Folder Deleted : C:\Users\Hans\AppData\Local\Winamp Toolbar
Folder Deleted : C:\Users\Ingeborg\AppData\Local\Temp\Babylon
Folder Deleted : C:\Users\Ingeborg\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Ingeborg\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Hans\AppData\Roaming\OpenCandy
Folder Deleted : C:\ProgramData\Winamp Toolbar
Folder Deleted : C:\Program Files\Babylon
Folder Deleted : C:\Program Files\Winamp Toolbar
Folder Deleted : C:\Program Files\Common Files\Software Update Utility

***** [Registry] *****
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1460988
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar
Key Deleted : HKCU\Software\Winamp Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\winamptbServer.exe
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.Downloader
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.Downloader.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper
Key Deleted : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper.1
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar
Key Deleted : HKLM\SOFTWARE\Winamp Toolbar

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B27D9527-3762-4D71-963D-FB7A94FDD678}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EF4E91D-DDD5-4478-BCA7-DA04435934C0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B38D6EDE-390B-4620-8365-29E16459EBDA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F20F11FD-203E-45A9-B7BB-AFC1B4FEA7A6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE178B09-C8AA-4734-804D-1849BCCA0C29}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{507591C2-2F4E-46A7-92D6-E6CFF82E5F26}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{538CD77C-BFDD-49B0-9562-77419CAB89D1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Google Chrome v [Unable to get version]

File : C:\Users\Ingeborg\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

File : C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [7025 octets] - [11/07/2012 08:45:14]
AdwCleaner[S1].txt - [7118 octets] - [11/07/2012 22:14:51]

########## EOF - C:\AdwCleaner[S1].txt - [7246 octets] ##########


cosinus 12.07.2012 10:11

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


KastorPollux 12.07.2012 13:01

Hallo Cosinus,
hier ist die neue logdatei von OTL.
OTL Logfile:
Code:

OTL logfile created on: 7/12/2012 1:30:50 PM - Run 2
OTL by OldTimer - Version 3.2.54.0    Folder = C:\Users\Hans\Desktop
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2.93 Gb Total Physical Memory | 1.96 Gb Available Physical Memory | 66.91% Memory free
5.86 Gb Paging File | 4.55 Gb Available in Paging File | 77.64% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 141.49 Gb Total Space | 76.45 Gb Free Space | 54.03% Space Free | Partition Type: NTFS
Drive D: | 58.86 Gb Total Space | 56.58 Gb Free Space | 96.12% Space Free | Partition Type: NTFS
Drive F: | 14.90 Gb Total Space | 14.75 Gb Free Space | 98.98% Space Free | Partition Type: FAT32
 
Computer Name: INGEBORG-PC | User Name: Hans | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/07/12 12:39:20 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Hans\Desktop\OTL.exe
PRC - [2012/06/28 12:27:34 | 000,096,792 | ---- | M] (Google Inc.) -- C:\Users\Hans\AppData\Local\Google\Chrome\Application\20.0.1132.47\chrome_frame_helper.exe
PRC - [2012/04/19 08:21:26 | 000,308,392 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\VirusScan\McVsShld.exe
PRC - [2012/03/21 21:16:10 | 001,318,816 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2012/03/20 13:11:32 | 000,151,880 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
PRC - [2012/03/20 13:05:00 | 000,161,632 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
PRC - [2012/03/20 13:04:32 | 000,166,288 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
PRC - [2012/01/18 08:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
PRC - [2012/01/03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/11/18 15:51:12 | 003,673,944 | ---- | M] () -- C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe
PRC - [2011/11/11 15:08:06 | 000,205,336 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2011/11/11 15:07:54 | 000,265,240 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
PRC - [2011/08/24 18:30:58 | 000,651,832 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
PRC - [2011/08/24 18:30:58 | 000,430,136 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
PRC - [2011/08/12 13:19:40 | 000,680,984 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
PRC - [2011/07/22 00:07:38 | 000,718,720 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
PRC - [2011/07/11 23:47:06 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe
PRC - [2011/04/25 03:24:16 | 000,726,976 | ---- | M] (Citrix Systems, Inc.) -- C:\Users\Hans\AppData\Local\Citrix\ICA Client\wfcrun32.exe
PRC - [2011/04/25 03:22:40 | 000,305,088 | ---- | M] (Citrix Systems, Inc.) -- C:\Users\Hans\AppData\Local\Citrix\ICA Client\concentr.exe
PRC - [2011/04/08 14:59:50 | 000,419,904 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MAT\McPvTray.exe
PRC - [2011/02/25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
PRC - [2011/01/02 21:29:50 | 000,009,216 | ---- | M] (www.shadowexplorer.com) -- C:\Program Files\ShadowExplorer\sesvc.exe
PRC - [2010/12/16 00:46:06 | 000,151,056 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\Core\mchost.exe
PRC - [2010/11/20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/04/13 21:11:14 | 000,229,688 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Online Backup\MOBKbackup.exe
PRC - [2010/01/19 11:34:48 | 002,201,192 | ---- | M] (SEC) -- C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
PRC - [2009/12/03 10:12:12 | 000,976,320 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\Event Manager\EEventManager.exe
PRC - [2009/09/14 07:00:00 | 000,153,600 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE
PRC - [2009/09/14 07:00:00 | 000,121,856 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
PRC - [2009/09/08 01:47:52 | 000,832,512 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2009/09/07 12:42:04 | 000,093,184 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
PRC - [2009/08/23 06:47:34 | 000,716,800 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2009/08/13 22:58:10 | 000,044,312 | ---- | M] () -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe
PRC - [2009/05/14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
PRC - [2008/01/16 10:51:44 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011/11/11 15:09:20 | 000,336,408 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll
MOD - [2011/11/11 15:07:54 | 000,265,240 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/12 13:19:40 | 000,680,984 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
MOD - [2011/08/12 13:18:56 | 000,342,552 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2011/08/12 13:18:56 | 000,128,536 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2011/08/12 13:18:56 | 000,029,208 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2011/08/12 13:18:54 | 007,956,504 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2011/08/12 13:18:54 | 002,145,304 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2011/03/17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2006/08/12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012/05/06 06:20:18 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/04/19 08:21:16 | 000,361,976 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2012/03/20 13:11:32 | 000,151,880 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe -- (mfevtp)
SRV - [2012/03/20 13:05:00 | 000,161,632 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV - [2012/03/20 13:04:32 | 000,166,288 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV - [2012/02/23 13:45:31 | 000,690,352 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) [Auto | Stopped] -- C:\Program Files\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe -- (StarMoney 8.0 OnlineUpdate)
SRV - [2012/01/18 08:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2012/01/03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/11/18 15:51:12 | 003,673,944 | ---- | M] () [Auto | Running] -- C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe -- (Radio.fx)
SRV - [2011/11/08 12:54:25 | 000,554,160 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) [Auto | Stopped] -- C:\Program Files\StarMoney 7.0\ouservice\StarMoneyOnlineUpdate.exe -- (StarMoney 7.0 OnlineUpdate)
SRV - [2011/08/24 18:30:58 | 000,430,136 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2011/07/01 11:34:50 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/06/12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (MSK80Service)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McProxy)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV - [2011/01/27 19:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV - [2011/01/02 21:29:50 | 000,009,216 | ---- | M] (www.shadowexplorer.com) [Auto | Running] -- C:\Program Files\ShadowExplorer\sesvc.exe -- (sesvc)
SRV - [2010/04/13 21:11:14 | 000,229,688 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee Online Backup\MOBKbackup.exe -- (MOBKbackup)
SRV - [2009/09/14 07:00:00 | 000,153,600 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE -- (EPSON_EB_RPCV4_04) EPSON V5 Service4(04)
SRV - [2009/09/14 07:00:00 | 000,121,856 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE -- (EPSON_PM_RPCV4_04) EPSON V3 Service4(04)
SRV - [2009/08/13 22:58:10 | 000,044,312 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe -- (OberonGameConsoleService)
SRV - [2009/07/14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/05/14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)
SRV - [2008/01/16 10:51:44 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
SRV - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (mfeavfk01)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_jubusenum.sys -- (huawei_enumerator)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2012/07/11 22:29:22 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2012/02/22 13:29:46 | 000,464,304 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2012/02/22 13:29:46 | 000,340,920 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2012/02/22 13:29:46 | 000,180,848 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2012/02/22 13:29:46 | 000,169,608 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2012/02/22 13:29:46 | 000,121,544 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2012/02/22 13:29:46 | 000,087,656 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2012/02/22 13:29:46 | 000,064,912 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk)
DRV - [2012/02/22 13:29:46 | 000,059,456 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2012/02/22 13:29:46 | 000,057,600 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cfwids.sys -- (cfwids)
DRV - [2012/01/18 08:44:52 | 004,332,960 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC) Logitech HD Webcam C525(UVC)
DRV - [2012/01/18 08:44:28 | 000,312,096 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS)
DRV - [2012/01/18 08:44:14 | 000,022,176 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvbusflt.sys -- (CompFilter)
DRV - [2011/04/25 02:49:16 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2011/04/11 15:29:16 | 000,064,048 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\McPvDrv.sys -- (McPvDrv)
DRV - [2010/11/20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/06/10 04:43:18 | 001,271,808 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2010/04/13 21:10:22 | 000,054,776 | ---- | M] (Mozy, Inc.) [File_System | System | Running] -- C:\Windows\System32\drivers\MOBK.sys -- (MOBKFilter)
DRV - [2009/07/14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope = {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1131658597-4005637612-88016806-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
IE - HKU\S-1-5-21-1131658597-4005637612-88016806-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-1131658597-4005637612-88016806-1008\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-1131658597-4005637612-88016806-1008\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-1131658597-4005637612-88016806-1008\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1131658597-4005637612-88016806-1008\..\SearchScopes\{1A4305F2-7B62-4EEE-A719-8CD1506DC37E}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-1131658597-4005637612-88016806-1008\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN
IE - HKU\S-1-5-21-1131658597-4005637612-88016806-1008\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SMSN_de
IE - HKU\S-1-5-21-1131658597-4005637612-88016806-1008\..\SearchScopes\{AA478EDB-37C2-468B-AD79-710F5B8E8EE6}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-1131658597-4005637612-88016806-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1131658597-4005637612-88016806-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledItems: {847b3a00-7ab1-11d4-8f02-006008948af5}:1.1.2
FF - prefs.js..extensions.enabledItems: msktbird@mcafee.com:1.0
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Hans\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Hans\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/07/12 05:53:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/07/12 12:43:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.20\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/03/24 21:35:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.20\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
 
[2010/12/05 18:47:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hans\AppData\Roaming\mozilla\Extensions
[2010/12/05 18:47:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hans\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/12/05 18:55:11 | 000,000,000 | ---D | M] (Enigmail) -- C:\USERS\HANS\APPDATA\ROAMING\THUNDERBIRD\PROFILES\WIH4NX1Z.DEFAULT\EXTENSIONS\{847B3A00-7AB1-11D4-8F02-006008948AF5}
[2011/08/03 23:10:34 | 000,000,000 | ---D | M] (McAfee Anti-Spam Thunderbird Extension) -- C:\USERS\HANS\APPDATA\ROAMING\THUNDERBIRD\PROFILES\WIH4NX1Z.DEFAULT\EXTENSIONS\MSKTBIRD@MCAFEE.COM
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google-Suche = C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: SiteAdvisor = C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\
CHR - Extension: Google Mail = C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
 
O1 HOSTS File: ([2009/06/10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120624094824.dll (McAfee, Inc.)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Users\Hans\AppData\Local\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [McPvTray_exe] C:\Program Files\McAfee\MAT\McPvTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-21-1131658597-4005637612-88016806-1008..\Run: [ChromeFrameHelper] C:\Users\Hans\AppData\Local\Google\Chrome\Application\20.0.1132.47\chrome_frame_helper.exe (Google Inc.)
O4 - HKU\S-1-5-21-1131658597-4005637612-88016806-1008..\Run: [Epson Stylus SX525WD(Netzwerk)] C:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIGAE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-1131658597-4005637612-88016806-1008..\Run: [EPSON SX525WD Series] C:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIGAE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-1131658597-4005637612-88016806-1008..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: An OneNote s&enden - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C08167AA-3C9D-4EE9-B072-3226732BC7F5}: DhcpNameServer = 78.42.43.62 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E366DA8A-EC55-4CAC-9A1B-0C76A4645162}: DhcpNameServer = 219.147.1.66 219.146.1.66
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011/08/04 18:13:52 | 000,000,110 | -H-- | M] () - F:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{8127cb97-a718-11e1-af93-001377ea838b}\Shell - "" = AutoRun
O33 - MountPoints2\{8127cb97-a718-11e1-af93-001377ea838b}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{8127cbb3-a718-11e1-af93-001377ea838b}\Shell - "" = AutoRun
O33 - MountPoints2\{8127cbb3-a718-11e1-af93-001377ea838b}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: mcmscsvc - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SafeBootMin: MCODS - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: McMPFSvc - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SafeBootNet: mcmscsvc - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SafeBootNet: MCODS - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SafeBootNet: Messenger - Service
SafeBootNet: mfefire - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SafeBootNet: mfefirek - C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
SafeBootNet: mfefirek.sys - C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
SafeBootNet: mfehidk - C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
SafeBootNet: mfehidk.sys - C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
SafeBootNet: mfevtp - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codec - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\windows\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\windows\System32\ir32_32.dll (Intel(R) Corporation)
Drivers32: vidc.iv32 - C:\windows\System32\ir32_32.dll (Intel(R) Corporation)
Drivers32: vidc.iv41 - C:\windows\System32\ir41_32.ax (Intel Corporation)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/07/12 12:42:54 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Hans\Desktop\OTL.exe
[2012/07/11 22:28:47 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2012/07/09 20:25:10 | 000,000,000 | ---D | C] -- C:\TEMP
[2012/07/09 20:01:01 | 000,000,000 | ---D | C] -- C:\Users\Hans\AppData\Roaming\JPEGsnoop
[2012/07/09 19:38:24 | 000,000,000 | ---D | C] -- C:\Users\Hans\AppData\Roaming\www.shadowexplorer.com
[2012/07/09 19:38:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShadowExplorer
[2012/07/09 19:38:06 | 000,000,000 | ---D | C] -- C:\Program Files\ShadowExplorer
[2012/07/08 08:23:28 | 000,000,000 | ---D | C] -- C:\Users\Hans\Documents\Trojaner
[2012/07/04 11:40:07 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/06/23 21:43:48 | 000,000,000 | ---D | C] -- C:\Users\Hans\AppData\Roaming\Malwarebytes
[2012/06/23 19:34:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/23 19:34:36 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2012/06/23 19:34:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/06/23 19:34:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/06/14 22:42:18 | 001,392,640 | ---- | C] (ImpulseAdventure) -- C:\Users\Hans\Desktop\JPEGsnoop.exe
 
========== Files - Modified Within 30 Days ==========
 
[2012/07/12 13:32:11 | 000,001,102 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/12 13:32:00 | 000,001,098 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/12 13:20:00 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/07/12 13:19:32 | 000,711,370 | ---- | M] () -- C:\windows\System32\perfh007.dat
[2012/07/12 13:19:32 | 000,662,950 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2012/07/12 13:19:32 | 000,153,766 | ---- | M] () -- C:\windows\System32\perfc007.dat
[2012/07/12 13:19:32 | 000,124,144 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2012/07/12 13:14:11 | 000,001,116 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1131658597-4005637612-88016806-1008UA.job
[2012/07/12 12:47:10 | 000,015,056 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/12 12:47:10 | 000,015,056 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/12 12:44:39 | 000,001,788 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2012/07/12 12:39:20 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Hans\Desktop\OTL.exe
[2012/07/12 12:38:54 | 000,065,536 | ---- | M] () -- C:\windows\System32\Ikeext.etl
[2012/07/12 12:38:42 | 000,435,160 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2012/07/12 12:38:33 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/07/12 12:37:24 | 2362,920,960 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/11 22:29:22 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2012/07/11 08:37:44 | 000,618,655 | ---- | M] () -- C:\Users\Hans\Desktop\adwcleaner.exe
[2012/07/10 21:55:29 | 000,003,108 | ---- | M] () -- C:\windows\MOBK.blk
[2012/07/10 21:55:29 | 000,002,010 | ---- | M] () -- C:\windows\MOBK.flt
[2012/07/09 20:34:20 | 001,392,640 | ---- | M] (ImpulseAdventure) -- C:\Users\Hans\Desktop\JPEGsnoop.exe
[2012/07/09 19:38:10 | 000,001,803 | ---- | M] () -- C:\Users\Hans\Desktop\ShadowExplorer.lnk
[2012/07/09 18:48:35 | 000,001,064 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1131658597-4005637612-88016806-1008Core.job
[2012/06/23 19:34:37 | 000,001,027 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
 
========== Files Created - No Company Name ==========
 
[2012/07/11 08:44:46 | 000,618,655 | ---- | C] () -- C:\Users\Hans\Desktop\adwcleaner.exe
[2012/07/09 19:38:10 | 000,001,803 | ---- | C] () -- C:\Users\Hans\Desktop\ShadowExplorer.lnk
[2012/06/23 19:34:37 | 000,001,027 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/25 08:54:55 | 000,007,597 | ---- | C] () -- C:\Users\Hans\AppData\Local\Resmon.ResmonCfg
[2012/01/18 08:44:00 | 010,920,984 | ---- | C] () -- C:\windows\System32\LogiDPP.dll
[2012/01/18 08:44:00 | 000,336,408 | ---- | C] () -- C:\windows\System32\DevManagerCore.dll
[2012/01/18 08:44:00 | 000,104,472 | ---- | C] () -- C:\windows\System32\LogiDPPApp.exe
[2011/12/27 21:41:04 | 000,000,345 | ---- | C] () -- C:\Users\Hans\AppData\Roaming\burnaware.ini
[2011/10/19 08:31:33 | 000,008,356 | ---- | C] () -- C:\Users\Hans\overlay.ini
[2011/10/19 08:31:33 | 000,000,000 | ---- | C] () -- C:\Users\Hans\vorlagen.ini
[2011/09/16 11:06:27 | 000,000,243 | ---- | C] () -- C:\Users\Hans\medcd.ini
[2011/08/12 13:20:14 | 000,015,896 | ---- | C] () -- C:\windows\System32\drivers\iKeyLFT2.dll
[2011/07/26 07:48:54 | 000,028,418 | ---- | C] () -- C:\windows\System32\lvcoinst.ini
[2011/06/28 09:50:15 | 000,000,000 | ---- | C] () -- C:\Users\Hans\AppData\Local\{A221B22A-93DD-4412-BE0A-08CEC5E0B6AC}
[2011/04/08 18:28:57 | 000,554,496 | ---- | C] () -- C:\windows\System32\dvmsg.dll
[2010/11/28 18:12:44 | 000,056,320 | ---- | C] () -- C:\windows\System32\iyvu9_32.dll
[2010/11/10 18:19:48 | 000,007,168 | ---- | C] () -- C:\Users\Hans\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/19 20:45:03 | 000,000,400 | ---- | C] () -- C:\windows\ODBC.INI
[2010/10/03 10:29:36 | 000,000,600 | ---- | C] () -- C:\Users\Hans\AppData\Roaming\winscp.rnd
[2010/08/25 20:30:02 | 000,439,308 | ---- | C] () -- C:\windows\System32\igcompkrng500.bin
[2010/08/25 20:30:00 | 000,982,240 | ---- | C] () -- C:\windows\System32\igkrng500.bin
[2010/08/25 20:30:00 | 000,092,356 | ---- | C] () -- C:\windows\System32\igfcg500m.bin
[2010/08/25 19:59:08 | 000,004,096 | ---- | C] ( ) -- C:\windows\System32\IGFXDEVLib.dll
[2009/12/26 08:39:38 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe
 
========== LOP Check ==========
 
[2011/06/05 22:29:44 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Amazon
[2011/08/14 18:33:45 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\EndNote
[2012/05/12 09:19:51 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Epson
[2011/10/08 17:24:02 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\gnupg
[2010/11/05 19:19:55 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\ICAClient
[2010/10/19 21:39:41 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\IrfanView
[2012/07/09 20:01:01 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\JPEGsnoop
[2010/11/05 19:13:07 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Juniper Networks
[2010/10/21 22:58:59 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\OpenOffice.org
[2010/10/21 22:32:24 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\SmartDraw
[2012/04/06 12:23:32 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\SmartTools
[2012/05/27 09:34:52 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\T-Mobile
[2012/05/29 09:09:42 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\T-Mobile Internet Manager
[2010/12/05 18:47:13 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Thunderbird
[2011/04/08 18:29:30 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Tobit
[2012/07/09 19:38:24 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\www.shadowexplorer.com
[2012/07/12 12:40:08 | 000,000,000 | R--D | M] -- C:\Users\Hans\AppData\Roaming\Xdtsrk
[2010/02/06 23:08:57 | 000,000,000 | -HSD | M] -- C:\Users\Ingeborg\AppData\Roaming\.#
[2012/07/09 19:03:25 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\EndNote
[2011/04/19 16:00:05 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\Epson
[2010/02/06 23:08:39 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\GameConsole
[2010/06/06 11:00:09 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\IrfanView
[2011/12/25 13:06:58 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\Leadertech
[2009/12/30 20:37:02 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\OpenOffice.org
[2010/12/23 23:13:52 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\Thunderbird
[2011/04/12 21:14:15 | 000,000,000 | ---D | M] -- C:\Users\Ingeborg\AppData\Roaming\Tobit
[2012/06/07 22:08:11 | 000,032,640 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011/08/14 09:48:41 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Adobe
[2011/06/05 22:29:44 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Amazon
[2011/10/12 18:43:55 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Apple Computer
[2011/08/14 18:33:45 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\EndNote
[2012/05/12 09:19:51 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Epson
[2011/10/08 17:24:02 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\gnupg
[2010/11/05 19:19:55 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\ICAClient
[2010/10/01 22:11:44 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Identities
[2011/04/18 19:51:03 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\InstallShield
[2010/10/19 21:39:41 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\IrfanView
[2012/07/09 20:01:01 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\JPEGsnoop
[2010/11/05 19:13:07 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Juniper Networks
[2010/10/01 23:06:31 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Macromedia
[2012/06/23 21:43:48 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Malwarebytes
[2009/09/18 01:16:15 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Media Center Programs
[2012/07/09 19:46:26 | 000,000,000 | --SD | M] -- C:\Users\Hans\AppData\Roaming\Microsoft
[2010/12/05 18:47:15 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Mozilla
[2010/10/21 22:58:59 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\OpenOffice.org
[2012/06/07 03:20:23 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Skype
[2010/10/21 22:32:24 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\SmartDraw
[2012/04/06 12:23:32 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\SmartTools
[2011/11/11 21:55:29 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Sony Corporation
[2012/05/27 09:34:52 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\T-Mobile
[2012/05/29 09:09:42 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\T-Mobile Internet Manager
[2010/12/05 18:47:13 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Thunderbird
[2011/04/08 18:29:30 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Tobit
[2011/12/25 18:07:02 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\Winamp
[2012/07/09 19:38:24 | 000,000,000 | ---D | M] -- C:\Users\Hans\AppData\Roaming\www.shadowexplorer.com
[2012/07/12 12:40:08 | 000,000,000 | R--D | M] -- C:\Users\Hans\AppData\Roaming\Xdtsrk
 
< %APPDATA%\*.exe /s >
[2012/06/10 18:45:52 | 000,253,000 | ---- | M] (Juniper Networks) -- C:\Users\Hans\AppData\Roaming\Juniper Networks\Java Secure Application Manager\jsamtool.exe
[2010/11/05 18:47:33 | 000,073,728 | R--- | M] () -- C:\Users\Hans\AppData\Roaming\Microsoft\Installer\{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}\ARPICON.exe
[2010/11/05 18:47:33 | 000,073,728 | R--- | M] () -- C:\Users\Hans\AppData\Roaming\Microsoft\Installer\{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}\liteico.exe.827545C6_7013_4DE1_8E6C_DAEE4C57F54A.exe
[2010/01/07 14:35:18 | 001,007,616 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Users\Hans\AppData\Roaming\T-Mobile Internet Manager\LiveUpdate.exe
[2009/12/31 14:13:52 | 000,110,592 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Users\Hans\AppData\Roaming\T-Mobile Internet Manager\ouc.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009/07/14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009/07/14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009/07/14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
[2009/07/14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009/07/14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009/07/14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009/07/14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
[2009/07/14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009/07/14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009/07/14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2009/06/04 11:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2009/06/04 11:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2009/06/04 11:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\drivers\iaStor.sys
[2009/06/04 11:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_4f144d6467fc7c22\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2011/03/11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\drivers\iaStorV.sys
[2011/03/11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys
[2011/03/11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011/03/11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys
[2011/03/11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2009/07/14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
[2010/11/20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010/11/20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
[2011/03/11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010/11/20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll
[2010/11/20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
[2009/07/14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011/03/11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\drivers\nvstor.sys
[2011/03/11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/03/11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011/03/11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys
[2011/03/11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2011/03/11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys
[2010/11/20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
[2009/07/14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009/07/14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
[2010/11/20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll
[2010/11/20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009/07/14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
[2010/11/20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll
[2010/11/20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010/11/20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010/11/20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009/07/14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009/07/14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012/04/04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010/11/20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009/07/14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009/07/14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2009/07/14 03:15:21 | 000,462,848 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\windows\system32\FirewallAPI.dll
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:A42A9F39

< End of report >

--- --- ---

cosinus 12.07.2012 14:54

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
FF - user.js - File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E366DA8A-EC55-4CAC-9A1B-0C76A4645162}: DhcpNameServer = 219.147.1.66 219.146.1.66
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011/08/04 18:13:52 | 000,000,110 | -H-- | M] () - F:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{8127cb97-a718-11e1-af93-001377ea838b}\Shell - "" = AutoRun
O33 - MountPoints2\{8127cb97-a718-11e1-af93-001377ea838b}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{8127cbb3-a718-11e1-af93-001377ea838b}\Shell - "" = AutoRun
O33 - MountPoints2\{8127cbb3-a718-11e1-af93-001377ea838b}\Shell\AutoRun\command - "" = F:\AutoRun.exe
[2012/07/10 21:55:29 | 000,003,108 | ---- | M] () -- C:\windows\MOBK.blk
[2012/07/10 21:55:29 | 000,002,010 | ---- | M] () -- C:\windows\MOBK.flt
[2009/12/26 08:39:38 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe
[2010/02/06 23:08:57 | 000,000,000 | -HSD | M] -- C:\Users\Ingeborg\AppData\Roaming\.#
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:A42A9F39
:Files
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

KastorPollux 12.07.2012 17:52

Hier ist der Logfile vom fixen:
Code:

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E366DA8A-EC55-4CAC-9A1B-0C76A4645162}\\DhcpNameServer| /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
F:\autorun.inf moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8127cb97-a718-11e1-af93-001377ea838b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8127cb97-a718-11e1-af93-001377ea838b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8127cb97-a718-11e1-af93-001377ea838b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8127cb97-a718-11e1-af93-001377ea838b}\ not found.
File F:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8127cbb3-a718-11e1-af93-001377ea838b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8127cbb3-a718-11e1-af93-001377ea838b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8127cbb3-a718-11e1-af93-001377ea838b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8127cbb3-a718-11e1-af93-001377ea838b}\ not found.
File F:\AutoRun.exe not found.
C:\Windows\MOBK.blk moved successfully.
C:\Windows\MOBK.flt moved successfully.
C:\ProgramData\FullRemove.exe moved successfully.
C:\Users\Ingeborg\AppData\Roaming\.# folder moved successfully.
ADS C:\ProgramData\TEMP:A42A9F39 deleted successfully.
========== FILES ==========
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\Hans\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\Ingeborg\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Hans
->Temp folder emptied: 1665483030 bytes
->Temporary Internet Files folder emptied: 492152142 bytes
->Google Chrome cache emptied: 337955098 bytes
->Flash cache emptied: 586 bytes
 
User: Ingeborg
->Temp folder emptied: 446678670 bytes
->Temporary Internet Files folder emptied: 774034956 bytes
->Google Chrome cache emptied: 353623964 bytes
->Flash cache emptied: 39502 bytes
 
User: Public
 
User: Temp
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 735333219 bytes
RecycleBin emptied: 2599095462 bytes
 
Total Files Cleaned = 7,061.00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
 
User: Default User
 
User: Hans
->Flash cache emptied: 0 bytes
 
User: Ingeborg
->Flash cache emptied: 0 bytes
 
User: Public
 
User: Temp
 
Total Flash Files Cleaned = 0.00 mb
 
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.54.0 log created on 07122012_182241

Files\Folders moved on Reboot...
File\Folder C:\Users\Hans\AppData\Local\Temp\OICE_132624AC-E61B-42D8-90C9-02B38ED5BB6C.0\41E3AF72. not found!

PendingFileRenameOperations files...
File C:\Users\Hans\AppData\Local\Temp\OICE_132624AC-E61B-42D8-90C9-02B38ED5BB6C.0\41E3AF72. not found!

Registry entries deleted on Reboot...

Wie geht es weiter? Kann ich auf das Neuaufsetzen des Systems verzichten? In den Diskussionen im Trojanerboard lese ich immer wieder, dass Neuaufsetzen nicht zu umgehen ist.
Vielen Dank für die Hilfe
Hans

cosinus 12.07.2012 19:30

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

KastorPollux 13.07.2012 08:10

Hallo Cosinus,
hier das TDSS Log:
Code:

08:23:34.0412 4852        TDSS rootkit removing tool 2.7.45.0 Jul  9 2012 12:46:35
08:23:34.0475 4852        ============================================================
08:23:34.0475 4852        Current date / time: 2012/07/13 08:23:34.0475
08:23:34.0475 4852        SystemInfo:
08:23:34.0475 4852       
08:23:34.0475 4852        OS Version: 6.1.7601 ServicePack: 1.0
08:23:34.0475 4852        Product type: Workstation
08:23:34.0475 4852        ComputerName: INGEBORG-PC
08:23:34.0475 4852        UserName: Hans
08:23:34.0475 4852        Windows directory: C:\windows
08:23:34.0475 4852        System windows directory: C:\windows
08:23:34.0475 4852        Processor architecture: Intel x86
08:23:34.0475 4852        Number of processors: 2
08:23:34.0475 4852        Page size: 0x1000
08:23:34.0475 4852        Boot type: Normal boot
08:23:34.0475 4852        ============================================================
08:23:36.0128 4852        Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
08:23:36.0128 4852        Drive \Device\Harddisk1\DR1 - Size: 0x3BA300000 (14.91 Gb), SectorSize: 0x200, Cylinders: 0x79A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
08:23:36.0128 4852        ============================================================
08:23:36.0128 4852        \Device\Harddisk0\DR0:
08:23:36.0128 4852        MBR partitions:
08:23:36.0128 4852        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1E00800, BlocksNum 0x32000
08:23:36.0128 4852        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1E32800, BlocksNum 0x11AFD000
08:23:36.0128 4852        \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1392F800, BlocksNum 0x75BA000
08:23:36.0128 4852        \Device\Harddisk1\DR1:
08:23:36.0128 4852        MBR partitions:
08:23:36.0128 4852        \Device\Harddisk1\DR1\Partition0: MBR, Type 0xC, StartLBA 0x20, BlocksNum 0x1DD17E0
08:23:36.0128 4852        ============================================================
08:23:36.0159 4852        C: <-> \Device\Harddisk0\DR0\Partition1
08:23:36.0206 4852        D: <-> \Device\Harddisk0\DR0\Partition2
08:23:36.0206 4852        ============================================================
08:23:36.0206 4852        Initialize success
08:23:36.0206 4852        ============================================================
08:24:12.0172 5120        ============================================================
08:24:12.0172 5120        Scan started
08:24:12.0172 5120        Mode: Manual; SigCheck; TDLFS;
08:24:12.0172 5120        ============================================================
08:24:12.0921 5120        1394ohci        (1b133875b8aa8ac48969bd3458afe9f5) C:\windows\system32\drivers\1394ohci.sys
08:24:13.0108 5120        1394ohci - ok
08:24:13.0280 5120        ABBYY.Licensing.FineReader.Sprint.9.0 (b33cf4de909a5b30f526d82053a63c8e) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
08:24:13.0342 5120        ABBYY.Licensing.FineReader.Sprint.9.0 - ok
08:24:13.0404 5120        ACPI            (cea80c80bed809aa0da6febc04733349) C:\windows\system32\drivers\ACPI.sys
08:24:13.0451 5120        ACPI - ok
08:24:13.0514 5120        AcpiPmi        (1efbc664abff416d1d07db115dcb264f) C:\windows\system32\drivers\acpipmi.sys
08:24:13.0607 5120        AcpiPmi - ok
08:24:13.0779 5120        AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
08:24:13.0810 5120        AdobeARMservice - ok
08:24:13.0904 5120        AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
08:24:13.0935 5120        AdobeFlashPlayerUpdateSvc - ok
08:24:14.0044 5120        adp94xx        (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys
08:24:14.0091 5120        adp94xx - ok
08:24:14.0122 5120        adpahci        (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys
08:24:14.0184 5120        adpahci - ok
08:24:14.0231 5120        adpu320        (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys
08:24:14.0262 5120        adpu320 - ok
08:24:14.0294 5120        AeLookupSvc    (8b5eefeec1e6d1a72a06c526628ad161) C:\windows\System32\aelupsvc.dll
08:24:14.0387 5120        AeLookupSvc - ok
08:24:14.0496 5120        AFD            (9ebbba55060f786f0fcaa3893bfa2806) C:\windows\system32\drivers\afd.sys
08:24:14.0574 5120        AFD - ok
08:24:14.0606 5120        agp440          (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\drivers\agp440.sys
08:24:14.0637 5120        agp440 - ok
08:24:14.0746 5120        aic78xx        (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys
08:24:14.0777 5120        aic78xx - ok
08:24:14.0824 5120        ALG            (18a54e132947cd98fea9accc57f98f13) C:\windows\System32\alg.exe
08:24:14.0902 5120        ALG - ok
08:24:14.0933 5120        aliide          (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\drivers\aliide.sys
08:24:14.0964 5120        aliide - ok
08:24:14.0980 5120        amdagp          (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\drivers\amdagp.sys
08:24:15.0011 5120        amdagp - ok
08:24:15.0042 5120        amdide          (cd5914170297126b6266860198d1d4f0) C:\windows\system32\drivers\amdide.sys
08:24:15.0074 5120        amdide - ok
08:24:15.0105 5120        AmdK8          (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys
08:24:15.0167 5120        AmdK8 - ok
08:24:15.0183 5120        AmdPPM          (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys
08:24:15.0230 5120        AmdPPM - ok
08:24:15.0292 5120        amdsata        (d320bf87125326f996d4904fe24300fc) C:\windows\system32\drivers\amdsata.sys
08:24:15.0323 5120        amdsata - ok
08:24:15.0370 5120        amdsbs          (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys
08:24:15.0417 5120        amdsbs - ok
08:24:15.0417 5120        amdxata        (46387fb17b086d16dea267d5be23a2f2) C:\windows\system32\drivers\amdxata.sys
08:24:15.0448 5120        amdxata - ok
08:24:15.0495 5120        AppID          (aea177f783e20150ace5383ee368da19) C:\windows\system32\drivers\appid.sys
08:24:15.0620 5120        AppID - ok
08:24:15.0713 5120        AppIDSvc        (62a9c86cb6085e20db4823e4e97826f5) C:\windows\System32\appidsvc.dll
08:24:15.0776 5120        AppIDSvc - ok
08:24:15.0822 5120        Appinfo        (fb1959012294d6ad43e5304df65e3c26) C:\windows\System32\appinfo.dll
08:24:15.0885 5120        Appinfo - ok
08:24:16.0010 5120        Apple Mobile Device (d8e18021f91ad79ca8491cb5a5da22d4) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
08:24:16.0025 5120        Apple Mobile Device - ok
08:24:16.0072 5120        arc            (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys
08:24:16.0119 5120        arc - ok
08:24:16.0134 5120        arcsas          (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys
08:24:16.0166 5120        arcsas - ok
08:24:16.0212 5120        AsyncMac        (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys
08:24:16.0337 5120        AsyncMac - ok
08:24:16.0368 5120        atapi          (338c86357871c167a96ab976519bf59e) C:\windows\system32\drivers\atapi.sys
08:24:16.0400 5120        atapi - ok
08:24:16.0540 5120        athr            (8efa8e1c4c5eea27951a8dd015ffe4cd) C:\windows\system32\DRIVERS\athr.sys
08:24:16.0665 5120        athr - ok
08:24:16.0868 5120        AudioEndpointBuilder (ce3b4e731638d2ef62fcb419be0d39f0) C:\windows\System32\Audiosrv.dll
08:24:16.0930 5120        AudioEndpointBuilder - ok
08:24:16.0946 5120        Audiosrv        (ce3b4e731638d2ef62fcb419be0d39f0) C:\windows\System32\Audiosrv.dll
08:24:17.0008 5120        Audiosrv - ok
08:24:17.0102 5120        AxInstSV        (6e30d02aac9cac84f421622e3a2f6178) C:\windows\System32\AxInstSV.dll
08:24:17.0195 5120        AxInstSV - ok
08:24:17.0273 5120        b06bdrv        (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys
08:24:17.0336 5120        b06bdrv - ok
08:24:17.0382 5120        b57nd60x        (bd8869eb9cde6bbe4508d869929869ee) C:\windows\system32\DRIVERS\b57nd60x.sys
08:24:17.0429 5120        b57nd60x - ok
08:24:17.0538 5120        BcmSqlStartupSvc (6163664c7e9cd110af70180c126c3fdc) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
08:24:17.0570 5120        BcmSqlStartupSvc - ok
08:24:17.0616 5120        BDESVC          (ee1e9c3bb8228ae423dd38db69128e71) C:\windows\System32\bdesvc.dll
08:24:17.0679 5120        BDESVC - ok
08:24:17.0710 5120        Beep            (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys
08:24:17.0788 5120        Beep - ok
08:24:17.0866 5120        BFE            (1e2bac209d184bb851e1a187d8a29136) C:\windows\System32\bfe.dll
08:24:17.0960 5120        BFE - ok
08:24:18.0022 5120        BITS            (e585445d5021971fae10393f0f1c3961) C:\windows\System32\qmgr.dll
08:24:18.0116 5120        BITS - ok
08:24:18.0131 5120        blbdrive        (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys
08:24:18.0178 5120        blbdrive - ok
08:24:18.0303 5120        Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe
08:24:18.0350 5120        Bonjour Service - ok
08:24:18.0396 5120        bowser          (8f2da3028d5fcbd1a060a3de64cd6506) C:\windows\system32\DRIVERS\bowser.sys
08:24:18.0459 5120        bowser - ok
08:24:18.0474 5120        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys
08:24:18.0552 5120        BrFiltLo - ok
08:24:18.0568 5120        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys
08:24:18.0630 5120        BrFiltUp - ok
08:24:18.0677 5120        Browser        (6e11f33d14d020f58d5e02e4d67dfa19) C:\windows\System32\browser.dll
08:24:18.0771 5120        Browser - ok
08:24:18.0818 5120        Brserid        (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys
08:24:18.0896 5120        Brserid - ok
08:24:18.0927 5120        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys
08:24:18.0958 5120        BrSerWdm - ok
08:24:18.0974 5120        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys
08:24:19.0005 5120        BrUsbMdm - ok
08:24:19.0036 5120        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys
08:24:19.0083 5120        BrUsbSer - ok
08:24:19.0098 5120        BTHMODEM        (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys
08:24:19.0145 5120        BTHMODEM - ok
08:24:19.0176 5120        bthserv        (1df19c96eef6c29d1c3e1a8678e07190) C:\windows\system32\bthserv.dll
08:24:19.0254 5120        bthserv - ok
08:24:19.0286 5120        cdfs            (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys
08:24:19.0364 5120        cdfs - ok
08:24:19.0426 5120        cdrom          (be167ed0fdb9c1fa1133953c18d5a6c9) C:\windows\system32\DRIVERS\cdrom.sys
08:24:19.0473 5120        cdrom - ok
08:24:19.0520 5120        CertPropSvc    (319c6b309773d063541d01df8ac6f55f) C:\windows\System32\certprop.dll
08:24:19.0582 5120        CertPropSvc - ok
08:24:19.0676 5120        cfwids          (1c7b1e36f3ced9e4b0b13385e627fe8b) C:\windows\system32\drivers\cfwids.sys
08:24:19.0722 5120        cfwids - ok
08:24:19.0769 5120        circlass        (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys
08:24:19.0800 5120        circlass - ok
08:24:19.0847 5120        CLFS            (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys
08:24:19.0878 5120        CLFS - ok
08:24:19.0972 5120        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
08:24:20.0003 5120        clr_optimization_v2.0.50727_32 - ok
08:24:20.0081 5120        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
08:24:20.0159 5120        clr_optimization_v4.0.30319_32 - ok
08:24:20.0190 5120        CmBatt          (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys
08:24:20.0237 5120        CmBatt - ok
08:24:20.0284 5120        cmdide          (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\drivers\cmdide.sys
08:24:20.0315 5120        cmdide - ok
08:24:20.0362 5120        CNG            (247b4ce2dab1160cd422d532d5241e1f) C:\windows\system32\Drivers\cng.sys
08:24:20.0424 5120        CNG - ok
08:24:20.0456 5120        Compbatt        (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys
08:24:20.0487 5120        Compbatt - ok
08:24:20.0534 5120        CompFilter      (9704b9c442e3ef2989746d08f80a3743) C:\windows\system32\DRIVERS\lvbusflt.sys
08:24:20.0565 5120        CompFilter - ok
08:24:20.0596 5120        CompositeBus    (cbe8c58a8579cfe5fccf809e6f114e89) C:\windows\system32\drivers\CompositeBus.sys
08:24:20.0643 5120        CompositeBus - ok
08:24:20.0705 5120        COMSysApp - ok
08:24:20.0721 5120        crcdisk        (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys
08:24:20.0752 5120        crcdisk - ok
08:24:20.0814 5120        CryptSvc        (06e771aa596b8761107ab57e99f128d7) C:\windows\system32\cryptsvc.dll
08:24:20.0877 5120        CryptSvc - ok
08:24:20.0955 5120        ctxusbm        (cb6ff7012bb5d59d7c12350db795ce1f) C:\windows\system32\DRIVERS\ctxusbm.sys
08:24:20.0970 5120        ctxusbm - ok
08:24:21.0048 5120        DcomLaunch      (7660f01d3b38aca1747e397d21d790af) C:\windows\system32\rpcss.dll
08:24:21.0111 5120        DcomLaunch - ok
08:24:21.0158 5120        defragsvc      (8d6e10a2d9a5eed59562d9b82cf804e1) C:\windows\System32\defragsvc.dll
08:24:21.0236 5120        defragsvc - ok
08:24:21.0298 5120        DfsC            (f024449c97ec1e464aaffda18593db88) C:\windows\system32\Drivers\dfsc.sys
08:24:21.0376 5120        DfsC - ok
08:24:21.0438 5120        Dhcp            (e9e01eb683c132f7fa27cd607b8a2b63) C:\windows\system32\dhcpcore.dll
08:24:21.0516 5120        Dhcp - ok
08:24:21.0532 5120        discache        (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys
08:24:21.0610 5120        discache - ok
08:24:21.0657 5120        Disk            (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys
08:24:21.0672 5120        Disk - ok
08:24:21.0735 5120        Dnscache        (33ef4861f19a0736b11314aad9ae28d0) C:\windows\System32\dnsrslvr.dll
08:24:21.0797 5120        Dnscache - ok
08:24:21.0860 5120        dot3svc        (366ba8fb4b7bb7435e3b9eacb3843f67) C:\windows\System32\dot3svc.dll
08:24:21.0922 5120        dot3svc - ok
08:24:21.0969 5120        DPS            (8ec04ca86f1d68da9e11952eb85973d6) C:\windows\system32\dps.dll
08:24:22.0062 5120        DPS - ok
08:24:22.0125 5120        drmkaud        (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys
08:24:22.0187 5120        drmkaud - ok
08:24:22.0265 5120        DXGKrnl        (23f5d28378a160352ba8f817bd8c71cb) C:\windows\System32\drivers\dxgkrnl.sys
08:24:22.0312 5120        DXGKrnl - ok
08:24:22.0343 5120        EapHost        (8600142fa91c1b96367d3300ad0f3f3a) C:\windows\System32\eapsvc.dll
08:24:22.0406 5120        EapHost - ok
08:24:22.0655 5120        ebdrv          (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys
08:24:22.0811 5120        ebdrv - ok
08:24:22.0952 5120        EFS            (81951f51e318aecc2d68559e47485cc4) C:\windows\System32\lsass.exe
08:24:22.0998 5120        EFS - ok
08:24:23.0092 5120        ehRecvr        (a8c362018efc87beb013ee28f29c0863) C:\windows\ehome\ehRecvr.exe
08:24:23.0154 5120        ehRecvr - ok
08:24:23.0201 5120        ehSched        (d389bff34f80caede417bf9d1507996a) C:\windows\ehome\ehsched.exe
08:24:23.0264 5120        ehSched - ok
08:24:23.0357 5120        elxstor        (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys
08:24:23.0404 5120        elxstor - ok
08:24:23.0513 5120        EpsonBidirectionalService (abdd5ad016affd34ad40e944ce94bf59) C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
08:24:23.0544 5120        EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - warning
08:24:23.0544 5120        EpsonBidirectionalService - detected UnsignedFile.Multi.Generic (1)
08:24:23.0607 5120        EPSON_EB_RPCV4_04 (b92f2b3247f0a99490c1298a1d3d7b4c) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE
08:24:23.0716 5120        EPSON_EB_RPCV4_04 - ok
08:24:23.0763 5120        EPSON_PM_RPCV4_04 (651336b99c75fb54e4b5971cf458f9bd) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
08:24:23.0810 5120        EPSON_PM_RPCV4_04 - ok
08:24:23.0856 5120        ErrDev          (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\drivers\errdev.sys
08:24:23.0903 5120        ErrDev - ok
08:24:23.0966 5120        EventSystem    (f6916efc29d9953d5d0df06882ae8e16) C:\windows\system32\es.dll
08:24:24.0028 5120        EventSystem - ok
08:24:24.0059 5120        ew_hwusbdev - ok
08:24:24.0090 5120        exfat          (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys
08:24:24.0168 5120        exfat - ok
08:24:24.0200 5120        fastfat        (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys
08:24:24.0278 5120        fastfat - ok
08:24:24.0340 5120        Fax            (967ea5b213e9984cbe270205df37755b) C:\windows\system32\fxssvc.exe
08:24:24.0418 5120        Fax - ok
08:24:24.0434 5120        fdc            (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys
08:24:24.0465 5120        fdc - ok
08:24:24.0496 5120        fdPHost        (f3222c893bd2f5821a0179e5c71e88fb) C:\windows\system32\fdPHost.dll
08:24:24.0574 5120        fdPHost - ok
08:24:24.0590 5120        FDResPub        (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\windows\system32\fdrespub.dll
08:24:24.0652 5120        FDResPub - ok
08:24:24.0683 5120        FileInfo        (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys
08:24:24.0714 5120        FileInfo - ok
08:24:24.0730 5120        Filetrace      (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys
08:24:24.0808 5120        Filetrace - ok
08:24:24.0824 5120        flpydisk        (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys
08:24:24.0855 5120        flpydisk - ok
08:24:24.0902 5120        FltMgr          (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys
08:24:24.0933 5120        FltMgr - ok
08:24:25.0042 5120        FontCache      (b3a5ec6b6b6673db7e87c2bcdbddc074) C:\windows\system32\FntCache.dll
08:24:25.0120 5120        FontCache - ok
08:24:25.0182 5120        FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
08:24:25.0198 5120        FontCache3.0.0.0 - ok
08:24:25.0229 5120        FsDepends      (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys
08:24:25.0260 5120        FsDepends - ok
08:24:25.0292 5120        fssfltr        (b74b0578fd1d3f897e95f2a2b69ea051) C:\windows\system32\DRIVERS\fssfltr.sys
08:24:25.0323 5120        fssfltr - ok
08:24:25.0416 5120        fsssvc          (206ad9a89bf05dfa1621f1fc7b82592d) C:\Program Files\Windows Live\Family Safety\fsssvc.exe
08:24:25.0479 5120        fsssvc - ok
08:24:25.0510 5120        Fs_Rec          (7dae5ebcc80e45d3253f4923dc424d05) C:\windows\system32\drivers\Fs_Rec.sys
08:24:25.0541 5120        Fs_Rec - ok
08:24:25.0604 5120        fvevol          (8a73e79089b282100b9393b644cb853b) C:\windows\system32\DRIVERS\fvevol.sys
08:24:25.0635 5120        fvevol - ok
08:24:25.0713 5120        gagp30kx        (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys
08:24:25.0744 5120        gagp30kx - ok
08:24:25.0791 5120        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\windows\system32\DRIVERS\GEARAspiWDM.sys
08:24:25.0806 5120        GEARAspiWDM - ok
08:24:25.0884 5120        gpsvc          (e897eaf5ed6ba41e081060c9b447a673) C:\windows\System32\gpsvc.dll
08:24:25.0962 5120        gpsvc - ok
08:24:26.0056 5120        gupdate        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
08:24:26.0103 5120        gupdate - ok
08:24:26.0118 5120        gupdatem        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
08:24:26.0150 5120        gupdatem - ok
08:24:26.0228 5120        gusvc          (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
08:24:26.0259 5120        gusvc - ok
08:24:26.0274 5120        hcw85cir        (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys
08:24:26.0352 5120        hcw85cir - ok
08:24:26.0415 5120        HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\windows\system32\drivers\HdAudio.sys
08:24:26.0493 5120        HdAudAddService - ok
08:24:26.0540 5120        HDAudBus        (9036377b8a6c15dc2eec53e489d159b5) C:\windows\system32\drivers\HDAudBus.sys
08:24:26.0586 5120        HDAudBus - ok
08:24:26.0602 5120        HidBatt        (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys
08:24:26.0649 5120        HidBatt - ok
08:24:26.0727 5120        HidBth          (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys
08:24:26.0774 5120        HidBth - ok
08:24:26.0805 5120        HidIr          (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys
08:24:26.0836 5120        HidIr - ok
08:24:26.0883 5120        hidserv        (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\windows\system32\hidserv.dll
08:24:26.0945 5120        hidserv - ok
08:24:27.0008 5120        HidUsb          (10c19f8290891af023eaec0832e1eb4d) C:\windows\system32\drivers\hidusb.sys
08:24:27.0054 5120        HidUsb - ok
08:24:27.0086 5120        hkmsvc          (196b4e3f4cccc24af836ce58facbb699) C:\windows\system32\kmsvc.dll
08:24:27.0179 5120        hkmsvc - ok
08:24:27.0226 5120        HomeGroupListener (6658f4404de03d75fe3ba09f7aba6a30) C:\windows\system32\ListSvc.dll
08:24:27.0288 5120        HomeGroupListener - ok
08:24:27.0335 5120        HomeGroupProvider (dbc02d918fff1cad628acbe0c0eaa8e8) C:\windows\system32\provsvc.dll
08:24:27.0382 5120        HomeGroupProvider - ok
08:24:27.0429 5120        HpSAMD          (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\drivers\HpSAMD.sys
08:24:27.0460 5120        HpSAMD - ok
08:24:27.0522 5120        HTTP            (871917b07a141bff43d76d8844d48106) C:\windows\system32\drivers\HTTP.sys
08:24:27.0600 5120        HTTP - ok
08:24:27.0616 5120        huawei_cdcacm - ok
08:24:27.0632 5120        huawei_enumerator - ok
08:24:27.0678 5120        hwpolicy        (0c4e035c7f105f1299258c90886c64c5) C:\windows\system32\drivers\hwpolicy.sys
08:24:27.0710 5120        hwpolicy - ok
08:24:27.0756 5120        i8042prt        (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\drivers\i8042prt.sys
08:24:27.0803 5120        i8042prt - ok
08:24:27.0866 5120        iaStor          (d483687eace0c065ee772481a96e05f5) C:\windows\system32\DRIVERS\iaStor.sys
08:24:27.0897 5120        iaStor - ok
08:24:27.0975 5120        iaStorV        (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\windows\system32\drivers\iaStorV.sys
08:24:28.0022 5120        iaStorV - ok
08:24:28.0146 5120        idsvc          (c521d7eb6497bb1af6afa89e322fb43c) C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
08:24:28.0209 5120        idsvc - ok
08:24:28.0973 5120        igfx            (8266ae06df974e5ba047b3e9e9e70b3f) C:\windows\system32\DRIVERS\igdkmd32.sys
08:24:29.0363 5120        igfx - ok
08:24:29.0550 5120        iirsp          (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys
08:24:29.0582 5120        iirsp - ok
08:24:29.0738 5120        IKEEXT          (f95622f161474511b8d80d6b093aa610) C:\windows\System32\ikeext.dll
08:24:29.0831 5120        IKEEXT - ok
08:24:30.0112 5120        IntcAzAudAddService (db96b8bd676bb24bd4f1dc53ca1f182c) C:\windows\system32\drivers\RTKVHDA.sys
08:24:30.0206 5120        IntcAzAudAddService - ok
08:24:30.0346 5120        intelide        (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\drivers\intelide.sys
08:24:30.0377 5120        intelide - ok
08:24:30.0424 5120        intelppm        (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys
08:24:30.0455 5120        intelppm - ok
08:24:30.0486 5120        IPBusEnum      (acb364b9075a45c0736e5c47be5cae19) C:\windows\system32\ipbusenum.dll
08:24:30.0564 5120        IPBusEnum - ok
08:24:30.0580 5120        IpFilterDriver  (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys
08:24:30.0642 5120        IpFilterDriver - ok
08:24:30.0767 5120        iphlpsvc        (4d65a07b795d6674312f879d09aa7663) C:\windows\System32\iphlpsvc.dll
08:24:30.0845 5120        iphlpsvc - ok
08:24:30.0876 5120        IPMIDRV        (4bd7134618c1d2a27466a099062547bf) C:\windows\system32\drivers\IPMIDrv.sys
08:24:30.0923 5120        IPMIDRV - ok
08:24:30.0939 5120        IPNAT          (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys
08:24:31.0001 5120        IPNAT - ok
08:24:31.0126 5120        iPod Service    (33642c17c232aa272c68e446a2619899) C:\Program Files\iPod\bin\iPodService.exe
08:24:31.0157 5120        iPod Service - ok
08:24:31.0204 5120        IRENUM          (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys
08:24:31.0282 5120        IRENUM - ok
08:24:31.0313 5120        isapnp          (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\drivers\isapnp.sys
08:24:31.0344 5120        isapnp - ok
08:24:31.0391 5120        iScsiPrt        (cb7a9abb12b8415bce5d74994c7ba3ae) C:\windows\system32\drivers\msiscsi.sys
08:24:31.0438 5120        iScsiPrt - ok
08:24:31.0469 5120        kbdclass        (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\drivers\kbdclass.sys
08:24:31.0500 5120        kbdclass - ok
08:24:31.0547 5120        kbdhid          (9e3ced91863e6ee98c24794d05e27a71) C:\windows\system32\drivers\kbdhid.sys
08:24:31.0594 5120        kbdhid - ok
08:24:31.0641 5120        KeyIso          (81951f51e318aecc2d68559e47485cc4) C:\windows\system32\lsass.exe
08:24:31.0672 5120        KeyIso - ok
08:24:31.0719 5120        KSecDD          (b7895b4182c0d16f6efadeb8081e8d36) C:\windows\system32\Drivers\ksecdd.sys
08:24:31.0750 5120        KSecDD - ok
08:24:31.0781 5120        KSecPkg        (d30159ac9237519fbc62c6ec247d2d46) C:\windows\system32\Drivers\ksecpkg.sys
08:24:31.0828 5120        KSecPkg - ok
08:24:31.0875 5120        KtmRm          (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\windows\system32\msdtckrm.dll
08:24:31.0968 5120        KtmRm - ok
08:24:32.0031 5120        LanmanServer    (d64af876d53eca3668bb97b51b4e70ab) C:\windows\system32\srvsvc.dll
08:24:32.0109 5120        LanmanServer - ok
08:24:32.0140 5120        LanmanWorkstation (58405e4f68ba8e4057c6e914f326aba2) C:\windows\System32\wkssvc.dll
08:24:32.0249 5120        LanmanWorkstation - ok
08:24:32.0280 5120        lltdio          (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys
08:24:32.0358 5120        lltdio - ok
08:24:32.0405 5120        lltdsvc        (5700673e13a2117fa3b9020c852c01e2) C:\windows\System32\lltdsvc.dll
08:24:32.0483 5120        lltdsvc - ok
08:24:32.0499 5120        lmhosts        (55ca01ba19d0006c8f2639b6c045e08b) C:\windows\System32\lmhsvc.dll
08:24:32.0561 5120        lmhosts - ok
08:24:32.0608 5120        LSI_FC          (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys
08:24:32.0639 5120        LSI_FC - ok
08:24:32.0702 5120        LSI_SAS        (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys
08:24:32.0733 5120        LSI_SAS - ok
08:24:32.0764 5120        LSI_SAS2        (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys
08:24:32.0795 5120        LSI_SAS2 - ok
08:24:32.0811 5120        LSI_SCSI        (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys
08:24:32.0842 5120        LSI_SCSI - ok
08:24:32.0873 5120        luafv          (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys
08:24:32.0951 5120        luafv - ok
08:24:33.0014 5120        LVRS            (ed643e777ba3f7151ef3f0fb6be4f7f0) C:\windows\system32\DRIVERS\lvrs.sys
08:24:33.0076 5120        LVRS - ok
08:24:33.0419 5120        LVUVC          (5bc80451109a8dd7f2ddd35bce2929a3) C:\windows\system32\DRIVERS\lvuvc.sys
08:24:33.0591 5120        LVUVC - ok
08:24:33.0856 5120        MBAMSwissArmy  (0db7527db188c7d967a37bb51bbf3963) C:\windows\system32\drivers\mbamswissarmy.sys
08:24:33.0887 5120        MBAMSwissArmy - ok
08:24:34.0012 5120        McAfee SiteAdvisor Service (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
08:24:34.0043 5120        McAfee SiteAdvisor Service - ok
08:24:34.0059 5120        McMPFSvc        (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
08:24:34.0090 5120        McMPFSvc - ok
08:24:34.0106 5120        mcmscsvc        (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
08:24:34.0137 5120        mcmscsvc - ok
08:24:34.0152 5120        McNaiAnn        (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
08:24:34.0184 5120        McNaiAnn - ok
08:24:34.0199 5120        McNASvc        (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
08:24:34.0230 5120        McNASvc - ok
08:24:34.0324 5120        McODS          (135aa9e9e7047b7dc1f753205d421a26) C:\Program Files\McAfee\VirusScan\mcods.exe
08:24:34.0371 5120        McODS - ok
08:24:34.0386 5120        McProxy        (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
08:24:34.0418 5120        McProxy - ok
08:24:34.0480 5120        McPvDrv        (000751813ecef491689176e72b3a8bee) C:\windows\system32\drivers\McPvDrv.sys
08:24:34.0496 5120        McPvDrv - ok
08:24:34.0574 5120        McShield        (593fa4c378818ece76ba64a11ad56cf2) C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
08:24:34.0620 5120        McShield - ok
08:24:34.0698 5120        Mcx2Svc        (bfb9ee8ee977efe85d1a3105abef6dd1) C:\windows\system32\Mcx2Svc.dll
08:24:34.0730 5120        Mcx2Svc - ok
08:24:34.0776 5120        megasas        (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys
08:24:34.0808 5120        megasas - ok
08:24:34.0839 5120        MegaSR          (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys
08:24:34.0886 5120        MegaSR - ok
08:24:34.0948 5120        mfeapfk        (43c31bdf404a6d7a7ac1bfd5ead2a566) C:\windows\system32\drivers\mfeapfk.sys
08:24:34.0979 5120        mfeapfk - ok
08:24:35.0042 5120        mfeavfk        (c1dc5f42d3367f33b6451be78b38bd46) C:\windows\system32\drivers\mfeavfk.sys
08:24:35.0073 5120        mfeavfk - ok
08:24:35.0088 5120        mfeavfk01 - ok
08:24:35.0120 5120        mfebopk        (0435c43f4c2be01b84868ad2a906397b) C:\windows\system32\drivers\mfebopk.sys
08:24:35.0135 5120        mfebopk - ok
08:24:35.0182 5120        mfefire        (7e1f8b1bdc8240f08bd358b3a466c005) C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
08:24:35.0229 5120        mfefire - ok
08:24:35.0276 5120        mfefirek        (4ea6ff90015424517843e931448e00f1) C:\windows\system32\drivers\mfefirek.sys
08:24:35.0322 5120        mfefirek - ok
08:24:35.0369 5120        mfehidk        (d1e998748ba24a731106611d535c6bbf) C:\windows\system32\drivers\mfehidk.sys
08:24:35.0432 5120        mfehidk - ok
08:24:35.0463 5120        mfenlfk        (ac04a618aef3de0fce91c766f9e069da) C:\windows\system32\DRIVERS\mfenlfk.sys
08:24:35.0494 5120        mfenlfk - ok
08:24:35.0525 5120        mferkdet        (f454a13377f0a006d20a8c14a753c432) C:\windows\system32\drivers\mferkdet.sys
08:24:35.0556 5120        mferkdet - ok
08:24:35.0697 5120        mfevtp          (b10c4efd40810c08f4b44df2efcb54f7) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
08:24:35.0744 5120        mfevtp - ok
08:24:35.0806 5120        mfewfpk        (f284337aedb7483df8a5fa840647e2b0) C:\windows\system32\drivers\mfewfpk.sys
08:24:35.0837 5120        mfewfpk - ok
08:24:35.0931 5120        Microsoft SharePoint Workspace Audit Service - ok
08:24:35.0946 5120        MMCSS          (146b6f43a673379a3c670e86d89be5ea) C:\windows\system32\mmcss.dll
08:24:36.0009 5120        MMCSS - ok
08:24:36.0087 5120        MOBKbackup      (35176fa09a0fc58db630991a81a0ba39) C:\Program Files\McAfee Online Backup\MOBKbackup.exe
08:24:36.0118 5120        MOBKbackup - ok
08:24:36.0180 5120        MOBKFilter      (e896775837a8bce436348df460522394) C:\windows\system32\DRIVERS\MOBK.sys
08:24:36.0196 5120        MOBKFilter - ok
08:24:36.0227 5120        Modem          (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys
08:24:36.0305 5120        Modem - ok
08:24:36.0321 5120        monitor        (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys
08:24:36.0368 5120        monitor - ok
08:24:36.0399 5120        mouclass        (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\drivers\mouclass.sys
08:24:36.0430 5120        mouclass - ok
08:24:36.0446 5120        mouhid          (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys
08:24:36.0492 5120        mouhid - ok
08:24:36.0524 5120        mountmgr        (fc8771f45ecccfd89684e38842539b9b) C:\windows\system32\drivers\mountmgr.sys
08:24:36.0555 5120        mountmgr - ok
08:24:36.0617 5120        mpio            (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\windows\system32\drivers\mpio.sys
08:24:36.0664 5120        mpio - ok
08:24:36.0711 5120        mpsdrv          (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys
08:24:36.0789 5120        mpsdrv - ok
08:24:36.0867 5120        MpsSvc          (9835584e999d25004e1ee8e5f3e3b881) C:\windows\system32\mpssvc.dll
08:24:36.0929 5120        MpsSvc - ok
08:24:36.0976 5120        MRxDAV          (ceb46ab7c01c9f825f8cc6babc18166a) C:\windows\system32\drivers\mrxdav.sys
08:24:37.0023 5120        MRxDAV - ok
08:24:37.0085 5120        mrxsmb          (5d16c921e3671636c0eba3bbaac5fd25) C:\windows\system32\DRIVERS\mrxsmb.sys
08:24:37.0163 5120        mrxsmb - ok
08:24:37.0210 5120        mrxsmb10        (6d17a4791aca19328c685d256349fefc) C:\windows\system32\DRIVERS\mrxsmb10.sys
08:24:37.0257 5120        mrxsmb10 - ok
08:24:37.0288 5120        mrxsmb20        (b81f204d146000be76651a50670a5e9e) C:\windows\system32\DRIVERS\mrxsmb20.sys
08:24:37.0319 5120        mrxsmb20 - ok
08:24:37.0350 5120        msahci          (012c5f4e9349e711e11e0f19a8589f0a) C:\windows\system32\drivers\msahci.sys
08:24:37.0382 5120        msahci - ok
08:24:37.0428 5120        msdsm          (55055f8ad8be27a64c831322a780a228) C:\windows\system32\drivers\msdsm.sys
08:24:37.0475 5120        msdsm - ok
08:24:37.0522 5120        MSDTC          (e1bce74a3bd9902b72599c0192a07e27) C:\windows\System32\msdtc.exe
08:24:37.0584 5120        MSDTC - ok
08:24:37.0631 5120        Msfs            (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys
08:24:37.0694 5120        Msfs - ok
08:24:37.0725 5120        mshidkmdf      (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys
08:24:37.0787 5120        mshidkmdf - ok
08:24:37.0818 5120        msisadrv        (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\drivers\msisadrv.sys
08:24:37.0850 5120        msisadrv - ok
08:24:37.0881 5120        MSiSCSI        (90f7d9e6b6f27e1a707d4a297f077828) C:\windows\system32\iscsiexe.dll
08:24:37.0974 5120        MSiSCSI - ok
08:24:37.0974 5120        msiserver - ok
08:24:38.0099 5120        MSK80Service    (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
08:24:38.0130 5120        MSK80Service - ok
08:24:38.0162 5120        MSKSSRV        (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys
08:24:38.0240 5120        MSKSSRV - ok
08:24:38.0255 5120        MSPCLOCK        (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys
08:24:38.0318 5120        MSPCLOCK - ok
08:24:38.0333 5120        MSPQM          (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys
08:24:38.0396 5120        MSPQM - ok
08:24:38.0427 5120        MsRPC          (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys
08:24:38.0474 5120        MsRPC - ok
08:24:38.0520 5120        mssmbios        (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\drivers\mssmbios.sys
08:24:38.0552 5120        mssmbios - ok
08:24:38.0614 5120        MSSQL$MSSMLBIZ - ok
08:24:38.0708 5120        MSSQLServerADHelper (1d89eb4e2a99cabd4e81225f4f4c4b25) C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
08:24:38.0739 5120        MSSQLServerADHelper - ok
08:24:38.0739 5120        MSTEE          (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys
08:24:38.0801 5120        MSTEE - ok
08:24:38.0817 5120        MTConfig        (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys
08:24:38.0864 5120        MTConfig - ok
08:24:38.0895 5120        Mup            (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys
08:24:38.0926 5120        Mup - ok
08:24:38.0988 5120        napagent        (61d57a5d7c6d9afe10e77dae6e1b445e) C:\windows\system32\qagentRT.dll
08:24:39.0066 5120        napagent - ok
08:24:39.0129 5120        NativeWifiP    (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys
08:24:39.0160 5120        NativeWifiP - ok
08:24:39.0238 5120        NDIS            (e7c54812a2aaf43316eb6930c1ffa108) C:\windows\system32\drivers\ndis.sys
08:24:39.0285 5120        NDIS - ok
08:24:39.0316 5120        NdisCap        (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys
08:24:39.0394 5120        NdisCap - ok
08:24:39.0425 5120        NdisTapi        (e4a8aec125a2e43a9e32afeea7c9c888) C:\windows\system32\DRIVERS\ndistapi.sys
08:24:39.0488 5120        NdisTapi - ok
08:24:39.0534 5120        Ndisuio        (d8a65dafb3eb41cbb622745676fcd072) C:\windows\system32\DRIVERS\ndisuio.sys
08:24:39.0612 5120        Ndisuio - ok
08:24:39.0659 5120        NdisWan        (38fbe267e7e6983311179230facb1017) C:\windows\system32\DRIVERS\ndiswan.sys
08:24:39.0768 5120        NdisWan - ok
08:24:39.0800 5120        NDProxy        (a4bdc541e69674fbff1a8ff00be913f2) C:\windows\system32\drivers\NDProxy.sys
08:24:39.0862 5120        NDProxy - ok
08:24:39.0909 5120        NetBIOS        (80b275b1ce3b0e79909db7b39af74d51) C:\windows\system32\DRIVERS\netbios.sys
08:24:39.0971 5120        NetBIOS - ok
08:24:40.0018 5120        NetBT          (280122ddcf04b378edd1ad54d71c1e54) C:\windows\system32\DRIVERS\netbt.sys
08:24:40.0080 5120        NetBT - ok
08:24:40.0112 5120        Netlogon        (81951f51e318aecc2d68559e47485cc4) C:\windows\system32\lsass.exe
08:24:40.0143 5120        Netlogon - ok
08:24:40.0205 5120        Netman          (7cccfca7510684768da22092d1fa4db2) C:\windows\System32\netman.dll
08:24:40.0283 5120        Netman - ok
08:24:40.0299 5120        netprofm        (8c338238c16777a802d6a9211eb2ba50) C:\windows\System32\netprofm.dll
08:24:40.0377 5120        netprofm - ok
08:24:40.0455 5120        NetTcpPortSharing (f476ec40033cdb91efbe73eb99b8362d) C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
08:24:40.0502 5120        NetTcpPortSharing - ok
08:24:40.0533 5120        nfrd960        (1d85c4b390b0ee09c7a46b91efb2c097) C:\windows\system32\DRIVERS\nfrd960.sys
08:24:40.0564 5120        nfrd960 - ok
08:24:40.0611 5120        NlaSvc          (912084381d30d8b89ec4e293053f4710) C:\windows\System32\nlasvc.dll
08:24:40.0673 5120        NlaSvc - ok
08:24:40.0704 5120        Npfs            (1db262a9f8c087e8153d89bef3d2235f) C:\windows\system32\drivers\Npfs.sys
08:24:40.0751 5120        Npfs - ok
08:24:40.0782 5120        nsi            (ba387e955e890c8a88306d9b8d06bf17) C:\windows\system32\nsisvc.dll
08:24:40.0829 5120        nsi - ok
08:24:40.0845 5120        nsiproxy        (e9a0a4d07e53d8fea2bb8387a3293c58) C:\windows\system32\drivers\nsiproxy.sys
08:24:40.0923 5120        nsiproxy - ok
08:24:41.0032 5120        Ntfs            (81189c3d7763838e55c397759d49007a) C:\windows\system32\drivers\Ntfs.sys
08:24:41.0126 5120        Ntfs - ok
08:24:41.0266 5120        Null            (f9756a98d69098dca8945d62858a812c) C:\windows\system32\drivers\Null.sys
08:24:41.0313 5120        Null - ok
08:24:41.0375 5120        nvraid          (b3e25ee28883877076e0e1ff877d02e0) C:\windows\system32\drivers\nvraid.sys
08:24:41.0406 5120        nvraid - ok
08:24:41.0438 5120        nvstor          (4380e59a170d88c4f1022eff6719a8a4) C:\windows\system32\drivers\nvstor.sys
08:24:41.0484 5120        nvstor - ok
08:24:41.0500 5120        nv_agp          (5a0983915f02bae73267cc2a041f717d) C:\windows\system32\drivers\nv_agp.sys
08:24:41.0547 5120        nv_agp - ok
08:24:41.0594 5120        OberonGameConsoleService (b5d5da8230d3d3525839d939a9196c3e) C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe
08:24:41.0625 5120        OberonGameConsoleService - ok
08:24:41.0687 5120        ohci1394        (08a70a1f2cdde9bb49b885cb817a66eb) C:\windows\system32\drivers\ohci1394.sys
08:24:41.0734 5120        ohci1394 - ok
08:24:41.0796 5120        ose            (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
08:24:41.0828 5120        ose - ok
08:24:42.0218 5120        osppsvc        (358a9cca612c68eb2f07ddad4ce1d8d7) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
08:24:42.0436 5120        osppsvc - ok
08:24:42.0686 5120        p2pimsvc        (82a8521ddc60710c3d3d3e7325209bec) C:\windows\system32\pnrpsvc.dll
08:24:42.0764 5120        p2pimsvc - ok
08:24:42.0795 5120        p2psvc          (59c3ddd501e39e006dac31bf55150d91) C:\windows\system32\p2psvc.dll
08:24:42.0842 5120        p2psvc - ok
08:24:42.0888 5120        Parport        (2ea877ed5dd9713c5ac74e8ea7348d14) C:\windows\system32\DRIVERS\parport.sys
08:24:42.0935 5120        Parport - ok
08:24:42.0982 5120        partmgr        (3f34a1b4c5f6475f320c275e63afce9b) C:\windows\system32\drivers\partmgr.sys
08:24:43.0013 5120        partmgr - ok
08:24:43.0029 5120        Parvdm          (eb0a59f29c19b86479d36b35983daadc) C:\windows\system32\DRIVERS\parvdm.sys
08:24:43.0076 5120        Parvdm - ok
08:24:43.0107 5120        PcaSvc          (358ab7956d3160000726574083dfc8a6) C:\windows\System32\pcasvc.dll
08:24:43.0154 5120        PcaSvc - ok
08:24:43.0185 5120        pci            (673e55c3498eb970088e812ea820aa8f) C:\windows\system32\drivers\pci.sys
08:24:43.0232 5120        pci - ok
08:24:43.0263 5120        pciide          (afe86f419014db4e5593f69ffe26ce0a) C:\windows\system32\drivers\pciide.sys
08:24:43.0294 5120        pciide - ok
08:24:43.0325 5120        pcmcia          (f396431b31693e71e8a80687ef523506) C:\windows\system32\DRIVERS\pcmcia.sys
08:24:43.0372 5120        pcmcia - ok
08:24:43.0388 5120        pcw            (250f6b43d2b613172035c6747aeeb19f) C:\windows\system32\drivers\pcw.sys
08:24:43.0403 5120        pcw - ok
08:24:43.0466 5120        PEAUTH          (9e0104ba49f4e6973749a02bf41344ed) C:\windows\system32\drivers\peauth.sys
08:24:43.0559 5120        PEAUTH - ok
08:24:43.0762 5120        pla            (414bba67a3ded1d28437eb66aeb8a720) C:\windows\system32\pla.dll
08:24:43.0871 5120        pla - ok
08:24:44.0058 5120        PlugPlay        (ec7bc28d207da09e79b3e9faf8b232ca) C:\windows\system32\umpnpmgr.dll
08:24:44.0136 5120        PlugPlay - ok
08:24:44.0292 5120        PMBDeviceInfoProvider (ae6c778717de2f6b0c0b5335036d3363) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
08:24:44.0370 5120        PMBDeviceInfoProvider - ok
08:24:44.0402 5120        PNRPAutoReg    (63ff8572611249931eb16bb8eed6afc8) C:\windows\system32\pnrpauto.dll
08:24:44.0448 5120        PNRPAutoReg - ok
08:24:44.0480 5120        PNRPsvc        (82a8521ddc60710c3d3d3e7325209bec) C:\windows\system32\pnrpsvc.dll
08:24:44.0526 5120        PNRPsvc - ok
08:24:44.0589 5120        PolicyAgent    (53946b69ba0836bd95b03759530c81ec) C:\windows\System32\ipsecsvc.dll
08:24:44.0682 5120        PolicyAgent - ok
08:24:44.0745 5120        Power          (f87d30e72e03d579a5199ccb3831d6ea) C:\windows\system32\umpo.dll
08:24:44.0870 5120        Power - ok
08:24:45.0057 5120        PptpMiniport    (631e3e205ad6d86f2aed6a4a8e69f2db) C:\windows\system32\DRIVERS\raspptp.sys
08:24:45.0166 5120        PptpMiniport - ok
08:24:45.0197 5120        Processor      (85b1e3a0c7585bc4aae6899ec6fcf011) C:\windows\system32\DRIVERS\processr.sys
08:24:45.0228 5120        Processor - ok
08:24:45.0306 5120        ProfSvc        (cadefac453040e370a1bdff3973be00d) C:\windows\system32\profsvc.dll
08:24:45.0370 5120        ProfSvc - ok
08:24:45.0417 5120        ProtectedStorage (81951f51e318aecc2d68559e47485cc4) C:\windows\system32\lsass.exe
08:24:45.0448 5120        ProtectedStorage - ok
08:24:45.0479 5120        Psched          (6270ccae2a86de6d146529fe55b3246a) C:\windows\system32\DRIVERS\pacer.sys
08:24:45.0557 5120        Psched - ok
08:24:45.0619 5120        PxHelp20        (e42e3433dbb4cffe8fdd91eab29aea8e) C:\windows\system32\Drivers\PxHelp20.sys
08:24:45.0651 5120        PxHelp20 - ok
08:24:45.0807 5120        ql2300          (ab95ecf1f6659a60ddc166d8315b0751) C:\windows\system32\DRIVERS\ql2300.sys
08:24:45.0885 5120        ql2300 - ok
08:24:46.0025 5120        ql40xx          (b4dd51dd25182244b86737dc51af2270) C:\windows\system32\DRIVERS\ql40xx.sys
08:24:46.0056 5120        ql40xx - ok
08:24:46.0165 5120        QWAVE          (31ac809e7707eb580b2bdb760390765a) C:\windows\system32\qwave.dll
08:24:46.0243 5120        QWAVE - ok
08:24:46.0275 5120        QWAVEdrv        (584078ca1b95ca72df2a27c336f9719d) C:\windows\system32\drivers\qwavedrv.sys
08:24:46.0321 5120        QWAVEdrv - ok
08:24:46.0775 5120        Radio.fx        (138f7963118ec710c348819c08f72230) C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe
08:24:46.0900 5120        Radio.fx - ok
08:24:47.0040 5120        RasAcd          (30a81b53c766d0133bb86d234e5556ab) C:\windows\system32\DRIVERS\rasacd.sys
08:24:47.0102 5120        RasAcd - ok
08:24:47.0165 5120        RasAgileVpn    (57ec4aef73660166074d8f7f31c0d4fd) C:\windows\system32\DRIVERS\AgileVpn.sys
08:24:47.0227 5120        RasAgileVpn - ok
08:24:47.0274 5120        RasAuto        (a60f1839849c0c00739787fd5ec03f13) C:\windows\System32\rasauto.dll
08:24:47.0368 5120        RasAuto - ok
08:24:47.0399 5120        Rasl2tp        (d9f91eafec2815365cbe6d167e4e332a) C:\windows\system32\DRIVERS\rasl2tp.sys
08:24:47.0477 5120        Rasl2tp - ok
08:24:47.0555 5120        RasMan          (cb9e04dc05eacf5b9a36ca276d475006) C:\windows\System32\rasmans.dll
08:24:47.0633 5120        RasMan - ok
08:24:47.0695 5120        RasPppoe        (0fe8b15916307a6ac12bfb6a63e45507) C:\windows\system32\DRIVERS\raspppoe.sys
08:24:47.0758 5120        RasPppoe - ok
08:24:47.0804 5120        RasSstp        (44101f495a83ea6401d886e7fd70096b) C:\windows\system32\DRIVERS\rassstp.sys
08:24:47.0882 5120        RasSstp - ok
08:24:47.0929 5120        rdbss          (d528bc58a489409ba40334ebf96a311b) C:\windows\system32\DRIVERS\rdbss.sys
08:24:47.0992 5120        rdbss - ok
08:24:48.0023 5120        rdpbus          (0d8f05481cb76e70e1da06ee9f0da9df) C:\windows\system32\DRIVERS\rdpbus.sys
08:24:48.0054 5120        rdpbus - ok
08:24:48.0101 5120        RDPCDD          (23dae03f29d253ae74c44f99e515f9a1) C:\windows\system32\DRIVERS\RDPCDD.sys
08:24:48.0163 5120        RDPCDD - ok
08:24:48.0210 5120        RDPENCDD        (5a53ca1598dd4156d44196d200c94b8a) C:\windows\system32\drivers\rdpencdd.sys
08:24:48.0272 5120        RDPENCDD - ok
08:24:48.0319 5120        RDPREFMP        (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\windows\system32\drivers\rdprefmp.sys
08:24:48.0397 5120        RDPREFMP - ok
08:24:48.0460 5120        RDPWD          (f031683e6d1fea157abb2ff260b51e61) C:\windows\system32\drivers\RDPWD.sys
08:24:48.0522 5120        RDPWD - ok
08:24:48.0584 5120        rdyboost        (518395321dc96fe2c9f0e96ac743b656) C:\windows\system32\drivers\rdyboost.sys
08:24:48.0631 5120        rdyboost - ok
08:24:48.0709 5120        RemoteAccess    (7b5e1419717fac363a31cc302895217a) C:\windows\System32\mprdim.dll
08:24:48.0787 5120        RemoteAccess - ok
08:24:48.0834 5120        RemoteRegistry  (cb9a8683f4ef2bf99e123d79950d7935) C:\windows\system32\regsvc.dll
08:24:48.0912 5120        RemoteRegistry - ok
08:24:48.0959 5120        RpcEptMapper    (78d072f35bc45d9e4e1b61895c152234) C:\windows\System32\RpcEpMap.dll
08:24:49.0037 5120        RpcEptMapper - ok
08:24:49.0084 5120        RpcLocator      (94d36c0e44677dd26981d2bfeef2a29d) C:\windows\system32\locator.exe
08:24:49.0130 5120        RpcLocator - ok
08:24:49.0177 5120        RpcSs          (7660f01d3b38aca1747e397d21d790af) C:\windows\system32\rpcss.dll
08:24:49.0240 5120        RpcSs - ok
08:24:49.0302 5120        rspndr          (032b0d36ad92b582d869879f5af5b928) C:\windows\system32\DRIVERS\rspndr.sys
08:24:49.0396 5120        rspndr - ok
08:24:49.0458 5120        RTL8167        (05c2613f661584190c752f6184d1c8ef) C:\windows\system32\DRIVERS\Rt86win7.sys
08:24:49.0520 5120        RTL8167 - ok
08:24:49.0567 5120        SABI            (6e5fbb7cbaec47038b945d5e9b144a64) C:\windows\system32\Drivers\SABI.sys
08:24:49.0614 5120        SABI - ok
08:24:49.0708 5120        SamSs          (81951f51e318aecc2d68559e47485cc4) C:\windows\system32\lsass.exe
08:24:49.0739 5120        SamSs - ok
08:24:49.0801 5120        sbp2port        (05d860da1040f111503ac416ccef2bca) C:\windows\system32\drivers\sbp2port.sys
08:24:49.0832 5120        sbp2port - ok
08:24:49.0879 5120        SCardSvr        (8fc518ffe9519c2631d37515a68009c4) C:\windows\System32\SCardSvr.dll
08:24:49.0957 5120        SCardSvr - ok
08:24:50.0004 5120        scfilter        (0693b5ec673e34dc147e195779a4dcf6) C:\windows\system32\DRIVERS\scfilter.sys
08:24:50.0082 5120        scfilter - ok
08:24:50.0176 5120        Schedule        (a04bb13f8a72f8b6e8b4071723e4e336) C:\windows\system32\schedsvc.dll
08:24:50.0269 5120        Schedule - ok
08:24:50.0316 5120        SCPolicySvc    (319c6b309773d063541d01df8ac6f55f) C:\windows\System32\certprop.dll
08:24:50.0378 5120        SCPolicySvc - ok
08:24:50.0425 5120        SDRSVC          (08236c4bce5edd0a0318a438af28e0f7) C:\windows\System32\SDRSVC.dll
08:24:50.0503 5120        SDRSVC - ok
08:24:50.0566 5120        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys
08:24:50.0644 5120        secdrv - ok
08:24:50.0737 5120        seclogon        (a59b3a4442c52060cc7a85293aa3546f) C:\windows\system32\seclogon.dll
08:24:50.0800 5120        seclogon - ok
08:24:50.0831 5120        SENS            (dcb7fcdcc97f87360f75d77425b81737) C:\windows\System32\sens.dll
08:24:50.0940 5120        SENS - ok
08:24:51.0002 5120        SensrSvc        (50087fe1ee447009c9cc2997b90de53f) C:\windows\system32\sensrsvc.dll
08:24:51.0049 5120        SensrSvc - ok
08:24:51.0268 5120        Serenum        (9ad8b8b515e3df6acd4212ef465de2d1) C:\windows\system32\DRIVERS\serenum.sys
08:24:51.0299 5120        Serenum - ok
08:24:51.0377 5120        Serial          (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\windows\system32\DRIVERS\serial.sys
08:24:51.0580 5120        Serial - ok
08:24:51.0704 5120        sermouse        (79bffb520327ff916a582dfea17aa813) C:\windows\system32\DRIVERS\sermouse.sys
08:24:51.0751 5120        sermouse - ok
08:24:51.0829 5120        SessionEnv      (4ae380f39a0032eab7dd953030b26d28) C:\windows\system32\sessenv.dll
08:24:51.0938 5120        SessionEnv - ok
08:24:52.0110 5120        sesvc          (4c99e251d89c95dcaaa26f9243747c99) C:\Program Files\ShadowExplorer\sesvc.exe
08:24:52.0126 5120        sesvc ( UnsignedFile.Multi.Generic ) - warning
08:24:52.0126 5120        sesvc - detected UnsignedFile.Multi.Generic (1)
08:24:52.0172 5120        sffdisk        (9f976e1eb233df46fce808d9dea3eb9c) C:\windows\system32\drivers\sffdisk.sys
08:24:52.0266 5120        sffdisk - ok
08:24:52.0297 5120        sffp_mmc        (932a68ee27833cfd57c1639d375f2731) C:\windows\system32\drivers\sffp_mmc.sys
08:24:52.0328 5120        sffp_mmc - ok
08:24:52.0344 5120        sffp_sd        (6d4ccaedc018f1cf52866bbbaa235982) C:\windows\system32\drivers\sffp_sd.sys
08:24:52.0391 5120        sffp_sd - ok
08:24:52.0422 5120        sfloppy        (db96666cc8312ebc45032f30b007a547) C:\windows\system32\DRIVERS\sfloppy.sys
08:24:52.0500 5120        sfloppy - ok
08:24:52.0562 5120        SharedAccess    (d1a079a0de2ea524513b6930c24527a2) C:\windows\System32\ipnathlp.dll
08:24:52.0656 5120        SharedAccess - ok
08:24:52.0734 5120        ShellHWDetection (414da952a35bf5d50192e28263b40577) C:\windows\System32\shsvcs.dll
08:24:52.0952 5120        ShellHWDetection - ok
08:24:53.0030 5120        sisagp          (2565cac0dc9fe0371bdce60832582b2e) C:\windows\system32\drivers\sisagp.sys
08:24:53.0062 5120        sisagp - ok
08:24:53.0108 5120        SiSRaid2        (a9f0486851becb6dda1d89d381e71055) C:\windows\system32\DRIVERS\SiSRaid2.sys
08:24:53.0140 5120        SiSRaid2 - ok
08:24:53.0171 5120        SiSRaid4        (3727097b55738e2f554972c3be5bc1aa) C:\windows\system32\DRIVERS\sisraid4.sys
08:24:53.0202 5120        SiSRaid4 - ok
08:24:53.0249 5120        Smb            (3e21c083b8a01cb70ba1f09303010fce) C:\windows\system32\DRIVERS\smb.sys
08:24:53.0358 5120        Smb - ok
08:24:53.0420 5120        SNMPTRAP        (6a984831644eca1a33ffeae4126f4f37) C:\windows\System32\snmptrap.exe
08:24:53.0483 5120        SNMPTRAP - ok
08:24:53.0514 5120        spldr          (95cf1ae7527fb70f7816563cbc09d942) C:\windows\system32\drivers\spldr.sys
08:24:53.0545 5120        spldr - ok
08:24:53.0686 5120        Spooler        (866a43013535dc8587c258e43579c764) C:\windows\System32\spoolsv.exe
08:24:53.0764 5120        Spooler - ok
08:24:54.0091 5120        sppsvc          (cf87a1de791347e75b98885214ced2b8) C:\windows\system32\sppsvc.exe
08:24:54.0278 5120        sppsvc - ok
08:24:54.0419 5120        sppuinotify    (b0180b20b065d89232a78a40fe56eaa6) C:\windows\system32\sppuinotify.dll
08:24:54.0481 5120        sppuinotify - ok
08:24:54.0607 5120        SQLBrowser      (86ebd8b1f23e743aad21f4d5b4d40985) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
08:24:54.0623 5120        SQLBrowser - ok
08:24:54.0701 5120        SQLWriter      (d89083c4eb02daca8f944b0e05e57f9d) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
08:24:54.0732 5120        SQLWriter - ok
08:24:54.0825 5120        srv            (e4c2764065d66ea1d2d3ebc28fe99c46) C:\windows\system32\DRIVERS\srv.sys
08:24:54.0888 5120        srv - ok
08:24:54.0935 5120        srv2            (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\windows\system32\DRIVERS\srv2.sys
08:24:54.0997 5120        srv2 - ok
08:24:55.0028 5120        srvnet          (be6bd660caa6f291ae06a718a4fa8abc) C:\windows\system32\DRIVERS\srvnet.sys
08:24:55.0091 5120        srvnet - ok
08:24:55.0137 5120        SSDPSRV        (d887c9fd02ac9fa880f6e5027a43e118) C:\windows\System32\ssdpsrv.dll
08:24:55.0200 5120        SSDPSRV - ok
08:24:55.0231 5120        SstpSvc        (d318f23be45d5e3a107469eb64815b50) C:\windows\system32\sstpsvc.dll
08:24:55.0309 5120        SstpSvc - ok
08:24:55.0465 5120        StarMoney 7.0 OnlineUpdate (e8606bf6be3b7481d95f1dd2e4f3fcba) C:\Program Files\StarMoney 7.0\ouservice\StarMoneyOnlineUpdate.exe
08:24:55.0512 5120        StarMoney 7.0 OnlineUpdate - ok
08:24:55.0730 5120        StarMoney 8.0 OnlineUpdate (7e784dc5c7ce2c6f3c392ad320f5f2c0) C:\Program Files\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe
08:24:55.0777 5120        StarMoney 8.0 OnlineUpdate - ok
08:24:56.0354 5120        stexstor        (db32d325c192b801df274bfd12a7e72b) C:\windows\system32\DRIVERS\stexstor.sys
08:24:56.0401 5120        stexstor - ok
08:24:56.0479 5120        StiSvc          (e1fb3706030fb4578a0d72c2fc3689e4) C:\windows\System32\wiaservc.dll
08:24:56.0713 5120        StiSvc - ok
08:24:56.0807 5120        swenum          (e58c78a848add9610a4db6d214af5224) C:\windows\system32\drivers\swenum.sys
08:24:56.0838 5120        swenum - ok
08:24:56.0900 5120        swprv          (a28bd92df340e57b024ba433165d34d7) C:\windows\System32\swprv.dll
08:24:57.0009 5120        swprv - ok
08:24:57.0087 5120        SynTP          (7a9025d8f7852b06d6d08ed536135e7e) C:\windows\system32\DRIVERS\SynTP.sys
08:24:57.0119 5120        SynTP - ok
08:24:57.0275 5120        SysMain        (36650d618ca34c9d357dfd3d89b2c56f) C:\windows\system32\sysmain.dll
08:24:57.0368 5120        SysMain - ok
08:24:57.0431 5120        TabletInputService (763fecdc3d30c815fe72dd57936c6cd1) C:\windows\System32\TabSvc.dll
08:24:57.0555 5120        TabletInputService - ok
08:24:57.0696 5120        TapiSrv        (613bf4820361543956909043a265c6ac) C:\windows\System32\tapisrv.dll
08:24:57.0836 5120        TapiSrv - ok
08:24:57.0883 5120        TBS            (b799d9fdb26111737f58288d8dc172d9) C:\windows\System32\tbssvc.dll
08:24:58.0023 5120        TBS - ok
08:24:58.0226 5120        Tcpip          (7fa2e0f8b072bd04b77b421480b6cc22) C:\windows\system32\drivers\tcpip.sys
08:24:58.0335 5120        Tcpip - ok
08:24:58.0741 5120        TCPIP6          (7fa2e0f8b072bd04b77b421480b6cc22) C:\windows\system32\DRIVERS\tcpip.sys
08:24:58.0819 5120        TCPIP6 - ok
08:24:59.0115 5120        tcpipreg        (cca24162e055c3714ce5a88b100c64ed) C:\windows\system32\drivers\tcpipreg.sys
08:24:59.0225 5120        tcpipreg - ok
08:24:59.0271 5120        TDPIPE          (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\windows\system32\drivers\tdpipe.sys
08:24:59.0318 5120        TDPIPE - ok
08:24:59.0412 5120        TDTCP          (2c2c5afe7ee4f620d69c23c0617651a8) C:\windows\system32\drivers\tdtcp.sys
08:24:59.0459 5120        TDTCP - ok
08:24:59.0505 5120        tdx            (b459575348c20e8121d6039da063c704) C:\windows\system32\DRIVERS\tdx.sys
08:24:59.0568 5120        tdx - ok
08:24:59.0615 5120        TermDD          (04dbf4b01ea4bf25a9a3e84affac9b20) C:\windows\system32\drivers\termdd.sys
08:24:59.0646 5120        TermDD - ok
08:24:59.0740 5120        TermService    (382c804c92811be57829d8e550a900e2) C:\windows\System32\termsrv.dll
08:24:59.0834 5120        TermService - ok
08:24:59.0881 5120        Themes          (42fb6afd6b79d9fe07381609172e7ca4) C:\windows\system32\themeservice.dll
08:24:59.0928 5120        Themes - ok
08:24:59.0974 5120        THREADORDER    (146b6f43a673379a3c670e86d89be5ea) C:\windows\system32\mmcss.dll
08:25:00.0052 5120        THREADORDER - ok
08:25:00.0084 5120        TrkWks          (4792c0378db99a9bc2ae2de6cfff0c3a) C:\windows\System32\trkwks.dll
08:25:00.0177 5120        TrkWks - ok
08:25:00.0271 5120        TrustedInstaller (2c49b175aee1d4364b91b531417fe583) C:\windows\servicing\TrustedInstaller.exe
08:25:00.0333 5120        TrustedInstaller - ok
08:25:00.0364 5120        tssecsrv        (254bb140eee3c59d6114c1a86b636877) C:\windows\system32\DRIVERS\tssecsrv.sys
08:25:00.0442 5120        tssecsrv - ok
08:25:00.0552 5120        TsUsbFlt        (fd1d6c73e6333be727cbcc6054247654) C:\windows\system32\drivers\tsusbflt.sys
08:25:00.0583 5120        TsUsbFlt - ok
08:25:00.0645 5120        tunnel          (b2fa25d9b17a68bb93d58b0556e8c90d) C:\windows\system32\DRIVERS\tunnel.sys
08:25:00.0770 5120        tunnel - ok
08:25:00.0817 5120        uagp35          (750fbcb269f4d7dd2e420c56b795db6d) C:\windows\system32\DRIVERS\uagp35.sys
08:25:00.0848 5120        uagp35 - ok
08:25:00.0910 5120        udfs            (ee43346c7e4b5e63e54f927babbb32ff) C:\windows\system32\DRIVERS\udfs.sys
08:25:01.0066 5120        udfs - ok
08:25:01.0113 5120        UI0Detect      (8344fd4fce927880aa1aa7681d4927e5) C:\windows\system32\UI0Detect.exe
08:25:01.0222 5120        UI0Detect - ok
08:25:01.0269 5120        uliagpkx        (44e8048ace47befbfdc2e9be4cbc8880) C:\windows\system32\drivers\uliagpkx.sys
08:25:01.0300 5120        uliagpkx - ok
08:25:01.0347 5120        umbus          (d295bed4b898f0fd999fcfa9b32b071b) C:\windows\system32\drivers\umbus.sys
08:25:01.0378 5120        umbus - ok
08:25:01.0410 5120        UmPass          (7550ad0c6998ba1cb4843e920ee0feac) C:\windows\system32\DRIVERS\umpass.sys
08:25:01.0456 5120        UmPass - ok
08:25:01.0628 5120        UMVPFSrv        (67a95b9d129ed5399e7965cd09cf30e7) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
08:25:01.0675 5120        UMVPFSrv - ok
08:25:01.0737 5120        upnphost        (833fbb672460efce8011d262175fad33) C:\windows\System32\upnphost.dll
08:25:01.0831 5120        upnphost - ok
08:25:01.0893 5120        usbaudio        (1d9f2bd026e8e2d45033a4df3f16b78c) C:\windows\system32\drivers\usbaudio.sys
08:25:01.0940 5120        usbaudio - ok
08:25:01.0987 5120        usbccgp        (bd9c55d7023c5de374507acc7a14e2ac) C:\windows\system32\DRIVERS\usbccgp.sys
08:25:02.0049 5120        usbccgp - ok
08:25:02.0112 5120        usbcir          (04ec7cec62ec3b6d9354eee93327fc82) C:\windows\system32\drivers\usbcir.sys
08:25:02.0158 5120        usbcir - ok
08:25:02.0205 5120        usbehci        (f92de757e4b7ce9c07c5e65423f3ae3b) C:\windows\system32\DRIVERS\usbehci.sys
08:25:02.0236 5120        usbehci - ok
08:25:02.0314 5120        usbhub          (8dc94aec6a7e644a06135ae7506dc2e9) C:\windows\system32\DRIVERS\usbhub.sys
08:25:02.0439 5120        usbhub - ok
08:25:02.0486 5120        usbohci        (e185d44fac515a18d9deddc23c2cdf44) C:\windows\system32\drivers\usbohci.sys
08:25:02.0564 5120        usbohci - ok
08:25:02.0611 5120        usbprint        (797d862fe0875e75c7cc4c1ad7b30252) C:\windows\system32\DRIVERS\usbprint.sys
08:25:02.0658 5120        usbprint - ok
08:25:02.0751 5120        usbscan        (576096ccbc07e7c4ea4f5e6686d6888f) C:\windows\system32\DRIVERS\usbscan.sys
08:25:02.0814 5120        usbscan - ok
08:25:02.0876 5120        USBSTOR        (f991ab9cc6b908db552166768176896a) C:\windows\system32\DRIVERS\USBSTOR.SYS
08:25:02.0954 5120        USBSTOR - ok
08:25:03.0001 5120        usbuhci        (68df884cf41cdada664beb01daf67e3d) C:\windows\system32\DRIVERS\usbuhci.sys
08:25:03.0063 5120        usbuhci - ok
08:25:03.0141 5120        usbvideo        (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\windows\system32\Drivers\usbvideo.sys
08:25:03.0219 5120        usbvideo - ok
08:25:03.0266 5120        UxSms          (081e6e1c91aec36758902a9f727cd23c) C:\windows\System32\uxsms.dll
08:25:03.0344 5120        UxSms - ok
08:25:03.0406 5120        VaultSvc        (81951f51e318aecc2d68559e47485cc4) C:\windows\system32\lsass.exe
08:25:03.0438 5120        VaultSvc - ok
08:25:03.0500 5120        vdrvroot        (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\windows\system32\drivers\vdrvroot.sys
08:25:03.0531 5120        vdrvroot - ok
08:25:03.0625 5120        vds            (c3cd30495687c2a2f66a65ca6fd89be9) C:\windows\System32\vds.exe
08:25:03.0718 5120        vds - ok
08:25:03.0765 5120        vga            (17c408214ea61696cec9c66e388b14f3) C:\windows\system32\DRIVERS\vgapnp.sys
08:25:03.0812 5120        vga - ok
08:25:03.0859 5120        VgaSave        (8e38096ad5c8570a6f1570a61e251561) C:\windows\System32\drivers\vga.sys
08:25:03.0921 5120        VgaSave - ok
08:25:03.0968 5120        vhdmp          (5461686cca2fda57b024547733ab42e3) C:\windows\system32\drivers\vhdmp.sys
08:25:04.0015 5120        vhdmp - ok
08:25:04.0062 5120        viaagp          (c829317a37b4bea8f39735d4b076e923) C:\windows\system32\drivers\viaagp.sys
08:25:04.0093 5120        viaagp - ok
08:25:04.0124 5120        ViaC7          (e02f079a6aa107f06b16549c6e5c7b74) C:\windows\system32\DRIVERS\viac7.sys
08:25:04.0171 5120        ViaC7 - ok
08:25:04.0202 5120        viaide          (e43574f6a56a0ee11809b48c09e4fd3c) C:\windows\system32\drivers\viaide.sys
08:25:04.0233 5120        viaide - ok
08:25:04.0249 5120        volmgr          (4c63e00f2f4b5f86ab48a58cd990f212) C:\windows\system32\drivers\volmgr.sys
08:25:04.0280 5120        volmgr - ok
08:25:04.0342 5120        volmgrx        (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\windows\system32\drivers\volmgrx.sys
08:25:04.0374 5120        volmgrx - ok
08:25:04.0420 5120        volsnap        (f497f67932c6fa693d7de2780631cfe7) C:\windows\system32\drivers\volsnap.sys
08:25:04.0467 5120        volsnap - ok
08:25:04.0514 5120        vsmraid        (9dfa0cc2f8855a04816729651175b631) C:\windows\system32\DRIVERS\vsmraid.sys
08:25:04.0561 5120        vsmraid - ok
08:25:04.0686 5120        VSS            (209a3b1901b83aeb8527ed211cce9e4c) C:\windows\system32\vssvc.exe
08:25:04.0795 5120        VSS - ok
08:25:04.0826 5120        vwifibus        (90567b1e658001e79d7c8bbd3dde5aa6) C:\windows\system32\DRIVERS\vwifibus.sys
08:25:04.0857 5120        vwifibus - ok
08:25:04.0920 5120        vwififlt        (7090d3436eeb4e7da3373090a23448f7) C:\windows\system32\DRIVERS\vwififlt.sys
08:25:04.0966 5120        vwififlt - ok
08:25:04.0998 5120        vwifimp        (a3f04cbea6c2a10e6cb01f8b47611882) C:\windows\system32\DRIVERS\vwifimp.sys
08:25:05.0044 5120        vwifimp - ok
08:25:05.0091 5120        W32Time        (55187fd710e27d5095d10a472c8baf1c) C:\windows\system32\w32time.dll
08:25:05.0185 5120        W32Time - ok
08:25:05.0232 5120        WacomPen        (de3721e89c653aa281428c8a69745d90) C:\windows\system32\DRIVERS\wacompen.sys
08:25:05.0278 5120        WacomPen - ok
08:25:05.0341 5120        WANARP          (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\windows\system32\DRIVERS\wanarp.sys
08:25:05.0434 5120        WANARP - ok
08:25:05.0450 5120        Wanarpv6        (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\windows\system32\DRIVERS\wanarp.sys
08:25:05.0497 5120        Wanarpv6 - ok
08:25:05.0700 5120        WatAdminSvc    (353a04c273ec58475d8633e75ccd5604) C:\windows\system32\Wat\WatAdminSvc.exe
08:25:05.0778 5120        WatAdminSvc - ok
08:25:06.0027 5120        wbengine        (691e3285e53dca558e1a84667f13e15a) C:\windows\system32\wbengine.exe
08:25:06.0121 5120        wbengine - ok
08:25:06.0168 5120        WbioSrvc        (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\windows\System32\wbiosrvc.dll
08:25:06.0230 5120        WbioSrvc - ok
08:25:06.0292 5120        wcncsvc        (34eee0dfaadb4f691d6d5308a51315dc) C:\windows\System32\wcncsvc.dll
08:25:06.0370 5120        wcncsvc - ok
08:25:06.0402 5120        WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\windows\System32\WcsPlugInService.dll
08:25:06.0448 5120        WcsPlugInService - ok
08:25:06.0511 5120        Wd              (1112a9badacb47b7c0bb0392e3158dff) C:\windows\system32\DRIVERS\wd.sys
08:25:06.0542 5120        Wd - ok
08:25:06.0604 5120        Wdf01000        (9950e3d0f08141c7e89e64456ae7dc73) C:\windows\system32\drivers\Wdf01000.sys
08:25:06.0651 5120        Wdf01000 - ok
08:25:06.0714 5120        WdiServiceHost  (46ef9dc96265fd0b423db72e7c38c2a5) C:\windows\system32\wdi.dll
08:25:06.0792 5120        WdiServiceHost - ok
08:25:06.0807 5120        WdiSystemHost  (46ef9dc96265fd0b423db72e7c38c2a5) C:\windows\system32\wdi.dll
08:25:06.0854 5120        WdiSystemHost - ok
08:25:06.0901 5120        WebClient      (a9d880f97530d5b8fee278923349929d) C:\windows\System32\webclnt.dll
08:25:06.0963 5120        WebClient - ok
08:25:07.0010 5120        Wecsvc          (760f0afe937a77cff27153206534f275) C:\windows\system32\wecsvc.dll
08:25:07.0088 5120        Wecsvc - ok
08:25:07.0119 5120        wercplsupport  (ac804569bb2364fb6017370258a4091b) C:\windows\System32\wercplsupport.dll
08:25:07.0182 5120        wercplsupport - ok
08:25:07.0244 5120        WerSvc          (08e420d873e4fd85241ee2421b02c4a4) C:\windows\System32\WerSvc.dll
08:25:07.0322 5120        WerSvc - ok
08:25:07.0353 5120        WfpLwf          (8b9a943f3b53861f2bfaf6c186168f79) C:\windows\system32\DRIVERS\wfplwf.sys
08:25:07.0416 5120        WfpLwf - ok
08:25:07.0431 5120        WIMMount        (5cf95b35e59e2a38023836fff31be64c) C:\windows\system32\drivers\wimmount.sys
08:25:07.0462 5120        WIMMount - ok
08:25:07.0603 5120        WinDefend      (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll
08:25:07.0681 5120        WinDefend - ok
08:25:07.0712 5120        WinHttpAutoProxySvc - ok
08:25:07.0806 5120        Winmgmt        (f62e510b6ad4c21eb9fe8668ed251826) C:\windows\system32\wbem\WMIsvc.dll
08:25:07.0868 5120        Winmgmt - ok
08:25:07.0993 5120        WinRM          (1b91cd34ea3a90ab6a4ef0550174f4cc) C:\windows\system32\WsmSvc.dll
08:25:08.0133 5120        WinRM - ok
08:25:08.0227 5120        WinUsb          (a67e5f9a400f3bd1be3d80613b45f708) C:\windows\system32\DRIVERS\WinUsb.sys
08:25:08.0289 5120        WinUsb - ok
08:25:08.0398 5120        Wlansvc        (16935c98ff639d185086a3529b1f2067) C:\windows\System32\wlansvc.dll
08:25:08.0461 5120        Wlansvc - ok
08:25:08.0648 5120        wlidsvc        (5144ae67d60ec653f97ddf3feed29e77) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
08:25:08.0726 5120        wlidsvc - ok
08:25:08.0882 5120        WmiAcpi        (0217679b8fca58714c3bf2726d2ca84e) C:\windows\system32\drivers\wmiacpi.sys
08:25:08.0913 5120        WmiAcpi - ok
08:25:09.0007 5120        wmiApSrv        (6eb6b66517b048d87dc1856ddf1f4c3f) C:\windows\system32\wbem\WmiApSrv.exe
08:25:09.0085 5120        wmiApSrv - ok
08:25:09.0256 5120        WMPNetworkSvc  (3b40d3a61aa8c21b88ae57c58ab3122e) C:\Program Files\Windows Media Player\wmpnetwk.exe
08:25:09.0350 5120        WMPNetworkSvc - ok
08:25:09.0490 5120        WPCSvc          (a2f0ec770a92f2b3f9de6d518e11409c) C:\windows\System32\wpcsvc.dll
08:25:09.0553 5120        WPCSvc - ok
08:25:09.0600 5120        WPDBusEnum      (aa53356d60af47eacc85bc617a4f3f66) C:\windows\system32\wpdbusenum.dll
08:25:09.0646 5120        WPDBusEnum - ok
08:25:09.0724 5120        ws2ifsl        (6db3276587b853bf886b69528fdb048c) C:\windows\system32\drivers\ws2ifsl.sys
08:25:09.0787 5120        ws2ifsl - ok
08:25:09.0818 5120        wscsvc          (6f5d49efe0e7164e03ae773a3fe25340) C:\windows\System32\wscsvc.dll
08:25:09.0880 5120        wscsvc - ok
08:25:09.0896 5120        WSearch - ok
08:25:10.0083 5120        wuauserv        (fc3ec24fce372c89423e015a2ac1a31e) C:\windows\system32\wuaueng.dll
08:25:10.0177 5120        wuauserv - ok
08:25:10.0333 5120        WudfPf          (e714a1c0354636837e20ccbf00888ee7) C:\windows\system32\drivers\WudfPf.sys
08:25:10.0395 5120        WudfPf - ok
08:25:10.0442 5120        WUDFRd          (1023ee888c9b47178c5293ed5336ab69) C:\windows\system32\DRIVERS\WUDFRd.sys
08:25:10.0504 5120        WUDFRd - ok
08:25:10.0582 5120        wudfsvc        (8d1e1e529a2c9e9b6a85b55a345f7629) C:\windows\System32\WUDFSvc.dll
08:25:10.0645 5120        wudfsvc - ok
08:25:10.0738 5120        WwanSvc        (ff2d745b560f7c71b31f30f4d49f73d2) C:\windows\System32\wwansvc.dll
08:25:10.0801 5120        WwanSvc - ok
08:25:10.0879 5120        MBR (0x1B8)    (2e5debb2116b3417023e0d6562d7ed07) \Device\Harddisk0\DR0
08:25:11.0440 5120        \Device\Harddisk0\DR0 - ok
08:25:11.0456 5120        MBR (0x1B8)    (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR1
08:25:11.0565 5120        \Device\Harddisk1\DR1 - ok
08:25:11.0565 5120        Boot (0x1200)  (21f9a82ddeb4df9cea3b7b9da55f8f8a) \Device\Harddisk0\DR0\Partition0
08:25:11.0565 5120        \Device\Harddisk0\DR0\Partition0 - ok
08:25:11.0596 5120        Boot (0x1200)  (1cf201412f0213464cb101bf59833b11) \Device\Harddisk0\DR0\Partition1
08:25:11.0596 5120        \Device\Harddisk0\DR0\Partition1 - ok
08:25:11.0628 5120        Boot (0x1200)  (f854311fe5e56e925d2359d3706f3093) \Device\Harddisk0\DR0\Partition2
08:25:11.0643 5120        \Device\Harddisk0\DR0\Partition2 - ok
08:25:11.0643 5120        Boot (0x1200)  (3b5e81e7d305a01fcf364730bd0fe86d) \Device\Harddisk1\DR1\Partition0
08:25:11.0659 5120        \Device\Harddisk1\DR1\Partition0 - ok
08:25:11.0659 5120        ============================================================
08:25:11.0659 5120        Scan finished
08:25:11.0659 5120        ============================================================
08:25:11.0674 5292        Detected object count: 2
08:25:11.0674 5292        Actual detected object count: 2
08:26:04.0730 5292        C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe - copied to quarantine
08:26:04.0730 5292        EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - User select action: Quarantine
08:26:04.0949 5292        C:\Program Files\ShadowExplorer\sesvc.exe - copied to quarantine
08:26:04.0949 5292        sesvc ( UnsignedFile.Multi.Generic ) - User select action: Quarantine

Leider habe ich die beiden gefundenen Files in Quarantäne gestellt anstatt sie unhebelligt zu lassen.
KastorPollux

cosinus 13.07.2012 16:03

ShadowExplorer und was von Epson - wirst du notfalls neu- oder nachinstallieren müssen

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

KastorPollux 13.07.2012 18:18

Hallo Cosinus,
hier ist der Combofix-Logfile:
[code]
Combofix Logfile:
Code:

ComboFix 12-07-13.03 - Hans 13.07.2012  18:38:40.1.2 - x86
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3005.2074 [GMT 2:00]
ausgeführt von:: c:\users\Hans\Desktop\ComboFix.exe
AV: McAfee  Anti-Virus und Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee  Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee  Anti-Virus und Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-06-13 bis 2012-07-13  ))))))))))))))))))))))))))))))
.
.
2012-07-13 16:47 . 2012-07-13 16:47        --------        d-----w-        c:\users\Ingeborg\AppData\Local\temp
2012-07-13 16:47 . 2012-07-13 16:47        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-07-13 06:26 . 2012-07-13 06:26        --------        d-----w-        C:\TDSSKiller_Quarantine
2012-07-12 16:22 . 2012-07-12 16:22        --------        d-----w-        C:\_OTL
2012-07-12 04:10 . 2012-06-02 08:16        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2012-07-12 04:10 . 2012-06-02 09:08        140920        ----a-w-        c:\program files\Internet Explorer\sqmapi.dll
2012-07-12 04:10 . 2012-06-02 08:22        194560        ----a-w-        c:\program files\Internet Explorer\ieproxy.dll
2012-07-12 04:10 . 2012-06-02 08:21        194048        ----a-w-        c:\program files\Internet Explorer\IEShims.dll
2012-07-12 04:10 . 2012-06-02 08:20        142848        ----a-w-        c:\windows\system32\ieUnatt.exe
2012-07-12 04:10 . 2012-06-02 08:33        1800192        ----a-w-        c:\windows\system32\jscript9.dll
2012-07-12 04:10 . 2012-06-02 08:25        1129472        ----a-w-        c:\windows\system32\wininet.dll
2012-07-12 04:09 . 2012-06-02 09:08        748664        ----a-w-        c:\program files\Internet Explorer\iexplore.exe
2012-07-12 04:09 . 2012-06-02 08:27        678912        ----a-w-        c:\program files\Internet Explorer\iedvtool.dll
2012-07-12 04:09 . 2012-06-02 08:26        387584        ----a-w-        c:\program files\Internet Explorer\jsdbgui.dll
2012-07-12 04:09 . 2012-06-02 08:25        1427968        ----a-w-        c:\windows\system32\inetcpl.cpl
2012-07-12 04:04 . 2012-06-12 02:40        2345984        ----a-w-        c:\windows\system32\win32k.sys
2012-07-11 20:28 . 2012-07-11 20:29        40776        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2012-07-11 20:27 . 2012-06-06 05:05        1019904        ----a-w-        c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 20:27 . 2012-06-06 05:05        352256        ----a-w-        c:\program files\Common Files\System\ado\msadomd.dll
2012-07-11 20:27 . 2012-06-06 05:03        805376        ----a-w-        c:\windows\system32\cdosys.dll
2012-07-11 20:27 . 2012-06-06 05:05        57344        ----a-w-        c:\program files\Common Files\System\ado\msador15.dll
2012-07-11 20:27 . 2012-06-06 05:05        212992        ----a-w-        c:\program files\Common Files\System\msadc\msadco.dll
2012-07-11 20:27 . 2012-06-06 05:05        143360        ----a-w-        c:\program files\Common Files\System\ado\msjro.dll
2012-07-11 20:27 . 2012-06-06 05:05        372736        ----a-w-        c:\program files\Common Files\System\ado\msadox.dll
2012-07-11 20:27 . 2012-06-06 05:05        1390080        ----a-w-        c:\windows\system32\msxml6.dll
2012-07-11 20:27 . 2012-06-06 05:05        1236992        ----a-w-        c:\windows\system32\msxml3.dll
2012-07-11 20:27 . 2010-06-26 03:24        2048        ----a-w-        c:\windows\system32\msxml3r.dll
2012-07-11 20:26 . 2012-06-02 04:40        369336        ----a-w-        c:\windows\system32\drivers\cng.sys
2012-07-11 20:26 . 2012-06-02 04:45        134000        ----a-w-        c:\windows\system32\drivers\ksecpkg.sys
2012-07-11 20:26 . 2012-06-02 04:39        219136        ----a-w-        c:\windows\system32\ncrypt.dll
2012-07-11 20:26 . 2012-06-02 04:40        225280        ----a-w-        c:\windows\system32\schannel.dll
2012-07-11 20:26 . 2012-06-02 04:45        67440        ----a-w-        c:\windows\system32\drivers\ksecdd.sys
2012-07-09 18:25 . 2012-07-11 13:31        --------        d-----w-        C:\TEMP
2012-07-09 18:01 . 2012-07-09 18:01        --------        d-----w-        c:\users\Hans\AppData\Roaming\JPEGsnoop
2012-07-09 17:38 . 2012-07-09 17:38        --------        d-----w-        c:\users\Hans\AppData\Roaming\www.shadowexplorer.com
2012-07-09 17:38 . 2012-07-09 17:38        --------        d-----w-        c:\program files\ShadowExplorer
2012-07-04 09:40 . 2012-07-04 09:40        --------        d-----w-        c:\program files\ESET
2012-06-25 14:04 . 2012-06-25 14:04        1394248        ----a-w-        c:\windows\system32\msxml4.dll
2012-06-25 07:34 . 2012-06-02 22:19        53784        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-25 07:34 . 2012-06-02 22:19        45080        ----a-w-        c:\windows\system32\wups2.dll
2012-06-25 07:34 . 2012-06-02 22:12        2422272        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-25 07:34 . 2012-06-02 22:19        1933848        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-25 07:33 . 2012-06-02 22:19        35864        ----a-w-        c:\windows\system32\wups.dll
2012-06-25 07:33 . 2012-06-02 22:19        577048        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-25 07:33 . 2012-06-02 22:12        88576        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-25 07:33 . 2012-06-02 13:19        171904        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-25 07:33 . 2012-06-02 13:12        33792        ----a-w-        c:\windows\system32\wuapp.exe
2012-06-23 19:43 . 2012-06-23 19:43        --------        d-----w-        c:\users\Hans\AppData\Roaming\Malwarebytes
2012-06-23 17:37 . 2012-04-07 11:26        2342400        ----a-w-        c:\windows\system32\msi.dll
2012-06-23 17:37 . 2012-04-26 04:45        58880        ----a-w-        c:\windows\system32\rdpwsx.dll
2012-06-23 17:37 . 2012-04-26 04:45        129536        ----a-w-        c:\windows\system32\rdpcorekmts.dll
2012-06-23 17:37 . 2012-04-26 04:41        8192        ----a-w-        c:\windows\system32\rdrmemptylst.exe
2012-06-23 17:37 . 2012-05-01 04:44        164352        ----a-w-        c:\windows\system32\profsvc.dll
2012-06-23 17:37 . 2012-04-24 04:36        140288        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-06-23 17:37 . 2012-04-24 04:36        1158656        ----a-w-        c:\windows\system32\crypt32.dll
2012-06-23 17:37 . 2012-04-24 04:36        103936        ----a-w-        c:\windows\system32\cryptnet.dll
2012-06-23 17:36 . 2012-04-28 03:17        183808        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-06-23 17:34 . 2012-06-23 17:34        --------        d-----w-        c:\users\Ingeborg\AppData\Roaming\Malwarebytes
2012-06-23 17:34 . 2012-06-23 17:34        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2012-06-23 17:34 . 2012-06-23 17:34        --------        d-----w-        c:\programdata\Malwarebytes
2012-06-23 17:34 . 2012-04-04 13:56        22344        ----a-w-        c:\windows\system32\drivers\mbam.sys
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-13 16:22 . 2012-04-28 15:49        426184        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-07-13 16:22 . 2011-05-16 04:24        70344        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-30 04:50 . 2012-05-30 04:50        163048        ----a-w-        c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10141.bin
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK]
@="{3c3f3c1a-9153-7c05-f938-622e7003894d}"
[HKEY_CLASSES_ROOT\CLSID\{3c3f3c1a-9153-7c05-f938-622e7003894d}]
2010-04-13 19:11        2872120        ----a-w-        c:\program files\McAfee Online Backup\MOBKshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK2]
@="{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}"
[HKEY_CLASSES_ROOT\CLSID\{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}]
2010-04-13 19:11        2872120        ----a-w-        c:\program files\McAfee Online Backup\MOBKshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK3]
@="{b4caf489-1eec-c617-49ad-8d7088598c06}"
[HKEY_CLASSES_ROOT\CLSID\{b4caf489-1eec-c617-49ad-8d7088598c06}]
2010-04-13 19:11        2872120        ----a-w-        c:\program files\McAfee Online Backup\MOBKshell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2011-07-21 718720]
"ChromeFrameHelper"="c:\users\Hans\AppData\Local\Google\Chrome\Application\20.0.1132.57\chrome_frame_helper.exe" [2012-07-10 96792]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-09-29 7744032]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-14 1541416]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-07-11 74752]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2011-08-24 651832]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-11-11 205336]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"ConnectionCenter"="c:\users\Hans\AppData\Local\Citrix\ICA Client\concentr.exe" [2011-04-25 305088]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-21 1318816]
"McPvTray_exe"="c:\program files\McAfee\MAT\McPvTray.exe" [2011-04-08 419904]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 StarMoney 7.0 OnlineUpdate;StarMoney 7.0 OnlineUpdate;c:\program files\StarMoney 7.0\ouservice\StarMoneyOnlineUpdate.exe [x]
R2 StarMoney 8.0 OnlineUpdate;StarMoney 8.0 OnlineUpdate;c:\program files\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 CompFilter;UVCCompositeFilter;c:\windows\system32\DRIVERS\lvbusflt.sys [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys [x]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 McPvDrv;McPvDrv Driver;c:\windows\system32\drivers\McPvDrv.sys [x]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [x]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x]
S1 MOBKFilter;MOBKFilter;c:\windows\system32\DRIVERS\MOBK.sys [x]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE [x]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [x]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [x]
S2 MOBKbackup;1%;c:\program files\McAfee Online Backup\MOBKbackup.exe [x]
S2 OberonGameConsoleService;Oberon Media Game Console service;c:\program files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe [x]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [x]
S2 Radio.fx;Radio.fx Server;c:\program files\Tobit Radio.fx\Server\rfx-server.exe [x]
S2 sesvc;ShadowExplorer Service;c:\program files\ShadowExplorer\sesvc.exe [x]
S2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 36018540
*Deregistered* - 36018540
*Deregistered* - mfeavfk01
.
Inhalt des "geplante Tasks" Ordners
.
2012-07-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-28 16:22]
.
2012-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 20:34]
.
2012-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 20:34]
.
2012-07-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1131658597-4005637612-88016806-1008Core.job
- c:\users\Hans\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-04 11:26]
.
2012-07-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1131658597-4005637612-88016806-1008UA.job
- c:\users\Hans\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-04 11:26]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
uInternet Settings,ProxyOverride = *.local
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 78.42.43.62 192.168.0.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
AddRemove-SmartDraw VP - c:\smartd~1\Uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(5784)
c:\program files\McAfee Online Backup\MOBKshell.dll
.
Zeit der Fertigstellung: 2012-07-13  18:49:17
ComboFix-quarantined-files.txt  2012-07-13 16:49
.
Vor Suchlauf: 10 Verzeichnis(se), 86.486.671.360 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 86.383.177.728 Bytes frei
.
- - End Of File - - E7DE66F63D9FA520E072DF46AE4EDC51

--- --- ---

Kann ich die TDSS quarantänisierten files nicht zurückbenennen und an den alten Ort zurückkopieren?
Vielen Dank
KastorPollux

cosinus 13.07.2012 21:41

Mir ist keine einfach Möglichkeit bekannt, wie man Elemente aus der TDSS-Killer-Q einfach per Knopfdruck recovern kann. Ich hoffe dafür gibt es in zukunfigen Versionen mal so eine Funktion. Bis dahin heißt es einfach die Anleitungen richtig lesen und umsetzen!

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

KastorPollux 14.07.2012 14:45

Liste der Anhänge anzeigen (Anzahl: 1)
Hallo Cosinus,
Es folgen der logfile von Gmer (als Anhang) und OSAM. aswMBR ist 3 mal an derselben Stelle abgestürzt. Einen Screenshot mit der Fehlermeldung habe ich angehängt.
OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 13:39:31 on 14.07.2012

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 32-bit
Default Browser: Microsoft Corporation Internet Explorer 9.00.8112.16421

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-1131658597-4005637612-88016806-1008Core.job" - "Google Inc." - C:\Users\Hans\AppData\Local\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-1131658597-4005637612-88016806-1008UA.job" - "Google Inc." - C:\Users\Hans\AppData\Local\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\windows\system32\FlashPlayerCPLApp.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\MLCFG32.CPL
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"catchme" (catchme) - ? - C:\Users\Hans\AppData\Local\Temp\catchme.sys  (File not found)
"Citrix USB Monitor Driver" (ctxusbm) - "Citrix Systems, Inc." - C:\windows\System32\DRIVERS\ctxusbm.sys
"FssFltr" (fssfltr) - "Microsoft Corporation" - C:\windows\System32\DRIVERS\fssfltr.sys
"Huawei MobileBroadband USB PNP Device" (ew_hwusbdev) - ? - C:\windows\System32\DRIVERS\ew_hwusbdev.sys  (File not found)
"huawei_cdcacm" (huawei_cdcacm) - ? - C:\windows\System32\DRIVERS\ew_jucdcacm.sys  (File not found)
"huawei_enumerator" (huawei_enumerator) - ? - C:\windows\System32\DRIVERS\ew_jubusenum.sys  (File not found)
"kxdyikow" (kxdyikow) - ? - C:\Users\Hans\AppData\Local\Temp\kxdyikow.sys  (Hidden registry entry, rootkit activity | File not found)
"MBAMSwissArmy" (MBAMSwissArmy) - "Malwarebytes Corporation" - C:\windows\system32\drivers\mbamswissarmy.sys
"McAfee Inc." (mfeavfk01) - ? - C:\windows\system32\drivers\mfeavfk01.sys  (File not found)
"MOBKFilter" (MOBKFilter) - "Mozy, Inc." - C:\windows\System32\DRIVERS\MOBK.sys
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\windows\System32\Drivers\PxHelp20.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Users\Hans\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll
{3EF5086B-5478-4598-A054-786C45D75692} "McInternetProtocolRoot Class" - "McAfee, Inc." - c:\progra~1\mcafee\msc\mcsniepl.dll
{807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{5513F07E-936B-4E52-9B00-067394E91CC5} "McAfee SACore Protocol Handler" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
{5513F07E-936B-4E52-9B00-067394E91CC5} "McAfee SACore Protocol Handler" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} "Arbeitsbereiche" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{D66DC78C-4F61-447F-942B-3FB6980118CF} "CInfoTipShellExt Class" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\VISSHE.DLL
{0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{506F4668-F13E-4AA1-BB04-B43203AB3CC0} "ImageExtractorShellExt Class" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\VISSHE.DLL
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{781bca65-20ed-8f6a-368f-b523ec4f51b2} "McAfee Online Backup" - "McAfee, Inc." - C:\Program Files\McAfee Online Backup\MOBKshell.dll
{3c3f3c1a-9153-7c05-f938-622e7003894d} "McAfee Online Backup Shell-Erweiterungen" - "McAfee, Inc." - C:\Program Files\McAfee Online Backup\MOBKshell.dll
{e6ea1d7d-144e-b977-98c4-84c53c1a69d0} "McAfee Online Backup Shell-Erweiterungen Icon Overlay 2" - "McAfee, Inc." - C:\Program Files\McAfee Online Backup\MOBKshell.dll
{b4caf489-1eec-c617-49ad-8d7088598c06} "McAfee Online Backup Shell-Erweiterungen Icon Overlay 3" - "McAfee, Inc." - C:\Program Files\McAfee Online Backup\MOBKshell.dll
{AF6FB31C-95D0-4A0E-8AFE-099969D8B689} "McAfee-Depots" - "McAfee, Inc." - c:\progra~1\mcafee\mat\mcpvns.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{0875DCB6-C686-4243-9432-ADCCF0B9F2D7} "Microsoft OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONFILTER.DLL
{00020D75-0000-0000-C000-000000000046} "Microsoft Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\MLSHEXT.DLL
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\OLKFSTUB.DLL
{6F5C0F40-1419-4DC8-8D2F-D5EC5FCF07AB} "Sprint.ExplorerIntegration.9" - "ABBYY" - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Integration\SprintIntegration.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )-----
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} "McAfee SiteAdvisor Toolbar" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} "Java Plug-in 1.6.0_18" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{7530BFB8-7293-4D34-9923-61A11451AFC5} "OnlineScanner Control" - "ESET" - C:\PROGRA~1\ESET\ESETON~1\ONLINE~1.OCX / hxxp://download.eset.com/special/eos/OnlineScanner.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? -  (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "In Blog veröffentlichen" - "Microsoft Corporation" - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
{FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} "Easy Photo Print" - "SEIKO EPSON CORPORATION / CyCom Technology Corp." - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} "McAfee SiteAdvisor Toolbar" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} "Easy Photo Print" - "SEIKO EPSON CORPORATION / CyCom Technology Corp." - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\ssv.dll
{B164E929-A1B6-4A06-B104-2CD0E90A88FF} "McAfee SiteAdvisor BHO" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
{B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} "scriptproxy" - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120624094824.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID-Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{5C255C8A-E604-49b4-9D64-90988571CECB} "{5C255C8A-E604-49b4-9D64-90988571CECB}" - ? -  (File not found | COM-object registry key not found)

[LSA Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )-----
"Security Packages" - "Microsoft Corporation" - C:\windows\system32\livessp.dll

[Logon]
-----( %APPDATA%\Xdtsrk )-----
"desktop.ini" - ? - C:\Users\Hans\AppData\Roaming\Xdtsrk\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"ChromeFrameHelper" - "Google Inc." - "C:\Users\Hans\AppData\Local\Google\Chrome\Application\20.0.1132.57\chrome_frame_helper.exe" --startup
"OfficeSyncProcess" - "Microsoft Corporation" - "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"BCSSync" - "Microsoft Corporation" - "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
"ConnectionCenter" - "Citrix Systems, Inc." - "C:\Users\Hans\AppData\Local\Citrix\ICA Client\concentr.exe" /startup
"EEventManager" - "SEIKO EPSON CORPORATION" - "C:\Program Files\Epson Software\Event Manager\EEventManager.exe"
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"LWS" - "Logitech Inc." - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
"McPvTray_exe" - "McAfee, Inc." - "C:\Program Files\McAfee\MAT\McPvTray.exe"
"mcui_exe" - "McAfee, Inc." - "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
"PMBVolumeWatcher" - "Sony Corporation" - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"WinampAgent" - "Nullsoft, Inc." - "C:\Program Files\Winamp\winampa.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"EpsonNet Print Port" - "SEIKO EPSON CORPORATION" - C:\windows\system32\enppmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"1%" (MOBKbackup) - "McAfee, Inc." - C:\Program Files\McAfee Online Backup\MOBKbackup.exe
"ABBYY FineReader 9.0 Sprint Licensing Service" (ABBYY.Licensing.FineReader.Sprint.9.0) - "ABBYY" - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"EpsonBidirectionalService" (EpsonBidirectionalService) - "SEIKO EPSON CORPORATION" - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"McAfee Anti-Spam Service" (MSK80Service) - "McAfee, Inc." - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
"McAfee Firewall Core Service" (mfefire) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
"McAfee McShield" (McShield) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
"McAfee Network Agent" (McNASvc) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
"McAfee Personal Firewall Service" (McMPFSvc) - "McAfee, Inc." - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
"McAfee Proxy Service" (McProxy) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
"McAfee Scanner" (McODS) - "McAfee, Inc." - C:\Program Files\McAfee\VirusScan\mcods.exe
"McAfee Services" (mcmscsvc) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
"McAfee SiteAdvisor Service" (McAfee SiteAdvisor Service) - "McAfee, Inc." - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
"McAfee Validation Trust Protection Service" (mfevtp) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
"McAfee VirusScan Announcer" (McNaiAnn) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft SharePoint Workspace Audit Service" (Microsoft SharePoint Workspace Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
"Oberon Media Game Console service" (OberonGameConsoleService) - ? - C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe
"Office  Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"PMBDeviceInfoProvider" (PMBDeviceInfoProvider) - "Sony Corporation" - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
"Radio.fx Server" (Radio.fx) - ? - C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe
"ShadowExplorer Service" (sesvc) - "www.shadowexplorer.com" - C:\Program Files\ShadowExplorer\sesvc.exe
"SQL Server (MSSMLBIZ)" (MSSQL$MSSMLBIZ) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
"SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
"SQL Server-Browser" (SQLBrowser) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
"SQL Server-Startdienst für Business Contact Manager" (BcmSqlStartupSvc) - "Microsoft Corporation" - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
"StarMoney 7.0 OnlineUpdate" (StarMoney 7.0 OnlineUpdate) - "Star Finanz - Software Entwicklung und Vertriebs GmbH" - C:\Program Files\StarMoney 7.0\ouservice\StarMoneyOnlineUpdate.exe
"StarMoney 8.0 OnlineUpdate" (StarMoney 8.0 OnlineUpdate) - "Star Finanz - Software Entwicklung und Vertriebs GmbH" - C:\Program Files\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe
"Windows Live Family Safety-Dienst" (fsssvc) - "Microsoft Corporation" - C:\Program Files\Windows Live\Family Safety\fsssvc.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
"WindowsLive Local NSP" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
"WindowsLive NSP" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL

===[ Logfile end ]=========================================[ Logfile end ]===

Vielen Dank
KastorPollux

cosinus 14.07.2012 15:56

zu aswMBR gab es extra ganz unten von mir deswegen einen Hinweis!

KastorPollux 14.07.2012 17:56

Danke für den Hinweis,
ich dachte ich könnte lesen.
Hier folgt der LOGfile:
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-14 18:48:27
-----------------------------
18:48:27.177    OS Version: Windows 6.1.7601 Service Pack 1
18:48:27.177    Number of processors: 2 586 0x170A
18:48:27.177    ComputerName: INGEBORG-PC  UserName: Hans
18:48:27.770    Initialize success
18:48:32.843    AVAST engine defs: 12071400
18:49:19.928    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:49:19.928    Disk 0 Vendor: WDC_WD32 11.0 Size: 305245MB BusType: 3
18:49:20.006    Disk 0 MBR read successfully
18:49:20.006    Disk 0 MBR scan
18:49:20.021    Disk 0 unknown MBR code
18:49:20.037    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        15360 MB offset 2048
18:49:20.053    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 31459328
18:49:20.068    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      144890 MB offset 31664128
18:49:20.099    Disk 0 Partition 4 00    07    HPFS/NTFS NTFS        60276 MB offset 328398848
18:49:20.115    Disk 0 scanning sectors +451844096
18:49:20.177    Disk 0 scanning C:\windows\system32\drivers
18:49:32.018    Service scanning
18:50:03.156    Modules scanning
18:50:11.798    Disk 0 trace - called modules:
18:50:11.829    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys halmacpi.dll
18:50:11.845    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x871b6030]
18:50:11.845    3 CLASSPNP.SYS[8c40459e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x86341028]
18:50:11.845    Scan finished successfully
18:50:35.276    Disk 0 MBR has been saved successfully to "C:\Users\Hans\Desktop\MBR.dat"
18:50:35.292    The log file has been saved successfully to "C:\Users\Hans\Desktop\aswMBR.txt"

Danke
KastorPollux

cosinus 14.07.2012 21:45

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.
Mach den Fix auch dann nicht, wenn du zB mit TrueCrypt oder anderen Verschlüsselungsprogrammen eine Vollverschlüsselung der Windowspartition bzw. gesamten Festplatte hast


Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!

Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

KastorPollux 15.07.2012 09:08

Hallo Cosinus,
hier folgt das LOG:
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-15 09:51:14
-----------------------------
09:51:14.739    OS Version: Windows 6.1.7601 Service Pack 1
09:51:14.739    Number of processors: 2 586 0x170A
09:51:14.754    ComputerName: INGEBORG-PC  UserName: Hans
09:51:16.143    Initialize success
09:51:24.504    AVAST engine defs: 12071400
09:51:37.405    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
09:51:37.405    Disk 0 Vendor: WDC_WD32 11.0 Size: 305245MB BusType: 3
09:51:37.452    Disk 0 MBR read successfully
09:51:37.452    Disk 0 MBR scan
09:51:37.467    Disk 0 Windows 7 default MBR code
09:51:37.483    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        15360 MB offset 2048
09:51:37.514    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 31459328
09:51:37.530    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      144890 MB offset 31664128
09:51:37.577    Disk 0 Partition 4 00    07    HPFS/NTFS NTFS        60276 MB offset 328398848
09:51:37.592    Disk 0 scanning sectors +451844096
09:51:37.701    Disk 0 scanning C:\windows\system32\drivers
09:51:53.475    Service scanning
09:52:31.509    Modules scanning
09:52:42.336    Disk 0 trace - called modules:
09:52:42.367    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys halmacpi.dll
09:52:42.383    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x871b77f0]
09:52:42.383    3 CLASSPNP.SYS[8c6ef59e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x86342028]
09:52:42.399    Scan finished successfully
09:53:32.272    Disk 0 MBR has been saved successfully to "C:\Users\Hans\Desktop\MBR.dat"
09:53:32.288    The log file has been saved successfully to "C:\Users\Hans\Desktop\aswMBR2.txt"

Danke
KastorPollux

cosinus 15.07.2012 16:54

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

KastorPollux 15.07.2012 21:44

Hallo Cosinus,
hier sind ide beiden LOGS:
Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.07.15.09

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Hans :: INGEBORG-PC [Administrator]

15.07.2012 18:41:29
mbam-log-2012-07-15 (18-41-29).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 386644
Laufzeit: 1 Stunde(n), 40 Minute(n), 20 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 07/15/2012 at 10:26 PM

Application Version : 5.5.1006

Core Rules Database Version : 8902
Trace Rules Database Version: 6714

Scan type      : Complete Scan
Total Scan Time : 01:27:33

Operating System Information
Windows 7 Home Premium 32-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned      : 882
Memory threats detected  : 0
Registry items scanned    : 37555
Registry threats detected : 0
File items scanned        : 138600
File threats detected    : 295

Adware.Tracking Cookie
        C:\USERS\HANS\AppData\Roaming\Microsoft\Windows\Cookies\Low\W5DDCSIF.txt [ Cookie:hans@www.google.de/accounts ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\OL6E3XXR.txt [ Cookie:ingeborg@c.atdmt.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\ingeborg@content.yieldmanager[1].txt [ Cookie:ingeborg@content.yieldmanager.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\ingeborg@wasistsocialmedia[1].txt [ Cookie:ingeborg@wasistsocialmedia.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@tracking.hannoversche[1].txt [ Cookie:ingeborg@tracking.hannoversche.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\X5IX4DAL.txt [ Cookie:ingeborg@doubleclick.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\PMMMZ09I.txt [ Cookie:ingeborg@interclick.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@mediamarkt[2].txt [ Cookie:ingeborg@mediamarkt.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@ad2.adfarm1.adition[1].txt [ Cookie:ingeborg@ad2.adfarm1.adition.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZWZY1PBZ.txt [ Cookie:ingeborg@zanox-affiliate.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@vodafonegroup.122.2o7[1].txt [ Cookie:ingeborg@vodafonegroup.122.2o7.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@rotator.adjuggler[2].txt [ Cookie:ingeborg@rotator.adjuggler.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\U3KXTB6O.txt [ Cookie:ingeborg@media6degrees.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@swrmediathek[2].txt [ Cookie:ingeborg@swrmediathek.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@ads.pointroll[1].txt [ Cookie:ingeborg@ads.pointroll.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@e-2dj6whk4kpd5igp.stats.esomniture[2].txt [ Cookie:ingeborg@e-2dj6whk4kpd5igp.stats.esomniture.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\N4A2SCW3.txt [ Cookie:ingeborg@track.effiliation.com/servlet/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@adbrite[2].txt [ Cookie:ingeborg@adbrite.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\JCV8OELI.txt [ Cookie:ingeborg@ad2.adfarm1.adition.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@www.piloh[1].txt [ Cookie:ingeborg@www.piloh.de/stats/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\WZ0FRR2M.txt [ Cookie:ingeborg@adfarm1.adition.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\DNNUBB6T.txt [ Cookie:ingeborg@google.com/accounts/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZBF1HAXD.txt [ Cookie:ingeborg@fastclick.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\F04Q6XNL.txt [ Cookie:ingeborg@tracking.mindshare.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\JM17ZN1I.txt [ Cookie:ingeborg@tradedoubler.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\CLYC46H7.txt [ Cookie:ingeborg@stat.dealtime.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@clkads[3].txt [ Cookie:ingeborg@clkads.com/adServe/static/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@collective-media[1].txt [ Cookie:ingeborg@collective-media.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\WIKFNZYG.txt [ Cookie:ingeborg@apmebf.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@pointroll[2].txt [ Cookie:ingeborg@pointroll.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@de.sitestat[1].txt [ Cookie:ingeborg@de.sitestat.com/sport1/sport1-de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\LUNT2I62.txt [ Cookie:ingeborg@ad4.adfarm1.adition.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\GUSL4C7K.txt [ Cookie:ingeborg@traffictrack.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@chitika[2].txt [ Cookie:ingeborg@chitika.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\P7GM4CSL.txt [ Cookie:ingeborg@smartadserver.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\DJKVAPV2.txt [ Cookie:ingeborg@statse.webtrendslive.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\RB6GOKYR.txt [ Cookie:ingeborg@imrworldwide.com/cgi-bin ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@ad.adnet[1].txt [ Cookie:ingeborg@ad.adnet.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\O1YKV2QV.txt [ Cookie:ingeborg@eas.apm.emediate.eu/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@stats.paypal[2].txt [ Cookie:ingeborg@stats.paypal.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@microsoftinternetexplorer.112.2o7[1].txt [ Cookie:ingeborg@microsoftinternetexplorer.112.2o7.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\UIMR7O4C.txt [ Cookie:ingeborg@paypal.112.2o7.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@ads.quartermedia[2].txt [ Cookie:ingeborg@ads.quartermedia.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@adx.chip[2].txt [ Cookie:ingeborg@adx.chip.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\TYVVVULH.txt [ Cookie:ingeborg@webmasterplan.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\2YJ9N8MG.txt [ Cookie:ingeborg@www.active-tracking.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@ru4[1].txt [ Cookie:ingeborg@ru4.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@www.brands4friends[3].txt [ Cookie:ingeborg@www.brands4friends.de/account/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@cmpmedica.112.2o7[1].txt [ Cookie:ingeborg@cmpmedica.112.2o7.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\98NTAK5J.txt [ Cookie:ingeborg@serving-sys.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\K4Q7OL3U.txt [ Cookie:ingeborg@ad.zanox.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ILFY3F1H.txt [ Cookie:ingeborg@invitemedia.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@srbg[2].txt [ Cookie:ingeborg@srbg.de/stats/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@zieltrack[1].txt [ Cookie:ingeborg@zieltrack.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@asco.122.2o7[1].txt [ Cookie:ingeborg@asco.122.2o7.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@cdn5.specificclick[1].txt [ Cookie:ingeborg@cdn5.specificclick.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\7K5RT0A9.txt [ Cookie:ingeborg@tomtailor.dyntracker.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\GLVWD0TN.txt [ Cookie:ingeborg@im.banner.t-online.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@e-2dj6wjmysjajihp.stats.esomniture[2].txt [ Cookie:ingeborg@e-2dj6wjmysjajihp.stats.esomniture.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@adlegend[2].txt [ Cookie:ingeborg@adlegend.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@tripod[2].txt [ Cookie:ingeborg@tripod.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@c.gigcount[1].txt [ Cookie:ingeborg@c.gigcount.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\P7ZB50K6.txt [ Cookie:ingeborg@pg2.solution.weborama.fr/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\0ENBU791.txt [ Cookie:ingeborg@adtech.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\724UYAMB.txt [ Cookie:ingeborg@revsci.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@rw.motorpresse-statistik[1].txt [ Cookie:ingeborg@rw.motorpresse-statistik.de/track/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\IFGKWGWH.txt [ Cookie:ingeborg@de.at.atwola.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\5HJHFH1J.txt [ Cookie:ingeborg@track.adform.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\311841DS.txt [ Cookie:ingeborg@stat.onestat.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@revsci[1].txt [ Cookie:ingeborg@revsci.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@pro-market[2].txt [ Cookie:ingeborg@pro-market.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@revenue[2].txt [ Cookie:ingeborg@revenue.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@microsoftsto.112.2o7[1].txt [ Cookie:ingeborg@microsoftsto.112.2o7.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@bizrate[3].txt [ Cookie:ingeborg@bizrate.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\H6J0GBB9.txt [ Cookie:ingeborg@wm.wiredminds.de/track/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\S3CO18M3.txt [ Cookie:ingeborg@ad1.adfarm1.adition.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\M3QTJWBN.txt [ Cookie:ingeborg@ad.dyntracker.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@liveperson[3].txt [ Cookie:ingeborg@liveperson.net/hc/LPneimanmarcus ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\VRPB6AYT.txt [ Cookie:ingeborg@adform.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@sleep-tracker[2].txt [ Cookie:ingeborg@sleep-tracker.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@w00tpublishers.wootmedia[1].txt [ Cookie:ingeborg@w00tpublishers.wootmedia.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@tracking.klicktel[2].txt [ Cookie:ingeborg@tracking.klicktel.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@s3.trafficmaxx[1].txt [ Cookie:ingeborg@s3.trafficmaxx.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@www.zieltracker[2].txt [ Cookie:ingeborg@www.zieltracker.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\EKDTIDNZ.txt [ Cookie:ingeborg@tracking.quisma.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@de.sitestat[2].txt [ Cookie:ingeborg@de.sitestat.com/sport1/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@www1.addfreestats[1].txt [ Cookie:ingeborg@www1.addfreestats.com/cgi-bin ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@nextag[1].txt [ Cookie:ingeborg@nextag.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@de.sitestat[3].txt [ Cookie:ingeborg@de.sitestat.com/sueddeutsche/sueddeutsche/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@himedia.individuad[2].txt [ Cookie:ingeborg@himedia.individuad.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\MFY0ROX4.txt [ Cookie:ingeborg@amazon-adsystem.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@dealtime[1].txt [ Cookie:ingeborg@dealtime.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\PR19NEK4.txt [ Cookie:ingeborg@lucidmedia.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@clicks.pangora[2].txt [ Cookie:ingeborg@clicks.pangora.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@wasistsocialmedia[1].txt [ Cookie:ingeborg@wasistsocialmedia.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@de.sitestat[4].txt [ Cookie:ingeborg@de.sitestat.com/is24/is24/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\VUXY79NG.txt [ Cookie:ingeborg@content.yieldmanager.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@fantasystats[1].txt [ Cookie:ingeborg@fantasystats.info/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@microsoftwindows.112.2o7[1].txt [ Cookie:ingeborg@microsoftwindows.112.2o7.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@keyword-advertising.web[1].txt [ Cookie:ingeborg@keyword-advertising.web.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@microsoftmachinetranslation.112.2o7[1].txt [ Cookie:ingeborg@microsoftmachinetranslation.112.2o7.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\4PWA1GYY.txt [ Cookie:ingeborg@accounts.google.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\R9SJ2CFV.txt [ Cookie:ingeborg@yieldmanager.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\6RRD077S.txt [ Cookie:ingeborg@frontlinegmbh.122.2o7.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@de.sitestat[7].txt [ Cookie:ingeborg@de.sitestat.com/ing-diba/de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@ad.adition[2].txt [ Cookie:ingeborg@ad.adition.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\XOA1MURA.txt [ Cookie:ingeborg@yadro.ru/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@adxpose[2].txt [ Cookie:ingeborg@adxpose.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\B9AKUKSC.txt [ Cookie:ingeborg@horyzon-media.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\B0F0JU7C.txt [ Cookie:ingeborg@forexyard.advertserve.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\FNXVVI39.txt [ Cookie:ingeborg@www.google.de/accounts ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@anrtx.tacoda[1].txt [ Cookie:ingeborg@anrtx.tacoda.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ANMW0KCP.txt [ Cookie:ingeborg@tracker.citizenhawk.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\SJSY8DCA.txt [ Cookie:ingeborg@estat.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\T734NYAJ.txt [ Cookie:ingeborg@histats.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@ad.adserver01[1].txt [ Cookie:ingeborg@ad.adserver01.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\0M2CBYJW.txt [ Cookie:ingeborg@www.burstnet.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\P06W0H5L.txt [ Cookie:ingeborg@e-2dj6aelosjc5ccp.stats.esomniture.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\F84DQIBL.txt [ Cookie:ingeborg@www.zanox-affiliate.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZNPP1K16.txt [ Cookie:ingeborg@bestwestern.solution.weborama.fr/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\5BASS1ZV.txt [ Cookie:ingeborg@track.webtrekk.de/565556556123999/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\U8MQNQRF.txt [ Cookie:ingeborg@deutschepostag.112.2o7.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\EA92MCUY.txt [ Cookie:ingeborg@studivz.adfarm1.adition.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\YOYZNXRH.txt [ Cookie:ingeborg@eyewonder.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\AWS255T1.txt [ Cookie:ingeborg@at.atwola.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\97YNQJFT.txt [ Cookie:ingeborg@ar.atwola.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\X9JY76RR.txt [ Cookie:ingeborg@guj.122.2o7.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\LQIDO06Y.txt [ Cookie:ingeborg@kantarmedia.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\JEOLS65D.txt [ Cookie:ingeborg@www.google.com/settings/ads/preferences/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@de.sitestat[10].txt [ Cookie:ingeborg@de.sitestat.com/ndr/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\4T6M281Q.txt [ Cookie:ingeborg@uk.at.atwola.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\EVH71VZ7.txt [ Cookie:ingeborg@unitymedia.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@insightexpressai[1].txt [ Cookie:ingeborg@insightexpressai.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@webstats.usz[1].txt [ Cookie:ingeborg@webstats.usz.ch/dcskr604d100008yvtp08umg1_4m8p ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\O5FEZYL2.txt [ Cookie:ingeborg@labelfinder.style.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\R6I8B94H.txt [ Cookie:ingeborg@eas4.emediate.eu/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@ads.mikinimedia[1].txt [ Cookie:ingeborg@ads.mikinimedia.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\TVZI0TT5.txt [ Cookie:ingeborg@www.google.com/accounts ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\5RDO2H2K.txt [ Cookie:ingeborg@e-2dj6wnkoglajsgo.stats.esomniture.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@de.sitestat[8].txt [ Cookie:ingeborg@de.sitestat.com/sueddeutscher/stuttgarter-zeitung/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\39U7KU8K.txt [ Cookie:ingeborg@www4.smartadserver.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\84NVPLFF.txt [ Cookie:ingeborg@specificclick.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ME44MQCE.txt [ Cookie:ingeborg@www.googleadservices.com/pagead/conversion/1070624563/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\6Q0HORN6.txt [ Cookie:ingeborg@conrad.122.2o7.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\ingeborg@liveperson[1].txt [ Cookie:ingeborg@liveperson.net/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\11A8XT9V.txt [ Cookie:ingeborg@moviepilot.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\Z6BPVIO1.txt [ Cookie:ingeborg@adserver.kino-zeit.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\EI00H0S3.txt [ Cookie:ingeborg@www.moviepilot.de/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\WBMHSFJK.txt [ Cookie:ingeborg@liveperson.net/hc/10599399 ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\TPHCTS7S.txt [ Cookie:ingeborg@bs.serving-sys.com/ ]
        C:\USERS\INGEBORG\AppData\Roaming\Microsoft\Windows\Cookies\Low\L5BAH08O.txt [ Cookie:ingeborg@ww251.smartadserver.com/ ]
        C:\USERS\INGEBORG\Cookies\OL6E3XXR.txt [ Cookie:ingeborg@c.atdmt.com/ ]
        C:\USERS\INGEBORG\Cookies\ingeborg@content.yieldmanager[1].txt [ Cookie:ingeborg@content.yieldmanager.com/ ]
        C:\USERS\INGEBORG\Cookies\ingeborg@wasistsocialmedia[1].txt [ Cookie:ingeborg@wasistsocialmedia.de/ ]
        .doubleclick.net [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.zanox.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad1.adfarm1.adition.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adfarm1.adition.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tradefx.advertserve.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad3.adfarm1.adition.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad2.adfarm1.adition.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.counter-go.de [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.adserver01.de [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.mlsat02.de [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .specificclick.net [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adviva.net [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\USERS\HANS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@ADVIVA[1].TXT [ /ADVIVA ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@AD4.ADFARM1.ADITION[2].TXT [ /AD4.ADFARM1.ADITION ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@ATDMT[2].TXT [ /ATDMT ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@ADBRITE[1].TXT [ /ADBRITE ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@AT.ATWOLA[2].TXT [ /AT.ATWOLA ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@IM.BANNER.T-ONLINE[2].TXT [ /IM.BANNER.T-ONLINE ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@MEDIAMARKT[2].TXT [ /MEDIAMARKT ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@AD.YIELDMANAGER[2].TXT [ /AD.YIELDMANAGER ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@WWW.GOOGLEADSERVICES[1].TXT [ /WWW.GOOGLEADSERVICES ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@ADFARM1.ADITION[1].TXT [ /ADFARM1.ADITION ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@ADFARM1.ADITION[2].TXT [ /ADFARM1.ADITION ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@ATDMT[1].TXT [ /ATDMT ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@ADXPOSE[1].TXT [ /ADXPOSE ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@ADVERTISING[1].TXT [ /ADVERTISING ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@TRACKING.QUISMA[1].TXT [ /TRACKING.QUISMA ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@AD.YIELDMANAGER[1].TXT [ /AD.YIELDMANAGER ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@REVSCI[2].TXT [ /REVSCI ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@AD1.ADFARM1.ADITION[2].TXT [ /AD1.ADFARM1.ADITION ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@TACODA.AT.ATWOLA[2].TXT [ /TACODA.AT.ATWOLA ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@AD3.ADFARM1.ADITION[1].TXT [ /AD3.ADFARM1.ADITION ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@CONTENT.YIELDMANAGER[2].TXT [ /CONTENT.YIELDMANAGER ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@CONTENT.YIELDMANAGER[1].TXT [ /CONTENT.YIELDMANAGER ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@DOUBLECLICK[1].TXT [ /DOUBLECLICK ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@DE.AT.ATWOLA[1].TXT [ /DE.AT.ATWOLA ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@EAS.APM.EMEDIATE[2].TXT [ /EAS.APM.EMEDIATE ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@DOUBLECLICK[2].TXT [ /DOUBLECLICK ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@FASTCLICK[1].TXT [ /FASTCLICK ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@IMRWORLDWIDE[2].TXT [ /IMRWORLDWIDE ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@INVITEMEDIA[1].TXT [ /INVITEMEDIA ]
        C:\USERS\HANS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANS@XITI[1].TXT [ /XITI ]
        .apmebf.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad1.adfarm1.adition.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad3.adfarm1.adition.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tradefx.advertserve.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad2.adfarm1.adition.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\INGEBORG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\INGEBORG@CONTENT.YIELDMANAGER[3].TXT [ /CONTENT.YIELDMANAGER ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\INGEBORG@CONTENT.YIELDMANAGER[2].TXT [ /CONTENT.YIELDMANAGER ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\INGEBORG@AD.YIELDMANAGER[3].TXT [ /AD.YIELDMANAGER ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\INGEBORG@AD.YIELDMANAGER[1].TXT [ /AD.YIELDMANAGER ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@SONYEUROPE.112.2O7[1].TXT [ /SONYEUROPE.112.2O7 ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@XITI[2].TXT [ /XITI ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@BIZRATE[1].TXT [ /BIZRATE ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@AD.WEB.BAZ[1].TXT [ /AD.WEB.BAZ ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ADSERVER.YOPI[1].TXT [ /ADSERVER.YOPI ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@DATA.COREMETRICS[1].TXT [ /DATA.COREMETRICS ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@MEDIAPLEX[2].TXT [ /MEDIAPLEX ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@XITI[1].TXT [ /XITI ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ICE.112.2O7[1].TXT [ /ICE.112.2O7 ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@SERVE.ADVERTONIC[2].TXT [ /SERVE.ADVERTONIC ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ADS.MYSWITZERLAND[1].TXT [ /ADS.MYSWITZERLAND ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@TRACK.EFFILIATION[1].TXT [ /TRACK.EFFILIATION ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@SERVING-SYS[2].TXT [ /SERVING-SYS ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@WWW.GOOGLEADSERVICES[9].TXT [ /WWW.GOOGLEADSERVICES ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ADS.MEDIENHAUS[1].TXT [ /ADS.MEDIENHAUS ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ATDMT[3].TXT [ /ATDMT ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@REALMEDIA[1].TXT [ /REALMEDIA ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ADECN[1].TXT [ /ADECN ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ADVERTISING[1].TXT [ /ADVERTISING ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@KABELBW.112.2O7[1].TXT [ /KABELBW.112.2O7 ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ZBOX.ZANOX[2].TXT [ /ZBOX.ZANOX ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@APMEBF[2].TXT [ /APMEBF ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ADS.PUBMATIC[2].TXT [ /ADS.PUBMATIC ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@DOUBLECLICK[2].TXT [ /DOUBLECLICK ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@CASALEMEDIA[2].TXT [ /CASALEMEDIA ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ADFARM1.ADITION[1].TXT [ /ADFARM1.ADITION ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@EHG-ARTNETWORLDWIDE.HITBOX[2].TXT [ /EHG-ARTNETWORLDWIDE.HITBOX ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ADS.AD4GAME[2].TXT [ /ADS.AD4GAME ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@RAINBOWMEDIA.122.2O7[1].TXT [ /RAINBOWMEDIA.122.2O7 ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@WEBSTATS.USZ[3].TXT [ /WEBSTATS.USZ ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@GENERALTRACKING[1].TXT [ /GENERALTRACKING ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@CONTENT.YIELDMANAGER[1].TXT [ /CONTENT.YIELDMANAGER ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@AD2.ADFARM1.ADITION[2].TXT [ /AD2.ADFARM1.ADITION ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@CLICKBANK[1].TXT [ /CLICKBANK ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@TRACKER.ISSUU[1].TXT [ /TRACKER.ISSUU ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ATDMT[1].TXT [ /ATDMT ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ADS.CREATIVE-SERVING[2].TXT [ /ADS.CREATIVE-SERVING ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ADFARM1.ADITION[2].TXT [ /ADFARM1.ADITION ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ADS.123RECHT[1].TXT [ /ADS.123RECHT ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@NEXTAG[2].TXT [ /NEXTAG ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ZEDO[2].TXT [ /ZEDO ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@HITBOX[2].TXT [ /HITBOX ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@ADS.IMMOBILIENSCOUT24[1].TXT [ /ADS.IMMOBILIENSCOUT24 ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@TRACK.OZONION[1].TXT [ /TRACK.OZONION ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@CONTENT.YIELDMANAGER[4].TXT [ /CONTENT.YIELDMANAGER ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@TRACKING.QUISMA[2].TXT [ /TRACKING.QUISMA ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@GENENTECH.122.2O7[1].TXT [ /GENENTECH.122.2O7 ]
        C:\USERS\INGEBORG\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\INGEBORG@TRIBALFUSION[1].TXT [ /TRIBALFUSION ]

Vielen Dank
KastorPollux

cosinus 16.07.2012 14:36

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?


Alle Zeitangaben in WEZ +1. Es ist jetzt 09:51 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58